CVSS EPSS %ile KEV — .3295 98.2 YES
AFFECTED Product Versions Fixed IOS unspecified —
TIMELINE Jul 13 Added to CISA KEV, due Jul 16 Jul 13 Published
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
337 CVEs published, led by openclaw (15).
337 CVEs published July 13, 2026: 49 critical, 147 high, 108 medium, 32 low; 1 in the KEV catalog at press time; 8 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 312 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 2798 | 15181 | 1296 | 2564 |
| KEV catalog size | 1671 | |||
680 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 40 | 1522 | 121 | 866 | 530 | 1 | 27 | 3 | 0.2 | 7.5 | .0013 | -56 ▼ |
| 79 | 1343 | 149 | 604 | 549 | 38 | 74 | 6 | 0.4 | 7.8 | .0023 | -512 ▼ | |
| microsoft | 54 | 820 | 61 | 555 | 189 | 6 | 380 | 28 | 3.4 | 7.8 | .0045 | -153 ▼ |
| red hat | 39 | 231 | 14 | 94 | 111 | 12 | 4 | 0 | 0.0 | 6.5 | .0026 | -5 ▼ |
| apple | 0 | 99 | 1 | 23 | 66 | 2 | 94 | 7 | 7.1 | 6.5 | .0031 | -14 ▼ |
| canonical | 1 | 21 | 2 | 6 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +1 ▲ |
| suse | 6 | 19 | 4 | 11 | 4 | 0 | 0 | 0 | 0.0 | 8.6 | .0036 | +6 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 4 | 3 | 8.3 | 8.8 | .0036 | +20 ▲ |
| cisco | 9 | 32 | 4 | 12 | 8 | 0 | 96 | 12 | 37.5 | 7.5 | .0066 | +6 ▲ |
| palo alto networks | 14 | 25 | 0 | 2 | 14 | 7 | 14 | 2 | 8.0 | 4.7 | .0021 | +5 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | -17 ▼ |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 ▼ |
| f5 | 0 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | 0 |
| ivanti | 0 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | -4 ▼ |
| fortinet | 0 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | -2 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 65 | 218 | 42 | 86 | 78 | 11 | 40 | 1 | 0.5 | 7.3 | .0048 | -2 ▼ |
| mozilla | 4 | 60 | 12 | 18 | 30 | 0 | 13 | 0 | 0.0 | 6.9 | .0025 | -1 ▼ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 5 | 1 | 2.0 | 5.9 | .0018 | +46 ▲ |
| gitlab | 7 | 40 | 0 | 5 | 27 | 6 | 4 | 2 | 5.0 | 4.7 | .0024 | -4 ▼ |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0026 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | -3 ▼ |
| adobe | 5 | 151 | 13 | 54 | 79 | 2 | 75 | 4 | 2.6 | 6.2 | .0021 | -119 ▼ |
| ibm | 2 | 126 | 38 | 42 | 46 | 0 | 7 | 0 | 0.0 | 7.5 | .0025 | -9 ▼ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 9 | 0 | 0.0 | 7.5 | .0034 | +5 ▲ |
| solarwinds | 0 | 7 | 1 | 2 | 2 | 0 | 11 | 4 | 57.1 | 7.5 | .0835 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .2673 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| d-link | 1 | 14 | 0 | 5 | 3 | 5 | 26 | 1 | 7.1 | 6.0 | .0058 | -8 ▼ |
| siemens | 4 | 13 | 0 | 7 | 6 | 0 | 1 | 0 | 0.0 | 7.1 | .0019 | -3 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -5 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -1 ▼ |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 35 | 106 | 0 | 0 | 55 | 51 | 0 | 0 | 0.0 | 5.5 | .0026 | -1 ▼ |
| dell | 33 | 89 | 4 | 41 | 40 | 3 | 2 | 1 | 1.1 | 7.0 | .0020 | +26 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0028 | +20 ▲ |
| openclaw | 16 | 83 | 0 | 48 | 25 | 10 | 0 | 0 | 0.0 | 7.2 | .0021 | -18 ▼ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -68 ▼ |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| itsourcecode | 11 | 64 | 0 | 0 | 19 | 45 | 0 | 0 | 0.0 | 2.1 | .0020 | -11 ▼ |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE-2026-48907 | .6883 | 99.3 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48282 | 10.0 | .9924 | KEV |
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-50160 | 10.0 | .1775 |
| Vendor | CVEs |
|---|---|
| 578 | |
| linux | 458 |
| oracle | 240 |
| red hat | 123 |
| apache | 119 |
| capgo | 81 |
| microsoft | 68 |
| ibm | 66 |
| dell | 64 |
| themerex | 60 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 12 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| adobe | 4 |
| solarwinds | 4 |
| synacor | 4 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 61 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1699 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1699 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1699 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1699 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1699 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1699 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1699 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1699 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1699 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1699 |
EXPLOIT PUBLISHED — CVE-2026-51536. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-51537. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-51538. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-51540. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-51541. Public exploit reference added.
How to read these box scores · glossary
337 CVEs published. 25 box scores, 312 table rows — nothing truncated.
CVSS EPSS %ile KEV — .3295 98.2 YES
AFFECTED Product Versions Fixed IOS unspecified —
TIMELINE Jul 13 Added to CISA KEV, due Jul 16 Jul 13 Published
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H H H 9.5 .2673 97.9 —
AFFECTED Product Versions Fixed ServiceNow AI Platform unspecified —
TIMELINE Apr 22 Reserved by CNA Jul 13 Published (CNA: SN)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0409 89.9 —
AFFECTED Product Versions Fixed Flamingo 4.12.2 – —
TIMELINE Jul 10 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0234 82.2 —
AFFECTED Product Versions Fixed Flamingo 4.12.2 – —
TIMELINE Jul 8 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0224 81.5 —
AFFECTED Product Versions Fixed 9Router unspecified —
TIMELINE Jul 7 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0105 61.6 —
AFFECTED Product Versions Fixed Tomato 1.0 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0105 61.6 —
AFFECTED Product Versions Fixed Tomato 1.0 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0091 57.2 —
AFFECTED Product Versions Fixed DC-80 unspecified —
TIMELINE Jan 6 Reserved by CNA Jul 13 Published (CNA: DIVD)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0091 57.2 —
AFFECTED Product Versions Fixed DC-80 unspecified —
TIMELINE Jan 6 Reserved by CNA Jul 13 Published (CNA: DIVD)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0081 54.1 —
AFFECTED Product Versions Fixed DC-80 unspecified —
TIMELINE Jan 6 Reserved by CNA Jul 13 Published (CNA: DIVD)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 7.7 .0078 53.0 —
AFFECTED Product Versions Fixed laravel-mediable unspecified —
TIMELINE Jun 2 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0077 52.8 —
AFFECTED Product Versions Fixed laravel-mediable unspecified —
TIMELINE Jun 2 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0075 52.0 —
AFFECTED Product Versions Fixed hfs 3.0.0 – —
TIMELINE Jul 10 Reserved by CNA Jul 13 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0075 52.0 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Feb 16 Reserved by CNA Jul 13 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0058 45.3 —
AFFECTED Product Versions Fixed ThemisNETPanel unspecified —
TIMELINE Apr 22 Reserved by CNA Jul 13 Published (CNA: CERT-PL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0056 44.0 —
AFFECTED Product Versions Fixed Tomato 1.0 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0053 42.4 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 8 Reserved by CNA Jul 13 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H N H 9.6 .0050 41.1 —
AFFECTED Product Versions Fixed Infra Monitoring 24.10.0 – —
TIMELINE Jul 2 Reserved by CNA Jul 13 Published (CNA: Centreon)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0049 40.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 8 Reserved by CNA Jul 13 Public exploit reference published Jul 13 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0048 39.5 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 8 Reserved by CNA Jul 13 Public exploit reference published Jul 13 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0048 39.4 —
AFFECTED Product Versions Fixed Apache Airflow Git provider unspecified —
TIMELINE Jun 28 Reserved by CNA Jul 13 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0048 39.3 —
AFFECTED Product Versions Fixed CH22 1.0.0.1 – —
TIMELINE Jul 12 Reserved by CNA Jul 13 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0047 39.2 —
AFFECTED Product Versions Fixed Apache Gravitino 1.0.0 – —
TIMELINE Apr 16 Reserved by CNA Jul 13 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0047 38.9 —
AFFECTED Product Versions Fixed Suspicious v1.2.0 – patched v1.3.5
TIMELINE Jun 23 Reserved by CNA Jul 13 Published (CNA: THA-PSIRT)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0046 38.0 —
AFFECTED Product Versions Fixed CRM < 7.4.0 – —
TIMELINE Jun 30 Reserved by CNA Jul 13 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-61505 | 6.9 | 37.7 | rejetto | hfs | CWE-22 | Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter |
| CVE-2026-4769 | 9.3 | 37.4 | WAGO | 0765-110x/0100-0000 | CWE-912 | Unauthenticated Access to Internal Diagnostic Interface |
| CVE-2026-62184 | 8.7 | 37.2 | openwrt | luci-app-banip | CWE-116 | luci-app-banip Log Monitor IP Extraction Bypass |
| CVE-2026-15544 | 7.4 | 36.6 | Shibby | Tomato | CWE-119 | Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow |
| CVE-2026-13221 | 9.1 | 36.2 | SHAY | perl | CWE-190 | Perl versions through 5.43.9 produce silently incorrect regular expression ma… |
| CVE-2026-51540 | 9.8 | 35.3 | n/a | n/a | CWE-191 | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe m… |
| CVE-2026-51541 | 9.1 | 35.3 | n/a | n/a | CWE-125 | OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message … |
| CVE-2026-52533 | 9.8 | 34.7 | n/a | n/a | CWE-269 | An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escal… |
| CVE-2026-12257 | 9.3 | 34.4 | Mura Software | CMS | CWE-94 | Remote code execution in Mura Software’s CMS |
| CVE-2026-39042 | 7.5 | 34.3 | n/a | n/a | CWE-190 | An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4… |
| CVE-2026-57743 | 8.1 | 33.7 | stmcan | RT-Theme 18 | Extensions | CWE-98 | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulne… |
| CVE-2026-15542 | 6.9 | 33.7 | will-moss | Isaiah | CWE-287 | will-moss Isaiah Websocket Connection Authentication main.go improper authent… |
| CVE-2026-49876 | 6.5 | 33.6 | Apache Software Foundation | Apache Gravitino | CWE-918 | Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-si… |
| CVE-2026-15557 | 5.5 | 33.1 | waooAI | waoowaoo | CWE-287 | waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight impr… |
| CVE-2026-15545 | 7.4 | 33.0 | Shibby | Tomato | CWE-119 | Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write |
| CVE-2026-15685 | 7.5 | 32.4 | Ollama | Ollama | CWE-129 | Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vuln… |
| CVE-2026-56877 | 6.3 | 32.4 | Skillable | SCORM Lab Launch Integration | CWE-472 | The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026… |
| CVE-2026-57856 | 8.7 | 32.2 | Cockpit HQ | Cockpit CMS | CWE-22 | Cockpit CMS Path Traversal via Bucket Name in Bucket File Storage API |
| CVE-2026-51538 | 9.1 | 32.2 | n/a | n/a | CWE-284 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access … |
| CVE-2026-58228 | 5.1 | 31.5 | phoenixframework | phoenix_live_view | CWE-79 | Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link> |
| CVE-2026-61462 | 9.2 | 31.3 | zereight | mcp-gitlab | CWE-73 | mcp-gitlab Path Traversal via job_id Parameter |
| CVE-2026-57724 | 9.8 | 30.8 | Themeum | Kirki | CWE-502 | WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability |
| CVE-2026-57738 | 9.8 | 30.8 | axiomthemes | 777 | CWE-502 | WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability |
| CVE-2026-57401 | 9.9 | 30.4 | Brainstorm Force | SureDash | CWE-22 | WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability |
| CVE-2026-62327 | 9.3 | 30.3 | decolua | 9Router | CWE-306 | 9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats |
| CVE-2026-62328 | 8.7 | 30.3 | decolua | 9Router | CWE-359 | 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints |
| CVE-2026-57389 | 8.6 | 30.4 | Adrian Tobey | Groundhogg | CWE-22 | WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability |
| CVE-2026-57709 | 8.6 | 30.4 | WP Swings | Membership For WooCommerce | CWE-22 | WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletio… |
| CVE-2026-57788 | 7.5 | 30.3 | Edge-Themes | Aalto | CWE-98 | WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability |
| CVE-2026-57789 | 7.5 | 30.3 | jwsthemes | Aqua | CWE-98 | WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability |
| CVE-2026-57790 | 7.5 | 30.3 | ThemeMove | Billey | CWE-98 | WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability |
| CVE-2026-57791 | 7.5 | 30.3 | ThemeMove | Brook | CWE-98 | WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability |
| CVE-2026-57792 | 7.5 | 30.3 | Mikado-Themes | Dør | CWE-98 | WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability |
| CVE-2026-57793 | 7.5 | 30.3 | Elated-Themes | Flow | CWE-98 | WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability |
| CVE-2026-57794 | 7.5 | 30.3 | uxper | Golo Framework | CWE-98 | WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability |
| CVE-2026-57795 | 7.5 | 30.3 | themelexus | Kitchor | CWE-98 | WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability |
| CVE-2026-57796 | 7.5 | 30.3 | VLThemes | Leedo | CWE-98 | WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability |
| CVE-2026-57798 | 7.5 | 30.3 | SaurabhSharma | NewsPlus Shortcodes | CWE-98 | WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerab… |
| CVE-2026-57799 | 7.5 | 30.3 | uxper | Nuss | CWE-98 | WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability |
| CVE-2026-57800 | 7.5 | 30.3 | Edge-Themes | Overworld | CWE-98 | WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability |
| CVE-2026-57801 | 7.5 | 30.3 | Select-Themes | SetSail | CWE-98 | WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability |
| CVE-2026-57802 | 7.5 | 30.3 | Select-Themes | Struktur | CWE-98 | WordPress Struktur theme < 2.7 - Local File Inclusion vulnerability |
| CVE-2026-57803 | 7.5 | 30.3 | Select-Themes | Struktur Core | CWE-98 | WordPress Struktur Core plugin < 2.7 - Local File Inclusion vulnerability |
| CVE-2026-57804 | 7.5 | 30.3 | CodexThemes | TheGem Theme Elements (for Elementor) | CWE-98 | WordPress TheGem Theme Elements (for Elementor) plugin < 5.12.1.1 - Local Fil… |
| CVE-2026-61463 | 8.7 | 30.1 | go-shiori | shiori | CWE-269 | Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account |
| CVE-2026-59245 | 8.1 | 29.2 | Apache Software Foundation | Apache Airflow FAB provider | CWE-269 | Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the… |
| CVE-2026-58487 | 5.1 | 29.1 | hedgedoc | hedgedoc | CWE-79 | HedgeDoc: Stored HTML injection via email local-part |
| CVE-2026-57433 | 9.8 | 28.9 | HAARG | Storable | CWE-190 | Storable versions before 3.41 for Perl have a signed integer overflow when de… |
| CVE-2026-57719 | 10.0 | 27.9 | CodeRevolution | Aimogen Pro | CWE-434 | WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability |
| CVE-2026-58411 | 7.0 | 27.9 | ChurchCRM | CRM | CWE-79 | ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request pa… |
| CVE-2026-15596 | 2.1 | 27.9 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System subject.php cross site scrip… |
| CVE-2026-55771 | 8.8 | 27.7 | cedar-policy | cedar-java | CWE-94 | CedarJava has policy injection, type confusion, and incorrect equality compar… |
| CVE-2026-57371 | 8.8 | 27.6 | denishua | WPJAM Basic | CWE-502 | WordPress WPJAM Basic plugin <= 7.0 - PHP Object Injection vulnerability |
| CVE-2026-51539 | 7.5 | 27.5 | n/a | n/a | CWE-400 | A Denial of Service (DoS) vulnerability exists in the receive loop of libmodb… |
| CVE-2026-61503 | 6.9 | 27.5 | rejetto | hfs | CWE-204 | Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences |
| CVE-2026-15597 | 5.5 | 25.8 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection |
| CVE-2026-57815 | 7.5 | 25.5 | WPMU DEV - Your All-in-One WordPress Platform | Forminator | CWE-22 | WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability |
| CVE-2026-57710 | 9.9 | 24.8 | quantumcloud | WoowBot Pro Max | CWE-434 | WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability |
| CVE-2026-57697 | 7.5 | 24.8 | Metagauss | ProfileGrid | CWE-288 | WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability |
| CVE-2026-15541 | 6.9 | 24.5 | will-moss | Isaiah | CWE-862 | will-moss Isaiah Master Websocket server.go Server.Handle authorization |
| CVE-2026-22102 | 9.3 | 24.2 | EVbee | DC-80 | CWE-20 | Arbitrary file overwrite through certificate update functionality |
| CVE-2026-62240 | 8.3 | 24.3 | crewAIInc | crewAI | CWE-918 | CrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools |
| CVE-2026-15598 | 5.3 | 24.1 | antv | layout | CWE-94 | antv layout object.js setNestedValue prototype pollution |
| CVE-2026-22096 | 9.3 | 24.0 | EVbee | DC-80 | CWE-306 | Missing authentication for webserver endpoints |
| CVE-2026-57811 | 10.0 | 23.9 | Realtyna | Realtyna Organic IDX plugin | CWE-94 | WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution… |
| CVE-2026-15530 | 5.5 | 23.9 | n/a | WuzhiCMS | CWE-200 | WuzhiCMS Attachment API index.php listimage information disclosure |
| CVE-2026-57713 | 8.8 | 23.5 | Marcus (aka @msykes) | Events Manager | CWE-502 | WordPress Events Manager plugin <= 7.3.6 - PHP Object Injection vulnerability |
| CVE-2026-61501 | 5.3 | 23.6 | rejetto | hfs | CWE-79 | Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer |
| CVE-2026-57744 | 9.8 | 23.1 | stmcan | RT-Theme 18 | Extensions | CWE-502 | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulne… |
| CVE-2026-57770 | 9.8 | 23.1 | ThemeGoods | Grand Photography | CWE-502 | WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability |
| CVE-2026-59518 | 9.8 | 23.1 | wpWax | Directorist | CWE-502 | WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability |
| CVE-2026-61458 | 8.7 | 23.1 | pglombardo | PasswordPusher | CWE-307 | PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint |
| CVE-2026-57830 | 8.8 | 23.0 | joomshaper.com | Helix Ultimate extension for Joomla | CWE-862 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion i… |
| CVE-2026-57805 | 7.5 | 22.7 | Select-Themes | Tonda | CWE-98 | WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability |
| CVE-2026-15594 | 2.9 | 22.4 | waooAI | waoowaoo | CWE-266 | waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authoriza… |
| CVE-2026-62199 | 8.7 | 22.1 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering |
| CVE-2026-62200 | 8.7 | 22.1 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport |
| CVE-2026-58488 | 6.9 | 22.2 | hedgedoc | hedgedoc | CWE-290 | HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing |
| CVE-2026-55773 | 8.8 | 22.0 | cedar-policy | cedar-java | CWE-94 | CedarJava has a policy injection vulnerability |
| CVE-2026-57774 | 5.3 | 21.9 | vowelweb | VW Food Corner | CWE-862 | WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability |
| CVE-2026-57776 | 5.3 | 21.9 | vowelweb | VW Wedding | CWE-862 | WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability |
| CVE-2026-59521 | 7.2 | 21.7 | ShapedPlugin LLC | Real Testimonials | CWE-502 | WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerabi… |
| CVE-2026-40553 | 5.1 | 21.6 | GNU | gawk | CWE-121 | Stack-based buffer overflow in gawk |
| CVE-2026-57727 | 7.5 | 21.2 | Themeum | Kirki | CWE-862 | WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability |
| CVE-2026-62190 | 8.7 | 21.1 | OpenClaw | OpenClaw | CWE-706 | OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper |
| CVE-2026-62185 | 8.6 | 21.0 | argoproj | argo-helm | CWE-1188 | Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE |
| CVE-2026-57702 | 9.3 | 20.9 | Melograno Venture Studio | Amelia | CWE-89 | WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability |
| CVE-2026-57707 | 9.3 | 20.9 | quantumcloud | Simple Business Directory Pro | CWE-89 | WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vuln… |
| CVE-2026-57714 | 9.3 | 20.9 | LatePoint | LatePoint | CWE-89 | WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability |
| CVE-2026-57726 | 9.3 | 20.9 | Themeum | Kirki | CWE-89 | WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability |
| CVE-2026-57739 | 9.3 | 20.9 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-89 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulner… |
| CVE-2026-57855 | 8.7 | 20.9 | Cockpit HQ | Cockpit CMS | CWE-284 | Cockpit CMS Missing Authorization in Bucket File Storage API |
| CVE-2026-62242 | 7.7 | 20.9 | codecentric | spring-boot-admin | CWE-918 | Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration |
| CVE-2026-57386 | 8.8 | 20.3 | Kodezen LLC | aBlocks | CWE-266 | WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability |
| CVE-2026-57410 | 8.8 | 20.3 | MailerPress Team | MailerPress | CWE-266 | WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability |
| CVE-2026-57729 | 7.5 | 20.4 | UX-themes | Flatsome | CWE-862 | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability |
| CVE-2026-15595 | 2.1 | 20.4 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System forsubject.php cross site sc… |
| CVE-2026-58500 | 8.2 | 20.0 | appium | appium-mcp | CWE-79 | MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGener… |
| CVE-2026-11964 | 9.1 | 20.0 | Unknown | User Registration & Membership | — | User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signa… |
| CVE-2026-15516 | 2.9 | 19.9 | n/a | MacCMS Pro | CWE-285 | MacCMS Pro Installation Index.php step5 authorization |
| CVE-2026-55772 | 8.8 | 19.7 | cedar-policy | cedar-java | CWE-843 | CedarJava has a type confusion vulnerability |
| CVE-2026-4765 | 5.1 | 19.7 | RD Station Conversas | Tallos Chat | CWE-79 | Stored Cross-Site Scripting (XSS) in Tallos Chat by RD Station Conversas |
| CVE-2026-57773 | 7.6 | 19.4 | Zorem | Advanced Shipment Tracking for WooCommerce | CWE-89 | WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Inje… |
| CVE-2026-57393 | 6.5 | 19.3 | EDGARROJAS | WooCommerce PDF Invoice Builder | CWE-497 | WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Ex… |
| CVE-2026-15537 | 5.5 | 18.3 | SourceCodester | Online Book Store System | CWE-74 | SourceCodester Online Book Store System login.php sql injection |
| CVE-2026-12582 | 8.6 | 18.2 | Unknown | Library Management System | — | Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id |
| CVE-2026-57813 | 9.8 | 18.0 | properfraction | MailOptin | CWE-266 | WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability |
| CVE-2026-15680 | 7.5 | 17.9 | Lorex | 2K Indoor Wi-Fi Security Camera | CWE-134 | Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Co… |
| CVE-2026-15574 | 7.5 | 17.8 | Red Hat | Red Hat OpenShift AI (RHOAI) | CWE-538 | Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header an… |
| CVE-2026-15529 | 5.3 | 17.6 | yzhao062 | pyod | CWE-20 | yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization |
| CVE-2026-15538 | 5.3 | 17.4 | primefaces | primereact | CWE-94 | primefaces primereact API ObjectUtils.mutateFieldData prototype pollution |
| CVE-2026-15517 | 5.5 | 17.1 | Jinher | OA | CWE-74 | Jinher OA PlanGiveOut.aspx sql injection |
| CVE-2026-15607 | 2.1 | 17.1 | tanstack | db | CWE-94 | tanstack db Alias Path select.ts select prototype pollution |
| CVE-2026-22098 | 9.2 | 17.0 | EVbee | DC-80 | CWE-532 | Sensitive information is written to logs |
| CVE-2026-57385 | 8.5 | 17.0 | appsbd | Vitepos | CWE-89 | WordPress Vitepos plugin <= 3.4.2 - SQL Injection vulnerability |
| CVE-2026-57771 | 8.5 | 17.0 | Milan Petrovic | GD Rating System | CWE-89 | WordPress GD Rating System plugin <= 3.7 - SQL Injection vulnerability |
| CVE-2026-57772 | 8.5 | 17.0 | WP Inventory | WP Inventory Manager | CWE-89 | WordPress WP Inventory Manager plugin <= 2.4.0 - SQL Injection vulnerability |
| CVE-2026-57787 | 8.5 | 17.0 | CreativeWS | CWS SVGicons | CWE-89 | WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability |
| CVE-2026-62194 | 8.7 | 16.8 | OpenClaw | OpenClaw | CWE-732 | OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install |
| CVE-2026-15553 | 6.9 | 16.7 | Ragic | Enterprise Cloud Database | CWE-434 | Ragic|Enterprise Cloud Database - Arbitrary File Upload |
| CVE-2026-14846 | 4.5 | 16.8 | PrestaShop | The firmware | CWE-1236 | Incorrect neutralisation in the PrestaShop firmware |
| CVE-2026-57364 | 6.5 | 16.4 | WPDeveloper | Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More | CWE-1284 | WordPress Better Payment – Instant Payments, Donations, Fundraising with Subs… |
| CVE-2026-57395 | 6.5 | 16.4 | Themefic | Tourfic | CWE-862 | WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability |
| CVE-2026-57418 | 6.5 | 16.4 | BoldGrid | Client Invoicing by Sprout Invoices | CWE-862 | WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Acce… |
| CVE-2026-15518 | 2.0 | 16.4 | AREA 17 | Twill CMS | CWE-284 | AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile un… |
| CVE-2026-15533 | 2.0 | 16.4 | n/a | DedeCMS | CWE-74 | DedeCMS Column Management search.php code injection |
| CVE-2026-15535 | 2.1 | 16.3 | AkariAsai | self-rag | CWE-20 | AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserializa… |
| CVE-2026-62189 | 7.6 | 16.2 | OpenClaw | OpenClaw | CWE-59 | OpenClaw < 2026.6.9 Symlink Following via Mirror Sync |
| CVE-2026-14165 | 7.5 | 16.2 | Dassault Systèmes | Tuleap Enterprise Edition | CWE-639 | Authorization Bypass Through User-Controlled Key vulnerability affecting Tule… |
| CVE-2026-15584 | 7.5 | 16.1 | Red Hat | Pen Drive Powered by Red Hat Lightspeed | CWE-250 | Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot deb… |
| CVE-2026-57698 | 6.5 | 16.0 | VillaTheme | Abandoned Cart Recovery for WooCommerce | CWE-288 | WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken A… |
| CVE-2026-59515 | 9.3 | 15.7 | Sergey | AIWU | CWE-89 | WordPress AIWU plugin <= 1.5.4 - SQL Injection vulnerability |
| CVE-2026-57377 | 6.5 | 15.6 | WPXPO | WowAddons | CWE-862 | WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability |
| CVE-2026-57390 | 6.5 | 15.6 | EDGARROJAS | Extra Product Options Builder for WooCommerce | CWE-862 | WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - B… |
| CVE-2026-57392 | 6.5 | 15.6 | Themefic | Tourfic | CWE-862 | WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability |
| CVE-2026-57404 | 6.5 | 15.6 | magepeopleteam | Booking and Rental Manager | CWE-862 | WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control … |
| CVE-2026-57408 | 6.5 | 15.6 | peachpayments | Peach Payments Gateway | CWE-862 | WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vuln… |
| CVE-2026-57412 | 6.5 | 15.6 | Codemenschen | Gift Vouchers | CWE-862 | WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability |
| CVE-2026-57424 | 6.5 | 15.6 | knitpay | Razorpay Payment Links for WooCommerce | CWE-862 | WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Acc… |
| CVE-2026-12385 | 4.3 | 15.7 | nextendweb | Smart Slider 3 | CWE-200 | Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contribu… |
| CVE-2026-15540 | 2.1 | 15.6 | SourceCodester | Online Book Store System | CWE-73 | SourceCodester Online Book Store System Administrative index.php php file inc… |
| CVE-2026-49969 | 5.3 | 15.5 | plank | laravel-mediable | CWE-918 | Laravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL Handling |
| CVE-2026-6850 | 6.5 | 15.4 | Mattermost | Mattermost | CWE-1333 | Crafted message attachment causes client-side denial of service via markdown … |
| CVE-2026-57797 | 4.3 | 15.4 | ThemeMove | EduMall | CWE-862 | WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability |
| CVE-2026-15618 | 2.1 | 15.3 | mosaxiv | clawlet | CWE-693 | mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection me… |
| CVE-2026-62143 | 8.3 | 15.2 | misp | misp-modules | CWE-918 | Server-Side Request Forgery protection bypass in misp-modules html_to_markdow… |
| CVE-2026-57378 | 7.5 | 15.2 | Phil Kurth | Advanced Forms | CWE-862 | WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability |
| CVE-2026-57705 | 7.5 | 15.2 | Nexcess | Event Tickets | CWE-862 | WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability |
| CVE-2026-15519 | 1.3 | 15.1 | usestrix | strix | CWE-829 | usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted c… |
| CVE-2026-57694 | 6.5 | 15.0 | Themeum | Tutor LMS | CWE-639 | WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDO… |
| CVE-2026-58486 | 8.3 | 14.6 | hedgedoc | hedgedoc | CWE-400 | HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter |
| CVE-2026-57400 | 6.5 | 14.7 | WP Swings | Event Tickets Manager for WooCommerce | CWE-862 | WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Acce… |
| CVE-2026-57406 | 6.5 | 14.7 | Roxnor | FundEngine | CWE-862 | WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability |
| CVE-2026-62192 | 7.2 | 14.4 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass |
| CVE-2026-62195 | 8.7 | 14.1 | OpenClaw | OpenClaw | CWE-732 | OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback |
| CVE-2026-62196 | 8.7 | 14.1 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs |
| CVE-2026-15539 | 2.0 | 13.7 | SourceCodester | Online Book Store System | CWE-284 | SourceCodester Online Book Store System Book Image Upload Feature index.php b… |
| CVE-2026-14934 | 9.4 | 13.6 | Google Cloud | BigQuery | CWE-862 | Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dat… |
| CVE-2026-61955 | 7.6 | 13.6 | Hannan | گرویتی فرم فارسی | CWE-89 | WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability |
| CVE-2026-57405 | 7.1 | 13.5 | themehunk | Open Shop | CWE-862 | WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability |
| CVE-2026-57740 | 7.1 | 13.5 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-862 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Contro… |
| CVE-2026-57768 | 8.2 | 12.9 | favethemes | Houzez Login Register | CWE-266 | WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulner… |
| CVE-2026-58408 | 6.5 | 12.5 | ChurchCRM | CRM | CWE-862 | ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privilege… |
| CVE-2026-58102 | 9.1 | 12.0 | JONASBN | Crypt::OpenSSL::X509 | CWE-125 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bound… |
| CVE-2026-15525 | 2.1 | 12.1 | kLOsk | adloop | CWE-918 | kLOsk adloop write.py _validate_urls server-side request forgery |
| CVE-2026-62187 | 8.6 | 11.9 | openclaw | feishu | CWE-863 | OpenClaw < 2026.6.9 Feishu tools Authorization Bypass |
| CVE-2026-62188 | 8.6 | 11.9 | openclaw | feishu | CWE-863 | OpenClaw < 2026.6.9 Feishu Authorization Bypass |
| CVE-2026-40467 | 5.1 | 12.0 | GNU | gawk | CWE-416 | Use after free in gawk |
| CVE-2026-40469 | 5.1 | 12.0 | GNU | gawk | CWE-190 | Heap buffer overflow in gawk |
| CVE-2026-57419 | 6.5 | 11.8 | Fahad Mahmood | Stock Locations for WooCommerce | CWE-862 | WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Con… |
| CVE-2026-57432 | 8.4 | 11.6 | SHAY | perl | CWE-125 | Perl versions through 5.43.10 have an integer overflow in S_measure_struct le… |
| CVE-2026-9708 | 4.9 | 11.5 | Mattermost | Mattermost | CWE-639 | Incoming webhook user attribution via unvalidated webhook owner |
| CVE-2026-15532 | 1.9 | 11.5 | SourceCodester | Online Book Store System | CWE-79 | SourceCodester Online Book Store System User Management cross site scripting |
| CVE-2026-62147 | 6.5 | 11.3 | Red Hat | Red Hat OpenShift distributed tracing 3 | CWE-863 | Tempo-operator: tempo operator: query rbac bypass |
| CVE-2026-22097 | 9.3 | 11.3 | EVbee | DC-80 | CWE-347 | Missing firmware validation allows remote code execution |
| CVE-2026-57778 | 5.3 | 11.2 | wpdevart | Booking calendar, Appointment Booking System | CWE-862 | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Bro… |
| CVE-2026-57779 | 5.3 | 11.2 | themebeez | Fascinate | CWE-862 | WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability |
| CVE-2026-57781 | 5.3 | 11.2 | Sovlix | MeetingHub | CWE-862 | WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability |
| CVE-2026-57782 | 5.3 | 11.2 | PressTigers | Universal Clocks | CWE-862 | WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability |
| CVE-2026-62191 | 7.1 | 11.1 | OpenClaw | OpenClaw | CWE-862 | OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations |
| CVE-2026-57810 | 8.5 | 10.8 | Saad Iqbal | APIExperts Square for WooCommerce | CWE-89 | WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection v… |
| CVE-2026-15552 | 5.3 | 10.8 | Ragic | Enterprise Cloud Database | CWE-79 | Ragic|Enterprise Cloud Database - Stored Cross-Site Scripting |
| CVE-2026-58101 | 7.5 | 10.8 | JONASBN | Crypt::OpenSSL::X509 | CWE-476 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service v… |
| CVE-2026-49971 | 5.3 | 10.6 | plank | laravel-mediable | CWE-79 | Laravel-Mediable < 7.0.0 Stored XSS via SVG File Upload |
| CVE-2026-11963 | 8.1 | 10.3 | Unknown | User Registration & Membership | — | User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Memb… |
| CVE-2026-40468 | 2.1 | 10.3 | GNU | gawk | CWE-190 | Heap buffer overflow in gawk |
| CVE-2025-45869 | 7.3 | 10.2 | n/a | n/a | CWE-918 | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server… |
| CVE-2026-15523 | 2.1 | 10.2 | CodeAstro | Simple Online Leave Management System | CWE-74 | CodeAstro Simple Online Leave Management System dashboard.php sql injection |
| CVE-2026-15536 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patviewprescription.php sql injection |
| CVE-2026-15558 | 2.1 | 10.2 | CodeAstro | Simple Online Leave Management System | CWE-74 | CodeAstro Simple Online Leave Management System deletemp.php sql injection |
| CVE-2026-15559 | 2.1 | 10.2 | CodeAstro | Simple Online Leave Management System | CWE-74 | CodeAstro Simple Online Leave Management System POST accept.php sql injection |
| CVE-2026-62197 | 6.3 | 10.1 | OpenClaw | OpenClaw | CWE-918 | OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery |
| CVE-2026-61975 | 5.3 | 9.9 | Crocoblock | JetReviews | CWE-497 | WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-61976 | 5.3 | 9.9 | Crocoblock | JetBlocks For Elementor | CWE-497 | WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure v… |
| CVE-2026-61977 | 5.3 | 9.9 | Crocoblock | JetSearch | CWE-497 | WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-57375 | 6.5 | 9.5 | FluxBuilder | MStore API | CWE-862 | WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability |
| CVE-2026-61952 | 4.9 | 9.3 | Jose Vega | WooCommerce Bulk Edit Products – WP Sheet Editor | CWE-862 | WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 -… |
| CVE-2026-62186 | 7.2 | 9.2 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override |
| CVE-2026-61971 | 2.7 | 9.2 | Cozmoslabs | User Profile Picture | CWE-639 | WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object Refer… |
| CVE-2026-57812 | 6.5 | 9.1 | NSquared | Simply Schedule Appointments | CWE-862 | WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Con… |
| CVE-2026-22099 | 8.7 | 8.8 | EVbee | DC-80 | CWE-287 | Missing authentication for Bluetooth communication |
| CVE-2026-57372 | 7.2 | 8.8 | denishua | WPJAM Basic | CWE-918 | WordPress WPJAM Basic plugin <= 7.0 - Server Side Request Forgery (SSRF) vuln… |
| CVE-2026-57407 | 7.2 | 8.8 | WP Swings | PDF Generator for WordPress | CWE-918 | WordPress PDF Generator for WordPress plugin <= 1.6.2 - Server Side Request F… |
| CVE-2026-62193 | 6.9 | 8.3 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install |
| CVE-2026-12274 | 6.5 | 8.4 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR |
| CVE-2026-57829 | 8.7 | 8.2 | joomshaper.com | Helix Ultimate extension for Joomla | CWE-79 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultim… |
| CVE-2026-61502 | 5.1 | 8.1 | rejetto | hfs | CWE-352 | Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests |
| CVE-2026-57368 | 7.1 | 7.9 | NooTheme | Jobmonster | CWE-79 | WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vu… |
| CVE-2026-57421 | 7.1 | 7.9 | CRM Perks | CRM Perks Forms | CWE-79 | WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-57733 | 7.1 | 7.9 | tagDiv | tagDiv Cloud Library | CWE-79 | WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) v… |
| CVE-2026-57695 | 7.1 | 7.7 | Dan Rossiter | Document Gallery | CWE-79 | WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-14906 | 5.3 | 7.5 | Mozilla | Firefox for iOS | CWE-434 | Malicious webpage titles could allow overwriting of bundled PDF resources whe… |
| CVE-2026-61983 | 5.3 | 7.4 | andy_moyle | Church Admin | CWE-862 | WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability |
| CVE-2026-61985 | 5.3 | 7.4 | magepeopleteam | Car Rental Manager | CWE-862 | WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerab… |
| CVE-2026-57363 | 7.1 | 7.3 | QuantumCloud | ChatBot | CWE-79 | WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57369 | 7.1 | 7.3 | themifyme | Themify Builder | CWE-79 | WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-57376 | 7.1 | 7.3 | Element Invader | ElementInvader Addons for Elementor | CWE-79 | WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Sc… |
| CVE-2026-57379 | 7.1 | 7.3 | WPPOOL | FormyChat | CWE-79 | WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57380 | 7.1 | 7.3 | hupe13 | Extensions for Leaflet Map | CWE-79 | WordPress Extensions for Leaflet Map plugin <= 5.1 - Cross Site Scripting (XS… |
| CVE-2026-57381 | 7.1 | 7.3 | Property Hive | PropertyHive | CWE-79 | WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57382 | 7.1 | 7.3 | Mitchell Bennis | Simple File List | CWE-79 | WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (… |
| CVE-2026-57383 | 7.1 | 7.3 | eyecix | JobSearch | CWE-79 | WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57387 | 7.1 | 7.3 | picu | picu | CWE-79 | WordPress picu plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57388 | 7.1 | 7.3 | Themefic | Hydra Booking | CWE-79 | WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57394 | 7.1 | 7.3 | Tribulant Software | Newsletters | CWE-79 | WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57396 | 7.1 | 7.3 | Flintop | Free Gifts for WooCommerce | CWE-79 | WordPress Free Gifts for WooCommerce plugin <= 13.1.0 - Cross Site Scripting … |
| CVE-2026-57398 | 7.1 | 7.3 | WebCodingPlace | Real Estate Manager Pro | CWE-79 | WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XS… |
| CVE-2026-57399 | 7.1 | 7.3 | Proxy & VPN Blocker | Proxy & VPN Blocker | CWE-79 | WordPress Proxy & VPN Blocker plugin <= 3.5.8 - Cross Site Scripting (XSS) vu… |
| CVE-2026-57403 | 7.1 | 7.3 | Milan Petrovic | GD Security Headers | CWE-79 | WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-57409 | 7.1 | 7.3 | RealMag777 | Active Products Tables for WooCommerce | CWE-79 | WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site… |
| CVE-2026-57411 | 7.1 | 7.3 | Aman | CF7 Views – Complete Entry Management for Contact Form 7 | CWE-79 | WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= … |
| CVE-2026-57415 | 7.1 | 7.3 | Codemenschen | Gift Vouchers | CWE-79 | WordPress Gift Vouchers plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57416 | 7.1 | 7.3 | SiteGround | SiteGround Email Marketing | CWE-79 | WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (… |
| CVE-2026-57417 | 7.1 | 7.3 | RexTheme | Cart Lift | CWE-79 | WordPress Cart Lift plugin <= 3.1.57 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57422 | 7.1 | 7.3 | VillaTheme | Bopo – WooCommerce Product Bundle Builder | CWE-79 | WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflect… |
| CVE-2026-57423 | 7.1 | 7.3 | Kofi Mokome | Message Filter for Contact Form 7 | CWE-79 | WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.8 - Reflected Cro… |
| CVE-2026-57668 | 7.1 | 7.3 | Basix | NEX-Forms | CWE-79 | WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57706 | 7.1 | 7.3 | Dokan, Inc. | Dokan | CWE-79 | WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57708 | 7.1 | 7.3 | CRM Perks | Contact Form Entries | CWE-79 | WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) v… |
| CVE-2026-57712 | 7.1 | 7.3 | WPZOOM | WPZOOM Portfolio | CWE-79 | WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-57715 | 7.1 | 7.3 | WPManageNinja | Fluent CRM | CWE-79 | WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57718 | 7.1 | 7.3 | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-79 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-57725 | 7.1 | 7.3 | Themeum | Kirki | CWE-79 | WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57728 | 7.1 | 7.3 | UX-themes | Flatsome | CWE-79 | WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vul… |
| CVE-2026-57732 | 7.1 | 7.3 | tagDiv | tagDiv Opt-In Builder | CWE-79 | WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) … |
| CVE-2026-57734 | 7.1 | 7.3 | tagDiv | tagDiv Composer | CWE-79 | WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (X… |
| CVE-2026-57741 | 7.1 | 7.3 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-79 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting… |
| CVE-2026-57745 | 7.1 | 7.3 | stmcan | RT-Theme 18 | Extensions | CWE-79 | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scrip… |
| CVE-2026-10106 | 6.5 | 7.2 | Mattermost | Mattermost | CWE-863 | Unauthorized users can trigger interactive post actions in private channels v… |
| CVE-2026-58410 | 7.1 | 7.2 | ChurchCRM | CRM | CWE-639 | ChurchCRM: Improper object-level authorization allows low-privileged users to… |
| CVE-2026-9571 | 6.5 | 7.2 | Mattermost | Mattermost | CWE-305 | Deactivated user accounts can continue to obtain valid OAuth access tokens vi… |
| CVE-2026-61504 | 5.1 | 7.0 | rejetto | hfs | CWE-79 | Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing |
| CVE-2026-12275 | 7.1 | 6.9 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private C… |
| CVE-2026-10085 | 5.4 | 6.7 | Mattermost | Mattermost | CWE-862 | Ordinary group/direct message member can enable group_constrained and remove … |
| CVE-2026-12271 | 5.4 | 6.7 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR |
| CVE-2026-12396 | 5.4 | 6.7 | Unknown | WP Job Portal | — | WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rej… |
| CVE-2026-61958 | 5.4 | 6.7 | Saad Iqbal | License Manager for WooCommerce | CWE-862 | WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Conten… |
| CVE-2026-61968 | 5.4 | 6.7 | Saad Iqbal | myCred | CWE-862 | WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability |
| CVE-2026-12273 | 4.3 | 6.8 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation |
| CVE-2026-12536 | 6.4 | 6.6 | themefusion | Avada (Fusion) Builder | CWE-79 | Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-57786 | 8.8 | 6.1 | purethemes | WorkScout-Core | CWE-352 | WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF)… |
| CVE-2026-57391 | 6.5 | 6.1 | Tangible | Loops & Logic | CWE-79 | WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57413 | 6.4 | 6.0 | bdthemes | Instant Image Generator | CWE-918 | WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forge… |
| CVE-2026-9824 | 4.3 | 5.9 | Mattermost | Mattermost | CWE-862 | Remote cluster metadata enumeration via /share-channel autocomplete |
| CVE-2026-12397 | 4.3 | 5.9 | Unknown | WP Job Portal | — | WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR |
| CVE-2026-22093 | 9.5 | 5.7 | EVbee | EVbee Service | CWE-295 | Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app |
| CVE-2026-62198 | 5.3 | 5.7 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search |
| CVE-2026-48363 | 8.2 | 5.5 | Adobe | ColdFusion | CWE-427 | ColdFusion | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-48364 | 8.2 | 5.5 | Adobe | ColdFusion | CWE-427 | ColdFusion | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-57365 | 6.5 | 5.3 | Hitesh Chandwani | reCAPTCHA (v2 & v3) for Asgaros Forum | CWE-79 | WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site … |
| CVE-2026-57402 | 6.5 | 5.3 | wpdesk | Flexible Refund and Return Order for WooCommerce | CWE-79 | WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 -… |
| CVE-2026-57414 | 6.5 | 5.3 | QuantumCloud | ChatBot for eCommerce – WoowBot | CWE-79 | WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Script… |
| CVE-2026-57420 | 6.5 | 5.3 | Netrr | Author Box WP Lens | CWE-79 | WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vul… |
| CVE-2026-57693 | 6.5 | 5.3 | Spacetime | Ad Inserter | CWE-79 | WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57711 | 6.5 | 5.3 | PSM Plugins | SupportCandy | CWE-79 | WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57780 | 6.5 | 5.3 | Plugin Envision | Envision Page Builder | CWE-79 | WordPress Envision Page Builder plugin <= 0.22 - Cross Site Scripting (XSS) v… |
| CVE-2026-57783 | 6.5 | 5.3 | merkulove | Speaker | CWE-79 | WordPress Speaker plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-59523 | 6.5 | 5.2 | NSquared | Simply Schedule Appointments | CWE-862 | WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Co… |
| CVE-2026-6541 | 4.3 | 4.9 | Mattermost | Mattermost | CWE-639 | Unscoped updates to other playbooks' metric configuration |
| CVE-2026-9820 | 3.8 | 4.9 | Mattermost | Mattermost | CWE-862 | Mattermost schemes teams endpoint exposes private team invite IDs |
| CVE-2026-15605 | 2.3 | 4.8 | n/a | wandb | CWE-327 | wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.downloa… |
| CVE-2026-10551 | 6.1 | 4.6 | Unknown | Breeze Cache | — | Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library |
| CVE-2026-57691 | 5.8 | 4.6 | Eli | Anti-Malware Security and Brute-Force Firewall | CWE-79 | WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.89 - … |
| CVE-2026-10103 | 4.3 | 4.2 | Mattermost | Mattermost | CWE-639 | Authenticated remote cluster can modify or delete posts it does not own in Ma… |
| CVE-2026-15684 | 7.3 | 4.0 | Glarysoft | Glary Utilities | CWE-59 | Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerabi… |
| CVE-2026-57814 | 7.1 | 4.0 | WPMU DEV - Your All-in-One WordPress Platform | Forminator | CWE-79 | WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57816 | 7.1 | 4.0 | FunnelKit | Funnel Builder by FunnelKit | CWE-79 | WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripti… |
| CVE-2026-59516 | 7.1 | 4.0 | Room 34 Creative Services, LLC | ICS Calendar | CWE-79 | WordPress ICS Calendar plugin <= 12.1.1 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-9597 | 5.4 | 3.9 | Mattermost | Mattermost | CWE-305 | Deactivated guest accounts can authenticate via magic-link token in Mattermos… |
| CVE-2026-15527 | 1.9 | 3.8 | better-auth | better-icons | CWE-22 | better-auth better-icons scan_project_icons/sync_icon path traversal |
| CVE-2026-12081 | 5.0 | 3.8 | Unknown | Database for Contact Form 7, WPforms, Elementor forms | — | Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticat… |
| CVE-2026-15521 | 1.9 | 3.6 | makafeli | n8n-workflow-builder | CWE-22 | makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal |
| CVE-2026-15522 | 1.9 | 3.6 | tugcantopaloglu | godot-mcp | CWE-22 | tugcantopaloglu godot-mcp run_project index.js validatePath path traversal |
| CVE-2026-15524 | 1.9 | 3.6 | alioshr | memory-bank-mcp | CWE-22 | alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal |
| CVE-2026-15526 | 1.9 | 3.6 | augmnt | augments-mcp-server | CWE-22 | augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProject… |
| CVE-2026-15520 | 1.9 | 3.5 | GNU | LibreDWG | CWE-119 | GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section he… |
| CVE-2026-15682 | 5.5 | 3.2 | AnyDesk | AnyDesk | CWE-59 | AnyDesk Support Information Link Following Denial-of-Service Vulnerability |
| CVE-2026-62239 | 5.3 | 2.9 | Dao-AILab | flash-attention | CWE-59 | FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py |
| CVE-2026-53365 | 5.5 | 2.8 | Linux | Linux | CWE-401 | vsock/virtio: fix zerocopy completion for multi-skb sends |
| CVE-2026-58489 | 6.8 | 2.7 | hedgedoc | hedgedoc | CWE-352 | HedgeDoc: CSRF in GitHub Gist export callback |
| CVE-2026-15531 | 1.9 | 2.3 | yashbhalgat | HashNeRF-pytorch | CWE-20 | yashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deseriali… |
| CVE-2026-61970 | 4.9 | 2.1 | Themeisle | Auto Featured Image (Auto Post Thumbnail) | CWE-918 | WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server … |
| CVE-2026-7162 | 7.8 | 2.0 | WinFsp | WinFsp | CWE-190 | Successful exploitation of the integer overflow vulnerability could allow an … |
| CVE-2026-60103 | 6.8 | 1.9 | blender | blender | CWE-125 | Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block |
| CVE-2026-15515 | 6.4 | 1.9 | Tencent | PC Manager | CWE-426 | Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path |
| CVE-2026-53364 | 5.5 | 1.7 | Linux | Linux | CWE-401 | Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() |
| CVE-2026-15528 | 1.9 | 1.6 | lamaalrajih | kicad-mcp | CWE-693 | lamaalrajih kicad-mcp path_validator.py protection mechanism |
| CVE-2026-9492 | 8.5 | 1.4 | GIGABYTE | MBStorage | CWE-782 | GIGABYTE|Gigabyte Control Center - Improper Access Control |
| CVE-2026-61956 | 7.1 | 1.3 | hamsalam | ووسلام – همگام سازی ووکامرس و باسلام | CWE-352 | WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site R… |
| CVE-2026-15681 | 5.5 | 1.2 | AnyDesk | AnyDesk | CWE-59 | AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability |
| CVE-2026-15683 | 7.5 | 0.8 | Lorex | 2K Indoor Wi-Fi Security Camera | CWE-295 | Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certi… |
| CVE-2026-15551 | 5.5 | 0.2 | Samsung Open Source | rlottie | CWE-190 | Samsung rlottie: Numeric truncation in gray_hline() leads to heap-based buffe… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-13 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.