boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, July 15, 2026 · all times UTC← 2026-07-14 · archive · 2026-07-16 →

Security Box Score — July 15, 2026

268 CVEs published, led by ImageMagick (14).

268 CVEs published July 15, 2026: 36 critical, 123 high, 92 medium, 17 low; 1 in the KEV catalog at press time; 14 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 243 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published407216475——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

716 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux40152012186653211120.17.5.0014-55 ▼
microsoft62413819296331214286221.67.8.0047+417 ▲
google941359150616555387760.47.8.0024-497 ▼
red hat502721410913217200.06.5.0032-3 ▼
apple01042287228876.76.5.0032-14 ▼
suse82141241000.08.5.0039+8 ▲
canonical1212685000.05.5.0011+1 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1537818110561129.77.5.0057+11 ▲
ubiquiti2536142110338.38.8.0049+20 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear62300221000.04.6.0024-11 ▼
fortinet12215610028314.37.2.0039+10 ▲
f58165830416.38.6.0057+8 ▲
ivanti211452025545.58.8.3445-2 ▼
checkpoint0915303111.17.5.0410-3 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache76231478983113310.47.5.0058+9 ▲
mozilla6621218320900.06.5.0026+1 ▲
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-4 ▼
github171150000.06.0.0039+1 ▲
docker070520000.08.2.0016-2 ▼
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle12711331161842731.18.8.0040-1 ▼
adobe932372610210541931.37.5.0026-31 ▼
ibm21263842460600.07.5.0034-9 ▼
progress101931420600.07.5.0037+5 ▲
solarwinds07232010457.17.5.4001-3 ▼
veeam042200100.09.0.0052-1 ▼
zohocorp031110000.08.4.01700
servicenow111000200.09.5.7758+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+17 ▲
synology02325133000.05.6.0025-5 ▼
siemens7161870000.07.6.00240
d-link1130535300.06.0.0059-8 ▼
abb060420000.07.2.0018-5 ▼
schneider electric060420000.07.8.0042-1 ▼
moxa050320000.07.0.0029-1 ▼
dahua030111000.06.9.0036-3 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester37108005652000.05.5.0032+1 ▲
dell3793542433211.17.0.0021+30 ▲
capgo2283242381000.07.1.0037+20 ▲
openclaw16830482510000.07.2.0024-18 ▼
nvidia40791252150000.07.8.0037+36 ▲
imagemagick3273155512000.05.3.0019+4 ▲
spring073231391000.06.5.0024-71 ▼
itsourcecode1265001946000.02.1.0033-10 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-20253.969499.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-48907.781099.510.0
CVE-2026-6875.775899.59.5
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-1540910.0.8366KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
Most disclosures (vendor)
VendorCVEs
microsoft638
google593
linux458
oracle241
apache130
red hat125
adobe111
capgo81
dell68
ibm66
Most KEV additions (YTD)
VendorKEV
microsoft22
cisco11
apple7
google6
ivanti5
solarwinds4
adobe3
berriai3
fortinet3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven62
PyPI5
npm5
NuGet3
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-45659Microsoft0
CVE-2026-46817Oracle Corporation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171701
CVE-2021-27102n/a2021-11-171701
CVE-2021-27101n/a2021-11-171701
CVE-2021-27103n/a2021-11-171701
CVE-2021-21017Adobe2021-11-171701
CVE-2021-28550Adobe2021-11-171701
CVE-2021-42013Apache Software Foundation2021-11-171701
CVE-2021-41773Apache Software Foundation2021-11-171701
CVE-2021-30858Apple2021-11-171701
CVE-2021-30860Apple2021-11-171701

Transactions

EXPLOIT PUBLISHED — CVE-2026-10673 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41580 (Stirling-Tools Stirling-PDF). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45737 (argoproj argo-cd). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45738 (argoproj argo-cd). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45804 (huggingface diffusers). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46709 (Eugeny tabby). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47703 (AdguardTeam AdGuardHome). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49987 (yamadashy repomix). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49988 (yamadashy repomix). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56398 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56400 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62947 (openwrt). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62948 (openwrt). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

268 CVEs published. 25 box scores, 243 table rows — nothing truncated.

Oracle E-Business Suite
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1302   96.0   YES
AFFECTED
  Product          Versions  Fixed
  Oracle Payments  12.2.3 –  —
TIMELINE
  May 18  Reserved by CNA
  Jul 15  Added to CISA KEV, due Jul 18
  Jul 15  Published (CNA: oracle)
CWE-269, CWE-287, CWE-306 · CNA: oracle · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due July 18, 2026
n/a n/a — LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. Th…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0500   91.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jul 15  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
F5 NGINX Plus — NGINX Map directive and Regex matching vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.2   .0406   89.9     —
AFFECTED
  Product            Versions    Fixed
  NGINX Plus         37.0.0.1 –  —
  NGINX Open Source  1.31.2 –    —
TIMELINE
  May 5   Reserved by CNA
  Jul 15  Published (CNA: f5)
CWE-122 · CNA: f5 · CVSS v4.0 · 1 reference · NVD status: Analyzed
decolua 9router — 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0335   87.8     —
AFFECTED
  Product  Versions               Fixed
  9router  >= 0.4.30, < 0.4.37 –  —
TIMELINE
  May 13  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-78, CWE-306 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Deferred
Apache Fineract: SQL injection in runreports endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0328   87.5     —
AFFECTED
  Product          Versions     Fixed
  Apache Fineract  unspecified  —
TIMELINE
  Apr 1   Reserved by CNA
  Jul 15  Published (CNA: apache)
CWE-89 · CNA: apache · CVSS v3.1 · 4 references · NVD status: Analyzed
decolua 9router — 9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0130   68.2     —
AFFECTED
  Product  Versions   Fixed
  9router  < 0.5.2 –  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
n/a n/a — xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and comm…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0120   65.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jul 15  Published (CNA: mitre)
CWE-94 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Deferred
getgrav grav — Grav Flex Objects - Server-Side Template Injection via Dynamic Titles
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0112   63.6     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  1.4.0
TIMELINE
  Jul 1   Reserved by CNA
  Jul 15  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
AWS jsii — OS command injection in jsii-diff in AWS jsii
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   A   H   H   H    8.4   .0103   61.1     —
AFFECTED
  Product  Versions     Fixed
  jsii     unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 15  Published (CNA: AMZN)
CWE-78 · CNA: AMZN · CVSS v4.0 · 2 references · NVD status: Awaiting Analysis
Composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0102   60.8     —
AFFECTED
  Product   Versions             Fixed
  composer  >= 1.0, < 1.10.28 –  —
TIMELINE
  May 13  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-200 · CNA: GitHub_M · CVSS v3.1 · 9 references · NVD status: Awaiting Analysis
Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0093   57.8     —
AFFECTED
  Product        Versions     Fixed
  Gravity Forms  unspecified  —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 15  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0089   56.7     —
AFFECTED
  Product   Versions    Fixed
  nocobase  < 2.0.61 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
n/a n/a — An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim sy…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0089   56.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Nov 18  Reserved by CNA
  Jul 15  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
getgrav grav — Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   N    5.3   .0083   54.9     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  1.0.3
TIMELINE
  Jul 9   Reserved by CNA
  Jul 15  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
CherryHQ cherry-studio — Cherry Studio RCE via SearchService nodeIntegration Misconfiguration
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    8.6   .0080   54.0     —
AFFECTED
  Product        Versions  Fixed
  cherry-studio  1.2.2 –   —
TIMELINE
  Apr 13  Reserved by CNA
  Jul 15  Published (CNA: VulnCheck)
CWE-829 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
Wekan: Shell Injection via Avatar Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0078   53.3     —
AFFECTED
  Product  Versions  Fixed
  wekan    < 9.07 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-78, CWE-88 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI before 1.6.78 Remote Code Execution via SkillTools
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   N    8.6   .0077   52.8     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  1.6.78
TIMELINE
  Jul 9   Reserved by CNA
  Jul 15  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Apache Fineract: Office list: SQL Injection via Subquery in orderBy
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  H    8.1   .0074   51.9     —
AFFECTED
  Product          Versions     Fixed
  Apache Fineract  unspecified  1.15.0
TIMELINE
  Jun 25  Reserved by CNA
  Jul 15  Published (CNA: apache)
CWE-89 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Analyzed
NocoBase backup restore schema name allows command injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  L  H  H    6.7   .0072   51.2     —
AFFECTED
  Product   Versions    Fixed
  nocobase  < 2.1.19 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
F5 NGINX Plus — NGINX ngx_http_slice_module vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   H    8.8   .0071   50.8     —
AFFECTED
  Product            Versions    Fixed
  NGINX Plus         37.0.0.1 –  —
  NGINX Open Source  1.31.2 –    —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 15  Published (CNA: f5)
CWE-908 · CNA: f5 · CVSS v4.0 · 1 reference · NVD status: Analyzed
n/a n/a — Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanen…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jul 15  Published (CNA: mitre)
CWE-120 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   H   N    8.8   .0069   49.8     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  4.6.78
TIMELINE
  Jul 9   Reserved by CNA
  Jul 15  Published (CNA: VulnCheck)
CWE-287 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Cursor: Cloud Agent Browser Sandbox Escape
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   H    7.7   .0068   49.5     —
AFFECTED
  Product  Versions        Fixed
  cursor   < 03/31/2026 –  —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-306 · CNA: GitHub_M · CVSS v4.0 · 1 reference · NVD status: Deferred
dani-garcia vaultwarden — Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token Exposure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   N    6.9   .0066   49.0     —
AFFECTED
  Product      Versions    Fixed
  vaultwarden  < 1.36.0 –  —
TIMELINE
  May 18  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-287 · CNA: GitHub_M · CVSS v4.0 · 4 references · NVD status: Deferred
whyour qinglong — Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0066   49.0     —
AFFECTED
  Product   Versions    Fixed
  qinglong  < 2.20.1 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-287 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-617409.348.9HKUDSLightRAGCWE-287LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /a…
CVE-2026-436378.848.9PreferredAIcornacCWE-22Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
CVE-2026-592358.748.7RoskusProspero Flow CRMCWE-639Missing authorization in Prospero Flow CRM allows low-privileged users to rea…
CVE-2026-562878.148.6Apache Software FoundationApache FineractCWE-89Apache Fineract: Boolean SQL Injection in Client Search API (orderBy paramete…
CVE-2026-592366.947.9RoskusProspero Flow CRMCWE-639Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant re…
CVE-2026-455349.047.8dataeasedataeaseCWE-94DataEase: RCE Vulnerability
CVE-2026-563988.547.7open-webuiopen-webuiCWE-20Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI
CVE-2026-556529.847.0wekanwekanCWE-287Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan…
CVE-2026-457388.746.3argoprojargo-cdCWE-79Argo CD: Stored XSS in application link annotations enables developer-to-admi…
CVE-2026-493529.846.1decolua9routerCWE-7989Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
CVE-2026-365907.545.5n/an/aCWE-400An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of…
CVE-2026-629489.645.1openwrtopenwrtCWE-79OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file line…
CVE-2026-599547.544.8apolloconfigapolloCWE-20Apollo ConfigService access key authentication bypass via appId parsing and n…
CVE-2026-599557.544.8apolloconfigapolloCWE-20Apollo ConfigService access key authentication bypass via raw config file app…
CVE-2026-597628.744.8F5BIG-IPCWE-770BIG-IP HTTP/2 vulnerability
CVE-2026-202977.244.6SplunkSplunk EnterpriseCWE-22Path Traversal through 'explicit_appname' in the App Install REST Endpoint in…
CVE-2026-623498.344.5taosdataTDengineCWE-121TDengine: Off-by-One Buffer Overflow
CVE-2026-501247.144.1dataeasedataeaseCWE-434DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper
CVE-2026-626858.143.7filebrowserfilebrowserCWE-647File Browser: Colliding username normalization gives two users the same home …
CVE-2026-487958.643.4adonisjscoreCWE-1321Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser
CVE-2026-158048.743.2MetaGuruHCMCWE-89MetaGuru|HCM - SQL Injection
CVE-2026-492797.743.0WWBNAVideoCWE-79WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSoc…
CVE-2026-623507.243.0taosdataTDengineCWE-94TDengine: UDF lead to RCE
CVE-2026-499877.542.9yamadashyrepomixCWE-88Repomix: Command Injection (RCE) via `--remote-branch` Argument Injection
CVE-2026-586588.842.8gpustackgpustackCWE-306GPUStack Unauthenticated Information Disclosure via Worker Endpoints
CVE-2026-528697.142.7modelcontextprotocolpython-sdkCWE-639MCP Python SDK: HTTP transports serve session requests without verifying the …
CVE-2026-617369.342.5HKUDSLightRAGCWE-942LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2026-613717.542.4n/an/aCWE-59Microsoft AVML before 0.17.0 could follow a symlink when opening a destinatio…
CVE-2026-155838.642.3GrafanaGrafana MCP ServerCWE-610SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
CVE-2026-464219.342.0cap-js@cap-js/sqliteCWE-506Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-…
CVE-2026-629474.942.0openwrtopenwrtCWE-22OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
CVE-2026-449869.942.0penpotpenpotCWE-287Penpot: Pre-authenticated account takeover via team-invitation token + prepar…
CVE-2026-457376.541.9argoprojargo-cdCWE-200Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive…
CVE-2026-564009.041.8open-webuiopen-webuiCWE-613open-webui - Remote Code Execution via CORS Misconfiguration and Session Vali…
CVE-2026-566798.741.7decolua9routerCWE-9159Router: Mass assignment in PATCH /api/settings allows authenticated authoriz…
CVE-2026-614368.841.7MervinPraisonPraisonAICWE-287PraisonAI before 4.6.78 Missing Webhook Signature Verification
CVE-2026-616848.841.3labringFastGPTCWE-798FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke…
CVE-2026-557238.741.1F5NGINX Ingress ControllerCWE-76NGINX Ingress Controller vulnerability
CVE-2026-544589.641.0WWBNAVideoCWE-79AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metada…
CVE-2026-260325.441.0Apache Software FoundationApache IvyCWE-22Apache Ivy: PackagerResolver path traversal vulnerability
CVE-2026-586607.240.8kanboardkanboardCWE-639Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop
CVE-2026-528657.140.6F5NGINX Ingress ControllerCWE-476NGINX Ingress Controller vulnerability
CVE-2026-118515.940.6ASUSRouterCWE-89Improper Neutralization of Special Elements used in an SQL Command ("SQL Inje…
CVE-2026-201465.540.5CiscoCisco Identity Services Engine SoftwareCWE-22Cisco Identity Services Engine Path Traversal Vulnerability
CVE-2026-534466.240.4wekanwekanCWE-918Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs
CVE-2026-623789.039.9rustfsconsoleCWE-79RustFS Console: Critical Stored XSS in Preview Modal leading to Administrativ…
CVE-2026-528939.239.2wekanwekanCWE-287Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in o…
CVE-2026-528907.139.0wekanwekanCWE-22Wekan: Arbitrary file read and server DoS via attachment versions.original.path
CVE-2026-618368.638.9directusdirectusCWE-524Directus: Authorization-dependent response served from unsegmented cache key
CVE-2026-631757.138.7LookylooPlaywrightCaptureCWE-613Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo -…
CVE-2026-563496.338.7n8nn8nCWE-20n8n - Guardrail Node Bypass via Crafted Input
CVE-2026-528886.838.5nocobasenocobaseCWE-184NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
CVE-2026-453208.738.4dataeasedataeaseCWE-89DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection
CVE-2026-201537.538.4CiscoCisco RoomOS SoftwareCWE-20Cisco RoomOS Security Hardening Release - Input Validation Vulnerabilities
CVE-2026-201587.538.4CiscoCisco RoomOS SoftwareCWE-664Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulner…
CVE-2026-201877.538.4CiscoCisco RoomOS SoftwareCWE-703Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vul…
CVE-2026-500307.138.4dataeasedataeaseCWE-89DataEase: Arbitrary SQL execution in preview path (direct data disclosure)
CVE-2026-498676.338.4dataeasedataeaseCWE-79DataEase: Authenticated Stored XSS in DataEase Template Static Resources
CVE-2026-123828.238.1Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-290Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject he…
CVE-2026-623145.838.1TecharoHQanubisCWE-284Anubis: Policy bypass via client controlled X-Original-URI header
CVE-2026-545607.638.1cloudrevecloudreveCWE-863Cloudreve: OAuth access tokens bypass scope enforcement due to missing client…
CVE-2026-528926.538.1wekanwekanCWE-862Wekan: Read-only board members can create/modify/delete Custom Fields (privil…
CVE-2026-555768.838.0MaaAssistantArknightsMaaAssistantArknightsCWE-78MaaAssistantArknights: PR-title expression injection in release-preparation.yml
CVE-2026-623517.537.9taosdataTDengineCWE-125TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in …
CVE-2026-618737.237.9getgravgravCWE-73Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename
CVE-2026-149609.837.8Pegatron Corp.Tdelo64.sysCWE-269CVE-2026-14960
CVE-2026-563398.737.8Cap-gocapgoCWE-203Capgo - Unauthenticated Organization Existence Enumeration via rescind_invita…
CVE-2026-454198.537.8dataeasedataeaseCWE-22DataEase: Arbitrary File Write Vulnerability
CVE-2026-455338.337.8dataeasedataeaseCWE-22DataEase: Path Traversal Vulnerability
CVE-2026-592587.237.6immich-appimmichCWE-863immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser
CVE-2026-564348.337.2F5NGINX PlusCWE-416NGINX ngx_http_ssi_module vulnerability
CVE-2026-471647.737.1dani-garciavaultwardenCWE-284Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Att…
CVE-2026-89197.237.0ASUSGameSDKCWE-942Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSD…
CVE-2026-125128.636.9UnknownQuotes llamaCWE-89Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter
CVE-2026-579968.736.6phpMyFAQphpMyFAQCWE-269phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endp…
CVE-2026-614497.136.4getgravgravCWE-409Grav before 2.0.2 Decompression Bomb via Forged ZIP Size
CVE-2026-592557.136.4SpecterOpsBloodHoundCWE-862BloodHound Missing Authorization on Custom Node Management API
CVE-2026-592596.036.3n8nn8nCWE-639n8n - Permission Bypass via Expression Parser Mismatch in External Secrets
CVE-2026-580778.736.2weeblr.com4Analytics extension for JoomlaCWE-79Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
CVE-2026-578338.636.2weeblr.com4Analytics extension for JoomlaCWE-79Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
CVE-2026-90075.536.2HCL SoftwareHCL NotesCWE-79Reflected XSS in HCL Notes
CVE-2026-464595.335.9ICU ScandinaviaBoomerangCWE-862Missing Authorization in ICU Scandinavia Boomerang
CVE-2026-451506.335.4zen-browserdesktopCWE-451Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing
CVE-2026-409576.135.5Absolute SecuritySecure AccessCWE-1021Frameable content vulnerability in the Secure Access server login page
CVE-2026-501489.135.4metabasemetabaseCWE-73Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
CVE-2026-535157.135.3better-authbetter-authCWE-269Better Auth: Privilege escalation via SSO provider registration: missing admi…
CVE-2026-552348.535.2wekanwekanCWE-284Wekan: Broken access control: any authenticated user can move their Cards/Lis…
CVE-2026-201508.835.1CiscoCisco RoomOS SoftwareCWE-284Cisco RoomOS Security Hardening Release - Access Control Vulnerabilities
CVE-2026-157466.935.0Amazonstrands-agents-toolsCWE-918Credential disclosure in Strands Agents Tools elasticsearch_memory tool
CVE-2026-614519.435.0getgravgravCWE-601Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url
CVE-2026-535178.134.9better-authbetter-authCWE-362Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Conc…
CVE-2026-464858.234.7lissy93dashyCWE-15Dash: Users can write to config despire permissions (OIDC tested)
CVE-2026-267196.134.8n/an/aCWE-79Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote a…
CVE-2026-623615.534.4knadhlistmonkCWE-89listmonk: SQL Injection in `/api/subscribers/export` bypasses table access co…
CVE-2026-616447.734.3labringFastGPTCWE-863FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant d…
CVE-2025-327816.534.3apolloconfigapolloCWE-639Apollo: Apollo Portal release endpoint allows cross-application configuration…
CVE-2026-534447.634.1wekanwekanCWE-269Wekan: Missing authorization on OIDC Meteor methods allows privilege escalati…
CVE-2026-534457.134.1wekanwekanCWE-862Wekan: Authorization bypass in copyBoard DDP method allows any user to copy p…
CVE-2026-159075.533.9H3CSecPath F1000-C8300CWE-74H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
CVE-2026-600858.733.7MervinPraisonPraisonAICWE-273PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
CVE-2026-535187.633.7better-authbetter-authCWE-362Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Ena…
CVE-2026-618357.733.6directusdirectusCWE-918Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
CVE-2026-387545.133.4BusyBoxBusyBoxCWE-125A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0…
CVE-2026-334458.733.4Absolute SecuritySecure AccessCWE-400Memory management vulnerability in Secure Access servers
CVE-2026-534476.533.0wekanwekanCWE-639Wekan: `cloneBoard` Meteor method has no authorization check — any user can c…
CVE-2026-545626.533.0cloudrevecloudreveCWE-918Cloudreve: Non-admin remote download users can SSRF loopback/internal service…
CVE-2026-578318.732.9digital-peak.comDP Calendar extension for JoomlaCWE-89Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in …
CVE-2026-578328.732.9joomdonation.comEDocman extension for JoomlaCWE-89Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in …
CVE-2026-471605.832.5dani-garciavaultwardenCWE-918Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex…
CVE-2026-106738.832.1zephyrprojectzephyrCWE-787Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly
CVE-2026-628436.831.9filebrowserfilebrowserCWE-22File Browser: Archive builder turns backslash filenames into path traversal (…
CVE-2026-142517.731.8Red HatRed Hat OpenShift GitOpsCWE-862Gitops-operator: gitops-operator: missing allowednamespace check in reconcile…
CVE-2026-614276.931.7MervinPraisonPraisonAICWE-20PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream
CVE-2026-115795.331.7UnknownKali Forms — Contact Form & Drag-and-Drop BuilderCWE-434Kali Forms < 2.4.17 - Unauthenticated Media Upload
CVE-2026-540529.931.6czlonkowskin8n-mcpCWE-639n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP…
CVE-2026-528707.631.6modelcontextprotocolpython-sdkCWE-862MCP Python SDK: Experimental task handlers allow any client to access and can…
CVE-2026-122818.131.1UnknownShibbolethCWE-287Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Ident…
CVE-2026-132305.330.9TP-Link Systems Inc.Kasa EC71 v4CWE-200Information Disclosure Vulnerability in Local Discovery Response in TP-Link K…
CVE-2026-458058.830.7penpotpenpotCWE-749Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoi…
CVE-2026-409582.330.5Absolute SecuritySecure AccessCWE-20Input validation error in Secure Access clients prior to 14.55
CVE-2026-454178.730.4dataeasedataeaseCWE-89DataEase: SQL injection vulnerability
CVE-2026-455358.730.4dataeasedataeaseCWE-89DataEase: Stored SQL Injection Vulnerability
CVE-2026-458047.530.4huggingfacediffusersCWE-367Diffusers: TOCTOU Trust Remote Code Bypass
CVE-2026-614407.130.3MervinPraisonPraisonAICWE-862PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints
CVE-2026-334437.130.1Absolute SecuritySecure AccessCWE-400Memory management error in Secure Access servers prior to 14.55
CVE-2026-553995.129.4Absolute SecuritySecure AccessCWE-400Resource exhaustion vulnerability in the Secure Access publisher
CVE-2026-544435.929.1lissy93dashyCWE-80Dashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas…
CVE-2026-592546.329.1n8nn8nCWE-639n8n - External Secrets Disclosure via Workflow Node Expressions
CVE-2026-616466.329.1labringFastGPTCWE-918FastGPT: Shared axios SSRF guard validates only the initial URL before follow…
CVE-2026-97708.629.0TP-Link Systems Inc.Kasa EC71 v4CWE-321Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link K…
CVE-2026-464587.128.5ICU ScandinaviaBoomerangCWE-522Credential exposure in ICU Scandinavia Boomerang
CVE-2026-493537.528.3decolua9routerCWE-2909Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
CVE-2026-458067.728.0penpotpenpotCWE-918Penpot: Authenticated SSRF in remote image import via create-file-media-objec…
CVE-2026-334446.928.0Absolute SecutitySecure AccessCWE-119Memory management vulnerability in Secure Access servers
CVE-2026-553986.928.1Absolute SecuritySecure AccessCWE-119Memory management vulnerability in Secure Access clients
CVE-2026-618716.328.0ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in ICON decoder
CVE-2026-614308.427.4MervinPraisonPraisonAICWE-918PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl
CVE-2026-499975.427.3surrealdbsurrealdbCWE-285SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
CVE-2026-387522.926.8BusyBoxBusyBoxCWE-674A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit…
CVE-2026-387552.926.8BusyBoxBusyBoxCWE-674A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.…
CVE-2026-501477.626.3metabasemetabaseCWE-88Metabase: Arbitrary File Read via MySQL Connection Property Injection
CVE-2026-159212.126.2nvm-shnvmCWE-22nvm path traversal via a malicious mirror's LTS codename writes outside the a…
CVE-2026-623535.425.6taosdataTDengineCWE-125TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken
CVE-2026-563536.325.3n8nn8nCWE-287n8n - Authentication Bypass in Chat Trigger Node
CVE-2026-336845.325.2WWBNAVideoCWE-862AVideo's Privilege AVideo: Escalation via Unguarded Permission Parameters in …
CVE-2026-563525.325.1n8nn8nCWE-22n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter
CVE-2026-586598.424.9Lightning-AIpytorch-lightningCWE-470PyTorch Lightning Arbitrary Code Execution via _instantiator Hyperparameter
CVE-2026-614468.624.8MervinPraisonPraisonAICWE-94PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery
CVE-2026-614526.924.8getgravgravCWE-613Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens
CVE-2026-115805.524.3UnknownKali Forms — Contact Form & Drag-and-Drop BuilderCWE-639Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
CVE-2026-409542.124.3Absolute SecuritySecure AccessCWE-191Integer underflow in Secure Access clients prior to 14.55
CVE-2026-409552.124.3Absolute SecuritySecure AccessCWE-191Integer underflow vulnerability in Secure Access clients
CVE-2026-466849.524.1dataeasedataeaseCWE-347DataEase: Unauthorized Command Execution Vulnerability
CVE-2026-545637.123.7cloudrevecloudreveCWE-863Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`…
CVE-2026-626833.123.7filebrowserfilebrowserCWE-863File Browser: Trailing-slash delete leaves a stale public share behind
CVE-2026-332136.122.7getredashredashCWE-601Redash: Open redirect vulnerability in post-login redirect handling
CVE-2026-614387.021.7MervinPraisonPraisonAICWE-78PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox
CVE-2026-567646.321.7HonoHonoCWE-208Hono - Timing Attack in basicAuth and bearerAuth Middleware
CVE-2026-600625.321.7F5NGINX AgentCWE-22NGINX Agent Vulnerability
CVE-2026-566786.421.4decolua9routerCWE-209Router: Kiro region injection allows authenticated SSRF with Authorization h…
CVE-2026-623485.420.7taosdataTDengineCWE-862TDengine: KILL SSMIGRATE missing authorization lets low-privilege users inter…
CVE-2026-501826.120.5WWBNAVideoCWE-79AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Ga…
CVE-2026-556085.420.0czlonkowskin8n-mcpCWE-200n8n-MCP: Incorrect authorization can expose default-scope workflow version ba…
CVE-2026-567428.919.5ciliumciliumCWE-862Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
CVE-2026-535129.119.4better-authbetter-authCWE-287Better Auth: OAuth refresh-token replay via missing client authentication on …
CVE-2026-409562.118.6Absolute SecuritySecure AccessCWE-200Memory disclosure in Secure Access Clients
CVE-2026-600656.317.9F5NGINX PlusCWE-125NGINX Plus ngx_stream_mqtt_filter_module vulnerability
CVE-2026-614535.117.7getgravgravCWE-79Grav before 2.0.1 XSS via Twig String Concatenation
CVE-2026-201569.816.8CiscoCisco RoomOS SoftwareCWE-119Cisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities
CVE-2026-501834.716.8WWBNAVideoCWE-79WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI …
CVE-2026-585596.516.5HuaweiHarmony OSCWE-789DoS vulnerability in the vibration service. Impact: Successful exploitation o…
CVE-2026-471588.316.4dani-garciavaultwardenCWE-352Vaultwarden: CSRF in SSO Authorization Flow
CVE-2026-616435.916.1labringFastGPTCWE-863FastGPT: workflow runtime can execute another user's private HTTP toolset
CVE-2026-535139.615.8better-authbetter-authCWE-20Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @b…
CVE-2026-567435.415.9ciliumciliumCWE-863Cilium may unexpectedly allow ingress traffic from the local namespace when a…
CVE-2026-528429.315.6lightpanda-iobrowserCWE-346Lightpanda:URL parser misidentifies page origin for URLs containing @ in the …
CVE-2026-387534.915.6BusyBoxBusyBoxCWE-416A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0…
CVE-2026-15634.815.1PegasystemsPega InfinityCWE-79Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cros…
CVE-2026-598384.815.1FortinetFortiSIEMCWE-80A improper neutralization of script-related html tags in a web page (basic xs…
CVE-2026-15624.615.1PegasystemsPega InfinityCWE-79Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-s…
CVE-2026-528439.314.1lightpanda-iobrowserCWE-346Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin…
CVE-2026-535168.313.8better-authbetter-authCWE-287Better Auth: Account takeover via OAuth auto-link to unverified pre-registere…
CVE-2026-599507.613.7modelcontextprotocolpython-sdkCWE-346MCP Python SDK: WebSocket server transport does not support Host/Origin valid…
CVE-2026-202986.513.7SplunkSplunk EnterpriseCWE-200Sensitive Information Disclosure through the storage/passwords REST Endpoint …
CVE-2026-623555.413.6taosdataTDengineCWE-269TDengine: Standard User permission unexpect
CVE-2026-415806.113.3Stirling-ToolsStirling-PDFCWE-79Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Au…
CVE-2026-467097.813.1EugenytabbyCWE-77Tabby: Drag-and-drop path injection still allows RCE via shell command substi…
CVE-2026-618606.312.5ImageMagickImageMagickCWE-416ImageMagick before 7.1.2-26 Use-After-Free via freetype
CVE-2026-618686.312.5ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in YUV Decoder
CVE-2026-267189.112.2n/an/aCWE-352A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin…
CVE-2026-487997.712.0gitroomhqpostiz-appCWE-345Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook
CVE-2026-505629.311.6labringFastGPTCWE-266FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview…
CVE-2026-453377.611.5better-authbetter-authCWE-285Better Auth: Device authorization approve and deny accept any authenticated s…
CVE-2026-560876.111.4DellThinOS 10CWE-693Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism…
CVE-2026-614338.511.1MervinPraisonPraisonAICWE-94PraisonAI before 4.6.78 Code Injection via API deployment generator
CVE-2026-535147.79.9better-authbetter-authCWE-287Better Auth: Unauthorized invitation acceptance via unverified email match in…
CVE-2026-499886.89.8yamadashyrepomixCWE-200Repomix: attach_packed_output can bypass file-read secret scanning for suppor…
CVE-2026-552428.89.4frappeerpnextCWE-863ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock …
CVE-2026-389745.39.1n/an/aCWE-295Dulwich through 1.1.0 was found to be missing SSH host key verification in co…
CVE-2026-618632.18.3ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder
CVE-2026-618662.18.3ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in JNG encoder
CVE-2026-202968.37.8SplunkSplunk EnterpriseCWE-352SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in De…
CVE-2026-429368.47.3SBI SECURITIES Co.,Ltd.HYPER SBI 2CWE-427The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If ther…
CVE-2026-150298.46.4ASUSSystem Control Interface v3CWE-822Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS Syste…
CVE-2026-494458.86.0ciliumciliumCWE-732Cilium: Sensitive information disclosure and cluster disruption via local Env…
CVE-2026-158097.85.7Red HatConfidential Compute AttestationCWE-134Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection …
CVE-2026-135858.25.7ASUSSystem Control Interface v3CWE-226Allocation of Resources Without Limits and Throttling and Sensitive Informati…
CVE-2026-149616.25.6Pegatron Corp.Tdelo64.sysCWE-20CVE-2026-14961
CVE-2026-501447.15.2TencentncnnCWE-20ncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negativ…
CVE-2026-566877.84.7DellThinOS 10CWE-448Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature i…
CVE-2026-618288.54.6NixOSnixpkgsCWE-276nixos/mysql : `services.mysql` is configured with insecure authentication by …
CVE-2026-453137.74.6sandboxie-plusSandboxieCWE-284Sandboxie-Plus: Sandboxie APC Injection Sandbox Escape
CVE-2026-600876.94.3MervinPraisonPraisonAICWE-863PraisonAI before 1.6.78 Tool Approval Cache Bypass
CVE-2026-563754.84.2ImageMagickImageMagickCWE-401ImageMagick - Memory Leak in ASHLAR Coder Action Failure
CVE-2026-133859.53.7ASUSRouterCWE-295An Improper Validation of Integrity Check Value and Improper Certificate Vali…
CVE-2026-622945.13.5flameshot-orgflameshotCWE-362Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open …
CVE-2026-618672.13.5ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder
CVE-2026-409528.53.3Absolute SecuritySecure AccessCWE-276Privilge misconfiguration in Secure Access installers
CVE-2026-150305.63.3ASUSSystem Control Interface v3CWE-125Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control I…
CVE-2026-585494.02.5HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585504.02.5HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585534.02.5HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585515.12.4HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585525.12.4HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585587.82.4HuaweiHarmony OSCWE-840Permission control vulnerability in the file system. Impact: Successful explo…
CVE-2026-618594.82.4ImageMagickImageMagickCWE-59ImageMagick before 7.1.2-26 Policy Bypass via script operation
CVE-2026-477036.32.2AdguardTeamAdGuardHomeCWE-330AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
CVE-2026-585556.61.7HuaweiHarmonyOSCWE-264Permission bypass vulnerability in the card module. Impact: Successful exploi…
CVE-2026-585565.11.6HuaweiHarmony OSCWE-264Permission control vulnerability in the Bluetooth module. Impact: Successful …
CVE-2026-89208.51.5ASUSAura Wallpaper ServiceCWE-73Improper Restriction of Communication Channel to Intended Endpoints and Exter…
CVE-2026-585546.61.4HuaweiHarmonyOSCWE-200Permission control vulnerability in the Settings module. Impact: Successful e…
CVE-2026-406335.51.4DellPowerScale OneFSCWE-532Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 th…
CVE-2026-201579.81.3CiscoCisco RoomOS SoftwareCWE-311Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
CVE-2026-495016.71.2DellPowerScale OneFSCWE-269Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.…
CVE-2026-618622.11.2ImageMagickImageMagickCWE-125ImageMagick before 7.1.2-26 Information Disclosure via identify
CVE-2026-157796.11.1Red HatRed Hat Enterprise Linux 10CWE-732Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths with…
CVE-2026-618642.11.0ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in Log Colorspace
CVE-2026-618652.11.0ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in Hough Lines
CVE-2026-618692.11.0ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in MIFF Encoder
CVE-2026-585574.81.0HuaweiHarmonyOSCWE-701Design defect vulnerability in Expedition mode. Impact: Successful exploitati…
CVE-2026-409536.70.8Absolute SecuritySecure AccessCWE-787Heap overflow in Secure Access clients
CVE-2026-618722.00.8ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak via TIFF Encoder
CVE-2026-614641.00.6ImageMagickImageMagickCWE-122ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-15 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.