boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, July 17, 2026 · all times UTC← 2026-07-16 · archive · 2026-07-18 →

Security Box Score — July 17, 2026

288 CVEs published, led by IBM (34).

288 CVEs published July 17, 2026: 38 critical, 99 high, 131 medium, 20 low; 1 in the KEV catalog at press time; 17 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 263 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published460717010——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

759 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux41152112186753211120.17.5.0014-55 ▼
microsoft64614039697531814286231.67.8.0047+438 ▲
google941359150616555387760.47.8.0024-586 ▼
red hat652871411514018200.06.5.00320
apple01042287228876.76.5.0032-14 ▼
canonical42436105000.05.5.0013+4 ▲
suse82141241000.08.5.0039+6 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1537818110561129.77.5.0057+6 ▲
ubiquiti2536142110338.38.8.0049+20 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear62300221000.04.6.0024-11 ▼
fortinet13226610028522.77.3.0039+11 ▲
f58165830416.38.6.0057+2 ▲
ivanti211452025545.58.8.3445-2 ▼
checkpoint0915303111.17.5.0410-3 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache77232478984113310.47.5.0058+3 ▲
mozilla6621218320900.06.5.0026-43 ▼
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-4 ▼
github5111280000.06.0.0042+5 ▲
docker070520000.08.2.0016-2 ▼
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle12711331161842731.18.8.0040-241 ▼
adobe942382610310541931.37.6.0026-35 ▼
ibm361605254540600.07.5.0036+25 ▲
progress101931420600.07.5.0037+5 ▲
solarwinds07232010457.17.5.4001-3 ▼
veeam042200100.09.0.0052-1 ▼
zohocorp031110000.08.4.01700
servicenow111000200.09.5.7758+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
siemens7161870000.07.6.00240
d-link1130535300.06.0.0059-8 ▼
abb170430000.07.2.0018-4 ▼
schneider electric060420000.07.8.0042-1 ▼
moxa050320000.07.0.0029-5 ▼
dahua030111000.06.9.0036-3 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
openclaw441110583914000.07.0.0026-17 ▼
sourcecodester37108005652000.05.5.00320
dell3793542433211.17.0.0021+11 ▲
capgo2283242381000.07.1.0037+20 ▲
nvidia40791252150000.07.8.0037+34 ▲
imagemagick3273155512000.05.3.0019+4 ▲
spring073231391000.06.5.0024-71 ▼
itsourcecode1366001947000.02.1.0033-9 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-20253.969499.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-1540910.0.8366KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
Most disclosures (vendor)
VendorCVEs
microsoft659
google504
linux458
red hat128
apache124
adobe107
ibm100
capgo81
dell49
sourcecodester49
Most KEV additions (YTD)
VendorKEV
microsoft23
cisco11
apple7
google6
fortinet5
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven56
PyPI5
npm5
NuGet3
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-25089Fortinet0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-45659Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171703
CVE-2021-27102n/a2021-11-171703
CVE-2021-27101n/a2021-11-171703
CVE-2021-27103n/a2021-11-171703
CVE-2021-21017Adobe2021-11-171703
CVE-2021-28550Adobe2021-11-171703
CVE-2021-42013Apache Software Foundation2021-11-171703
CVE-2021-41773Apache Software Foundation2021-11-171703
CVE-2021-30858Apple2021-11-171703
CVE-2021-30860Apple2021-11-171703

Transactions

EXPLOIT PUBLISHED — CVE-2025-60357. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16014 (code-projects Hospital Bed Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16073 (AstrBotDevs AstrBot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16074 (AstrBotDevs AstrBot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44251 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44891 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45309 (ronf asyncssh). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45799 (square wire). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50185 (RustCrypto utils). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50289 (sebhildebrandt systeminformation). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-53727 (premailer css_parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54497 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54498 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56740 (jline3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56741 (jline3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62238 (openremote). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62241 (MohibShaikh clawvet). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63094 (signoz). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63100 (maybe-finance maybe). Public exploit reference added.

DUE DATE PASSED — CVE-2008-4128 (Cisco IOS). CISA remediation deadline was July 16, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

288 CVEs published. 25 box scores, 263 table rows — nothing truncated.

IBM Langflow OSS — Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .3733   98.4   YES
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 21  Reserved by CNA
  Jul 17  Published (CNA: ibm)
  Aug 4   Added to CISA KEV, due Aug 7
CWE-94 · CNA: ibm · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due August 7, 2026
MohibShaikh clawvet — clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0655   93.3     —
AFFECTED
  Product  Versions     Fixed
  clawvet  unspecified  0.7.5
TIMELINE
  Jul 13  Reserved by CNA
  Jul 17  Public exploit reference published
  Jul 17  Published (CNA: VulnCheck)
CWE-306, CWE-321 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
sebhildebrandt systeminformation — systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0218   81.0     —
AFFECTED
  Product            Versions    Fixed
  systeminformation  < 5.31.7 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jul 17  Public exploit reference published
  Jul 17  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Analyzed
n/a n/a — django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0205   79.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 24  Reserved by CNA
  Jul 17  Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Deferred
shivammathur setup-php — setup-php: Command Injection in Repository-Derived PHP Version Resolution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0154   72.9     —
AFFECTED
  Product    Versions               Fixed
  setup-php  >= 2.25.0, < 2.37.1 –  —
TIMELINE
  May 13  Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Analyzed
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0114   64.1     —
AFFECTED
  Product                                                      Versions     Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 17  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0107   62.4     —
AFFECTED
  Product                                                                                                                Versions     Fixed
  Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 17  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Pimcore: Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  H  H  H    8.0   .0099   59.7     —
AFFECTED
  Product  Versions     Fixed
  pimcore  < 11.5.17 –  —
TIMELINE
  May 8   Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
IBM Langflow OSS — Disk Cache Deserialization Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0090   56.9     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 13  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-502 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
ruvnet agentic-flow — Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0087   55.9     —
AFFECTED
  Product       Versions    Fixed
  agentic-flow  < 2.0.14 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 7 references · NVD status: Deferred
IBM Langflow OSS — Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0084   55.1     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 20  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-94 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
IBM Langflow OSS — Remote Code Execution via Code Validation Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0081   54.1     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 13  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-94 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
DataDog dd-trace-py — dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0079   53.6     —
AFFECTED
  Product      Versions   Fixed
  dd-trace-py  < 4.8.2 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Awaiting Analysis
DataDog dd-trace-js — dd-trace: Improper parsing of W3C baggage headers may lead to DoS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0079   53.6     —
AFFECTED
  Product      Versions     Fixed
  dd-trace-js  < 5.100.0 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Awaiting Analysis
Datadog .NET Tracer: Improper parsing of W3C baggage headers may lead to DoS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0079   53.6     —
AFFECTED
  Product          Versions    Fixed
  dd-trace-dotnet  < 3.43.0 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Awaiting Analysis
DataDog dd-trace-go — dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0079   53.6     —
AFFECTED
  Product      Versions   Fixed
  dd-trace-go  < 2.8.1 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Awaiting Analysis
codeigniter4 CodeIgniter4 — CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0077   53.0     —
AFFECTED
  Product       Versions   Fixed
  CodeIgniter4  < 4.7.3 –  —
TIMELINE
  May 20  Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-434 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
PrestaShop ps_facetedsearch — ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0075   52.2     —
AFFECTED
  Product           Versions             Fixed
  ps_facetedsearch  >= 3.0.0, < 4.0.4 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-74 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
IBM Langflow OSS — MCP Server Configuration Validator Bypass via File Upload API
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0075   52.1     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 4   Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-20 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Modified
liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0074   51.9     —
AFFECTED
  Product  Versions                                    Fixed
  CIPster  632336d414ef708a542377c1aa8d6fdb7c70a760 –  —
TIMELINE
  Jul 17  Reserved by CNA
  Jul 17  Published (CNA: VulDB)
CWE-119, CWE-125 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
IBM Langflow OSS — Unauthenticated Superuser Token Issuance via Auto-Login Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0072   51.2     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 20  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-306 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    7.7   .0072   51.0     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.5.18
TIMELINE
  Jul 13  Reserved by CNA
  Jul 17  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
Sangoma Switchvox SMB Edition — Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0069   50.2     —
AFFECTED
  Product                Versions        Fixed
  Switchvox SMB Edition  8.3 (104997) –  —
TIMELINE
  May 26  Reserved by CNA
  Jul 17  Published (CNA: SRA)
CWE-89 · CNA: SRA · CVSS v4.0 · 2 references · NVD status: Deferred
jsonata-js jsonata — JSONata: Malicious inputs to "$toMillis" function can cause resource exhaustion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0069   50.0     —
AFFECTED
  Product  Versions             Fixed
  jsonata  >= 2.0.0, < 2.2.0 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-1333 · CNA: GitHub_M · CVSS v3.1 · 7 references · NVD status: Modified
thimpress WP Hotel Booking — WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0069   49.9     —
AFFECTED
  Product           Versions     Fixed
  WP Hotel Booking  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 17  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-137657.549.8thimpressLearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-862LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Info…
CVE-2026-494857.549.8hapifhirorg.hl7.fhir.coreCWE-400HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HT…
CVE-2026-134489.849.0IBMLangflow OSSCWE-184Langflow is affected by remote code execution, denial of service, path traver…
CVE-2026-144998.849.0IBMLangflow OSSCWE-78Langflow is affected by remote code execution, denial of service, path traver…
CVE-2026-521999.149.0n/an/aCWE-77An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attac…
CVE-2026-151604.349.0SaturdayDriveNinja Forms - Excel ExportCWE-22Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated …
CVE-2026-561717.548.8MicrosoftRemote Desktop Web ClientCWE-359Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-126929.848.0Vimesoft Inc.Enterprise Video PlatformCWE-620Improper Authentication in Vimesoft's Enterprise Video Platform
CVE-2026-452608.147.7pimcorepimcoreCWE-862Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling
CVE-2026-150075.747.7GitHubEnterprise ServerCWE-770Denial of service vulnerability in GitHub Enterprise Server allowed service d…
CVE-2026-592528.247.4ZenHivemppCWE-1284Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
CVE-2025-516779.147.3n/an/aCWE-116An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch …
CVE-2025-516787.546.5n/an/aCWE-119An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the P…
CVE-2026-567417.545.8jlinejline3CWE-400JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
CVE-2026-567407.545.7jlinejline3CWE-400JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVI…
CVE-2026-122836.145.6AWSaws-athena-query-federationCWE-89SQL injection in Amazon Athena Synapse connector
CVE-2026-480495.345.6hapijsinertCWE-22@hapi/inert: Static-file confinement bypass via sibling-prefix path
CVE-2026-160152.145.1poco-aipoco-clawCWE-287poco-ai poco-claw executor_manager API tasks.py create_task missing authentic…
CVE-2026-630938.744.8Anysphere, Inc.CursorCWE-426Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
CVE-2026-85059.844.7IBMLangflow OSSCWE-306Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution
CVE-2026-153438.644.6GitHubEnterprise ServerCWE-22Path traversal vulnerability in GitHub Enterprise Server allowed writing file…
CVE-2026-150919.344.5IBMEngineering AI HubCWE-79Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-78728.144.4IBMLangflow OSSCWE-22Path Traversal Vulnerability in File Component Leading to Arbitrary File Read…
CVE-2026-622077.744.4OpenClawOpenClawCWE-862OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools
CVE-2026-366699.844.3n/an/aCWE-434An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.p…
CVE-2026-88599.944.0IBMLangflow OSSCWE-22Path Traversal in APIRequest Component via Content-Disposition Header
CVE-2026-76678.844.0IBMLangflow OSSCWE-22Path Traversal Vulnerability in API Request Component Content-Disposition Hea…
CVE-2026-492095.344.1symfonyuxCWE-770Symfony UX: Denial of service in symfony/ux-live-component via unbounded batc…
CVE-2026-95858.643.8SangomaSwitchvox SMB EditionCWE-79Unauthenticated Reflected Cross-Site Scripting (XSS) in Switchvox SMB Web Portal
CVE-2026-501977.843.5zalandoskipperCWE-444Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-E…
CVE-2026-91717.543.5IBMPowerVM NovalinkCWE-400Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.
CVE-2026-457997.543.3squarewireCWE-129Wire: skipGroup() missing negative-length check allows 10-byte payload to cra…
CVE-2026-600249.843.3joomdonation.comEvents Booking extension for JoomlaCWE-1188Joomla Extension - joomdonation.com - Insecure default configuration Events B…
CVE-2026-622027.743.1OpenClawOpenClawCWE-863OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron
CVE-2026-492116.942.5symfonyuxCWE-200Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearch…
CVE-2026-86359.942.4IBMLangflow OSSCWE-94Arbitrary Code Execution in Python Interpreter Component
CVE-2026-80568.842.4IBMLangflow OSSCWE-94Parameter Injection Vulnerability in API Graph Execution Engine
CVE-2026-622037.742.1OpenClawOpenClawCWE-184OpenClaw < 2026.6.6 Environment Variable Injection via rustup
CVE-2026-596948.342.0ZenHivemppCWE-1284Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment
CVE-2026-596958.342.0ZenHivemppCWE-1284Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request walle…
CVE-2026-631018.741.8fossasiaopen-event-serverCWE-306Open Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export …
CVE-2026-622206.341.7OpenClawOpenClawCWE-307OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
CVE-2026-510809.841.6n/an/aCWE-611libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to c…
CVE-2026-126917.541.5Vimesoft Inc.Enterprise Video PlatformCWE-306Authentication Bypass in Vimesoft's Enterprise Video Platform
CVE-2026-153227.541.5IBMEngineering AI HubCWE-598Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-522037.541.5n/an/aCWE-200An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive informa…
CVE-2026-501626.940.9oras-projectoras-goCWE-73oras-go: file store write outside workingDir via symlink traversal
CVE-2026-145036.540.9ploudapppCloud WP BackupCWE-200pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX …
CVE-2026-92029.840.7IBMLangflow OSSCWE-306Unauthenticated User Registration Could Lead to Remote Code Execution
CVE-2026-98109.840.4UnknownAI CopilotCWE-269AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege …
CVE-2026-160165.540.2poco-aipoco-clawCWE-918poco-ai poco-claw task.py run_task server-side request forgery
CVE-2026-480154.939.5shopwareshopwareCWE-79Shopware: Stored XSS via SVG file upload — no SVG sanitization
CVE-2026-622308.739.2getgravgravCWE-178Grav < 2.0.4 File Access Bypass via Case Variation
CVE-2026-153494.338.7wedevsERP: Complete HR, Accounting & CRM Suite Built for WooCommerceCWE-862ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Mi…
CVE-2026-449747.738.7hapijscontentCWE-436Parameter smuggling in @hapi/content header parser allows upload-filter bypas…
CVE-2026-480086.538.7shopwareshopwareCWE-862Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
CVE-2026-480106.538.7shopwareshopwareCWE-269Shopware: Privilege escalation: non-admin user with user:create ACL can creat…
CVE-2026-627645.738.6Apache Software FoundationApache AccumuloCWE-274Apache Accumulo: A user can trigger a graceful shutdown of services without t…
CVE-2026-134739.838.5IBMStorage Protect ClientCWE-122IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow
CVE-2026-82979.838.4Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.GisLab Laboratory Management SystemCWE-89SQLi in GIS Informatics' GisLab Laboratory Management System
CVE-2026-523489.838.4n/an/aCWE-89cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method…
CVE-2026-126939.437.8Vimesoft Inc.Enterprise Video PlatformCWE-639IDOR in Vimesoft's Enterprise Video Platform
CVE-2026-480096.837.7shopwareshopwareCWE-200Shopware: Admin Account Takeover via User Recovery Hash Exposure
CVE-2026-160082.137.7sagoldjson-schema-libraryCWE-94sagold json-schema-library propertyDependencies.ts parsePropertyDependencies …
CVE-2026-622329.137.4getgravgravCWE-862Grav < 2.0.4 2FA Bypass via Secret Regeneration
CVE-2026-622188.737.3OpenClawOpenClawCWE-862OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve
CVE-2026-622237.737.3OpenClawOpenClawCWE-863OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
CVE-2026-622287.737.3OpenClawOpenClawCWE-863OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals
CVE-2026-221047.137.2hashtopolisserverCWE-639Improper access control in Hashtopolis server chunk activity component
CVE-2026-622106.037.2OpenClawOpenClawCWE-770OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs
CVE-2026-157835.337.1GitHubEnterprise ServerCWE-862Missing Authorization vulnerability was identified in GitHub Enterprise Serve…
CVE-2026-555189.637.1avo-hqavoCWE-639Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthor…
CVE-2026-622177.737.0OpenClawOpenClawCWE-863OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals
CVE-2026-498357.537.0sigstoretimestamp-authorityCWE-770Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality
CVE-2026-544646.336.8fayewebsocket-driver-rubyCWE-770websocket-driver: Resource limit bypass via message compression
CVE-2026-442516.536.8wazuhwazuhCWE-122Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and po…
CVE-2026-622338.736.6getgravgravCWE-639grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey
CVE-2026-453098.236.4ronfasyncsshCWE-22AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected auth…
CVE-2026-83967.536.5Netcad Software Inc.NetGISCWE-611XXE in Netcad's NetGIS
CVE-2026-622146.036.5openclawmsteamsCWE-522OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation
CVE-2026-126949.136.2Vimesoft Inc.Enterprise Video PlatformCWE-862Missing Authorization in Vimesoft's Enterprise Video Platform
CVE-2026-581488.736.2chronoengine.comChronoForms extension for JoomlaCWE-79Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for…
CVE-2026-622376.036.1getgravgravCWE-1333Grav < 2.0.4 ReDoS via regex_replace in Sandbox
CVE-2026-623868.235.8getgravgravCWE-598Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter
CVE-2026-160145.535.7code-projectsHospital Bed Management SystemCWE-74code-projects Hospital Bed Management System Login Form sql injection
CVE-2026-501637.135.5oras-projectoras-goCWE-22oras-go: Hardlink entry with relative Linkname escapes extract dir via proces…
CVE-2026-153957.235.5wpchillKali Forms — Contact Form & Drag-and-Drop BuilderCWE-79Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digit…
CVE-2026-148717.135.4osTicketosTicketCWE-863osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-d…
CVE-2026-457047.135.4pimcorepimcoreCWE-862Pimcore: CustomReports Share Bypass
CVE-2026-541716.535.4exconexconCWE-201Excon: redact additional sensitive/risky headers when following redirects
CVE-2026-448917.535.1nettynettyCWE-400Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVE-2026-80756.534.8MattermostMattermostCWE-754Posting a malicious markdown image crashes the Mattermost Desktop App
CVE-2026-96026.534.8MattermostMattermostCWE-400Mattermost Desktop App crashes when malformed arguments are provided to some …
CVE-2026-449796.334.7hapijswreckCWE-200@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-host…
CVE-2025-603578.134.6n/an/aCWE-943AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injec…
CVE-2026-485045.334.5open-telemetryopentelemetry-rustCWE-770OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation
CVE-2026-71897.534.3Proliz Software Ltd. Co.Proliz's OBSCWE-201Sensitive Data Exposure in Proliz's OBS
CVE-2026-74887.534.3IKAS Technology Inc.E-CommerceCWE-201Sensitive Data Exposure in IKAS Technologies' E-Commerce
CVE-2026-480164.334.2shopwareshopwareCWE-639Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/hand…
CVE-2026-492086.934.0symfonyuxCWE-20Symfony UX: Format-less date LiveProps parsed with the permissive DateTime co…
CVE-2026-518337.533.7n/an/aCWE-918Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privil…
CVE-2026-95887.033.4SangomaSwitchvox SMB EditionCWE-79Authenticated Stored Cross-Site Scripting (XSS) in Switchvox SMB Web Portal
CVE-2026-633077.133.0OtterMindChat2DBCWE-639Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/data…
CVE-2024-235655.333.1HCLSoftwareAftermarket EPCCWE-799HCL Aftermarket EPC is vulnerable to email flooding as the application does n…
CVE-2024-235685.333.1HCLSoftwareAftermarket EPCCWE-200HCL Aftermarket EPC is vulnerable to attacks since the server software versio…
CVE-2026-88615.333.0IBMVerify Identity AccessCWE-209Security vulnerabilities have been found in IBM Verify Identity Access and IB…
CVE-2026-622348.432.4getgravgravCWE-918Grav < 2.0.4 SSRF via Unrestricted cURL Protocols
CVE-2026-447398.732.0pimcorepimcoreCWE-89Pimcore: SQL Injection in Custom Reports Column Configuration
CVE-2026-579805.431.9MicrosoftMicrosoft Edge (Chromium-based)CWE-288Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2026-622274.932.0OpenClawOpenClawCWE-918OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot
CVE-2026-86165.331.9devozonFense Proxy & VPN BlockerCWE-862Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated…
CVE-2026-471836.531.7python-zeroconfpython-zeroconfCWE-400Zeroconf: Unbounded exception-dedup state retains packet buffers via tracebac…
CVE-2026-471846.531.7python-zeroconfpython-zeroconfCWE-770Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via m…
CVE-2026-480146.531.7shopwareshopwareCWE-862Shopware: Admin API ACL Bypass in Order State Transition Endpoints
CVE-2026-113246.131.7evertecWooCommerce Placetopay Gateway BeliceCWE-79WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via …
CVE-2026-543353.731.7feathersjsfeathersCWE-1321Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parse…
CVE-2026-622318.631.4getgravgravCWE-863Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator
CVE-2026-149797.531.4IBMEngineering Lifecycle ManagementCWE-776IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML E…
CVE-2026-510827.231.3n/an/aCWE-362A race condition between the vncproxy and vncwebsocket API calls in Proxmox V…
CVE-2026-134108.231.1GARUDancer::Plugin::Auth::GoogleCWE-295Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verificat…
CVE-2026-119618.131.1UnknownUser Registration & MembershipCWE-269User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation…
CVE-2026-134469.830.9IBMLangflow OSSCWE-798Langflow is affected by remote code execution, denial of service, path traver…
CVE-2026-95877.130.5SangomaSwitchvox SMB EditionCWE-73Authenticated Local File Inclusion (LFI) in Switchvox SMB Web Portal
CVE-2026-622097.629.8OpenClawOpenClawCWE-863OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode disp…
CVE-2026-471806.529.7python-zeroconfpython-zeroconfCWE-674Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-l…
CVE-2026-480456.529.7python-zeroconfpython-zeroconfCWE-770Zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via …
CVE-2026-160172.129.3mosaxivclawletCWE-862mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
CVE-2026-537278.929.2premailercss_parserCWE-918css_parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_…
CVE-2026-150934.329.2IBMEngineering AI HubCWE-601Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-501517.529.1oras-projectoras-goCWE-918oras-go: credential forwarding via unvalidated Location header in blob upload
CVE-2026-117636.528.8Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.GisLab Laboratory Management SystemCWE-639IDOR in GIS Informatics' GisLab Laboratory Management System
CVE-2026-622014.928.7OpenClawOpenClawCWE-918OpenClaw < 2026.6.6 Network Policy Bypass via exec-server
CVE-2026-115757.528.4UnknownPhonePe Payment SolutionsCWE-862PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged…
CVE-2026-622086.028.4OpenClawOpenClawCWE-522OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE
CVE-2026-622136.028.4openclawmsteamsCWE-522OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests
CVE-2026-622056.028.2OpenClawOpenClawCWE-862OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions
CVE-2026-622066.028.2OpenClawOpenClawCWE-862OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions
CVE-2026-630997.128.0TheHive-ProjectTheHiveCWE-639TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endp…
CVE-2026-631007.128.0maybe-financemaybeCWE-862Maybe 0.6.0 Missing Authorization via HostingsController show/update
CVE-2026-499774.328.0AmauriCtarteaucitron.jsCWE-285tarteaucitron.js: data-cookie attribute can be used to delete arbitrary cookies
CVE-2026-147417.527.9OALDERSHTTP::DateCWE-1333HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial …
CVE-2026-154156.827.9AWSaws-healthomics-mcp-serverCWE-23Path traversal and arbitrary file write in the workflow linters of aws-health…
CVE-2026-488194.827.8hey-apiopenapi-tsCWE-1321Hey API: `buildClientParams` template: prototype chain substitution via unkno…
CVE-2026-149569.827.7BricksforgeBricksforgeCWE-269Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms f…
CVE-2026-127158.527.7Google CloudFirebase StudioCWE-862Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft
CVE-2026-134458.127.6IBMLangflow OSSCWE-639Langflow is affected by remote code execution, denial of service, path traver…
CVE-2026-157596.427.5themeatelierChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat FormCWE-79ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-160742.127.3AstrBotDevsAstrBotCWE-918AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side re…
CVE-2026-134025.327.0UnknownRoyal Addons for ElementorCWE-200Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Templat…
CVE-2026-581495.327.0joomdonation.comEvents Booking extension for JoomlaCWE-200Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0
CVE-2026-160724.927.1Red HatRed Hat Build of KeycloakCWE-284Keycloak-services: keycloak-services: organization invitation link exposure a…
CVE-2026-544636.926.9fayewebsocket-driver-rubyCWE-770websocket-driver: Memory exhaustion via abuse of protocol length headers
CVE-2026-544656.326.9fayewebsocket-driver-rubyCWE-770websocket-driver: Memory exhaustion in HTTP header parser
CVE-2026-623877.126.6getgravgravCWE-942Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin
CVE-2026-161034.326.6Red HatRed Hat Build of KeycloakCWE-841Keycloak-services: keycloak-services: incomplete fix for ciba brute-force loc…
CVE-2026-77546.526.5IBMLangflow OSSCWE-918SSRF Protection Configuration Vulnerability
CVE-2026-510836.526.5n/an/aCWE-284Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server…
CVE-2026-159829.826.4CodeRevolutionAimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation ToolkitCWE-269Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Tool…
CVE-2026-542436.126.2statamiccmsCWE-1236Statamic: CSV formula injection in form submission exports
CVE-2026-492102.326.2symfonyuxCWE-79Symfony UX: XSS in symfony/ux-live-component via attacker-controlled child co…
CVE-2026-483737.826.2AdobeAcrobat ReaderCWE-122Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
CVE-2026-159435.526.1Red HatRed Hat Build of KeycloakCWE-1288Keycloak-services: keycloak-services: oidc idp update reuses masked client se…
CVE-2026-630966.926.0matrix-orgdendriteCWE-918Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
CVE-2026-622265.125.8OpenClawOpenClawCWE-918OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route
CVE-2026-622387.225.7openremoteopenremoteCWE-89OpenRemote < 1.26.0 SQL Injection via Crosstab Export
CVE-2026-160092.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System prescriptionorderdetail.php sql injec…
CVE-2026-633095.325.4surrealdbsurrealdbCWE-863SurrealDB < 3.1.5 Information Disclosure via ORDER BY
CVE-2026-160732.025.4AstrBotDevsAstrBotCWE-79AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross si…
CVE-2024-235745.325.3HCLSoftwareAftermarket EPCCWE-204HCL Aftermarket EPC is vulnerable to attack since It was found that a malicio…
CVE-2024-235755.325.3HCLSoftwareAftermarket EPCCWE-209HCL Aftermarket EPC is vulnerable to attack since the application returns det…
CVE-2024-422145.325.3HCLSoftwareAftermarket EPCCWE-692HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enab…
CVE-2026-161064.925.3Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: incorrect authorization in admin role-c…
CVE-2026-95375.324.5JBERGERMojo::JWTCWE-208Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-con…
CVE-2026-25946.424.3inc2734Smart Custom FieldsCWE-79Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scri…
CVE-2026-583175.124.3TeraTerm ProjectTTSSH2CWE-196Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 …
CVE-2026-600605.124.3TeraTerm ProjectTTSSH2CWE-130Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability e…
CVE-2026-630986.923.9TheHive-ProjectTheHiveCWE-306TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
CVE-2026-457036.423.9pimcorepimcoreCWE-862Pimcore: WordExport Authorization Bypass for Unauthorized Document Export
CVE-2026-145019.823.7IBMDb2 Genius HubCWE-676Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
CVE-2026-544969.323.7ZcashFoundationzebraCWE-345Missing copy constraint in halo2_gadgets variable-base scalar multiplication …
CVE-2026-544988.723.4ViewComponentview_componentCWE-79view_component: around_render HTML-Safety Bypass
CVE-2026-492165.123.3symfonyuxCWE-79Symfony UX: XSS in symfony/ux-autocomplete via unescaped AJAX response data
CVE-2024-235674.322.7HCLSoftwareAftermarket EPCCWE-804HCL Aftermarket EPC is affected by Sensitive Information in GET method & in U…
CVE-2026-130825.322.6BURAKGD::SecurityImageCWE-338GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
CVE-2026-160935.422.5Red HatRed Hat Build of KeycloakCWE-807Keycloak-services: keycloak-services: required signed-jwt assertion policy ca…
CVE-2026-119665.322.4UnknownUser Registration & MembershipCWE-639User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletio…
CVE-2026-542443.522.3statamiccmsCWE-863Statamic: Incorrect authorization lets view-only users submit Live Preview co…
CVE-2026-150695.422.2IBMEngineering AI HubCWE-78Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-622196.022.1OpenClawOpenClawCWE-863OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs
CVE-2026-49386.521.9IBMVerify Identity AccessCWE-863Incorrect Authorization in IBM Verify Identity Access and IBM Security Verify…
CVE-2024-235694.321.7HCLSoftwareAftermarket EPCCWE-692HCL Aftermarket EPC is vulnerable to attack since the server is not configure…
CVE-2024-235714.321.7HCLSoftwareAftermarket EPCCWE-525HCL Aftermarket EPC is vulnerable to attack since the application does not ha…
CVE-2024-235774.321.7HCLSoftwareAftermarket EPCCWE-20HCL Aftermarket EPC is vulnerable since the application does not have a valid…
CVE-2026-630957.121.6matrix-orgdendriteCWE-639Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint
CVE-2024-235649.121.4HCL SoftwareAftermarket EPCCWE-326HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a…
CVE-2026-622162.321.2OpenClawOpenClawCWE-918OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload
CVE-2026-123935.420.7UnknownWPS Bookings for WooCommerceCWE-639WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order C…
CVE-2026-622352.320.6getgravgravCWE-636Grav Flex-Objects < 1.4.3 Authorization Bypass via API
CVE-2026-541634.720.5githubsecure_headersCWE-79secure_headers: CSP directive injection via sandbox, plugin_types, and report…
CVE-2026-151594.320.0SaturdayDriveNinja Forms - Excel ExportCWE-639Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Aut…
CVE-2024-235704.319.8HCLSoftwareAftermarket EPCCWE-200HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scr…
CVE-2026-105256.119.4UnknownNEX-FormsCWE-79NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
CVE-2026-633085.319.3helmhelmCWE-129Helm Files.Lines Denial of Service via Empty Chart Files
CVE-2026-630975.318.3matrix-orgdendriteCWE-863Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure
CVE-2024-235666.518.1HCLSoftwareAftermarket EPCCWE-804HCL Aftermarket EPC is vulnerable to brute force attacks since application do…
CVE-2026-96564.317.8hubspotdevHubSpot All-In-One Marketing – Forms, Popups, Live ChatCWE-200HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensit…
CVE-2026-544906.317.7fayewebsocket-driver-nodeCWE-770websocket-driver: Resource limit bypass via message compression
CVE-2026-630947.617.6SigNozsignozCWE-345SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft
CVE-2026-151616.417.4SaturdayDriveNinja Forms - Excel ExportCWE-79Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cros…
CVE-2026-537128.217.3ongresscramCWE-636SCRAM: Silent channel-binding authentication downgrade via unsupported certif…
CVE-2026-622242.317.3openclawmsteamsCWE-290OpenClaw MS Teams < 2026.5.12 Authorization Bypass
CVE-2026-489782.117.4oras-projectoras-goCWE-319oras-go: Malicious registry can hijack Bearer token realm to exfiltrate crede…
CVE-2026-73646.117.2IBMVerify Identity AccessCWE-601Security vulnerabilities have been found in IBM Verify Identity Access and IB…
CVE-2026-510816.116.4n/an/aCWE-79A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PV…
CVE-2026-622155.116.1OpenClawOpenClawCWE-345OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas
CVE-2026-544976.815.9ViewComponentview_componentCWE-362view_component: Reused Component Instances Retain Stale Render Context
CVE-2026-622252.316.0OpenClawOpenClawCWE-863OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch
CVE-2026-484875.315.8python-zeroconfpython-zeroconfCWE-130Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cac…
CVE-2026-49427.515.7IBMiCWE-757IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
CVE-2024-235733.715.4HCLSoftwareAftermarket EPCCWE-425HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerab…
CVE-2026-492126.915.0symfonyuxCWE-345Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding
CVE-2026-622212.315.1OpenClawOpenClawCWE-863OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom
CVE-2026-95927.515.0SEPPmailSEPPmail Secure Email Gateway & SEPPmail CloudCWE-598Sensitive Information Disclosure in HTTP header
CVE-2026-542424.913.1statamiccmsCWE-367Statamic: Server-Side Request Forgery via Glide (DNS rebinding)
CVE-2026-622125.113.0OpenClawOpenClawCWE-367OpenClaw < 2026.5.28 Authentication Bypass via safeFetch
CVE-2026-492847.112.6simplesamlphpsimplesamlphpCWE-345SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Res…
CVE-2026-544669.212.5fayewebsocket-driver-nodeCWE-130websocket-driver: Message corruption via abuse of protocol length headers
CVE-2026-161046.511.2Red HatRed Hat Build of KeycloakCWE-522Keycloak-services: keycloak-services: authenticator config endpoint exposes r…
CVE-2026-217604.610.7HCLSoftwareDevOps LoopCWE-425Unauthorized Access to Admin Functionality via Forced Browsing
CVE-2026-600258.89.8joomdonation.comEvents Booking extension for JoomlaCWE-352Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0
CVE-2026-578608.49.3tailcallhqforgecodeCWE-829ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Reposi…
CVE-2024-235784.29.3HCLSoftwareAftermarket EPCCWE-942HCL Aftermarket EPC is vulnerable to attack as the application implements an …
CVE-2026-498528.79.1authlibjoserfcCWE-287joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language …
CVE-2026-161086.59.1Red HatRed Hat Build of KeycloakCWE-200Keycloak-services: keycloak-services: realm default-group reads disclose hidd…
CVE-2026-552546.58.8ncalcncalcCWE-190NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
CVE-2026-457856.28.0openmcdfopenmcdfCWE-835OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on …
CVE-2026-492152.17.2symfonyuxCWE-352Symfony UX: CSRF Protection Bypass in symfony/ux-live-component — Accept Head…
CVE-2026-622227.17.1OpenClawOpenClawCWE-829OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode
CVE-2026-480226.57.1hapijswreckCWE-319@hapi/wreck: Sensitive credential headers leak across cross-port and cross-sc…
CVE-2026-217625.36.6HCLSoftwareDevOps LoopCWE-644Missing HTTP Security Headers in DevOps Loop
CVE-2026-153805.16.2BroadcomSymantec Management SuiteCWE-269Local privilege escalation in Symantec ITMS
CVE-2026-97627.85.9IBMDb2CWE-94IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execut…
CVE-2026-525847.15.7n/an/aCWE-121Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local at…
CVE-2026-501852.05.0RustCryptoutilsCWE-758RustCrypto Cmov/CmovEq on aarch64 can produce wrong results if high-bits of r…
CVE-2026-127055.94.6ABBKNX Update Tool (ABB)CWE-353Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool
CVE-2026-419936.74.4TXOne NetworksSafePortAgentCWE-284Improper Access Control vulnerability in the Removable Media Validation funct…
CVE-2026-622114.14.4OpenClawOpenClawCWE-532OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export
CVE-2026-77715.54.2IBMDb2CWE-835IBM® Db2® is vulnerable to a trap when compiling specially crafted statements…
CVE-2026-217615.44.1HCLSoftwareDevOps LoopCWE-942CORS Misconfiguration in DevOps Loop
CVE-2026-153795.14.1BroadcomSymantec IT Management SuiteCWE-269Arbitrary File Read as SYSTEM in Symantec ITMS
CVE-2026-622362.33.8getgravgravCWE-352grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret
CVE-2026-160895.93.7Red HatRed Hat Build of KeycloakCWE-384Keycloak-services: keycloak-services: authorization codes can be retargeted t…
CVE-2026-161187.13.1xdgxdgmimeCWE-122Xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in …
CVE-2026-457845.13.1rust-opensslrust-opensslCWE-131rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_i…
CVE-2026-217644.33.0HCLSoftwareDevOps LoopCWE-754Insufficient Input Validation in DevOps Loop
CVE-2024-235724.22.9HCLSoftwareAftermarket EPCCWE-614HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a se…
CVE-2019-257647.32.2ASUSAURA SYNCCWE-782**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control …
CVE-2026-447226.21.8danifuspyzipperCWE-480pyzipper: Encryption bypass for small files encrypted with pyzipper
CVE-2026-498347.51.5sigstoresigstore-goCWE-347sigstore-go: Multi-log threshold bypass via single compromised log
CVE-2026-217706.51.5HCLSoftwareHCL Traveler for Microsoft Outlook (HTMO)CWE-427HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking
CVE-2026-149717.01.0IBMPowerVM NovalinkCWE-16This PowerVM Novalink update is being released to address
CVE-2026-159954.21.0IBMCognos AnalyticsCWE-362IBM Cognos Analytics 12.1.3 general availability package contains a data inte…
CVE-2025-598663.31.0HCLSoftwareDFMPro for CATIACWE-732The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecu…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-17 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.