AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H H 7.7 .0177 76.4 —
AFFECTED Product Versions Fixed Roo-Code unspecified —
TIMELINE Jul 15 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
266 CVEs published, led by surrealdb (31).
266 CVEs published July 20, 2026: 48 critical, 99 high, 115 medium, 4 low; 0 in the KEV catalog at press time; 22 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 241 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 5417 | 17820 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
795 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 479 | 1959 | 178 | 1079 | 596 | 1 | 11 | 2 | 0.1 | 7.8 | .0016 | +380 ▲ |
| microsoft | 646 | 1403 | 96 | 975 | 318 | 14 | 286 | 23 | 1.6 | 7.8 | .0047 | +426 ▲ |
| 101 | 1366 | 153 | 620 | 555 | 38 | 77 | 6 | 0.4 | 7.8 | .0024 | -583 ▼ | |
| red hat | 73 | 295 | 16 | 117 | 144 | 18 | 2 | 0 | 0.0 | 6.5 | .0032 | -2 ▼ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | -14 ▼ |
| canonical | 4 | 24 | 3 | 6 | 10 | 5 | 0 | 0 | 0.0 | 5.5 | .0013 | +3 ▲ |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0039 | +4 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 15 | 37 | 8 | 18 | 11 | 0 | 56 | 11 | 29.7 | 7.5 | .0057 | +6 ▲ |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +20 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | -11 ▼ |
| fortinet | 13 | 22 | 6 | 6 | 10 | 0 | 28 | 5 | 22.7 | 7.3 | .0039 | +11 ▲ |
| f5 | 8 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | +2 ▲ |
| vmware | 8 | 12 | 1 | 8 | 2 | 1 | 7 | 1 | 8.3 | 8.2 | .0039 | +5 ▲ |
| ivanti | 2 | 11 | 4 | 5 | 2 | 0 | 25 | 5 | 45.5 | 8.8 | .3445 | -2 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 88 | 243 | 52 | 94 | 85 | 11 | 33 | 1 | 0.4 | 7.5 | .0058 | +2 ▲ |
| mozilla | 6 | 62 | 12 | 18 | 32 | 0 | 9 | 0 | 0.0 | 6.5 | .0026 | -43 ▼ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -4 ▼ |
| github | 5 | 11 | 1 | 2 | 8 | 0 | 0 | 0 | 0.0 | 6.0 | .0042 | +5 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -4 ▼ |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1 | 271 | 133 | 116 | 18 | 4 | 27 | 3 | 1.1 | 8.8 | .0040 | -241 ▼ |
| adobe | 95 | 239 | 26 | 104 | 105 | 4 | 19 | 3 | 1.3 | 7.7 | .0026 | -34 ▼ |
| ibm | 36 | 160 | 52 | 54 | 54 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +25 ▲ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 6 | 0 | 0.0 | 7.5 | .0037 | +5 ▲ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .7758 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | +10 ▲ |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| d-link | 2 | 14 | 0 | 5 | 4 | 5 | 3 | 0 | 0.0 | 5.8 | .0064 | -7 ▼ |
| abb | 1 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -5 ▼ |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 46 | 117 | 0 | 0 | 61 | 56 | 0 | 0 | 0.0 | 5.5 | .0033 | +9 ▲ |
| openclaw | 44 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -17 ▼ |
| dell | 37 | 93 | 5 | 42 | 43 | 3 | 2 | 1 | 1.1 | 7.0 | .0021 | +10 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | +5 ▲ |
| nvidia | 40 | 79 | 12 | 52 | 15 | 0 | 0 | 0 | 0.0 | 7.8 | .0037 | +34 ▲ |
| imagemagick | 32 | 73 | 1 | 5 | 55 | 12 | 0 | 0 | 0.0 | 5.3 | .0019 | +4 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -71 ▼ |
| itsourcecode | 16 | 69 | 0 | 0 | 19 | 50 | 0 | 0 | 0.0 | 2.1 | .0033 | -6 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE-2026-48282 | .4239 | 98.6 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 |
| Vendor | CVEs |
|---|---|
| linux | 893 |
| microsoft | 647 |
| 507 | |
| red hat | 126 |
| apache | 123 |
| adobe | 108 |
| ibm | 100 |
| capgo | 66 |
| sourcecodester | 58 |
| surrealdb | 57 |
| Vendor | KEV |
|---|---|
| microsoft | 23 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| fortinet | 5 |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 64 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE-2026-46817 | Oracle Corporation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1706 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1706 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1706 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1706 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1706 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1706 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1706 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1706 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1706 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1706 |
EXPLOIT PUBLISHED — Jovancoding Network-AI: 6 CVEs (CVE-2026-46701, CVE-2026-58413, CVE-2026-58414, CVE-2026-58481, CVE-2026-58482, CVE-2026-58484). Public exploit references added.
EXPLOIT PUBLISHED — axllent mailpit: 5 CVEs (CVE-2026-45709, CVE-2026-45711, CVE-2026-45712, CVE-2026-45713, CVE-2026-48824). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-26197 (HDFGroup hdf5). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-26199 (HDFGroup hdf5). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-28220 (wazuh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-32286 (github.com/jackc/pgproto3/v2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47774 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64620 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64621 (FreeRDP). Public exploit reference added.
DUE DATE PASSED — CVE-2026-25089 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-39808 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-58644 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 19, 2026; still in catalog.
RESCORED — nextlevelbuilder GoClaw: 5 CVEs (CVE-2026-16120, CVE-2026-16121, CVE-2026-16122, CVE-2026-16124, CVE-2026-16199). CVSS rescored — before/after on each CVE page.
RESCORED — Sipeed PicoClaw: 5 CVEs (CVE-2026-16081, CVE-2026-16083, CVE-2026-16085, CVE-2026-16195, CVE-2026-16197). CVSS rescored — before/after on each CVE page.
RESCORED — zevorn rt-claw: 5 CVEs (CVE-2026-16126, CVE-2026-16127, CVE-2026-16128, CVE-2026-16200, CVE-2026-16201). CVSS rescored — before/after on each CVE page.
RESCORED — AstrBotDevs AstrBot: 3 CVEs (CVE-2026-16074, CVE-2026-16076, CVE-2026-16077). CVSS rescored — before/after on each CVE page.
RESCORED — Microsoft Windows 10 Version 1607: 3 CVEs (CVE-2026-49790, CVE-2026-54992, CVE-2026-54995). CVSS rescored — before/after on each CVE page.
RESCORED — SourceCodester Class and Exam Timetabling System: 3 CVEs (CVE-2026-16154, CVE-2026-16203, CVE-2026-16228). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). CVSS 6.2 → 7.5 (NVD).
RESCORED — CVE-2024-35260 (Microsoft Power Platform). CVSS 8 → 9.8 (NVD).
RESCORED — CVE-2026-16088 (halo-dev halo). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-16130 (nearai ironclaw). CVSS 4.8 → 1.9 (NVD).
RESCORED — CVE-2026-16133 (LiuMengxuan04 MiniCode). CVSS 2.3 → 1.3 (NVD).
RESCORED — CVE-2026-16194 (zhayujie CowAgent). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16205 (Pluck CMS). CVSS 4.8 → 1.9 (NVD).
RESCORED — CVE-2026-16209 (Gerapy). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16211 (allegro). CVSS 2.1 → 1.2 (NVD).
RESCORED — CVE-2026-16212 (awesto django-shop). CVSS 2.3 → 1.3 (NVD).
RESCORED — CVE-2026-16215 (geex-arts django-jet). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16217 (guohongze adminset). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16219 (Croogo CMS). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16222 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16225 (davenardella snap7). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-33845 (gnutls). CVSS 7.5 → 9.1 (NVD).
RESCORED — CVE-2026-3602 (IBM App Connect Enterprise). CVSS 4.7 → 5.5 (NVD).
RESCORED — CVE-2026-50374 (Microsoft Windows 10 Version 1809). CVSS 6.3 → 6.8 (NVD).
RESCORED — CVE-2026-54991 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2026-57973 (Microsoft Windows Subsystem for Linux (WSL2)). CVSS 6.3 → 4.7 (NVD).
RESCORED — CVE-2026-7872 (IBM Langflow OSS). CVSS 7.5 → 8.1 (NVD).
How to read these box scores · glossary
266 CVEs published. 25 box scores, 241 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H H 7.7 .0177 76.4 —
AFFECTED Product Versions Fixed Roo-Code unspecified —
TIMELINE Jul 15 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0175 76.1 —
AFFECTED Product Versions Fixed GPT-SoVITS unspecified —
TIMELINE Jul 18 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0157 73.5 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 20 Reserved by CNA Jul 20 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0144 71.1 —
AFFECTED Product Versions Fixed Net::DNS unspecified —
TIMELINE Jul 19 Reserved by CNA Jul 20 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0125 67.2 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 7 Reserved by CNA Jul 20 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C L H H 9.0 .0119 65.6 —
AFFECTED Product Versions Fixed Red Hat Ansible Automation Platform 2.5 for RHEL 8 unspecified 0:3.49.63-2.el8ap Red Hat Ansible Automation Platform 2.5 for RHEL 9 unspecified 0:3.49.63-2.el9ap Red Hat Ansible Automation Platform 2.6 for RHEL 9 unspecified 0:3.49.63-2.el9ap Red Hat Satellite 6.16 for RHEL 8 unspecified 0:3.49.39-2.el8pc Red Hat Satellite 6.16 for RHEL 8 unspecified 0:3.49.39-2.el8pc Red Hat Satellite 6.16 for RHEL 9 unspecified 0:3.49.39-2.el9pc Red Hat Satellite 6.16 for RHEL 9 unspecified 0:3.49.39-2.el9pc Red Hat Satellite 6.17 for RHEL 9 unspecified 0:3.63.21-2.el9pc Red Hat Satellite 6.17 for RHEL 9 unspecified 0:3.63.21-2.el9pc Red Hat Satellite 6.18 for RHEL 9 unspecified 0:3.73.30-2.el9pc + 8 more
TIMELINE Jun 19 Reserved by CNA Jul 20 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0112 63.6 —
AFFECTED Product Versions Fixed ktransformers unspecified def0f9313d6e063b5c5ccdfa1f6707f7a40dfdca
TIMELINE Jul 18 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0103 61.0 —
AFFECTED Product Versions Fixed egroupware <= 26.2.20260216 – —
TIMELINE Feb 24 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0094 58.1 —
AFFECTED Product Versions Fixed mbCONNECT24 1.0.0 – — mymbCONNECT24 1.0.0 – — mbCONNECT24 2.20.0 – — mymbCONNECT24 2.20.0 – — myREX24V2 1.0.0 – — myREX24V2.virtual 1.0.0 – — myREX24V2 2.20.0 – — myREX24V2.virtual 2.20.0 – —
TIMELINE Jul 2 Reserved by CNA Jul 20 Published (CNA: CERTVDE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0093 58.0 —
AFFECTED Product Versions Fixed egroupware <= 26.0 – —
TIMELINE Apr 9 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0093 57.9 —
AFFECTED Product Versions Fixed proftpd unspecified —
TIMELINE Jul 15 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0091 57.3 —
AFFECTED Product Versions Fixed Kirki unspecified —
TIMELINE Jun 24 Reserved by CNA Jul 20 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0089 56.8 —
AFFECTED Product Versions Fixed dataCycle-CORE <= 25.07.3 – —
TIMELINE Mar 16 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0088 56.4 —
AFFECTED Product Versions Fixed xrdp < 0.10.6.1 – —
TIMELINE May 5 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0085 55.5 —
AFFECTED Product Versions Fixed AC10 16.03.10.09_multi_TDE01 – —
TIMELINE Jul 20 Reserved by CNA Jul 20 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0085 55.4 —
AFFECTED Product Versions Fixed FreeRDP unspecified 3.28.0
TIMELINE Jul 20 Public exploit reference published Jul 20 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0083 54.9 —
AFFECTED Product Versions Fixed Apache Syncope 3.0.0-M0 – —
TIMELINE Jun 24 Reserved by CNA Jul 20 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H L 9.4 .0080 53.7 —
AFFECTED Product Versions Fixed multicluster engine for Kubernetes 2.1 unspecified 1784905766 multicluster engine for Kubernetes 2.1 unspecified 1784905766 multicluster engine for Kubernetes 2.11 unspecified 1784945966 multicluster engine for Kubernetes 2.17 unspecified 1784856942 multicluster engine for Kubernetes 2.6 unspecified 1784905804 multicluster engine for Kubernetes 2.8 unspecified 1784905783 multicluster engine for Kubernetes 2.9 unspecified 1784905769 Red Hat OpenShift Container Platform 4.16 unspecified 1785534428 Red Hat OpenShift Container Platform 4.17 unspecified 1784914869 Red Hat OpenShift Container Platform 4.18 unspecified 1784912882 + 32 more
TIMELINE Jul 20 Reserved by CNA Jul 20 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0076 52.7 —
AFFECTED Product Versions Fixed beproduct-org-nestjs-auth >= 0.1.2, <= 0.1.19 – —
TIMELINE May 13 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0075 52.2 —
AFFECTED Product Versions Fixed Apache Syncope 3.0.0-M0 – —
TIMELINE Jul 15 Reserved by CNA Jul 20 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0075 52.0 —
AFFECTED Product Versions Fixed Apache Syncope 3.0.0-M0 – —
TIMELINE Jun 9 Reserved by CNA Jul 20 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 8 Reserved by CNA Jul 20 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 50.0 —
AFFECTED Product Versions Fixed Apache Syncope 3.0.0-M0 – —
TIMELINE Jul 13 Reserved by CNA Jul 20 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N L L L 6.3 .0069 49.9 —
AFFECTED Product Versions Fixed Grav CMS scheduler-webhook plugin unspecified —
TIMELINE Jun 25 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0068 49.5 —
AFFECTED Product Versions Fixed Apache Syncope 3.0.0-M0 – —
TIMELINE Jun 9 Reserved by CNA Jul 20 Published (CNA: apache)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-54538 | 7.5 | 49.3 | neutrinolabs | xrdp | CWE-835 | xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER |
| CVE-2026-41521 | 9.1 | 49.2 | neutrinolabs | xrdp | CWE-190 | xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass |
| CVE-2026-54051 | 9.9 | 49.1 | Jovancoding | Network-AI | CWE-78 | Network-AI has an an OS Command Injection issue |
| CVE-2026-58624 | 5.4 | 47.7 | Apache Software Foundation | Apache MINA SSHD | CWE-20 | Apache MINA SSHD: Remote execution of JGit commands can write files on the se… |
| CVE-2026-48812 | 7.5 | 47.6 | freescout-help-desk | freescout | CWE-287 | FreeScout Allows Unauthenticated Access to Legacy Attachment Files |
| CVE-2026-57311 | 5.3 | 47.6 | JCD | Windu CMS | CWE-434 | Unrestricted Upload of File with Dangerous Type in Windu CMS |
| CVE-2026-51027 | 9.9 | 46.8 | n/a | n/a | CWE-200 | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive … |
| CVE-2026-41252 | 9.8 | 46.4 | neutrinolabs | xrdp | CWE-122 | xrdp: lib_palette_update Heap Buffer Overflow & RCE |
| CVE-2024-51311 | 9.8 | 46.0 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the… |
| CVE-2024-51312 | 9.8 | 46.0 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the… |
| CVE-2024-51313 | 9.8 | 46.0 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the… |
| CVE-2024-51314 | 9.8 | 46.0 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the… |
| CVE-2024-51315 | 9.8 | 46.0 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the… |
| CVE-2026-64625 | 9.3 | 46.0 | WWBN | AVideo | CWE-78 | AVideo before 29.0 OS Command Injection via execAsync |
| CVE-2026-35048 | 9.8 | 45.0 | Piwigo | Piwigo | CWE-20 | Piwigo RCE via PHP Code Injection into Config File in Installer |
| CVE-2026-61425 | 9.4 | 44.7 | balbooa.com | Gridbox extension for Joomla | CWE-288 | Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 |
| CVE-2026-15903 | 8.8 | 44.8 | Chrome | CWE-125 | Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 a… | |
| CVE-2026-56623 | 7.1 | 44.6 | Apache Software Foundation | Apache MINA SSHD | CWE-22 | Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows |
| CVE-2026-45797 | 6.4 | 44.6 | heyform | heyform | CWE-79 | HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload |
| CVE-2026-59238 | 6.9 | 44.1 | maalfer | Pentestify | CWE-79 | Stored XSS in Pentestify via unsanitized finding images and report client logo |
| CVE-2026-8170 | 8.7 | 44.1 | Extreme Networks | Switch Engine (EXOS) | CWE-59 | ExtremeXOS Privilege Escalation via Symlink Following in File Utilities |
| CVE-2026-16235 | 9.8 | 43.7 | DRSTEVE | Crypt::Password | CWE-338 | Crypt::Password versions through 0.28 for Perl generate insecure random value… |
| CVE-2026-16337 | 9.4 | 43.5 | dotCMS | dotCMS | CWE-269 | Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoin… |
| CVE-2026-25039 | 8.8 | 43.4 | Scille | parsec-cloud | CWE-40 | The application evaluate UNC path in workspace name |
| CVE-2026-26080 | 3.7 | 43.3 | HAProxy | HAProxy | CWE-252 | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop o… |
| CVE-2026-53595 | 9.4 | 43.1 | freescout-help-desk | freescout | CWE-178 | FreeScout vulnerable to anonymous account takeover via /user-setup empty invi… |
| CVE-2026-63757 | 8.7 | 42.8 | surrealdb | surrealdb | CWE-306 | SurrealDB before 3.1.0 Session Hijacking via /rpc sessions |
| CVE-2026-44978 | 5.3 | 42.5 | neutrinolabs | xrdp | CWE-20 | xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-… |
| CVE-2026-57309 | 9.3 | 42.5 | JCD | Windu CMS | CWE-89 | Blind SQL Injection in Windu CMS |
| CVE-2026-51385 | 6.9 | 42.4 | n/a | n/a | CWE-94 | An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a … |
| CVE-2026-60026 | 8.9 | 42.3 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-94 | Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix … |
| CVE-2026-53594 | 4.9 | 42.2 | freescout-help-desk | freescout | CWE-22 | FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path |
| CVE-2026-63091 | 7.1 | 42.1 | proftpd | proftpd | CWE-126 | ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser |
| CVE-2026-42210 | 5.3 | 41.9 | webmin | webmin | CWE-287 | Webmin 2FA requirement bypass |
| CVE-2026-60027 | 8.7 | 41.7 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-22 | Joomla Extension - themexpert.com - Unauthenticated path traversal / file rea… |
| CVE-2026-55238 | 5.3 | 41.6 | neutrinolabs | xrdp | CWE-126 | xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads |
| CVE-2026-63747 | 8.7 | 41.5 | surrealdb | surrealdb | CWE-248 | SurrealDB before 3.1.0 Denial of Service via malformed RPC use |
| CVE-2026-63760 | 8.7 | 41.5 | surrealdb | surrealdb | CWE-674 | SurrealDB before 3.1.0 Denial of Service via JSON Parser |
| CVE-2026-56452 | 7.5 | 41.2 | Apache Software Foundation | Apache MINA SSHD | CWE-22 | Apache MINA SSHD: Path traversal in SCP file reception |
| CVE-2026-53593 | 8.8 | 41.1 | freescout-help-desk | freescout | CWE-434 | FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete up… |
| CVE-2026-63429 | 8.6 | 40.9 | heyform | heyform | CWE-306 | HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files… |
| CVE-2026-16277 | 6.5 | 40.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() |
| CVE-2026-63763 | 7.5 | 40.3 | surrealdb | surrealdb | CWE-639 | SurrealDB before 2.5.0 Privilege Escalation via Future Fields |
| CVE-2026-63750 | 6.9 | 40.1 | surrealdb | surrealdb | CWE-770 | SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket |
| CVE-2026-6656 | 7.5 | 40.0 | DRSTEVE | Crypt::Password | CWE-208 | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks |
| CVE-2026-35198 | 9.0 | 39.9 | heyform | heyform | CWE-79 | HeyForm vulnerable to stored XSS via form field titles |
| CVE-2024-51316 | 7.5 | 39.8 | n/a | n/a | CWE-400 | The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in … |
| CVE-2026-51031 | 7.5 | 39.8 | n/a | n/a | CWE-918 | FlareSolverr before version 3.4.7 contains a server-side request forgery (SSR… |
| CVE-2026-46715 | 5.3 | 39.8 | pallets-eco | Flask-Security-Too | CWE-287 | Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OA… |
| CVE-2026-63737 | 7.1 | 39.7 | surrealdb | surrealdb | CWE-674 | SurrealDB before 3.1.5 Denial of Service via deep operator chains |
| CVE-2026-45139 | 6.5 | 39.2 | ci4-cms-erp | ci4ms | CWE-73 | CI4MS Fileeditor allows deletion and rename of critical application files due… |
| CVE-2026-55645 | 6.5 | 39.2 | neutrinolabs | xrdp | CWE-125 | xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_d… |
| CVE-2026-63739 | 8.3 | 39.0 | surrealdb | surrealdb | CWE-22 | SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER |
| CVE-2026-26081 | 4.8 | 39.0 | HAProxy | HAProxy | CWE-130 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check f… |
| CVE-2026-62418 | 8.1 | 38.7 | Apache Software Foundation | Apache Syncope | CWE-918 | Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources… |
| CVE-2026-63734 | 6.9 | 38.7 | surrealdb | surrealdb | CWE-20 | SurrealDB before 3.2.0 Denial of Service via malformed SurrealML import |
| CVE-2026-16324 | 5.5 | 38.7 | Metasoft 美特软件 | MetaCRM | CWE-284 | Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload |
| CVE-2026-54685 | 5.3 | 38.5 | gtsteffaniak | filebrowser | CWE-208 | FileBrowser Quantum has Username Enumeration via Authentication Timing Side-C… |
| CVE-2026-34239 | 7.5 | 38.2 | chamilo | chamilo-lms | CWE-285 | Chamilo Authenticated Remote Code Execution |
| CVE-2026-12898 | 6.5 | 38.0 | Unknown | All-in-One WP Migration and Backup | CWE-22 | All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Locati… |
| CVE-2026-54910 | 7.7 | 37.9 | gtsteffaniak | filebrowser | CWE-22 | FileBrowser Quantum's path traversal issue in subtitle handler allows any aut… |
| CVE-2026-64622 | 9.3 | 37.4 | Jovancoding | Network-AI | CWE-862 | Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox |
| CVE-2026-13577 | 8.2 | 37.4 | CROMEDOME | Dancer2 | CWE-338 | Dancer2 versions through 2.1.0 for Perl generate insecure session ids when re… |
| CVE-2026-63754 | 7.1 | 37.2 | surrealdb | surrealdb | CWE-754 | SurrealDB before 3.1.0 Denial of Service via LIVE Query |
| CVE-2026-63759 | 7.1 | 37.2 | surrealdb | surrealdb | CWE-674 | SurrealDB before 3.1.0 Denial of Service nested type annotations |
| CVE-2026-63762 | 6.0 | 37.2 | surrealdb | surrealdb | CWE-476 | SurrealDB before v2.6.1 Denial of Service via scripting |
| CVE-2026-61424 | 10.0 | 36.8 | dj-extensions.com | DJ-Classifieds extension for Joomla | CWE-434 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload … |
| CVE-2026-61900 | 10.0 | 36.8 | dj-extensions.com | jDownloads extension for Joomla | CWE-434 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload … |
| CVE-2026-46410 | 8.7 | 36.8 | gtsteffaniak | filebrowser | CWE-200 | FileBrowser Quantum: unauthenticated user share share info |
| CVE-2026-11349 | 8.6 | 36.9 | Unknown | Modern Event Calendar Pro | CWE-89 | Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection … |
| CVE-2026-15901 | 9.6 | 36.7 | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a … | |
| CVE-2026-46516 | 4.8 | 36.5 | mwtcmi | frogman | CWE-79 | Frogman vulnerable to stored XSS in chat console formatter (escalation vector… |
| CVE-2026-55831 | 7.5 | 36.4 | netty | netty | CWE-400 | Netty SPDY SETTINGS frame count materializes unbounded settings map |
| CVE-2026-39878 | 9.3 | 36.0 | chamilo | chamilo-lms | CWE-79 | Chamilo stored XSS via user registration leads to admin account takeover |
| CVE-2026-16252 | 5.5 | 35.7 | Beijing Shenzhou Shihan Technology | Multimedia Integrated Business Display System | CWE-74 | Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display Sys… |
| CVE-2026-63771 | 6.0 | 35.6 | vrana | adminer | CWE-113 | Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header |
| CVE-2026-60031 | 6.9 | 35.4 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-200 | Joomla Extension - themexpert.com - Information disclosure in Quix Page Build… |
| CVE-2026-21824 | 8.8 | 35.1 | HCLSoftware | Commerce | CWE-266 | A privilege escalation vulnerability affects HCL Commerce |
| CVE-2026-55639 | 5.3 | 35.1 | neutrinolabs | xrdp | CWE-125 | xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY process… |
| CVE-2026-55833 | 7.5 | 35.1 | netty | netty | CWE-400 | Netty SPDY zlib header block continues decoded expansion after maxHeaderSize … |
| CVE-2026-48824 | 5.3 | 34.9 | axllent | mailpit | CWE-770 | Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /a… |
| CVE-2026-60034 | 9.4 | 34.5 | themexpert.com | JMedia extension for Joomla | CWE-79 | Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extens… |
| CVE-2026-60028 | 8.6 | 34.5 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-79 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Bui… |
| CVE-2026-42218 | 5.3 | 34.5 | neutrinolabs | xrdp | CWE-204 | XRDP is vulnerable to a server timing attack, leading to user enumeration |
| CVE-2026-60029 | 5.1 | 34.5 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-79 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Bui… |
| CVE-2026-64194 | 7.5 | 34.4 | NLNETLABS | Net::DNS | CWE-674 | Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS … |
| CVE-2026-63731 | 6.3 | 34.3 | hyperdxio | hyperdx | CWE-918 | HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint |
| CVE-2026-44583 | 5.3 | 34.3 | Paymenter | Paymenter | CWE-918 | Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module |
| CVE-2026-44231 | 9.1 | 33.9 | bestpractical | rt | CWE-200 | RT: Privilege escalation and information disclosure via REST 2.0 user collect… |
| CVE-2026-47276 | 6.5 | 33.9 | nanomq | nanomq | CWE-476 | NULL Pointer Dereference in REST API properties_parse via Malformed user_prop… |
| CVE-2026-60032 | 9.4 | 33.8 | themexpert.com | JMedia extension for Joomla | CWE-434 | Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JM… |
| CVE-2026-60030 | 8.7 | 33.4 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-284 | Joomla Extension - themexpert.com - Broken Access Control for media managemen… |
| CVE-2026-62414 | 9.1 | 33.3 | joomlack.fr | Page Builder CK extension for Joomla | CWE-284 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK <… |
| CVE-2026-47198 | 8.5 | 33.1 | Paymenter | Paymenter | CWE-20 | Paymenter: URL parameter injection bypasses paid plan limits at checkout |
| CVE-2026-63769 | 6.3 | 33.0 | huginn | huginn | CWE-918 | Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method |
| CVE-2026-53596 | 5.3 | 33.1 | freescout-help-desk | freescout | CWE-400 | FreeScout has unrestricted file upload without rate limiting that leads to re… |
| CVE-2026-47129 | 8.1 | 32.9 | pdovhomilja | nextcrm-app | CWE-862 | NextCRM has Broken Access Control in Server Actions that allows any authentic… |
| CVE-2026-63730 | 5.3 | 32.8 | hyperdxio | hyperdx | CWE-918 | HyperDX < 2.31.0 SSRF via Webhook Test Endpoint |
| CVE-2026-15899 | 9.6 | 32.7 | Chrome | CWE-416 | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.1… | |
| CVE-2026-15900 | 9.6 | 32.7 | Chrome | CWE-416 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 all… | |
| CVE-2026-63746 | 7.1 | 32.7 | surrealdb | surrealdb | CWE-200 | SurrealDB before 3.1.0 Permission Bypass via Graph Traversal |
| CVE-2026-8825 | 4.9 | 32.6 | Unknown | Elementor Website Builder | CWE-200 | Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API |
| CVE-2026-28220 | 9.1 | 32.4 | wazuh | wazuh | CWE-502 | Wazuh cluster DAPI arbitrary callable deserialization and RBAC context inject… |
| CVE-2026-32806 | 7.5 | 32.2 | datacycle-engine | dataCycle-CORE | CWE-285 | dataCycle Authorization Bypass Via /remote_render |
| CVE-2026-32807 | 7.5 | 32.2 | datacycle-engine | dataCycle-CORE | CWE-285 | dataCycle Public DataLink Text File Download Ignores Validity And Authorization |
| CVE-2026-45713 | 7.5 | 31.6 | axllent | mailpit | CWE-400 | Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA… |
| CVE-2026-60033 | 5.1 | 31.6 | themexpert.com | JMedia extension for Joomla | CWE-918 | Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extens… |
| CVE-2026-13142 | 8.1 | 31.1 | Unknown | Social Login, Passkeys, Magic Link & Email OTP | CWE-269 | Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeove… |
| CVE-2026-8169 | 8.7 | 30.9 | Extreme Networks | Switch Engine (EXOS) | CWE-338 | ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG |
| CVE-2026-64612 | 7.5 | 30.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-248 | Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort… |
| CVE-2026-52349 | 7.8 | 30.8 | n/a | n/a | CWE-22 | Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa4… |
| CVE-2026-53591 | 8.6 | 30.2 | freescout-help-desk | freescout | CWE-287 | FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMA… |
| CVE-2026-16254 | 4.3 | 30.1 | Red Hat | Red Hat Advanced Cluster Security 4 | CWE-125 | Claircore: claircore: denial of service via out-of-bounds slice in claircore'… |
| CVE-2026-39385 | 7.1 | 29.9 | frappe | lms | CWE-288 | Frappe LMS enrollment bypass in paid courses via unrelated batch |
| CVE-2026-57494 | 7.1 | 29.9 | agenticmail | @agenticmail/api | CWE-639 | AgenticMail: Cross-agent task authorization bypass in AgenticMail API |
| CVE-2026-63741 | 6.9 | 29.6 | surrealdb | surrealdb | CWE-862 | SurrealDB before 3.1.0 Authentication Bypass via USE statement |
| CVE-2026-63756 | 9.2 | 29.5 | surrealdb | surrealdb | CWE-362 | SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition |
| CVE-2026-45270 | 8.7 | 29.3 | ci4-cms-erp | ci4ms | CWE-79 | CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule |
| CVE-2026-63735 | 8.6 | 29.4 | surrealdb | surrealdb | CWE-639 | SurrealDB before 3.2.0 Authentication Bypass via Custom API |
| CVE-2026-51025 | 6.1 | 29.1 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 al… |
| CVE-2026-57495 | 8.2 | 28.9 | agenticmail | @agenticmail/core | CWE-306 | AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume o… |
| CVE-2026-63755 | 7.1 | 28.7 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.0 Permission Bypass via WHERE Clause |
| CVE-2026-63749 | 5.3 | 28.7 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT |
| CVE-2026-15813 | 6.5 | 28.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Kronosnet: kronosnet: memory corruption and out-of-bounds access via malforme… |
| CVE-2026-63740 | 7.1 | 28.4 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.4 Array Element Permission Bypass |
| CVE-2026-63107 | 6.3 | 28.0 | LimeSurvey | LimeSurvey | CWE-918 | LimeSurvey SSRF via REST API Survey Template Host Header |
| CVE-2026-12592 | 7.5 | 27.8 | Unknown | SlimStat Analytics | CWE-79 | SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header |
| CVE-2026-32821 | 8.1 | 27.6 | datacycle-engine | dataCycle-CORE | CWE-285 | API Collection Impersonation Via user_email And Missing Object- Level Authori… |
| CVE-2026-63753 | 5.3 | 27.6 | surrealdb | surrealdb | CWE-613 | SurrealDB before 3.1.0 Authentication Bypass via LIVE Query |
| CVE-2026-15902 | 8.8 | 27.5 | Chrome | CWE-416 | Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a rem… | |
| CVE-2026-32824 | 7.3 | 26.8 | datacycle-engine | dataCycle-CORE | CWE-601 | dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Cont… |
| CVE-2026-32825 | 7.3 | 26.8 | datacycle-engine | dataCycle-CORE | CWE-307 | dataCycle No Brute-Force Protection On Web And API Login Endpoints |
| CVE-2026-63428 | 5.8 | 26.8 | heyform | heyform | CWE-20 | HeyForm: completeSubmission persists submitter-supplied hidden fields verbati… |
| CVE-2026-63768 | 5.3 | 26.8 | calcom | cal.diy | CWE-601 | cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State |
| CVE-2026-12723 | 5.3 | 26.4 | Unknown | Kirki | CWE-862 | Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderatio… |
| CVE-2026-55550 | 7.1 | 26.3 | pdovhomilja | nextcrm-app | CWE-269 | NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users… |
| CVE-2026-45295 | 6.5 | 26.3 | freescout-help-desk | freescout | CWE-639 | FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and C… |
| CVE-2026-48389 | 7.8 | 26.2 | Adobe | DNG SDK | CWE-121 | DNG SDK | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-63102 | 5.3 | 25.9 | rConfig | rConfig v8 Core | CWE-915 | rConfig Core < 8.2.8 Privilege Escalation via Users API role field |
| CVE-2026-16244 | 2.1 | 25.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System prescriptionorderreport.php sql injec… |
| CVE-2026-63748 | 5.3 | 24.9 | surrealdb | surrealdb | CWE-209 | SurrealDB before 3.1.0 Information Disclosure via Error Messages |
| CVE-2026-63744 | 5.1 | 24.7 | surrealdb | surrealdb | CWE-918 | SurrealDB before 3.1.5 SSRF via JWKS URL Redirect |
| CVE-2026-12900 | 6.4 | 24.3 | brainstormforce | Spectra Legacy – Gutenberg Blocks | CWE-79 | Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cro… |
| CVE-2026-35217 | 6.5 | 24.2 | nanomq | nanomq | CWE-125 | NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an AS… |
| CVE-2026-46428 | 9.1 | 24.1 | lettre | lettre | CWE-295 | lettre has TLS hostname verification disabled when using Boring TLS backend |
| CVE-2026-26197 | 5.9 | 24.1 | HDFGroup | hdf5 | CWE-125 | Array full size, element count, and element size are not checked to make sure… |
| CVE-2026-64626 | 5.3 | 24.1 | WWBN | AVideo | CWE-918 | AVideo Encoder downloadURL SSRF via unpinned retry fallback |
| CVE-2026-55544 | 7.6 | 23.5 | pdovhomilja | nextcrm-app | CWE-284 | NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign D… |
| CVE-2026-63736 | 5.1 | 23.6 | surrealdb | surrealdb | CWE-918 | SurrealDB before 3.2.0 SSRF via JWKS URL hostname resolution |
| CVE-2026-45711 | 8.2 | 23.3 | axllent | mailpit | CWE-22 | Mailpit: Path traversal & arbitrary file write in mailpit dump --http via att… |
| CVE-2026-63758 | 5.3 | 23.0 | surrealdb | surrealdb | CWE-862 | SurrealDB before 3.1.0 Authorization Bypass via KILL Statement |
| CVE-2026-64621 | 9.3 | 22.4 | FreeRDP | FreeRDP | CWE-415 | FreeRDP before 3.28.0 Double-Free via selectedmonitors |
| CVE-2026-11868 | 5.3 | 22.4 | Unknown | WP Travel | CWE-862 | WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation |
| CVE-2026-15904 | 8.8 | 21.8 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 all… | |
| CVE-2026-26199 | 5.9 | 21.7 | HDFGroup | hdf5 | CWE-124 | Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero |
| CVE-2026-64619 | 8.7 | 21.5 | vastsa | FileCodeBox | CWE-348 | FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers |
| CVE-2026-63770 | 8.2 | 21.5 | glanceapp | glance | CWE-348 | Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass |
| CVE-2026-12972 | 5.3 | 21.4 | Unknown | PayPlus Payment Gateway | CWE-284 | PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tamp… |
| CVE-2026-63742 | 5.3 | 21.2 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT |
| CVE-2026-63751 | 5.3 | 21.2 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch |
| CVE-2026-10081 | 8.8 | 21.1 | Unknown | Unlimited Elements For Elementor | CWE-79 | Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Go… |
| CVE-2026-56624 | 7.3 | 20.9 | Apache Software Foundation | Apache MINA SSHD | CWE-295 | Apache MINA SSHD: SSH certificate options lack validations |
| CVE-2026-13432 | 5.4 | 20.7 | Unknown | ThumbPress | CWE-862 | ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation |
| CVE-2026-63733 | 5.3 | 20.7 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause |
| CVE-2026-44585 | 5.4 | 20.4 | Paymenter | Paymenter | CWE-639 | Paymenter: Broken object level authorization via service reference manipulati… |
| CVE-2026-63738 | 5.3 | 20.3 | surrealdb | surrealdb | CWE-863 | SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal |
| CVE-2026-9833 | 7.1 | 20.1 | Unknown | Tag Groups is the Advanced Way to Display Your Taxonomy Terms | CWE-79 | Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter |
| CVE-2026-10755 | 2.7 | 20.1 | Unknown | All in One SEO | CWE-863 | All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration |
| CVE-2026-57310 | 6.3 | 19.9 | JCD | Windu CMS | CWE-916 | Weak password hashing in Windu CMS |
| CVE-2026-63752 | 5.3 | 19.9 | surrealdb | surrealdb | CWE-285 | SurrealDB before 3.1.0 RELATE Statement Record Overwrite |
| CVE-2026-64623 | 8.8 | 19.7 | Jovancoding | Network-AI | CWE-347 | Network-AI before 5.13.4 Cryptographic Signature Verification Bypass |
| CVE-2026-47130 | 7.1 | 19.6 | pdovhomilja | nextcrm-app | CWE-639 | NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Ten… |
| CVE-2026-63761 | 5.3 | 19.6 | surrealdb | surrealdb | CWE-327 | SurrealDB before 3.1.0 Algorithm Downgrade via ES512 |
| CVE-2026-13724 | 4.3 | 19.6 | Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. | Corporate Training Management System | CWE-602 | Business Logic Bypass in Gobito's Corporate Training Management System |
| CVE-2026-32822 | 6.1 | 19.4 | datacycle-engine | dataCycle-CORE | CWE-80 | dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages |
| CVE-2026-15788 | 5.6 | 19.2 | moby | BuildKit | CWE-59 | WCOW cache mount source selector resolves NTFS junctions outside of cache root |
| CVE-2026-47275 | 2.6 | 19.2 | nanomq | nanomq | CWE-476 | nanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to R… |
| CVE-2026-39879 | 7.1 | 18.6 | syslog-ng | syslog-ng | CWE-150 | SQL injection in syslog-ng SQL destionation driver |
| CVE-2026-32819 | 4.3 | 18.7 | datacycle-engine | dataCycle-CORE | CWE-285 | dataCycle User Directory Enumeration Via /users/search |
| CVE-2026-12973 | 6.5 | 18.3 | Unknown | PayPlus Payment Gateway | CWE-862 | PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Or… |
| CVE-2026-45709 | 5.8 | 18.0 | axllent | mailpit | CWE-918 | Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to… |
| CVE-2026-26483 | 6.1 | 17.7 | n/a | n/a | CWE-79 | Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (X… |
| CVE-2026-44227 | 6.1 | 17.7 | bestpractical | rt | CWE-79 | RT: Reflected Cross-Site Scripting via URL parameters |
| CVE-2026-44230 | 6.1 | 17.7 | bestpractical | rt | CWE-79 | RT: Reflected Cross-Site Scripting in search results chart |
| CVE-2026-64206 | 8.8 | 17.2 | Linux | Linux | — | Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock |
| CVE-2026-44228 | 5.4 | 16.8 | bestpractical | rt | CWE-79 | RT: Stored Cross-Site Scripting via insufficient template escaping |
| CVE-2026-2445 | 6.1 | 16.4 | WSO2 | WSO2 API Manager | CWE-79 | Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products En… |
| CVE-2026-47255 | 8.2 | 16.3 | agenticmail | @agenticmail/api | CWE-20 | AgenticMail API/storage and outbound relay hardening |
| CVE-2026-12970 | 7.1 | 16.3 | Unknown | LearnPress | CWE-79 | LearnPress < 4.4.1 - Reflected XSS via c_search |
| CVE-2026-63743 | 5.3 | 16.0 | surrealdb | surrealdb | CWE-918 | SurrealDB before 3.1.0 Port-Specific Deny Rule Bypass via HTTP Redirect |
| CVE-2026-63745 | 5.3 | 16.0 | surrealdb | surrealdb | CWE-639 | SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id |
| CVE-2026-45712 | 5.9 | 15.8 | axllent | mailpit | CWE-362 | Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth cr… |
| CVE-2026-61901 | 6.1 | 14.8 | hikashop.com | Hikashop extension for Joomla | CWE-601 | Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 |
| CVE-2026-44229 | 5.4 | 14.8 | bestpractical | rt | CWE-79 | RT: Cross-Site Scripting via inline-served uploaded content |
| CVE-2026-13380 | 9.0 | 14.2 | VSee | Clinic | CWE-201 | VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTT… |
| CVE-2026-46415 | 8.2 | 14.1 | JasonLovesDoggo | caddy-defender | CWE-284 | Caddy Defender trusted proxy client IP bypass |
| CVE-2026-6793 | 5.4 | 13.1 | Bifra Engineering Consulting Ltd. | Q-smart NexT Poll | CWE-79 | Stored XSS in Bifra Engineering's Q-smart NexT Poll |
| CVE-2026-46701 | 7.6 | 12.7 | Jovancoding | Network-AI | CWE-346 | Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Defaul… |
| CVE-2026-12341 | 9.8 | 11.9 | SailPoint Technologies | IdentityIQ | CWE-287 | SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability |
| CVE-2026-55219 | 5.3 | 11.5 | Paymenter | Paymenter | CWE-362 | Paymenter: Race condition in payWithCredit() enables credit double-spend |
| CVE-2026-13381 | 8.7 | 10.9 | VSee | Clinic | CWE-639 | VSee Clinic and API Insecure Direct Object Reference in File API Allows Unaut… |
| CVE-2026-58484 | 7.1 | 10.7 | Jovancoding | Network-AI | CWE-22 | Network-AI: Poisoned environment backup manifest allows arbitrary recursive d… |
| CVE-2026-63728 | 8.1 | 10.6 | gitleaks | gitleaks | CWE-1336 | Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Rep… |
| CVE-2026-58481 | 6.5 | 10.1 | Jovancoding | Network-AI | CWE-22 | Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside… |
| CVE-2026-58413 | 6.1 | 10.1 | Jovancoding | Network-AI | CWE-22 | EnvironmentManager.restore() backup ID path traversal copies arbitrary direct… |
| CVE-2026-58414 | 5.5 | 10.1 | Jovancoding | Network-AI | CWE-22 | Network-AI: EnvironmentManager.backup() follows symlinked directories and cop… |
| CVE-2026-53592 | 4.6 | 9.1 | freescout-help-desk | freescout | CWE-1321 | FreeScout vulnerable to prototype pollution in getQueryParam |
| CVE-2026-15588 | 5.3 | 8.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl lin… |
| CVE-2026-46671 | 4.4 | 8.8 | msiemens | onenote.rs | CWE-22 | Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows r… |
| CVE-2026-46555 | 7.1 | 8.5 | verygoodplugins | whatsapp-mcp | CWE-22 | WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary… |
| CVE-2026-47144 | 5.5 | 8.0 | BKDDFS | shamefile | CWE-22 | Shamefile has an arbitrary file read via shamefile.yaml in shame next |
| CVE-2026-12080 | 7.3 | 7.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-61 | Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in … |
| CVE-2026-64624 | 8.5 | 7.6 | FreeRDP | FreeRDP | CWE-88 | FreeRDP RDP File Parser Remote Code Execution via CLI Options |
| CVE-2026-64205 | 5.5 | 6.6 | Linux | Linux | — | i2c: i801: fix hardware state machine corruption in error path |
| CVE-2026-15905 | 7.8 | 6.4 | Chrome | CWE-416 | Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a loc… | |
| CVE-2026-33327 | 7.0 | 6.0 | libvips | libvips | CWE-190 | Possible integer overflow leading to potential heap-based buffer overflow |
| CVE-2026-35591 | 7.0 | 6.0 | libvips | libvips | CWE-122 | Possible heap-based buffer overflow when decoding TIFF image containing well-… |
| CVE-2026-44584 | 4.3 | 5.7 | Paymenter | Paymenter | CWE-345 | Paymenter doesn't reset email verification status after email change |
| CVE-2026-64650 | 6.3 | 5.5 | vercel | @ai-sdk/harness-codex | CWE-863 | AI SDK Codex Harness Tool Relay Authorization Bypass |
| CVE-2026-64651 | 6.3 | 5.5 | vercel | @ai-sdk/harness-opencode | CWE-863 | AI SDK OpenCode Harness Tool Relay Authorization Bypass |
| CVE-2026-58482 | 5.9 | 5.3 | Jovancoding | Network-AI | CWE-352 | Network-AI: ApprovalInbox HTTP server has no authentication — anyone can appr… |
| CVE-2026-16246 | 7.3 | 4.9 | Bizerba SE & Co. KG | BRAIN2 | CWE-276 | Insecure permission assignment due to execution of LogPathConfig.exe during s… |
| CVE-2026-47133 | 6.9 | 4.5 | craigjbass | clearancekit | CWE-294 | ClearanceKit's signed policy tables lack monotonic counter, allowing replay o… |
| CVE-2026-47134 | 6.9 | 4.5 | craigjbass | clearancekit | CWE-732 | ClearanceKit: Policy signing key in System Keychain has permissive ACL allowi… |
| CVE-2026-33328 | 6.8 | 4.1 | libvips | libvips | CWE-190 | Possible integer overflow on 32-bit systems when reading GIF images |
| CVE-2026-35590 | 6.8 | 4.1 | libvips | libvips | CWE-122 | Possible out-of-bounds read leading to crash when decoding well-crafted EXIF … |
| CVE-2026-12724 | 4.3 | 4.1 | Unknown | Kirki | CWE-345 | Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via k… |
| CVE-2026-50743 | 5.4 | 4.0 | Revive | Adserver | CWE-352 | A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserv… |
| CVE-2026-64190 | 5.5 | 3.8 | Linux | Linux | CWE-476 | net: team: fix NULL pointer dereference in team_xmit during mode change |
| CVE-2026-16247 | 7.3 | 3.7 | Bizerba SE & Co. KG | _connect.BRAIN | CWE-276 | Insecure permission overwrite due to execution of LogPathConfig.exe while ins… |
| CVE-2026-32823 | 4.3 | 3.7 | datacycle-engine | dataCycle-CORE | CWE-352 | dataCycle State-Changing GET Endpoints Enable CSRF |
| CVE-2026-13156 | 5.4 | 3.4 | Unknown | MailerSend | CWE-352 | MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin… |
| CVE-2026-47128 | 6.1 | 2.8 | always-further | nono | CWE-863 | nono: Sandbox escape on Linux via D-Bus: `systemd-run --user` |
| CVE-2026-64191 | 7.8 | 2.6 | Linux | Linux | CWE-125 | i2c: stub: Reject I2C block transfers with invalid length |
| CVE-2026-55626 | 7.3 | 2.5 | neutrinolabs | xrdp | CWE-287 | xrdp: No authentication required with Xvnc backend on RHEL 9 |
| CVE-2026-10724 | 4.8 | 2.5 | Unknown | Reviews Feed | CWE-345 | Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution v… |
| CVE-2026-64192 | 5.5 | 1.9 | Linux | Linux | CWE-476 | bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized |
| CVE-2026-64188 | 7.8 | 1.9 | Linux | Linux | CWE-416 | net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() |
| CVE-2026-64187 | 5.5 | 1.7 | Linux | Linux | CWE-476 | xfs: fail recovery on a committed log item with no regions |
| CVE-2026-64207 | 5.5 | 1.6 | Linux | Linux | CWE-476 | net/sched: dualpi2: fix GSO backlog accounting |
| CVE-2026-64189 | 7.8 | 0.8 | Linux | Linux | CWE-362 | netfilter: ipset: fix race between dump and ip_set_list resize |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-20 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.