AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .3733 98.4 YES
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE May 21 Reserved by CNA Jul 17 Published (CNA: ibm) Aug 4 Added to CISA KEV, due Aug 7
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
288 CVEs published, led by IBM (34).
288 CVEs published July 17, 2026: 38 critical, 99 high, 131 medium, 20 low; 1 in the KEV catalog at press time; 17 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 263 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4607 | 17010 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
759 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 41 | 1521 | 121 | 867 | 532 | 1 | 11 | 2 | 0.1 | 7.5 | .0014 | -55 ▼ |
| microsoft | 646 | 1403 | 96 | 975 | 318 | 14 | 286 | 23 | 1.6 | 7.8 | .0047 | +438 ▲ |
| 94 | 1359 | 150 | 616 | 555 | 38 | 77 | 6 | 0.4 | 7.8 | .0024 | -586 ▼ | |
| red hat | 65 | 287 | 14 | 115 | 140 | 18 | 2 | 0 | 0.0 | 6.5 | .0032 | 0 |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | -14 ▼ |
| canonical | 4 | 24 | 3 | 6 | 10 | 5 | 0 | 0 | 0.0 | 5.5 | .0013 | +4 ▲ |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0039 | +6 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 15 | 37 | 8 | 18 | 11 | 0 | 56 | 11 | 29.7 | 7.5 | .0057 | +6 ▲ |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +20 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | -11 ▼ |
| fortinet | 13 | 22 | 6 | 6 | 10 | 0 | 28 | 5 | 22.7 | 7.3 | .0039 | +11 ▲ |
| f5 | 8 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | +2 ▲ |
| ivanti | 2 | 11 | 4 | 5 | 2 | 0 | 25 | 5 | 45.5 | 8.8 | .3445 | -2 ▼ |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 77 | 232 | 47 | 89 | 84 | 11 | 33 | 1 | 0.4 | 7.5 | .0058 | +3 ▲ |
| mozilla | 6 | 62 | 12 | 18 | 32 | 0 | 9 | 0 | 0.0 | 6.5 | .0026 | -43 ▼ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -4 ▼ |
| github | 5 | 11 | 1 | 2 | 8 | 0 | 0 | 0 | 0.0 | 6.0 | .0042 | +5 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1 | 271 | 133 | 116 | 18 | 4 | 27 | 3 | 1.1 | 8.8 | .0040 | -241 ▼ |
| adobe | 94 | 238 | 26 | 103 | 105 | 4 | 19 | 3 | 1.3 | 7.6 | .0026 | -35 ▼ |
| ibm | 36 | 160 | 52 | 54 | 54 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +25 ▲ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 6 | 0 | 0.0 | 7.5 | .0037 | +5 ▲ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .7758 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | +10 ▲ |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| d-link | 1 | 13 | 0 | 5 | 3 | 5 | 3 | 0 | 0.0 | 6.0 | .0059 | -8 ▼ |
| abb | 1 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -5 ▼ |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| openclaw | 44 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -17 ▼ |
| sourcecodester | 37 | 108 | 0 | 0 | 56 | 52 | 0 | 0 | 0.0 | 5.5 | .0032 | 0 |
| dell | 37 | 93 | 5 | 42 | 43 | 3 | 2 | 1 | 1.1 | 7.0 | .0021 | +11 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | +20 ▲ |
| nvidia | 40 | 79 | 12 | 52 | 15 | 0 | 0 | 0 | 0.0 | 7.8 | .0037 | +34 ▲ |
| imagemagick | 32 | 73 | 1 | 5 | 55 | 12 | 0 | 0 | 0.0 | 5.3 | .0019 | +4 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -71 ▼ |
| itsourcecode | 13 | 66 | 0 | 0 | 19 | 47 | 0 | 0 | 0.0 | 2.1 | .0033 | -9 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 |
| Vendor | CVEs |
|---|---|
| microsoft | 659 |
| 504 | |
| linux | 458 |
| red hat | 128 |
| apache | 124 |
| adobe | 107 |
| ibm | 100 |
| capgo | 81 |
| dell | 49 |
| sourcecodester | 49 |
| Vendor | KEV |
|---|---|
| microsoft | 23 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| fortinet | 5 |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 56 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1703 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1703 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1703 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1703 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1703 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1703 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1703 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1703 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1703 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1703 |
EXPLOIT PUBLISHED — CVE-2025-60357. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16014 (code-projects Hospital Bed Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16073 (AstrBotDevs AstrBot). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16074 (AstrBotDevs AstrBot). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44251 (wazuh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44891 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45309 (ronf asyncssh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45799 (square wire). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50185 (RustCrypto utils). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50289 (sebhildebrandt systeminformation). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53727 (premailer css_parser). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54497 (ViewComponent view_component). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54498 (ViewComponent view_component). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56740 (jline3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56741 (jline3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62238 (openremote). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62241 (MohibShaikh clawvet). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63094 (signoz). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63100 (maybe-finance maybe). Public exploit reference added.
DUE DATE PASSED — CVE-2008-4128 (Cisco IOS). CISA remediation deadline was July 16, 2026; still in catalog.
How to read these box scores · glossary
288 CVEs published. 25 box scores, 263 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .3733 98.4 YES
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE May 21 Reserved by CNA Jul 17 Published (CNA: ibm) Aug 4 Added to CISA KEV, due Aug 7
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H N 9.3 .0655 93.3 —
AFFECTED Product Versions Fixed clawvet unspecified 0.7.5
TIMELINE Jul 13 Reserved by CNA Jul 17 Public exploit reference published Jul 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0218 81.0 —
AFFECTED Product Versions Fixed systeminformation < 5.31.7 – —
TIMELINE Jun 4 Reserved by CNA Jul 17 Public exploit reference published Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0205 79.8 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 24 Reserved by CNA Jul 17 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0154 72.9 —
AFFECTED Product Versions Fixed setup-php >= 2.25.0, < 2.37.1 – —
TIMELINE May 13 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0114 64.1 —
AFFECTED Product Versions Fixed Kirki – Freeform Page Builder, Website Builder & Customizer unspecified —
TIMELINE Jul 10 Reserved by CNA Jul 17 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0107 62.4 —
AFFECTED Product Versions Fixed Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress unspecified —
TIMELINE Jun 25 Reserved by CNA Jul 17 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N C H H H 8.0 .0099 59.7 —
AFFECTED Product Versions Fixed pimcore < 11.5.17 – —
TIMELINE May 8 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0090 56.9 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE May 13 Reserved by CNA Jul 17 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0087 55.9 —
AFFECTED Product Versions Fixed agentic-flow < 2.0.14 – —
TIMELINE Jun 29 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0084 55.1 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE May 20 Reserved by CNA Jul 17 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0081 54.1 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE May 13 Reserved by CNA Jul 17 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0079 53.6 —
AFFECTED Product Versions Fixed dd-trace-py < 4.8.2 – —
TIMELINE Jun 4 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0079 53.6 —
AFFECTED Product Versions Fixed dd-trace-js < 5.100.0 – —
TIMELINE Jun 4 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0079 53.6 —
AFFECTED Product Versions Fixed dd-trace-dotnet < 3.43.0 – —
TIMELINE Jun 4 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0079 53.6 —
AFFECTED Product Versions Fixed dd-trace-go < 2.8.1 – —
TIMELINE Jun 4 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0077 53.0 —
AFFECTED Product Versions Fixed CodeIgniter4 < 4.7.3 – —
TIMELINE May 20 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0075 52.2 —
AFFECTED Product Versions Fixed ps_facetedsearch >= 3.0.0, < 4.0.4 – —
TIMELINE Jun 11 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0075 52.1 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE May 4 Reserved by CNA Jul 17 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 5.5 .0074 51.9 —
AFFECTED Product Versions Fixed CIPster 632336d414ef708a542377c1aa8d6fdb7c70a760 – —
TIMELINE Jul 17 Reserved by CNA Jul 17 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0072 51.2 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE May 20 Reserved by CNA Jul 17 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 7.7 .0072 51.0 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.5.18
TIMELINE Jul 13 Reserved by CNA Jul 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0069 50.2 —
AFFECTED Product Versions Fixed Switchvox SMB Edition 8.3 (104997) – —
TIMELINE May 26 Reserved by CNA Jul 17 Published (CNA: SRA)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0069 50.0 —
AFFECTED Product Versions Fixed jsonata >= 2.0.0, < 2.2.0 – —
TIMELINE Jun 8 Reserved by CNA Jul 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L L N 6.1 .0069 49.9 —
AFFECTED Product Versions Fixed WP Hotel Booking unspecified —
TIMELINE Jul 8 Reserved by CNA Jul 17 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-13765 | 7.5 | 49.8 | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | CWE-862 | LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Info… |
| CVE-2026-49485 | 7.5 | 49.8 | hapifhir | org.hl7.fhir.core | CWE-400 | HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HT… |
| CVE-2026-13448 | 9.8 | 49.0 | IBM | Langflow OSS | CWE-184 | Langflow is affected by remote code execution, denial of service, path traver… |
| CVE-2026-14499 | 8.8 | 49.0 | IBM | Langflow OSS | CWE-78 | Langflow is affected by remote code execution, denial of service, path traver… |
| CVE-2026-52199 | 9.1 | 49.0 | n/a | n/a | CWE-77 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attac… |
| CVE-2026-15160 | 4.3 | 49.0 | SaturdayDrive | Ninja Forms - Excel Export | CWE-22 | Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated … |
| CVE-2026-56171 | 7.5 | 48.8 | Microsoft | Remote Desktop Web Client | CWE-359 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-12692 | 9.8 | 48.0 | Vimesoft Inc. | Enterprise Video Platform | CWE-620 | Improper Authentication in Vimesoft's Enterprise Video Platform |
| CVE-2026-45260 | 8.1 | 47.7 | pimcore | pimcore | CWE-862 | Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling |
| CVE-2026-15007 | 5.7 | 47.7 | GitHub | Enterprise Server | CWE-770 | Denial of service vulnerability in GitHub Enterprise Server allowed service d… |
| CVE-2026-59252 | 8.2 | 47.4 | ZenHive | mpp | CWE-1284 | Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain |
| CVE-2025-51677 | 9.1 | 47.3 | n/a | n/a | CWE-116 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch … |
| CVE-2025-51678 | 7.5 | 46.5 | n/a | n/a | CWE-119 | An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the P… |
| CVE-2026-56741 | 7.5 | 45.8 | jline | jline3 | CWE-400 | JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry |
| CVE-2026-56740 | 7.5 | 45.7 | jline | jline3 | CWE-400 | JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVI… |
| CVE-2026-12283 | 6.1 | 45.6 | AWS | aws-athena-query-federation | CWE-89 | SQL injection in Amazon Athena Synapse connector |
| CVE-2026-48049 | 5.3 | 45.6 | hapijs | inert | CWE-22 | @hapi/inert: Static-file confinement bypass via sibling-prefix path |
| CVE-2026-16015 | 2.1 | 45.1 | poco-ai | poco-claw | CWE-287 | poco-ai poco-claw executor_manager API tasks.py create_task missing authentic… |
| CVE-2026-63093 | 8.7 | 44.8 | Anysphere, Inc. | Cursor | CWE-426 | Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace |
| CVE-2026-8505 | 9.8 | 44.7 | IBM | Langflow OSS | CWE-306 | Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution |
| CVE-2026-15343 | 8.6 | 44.6 | GitHub | Enterprise Server | CWE-22 | Path traversal vulnerability in GitHub Enterprise Server allowed writing file… |
| CVE-2026-15091 | 9.3 | 44.5 | IBM | Engineering AI Hub | CWE-79 | Multiple Vulnerabilities in IBM Engineering AI hub. |
| CVE-2026-7872 | 8.1 | 44.4 | IBM | Langflow OSS | CWE-22 | Path Traversal Vulnerability in File Component Leading to Arbitrary File Read… |
| CVE-2026-62207 | 7.7 | 44.4 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools |
| CVE-2026-36669 | 9.8 | 44.3 | n/a | n/a | CWE-434 | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.p… |
| CVE-2026-8859 | 9.9 | 44.0 | IBM | Langflow OSS | CWE-22 | Path Traversal in APIRequest Component via Content-Disposition Header |
| CVE-2026-7667 | 8.8 | 44.0 | IBM | Langflow OSS | CWE-22 | Path Traversal Vulnerability in API Request Component Content-Disposition Hea… |
| CVE-2026-49209 | 5.3 | 44.1 | symfony | ux | CWE-770 | Symfony UX: Denial of service in symfony/ux-live-component via unbounded batc… |
| CVE-2026-9585 | 8.6 | 43.8 | Sangoma | Switchvox SMB Edition | CWE-79 | Unauthenticated Reflected Cross-Site Scripting (XSS) in Switchvox SMB Web Portal |
| CVE-2026-50197 | 7.8 | 43.5 | zalando | skipper | CWE-444 | Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-E… |
| CVE-2026-9171 | 7.5 | 43.5 | IBM | PowerVM Novalink | CWE-400 | Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink. |
| CVE-2026-45799 | 7.5 | 43.3 | square | wire | CWE-129 | Wire: skipGroup() missing negative-length check allows 10-byte payload to cra… |
| CVE-2026-60024 | 9.8 | 43.3 | joomdonation.com | Events Booking extension for Joomla | CWE-1188 | Joomla Extension - joomdonation.com - Insecure default configuration Events B… |
| CVE-2026-62202 | 7.7 | 43.1 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron |
| CVE-2026-49211 | 6.9 | 42.5 | symfony | ux | CWE-200 | Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearch… |
| CVE-2026-8635 | 9.9 | 42.4 | IBM | Langflow OSS | CWE-94 | Arbitrary Code Execution in Python Interpreter Component |
| CVE-2026-8056 | 8.8 | 42.4 | IBM | Langflow OSS | CWE-94 | Parameter Injection Vulnerability in API Graph Execution Engine |
| CVE-2026-62203 | 7.7 | 42.1 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.6.6 Environment Variable Injection via rustup |
| CVE-2026-59694 | 8.3 | 42.0 | ZenHive | mpp | CWE-1284 | Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment |
| CVE-2026-59695 | 8.3 | 42.0 | ZenHive | mpp | CWE-1284 | Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request walle… |
| CVE-2026-63101 | 8.7 | 41.8 | fossasia | open-event-server | CWE-306 | Open Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export … |
| CVE-2026-62220 | 6.3 | 41.7 | OpenClaw | OpenClaw | CWE-307 | OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass |
| CVE-2026-51080 | 9.8 | 41.6 | n/a | n/a | CWE-611 | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to c… |
| CVE-2026-12691 | 7.5 | 41.5 | Vimesoft Inc. | Enterprise Video Platform | CWE-306 | Authentication Bypass in Vimesoft's Enterprise Video Platform |
| CVE-2026-15322 | 7.5 | 41.5 | IBM | Engineering AI Hub | CWE-598 | Multiple Vulnerabilities in IBM Engineering AI hub. |
| CVE-2026-52203 | 7.5 | 41.5 | n/a | n/a | CWE-200 | An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive informa… |
| CVE-2026-50162 | 6.9 | 40.9 | oras-project | oras-go | CWE-73 | oras-go: file store write outside workingDir via symlink traversal |
| CVE-2026-14503 | 6.5 | 40.9 | ploudapp | pCloud WP Backup | CWE-200 | pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX … |
| CVE-2026-9202 | 9.8 | 40.7 | IBM | Langflow OSS | CWE-306 | Unauthenticated User Registration Could Lead to Remote Code Execution |
| CVE-2026-9810 | 9.8 | 40.4 | Unknown | AI Copilot | CWE-269 | AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege … |
| CVE-2026-16016 | 5.5 | 40.2 | poco-ai | poco-claw | CWE-918 | poco-ai poco-claw task.py run_task server-side request forgery |
| CVE-2026-48015 | 4.9 | 39.5 | shopware | shopware | CWE-79 | Shopware: Stored XSS via SVG file upload — no SVG sanitization |
| CVE-2026-62230 | 8.7 | 39.2 | getgrav | grav | CWE-178 | Grav < 2.0.4 File Access Bypass via Case Variation |
| CVE-2026-15349 | 4.3 | 38.7 | wedevs | ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce | CWE-862 | ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Mi… |
| CVE-2026-44974 | 7.7 | 38.7 | hapijs | content | CWE-436 | Parameter smuggling in @hapi/content header parser allows upload-filter bypas… |
| CVE-2026-48008 | 6.5 | 38.7 | shopware | shopware | CWE-862 | Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass |
| CVE-2026-48010 | 6.5 | 38.7 | shopware | shopware | CWE-269 | Shopware: Privilege escalation: non-admin user with user:create ACL can creat… |
| CVE-2026-62764 | 5.7 | 38.6 | Apache Software Foundation | Apache Accumulo | CWE-274 | Apache Accumulo: A user can trigger a graceful shutdown of services without t… |
| CVE-2026-13473 | 9.8 | 38.5 | IBM | Storage Protect Client | CWE-122 | IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow |
| CVE-2026-8297 | 9.8 | 38.4 | Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. | GisLab Laboratory Management System | CWE-89 | SQLi in GIS Informatics' GisLab Laboratory Management System |
| CVE-2026-52348 | 9.8 | 38.4 | n/a | n/a | CWE-89 | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method… |
| CVE-2026-12693 | 9.4 | 37.8 | Vimesoft Inc. | Enterprise Video Platform | CWE-639 | IDOR in Vimesoft's Enterprise Video Platform |
| CVE-2026-48009 | 6.8 | 37.7 | shopware | shopware | CWE-200 | Shopware: Admin Account Takeover via User Recovery Hash Exposure |
| CVE-2026-16008 | 2.1 | 37.7 | sagold | json-schema-library | CWE-94 | sagold json-schema-library propertyDependencies.ts parsePropertyDependencies … |
| CVE-2026-62232 | 9.1 | 37.4 | getgrav | grav | CWE-862 | Grav < 2.0.4 2FA Bypass via Secret Regeneration |
| CVE-2026-62218 | 8.7 | 37.3 | OpenClaw | OpenClaw | CWE-862 | OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve |
| CVE-2026-62223 | 7.7 | 37.3 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.5.18 Authorization Bypass via Device-pair |
| CVE-2026-62228 | 7.7 | 37.3 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals |
| CVE-2026-22104 | 7.1 | 37.2 | hashtopolis | server | CWE-639 | Improper access control in Hashtopolis server chunk activity component |
| CVE-2026-62210 | 6.0 | 37.2 | OpenClaw | OpenClaw | CWE-770 | OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs |
| CVE-2026-15783 | 5.3 | 37.1 | GitHub | Enterprise Server | CWE-862 | Missing Authorization vulnerability was identified in GitHub Enterprise Serve… |
| CVE-2026-55518 | 9.6 | 37.1 | avo-hq | avo | CWE-639 | Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthor… |
| CVE-2026-62217 | 7.7 | 37.0 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals |
| CVE-2026-49835 | 7.5 | 37.0 | sigstore | timestamp-authority | CWE-770 | Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality |
| CVE-2026-54464 | 6.3 | 36.8 | faye | websocket-driver-ruby | CWE-770 | websocket-driver: Resource limit bypass via message compression |
| CVE-2026-44251 | 6.5 | 36.8 | wazuh | wazuh | CWE-122 | Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and po… |
| CVE-2026-62233 | 8.7 | 36.6 | getgrav | grav | CWE-639 | grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey |
| CVE-2026-45309 | 8.2 | 36.4 | ronf | asyncssh | CWE-22 | AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected auth… |
| CVE-2026-8396 | 7.5 | 36.5 | Netcad Software Inc. | NetGIS | CWE-611 | XXE in Netcad's NetGIS |
| CVE-2026-62214 | 6.0 | 36.5 | openclaw | msteams | CWE-522 | OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation |
| CVE-2026-12694 | 9.1 | 36.2 | Vimesoft Inc. | Enterprise Video Platform | CWE-862 | Missing Authorization in Vimesoft's Enterprise Video Platform |
| CVE-2026-58148 | 8.7 | 36.2 | chronoengine.com | ChronoForms extension for Joomla | CWE-79 | Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for… |
| CVE-2026-62237 | 6.0 | 36.1 | getgrav | grav | CWE-1333 | Grav < 2.0.4 ReDoS via regex_replace in Sandbox |
| CVE-2026-62386 | 8.2 | 35.8 | getgrav | grav | CWE-598 | Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter |
| CVE-2026-16014 | 5.5 | 35.7 | code-projects | Hospital Bed Management System | CWE-74 | code-projects Hospital Bed Management System Login Form sql injection |
| CVE-2026-50163 | 7.1 | 35.5 | oras-project | oras-go | CWE-22 | oras-go: Hardlink entry with relative Linkname escapes extract dir via proces… |
| CVE-2026-15395 | 7.2 | 35.5 | wpchill | Kali Forms — Contact Form & Drag-and-Drop Builder | CWE-79 | Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digit… |
| CVE-2026-14871 | 7.1 | 35.4 | osTicket | osTicket | CWE-863 | osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-d… |
| CVE-2026-45704 | 7.1 | 35.4 | pimcore | pimcore | CWE-862 | Pimcore: CustomReports Share Bypass |
| CVE-2026-54171 | 6.5 | 35.4 | excon | excon | CWE-201 | Excon: redact additional sensitive/risky headers when following redirects |
| CVE-2026-44891 | 7.5 | 35.1 | netty | netty | CWE-400 | Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder |
| CVE-2026-8075 | 6.5 | 34.8 | Mattermost | Mattermost | CWE-754 | Posting a malicious markdown image crashes the Mattermost Desktop App |
| CVE-2026-9602 | 6.5 | 34.8 | Mattermost | Mattermost | CWE-400 | Mattermost Desktop App crashes when malformed arguments are provided to some … |
| CVE-2026-44979 | 6.3 | 34.7 | hapijs | wreck | CWE-200 | @hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-host… |
| CVE-2025-60357 | 8.1 | 34.6 | n/a | n/a | CWE-943 | AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injec… |
| CVE-2026-48504 | 5.3 | 34.5 | open-telemetry | opentelemetry-rust | CWE-770 | OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation |
| CVE-2026-7189 | 7.5 | 34.3 | Proliz Software Ltd. Co. | Proliz's OBS | CWE-201 | Sensitive Data Exposure in Proliz's OBS |
| CVE-2026-7488 | 7.5 | 34.3 | IKAS Technology Inc. | E-Commerce | CWE-201 | Sensitive Data Exposure in IKAS Technologies' E-Commerce |
| CVE-2026-48016 | 4.3 | 34.2 | shopware | shopware | CWE-639 | Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/hand… |
| CVE-2026-49208 | 6.9 | 34.0 | symfony | ux | CWE-20 | Symfony UX: Format-less date LiveProps parsed with the permissive DateTime co… |
| CVE-2026-51833 | 7.5 | 33.7 | n/a | n/a | CWE-918 | Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privil… |
| CVE-2026-9588 | 7.0 | 33.4 | Sangoma | Switchvox SMB Edition | CWE-79 | Authenticated Stored Cross-Site Scripting (XSS) in Switchvox SMB Web Portal |
| CVE-2026-63307 | 7.1 | 33.0 | OtterMind | Chat2DB | CWE-639 | Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/data… |
| CVE-2024-23565 | 5.3 | 33.1 | HCLSoftware | Aftermarket EPC | CWE-799 | HCL Aftermarket EPC is vulnerable to email flooding as the application does n… |
| CVE-2024-23568 | 5.3 | 33.1 | HCLSoftware | Aftermarket EPC | CWE-200 | HCL Aftermarket EPC is vulnerable to attacks since the server software versio… |
| CVE-2026-8861 | 5.3 | 33.0 | IBM | Verify Identity Access | CWE-209 | Security vulnerabilities have been found in IBM Verify Identity Access and IB… |
| CVE-2026-62234 | 8.4 | 32.4 | getgrav | grav | CWE-918 | Grav < 2.0.4 SSRF via Unrestricted cURL Protocols |
| CVE-2026-44739 | 8.7 | 32.0 | pimcore | pimcore | CWE-89 | Pimcore: SQL Injection in Custom Reports Column Configuration |
| CVE-2026-57980 | 5.4 | 31.9 | Microsoft | Microsoft Edge (Chromium-based) | CWE-288 | Microsoft Edge (Chromium-based) Tampering Vulnerability |
| CVE-2026-62227 | 4.9 | 32.0 | OpenClaw | OpenClaw | CWE-918 | OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot |
| CVE-2026-8616 | 5.3 | 31.9 | devozon | Fense Proxy & VPN Blocker | CWE-862 | Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated… |
| CVE-2026-47183 | 6.5 | 31.7 | python-zeroconf | python-zeroconf | CWE-400 | Zeroconf: Unbounded exception-dedup state retains packet buffers via tracebac… |
| CVE-2026-47184 | 6.5 | 31.7 | python-zeroconf | python-zeroconf | CWE-770 | Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via m… |
| CVE-2026-48014 | 6.5 | 31.7 | shopware | shopware | CWE-862 | Shopware: Admin API ACL Bypass in Order State Transition Endpoints |
| CVE-2026-11324 | 6.1 | 31.7 | evertec | WooCommerce Placetopay Gateway Belice | CWE-79 | WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via … |
| CVE-2026-54335 | 3.7 | 31.7 | feathersjs | feathers | CWE-1321 | Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parse… |
| CVE-2026-62231 | 8.6 | 31.4 | getgrav | grav | CWE-863 | Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator |
| CVE-2026-14979 | 7.5 | 31.4 | IBM | Engineering Lifecycle Management | CWE-776 | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML E… |
| CVE-2026-51082 | 7.2 | 31.3 | n/a | n/a | CWE-362 | A race condition between the vncproxy and vncwebsocket API calls in Proxmox V… |
| CVE-2026-13410 | 8.2 | 31.1 | GARU | Dancer::Plugin::Auth::Google | CWE-295 | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verificat… |
| CVE-2026-11961 | 8.1 | 31.1 | Unknown | User Registration & Membership | CWE-269 | User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation… |
| CVE-2026-13446 | 9.8 | 30.9 | IBM | Langflow OSS | CWE-798 | Langflow is affected by remote code execution, denial of service, path traver… |
| CVE-2026-9587 | 7.1 | 30.5 | Sangoma | Switchvox SMB Edition | CWE-73 | Authenticated Local File Inclusion (LFI) in Switchvox SMB Web Portal |
| CVE-2026-62209 | 7.6 | 29.8 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode disp… |
| CVE-2026-47180 | 6.5 | 29.7 | python-zeroconf | python-zeroconf | CWE-674 | Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-l… |
| CVE-2026-48045 | 6.5 | 29.7 | python-zeroconf | python-zeroconf | CWE-770 | Zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via … |
| CVE-2026-16017 | 2.1 | 29.3 | mosaxiv | clawlet | CWE-862 | mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization |
| CVE-2026-53727 | 8.9 | 29.2 | premailer | css_parser | CWE-918 | css_parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_… |
| CVE-2026-15093 | 4.3 | 29.2 | IBM | Engineering AI Hub | CWE-601 | Multiple Vulnerabilities in IBM Engineering AI hub. |
| CVE-2026-50151 | 7.5 | 29.1 | oras-project | oras-go | CWE-918 | oras-go: credential forwarding via unvalidated Location header in blob upload |
| CVE-2026-11763 | 6.5 | 28.8 | Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. | GisLab Laboratory Management System | CWE-639 | IDOR in GIS Informatics' GisLab Laboratory Management System |
| CVE-2026-62201 | 4.9 | 28.7 | OpenClaw | OpenClaw | CWE-918 | OpenClaw < 2026.6.6 Network Policy Bypass via exec-server |
| CVE-2026-11575 | 7.5 | 28.4 | Unknown | PhonePe Payment Solutions | CWE-862 | PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged… |
| CVE-2026-62208 | 6.0 | 28.4 | OpenClaw | OpenClaw | CWE-522 | OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE |
| CVE-2026-62213 | 6.0 | 28.4 | openclaw | msteams | CWE-522 | OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests |
| CVE-2026-62205 | 6.0 | 28.2 | OpenClaw | OpenClaw | CWE-862 | OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions |
| CVE-2026-62206 | 6.0 | 28.2 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions |
| CVE-2026-63099 | 7.1 | 28.0 | TheHive-Project | TheHive | CWE-639 | TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endp… |
| CVE-2026-63100 | 7.1 | 28.0 | maybe-finance | maybe | CWE-862 | Maybe 0.6.0 Missing Authorization via HostingsController show/update |
| CVE-2026-49977 | 4.3 | 28.0 | AmauriC | tarteaucitron.js | CWE-285 | tarteaucitron.js: data-cookie attribute can be used to delete arbitrary cookies |
| CVE-2026-14741 | 7.5 | 27.9 | OALDERS | HTTP::Date | CWE-1333 | HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial … |
| CVE-2026-15415 | 6.8 | 27.9 | AWS | aws-healthomics-mcp-server | CWE-23 | Path traversal and arbitrary file write in the workflow linters of aws-health… |
| CVE-2026-48819 | 4.8 | 27.8 | hey-api | openapi-ts | CWE-1321 | Hey API: `buildClientParams` template: prototype chain substitution via unkno… |
| CVE-2026-14956 | 9.8 | 27.7 | Bricksforge | Bricksforge | CWE-269 | Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms f… |
| CVE-2026-12715 | 8.5 | 27.7 | Google Cloud | Firebase Studio | CWE-862 | Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft |
| CVE-2026-13445 | 8.1 | 27.6 | IBM | Langflow OSS | CWE-639 | Langflow is affected by remote code execution, denial of service, path traver… |
| CVE-2026-15759 | 6.4 | 27.5 | themeatelier | ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form | CWE-79 | ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting … |
| CVE-2026-16074 | 2.1 | 27.3 | AstrBotDevs | AstrBot | CWE-918 | AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side re… |
| CVE-2026-13402 | 5.3 | 27.0 | Unknown | Royal Addons for Elementor | CWE-200 | Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Templat… |
| CVE-2026-58149 | 5.3 | 27.0 | joomdonation.com | Events Booking extension for Joomla | CWE-200 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 |
| CVE-2026-16072 | 4.9 | 27.1 | Red Hat | Red Hat Build of Keycloak | CWE-284 | Keycloak-services: keycloak-services: organization invitation link exposure a… |
| CVE-2026-54463 | 6.9 | 26.9 | faye | websocket-driver-ruby | CWE-770 | websocket-driver: Memory exhaustion via abuse of protocol length headers |
| CVE-2026-54465 | 6.3 | 26.9 | faye | websocket-driver-ruby | CWE-770 | websocket-driver: Memory exhaustion in HTTP header parser |
| CVE-2026-62387 | 7.1 | 26.6 | getgrav | grav | CWE-942 | Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin |
| CVE-2026-16103 | 4.3 | 26.6 | Red Hat | Red Hat Build of Keycloak | CWE-841 | Keycloak-services: keycloak-services: incomplete fix for ciba brute-force loc… |
| CVE-2026-7754 | 6.5 | 26.5 | IBM | Langflow OSS | CWE-918 | SSRF Protection Configuration Vulnerability |
| CVE-2026-51083 | 6.5 | 26.5 | n/a | n/a | CWE-284 | Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server… |
| CVE-2026-15982 | 9.8 | 26.4 | CodeRevolution | Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit | CWE-269 | Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Tool… |
| CVE-2026-54243 | 6.1 | 26.2 | statamic | cms | CWE-1236 | Statamic: CSV formula injection in form submission exports |
| CVE-2026-49210 | 2.3 | 26.2 | symfony | ux | CWE-79 | Symfony UX: XSS in symfony/ux-live-component via attacker-controlled child co… |
| CVE-2026-48373 | 7.8 | 26.2 | Adobe | Acrobat Reader | CWE-122 | Acrobat Reader | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-15943 | 5.5 | 26.1 | Red Hat | Red Hat Build of Keycloak | CWE-1288 | Keycloak-services: keycloak-services: oidc idp update reuses masked client se… |
| CVE-2026-63096 | 6.9 | 26.0 | matrix-org | dendrite | CWE-918 | Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint |
| CVE-2026-62226 | 5.1 | 25.8 | OpenClaw | OpenClaw | CWE-918 | OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route |
| CVE-2026-62238 | 7.2 | 25.7 | openremote | openremote | CWE-89 | OpenRemote < 1.26.0 SQL Injection via Crosstab Export |
| CVE-2026-16009 | 2.1 | 25.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System prescriptionorderdetail.php sql injec… |
| CVE-2026-63309 | 5.3 | 25.4 | surrealdb | surrealdb | CWE-863 | SurrealDB < 3.1.5 Information Disclosure via ORDER BY |
| CVE-2026-16073 | 2.0 | 25.4 | AstrBotDevs | AstrBot | CWE-79 | AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross si… |
| CVE-2024-23574 | 5.3 | 25.3 | HCLSoftware | Aftermarket EPC | CWE-204 | HCL Aftermarket EPC is vulnerable to attack since It was found that a malicio… |
| CVE-2024-23575 | 5.3 | 25.3 | HCLSoftware | Aftermarket EPC | CWE-209 | HCL Aftermarket EPC is vulnerable to attack since the application returns det… |
| CVE-2024-42214 | 5.3 | 25.3 | HCLSoftware | Aftermarket EPC | CWE-692 | HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enab… |
| CVE-2026-16106 | 4.9 | 25.3 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: incorrect authorization in admin role-c… |
| CVE-2026-9537 | 5.3 | 24.5 | JBERGER | Mojo::JWT | CWE-208 | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-con… |
| CVE-2026-2594 | 6.4 | 24.3 | inc2734 | Smart Custom Fields | CWE-79 | Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scri… |
| CVE-2026-58317 | 5.1 | 24.3 | TeraTerm Project | TTSSH2 | CWE-196 | Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 … |
| CVE-2026-60060 | 5.1 | 24.3 | TeraTerm Project | TTSSH2 | CWE-130 | Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability e… |
| CVE-2026-63098 | 6.9 | 23.9 | TheHive-Project | TheHive | CWE-306 | TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint |
| CVE-2026-45703 | 6.4 | 23.9 | pimcore | pimcore | CWE-862 | Pimcore: WordExport Authorization Bypass for Unauthorized Document Export |
| CVE-2026-14501 | 9.8 | 23.7 | IBM | Db2 Genius Hub | CWE-676 | Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub |
| CVE-2026-54496 | 9.3 | 23.7 | ZcashFoundation | zebra | CWE-345 | Missing copy constraint in halo2_gadgets variable-base scalar multiplication … |
| CVE-2026-54498 | 8.7 | 23.4 | ViewComponent | view_component | CWE-79 | view_component: around_render HTML-Safety Bypass |
| CVE-2026-49216 | 5.1 | 23.3 | symfony | ux | CWE-79 | Symfony UX: XSS in symfony/ux-autocomplete via unescaped AJAX response data |
| CVE-2024-23567 | 4.3 | 22.7 | HCLSoftware | Aftermarket EPC | CWE-804 | HCL Aftermarket EPC is affected by Sensitive Information in GET method & in U… |
| CVE-2026-13082 | 5.3 | 22.6 | BURAK | GD::SecurityImage | CWE-338 | GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets |
| CVE-2026-16093 | 5.4 | 22.5 | Red Hat | Red Hat Build of Keycloak | CWE-807 | Keycloak-services: keycloak-services: required signed-jwt assertion policy ca… |
| CVE-2026-11966 | 5.3 | 22.4 | Unknown | User Registration & Membership | CWE-639 | User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletio… |
| CVE-2026-54244 | 3.5 | 22.3 | statamic | cms | CWE-863 | Statamic: Incorrect authorization lets view-only users submit Live Preview co… |
| CVE-2026-15069 | 5.4 | 22.2 | IBM | Engineering AI Hub | CWE-78 | Multiple Vulnerabilities in IBM Engineering AI hub. |
| CVE-2026-62219 | 6.0 | 22.1 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs |
| CVE-2026-4938 | 6.5 | 21.9 | IBM | Verify Identity Access | CWE-863 | Incorrect Authorization in IBM Verify Identity Access and IBM Security Verify… |
| CVE-2024-23569 | 4.3 | 21.7 | HCLSoftware | Aftermarket EPC | CWE-692 | HCL Aftermarket EPC is vulnerable to attack since the server is not configure… |
| CVE-2024-23571 | 4.3 | 21.7 | HCLSoftware | Aftermarket EPC | CWE-525 | HCL Aftermarket EPC is vulnerable to attack since the application does not ha… |
| CVE-2024-23577 | 4.3 | 21.7 | HCLSoftware | Aftermarket EPC | CWE-20 | HCL Aftermarket EPC is vulnerable since the application does not have a valid… |
| CVE-2026-63095 | 7.1 | 21.6 | matrix-org | dendrite | CWE-639 | Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint |
| CVE-2024-23564 | 9.1 | 21.4 | HCL Software | Aftermarket EPC | CWE-326 | HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a… |
| CVE-2026-62216 | 2.3 | 21.2 | OpenClaw | OpenClaw | CWE-918 | OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload |
| CVE-2026-12393 | 5.4 | 20.7 | Unknown | WPS Bookings for WooCommerce | CWE-639 | WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order C… |
| CVE-2026-62235 | 2.3 | 20.6 | getgrav | grav | CWE-636 | Grav Flex-Objects < 1.4.3 Authorization Bypass via API |
| CVE-2026-54163 | 4.7 | 20.5 | github | secure_headers | CWE-79 | secure_headers: CSP directive injection via sandbox, plugin_types, and report… |
| CVE-2026-15159 | 4.3 | 20.0 | SaturdayDrive | Ninja Forms - Excel Export | CWE-639 | Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Aut… |
| CVE-2024-23570 | 4.3 | 19.8 | HCLSoftware | Aftermarket EPC | CWE-200 | HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scr… |
| CVE-2026-10525 | 6.1 | 19.4 | Unknown | NEX-Forms | CWE-79 | NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission |
| CVE-2026-63308 | 5.3 | 19.3 | helm | helm | CWE-129 | Helm Files.Lines Denial of Service via Empty Chart Files |
| CVE-2026-63097 | 5.3 | 18.3 | matrix-org | dendrite | CWE-863 | Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure |
| CVE-2024-23566 | 6.5 | 18.1 | HCLSoftware | Aftermarket EPC | CWE-804 | HCL Aftermarket EPC is vulnerable to brute force attacks since application do… |
| CVE-2026-9656 | 4.3 | 17.8 | hubspotdev | HubSpot All-In-One Marketing – Forms, Popups, Live Chat | CWE-200 | HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensit… |
| CVE-2026-54490 | 6.3 | 17.7 | faye | websocket-driver-node | CWE-770 | websocket-driver: Resource limit bypass via message compression |
| CVE-2026-63094 | 7.6 | 17.6 | SigNoz | signoz | CWE-345 | SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft |
| CVE-2026-15161 | 6.4 | 17.4 | SaturdayDrive | Ninja Forms - Excel Export | CWE-79 | Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cros… |
| CVE-2026-53712 | 8.2 | 17.3 | ongres | scram | CWE-636 | SCRAM: Silent channel-binding authentication downgrade via unsupported certif… |
| CVE-2026-62224 | 2.3 | 17.3 | openclaw | msteams | CWE-290 | OpenClaw MS Teams < 2026.5.12 Authorization Bypass |
| CVE-2026-48978 | 2.1 | 17.4 | oras-project | oras-go | CWE-319 | oras-go: Malicious registry can hijack Bearer token realm to exfiltrate crede… |
| CVE-2026-7364 | 6.1 | 17.2 | IBM | Verify Identity Access | CWE-601 | Security vulnerabilities have been found in IBM Verify Identity Access and IB… |
| CVE-2026-51081 | 6.1 | 16.4 | n/a | n/a | CWE-79 | A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PV… |
| CVE-2026-62215 | 5.1 | 16.1 | OpenClaw | OpenClaw | CWE-345 | OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas |
| CVE-2026-54497 | 6.8 | 15.9 | ViewComponent | view_component | CWE-362 | view_component: Reused Component Instances Retain Stale Render Context |
| CVE-2026-62225 | 2.3 | 16.0 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch |
| CVE-2026-48487 | 5.3 | 15.8 | python-zeroconf | python-zeroconf | CWE-130 | Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cac… |
| CVE-2026-4942 | 7.5 | 15.7 | IBM | i | CWE-757 | IBM i is Affected by Algorithm Downgrade in Transport Layer Security [] |
| CVE-2024-23573 | 3.7 | 15.4 | HCLSoftware | Aftermarket EPC | CWE-425 | HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerab… |
| CVE-2026-49212 | 6.9 | 15.0 | symfony | ux | CWE-345 | Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding |
| CVE-2026-62221 | 2.3 | 15.1 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom |
| CVE-2026-9592 | 7.5 | 15.0 | SEPPmail | SEPPmail Secure Email Gateway & SEPPmail Cloud | CWE-598 | Sensitive Information Disclosure in HTTP header |
| CVE-2026-54242 | 4.9 | 13.1 | statamic | cms | CWE-367 | Statamic: Server-Side Request Forgery via Glide (DNS rebinding) |
| CVE-2026-62212 | 5.1 | 13.0 | OpenClaw | OpenClaw | CWE-367 | OpenClaw < 2026.5.28 Authentication Bypass via safeFetch |
| CVE-2026-49284 | 7.1 | 12.6 | simplesamlphp | simplesamlphp | CWE-345 | SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Res… |
| CVE-2026-54466 | 9.2 | 12.5 | faye | websocket-driver-node | CWE-130 | websocket-driver: Message corruption via abuse of protocol length headers |
| CVE-2026-16104 | 6.5 | 11.2 | Red Hat | Red Hat Build of Keycloak | CWE-522 | Keycloak-services: keycloak-services: authenticator config endpoint exposes r… |
| CVE-2026-21760 | 4.6 | 10.7 | HCLSoftware | DevOps Loop | CWE-425 | Unauthorized Access to Admin Functionality via Forced Browsing |
| CVE-2026-60025 | 8.8 | 9.8 | joomdonation.com | Events Booking extension for Joomla | CWE-352 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 |
| CVE-2026-57860 | 8.4 | 9.3 | tailcallhq | forgecode | CWE-829 | ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Reposi… |
| CVE-2024-23578 | 4.2 | 9.3 | HCLSoftware | Aftermarket EPC | CWE-942 | HCL Aftermarket EPC is vulnerable to attack as the application implements an … |
| CVE-2026-49852 | 8.7 | 9.1 | authlib | joserfc | CWE-287 | joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language … |
| CVE-2026-16108 | 6.5 | 9.1 | Red Hat | Red Hat Build of Keycloak | CWE-200 | Keycloak-services: keycloak-services: realm default-group reads disclose hidd… |
| CVE-2026-55254 | 6.5 | 8.8 | ncalc | ncalc | CWE-190 | NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation |
| CVE-2026-45785 | 6.2 | 8.0 | openmcdf | openmcdf | CWE-835 | OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on … |
| CVE-2026-49215 | 2.1 | 7.2 | symfony | ux | CWE-352 | Symfony UX: CSRF Protection Bypass in symfony/ux-live-component — Accept Head… |
| CVE-2026-62222 | 7.1 | 7.1 | OpenClaw | OpenClaw | CWE-829 | OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode |
| CVE-2026-48022 | 6.5 | 7.1 | hapijs | wreck | CWE-319 | @hapi/wreck: Sensitive credential headers leak across cross-port and cross-sc… |
| CVE-2026-21762 | 5.3 | 6.6 | HCLSoftware | DevOps Loop | CWE-644 | Missing HTTP Security Headers in DevOps Loop |
| CVE-2026-15380 | 5.1 | 6.2 | Broadcom | Symantec Management Suite | CWE-269 | Local privilege escalation in Symantec ITMS |
| CVE-2026-9762 | 7.8 | 5.9 | IBM | Db2 | CWE-94 | IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execut… |
| CVE-2026-52584 | 7.1 | 5.7 | n/a | n/a | CWE-121 | Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local at… |
| CVE-2026-50185 | 2.0 | 5.0 | RustCrypto | utils | CWE-758 | RustCrypto Cmov/CmovEq on aarch64 can produce wrong results if high-bits of r… |
| CVE-2026-12705 | 5.9 | 4.6 | ABB | KNX Update Tool (ABB) | CWE-353 | Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool |
| CVE-2026-41993 | 6.7 | 4.4 | TXOne Networks | SafePortAgent | CWE-284 | Improper Access Control vulnerability in the Removable Media Validation funct… |
| CVE-2026-62211 | 4.1 | 4.4 | OpenClaw | OpenClaw | CWE-532 | OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export |
| CVE-2026-7771 | 5.5 | 4.2 | IBM | Db2 | CWE-835 | IBM® Db2® is vulnerable to a trap when compiling specially crafted statements… |
| CVE-2026-21761 | 5.4 | 4.1 | HCLSoftware | DevOps Loop | CWE-942 | CORS Misconfiguration in DevOps Loop |
| CVE-2026-15379 | 5.1 | 4.1 | Broadcom | Symantec IT Management Suite | CWE-269 | Arbitrary File Read as SYSTEM in Symantec ITMS |
| CVE-2026-62236 | 2.3 | 3.8 | getgrav | grav | CWE-352 | grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret |
| CVE-2026-16089 | 5.9 | 3.7 | Red Hat | Red Hat Build of Keycloak | CWE-384 | Keycloak-services: keycloak-services: authorization codes can be retargeted t… |
| CVE-2026-16118 | 7.1 | 3.1 | xdg | xdgmime | CWE-122 | Xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in … |
| CVE-2026-45784 | 5.1 | 3.1 | rust-openssl | rust-openssl | CWE-131 | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_i… |
| CVE-2026-21764 | 4.3 | 3.0 | HCLSoftware | DevOps Loop | CWE-754 | Insufficient Input Validation in DevOps Loop |
| CVE-2024-23572 | 4.2 | 2.9 | HCLSoftware | Aftermarket EPC | CWE-614 | HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a se… |
| CVE-2019-25764 | 7.3 | 2.2 | ASUS | AURA SYNC | CWE-782 | **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control … |
| CVE-2026-44722 | 6.2 | 1.8 | danifus | pyzipper | CWE-480 | pyzipper: Encryption bypass for small files encrypted with pyzipper |
| CVE-2026-49834 | 7.5 | 1.5 | sigstore | sigstore-go | CWE-347 | sigstore-go: Multi-log threshold bypass via single compromised log |
| CVE-2026-21770 | 6.5 | 1.5 | HCLSoftware | HCL Traveler for Microsoft Outlook (HTMO) | CWE-427 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking |
| CVE-2026-14971 | 7.0 | 1.0 | IBM | PowerVM Novalink | CWE-16 | This PowerVM Novalink update is being released to address |
| CVE-2026-15995 | 4.2 | 1.0 | IBM | Cognos Analytics | CWE-362 | IBM Cognos Analytics 12.1.3 general availability package contains a data inte… |
| CVE-2025-59866 | 3.3 | 1.0 | HCLSoftware | DFMPro for CATIA | CWE-732 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecu… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-17 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.