AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H H H 9.5 .7758 99.5 —
AFFECTED Product Versions Fixed ServiceNow AI Platform unspecified —
TIMELINE Apr 22 Reserved by CNA Jul 13 Published (CNA: SN)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
336 CVEs published, led by openclaw (15).
336 CVEs published July 13, 2026: 49 critical, 147 high, 108 medium, 32 low; 0 in the KEV catalog at press time; 8 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 311 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 2797 | 15200 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
682 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 40 | 1520 | 121 | 866 | 532 | 1 | 11 | 2 | 0.1 | 7.5 | .0014 | -55 ▼ |
| 79 | 1344 | 149 | 608 | 549 | 38 | 77 | 6 | 0.4 | 7.8 | .0024 | -512 ▼ | |
| microsoft | 54 | 811 | 61 | 555 | 189 | 6 | 286 | 20 | 2.5 | 7.8 | .0046 | -153 ▼ |
| red hat | 39 | 261 | 14 | 103 | 127 | 17 | 2 | 0 | 0.0 | 6.5 | .0031 | -5 ▼ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | -14 ▼ |
| canonical | 1 | 21 | 2 | 6 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +1 ▲ |
| suse | 6 | 19 | 4 | 11 | 4 | 0 | 0 | 0 | 0.0 | 8.6 | .0042 | +6 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +20 ▲ |
| cisco | 8 | 30 | 6 | 14 | 10 | 0 | 56 | 11 | 36.7 | 7.5 | .0057 | +5 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | -17 ▼ |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 ▼ |
| fortinet | 0 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | -2 ▼ |
| ivanti | 0 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | -4 ▼ |
| f5 | 0 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 65 | 220 | 42 | 86 | 80 | 11 | 33 | 1 | 0.5 | 7.3 | .0058 | -2 ▼ |
| mozilla | 4 | 60 | 12 | 18 | 30 | 0 | 9 | 0 | 0.0 | 6.9 | .0026 | -1 ▼ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -4 ▼ |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0039 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | -2 ▼ |
| adobe | 5 | 149 | 13 | 55 | 79 | 2 | 19 | 3 | 2.0 | 6.2 | .0021 | -119 ▼ |
| ibm | 2 | 126 | 38 | 42 | 46 | 0 | 6 | 0 | 0.0 | 7.5 | .0034 | -9 ▼ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 6 | 0 | 0.0 | 7.5 | .0037 | +5 ▲ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .7758 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| siemens | 4 | 13 | 0 | 7 | 6 | 0 | 0 | 0 | 0.0 | 7.1 | .0023 | -3 ▼ |
| d-link | 1 | 13 | 0 | 5 | 3 | 5 | 3 | 0 | 0.0 | 6.0 | .0059 | -8 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -5 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -1 ▼ |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 35 | 106 | 0 | 0 | 55 | 51 | 0 | 0 | 0.0 | 5.5 | .0032 | -1 ▼ |
| dell | 33 | 89 | 5 | 41 | 40 | 3 | 2 | 1 | 1.1 | 7.0 | .0021 | +26 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | +20 ▲ |
| openclaw | 16 | 83 | 0 | 48 | 25 | 10 | 0 | 0 | 0.0 | 7.2 | .0024 | -18 ▼ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -68 ▼ |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0080 | 0 |
| itsourcecode | 11 | 64 | 0 | 0 | 19 | 45 | 0 | 0 | 0.0 | 2.1 | .0033 | -11 ▼ |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE-2026-48282 | .4239 | 98.6 | 10.0 |
| CVE-2026-12569 | .4059 | 98.5 | 9.3 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 |
| Vendor | CVEs |
|---|---|
| 578 | |
| linux | 458 |
| oracle | 240 |
| red hat | 123 |
| apache | 119 |
| capgo | 81 |
| microsoft | 68 |
| ibm | 66 |
| dell | 64 |
| themerex | 60 |
| Vendor | KEV |
|---|---|
| microsoft | 20 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 61 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE-2026-48282 | Adobe | 0 |
| CVE-2026-48558 | SimpleHelp | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1699 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1699 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1699 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1699 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1699 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1699 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1699 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1699 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1699 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1699 |
EXPLOIT PUBLISHED — CVE-2026-51536. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-51537. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-51538. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-51540. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-51541. Public exploit reference added.
How to read these box scores · glossary
336 CVEs published. 25 box scores, 311 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H H H 9.5 .7758 99.5 —
AFFECTED Product Versions Fixed ServiceNow AI Platform unspecified —
TIMELINE Apr 22 Reserved by CNA Jul 13 Published (CNA: SN)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0409 89.9 —
AFFECTED Product Versions Fixed Flamingo 4.12.2 – —
TIMELINE Jul 10 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0291 85.9 —
AFFECTED Product Versions Fixed 9Router unspecified —
TIMELINE Jul 7 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0234 82.3 —
AFFECTED Product Versions Fixed Flamingo 4.12.2 – —
TIMELINE Jul 8 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0177 76.4 —
AFFECTED Product Versions Fixed Tomato 1.0 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0177 76.4 —
AFFECTED Product Versions Fixed Tomato 1.0 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0139 70.2 —
AFFECTED Product Versions Fixed DC-80 unspecified —
TIMELINE Jan 6 Reserved by CNA Jul 13 Published (CNA: DIVD)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0139 70.2 —
AFFECTED Product Versions Fixed DC-80 unspecified —
TIMELINE Jan 6 Reserved by CNA Jul 13 Published (CNA: DIVD)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0112 63.6 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Feb 16 Reserved by CNA Jul 13 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0110 63.1 —
AFFECTED Product Versions Fixed DC-80 unspecified —
TIMELINE Jan 6 Reserved by CNA Jul 13 Published (CNA: DIVD)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 7.7 .0108 62.5 —
AFFECTED Product Versions Fixed laravel-mediable unspecified —
TIMELINE Jun 2 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0103 61.0 —
AFFECTED Product Versions Fixed laravel-mediable unspecified —
TIMELINE Jun 2 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0088 56.3 —
AFFECTED Product Versions Fixed ThemisNETPanel unspecified —
TIMELINE Apr 22 Reserved by CNA Jul 13 Published (CNA: CERT-PL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0086 55.6 —
AFFECTED Product Versions Fixed hfs 3.0.0 – —
TIMELINE Jul 10 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0085 55.5 —
AFFECTED Product Versions Fixed CH22 1.0.0.1 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H N H 9.6 .0084 55.0 —
AFFECTED Product Versions Fixed Infra Monitoring 24.10.0 – —
TIMELINE Jul 2 Reserved by CNA Jul 13 Published (CNA: Centreon)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0079 53.5 —
AFFECTED Product Versions Fixed Tomato 1.0 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0079 53.5 —
AFFECTED Product Versions Fixed Tomato 1.0 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0078 53.3 —
AFFECTED Product Versions Fixed luci-app-banip unspecified d9bbc372e29618a8807b693a1ccf6d0e42cd196c
TIMELINE Jul 13 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0077 52.8 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 8 Reserved by CNA Jul 13 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0076 52.5 —
AFFECTED Product Versions Fixed CRM < 7.4.0 – —
TIMELINE Jun 30 Reserved by CNA Jul 13 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0076 52.4 —
AFFECTED Product Versions Fixed 0765-110x/0100-0000 1.0.0.0 – — 0765-120x/0100-0000 1.0.0.0 – — 0765-150x/0100-0000 1.0.0.0 – — 0765-2101/0100-0000 1.0.0.0 – — 0765-2102/0100-0000 1.0.0.0 – — 0765-410x/0100-0000 1.0.0.0 – — 0765-420x/0100-0000 1.0.0.0 – — 0765-450x/0100-0000 1.0.0.0 – —
TIMELINE Mar 24 Reserved by CNA Jul 13 Published (CNA: CERTVDE)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0074 51.7 —
AFFECTED Product Versions Fixed Apache Airflow Git provider unspecified —
TIMELINE Jun 28 Reserved by CNA Jul 13 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0073 51.6 —
AFFECTED Product Versions Fixed Tomato 1.0 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0072 51.0 —
AFFECTED Product Versions Fixed Ollama 0.7.1 – —
TIMELINE Jul 13 Reserved by CNA Jul 13 Published (CNA: zdi)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-13014 | 9.2 | 50.5 | Thales CERT | Suspicious | CWE-22 | Remote Code Execution vulnerability in "Suspicious" application |
| CVE-2026-12257 | 9.3 | 50.2 | Mura Software | CMS | CWE-94 | Remote code execution in Mura Software’s CMS |
| CVE-2026-15542 | 6.9 | 50.2 | will-moss | Isaiah | CWE-287 | will-moss Isaiah Websocket Connection Authentication main.go improper authent… |
| CVE-2026-15557 | 5.5 | 49.9 | waooAI | waoowaoo | CWE-287 | waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight impr… |
| CVE-2026-62327 | 9.3 | 47.9 | decolua | 9Router | CWE-306 | 9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats |
| CVE-2026-62328 | 8.7 | 47.2 | decolua | 9Router | CWE-359 | 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints |
| CVE-2026-57856 | 8.7 | 46.3 | Cockpit HQ | Cockpit CMS | CWE-22 | Cockpit CMS Path Traversal via Bucket Name in Bucket File Storage API |
| CVE-2026-52533 | 9.8 | 46.1 | n/a | n/a | CWE-269 | An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escal… |
| CVE-2026-59245 | 8.1 | 46.0 | Apache Software Foundation | Apache Airflow FAB provider | CWE-269 | Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the… |
| CVE-2026-41041 | 9.1 | 45.9 | Apache Software Foundation | Apache Gravitino | CWE-177 | Apache Gravitino: URL path injection via unencoded user-supplied identifiers … |
| CVE-2026-39042 | 7.5 | 45.2 | n/a | n/a | CWE-190 | An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4… |
| CVE-2026-55771 | 8.8 | 44.8 | cedar-policy | cedar-java | CWE-94 | CedarJava has policy injection, type confusion, and incorrect equality compar… |
| CVE-2026-58228 | 5.1 | 44.8 | phoenixframework | phoenix_live_view | CWE-79 | Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link> |
| CVE-2026-57811 | 10.0 | 44.3 | Realtyna | Realtyna Organic IDX plugin | CWE-94 | WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution… |
| CVE-2026-57724 | 9.8 | 44.3 | Themeum | Kirki | CWE-502 | WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability |
| CVE-2026-57738 | 9.8 | 44.3 | axiomthemes | 777 | CWE-502 | WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability |
| CVE-2026-57744 | 9.8 | 44.3 | stmcan | RT-Theme 18 | Extensions | CWE-502 | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulne… |
| CVE-2026-57770 | 9.8 | 44.3 | ThemeGoods | Grand Photography | CWE-502 | WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability |
| CVE-2026-59518 | 9.8 | 44.3 | wpWax | Directorist | CWE-502 | WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability |
| CVE-2026-57433 | 9.8 | 44.0 | HAARG | Storable | CWE-190 | Storable versions before 3.41 for Perl have a signed integer overflow when de… |
| CVE-2026-57743 | 8.1 | 43.9 | stmcan | RT-Theme 18 | Extensions | CWE-98 | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulne… |
| CVE-2026-57401 | 9.9 | 43.4 | Brainstorm Force | SureDash | CWE-22 | WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability |
| CVE-2026-22096 | 9.3 | 43.3 | EVbee | DC-80 | CWE-306 | Missing authentication for webserver endpoints |
| CVE-2026-15541 | 6.9 | 43.2 | will-moss | Isaiah | CWE-862 | will-moss Isaiah Master Websocket server.go Server.Handle authorization |
| CVE-2026-59521 | 7.2 | 43.0 | ShapedPlugin LLC | Real Testimonials | CWE-502 | WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerabi… |
| CVE-2026-57389 | 8.6 | 42.6 | Adrian Tobey | Groundhogg | CWE-22 | WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability |
| CVE-2026-57709 | 8.6 | 42.6 | WP Swings | Membership For WooCommerce | CWE-22 | WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletio… |
| CVE-2026-15530 | 5.5 | 42.5 | n/a | WuzhiCMS | CWE-200 | WuzhiCMS Attachment API index.php listimage information disclosure |
| CVE-2026-22102 | 9.3 | 42.5 | EVbee | DC-80 | CWE-20 | Arbitrary file overwrite through certificate update functionality |
| CVE-2026-62199 | 8.7 | 42.1 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering |
| CVE-2026-62200 | 8.7 | 42.1 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport |
| CVE-2026-57855 | 8.7 | 42.0 | Cockpit HQ | Cockpit CMS | CWE-284 | Cockpit CMS Missing Authorization in Bucket File Storage API |
| CVE-2026-61463 | 8.7 | 42.0 | go-shiori | shiori | CWE-269 | Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account |
| CVE-2026-57719 | 10.0 | 41.9 | CodeRevolution | Aimogen Pro | CWE-434 | WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability |
| CVE-2026-61505 | 6.9 | 41.9 | rejetto | hfs | CWE-22 | Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter |
| CVE-2026-62240 | 8.3 | 41.8 | crewAIInc | crewAI | CWE-918 | CrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools |
| CVE-2026-55773 | 8.8 | 41.7 | cedar-policy | cedar-java | CWE-94 | CedarJava has a policy injection vulnerability |
| CVE-2026-57371 | 8.8 | 41.7 | denishua | WPJAM Basic | CWE-502 | WordPress WPJAM Basic plugin <= 7.0 - PHP Object Injection vulnerability |
| CVE-2026-57788 | 7.5 | 41.2 | Edge-Themes | Aalto | CWE-98 | WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability |
| CVE-2026-57789 | 7.5 | 41.2 | jwsthemes | Aqua | CWE-98 | WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability |
| CVE-2026-57790 | 7.5 | 41.2 | ThemeMove | Billey | CWE-98 | WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability |
| CVE-2026-57791 | 7.5 | 41.2 | ThemeMove | Brook | CWE-98 | WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability |
| CVE-2026-57792 | 7.5 | 41.2 | Mikado-Themes | Dør | CWE-98 | WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability |
| CVE-2026-57793 | 7.5 | 41.2 | Elated-Themes | Flow | CWE-98 | WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability |
| CVE-2026-57794 | 7.5 | 41.2 | uxper | Golo Framework | CWE-98 | WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability |
| CVE-2026-57795 | 7.5 | 41.2 | themelexus | Kitchor | CWE-98 | WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability |
| CVE-2026-57796 | 7.5 | 41.2 | VLThemes | Leedo | CWE-98 | WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability |
| CVE-2026-57798 | 7.5 | 41.2 | SaurabhSharma | NewsPlus Shortcodes | CWE-98 | WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerab… |
| CVE-2026-57799 | 7.5 | 41.2 | uxper | Nuss | CWE-98 | WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability |
| CVE-2026-57800 | 7.5 | 41.2 | Edge-Themes | Overworld | CWE-98 | WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability |
| CVE-2026-57801 | 7.5 | 41.2 | Select-Themes | SetSail | CWE-98 | WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability |
| CVE-2026-57802 | 7.5 | 41.2 | Select-Themes | Struktur | CWE-98 | WordPress Struktur theme < 2.7 - Local File Inclusion vulnerability |
| CVE-2026-57803 | 7.5 | 41.2 | Select-Themes | Struktur Core | CWE-98 | WordPress Struktur Core plugin < 2.7 - Local File Inclusion vulnerability |
| CVE-2026-57804 | 7.5 | 41.2 | CodexThemes | TheGem Theme Elements (for Elementor) | CWE-98 | WordPress TheGem Theme Elements (for Elementor) plugin < 5.12.1.1 - Local Fil… |
| CVE-2026-57805 | 7.5 | 41.2 | Select-Themes | Tonda | CWE-98 | WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability |
| CVE-2026-61462 | 9.2 | 41.1 | zereight | mcp-gitlab | CWE-73 | mcp-gitlab Path Traversal via job_id Parameter |
| CVE-2026-62190 | 8.7 | 41.1 | OpenClaw | OpenClaw | CWE-706 | OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper |
| CVE-2026-57815 | 7.5 | 40.7 | WPMU DEV - Your All-in-One WordPress Platform | Forminator | CWE-22 | WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability |
| CVE-2026-51536 | 9.1 | 40.0 | n/a | n/a | CWE-190 | In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial… |
| CVE-2026-49876 | 6.5 | 40.0 | Apache Software Foundation | Apache Gravitino | CWE-918 | Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-si… |
| CVE-2026-58487 | 5.1 | 40.0 | hedgedoc | hedgedoc | CWE-79 | HedgeDoc: Stored HTML injection via email local-part |
| CVE-2026-51539 | 7.5 | 39.8 | n/a | n/a | CWE-400 | A Denial of Service (DoS) vulnerability exists in the receive loop of libmodb… |
| CVE-2026-57813 | 9.8 | 39.4 | properfraction | MailOptin | CWE-266 | WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability |
| CVE-2026-62242 | 7.7 | 39.4 | codecentric | spring-boot-admin | CWE-918 | Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration |
| CVE-2026-51537 | 9.1 | 39.2 | n/a | n/a | CWE-125 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue i… |
| CVE-2026-57710 | 9.9 | 39.2 | quantumcloud | WoowBot Pro Max | CWE-434 | WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability |
| CVE-2026-55772 | 8.8 | 39.2 | cedar-policy | cedar-java | CWE-843 | CedarJava has a type confusion vulnerability |
| CVE-2026-57697 | 7.5 | 39.0 | Metagauss | ProfileGrid | CWE-288 | WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability |
| CVE-2026-15595 | 2.1 | 38.6 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System forsubject.php cross site sc… |
| CVE-2026-15596 | 2.1 | 38.6 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System subject.php cross site scrip… |
| CVE-2026-15594 | 2.9 | 38.1 | waooAI | waoowaoo | CWE-266 | waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authoriza… |
| CVE-2026-57713 | 8.8 | 38.0 | Marcus (aka @msykes) | Events Manager | CWE-502 | WordPress Events Manager plugin <= 7.3.6 - PHP Object Injection vulnerability |
| CVE-2026-62185 | 8.6 | 37.9 | argoproj | argo-helm | CWE-1188 | Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE |
| CVE-2026-11964 | 9.1 | 37.5 | Unknown | User Registration & Membership | — | User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signa… |
| CVE-2026-62194 | 8.7 | 37.0 | OpenClaw | OpenClaw | CWE-732 | OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install |
| CVE-2026-15538 | 5.3 | 37.0 | primefaces | primereact | CWE-94 | primefaces primereact API ObjectUtils.mutateFieldData prototype pollution |
| CVE-2026-12582 | 8.6 | 36.9 | Unknown | Library Management System | — | Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id |
| CVE-2026-15529 | 5.3 | 36.5 | yzhao062 | pyod | CWE-20 | yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization |
| CVE-2026-15516 | 2.9 | 36.5 | n/a | MacCMS Pro | CWE-285 | MacCMS Pro Installation Index.php step5 authorization |
| CVE-2026-15574 | 7.5 | 36.4 | Red Hat | Red Hat OpenShift AI (RHOAI) | CWE-538 | Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header an… |
| CVE-2026-57830 | 8.8 | 36.2 | joomshaper.com | Helix Ultimate extension for Joomla | CWE-862 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion i… |
| CVE-2026-15607 | 2.1 | 36.3 | tanstack | db | CWE-94 | tanstack db Alias Path select.ts select prototype pollution |
| CVE-2026-58411 | 7.0 | 36.2 | ChurchCRM | CRM | CWE-79 | ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request pa… |
| CVE-2026-61503 | 6.9 | 36.2 | rejetto | hfs | CWE-204 | Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences |
| CVE-2026-4765 | 5.1 | 36.2 | RD Station Conversas | Tallos Chat | CWE-79 | Stored Cross-Site Scripting (XSS) in Tallos Chat by RD Station Conversas |
| CVE-2026-15533 | 2.0 | 35.9 | n/a | DedeCMS | CWE-74 | DedeCMS Column Management search.php code injection |
| CVE-2026-13221 | 9.1 | 35.8 | SHAY | perl | CWE-190 | Perl versions through 5.43.9 produce silently incorrect regular expression ma… |
| CVE-2026-15537 | 5.5 | 35.7 | SourceCodester | Online Book Store System | CWE-74 | SourceCodester Online Book Store System login.php sql injection |
| CVE-2026-15597 | 5.5 | 35.7 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection |
| CVE-2026-15535 | 2.1 | 35.6 | AkariAsai | self-rag | CWE-20 | AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserializa… |
| CVE-2026-22098 | 9.2 | 35.4 | EVbee | DC-80 | CWE-532 | Sensitive information is written to logs |
| CVE-2026-14846 | 4.5 | 35.1 | PrestaShop | The firmware | CWE-1236 | Incorrect neutralisation in the PrestaShop firmware |
| CVE-2026-15598 | 5.3 | 35.1 | antv | layout | CWE-94 | antv layout object.js setNestedValue prototype pollution |
| CVE-2026-51540 | 9.8 | 34.8 | n/a | n/a | CWE-191 | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe m… |
| CVE-2026-51541 | 9.1 | 34.8 | n/a | n/a | CWE-125 | OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message … |
| CVE-2026-6850 | 6.5 | 34.8 | Mattermost | Mattermost | CWE-1333 | Crafted message attachment causes client-side denial of service via markdown … |
| CVE-2026-15540 | 2.1 | 34.8 | SourceCodester | Online Book Store System | CWE-73 | SourceCodester Online Book Store System Administrative index.php php file inc… |
| CVE-2026-61501 | 5.3 | 34.6 | rejetto | hfs | CWE-79 | Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer |
| CVE-2026-14165 | 7.5 | 34.5 | Dassault Systèmes | Tuleap Enterprise Edition | CWE-639 | Authorization Bypass Through User-Controlled Key vulnerability affecting Tule… |
| CVE-2026-49969 | 5.3 | 34.6 | plank | laravel-mediable | CWE-918 | Laravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL Handling |
| CVE-2026-15618 | 2.1 | 34.6 | mosaxiv | clawlet | CWE-693 | mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection me… |
| CVE-2026-57386 | 8.8 | 34.5 | Kodezen LLC | aBlocks | CWE-266 | WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability |
| CVE-2026-57410 | 8.8 | 34.5 | MailerPress Team | MailerPress | CWE-266 | WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability |
| CVE-2026-15584 | 7.5 | 34.4 | Red Hat | Pen Drive Powered by Red Hat Lightspeed | CWE-250 | Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot deb… |
| CVE-2026-62192 | 7.2 | 34.3 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass |
| CVE-2026-57774 | 5.3 | 34.2 | vowelweb | VW Food Corner | CWE-862 | WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability |
| CVE-2026-57776 | 5.3 | 34.2 | vowelweb | VW Wedding | CWE-862 | WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability |
| CVE-2026-12385 | 4.3 | 34.0 | nextendweb | Smart Slider 3 | CWE-200 | Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contribu… |
| CVE-2026-15517 | 5.5 | 33.9 | Jinher | OA | CWE-74 | Jinher OA PlanGiveOut.aspx sql injection |
| CVE-2026-15553 | 6.9 | 33.8 | Ragic | Enterprise Cloud Database | CWE-434 | Ragic|Enterprise Cloud Database - Arbitrary File Upload |
| CVE-2026-61458 | 8.7 | 33.7 | pglombardo | PasswordPusher | CWE-307 | PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint |
| CVE-2026-15680 | 7.5 | 33.7 | Lorex | 2K Indoor Wi-Fi Security Camera | CWE-134 | Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Co… |
| CVE-2026-58488 | 6.9 | 33.4 | hedgedoc | hedgedoc | CWE-290 | HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing |
| CVE-2026-62143 | 8.3 | 33.3 | misp | misp-modules | CWE-918 | Server-Side Request Forgery protection bypass in misp-modules html_to_markdow… |
| CVE-2026-57702 | 9.3 | 32.9 | Melograno Venture Studio | Amelia | CWE-89 | WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability |
| CVE-2026-57707 | 9.3 | 32.9 | quantumcloud | Simple Business Directory Pro | CWE-89 | WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vuln… |
| CVE-2026-57714 | 9.3 | 32.9 | LatePoint | LatePoint | CWE-89 | WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability |
| CVE-2026-57726 | 9.3 | 32.9 | Themeum | Kirki | CWE-89 | WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability |
| CVE-2026-57739 | 9.3 | 32.9 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-89 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulner… |
| CVE-2026-59515 | 9.3 | 32.9 | Sergey | AIWU | CWE-89 | WordPress AIWU plugin <= 1.5.4 - SQL Injection vulnerability |
| CVE-2026-58486 | 8.3 | 32.5 | hedgedoc | hedgedoc | CWE-400 | HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter |
| CVE-2026-62195 | 8.7 | 32.4 | OpenClaw | OpenClaw | CWE-732 | OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback |
| CVE-2026-62196 | 8.7 | 32.4 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs |
| CVE-2026-15539 | 2.0 | 32.5 | SourceCodester | Online Book Store System | CWE-284 | SourceCodester Online Book Store System Book Image Upload Feature index.php b… |
| CVE-2026-57727 | 7.5 | 32.2 | Themeum | Kirki | CWE-862 | WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability |
| CVE-2026-57729 | 7.5 | 32.2 | UX-themes | Flatsome | CWE-862 | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability |
| CVE-2026-56877 | 6.3 | 32.1 | Skillable | SCORM Lab Launch Integration | CWE-472 | The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026… |
| CVE-2026-51538 | 9.1 | 31.6 | n/a | n/a | CWE-284 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access … |
| CVE-2026-58500 | 8.2 | 31.5 | appium | appium-mcp | CWE-79 | MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGener… |
| CVE-2026-57773 | 7.6 | 31.1 | Zorem | Advanced Shipment Tracking for WooCommerce | CWE-89 | WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Inje… |
| CVE-2026-61955 | 7.6 | 31.0 | Hannan | گرویتی فرم فارسی | CWE-89 | WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability |
| CVE-2026-15518 | 2.0 | 30.4 | AREA 17 | Twill CMS | CWE-284 | AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile un… |
| CVE-2026-62189 | 7.6 | 30.3 | OpenClaw | OpenClaw | CWE-59 | OpenClaw < 2026.6.9 Symlink Following via Mirror Sync |
| CVE-2026-15525 | 2.1 | 30.2 | kLOsk | adloop | CWE-918 | kLOsk adloop write.py _validate_urls server-side request forgery |
| CVE-2026-57393 | 6.5 | 29.8 | EDGARROJAS | WooCommerce PDF Invoice Builder | CWE-497 | WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Ex… |
| CVE-2026-15532 | 1.9 | 29.5 | SourceCodester | Online Book Store System | CWE-79 | SourceCodester Online Book Store System User Management cross site scripting |
| CVE-2026-62187 | 8.6 | 29.4 | openclaw | feishu | CWE-863 | OpenClaw < 2026.6.9 Feishu tools Authorization Bypass |
| CVE-2026-62188 | 8.6 | 29.4 | openclaw | feishu | CWE-863 | OpenClaw < 2026.6.9 Feishu Authorization Bypass |
| CVE-2026-62191 | 7.1 | 29.1 | OpenClaw | OpenClaw | CWE-862 | OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations |
| CVE-2026-58408 | 6.5 | 28.8 | ChurchCRM | CRM | CWE-862 | ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privilege… |
| CVE-2026-9708 | 4.9 | 28.7 | Mattermost | Mattermost | CWE-639 | Incoming webhook user attribution via unvalidated webhook owner |
| CVE-2026-49971 | 5.3 | 28.6 | plank | laravel-mediable | CWE-79 | Laravel-Mediable < 7.0.0 Stored XSS via SVG File Upload |
| CVE-2026-57385 | 8.5 | 28.4 | appsbd | Vitepos | CWE-89 | WordPress Vitepos plugin <= 3.4.2 - SQL Injection vulnerability |
| CVE-2026-57771 | 8.5 | 28.4 | Milan Petrovic | GD Rating System | CWE-89 | WordPress GD Rating System plugin <= 3.7 - SQL Injection vulnerability |
| CVE-2026-57772 | 8.5 | 28.4 | WP Inventory | WP Inventory Manager | CWE-89 | WordPress WP Inventory Manager plugin <= 2.4.0 - SQL Injection vulnerability |
| CVE-2026-57787 | 8.5 | 28.4 | CreativeWS | CWS SVGicons | CWE-89 | WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability |
| CVE-2026-57810 | 8.5 | 28.4 | Saad Iqbal | APIExperts Square for WooCommerce | CWE-89 | WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection v… |
| CVE-2026-57698 | 6.5 | 28.2 | VillaTheme | Abandoned Cart Recovery for WooCommerce | CWE-288 | WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken A… |
| CVE-2026-62147 | 6.5 | 28.0 | Red Hat | Red Hat OpenShift distributed tracing 3 | CWE-863 | Tempo-operator: tempo operator: query rbac bypass |
| CVE-2026-40469 | 5.1 | 27.9 | GNU | gawk | CWE-190 | Heap buffer overflow in gawk |
| CVE-2026-14934 | 9.4 | 27.7 | Google Cloud | BigQuery | CWE-862 | Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dat… |
| CVE-2026-57364 | 6.5 | 27.7 | WPDeveloper | Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More | CWE-1284 | WordPress Better Payment – Instant Payments, Donations, Fundraising with Subs… |
| CVE-2026-11963 | 8.1 | 27.6 | Unknown | User Registration & Membership | — | User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Memb… |
| CVE-2026-57378 | 7.5 | 27.2 | Phil Kurth | Advanced Forms | CWE-862 | WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability |
| CVE-2026-57705 | 7.5 | 27.2 | Nexcess | Event Tickets | CWE-862 | WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability |
| CVE-2026-15519 | 1.3 | 27.1 | usestrix | strix | CWE-829 | usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted c… |
| CVE-2026-58102 | 9.1 | 26.6 | JONASBN | Crypt::OpenSSL::X509 | CWE-125 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bound… |
| CVE-2026-15552 | 5.3 | 26.6 | Ragic | Enterprise Cloud Database | CWE-79 | Ragic|Enterprise Cloud Database - Stored Cross-Site Scripting |
| CVE-2026-57395 | 6.5 | 26.5 | Themefic | Tourfic | CWE-862 | WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability |
| CVE-2026-57418 | 6.5 | 26.5 | BoldGrid | Client Invoicing by Sprout Invoices | CWE-862 | WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Acce… |
| CVE-2025-45869 | 7.3 | 26.3 | n/a | n/a | CWE-918 | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server… |
| CVE-2026-57694 | 6.5 | 25.9 | Themeum | Tutor LMS | CWE-639 | WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDO… |
| CVE-2026-22097 | 9.3 | 25.8 | EVbee | DC-80 | CWE-347 | Missing firmware validation allows remote code execution |
| CVE-2026-62197 | 6.3 | 25.8 | OpenClaw | OpenClaw | CWE-918 | OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery |
| CVE-2026-15523 | 2.1 | 25.7 | CodeAstro | Simple Online Leave Management System | CWE-74 | CodeAstro Simple Online Leave Management System dashboard.php sql injection |
| CVE-2026-15536 | 2.1 | 25.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patviewprescription.php sql injection |
| CVE-2026-15558 | 2.1 | 25.7 | CodeAstro | Simple Online Leave Management System | CWE-74 | CodeAstro Simple Online Leave Management System deletemp.php sql injection |
| CVE-2026-15559 | 2.1 | 25.7 | CodeAstro | Simple Online Leave Management System | CWE-74 | CodeAstro Simple Online Leave Management System POST accept.php sql injection |
| CVE-2026-57377 | 6.5 | 25.6 | WPXPO | WowAddons | CWE-862 | WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability |
| CVE-2026-57390 | 6.5 | 25.6 | EDGARROJAS | Extra Product Options Builder for WooCommerce | CWE-862 | WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - B… |
| CVE-2026-57392 | 6.5 | 25.6 | Themefic | Tourfic | CWE-862 | WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability |
| CVE-2026-57400 | 6.5 | 25.6 | WP Swings | Event Tickets Manager for WooCommerce | CWE-862 | WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Acce… |
| CVE-2026-57404 | 6.5 | 25.6 | magepeopleteam | Booking and Rental Manager | CWE-862 | WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control … |
| CVE-2026-57406 | 6.5 | 25.6 | Roxnor | FundEngine | CWE-862 | WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability |
| CVE-2026-57408 | 6.5 | 25.6 | peachpayments | Peach Payments Gateway | CWE-862 | WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vuln… |
| CVE-2026-57412 | 6.5 | 25.6 | Codemenschen | Gift Vouchers | CWE-862 | WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability |
| CVE-2026-57424 | 6.5 | 25.6 | knitpay | Razorpay Payment Links for WooCommerce | CWE-862 | WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Acc… |
| CVE-2026-57812 | 6.5 | 25.6 | NSquared | Simply Schedule Appointments | CWE-862 | WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Con… |
| CVE-2026-61952 | 4.9 | 25.5 | Jose Vega | WooCommerce Bulk Edit Products – WP Sheet Editor | CWE-862 | WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 -… |
| CVE-2026-61975 | 5.3 | 25.3 | Crocoblock | JetReviews | CWE-497 | WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-61976 | 5.3 | 25.3 | Crocoblock | JetBlocks For Elementor | CWE-497 | WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure v… |
| CVE-2026-61977 | 5.3 | 25.3 | Crocoblock | JetSearch | CWE-497 | WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-57797 | 4.3 | 25.3 | ThemeMove | EduMall | CWE-862 | WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability |
| CVE-2026-62186 | 7.2 | 25.1 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override |
| CVE-2026-15531 | 1.9 | 24.6 | yashbhalgat | HashNeRF-pytorch | CWE-20 | yashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deseriali… |
| CVE-2026-57768 | 8.2 | 24.3 | favethemes | Houzez Login Register | CWE-266 | WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulner… |
| CVE-2026-57405 | 7.1 | 24.3 | themehunk | Open Shop | CWE-862 | WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability |
| CVE-2026-57740 | 7.1 | 24.3 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-862 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Contro… |
| CVE-2026-62193 | 6.9 | 24.1 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install |
| CVE-2026-61971 | 2.7 | 23.6 | Cozmoslabs | User Profile Picture | CWE-639 | WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object Refer… |
| CVE-2026-58101 | 7.5 | 23.0 | JONASBN | Crypt::OpenSSL::X509 | CWE-476 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service v… |
| CVE-2026-9571 | 6.5 | 22.4 | Mattermost | Mattermost | CWE-305 | Deactivated user accounts can continue to obtain valid OAuth access tokens vi… |
| CVE-2026-22099 | 8.7 | 22.1 | EVbee | DC-80 | CWE-287 | Missing authentication for Bluetooth communication |
| CVE-2026-10106 | 6.5 | 21.9 | Mattermost | Mattermost | CWE-863 | Unauthorized users can trigger interactive post actions in private channels v… |
| CVE-2026-12274 | 6.5 | 21.9 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR |
| CVE-2026-57419 | 6.5 | 21.9 | Fahad Mahmood | Stock Locations for WooCommerce | CWE-862 | WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Con… |
| CVE-2026-57778 | 5.3 | 21.4 | wpdevart | Booking calendar, Appointment Booking System | CWE-862 | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Bro… |
| CVE-2026-57779 | 5.3 | 21.4 | themebeez | Fascinate | CWE-862 | WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability |
| CVE-2026-57781 | 5.3 | 21.4 | Sovlix | MeetingHub | CWE-862 | WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability |
| CVE-2026-57782 | 5.3 | 21.4 | PressTigers | Universal Clocks | CWE-862 | WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability |
| CVE-2026-61983 | 5.3 | 21.4 | andy_moyle | Church Admin | CWE-862 | WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability |
| CVE-2026-61985 | 5.3 | 21.4 | magepeopleteam | Car Rental Manager | CWE-862 | WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerab… |
| CVE-2026-14906 | 5.3 | 21.0 | Mozilla | Firefox for iOS | CWE-434 | Malicious webpage titles could allow overwriting of bundled PDF resources whe… |
| CVE-2026-40553 | 5.1 | 21.0 | GNU | gawk | CWE-121 | Stack-based buffer overflow in gawk |
| CVE-2026-12275 | 7.1 | 20.9 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private C… |
| CVE-2026-58410 | 7.1 | 20.9 | ChurchCRM | CRM | CWE-639 | ChurchCRM: Improper object-level authorization allows low-privileged users to… |
| CVE-2026-10085 | 5.4 | 20.7 | Mattermost | Mattermost | CWE-862 | Ordinary group/direct message member can enable group_constrained and remove … |
| CVE-2026-12271 | 5.4 | 20.7 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR |
| CVE-2026-12396 | 5.4 | 20.7 | Unknown | WP Job Portal | — | WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rej… |
| CVE-2026-61958 | 5.4 | 20.7 | Saad Iqbal | License Manager for WooCommerce | CWE-862 | WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Conten… |
| CVE-2026-61968 | 5.4 | 20.7 | Saad Iqbal | myCred | CWE-862 | WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability |
| CVE-2026-12273 | 4.3 | 20.3 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation |
| CVE-2026-62198 | 5.3 | 18.8 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search |
| CVE-2026-9824 | 4.3 | 18.7 | Mattermost | Mattermost | CWE-862 | Remote cluster metadata enumeration via /share-channel autocomplete |
| CVE-2026-12397 | 4.3 | 18.7 | Unknown | WP Job Portal | — | WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR |
| CVE-2026-48363 | 8.2 | 18.5 | Adobe | ColdFusion | CWE-427 | ColdFusion | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-48364 | 8.2 | 18.5 | Adobe | ColdFusion | CWE-427 | ColdFusion | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-57372 | 7.2 | 18.1 | denishua | WPJAM Basic | CWE-918 | WordPress WPJAM Basic plugin <= 7.0 - Server Side Request Forgery (SSRF) vuln… |
| CVE-2026-57407 | 7.2 | 18.1 | WP Swings | PDF Generator for WordPress | CWE-918 | WordPress PDF Generator for WordPress plugin <= 1.6.2 - Server Side Request F… |
| CVE-2026-57375 | 6.5 | 18.1 | FluxBuilder | MStore API | CWE-862 | WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability |
| CVE-2026-59523 | 6.5 | 18.1 | NSquared | Simply Schedule Appointments | CWE-862 | WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Co… |
| CVE-2026-22093 | 9.5 | 17.5 | EVbee | EVbee Service | CWE-295 | Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app |
| CVE-2026-12536 | 6.4 | 17.4 | themefusion | Avada (Fusion) Builder | CWE-79 | Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-9820 | 3.8 | 16.7 | Mattermost | Mattermost | CWE-862 | Mattermost schemes teams endpoint exposes private team invite IDs |
| CVE-2026-6541 | 4.3 | 16.6 | Mattermost | Mattermost | CWE-639 | Unscoped updates to other playbooks' metric configuration |
| CVE-2026-57829 | 8.7 | 16.4 | joomshaper.com | Helix Ultimate extension for Joomla | CWE-79 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultim… |
| CVE-2026-10551 | 6.1 | 16.4 | Unknown | Breeze Cache | — | Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library |
| CVE-2026-57363 | 7.1 | 16.3 | QuantumCloud | ChatBot | CWE-79 | WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57368 | 7.1 | 16.3 | NooTheme | Jobmonster | CWE-79 | WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vu… |
| CVE-2026-57369 | 7.1 | 16.3 | themifyme | Themify Builder | CWE-79 | WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-57376 | 7.1 | 16.3 | Element Invader | ElementInvader Addons for Elementor | CWE-79 | WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Sc… |
| CVE-2026-57379 | 7.1 | 16.3 | WPPOOL | FormyChat | CWE-79 | WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57380 | 7.1 | 16.3 | hupe13 | Extensions for Leaflet Map | CWE-79 | WordPress Extensions for Leaflet Map plugin <= 5.1 - Cross Site Scripting (XS… |
| CVE-2026-57381 | 7.1 | 16.3 | Property Hive | PropertyHive | CWE-79 | WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57382 | 7.1 | 16.3 | Mitchell Bennis | Simple File List | CWE-79 | WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (… |
| CVE-2026-57383 | 7.1 | 16.3 | eyecix | JobSearch | CWE-79 | WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57387 | 7.1 | 16.3 | picu | picu | CWE-79 | WordPress picu plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57388 | 7.1 | 16.3 | Themefic | Hydra Booking | CWE-79 | WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57394 | 7.1 | 16.3 | Tribulant Software | Newsletters | CWE-79 | WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57396 | 7.1 | 16.3 | Flintop | Free Gifts for WooCommerce | CWE-79 | WordPress Free Gifts for WooCommerce plugin <= 13.1.0 - Cross Site Scripting … |
| CVE-2026-57398 | 7.1 | 16.3 | WebCodingPlace | Real Estate Manager Pro | CWE-79 | WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XS… |
| CVE-2026-57399 | 7.1 | 16.3 | Proxy & VPN Blocker | Proxy & VPN Blocker | CWE-79 | WordPress Proxy & VPN Blocker plugin <= 3.5.8 - Cross Site Scripting (XSS) vu… |
| CVE-2026-57403 | 7.1 | 16.3 | Milan Petrovic | GD Security Headers | CWE-79 | WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-57409 | 7.1 | 16.3 | RealMag777 | Active Products Tables for WooCommerce | CWE-79 | WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site… |
| CVE-2026-57411 | 7.1 | 16.3 | Aman | CF7 Views – Complete Entry Management for Contact Form 7 | CWE-79 | WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= … |
| CVE-2026-57415 | 7.1 | 16.2 | Codemenschen | Gift Vouchers | CWE-79 | WordPress Gift Vouchers plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57416 | 7.1 | 16.2 | SiteGround | SiteGround Email Marketing | CWE-79 | WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (… |
| CVE-2026-57417 | 7.1 | 16.2 | RexTheme | Cart Lift | CWE-79 | WordPress Cart Lift plugin <= 3.1.57 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57421 | 7.1 | 16.2 | CRM Perks | CRM Perks Forms | CWE-79 | WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-57422 | 7.1 | 16.2 | VillaTheme | Bopo – WooCommerce Product Bundle Builder | CWE-79 | WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflect… |
| CVE-2026-57423 | 7.1 | 16.2 | Kofi Mokome | Message Filter for Contact Form 7 | CWE-79 | WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.8 - Reflected Cro… |
| CVE-2026-57668 | 7.1 | 16.3 | Basix | NEX-Forms | CWE-79 | WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57695 | 7.1 | 16.3 | Dan Rossiter | Document Gallery | CWE-79 | WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-57706 | 7.1 | 16.3 | Dokan, Inc. | Dokan | CWE-79 | WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57708 | 7.1 | 16.3 | CRM Perks | Contact Form Entries | CWE-79 | WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) v… |
| CVE-2026-57712 | 7.1 | 16.3 | WPZOOM | WPZOOM Portfolio | CWE-79 | WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-57715 | 7.1 | 16.3 | WPManageNinja | Fluent CRM | CWE-79 | WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57718 | 7.1 | 16.3 | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-79 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-57725 | 7.1 | 16.3 | Themeum | Kirki | CWE-79 | WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57728 | 7.1 | 16.3 | UX-themes | Flatsome | CWE-79 | WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vul… |
| CVE-2026-57732 | 7.1 | 16.3 | tagDiv | tagDiv Opt-In Builder | CWE-79 | WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) … |
| CVE-2026-57733 | 7.1 | 16.3 | tagDiv | tagDiv Cloud Library | CWE-79 | WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) v… |
| CVE-2026-57734 | 7.1 | 16.3 | tagDiv | tagDiv Composer | CWE-79 | WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (X… |
| CVE-2026-57741 | 7.1 | 16.3 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-79 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting… |
| CVE-2026-57745 | 7.1 | 16.3 | stmcan | RT-Theme 18 | Extensions | CWE-79 | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scrip… |
| CVE-2026-57814 | 7.1 | 16.3 | WPMU DEV - Your All-in-One WordPress Platform | Forminator | CWE-79 | WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57816 | 7.1 | 16.2 | FunnelKit | Funnel Builder by FunnelKit | CWE-79 | WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripti… |
| CVE-2026-59516 | 7.1 | 16.3 | Room 34 Creative Services, LLC | ICS Calendar | CWE-79 | WordPress ICS Calendar plugin <= 12.1.1 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-10103 | 4.3 | 15.0 | Mattermost | Mattermost | CWE-639 | Authenticated remote cluster can modify or delete posts it does not own in Ma… |
| CVE-2026-57391 | 6.5 | 14.3 | Tangible | Loops & Logic | CWE-79 | WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-61504 | 5.1 | 14.2 | rejetto | hfs | CWE-79 | Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing |
| CVE-2026-15605 | 2.3 | 13.9 | n/a | wandb | CWE-327 | wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.downloa… |
| CVE-2026-57786 | 8.8 | 13.7 | purethemes | WorkScout-Core | CWE-352 | WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF)… |
| CVE-2026-57413 | 6.4 | 13.6 | bdthemes | Instant Image Generator | CWE-918 | WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forge… |
| CVE-2026-9597 | 5.4 | 13.6 | Mattermost | Mattermost | CWE-305 | Deactivated guest accounts can authenticate via magic-link token in Mattermos… |
| CVE-2026-12081 | 5.0 | 13.0 | Unknown | Database for Contact Form 7, WPforms, Elementor forms | — | Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticat… |
| CVE-2026-57365 | 6.5 | 12.9 | Hitesh Chandwani | reCAPTCHA (v2 & v3) for Asgaros Forum | CWE-79 | WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site … |
| CVE-2026-57402 | 6.5 | 12.9 | wpdesk | Flexible Refund and Return Order for WooCommerce | CWE-79 | WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 -… |
| CVE-2026-57414 | 6.5 | 12.9 | QuantumCloud | ChatBot for eCommerce – WoowBot | CWE-79 | WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Script… |
| CVE-2026-57420 | 6.5 | 12.9 | Netrr | Author Box WP Lens | CWE-79 | WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vul… |
| CVE-2026-57693 | 6.5 | 12.9 | Spacetime | Ad Inserter | CWE-79 | WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57711 | 6.5 | 12.9 | PSM Plugins | SupportCandy | CWE-79 | WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57780 | 6.5 | 12.9 | Plugin Envision | Envision Page Builder | CWE-79 | WordPress Envision Page Builder plugin <= 0.22 - Cross Site Scripting (XSS) v… |
| CVE-2026-57783 | 6.5 | 12.9 | merkulove | Speaker | CWE-79 | WordPress Speaker plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-61502 | 5.1 | 11.8 | rejetto | hfs | CWE-352 | Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests |
| CVE-2026-40467 | 5.1 | 11.5 | GNU | gawk | CWE-416 | Use after free in gawk |
| CVE-2026-57432 | 8.4 | 11.2 | SHAY | perl | CWE-125 | Perl versions through 5.43.10 have an integer overflow in S_measure_struct le… |
| CVE-2026-57691 | 5.8 | 9.9 | Eli | Anti-Malware Security and Brute-Force Firewall | CWE-79 | WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.89 - … |
| CVE-2026-40468 | 2.1 | 9.9 | GNU | gawk | CWE-190 | Heap buffer overflow in gawk |
| CVE-2026-15684 | 7.3 | 9.1 | Glarysoft | Glary Utilities | CWE-59 | Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerabi… |
| CVE-2026-61970 | 4.9 | 8.4 | Themeisle | Auto Featured Image (Auto Post Thumbnail) | CWE-918 | WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server … |
| CVE-2026-15520 | 1.9 | 8.1 | GNU | LibreDWG | CWE-119 | GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section he… |
| CVE-2026-15524 | 1.9 | 6.8 | alioshr | memory-bank-mcp | CWE-22 | alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal |
| CVE-2026-15526 | 1.9 | 6.8 | augmnt | augments-mcp-server | CWE-22 | augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProject… |
| CVE-2026-53365 | 5.5 | 6.8 | Linux | Linux | CWE-401 | vsock/virtio: fix zerocopy completion for multi-skb sends |
| CVE-2026-58489 | 6.8 | 6.7 | hedgedoc | hedgedoc | CWE-352 | HedgeDoc: CSRF in GitHub Gist export callback |
| CVE-2026-15521 | 1.9 | 6.7 | makafeli | n8n-workflow-builder | CWE-22 | makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal |
| CVE-2026-15522 | 1.9 | 6.7 | tugcantopaloglu | godot-mcp | CWE-22 | tugcantopaloglu godot-mcp run_project index.js validatePath path traversal |
| CVE-2026-15527 | 1.9 | 6.7 | better-auth | better-icons | CWE-22 | better-auth better-icons scan_project_icons/sync_icon path traversal |
| CVE-2026-60103 | 6.8 | 6.3 | blender | blender | CWE-125 | Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block |
| CVE-2026-62239 | 5.3 | 5.8 | Dao-AILab | flash-attention | CWE-59 | FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py |
| CVE-2026-53364 | 5.5 | 5.5 | Linux | Linux | CWE-401 | Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() |
| CVE-2026-15528 | 1.9 | 5.4 | lamaalrajih | kicad-mcp | CWE-693 | lamaalrajih kicad-mcp path_validator.py protection mechanism |
| CVE-2026-61956 | 7.1 | 5.3 | hamsalam | ووسلام – همگام سازی ووکامرس و باسلام | CWE-352 | WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site R… |
| CVE-2026-15515 | 6.4 | 5.3 | Tencent | PC Manager | CWE-426 | Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path |
| CVE-2026-9492 | 8.5 | 5.0 | GIGABYTE | MBStorage | CWE-782 | GIGABYTE|Gigabyte Control Center - Improper Access Control |
| CVE-2026-15683 | 7.5 | 4.3 | Lorex | 2K Indoor Wi-Fi Security Camera | CWE-295 | Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certi… |
| CVE-2026-7162 | 7.8 | 3.7 | WinFsp | WinFsp | CWE-190 | Successful exploitation of the integer overflow vulnerability could allow an … |
| CVE-2026-15681 | 5.5 | 3.6 | AnyDesk | AnyDesk | CWE-59 | AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability |
| CVE-2026-15682 | 5.5 | 3.6 | AnyDesk | AnyDesk | CWE-59 | AnyDesk Support Information Link Following Denial-of-Service Vulnerability |
| CVE-2026-15551 | 5.5 | 1.4 | Samsung Open Source | rlottie | CWE-190 | Samsung rlottie: Numeric truncation in gray_hline() leads to heap-based buffe… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-13 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.