AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N P L L L 1.3 .0123 66.5 —
AFFECTED Product Versions Fixed MiniCode 0.1.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
80 CVEs published, led by surrealdb (24).
80 CVEs published July 18, 2026: 7 critical, 28 high, 19 medium, 26 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 55 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4687 | 17090 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
759 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 41 | 1521 | 121 | 867 | 532 | 1 | 11 | 2 | 0.1 | 7.5 | .0014 | -55 ▼ |
| microsoft | 646 | 1403 | 96 | 975 | 318 | 14 | 286 | 23 | 1.6 | 7.8 | .0047 | +434 ▲ |
| 94 | 1359 | 150 | 616 | 555 | 38 | 77 | 6 | 0.4 | 7.8 | .0024 | -590 ▼ | |
| red hat | 65 | 287 | 14 | 115 | 140 | 18 | 2 | 0 | 0.0 | 6.5 | .0032 | -2 ▼ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | -14 ▼ |
| canonical | 4 | 24 | 3 | 6 | 10 | 5 | 0 | 0 | 0.0 | 5.5 | .0013 | +4 ▲ |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0039 | +5 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 15 | 37 | 8 | 18 | 11 | 0 | 56 | 11 | 29.7 | 7.5 | .0057 | +6 ▲ |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +20 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | -11 ▼ |
| fortinet | 13 | 22 | 6 | 6 | 10 | 0 | 28 | 5 | 22.7 | 7.3 | .0039 | +11 ▲ |
| f5 | 8 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | +2 ▲ |
| vmware | 8 | 12 | 1 | 8 | 2 | 1 | 7 | 1 | 8.3 | 8.2 | .0039 | +5 ▲ |
| ivanti | 2 | 11 | 4 | 5 | 2 | 0 | 25 | 5 | 45.5 | 8.8 | .3445 | -2 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 78 | 233 | 47 | 90 | 84 | 11 | 33 | 1 | 0.4 | 7.5 | .0058 | +4 ▲ |
| mozilla | 6 | 62 | 12 | 18 | 32 | 0 | 9 | 0 | 0.0 | 6.5 | .0026 | -43 ▼ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -4 ▼ |
| github | 5 | 11 | 1 | 2 | 8 | 0 | 0 | 0 | 0.0 | 6.0 | .0042 | +5 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -4 ▼ |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1 | 271 | 133 | 116 | 18 | 4 | 27 | 3 | 1.1 | 8.8 | .0040 | -241 ▼ |
| adobe | 94 | 238 | 26 | 103 | 105 | 4 | 19 | 3 | 1.3 | 7.6 | .0026 | -35 ▼ |
| ibm | 36 | 160 | 52 | 54 | 54 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +25 ▲ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 6 | 0 | 0.0 | 7.5 | .0037 | +5 ▲ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .7758 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | +10 ▲ |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| d-link | 1 | 13 | 0 | 5 | 3 | 5 | 3 | 0 | 0.0 | 6.0 | .0059 | -8 ▼ |
| abb | 1 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -5 ▼ |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 41 | 112 | 0 | 0 | 58 | 54 | 0 | 0 | 0.0 | 5.5 | .0033 | +4 ▲ |
| openclaw | 44 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -17 ▼ |
| dell | 37 | 93 | 5 | 42 | 43 | 3 | 2 | 1 | 1.1 | 7.0 | .0021 | +11 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | +20 ▲ |
| nvidia | 40 | 79 | 12 | 52 | 15 | 0 | 0 | 0 | 0.0 | 7.8 | .0037 | +34 ▲ |
| imagemagick | 32 | 73 | 1 | 5 | 55 | 12 | 0 | 0 | 0.0 | 5.3 | .0019 | +4 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -71 ▼ |
| itsourcecode | 14 | 67 | 0 | 0 | 19 | 48 | 0 | 0 | 0.0 | 2.1 | .0033 | -8 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE-2026-48282 | .4239 | 98.6 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 |
| Vendor | CVEs |
|---|---|
| microsoft | 655 |
| 500 | |
| linux | 458 |
| red hat | 126 |
| apache | 125 |
| adobe | 107 |
| ibm | 100 |
| capgo | 81 |
| sourcecodester | 53 |
| dell | 49 |
| Vendor | KEV |
|---|---|
| microsoft | 23 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| fortinet | 5 |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 56 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE-2026-46817 | Oracle Corporation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1704 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1704 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1704 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1704 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1704 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1704 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1704 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1704 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1704 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1704 |
EXPLOIT PUBLISHED — Sipeed PicoClaw: 9 CVEs (CVE-2026-16081, CVE-2026-16082, CVE-2026-16083, CVE-2026-16084, CVE-2026-16085, CVE-2026-16195, CVE-2026-16196, CVE-2026-16197, CVE-2026-16198). Public exploit references added.
EXPLOIT PUBLISHED — nextlevelbuilder GoClaw: 6 CVEs (CVE-2026-16119, CVE-2026-16120, CVE-2026-16121, CVE-2026-16122, CVE-2026-16123, CVE-2026-16124). Public exploit references added.
EXPLOIT PUBLISHED — SourceCodester Class and Exam Timetabling System: 4 CVEs (CVE-2026-16152, CVE-2026-16154, CVE-2026-16155, CVE-2026-16156). Public exploit references added.
EXPLOIT PUBLISHED — zevorn rt-claw: 4 CVEs (CVE-2026-16125, CVE-2026-16126, CVE-2026-16127, CVE-2026-16128). Public exploit references added.
EXPLOIT PUBLISHED — AstrBotDevs AstrBot: 3 CVEs (CVE-2026-16075, CVE-2026-16076, CVE-2026-16077). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-16088 (halo-dev halo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16130 (nearai ironclaw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16131 (itsourcecode Hospital Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16133 (LiuMengxuan04 MiniCode). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16194 (zhayujie CowAgent). Public exploit reference added.
DUE DATE PASSED — CVE-2026-15409 (SonicWall SMA1000). CISA remediation deadline was July 17, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-15410 (SonicWall SMA1000). CISA remediation deadline was July 17, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-56164 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 17, 2026; still in catalog.
How to read these box scores · glossary
80 CVEs published. 25 box scores, 55 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N P L L L 1.3 .0123 66.5 —
AFFECTED Product Versions Fixed MiniCode 0.1.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0083 54.8 —
AFFECTED Product Versions Fixed Avi Load Balancer 31.1.1 – —
TIMELINE May 20 Reserved by CNA Jul 18 Published (CNA: vmware)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0079 53.5 —
AFFECTED Product Versions Fixed Tomato 1.28 RT-N5x MIPSR2 Build 124 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0079 53.5 —
AFFECTED Product Versions Fixed Tomato 1.28 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0075 52.2 —
AFFECTED Product Versions Fixed OpenPLC_v3 unspecified —
TIMELINE Jun 9 Reserved by CNA Jul 18 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0073 51.6 —
AFFECTED Product Versions Fixed Tomato 1.28 RT-N5x MIPSR2 Build 124 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L N 5.5 .0072 51.1 —
AFFECTED Product Versions Fixed PicoClaw 0.2.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0071 50.6 —
AFFECTED Product Versions Fixed Apache Traffic Server 9.0.0 – —
TIMELINE Jul 2 Reserved by CNA Jul 18 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0066 49.0 —
AFFECTED Product Versions Fixed Avi Load Balancer 32.1.1 – —
TIMELINE May 20 Reserved by CNA Jul 18 Published (CNA: vmware)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0065 48.5 —
AFFECTED Product Versions Fixed surrealdb unspecified 1.1.0
TIMELINE Jul 18 Reserved by CNA Jul 18 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0064 47.8 —
AFFECTED Product Versions Fixed surrealdb unspecified 1.5.5 surrealdb unspecified 1.5.2
TIMELINE Jul 18 Reserved by CNA Jul 18 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N L L L 2.9 .0063 47.6 —
AFFECTED Product Versions Fixed PicoClaw 0.2.0 – —
TIMELINE Jul 18 Public exploit reference published Jul 18 Reserved by CNA Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H L N 8.8 .0056 44.0 —
AFFECTED Product Versions Fixed QueryWeaver unspecified 0.3.1
TIMELINE May 29 Reserved by CNA Jul 18 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0056 43.8 —
AFFECTED Product Versions Fixed PicoClaw 0.2.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0051 41.3 —
AFFECTED Product Versions Fixed rt-claw 0.1 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0051 40.9 —
AFFECTED Product Versions Fixed AstrBot 4.25.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0050 40.3 —
AFFECTED Product Versions Fixed Avi Load Balancer 32.1.1 – —
TIMELINE May 20 Reserved by CNA Jul 18 Published (CNA: vmware)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0050 40.3 —
AFFECTED Product Versions Fixed Avi Load Balancer 32.1.1 – —
TIMELINE May 20 Reserved by CNA Jul 18 Published (CNA: vmware)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0050 40.2 —
AFFECTED Product Versions Fixed rt-claw 0.1 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0050 40.2 —
AFFECTED Product Versions Fixed rt-claw 0.1 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0050 40.2 —
AFFECTED Product Versions Fixed rt-claw 0.1 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N N H 7.1 .0049 39.7 —
AFFECTED Product Versions Fixed surrealdb unspecified 1.1.0
TIMELINE Jul 18 Reserved by CNA Jul 18 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0049 39.6 —
AFFECTED Product Versions Fixed halo 2.24.0 – —
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N N N H 6.9 .0047 38.7 —
AFFECTED Product Versions Fixed surrealdb unspecified 2.1.0 surrealdb unspecified 2.1.0
TIMELINE Jun 8 Reserved by CNA Jul 18 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0046 38.2 —
AFFECTED Product Versions Fixed GoClaw 3.15.0-beta.0 – 3.15.0-beta.33
TIMELINE Jul 17 Reserved by CNA Jul 18 Public exploit reference published Jul 18 Published (CNA: VulDB)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-16194 | 2.1 | 38.2 | zhayujie | CowAgent | CWE-918 | zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery |
| CVE-2023-54366 | 8.7 | 38.0 | surrealdb | surrealdb | CWE-276 | SurrealDB before 1.0.1 Insecure Default Table Permissions |
| CVE-2024-58357 | 7.1 | 37.2 | surrealdb | surrealdb | CWE-248 | SurrealDB before 2.1.0 Denial of Service via rand::time() |
| CVE-2024-58359 | 7.1 | 37.2 | surrealdb | surrealdb | CWE-248 | SurrealDB before 2.1.0 Denial of Service via rand() Sorting |
| CVE-2024-58361 | 7.1 | 37.2 | surrealdb | surrealdb | CWE-248 | SurrealDB before 2.0.4 Denial of Service via Parser Exception |
| CVE-2024-58364 | 7.1 | 37.2 | surrealdb | surrealdb | CWE-248 | SurrealDB before 1.2.1 Denial of Service via Parsing Error |
| CVE-2024-58365 | 7.1 | 37.2 | surrealdb | surrealdb | CWE-248 | SurrealDB before 1.2.0 Denial of Service via Nonexistent Function |
| CVE-2024-58369 | 7.1 | 37.2 | surrealdb | surrealdb | CWE-248 | SurrealDB before 1.1.1 Denial of Service via Global Parameters |
| CVE-2026-16150 | 5.3 | 37.0 | RobinHerbots | Inputmask | CWE-94 | RobinHerbots Inputmask Internal Deep Merge Helper extend.js extendAliases pro… |
| CVE-2026-16151 | 5.3 | 37.0 | CartoDB | carto-api-client | CWE-94 | CartoDB carto-api-client filters.ts addFilter prototype pollution |
| CVE-2026-16117 | 10.0 | 36.7 | @fastify/http-proxy | @fastify/http-proxy | CWE-20 | @fastify/http-proxy vulnerable to prefix escape via URL-encoded characters |
| CVE-2026-16152 | 5.5 | 35.7 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection |
| CVE-2026-16154 | 5.5 | 35.7 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_room1.php sql injection |
| CVE-2026-53994 | 7.7 | 35.1 | ProFTPD Project | ProFTPD | CWE-122 | ProFTPD mod_sftp Heap Buffer Overflow via Unsigned Integer Underflow and Size… |
| CVE-2026-9323 | 9.2 | 34.8 | urwid | urwid | CWE-338 | Insecure PRNG and Information Exposure in urwid Web Display Backend |
| CVE-2026-16196 | 2.1 | 33.6 | Sipeed | PicoClaw | CWE-918 | Sipeed PicoClaw web_fetch web.go isPrivateOrRestrictedIP server-side request … |
| CVE-2026-16120 | 2.1 | 32.7 | nextlevelbuilder | GoClaw | CWE-706 | nextlevelbuilder GoClaw exec_approval.go extractBin name resolution |
| CVE-2026-16119 | 2.1 | 32.6 | nextlevelbuilder | GoClaw | CWE-285 | nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestA… |
| CVE-2026-47866 | 8.3 | 30.4 | VMware | Avi Load Balancer | CWE-863 | VMware Avi Load Balancer Authorization Bypass Vulnerability |
| CVE-2026-16075 | 2.1 | 30.1 | AstrBotDevs | AstrBot | CWE-285 | AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_cha… |
| CVE-2026-16121 | 2.1 | 29.3 | nextlevelbuilder | GoClaw | CWE-266 | nextlevelbuilder GoClaw exec_approval.go isSafeBin improper authorization |
| CVE-2026-16123 | 2.1 | 29.3 | nextlevelbuilder | GoClaw | CWE-862 | nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.Se… |
| CVE-2026-16195 | 2.1 | 29.3 | Sipeed | PicoClaw | CWE-285 | Sipeed PicoClaw Group Message wecom.go dispatchIncoming authorization |
| CVE-2026-16197 | 2.1 | 29.3 | Sipeed | PicoClaw | CWE-862 | Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization |
| CVE-2026-16155 | 2.0 | 27.4 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System schoolyr.php cross site scri… |
| CVE-2026-16156 | 2.0 | 27.4 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System forexam.php cross site scrip… |
| CVE-2024-58363 | 5.3 | 26.8 | surrealdb | surrealdb | CWE-287 | SurrealDB before 1.5.4 Authentication Bypass via Database Switch |
| CVE-2026-57857 | 5.1 | 26.0 | Flow | Flow Payment | CWE-79 | Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_me… |
| CVE-2026-16131 | 2.1 | 25.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System prescriptionrecord.php sql injection |
| CVE-2026-15631 | 10.0 | 24.9 | @fastify/http-proxy | @fastify/http-proxy | CWE-22 | @fastify/http-proxy vulnerable to prefix escape via WebSocket path traversal |
| CVE-2024-58366 | 9.0 | 23.7 | surrealdb | surrealdb | CWE-134 | SurrealDB before 1.1.1 Format String via Scripting Functions |
| CVE-2025-71397 | 7.1 | 23.2 | surrealdb | surrealdb | CWE-835 | SurrealDB before 2.2.2 CPU Exhaustion via nested FOR loops |
| CVE-2025-71396 | 2.3 | 23.2 | surrealdb | surrealdb | CWE-770 | SurrealDB before 2.2.2 Denial of Service via JavaScript Scripting |
| CVE-2026-16122 | 1.9 | 22.6 | nextlevelbuilder | GoClaw | CWE-285 | nextlevelbuilder GoClaw exec_approval.go matchesAllowlist authorization |
| CVE-2025-71391 | 7.1 | 22.1 | surrealdb | surrealdb | CWE-248 | SurrealDB before 2.2.2 Denial of Service via /sql endpoint |
| CVE-2026-47870 | 8.8 | 19.1 | VMware | Avi Load Balancer | CWE-269 | VMware Avi Load Balancer Privilege Escalation Vulnerability |
| CVE-2025-71393 | 6.0 | 17.4 | surrealdb | surrealdb | CWE-674 | SurrealDB before 2.2.2 Memory Exhaustion via Nested Functions |
| CVE-2025-71395 | 7.1 | 16.6 | surrealdb | surrealdb | CWE-789 | SurrealDB before 2.2.2 Memory Exhaustion via string::replace |
| CVE-2025-71390 | 5.8 | 15.8 | surrealdb | surrealdb | CWE-863 | SurrealDB before 2.3.6 deny-net Bypass via DNS Resolution |
| CVE-2025-71394 | 2.3 | 15.6 | surrealdb | surrealdb | CWE-22 | SurrealDB before 2.2.2 Local File Read via DEFINE ANALYZER |
| CVE-2026-16081 | 2.1 | 14.9 | Sipeed | PicoClaw | CWE-352 | Sipeed PicoClaw auth.go cross-site request forgery |
| CVE-2025-71392 | 9.4 | 14.7 | surrealdb | surrealdb | CWE-77 | SurrealDB before 2.2.2 SurrealQL Injection via export |
| CVE-2026-16158 | 10.0 | 13.7 | @fastify/reply-from | @fastify/reply-from | CWE-441 | @fastify/reply-from vulnerable to cross-upstream request routing via URL cach… |
| CVE-2026-9147 | 8.5 | 12.8 | scikit-hep | uproot | CWE-94 | uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata |
| CVE-2026-12228 | 5.4 | 12.1 | parisneo | parisneo/lollms | CWE-79 | Stored XSS in Direct Messages via Prompt Sharing in parisneo/lollms |
| CVE-2026-16077 | 1.9 | 11.1 | AstrBotDevs | AstrBot | CWE-59 | AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path lin… |
| CVE-2024-58367 | 7.1 | 10.9 | surrealdb | surrealdb | CWE-285 | SurrealDB before 2.0.4 Improper Authorization via SELECT Permissions |
| CVE-2026-57848 | 6.8 | 10.2 | stoatchat | Stoat for Android | CWE-926 | Stoat for Android Internal File Disclosure via Exported ShareTargetActivity U… |
| CVE-2024-58356 | 2.3 | 9.4 | surrealdb | surrealdb | CWE-276 | SurrealDB before 2.1.4 Permission Bypass via DEFINE TABLE OVERWRITE |
| CVE-2025-71398 | 5.8 | 8.8 | surrealdb | surrealdb | CWE-918 | SurrealDB before 2.2.2 SSRF via HTTP Redirect Bypass |
| CVE-2026-9734 | 4.3 | 8.7 | w3scloud | W3SC Elementor to Zoho CRM | CWE-352 | W3SC Elementor to Zoho CRM <= 2.2.0 - Cross-Site Request Forgery to Settings … |
| CVE-2026-16130 | 1.9 | 6.7 | nearai | ironclaw | CWE-59 | nearai ironclaw write_file path_utils.rs validate_path link following |
| CVE-2026-16085 | 1.9 | 5.2 | Sipeed | PicoClaw | CWE-829 | Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from … |
| CVE-2026-47868 | 7.8 | 3.3 | VMware | Avi Load Balancer | CWE-269 | VMware Avi Load Balancer Local Privilege Escalation Vulnerability |
| CVE-2026-16082 | 1.9 | 2.4 | Sipeed | PicoClaw | CWE-362 | Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-18 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.