AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1302 96.0 YES
AFFECTED Product Versions Fixed Oracle Payments 12.2.3 – —
TIMELINE May 18 Reserved by CNA Jul 15 Added to CISA KEV, due Jul 18 Jul 15 Published (CNA: oracle)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
268 CVEs published, led by ImageMagick (14).
268 CVEs published July 15, 2026: 36 critical, 123 high, 92 medium, 17 low; 1 in the KEV catalog at press time; 14 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 243 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4072 | 16475 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
716 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 40 | 1520 | 121 | 866 | 532 | 1 | 11 | 2 | 0.1 | 7.5 | .0014 | -55 ▼ |
| microsoft | 624 | 1381 | 92 | 963 | 312 | 14 | 286 | 22 | 1.6 | 7.8 | .0047 | +417 ▲ |
| 94 | 1359 | 150 | 616 | 555 | 38 | 77 | 6 | 0.4 | 7.8 | .0024 | -497 ▼ | |
| red hat | 50 | 272 | 14 | 109 | 132 | 17 | 2 | 0 | 0.0 | 6.5 | .0032 | -3 ▼ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | -14 ▼ |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0039 | +8 ▲ |
| canonical | 1 | 21 | 2 | 6 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +1 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 15 | 37 | 8 | 18 | 11 | 0 | 56 | 11 | 29.7 | 7.5 | .0057 | +11 ▲ |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +20 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | -11 ▼ |
| fortinet | 12 | 21 | 5 | 6 | 10 | 0 | 28 | 3 | 14.3 | 7.2 | .0039 | +10 ▲ |
| f5 | 8 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | +8 ▲ |
| ivanti | 2 | 11 | 4 | 5 | 2 | 0 | 25 | 5 | 45.5 | 8.8 | .3445 | -2 ▼ |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 76 | 231 | 47 | 89 | 83 | 11 | 33 | 1 | 0.4 | 7.5 | .0058 | +9 ▲ |
| mozilla | 6 | 62 | 12 | 18 | 32 | 0 | 9 | 0 | 0.0 | 6.5 | .0026 | +1 ▲ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -4 ▼ |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0039 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1 | 271 | 133 | 116 | 18 | 4 | 27 | 3 | 1.1 | 8.8 | .0040 | -1 ▼ |
| adobe | 93 | 237 | 26 | 102 | 105 | 4 | 19 | 3 | 1.3 | 7.5 | .0026 | -31 ▼ |
| ibm | 2 | 126 | 38 | 42 | 46 | 0 | 6 | 0 | 0.0 | 7.5 | .0034 | -9 ▼ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 6 | 0 | 0.0 | 7.5 | .0037 | +5 ▲ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .7758 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | +17 ▲ |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| d-link | 1 | 13 | 0 | 5 | 3 | 5 | 3 | 0 | 0.0 | 6.0 | .0059 | -8 ▼ |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -5 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -1 ▼ |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 37 | 108 | 0 | 0 | 56 | 52 | 0 | 0 | 0.0 | 5.5 | .0032 | +1 ▲ |
| dell | 37 | 93 | 5 | 42 | 43 | 3 | 2 | 1 | 1.1 | 7.0 | .0021 | +30 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | +20 ▲ |
| openclaw | 16 | 83 | 0 | 48 | 25 | 10 | 0 | 0 | 0.0 | 7.2 | .0024 | -18 ▼ |
| nvidia | 40 | 79 | 12 | 52 | 15 | 0 | 0 | 0 | 0.0 | 7.8 | .0037 | +36 ▲ |
| imagemagick | 32 | 73 | 1 | 5 | 55 | 12 | 0 | 0 | 0.0 | 5.3 | .0019 | +4 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -71 ▼ |
| itsourcecode | 12 | 65 | 0 | 0 | 19 | 46 | 0 | 0 | 0.0 | 2.1 | .0033 | -10 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| Vendor | CVEs |
|---|---|
| microsoft | 638 |
| 593 | |
| linux | 458 |
| oracle | 241 |
| apache | 130 |
| red hat | 125 |
| adobe | 111 |
| capgo | 81 |
| dell | 68 |
| ibm | 66 |
| Vendor | KEV |
|---|---|
| microsoft | 22 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| fortinet | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 62 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE-2026-46817 | Oracle Corporation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1701 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1701 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1701 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1701 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1701 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1701 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1701 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1701 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1701 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1701 |
EXPLOIT PUBLISHED — CVE-2026-10673 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41580 (Stirling-Tools Stirling-PDF). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45737 (argoproj argo-cd). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45738 (argoproj argo-cd). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45804 (huggingface diffusers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46709 (Eugeny tabby). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47703 (AdguardTeam AdGuardHome). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49987 (yamadashy repomix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49988 (yamadashy repomix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56398 (open-webui). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56400 (open-webui). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62947 (openwrt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62948 (openwrt). Public exploit reference added.
How to read these box scores · glossary
268 CVEs published. 25 box scores, 243 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1302 96.0 YES
AFFECTED Product Versions Fixed Oracle Payments 12.2.3 – —
TIMELINE May 18 Reserved by CNA Jul 15 Added to CISA KEV, due Jul 18 Jul 15 Published (CNA: oracle)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0500 91.6 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 4 Reserved by CNA Jul 15 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H H H 9.2 .0406 89.9 —
AFFECTED Product Versions Fixed NGINX Plus 37.0.0.1 – — NGINX Open Source 1.31.2 – —
TIMELINE May 5 Reserved by CNA Jul 15 Published (CNA: f5)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0335 87.8 —
AFFECTED Product Versions Fixed 9router >= 0.4.30, < 0.4.37 – —
TIMELINE May 13 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0328 87.5 —
AFFECTED Product Versions Fixed Apache Fineract unspecified —
TIMELINE Apr 1 Reserved by CNA Jul 15 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0130 68.2 —
AFFECTED Product Versions Fixed 9router < 0.5.2 – —
TIMELINE Jul 13 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0120 65.7 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 4 Reserved by CNA Jul 15 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0112 63.6 —
AFFECTED Product Versions Fixed grav unspecified 1.4.0
TIMELINE Jul 1 Reserved by CNA Jul 15 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N A H H H 8.4 .0103 61.1 —
AFFECTED Product Versions Fixed jsii unspecified —
TIMELINE Jul 15 Reserved by CNA Jul 15 Published (CNA: AMZN)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0102 60.8 —
AFFECTED Product Versions Fixed composer >= 1.0, < 1.10.28 – —
TIMELINE May 13 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0093 57.8 —
AFFECTED Product Versions Fixed Gravity Forms unspecified —
TIMELINE Jun 23 Reserved by CNA Jul 15 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0089 56.7 —
AFFECTED Product Versions Fixed nocobase < 2.0.61 – —
TIMELINE Jun 8 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0089 56.7 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Nov 18 Reserved by CNA Jul 15 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L N 5.3 .0083 54.9 —
AFFECTED Product Versions Fixed grav unspecified 1.0.3
TIMELINE Jul 9 Reserved by CNA Jul 15 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A H H H 8.6 .0080 54.0 —
AFFECTED Product Versions Fixed cherry-studio 1.2.2 – —
TIMELINE Apr 13 Reserved by CNA Jul 15 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0078 53.3 —
AFFECTED Product Versions Fixed wekan < 9.07 – —
TIMELINE Jun 8 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H N 8.6 .0077 52.8 —
AFFECTED Product Versions Fixed PraisonAI unspecified 1.6.78
TIMELINE Jul 9 Reserved by CNA Jul 15 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N H 8.1 .0074 51.9 —
AFFECTED Product Versions Fixed Apache Fineract unspecified 1.15.0
TIMELINE Jun 25 Reserved by CNA Jul 15 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U L H H 6.7 .0072 51.2 —
AFFECTED Product Versions Fixed nocobase < 2.1.19 – —
TIMELINE Jun 16 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N H 8.8 .0071 50.8 —
AFFECTED Product Versions Fixed NGINX Plus 37.0.0.1 – — NGINX Open Source 1.31.2 – —
TIMELINE Jul 8 Reserved by CNA Jul 15 Published (CNA: f5)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0070 50.5 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 7 Reserved by CNA Jul 15 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L H N 8.8 .0069 49.8 —
AFFECTED Product Versions Fixed PraisonAI unspecified 4.6.78
TIMELINE Jul 9 Reserved by CNA Jul 15 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H H 7.7 .0068 49.5 —
AFFECTED Product Versions Fixed cursor < 03/31/2026 – —
TIMELINE Jul 10 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L N 6.9 .0066 49.0 —
AFFECTED Product Versions Fixed vaultwarden < 1.36.0 – —
TIMELINE May 18 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H N 9.3 .0066 49.0 —
AFFECTED Product Versions Fixed qinglong < 2.20.1 – —
TIMELINE Jun 16 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-61740 | 9.3 | 48.9 | HKUDS | LightRAG | CWE-287 | LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /a… |
| CVE-2026-43637 | 8.8 | 48.9 | PreferredAI | cornac | CWE-22 | Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py |
| CVE-2026-59235 | 8.7 | 48.7 | Roskus | Prospero Flow CRM | CWE-639 | Missing authorization in Prospero Flow CRM allows low-privileged users to rea… |
| CVE-2026-56287 | 8.1 | 48.6 | Apache Software Foundation | Apache Fineract | CWE-89 | Apache Fineract: Boolean SQL Injection in Client Search API (orderBy paramete… |
| CVE-2026-59236 | 6.9 | 47.9 | Roskus | Prospero Flow CRM | CWE-639 | Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant re… |
| CVE-2026-45534 | 9.0 | 47.8 | dataease | dataease | CWE-94 | DataEase: RCE Vulnerability |
| CVE-2026-56398 | 8.5 | 47.7 | open-webui | open-webui | CWE-20 | Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI |
| CVE-2026-55652 | 9.8 | 47.0 | wekan | wekan | CWE-287 | Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan… |
| CVE-2026-45738 | 8.7 | 46.3 | argoproj | argo-cd | CWE-79 | Argo CD: Stored XSS in application link annotations enables developer-to-admi… |
| CVE-2026-49352 | 9.8 | 46.1 | decolua | 9router | CWE-798 | 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass |
| CVE-2026-36590 | 7.5 | 45.5 | n/a | n/a | CWE-400 | An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of… |
| CVE-2026-62948 | 9.6 | 45.1 | openwrt | openwrt | CWE-79 | OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file line… |
| CVE-2026-59954 | 7.5 | 44.8 | apolloconfig | apollo | CWE-20 | Apollo ConfigService access key authentication bypass via appId parsing and n… |
| CVE-2026-59955 | 7.5 | 44.8 | apolloconfig | apollo | CWE-20 | Apollo ConfigService access key authentication bypass via raw config file app… |
| CVE-2026-59762 | 8.7 | 44.8 | F5 | BIG-IP | CWE-770 | BIG-IP HTTP/2 vulnerability |
| CVE-2026-20297 | 7.2 | 44.6 | Splunk | Splunk Enterprise | CWE-22 | Path Traversal through 'explicit_appname' in the App Install REST Endpoint in… |
| CVE-2026-62349 | 8.3 | 44.5 | taosdata | TDengine | CWE-121 | TDengine: Off-by-One Buffer Overflow |
| CVE-2026-50124 | 7.1 | 44.1 | dataease | dataease | CWE-434 | DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper |
| CVE-2026-62685 | 8.1 | 43.7 | filebrowser | filebrowser | CWE-647 | File Browser: Colliding username normalization gives two users the same home … |
| CVE-2026-48795 | 8.6 | 43.4 | adonisjs | core | CWE-1321 | Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser |
| CVE-2026-15804 | 8.7 | 43.2 | MetaGuru | HCM | CWE-89 | MetaGuru|HCM - SQL Injection |
| CVE-2026-49279 | 7.7 | 43.0 | WWBN | AVideo | CWE-79 | WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSoc… |
| CVE-2026-62350 | 7.2 | 43.0 | taosdata | TDengine | CWE-94 | TDengine: UDF lead to RCE |
| CVE-2026-49987 | 7.5 | 42.9 | yamadashy | repomix | CWE-88 | Repomix: Command Injection (RCE) via `--remote-branch` Argument Injection |
| CVE-2026-58658 | 8.8 | 42.8 | gpustack | gpustack | CWE-306 | GPUStack Unauthenticated Information Disclosure via Worker Endpoints |
| CVE-2026-52869 | 7.1 | 42.7 | modelcontextprotocol | python-sdk | CWE-639 | MCP Python SDK: HTTP transports serve session requests without verifying the … |
| CVE-2026-61736 | 9.3 | 42.5 | HKUDS | LightRAG | CWE-942 | LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests |
| CVE-2026-61371 | 7.5 | 42.4 | n/a | n/a | CWE-59 | Microsoft AVML before 0.17.0 could follow a symlink when opening a destinatio… |
| CVE-2026-15583 | 8.6 | 42.3 | Grafana | Grafana MCP Server | CWE-610 | SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header |
| CVE-2026-46421 | 9.3 | 42.0 | cap-js | @cap-js/sqlite | CWE-506 | Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-… |
| CVE-2026-62947 | 4.9 | 42.0 | openwrt | openwrt | CWE-22 | OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download |
| CVE-2026-44986 | 9.9 | 42.0 | penpot | penpot | CWE-287 | Penpot: Pre-authenticated account takeover via team-invitation token + prepar… |
| CVE-2026-45737 | 6.5 | 41.9 | argoproj | argo-cd | CWE-200 | Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive… |
| CVE-2026-56400 | 9.0 | 41.8 | open-webui | open-webui | CWE-613 | open-webui - Remote Code Execution via CORS Misconfiguration and Session Vali… |
| CVE-2026-56679 | 8.7 | 41.7 | decolua | 9router | CWE-915 | 9Router: Mass assignment in PATCH /api/settings allows authenticated authoriz… |
| CVE-2026-61436 | 8.8 | 41.7 | MervinPraison | PraisonAI | CWE-287 | PraisonAI before 4.6.78 Missing Webhook Signature Verification |
| CVE-2026-61684 | 8.8 | 41.3 | labring | FastGPT | CWE-798 | FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke… |
| CVE-2026-55723 | 8.7 | 41.1 | F5 | NGINX Ingress Controller | CWE-76 | NGINX Ingress Controller vulnerability |
| CVE-2026-54458 | 9.6 | 41.0 | WWBN | AVideo | CWE-79 | AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metada… |
| CVE-2026-26032 | 5.4 | 41.0 | Apache Software Foundation | Apache Ivy | CWE-22 | Apache Ivy: PackagerResolver path traversal vulnerability |
| CVE-2026-58660 | 7.2 | 40.8 | kanboard | kanboard | CWE-639 | Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop |
| CVE-2026-52865 | 7.1 | 40.6 | F5 | NGINX Ingress Controller | CWE-476 | NGINX Ingress Controller vulnerability |
| CVE-2026-11851 | 5.9 | 40.6 | ASUS | Router | CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Inje… |
| CVE-2026-20146 | 5.5 | 40.5 | Cisco | Cisco Identity Services Engine Software | CWE-22 | Cisco Identity Services Engine Path Traversal Vulnerability |
| CVE-2026-53446 | 6.2 | 40.4 | wekan | wekan | CWE-918 | Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs |
| CVE-2026-62378 | 9.0 | 39.9 | rustfs | console | CWE-79 | RustFS Console: Critical Stored XSS in Preview Modal leading to Administrativ… |
| CVE-2026-52893 | 9.2 | 39.2 | wekan | wekan | CWE-287 | Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in o… |
| CVE-2026-52890 | 7.1 | 39.0 | wekan | wekan | CWE-22 | Wekan: Arbitrary file read and server DoS via attachment versions.original.path |
| CVE-2026-61836 | 8.6 | 38.9 | directus | directus | CWE-524 | Directus: Authorization-dependent response served from unsegmented cache key |
| CVE-2026-63175 | 7.1 | 38.7 | Lookyloo | PlaywrightCapture | CWE-613 | Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo -… |
| CVE-2026-56349 | 6.3 | 38.7 | n8n | n8n | CWE-20 | n8n - Guardrail Node Bypass via Crafted Input |
| CVE-2026-52888 | 6.8 | 38.5 | nocobase | nocobase | CWE-184 | NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass |
| CVE-2026-45320 | 8.7 | 38.4 | dataease | dataease | CWE-89 | DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection |
| CVE-2026-20153 | 7.5 | 38.4 | Cisco | Cisco RoomOS Software | CWE-20 | Cisco RoomOS Security Hardening Release - Input Validation Vulnerabilities |
| CVE-2026-20158 | 7.5 | 38.4 | Cisco | Cisco RoomOS Software | CWE-664 | Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulner… |
| CVE-2026-20187 | 7.5 | 38.4 | Cisco | Cisco RoomOS Software | CWE-703 | Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vul… |
| CVE-2026-50030 | 7.1 | 38.4 | dataease | dataease | CWE-89 | DataEase: Arbitrary SQL execution in preview path (direct data disclosure) |
| CVE-2026-49867 | 6.3 | 38.4 | dataease | dataease | CWE-79 | DataEase: Authenticated Stored XSS in DataEase Template Static Resources |
| CVE-2026-12382 | 8.2 | 38.1 | Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | CWE-290 | Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject he… |
| CVE-2026-62314 | 5.8 | 38.1 | TecharoHQ | anubis | CWE-284 | Anubis: Policy bypass via client controlled X-Original-URI header |
| CVE-2026-54560 | 7.6 | 38.1 | cloudreve | cloudreve | CWE-863 | Cloudreve: OAuth access tokens bypass scope enforcement due to missing client… |
| CVE-2026-52892 | 6.5 | 38.1 | wekan | wekan | CWE-862 | Wekan: Read-only board members can create/modify/delete Custom Fields (privil… |
| CVE-2026-55576 | 8.8 | 38.0 | MaaAssistantArknights | MaaAssistantArknights | CWE-78 | MaaAssistantArknights: PR-title expression injection in release-preparation.yml |
| CVE-2026-62351 | 7.5 | 37.9 | taosdata | TDengine | CWE-125 | TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in … |
| CVE-2026-61873 | 7.2 | 37.9 | getgrav | grav | CWE-73 | Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename |
| CVE-2026-14960 | 9.8 | 37.8 | Pegatron Corp. | Tdelo64.sys | CWE-269 | CVE-2026-14960 |
| CVE-2026-56339 | 8.7 | 37.8 | Cap-go | capgo | CWE-203 | Capgo - Unauthenticated Organization Existence Enumeration via rescind_invita… |
| CVE-2026-45419 | 8.5 | 37.8 | dataease | dataease | CWE-22 | DataEase: Arbitrary File Write Vulnerability |
| CVE-2026-45533 | 8.3 | 37.8 | dataease | dataease | CWE-22 | DataEase: Path Traversal Vulnerability |
| CVE-2026-59258 | 7.2 | 37.6 | immich-app | immich | CWE-863 | immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser |
| CVE-2026-56434 | 8.3 | 37.2 | F5 | NGINX Plus | CWE-416 | NGINX ngx_http_ssi_module vulnerability |
| CVE-2026-47164 | 7.7 | 37.1 | dani-garcia | vaultwarden | CWE-284 | Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Att… |
| CVE-2026-8919 | 7.2 | 37.0 | ASUS | GameSDK | CWE-942 | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSD… |
| CVE-2026-12512 | 8.6 | 36.9 | Unknown | Quotes llama | CWE-89 | Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter |
| CVE-2026-57996 | 8.7 | 36.6 | phpMyFAQ | phpMyFAQ | CWE-269 | phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endp… |
| CVE-2026-61449 | 7.1 | 36.4 | getgrav | grav | CWE-409 | Grav before 2.0.2 Decompression Bomb via Forged ZIP Size |
| CVE-2026-59255 | 7.1 | 36.4 | SpecterOps | BloodHound | CWE-862 | BloodHound Missing Authorization on Custom Node Management API |
| CVE-2026-59259 | 6.0 | 36.3 | n8n | n8n | CWE-639 | n8n - Permission Bypass via Expression Parser Mismatch in External Secrets |
| CVE-2026-58077 | 8.7 | 36.2 | weeblr.com | 4Analytics extension for Joomla | CWE-79 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 |
| CVE-2026-57833 | 8.6 | 36.2 | weeblr.com | 4Analytics extension for Joomla | CWE-79 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 |
| CVE-2026-9007 | 5.5 | 36.2 | HCL Software | HCL Notes | CWE-79 | Reflected XSS in HCL Notes |
| CVE-2026-46459 | 5.3 | 35.9 | ICU Scandinavia | Boomerang | CWE-862 | Missing Authorization in ICU Scandinavia Boomerang |
| CVE-2026-45150 | 6.3 | 35.4 | zen-browser | desktop | CWE-451 | Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing |
| CVE-2026-40957 | 6.1 | 35.5 | Absolute Security | Secure Access | CWE-1021 | Frameable content vulnerability in the Secure Access server login page |
| CVE-2026-50148 | 9.1 | 35.4 | metabase | metabase | CWE-73 | Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write |
| CVE-2026-53515 | 7.1 | 35.3 | better-auth | better-auth | CWE-269 | Better Auth: Privilege escalation via SSO provider registration: missing admi… |
| CVE-2026-55234 | 8.5 | 35.2 | wekan | wekan | CWE-284 | Wekan: Broken access control: any authenticated user can move their Cards/Lis… |
| CVE-2026-20150 | 8.8 | 35.1 | Cisco | Cisco RoomOS Software | CWE-284 | Cisco RoomOS Security Hardening Release - Access Control Vulnerabilities |
| CVE-2026-15746 | 6.9 | 35.0 | Amazon | strands-agents-tools | CWE-918 | Credential disclosure in Strands Agents Tools elasticsearch_memory tool |
| CVE-2026-61451 | 9.4 | 35.0 | getgrav | grav | CWE-601 | Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url |
| CVE-2026-53517 | 8.1 | 34.9 | better-auth | better-auth | CWE-362 | Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Conc… |
| CVE-2026-46485 | 8.2 | 34.7 | lissy93 | dashy | CWE-15 | Dash: Users can write to config despire permissions (OIDC tested) |
| CVE-2026-26719 | 6.1 | 34.8 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote a… |
| CVE-2026-62361 | 5.5 | 34.4 | knadh | listmonk | CWE-89 | listmonk: SQL Injection in `/api/subscribers/export` bypasses table access co… |
| CVE-2026-61644 | 7.7 | 34.3 | labring | FastGPT | CWE-863 | FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant d… |
| CVE-2025-32781 | 6.5 | 34.3 | apolloconfig | apollo | CWE-639 | Apollo: Apollo Portal release endpoint allows cross-application configuration… |
| CVE-2026-53444 | 7.6 | 34.1 | wekan | wekan | CWE-269 | Wekan: Missing authorization on OIDC Meteor methods allows privilege escalati… |
| CVE-2026-53445 | 7.1 | 34.1 | wekan | wekan | CWE-862 | Wekan: Authorization bypass in copyBoard DDP method allows any user to copy p… |
| CVE-2026-15907 | 5.5 | 33.9 | H3C | SecPath F1000-C8300 | CWE-74 | H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection |
| CVE-2026-60085 | 8.7 | 33.7 | MervinPraison | PraisonAI | CWE-273 | PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox |
| CVE-2026-53518 | 7.6 | 33.7 | better-auth | better-auth | CWE-362 | Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Ena… |
| CVE-2026-61835 | 7.7 | 33.6 | directus | directus | CWE-918 | Directus: SSRF Protection Bypass via 0.0.0.0 in File Import |
| CVE-2026-38754 | 5.1 | 33.4 | BusyBox | BusyBox | CWE-125 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0… |
| CVE-2026-33445 | 8.7 | 33.4 | Absolute Security | Secure Access | CWE-400 | Memory management vulnerability in Secure Access servers |
| CVE-2026-53447 | 6.5 | 33.0 | wekan | wekan | CWE-639 | Wekan: `cloneBoard` Meteor method has no authorization check — any user can c… |
| CVE-2026-54562 | 6.5 | 33.0 | cloudreve | cloudreve | CWE-918 | Cloudreve: Non-admin remote download users can SSRF loopback/internal service… |
| CVE-2026-57831 | 8.7 | 32.9 | digital-peak.com | DP Calendar extension for Joomla | CWE-89 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in … |
| CVE-2026-57832 | 8.7 | 32.9 | joomdonation.com | EDocman extension for Joomla | CWE-89 | Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in … |
| CVE-2026-47160 | 5.8 | 32.5 | dani-garcia | vaultwarden | CWE-918 | Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex… |
| CVE-2026-10673 | 8.8 | 32.1 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly |
| CVE-2026-62843 | 6.8 | 31.9 | filebrowser | filebrowser | CWE-22 | File Browser: Archive builder turns backslash filenames into path traversal (… |
| CVE-2026-14251 | 7.7 | 31.8 | Red Hat | Red Hat OpenShift GitOps | CWE-862 | Gitops-operator: gitops-operator: missing allowednamespace check in reconcile… |
| CVE-2026-61427 | 6.9 | 31.7 | MervinPraison | PraisonAI | CWE-20 | PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream |
| CVE-2026-11579 | 5.3 | 31.7 | Unknown | Kali Forms — Contact Form & Drag-and-Drop Builder | CWE-434 | Kali Forms < 2.4.17 - Unauthenticated Media Upload |
| CVE-2026-54052 | 9.9 | 31.6 | czlonkowski | n8n-mcp | CWE-639 | n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP… |
| CVE-2026-52870 | 7.6 | 31.6 | modelcontextprotocol | python-sdk | CWE-862 | MCP Python SDK: Experimental task handlers allow any client to access and can… |
| CVE-2026-12281 | 8.1 | 31.1 | Unknown | Shibboleth | CWE-287 | Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Ident… |
| CVE-2026-13230 | 5.3 | 30.9 | TP-Link Systems Inc. | Kasa EC71 v4 | CWE-200 | Information Disclosure Vulnerability in Local Discovery Response in TP-Link K… |
| CVE-2026-45805 | 8.8 | 30.7 | penpot | penpot | CWE-749 | Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoi… |
| CVE-2026-40958 | 2.3 | 30.5 | Absolute Security | Secure Access | CWE-20 | Input validation error in Secure Access clients prior to 14.55 |
| CVE-2026-45417 | 8.7 | 30.4 | dataease | dataease | CWE-89 | DataEase: SQL injection vulnerability |
| CVE-2026-45535 | 8.7 | 30.4 | dataease | dataease | CWE-89 | DataEase: Stored SQL Injection Vulnerability |
| CVE-2026-45804 | 7.5 | 30.4 | huggingface | diffusers | CWE-367 | Diffusers: TOCTOU Trust Remote Code Bypass |
| CVE-2026-61440 | 7.1 | 30.3 | MervinPraison | PraisonAI | CWE-862 | PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints |
| CVE-2026-33443 | 7.1 | 30.1 | Absolute Security | Secure Access | CWE-400 | Memory management error in Secure Access servers prior to 14.55 |
| CVE-2026-55399 | 5.1 | 29.4 | Absolute Security | Secure Access | CWE-400 | Resource exhaustion vulnerability in the Secure Access publisher |
| CVE-2026-54443 | 5.9 | 29.1 | lissy93 | dashy | CWE-80 | Dashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas… |
| CVE-2026-59254 | 6.3 | 29.1 | n8n | n8n | CWE-639 | n8n - External Secrets Disclosure via Workflow Node Expressions |
| CVE-2026-61646 | 6.3 | 29.1 | labring | FastGPT | CWE-918 | FastGPT: Shared axios SSRF guard validates only the initial URL before follow… |
| CVE-2026-9770 | 8.6 | 29.0 | TP-Link Systems Inc. | Kasa EC71 v4 | CWE-321 | Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link K… |
| CVE-2026-46458 | 7.1 | 28.5 | ICU Scandinavia | Boomerang | CWE-522 | Credential exposure in ICU Scandinavia Boomerang |
| CVE-2026-49353 | 7.5 | 28.3 | decolua | 9router | CWE-290 | 9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING |
| CVE-2026-45806 | 7.7 | 28.0 | penpot | penpot | CWE-918 | Penpot: Authenticated SSRF in remote image import via create-file-media-objec… |
| CVE-2026-33444 | 6.9 | 28.0 | Absolute Secutity | Secure Access | CWE-119 | Memory management vulnerability in Secure Access servers |
| CVE-2026-55398 | 6.9 | 28.1 | Absolute Security | Secure Access | CWE-119 | Memory management vulnerability in Secure Access clients |
| CVE-2026-61871 | 6.3 | 28.0 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in ICON decoder |
| CVE-2026-61430 | 8.4 | 27.4 | MervinPraison | PraisonAI | CWE-918 | PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl |
| CVE-2026-49997 | 5.4 | 27.3 | surrealdb | surrealdb | CWE-285 | SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted |
| CVE-2026-38752 | 2.9 | 26.8 | BusyBox | BusyBox | CWE-674 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit… |
| CVE-2026-38755 | 2.9 | 26.8 | BusyBox | BusyBox | CWE-674 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.… |
| CVE-2026-50147 | 7.6 | 26.3 | metabase | metabase | CWE-88 | Metabase: Arbitrary File Read via MySQL Connection Property Injection |
| CVE-2026-15921 | 2.1 | 26.2 | nvm-sh | nvm | CWE-22 | nvm path traversal via a malicious mirror's LTS codename writes outside the a… |
| CVE-2026-62353 | 5.4 | 25.6 | taosdata | TDengine | CWE-125 | TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken |
| CVE-2026-56353 | 6.3 | 25.3 | n8n | n8n | CWE-287 | n8n - Authentication Bypass in Chat Trigger Node |
| CVE-2026-33684 | 5.3 | 25.2 | WWBN | AVideo | CWE-862 | AVideo's Privilege AVideo: Escalation via Unguarded Permission Parameters in … |
| CVE-2026-56352 | 5.3 | 25.1 | n8n | n8n | CWE-22 | n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter |
| CVE-2026-58659 | 8.4 | 24.9 | Lightning-AI | pytorch-lightning | CWE-470 | PyTorch Lightning Arbitrary Code Execution via _instantiator Hyperparameter |
| CVE-2026-61446 | 8.6 | 24.8 | MervinPraison | PraisonAI | CWE-94 | PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery |
| CVE-2026-61452 | 6.9 | 24.8 | getgrav | grav | CWE-613 | Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens |
| CVE-2026-11580 | 5.5 | 24.3 | Unknown | Kali Forms — Contact Form & Drag-and-Drop Builder | CWE-639 | Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR |
| CVE-2026-40954 | 2.1 | 24.3 | Absolute Security | Secure Access | CWE-191 | Integer underflow in Secure Access clients prior to 14.55 |
| CVE-2026-40955 | 2.1 | 24.3 | Absolute Security | Secure Access | CWE-191 | Integer underflow vulnerability in Secure Access clients |
| CVE-2026-46684 | 9.5 | 24.1 | dataease | dataease | CWE-347 | DataEase: Unauthorized Command Execution Vulnerability |
| CVE-2026-54563 | 7.1 | 23.7 | cloudreve | cloudreve | CWE-863 | Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`… |
| CVE-2026-62683 | 3.1 | 23.7 | filebrowser | filebrowser | CWE-863 | File Browser: Trailing-slash delete leaves a stale public share behind |
| CVE-2026-33213 | 6.1 | 22.7 | getredash | redash | CWE-601 | Redash: Open redirect vulnerability in post-login redirect handling |
| CVE-2026-61438 | 7.0 | 21.7 | MervinPraison | PraisonAI | CWE-78 | PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox |
| CVE-2026-56764 | 6.3 | 21.7 | Hono | Hono | CWE-208 | Hono - Timing Attack in basicAuth and bearerAuth Middleware |
| CVE-2026-60062 | 5.3 | 21.7 | F5 | NGINX Agent | CWE-22 | NGINX Agent Vulnerability |
| CVE-2026-56678 | 6.4 | 21.4 | decolua | 9router | CWE-20 | 9Router: Kiro region injection allows authenticated SSRF with Authorization h… |
| CVE-2026-62348 | 5.4 | 20.7 | taosdata | TDengine | CWE-862 | TDengine: KILL SSMIGRATE missing authorization lets low-privilege users inter… |
| CVE-2026-50182 | 6.1 | 20.5 | WWBN | AVideo | CWE-79 | AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Ga… |
| CVE-2026-55608 | 5.4 | 20.0 | czlonkowski | n8n-mcp | CWE-200 | n8n-MCP: Incorrect authorization can expose default-scope workflow version ba… |
| CVE-2026-56742 | 8.9 | 19.5 | cilium | cilium | CWE-862 | Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces |
| CVE-2026-53512 | 9.1 | 19.4 | better-auth | better-auth | CWE-287 | Better Auth: OAuth refresh-token replay via missing client authentication on … |
| CVE-2026-40956 | 2.1 | 18.6 | Absolute Security | Secure Access | CWE-200 | Memory disclosure in Secure Access Clients |
| CVE-2026-60065 | 6.3 | 17.9 | F5 | NGINX Plus | CWE-125 | NGINX Plus ngx_stream_mqtt_filter_module vulnerability |
| CVE-2026-61453 | 5.1 | 17.7 | getgrav | grav | CWE-79 | Grav before 2.0.1 XSS via Twig String Concatenation |
| CVE-2026-20156 | 9.8 | 16.8 | Cisco | Cisco RoomOS Software | CWE-119 | Cisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities |
| CVE-2026-50183 | 4.7 | 16.8 | WWBN | AVideo | CWE-79 | WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI … |
| CVE-2026-58559 | 6.5 | 16.5 | Huawei | Harmony OS | CWE-789 | DoS vulnerability in the vibration service. Impact: Successful exploitation o… |
| CVE-2026-47158 | 8.3 | 16.4 | dani-garcia | vaultwarden | CWE-352 | Vaultwarden: CSRF in SSO Authorization Flow |
| CVE-2026-61643 | 5.9 | 16.1 | labring | FastGPT | CWE-863 | FastGPT: workflow runtime can execute another user's private HTTP toolset |
| CVE-2026-53513 | 9.6 | 15.8 | better-auth | better-auth | CWE-20 | Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @b… |
| CVE-2026-56743 | 5.4 | 15.9 | cilium | cilium | CWE-863 | Cilium may unexpectedly allow ingress traffic from the local namespace when a… |
| CVE-2026-52842 | 9.3 | 15.6 | lightpanda-io | browser | CWE-346 | Lightpanda:URL parser misidentifies page origin for URLs containing @ in the … |
| CVE-2026-38753 | 4.9 | 15.6 | BusyBox | BusyBox | CWE-416 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0… |
| CVE-2026-1563 | 4.8 | 15.1 | Pegasystems | Pega Infinity | CWE-79 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cros… |
| CVE-2026-59838 | 4.8 | 15.1 | Fortinet | FortiSIEM | CWE-80 | A improper neutralization of script-related html tags in a web page (basic xs… |
| CVE-2026-1562 | 4.6 | 15.1 | Pegasystems | Pega Infinity | CWE-79 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-s… |
| CVE-2026-52843 | 9.3 | 14.1 | lightpanda-io | browser | CWE-346 | Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin… |
| CVE-2026-53516 | 8.3 | 13.8 | better-auth | better-auth | CWE-287 | Better Auth: Account takeover via OAuth auto-link to unverified pre-registere… |
| CVE-2026-59950 | 7.6 | 13.7 | modelcontextprotocol | python-sdk | CWE-346 | MCP Python SDK: WebSocket server transport does not support Host/Origin valid… |
| CVE-2026-20298 | 6.5 | 13.7 | Splunk | Splunk Enterprise | CWE-200 | Sensitive Information Disclosure through the storage/passwords REST Endpoint … |
| CVE-2026-62355 | 5.4 | 13.6 | taosdata | TDengine | CWE-269 | TDengine: Standard User permission unexpect |
| CVE-2026-41580 | 6.1 | 13.3 | Stirling-Tools | Stirling-PDF | CWE-79 | Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Au… |
| CVE-2026-46709 | 7.8 | 13.1 | Eugeny | tabby | CWE-77 | Tabby: Drag-and-drop path injection still allows RCE via shell command substi… |
| CVE-2026-61860 | 6.3 | 12.5 | ImageMagick | ImageMagick | CWE-416 | ImageMagick before 7.1.2-26 Use-After-Free via freetype |
| CVE-2026-61868 | 6.3 | 12.5 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in YUV Decoder |
| CVE-2026-26718 | 9.1 | 12.2 | n/a | n/a | CWE-352 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin… |
| CVE-2026-48799 | 7.7 | 12.0 | gitroomhq | postiz-app | CWE-345 | Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook |
| CVE-2026-50562 | 9.3 | 11.6 | labring | FastGPT | CWE-266 | FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview… |
| CVE-2026-45337 | 7.6 | 11.5 | better-auth | better-auth | CWE-285 | Better Auth: Device authorization approve and deny accept any authenticated s… |
| CVE-2026-56087 | 6.1 | 11.4 | Dell | ThinOS 10 | CWE-693 | Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism… |
| CVE-2026-61433 | 8.5 | 11.1 | MervinPraison | PraisonAI | CWE-94 | PraisonAI before 4.6.78 Code Injection via API deployment generator |
| CVE-2026-53514 | 7.7 | 9.9 | better-auth | better-auth | CWE-287 | Better Auth: Unauthorized invitation acceptance via unverified email match in… |
| CVE-2026-49988 | 6.8 | 9.8 | yamadashy | repomix | CWE-200 | Repomix: attach_packed_output can bypass file-read secret scanning for suppor… |
| CVE-2026-55242 | 8.8 | 9.4 | frappe | erpnext | CWE-863 | ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock … |
| CVE-2026-38974 | 5.3 | 9.1 | n/a | n/a | CWE-295 | Dulwich through 1.1.0 was found to be missing SSH host key verification in co… |
| CVE-2026-61863 | 2.1 | 8.3 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder |
| CVE-2026-61866 | 2.1 | 8.3 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in JNG encoder |
| CVE-2026-20296 | 8.3 | 7.8 | Splunk | Splunk Enterprise | CWE-352 | SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in De… |
| CVE-2026-42936 | 8.4 | 7.3 | SBI SECURITIES Co.,Ltd. | HYPER SBI 2 | CWE-427 | The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If ther… |
| CVE-2026-15029 | 8.4 | 6.4 | ASUS | System Control Interface v3 | CWE-822 | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS Syste… |
| CVE-2026-49445 | 8.8 | 6.0 | cilium | cilium | CWE-732 | Cilium: Sensitive information disclosure and cluster disruption via local Env… |
| CVE-2026-15809 | 7.8 | 5.7 | Red Hat | Confidential Compute Attestation | CWE-134 | Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection … |
| CVE-2026-13585 | 8.2 | 5.7 | ASUS | System Control Interface v3 | CWE-226 | Allocation of Resources Without Limits and Throttling and Sensitive Informati… |
| CVE-2026-14961 | 6.2 | 5.6 | Pegatron Corp. | Tdelo64.sys | CWE-20 | CVE-2026-14961 |
| CVE-2026-50144 | 7.1 | 5.2 | Tencent | ncnn | CWE-20 | ncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negativ… |
| CVE-2026-56687 | 7.8 | 4.7 | Dell | ThinOS 10 | CWE-448 | Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature i… |
| CVE-2026-61828 | 8.5 | 4.6 | NixOS | nixpkgs | CWE-276 | nixos/mysql : `services.mysql` is configured with insecure authentication by … |
| CVE-2026-45313 | 7.7 | 4.6 | sandboxie-plus | Sandboxie | CWE-284 | Sandboxie-Plus: Sandboxie APC Injection Sandbox Escape |
| CVE-2026-60087 | 6.9 | 4.3 | MervinPraison | PraisonAI | CWE-863 | PraisonAI before 1.6.78 Tool Approval Cache Bypass |
| CVE-2026-56375 | 4.8 | 4.2 | ImageMagick | ImageMagick | CWE-401 | ImageMagick - Memory Leak in ASHLAR Coder Action Failure |
| CVE-2026-13385 | 9.5 | 3.7 | ASUS | Router | CWE-295 | An Improper Validation of Integrity Check Value and Improper Certificate Vali… |
| CVE-2026-62294 | 5.1 | 3.5 | flameshot-org | flameshot | CWE-362 | Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open … |
| CVE-2026-61867 | 2.1 | 3.5 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder |
| CVE-2026-40952 | 8.5 | 3.3 | Absolute Security | Secure Access | CWE-276 | Privilge misconfiguration in Secure Access installers |
| CVE-2026-15030 | 5.6 | 3.3 | ASUS | System Control Interface v3 | CWE-125 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control I… |
| CVE-2026-58549 | 4.0 | 2.5 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58550 | 4.0 | 2.5 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58553 | 4.0 | 2.5 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58551 | 5.1 | 2.4 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58552 | 5.1 | 2.4 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58558 | 7.8 | 2.4 | Huawei | Harmony OS | CWE-840 | Permission control vulnerability in the file system. Impact: Successful explo… |
| CVE-2026-61859 | 4.8 | 2.4 | ImageMagick | ImageMagick | CWE-59 | ImageMagick before 7.1.2-26 Policy Bypass via script operation |
| CVE-2026-47703 | 6.3 | 2.2 | AdguardTeam | AdGuardHome | CWE-330 | AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle |
| CVE-2026-58555 | 6.6 | 1.7 | Huawei | HarmonyOS | CWE-264 | Permission bypass vulnerability in the card module. Impact: Successful exploi… |
| CVE-2026-58556 | 5.1 | 1.6 | Huawei | Harmony OS | CWE-264 | Permission control vulnerability in the Bluetooth module. Impact: Successful … |
| CVE-2026-8920 | 8.5 | 1.5 | ASUS | Aura Wallpaper Service | CWE-73 | Improper Restriction of Communication Channel to Intended Endpoints and Exter… |
| CVE-2026-58554 | 6.6 | 1.4 | Huawei | HarmonyOS | CWE-200 | Permission control vulnerability in the Settings module. Impact: Successful e… |
| CVE-2026-40633 | 5.5 | 1.4 | Dell | PowerScale OneFS | CWE-532 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 th… |
| CVE-2026-20157 | 9.8 | 1.3 | Cisco | Cisco RoomOS Software | CWE-311 | Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities |
| CVE-2026-49501 | 6.7 | 1.2 | Dell | PowerScale OneFS | CWE-269 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.… |
| CVE-2026-61862 | 2.1 | 1.2 | ImageMagick | ImageMagick | CWE-125 | ImageMagick before 7.1.2-26 Information Disclosure via identify |
| CVE-2026-15779 | 6.1 | 1.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-732 | Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths with… |
| CVE-2026-61864 | 2.1 | 1.0 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in Log Colorspace |
| CVE-2026-61865 | 2.1 | 1.0 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in Hough Lines |
| CVE-2026-61869 | 2.1 | 1.0 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in MIFF Encoder |
| CVE-2026-58557 | 4.8 | 1.0 | Huawei | HarmonyOS | CWE-701 | Design defect vulnerability in Expedition mode. Impact: Successful exploitati… |
| CVE-2026-40953 | 6.7 | 0.8 | Absolute Security | Secure Access | CWE-787 | Heap overflow in Secure Access clients |
| CVE-2026-61872 | 2.0 | 0.8 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak via TIFF Encoder |
| CVE-2026-61464 | 1.0 | 0.6 | ImageMagick | ImageMagick | CWE-122 | ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11 |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-15 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.