boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, July 20, 2026 · all times UTC← 2026-07-19 · archive · 2026-07-21 →

Security Box Score — July 20, 2026

266 CVEs published, led by surrealdb (31).

266 CVEs published July 20, 2026: 48 critical, 99 high, 115 medium, 4 low; 0 in the KEV catalog at press time; 22 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 241 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published541717820——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

795 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux4791959178107959611120.17.8.0016+380 ▲
microsoft64614039697531814286231.67.8.0047+426 ▲
google1011366153620555387760.47.8.0024-583 ▼
red hat732951611714418200.06.5.0032-2 ▼
apple01042287228876.76.5.0032-14 ▼
canonical42436105000.05.5.0013+3 ▲
suse82141241000.08.5.0039+4 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1537818110561129.77.5.0057+6 ▲
ubiquiti2536142110338.38.8.0049+20 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear62300221000.04.6.0024-11 ▼
fortinet13226610028522.77.3.0039+11 ▲
f58165830416.38.6.0057+2 ▲
vmware8121821718.38.2.0039+5 ▲
ivanti211452025545.58.8.3445-2 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache88243529485113310.47.5.0058+2 ▲
mozilla6621218320900.06.5.0026-43 ▼
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-4 ▼
github5111280000.06.0.0042+5 ▲
docker070520000.08.2.0016-4 ▼
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle12711331161842731.18.8.0040-241 ▼
adobe952392610410541931.37.7.0026-34 ▼
ibm361605254540600.07.5.0036+25 ▲
progress101931420600.07.5.0037+5 ▲
solarwinds07232010457.17.5.4001-3 ▼
veeam042200100.09.0.0052-1 ▼
zohocorp031110000.08.4.01700
servicenow111000200.09.5.7758+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
siemens7161870000.07.6.00240
d-link2140545300.05.8.0064-7 ▼
abb170430000.07.2.0018-4 ▼
schneider electric060420000.07.8.0042-1 ▼
moxa050320000.07.0.0029-5 ▼
dahua030111000.06.9.0036-3 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester46117006156000.05.5.0033+9 ▲
openclaw441110583914000.07.0.0026-17 ▼
dell3793542433211.17.0.0021+10 ▲
capgo2283242381000.07.1.0037+5 ▲
nvidia40791252150000.07.8.0037+34 ▲
imagemagick3273155512000.05.3.0019+4 ▲
spring073231391000.06.5.0024-71 ▼
itsourcecode1669001950000.02.1.0033-6 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
CVE-2026-48282.423998.610.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-1540910.0.8366KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
Most disclosures (vendor)
VendorCVEs
linux893
microsoft647
google507
red hat126
apache123
adobe108
ibm100
capgo66
sourcecodester58
surrealdb57
Most KEV additions (YTD)
VendorKEV
microsoft23
cisco11
apple7
google6
fortinet5
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven64
PyPI5
npm5
NuGet3
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-25089Fortinet0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-45659Microsoft0
CVE-2026-46817Oracle Corporation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171706
CVE-2021-27102n/a2021-11-171706
CVE-2021-27101n/a2021-11-171706
CVE-2021-27103n/a2021-11-171706
CVE-2021-21017Adobe2021-11-171706
CVE-2021-28550Adobe2021-11-171706
CVE-2021-42013Apache Software Foundation2021-11-171706
CVE-2021-41773Apache Software Foundation2021-11-171706
CVE-2021-30858Apple2021-11-171706
CVE-2021-30860Apple2021-11-171706

Transactions

EXPLOIT PUBLISHED — Jovancoding Network-AI: 6 CVEs (CVE-2026-46701, CVE-2026-58413, CVE-2026-58414, CVE-2026-58481, CVE-2026-58482, CVE-2026-58484). Public exploit references added.

EXPLOIT PUBLISHED — axllent mailpit: 5 CVEs (CVE-2026-45709, CVE-2026-45711, CVE-2026-45712, CVE-2026-45713, CVE-2026-48824). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26197 (HDFGroup hdf5). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26199 (HDFGroup hdf5). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-28220 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-32286 (github.com/jackc/pgproto3/v2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47774 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64620 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64621 (FreeRDP). Public exploit reference added.

DUE DATE PASSED — CVE-2026-25089 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-39808 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-58644 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 19, 2026; still in catalog.

RESCORED — nextlevelbuilder GoClaw: 5 CVEs (CVE-2026-16120, CVE-2026-16121, CVE-2026-16122, CVE-2026-16124, CVE-2026-16199). CVSS rescored — before/after on each CVE page.

RESCORED — Sipeed PicoClaw: 5 CVEs (CVE-2026-16081, CVE-2026-16083, CVE-2026-16085, CVE-2026-16195, CVE-2026-16197). CVSS rescored — before/after on each CVE page.

RESCORED — zevorn rt-claw: 5 CVEs (CVE-2026-16126, CVE-2026-16127, CVE-2026-16128, CVE-2026-16200, CVE-2026-16201). CVSS rescored — before/after on each CVE page.

RESCORED — AstrBotDevs AstrBot: 3 CVEs (CVE-2026-16074, CVE-2026-16076, CVE-2026-16077). CVSS rescored — before/after on each CVE page.

RESCORED — Microsoft Windows 10 Version 1607: 3 CVEs (CVE-2026-49790, CVE-2026-54992, CVE-2026-54995). CVSS rescored — before/after on each CVE page.

RESCORED — SourceCodester Class and Exam Timetabling System: 3 CVEs (CVE-2026-16154, CVE-2026-16203, CVE-2026-16228). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). CVSS 6.2 → 7.5 (NVD).

RESCORED — CVE-2024-35260 (Microsoft Power Platform). CVSS 8 → 9.8 (NVD).

RESCORED — CVE-2026-16088 (halo-dev halo). CVSS 5.1 → 2 (NVD).

RESCORED — CVE-2026-16130 (nearai ironclaw). CVSS 4.8 → 1.9 (NVD).

RESCORED — CVE-2026-16133 (LiuMengxuan04 MiniCode). CVSS 2.3 → 1.3 (NVD).

RESCORED — CVE-2026-16194 (zhayujie CowAgent). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16205 (Pluck CMS). CVSS 4.8 → 1.9 (NVD).

RESCORED — CVE-2026-16209 (Gerapy). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-16211 (allegro). CVSS 2.1 → 1.2 (NVD).

RESCORED — CVE-2026-16212 (awesto django-shop). CVSS 2.3 → 1.3 (NVD).

RESCORED — CVE-2026-16215 (geex-arts django-jet). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-16217 (guohongze adminset). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16219 (Croogo CMS). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16222 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16225 (davenardella snap7). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-33845 (gnutls). CVSS 7.5 → 9.1 (NVD).

RESCORED — CVE-2026-3602 (IBM App Connect Enterprise). CVSS 4.7 → 5.5 (NVD).

RESCORED — CVE-2026-50374 (Microsoft Windows 10 Version 1809). CVSS 6.3 → 6.8 (NVD).

RESCORED — CVE-2026-54991 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD).

RESCORED — CVE-2026-57973 (Microsoft Windows Subsystem for Linux (WSL2)). CVSS 6.3 → 4.7 (NVD).

RESCORED — CVE-2026-7872 (IBM Langflow OSS). CVSS 7.5 → 8.1 (NVD).

Yesterday's Results

How to read these box scores · glossary

266 CVEs published. 25 box scores, 241 table rows — nothing truncated.

RooCodeInc Roo-Code — Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   H    7.7   .0177   76.4     —
AFFECTED
  Product   Versions     Fixed
  Roo-Code  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-184 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
RVC-Boss GPT-SoVITS — GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0175   76.1     —
AFFECTED
  Product     Versions     Fixed
  GPT-SoVITS  unspecified  —
TIMELINE
  Jul 18  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
D-Link DNS-320 upload.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0157   73.5     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 20  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
NLNETLABS Net::DNS — Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0144   71.1     —
AFFECTED
  Product   Versions     Fixed
  Net::DNS  unspecified  —
TIMELINE
  Jul 19  Reserved by CNA
  Jul 20  Published (CNA: CPANSec)
CWE-95 · CNA: CPANSec · CVSS v3.1 · 4 references · NVD status: Deferred
n/a n/a — Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive infor…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0125   67.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jul 20  Published (CNA: mitre)
CWE-23 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Deferred
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 — Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  L  H  H    9.0   .0119   65.6     —
AFFECTED
  Product                                             Versions     Fixed
  Red Hat Ansible Automation Platform 2.5 for RHEL 8  unspecified  0:3.49.63-2.el8ap
  Red Hat Ansible Automation Platform 2.5 for RHEL 9  unspecified  0:3.49.63-2.el9ap
  Red Hat Ansible Automation Platform 2.6 for RHEL 9  unspecified  0:3.49.63-2.el9ap
  Red Hat Satellite 6.16 for RHEL 8                   unspecified  0:3.49.39-2.el8pc
  Red Hat Satellite 6.16 for RHEL 8                   unspecified  0:3.49.39-2.el8pc
  Red Hat Satellite 6.16 for RHEL 9                   unspecified  0:3.49.39-2.el9pc
  Red Hat Satellite 6.16 for RHEL 9                   unspecified  0:3.49.39-2.el9pc
  Red Hat Satellite 6.17 for RHEL 9                   unspecified  0:3.63.21-2.el9pc
  Red Hat Satellite 6.17 for RHEL 9                   unspecified  0:3.63.21-2.el9pc
  Red Hat Satellite 6.18 for RHEL 9                   unspecified  0:3.73.30-2.el9pc
  + 8 more
TIMELINE
  Jun 19  Reserved by CNA
  Jul 20  Published (CNA: redhat)
CWE-22 · CNA: redhat · CVSS v3.1 · 10 references · NVD status: Awaiting Analysis
kvcache-ai ktransformers — ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0112   63.6     —
AFFECTED
  Product        Versions     Fixed
  ktransformers  unspecified  def0f9313d6e063b5c5ccdfa1f6707f7a40dfdca
TIMELINE
  Jul 18  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
EGroupware egroupware — Remote Code Execution Vulnerability in EGroupware
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0103   61.0     —
AFFECTED
  Product     Versions            Fixed
  egroupware  <= 26.2.20260216 –  —
TIMELINE
  Feb 24  Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-285 · CNA: GitHub_M · CVSS v4.0 · 1 reference · NVD status: Deferred
MB connect line mbCONNECT24 — Authenticated RCE in system_certificates view
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0094   58.1     —
AFFECTED
  Product            Versions  Fixed
  mbCONNECT24        1.0.0 –   —
  mymbCONNECT24      1.0.0 –   —
  mbCONNECT24        2.20.0 –  —
  mymbCONNECT24      2.20.0 –  —
  myREX24V2          1.0.0 –   —
  myREX24V2.virtual  1.0.0 –   —
  myREX24V2          2.20.0 –  —
  myREX24V2.virtual  2.20.0 –  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 20  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v4.0 · 2 references · NVD status: Deferred
EGroupware egroupware — Authenticated RCE via Malicious eTemplate Upload in EGroupware
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0093   58.0     —
AFFECTED
  Product     Versions   Fixed
  egroupware  <= 26.0 –  —
TIMELINE
  Apr 9   Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-78, CWE-95 · CNA: GitHub_M · CVSS v4.0 · 1 reference · NVD status: Deferred
ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0093   57.9     —
AFFECTED
  Product  Versions     Fixed
  proftpd  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-122 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Analyzed
Unknown Kirki — Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0091   57.3     —
AFFECTED
  Product  Versions     Fixed
  Kirki    unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 20  Published (CNA: WPScan)
CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
datacycle-engine dataCycle-CORE — dataCycle Public Markdown Path Traversal Via /docs/*path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0089   56.8     —
AFFECTED
  Product         Versions      Fixed
  dataCycle-CORE  <= 25.07.3 –  —
TIMELINE
  Mar 16  Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
neutrinolabs xrdp — xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0088   56.4     —
AFFECTED
  Product  Versions      Fixed
  xrdp     < 0.10.6.1 –  —
TIMELINE
  May 5   Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-122 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Analyzed
Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0085   55.5     —
AFFECTED
  Product  Versions                   Fixed
  AC10     16.03.10.09_multi_TDE01 –  —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 20  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0085   55.4     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.28.0
TIMELINE
  Jul 20  Public exploit reference published
  Jul 20  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-122 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
Apache Syncope: SQL injection vulnerability in Audit Events search
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0083   54.9     —
AFFECTED
  Product         Versions    Fixed
  Apache Syncope  3.0.0-M0 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-89 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Red Hat multicluster engine for Kubernetes 2.1 — Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  L    9.4   .0080   53.7     —
AFFECTED
  Product                                    Versions     Fixed
  multicluster engine for Kubernetes 2.1     unspecified  1784905766
  multicluster engine for Kubernetes 2.1     unspecified  1784905766
  multicluster engine for Kubernetes 2.11    unspecified  1784945966
  multicluster engine for Kubernetes 2.17    unspecified  1784856942
  multicluster engine for Kubernetes 2.6     unspecified  1784905804
  multicluster engine for Kubernetes 2.8     unspecified  1784905783
  multicluster engine for Kubernetes 2.9     unspecified  1784905769
  Red Hat OpenShift Container Platform 4.16  unspecified  1785534428
  Red Hat OpenShift Container Platform 4.17  unspecified  1784914869
  Red Hat OpenShift Container Platform 4.18  unspecified  1784912882
  + 32 more
TIMELINE
  Jul 20  Reserved by CNA
  Jul 20  Published (CNA: redhat)
CWE-306 · CNA: redhat · CVSS v3.1 · 17 references · NVD status: Awaiting Analysis
BeProduct beproduct-org-nestjs-auth — Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0076   52.7     —
AFFECTED
  Product                    Versions               Fixed
  beproduct-org-nestjs-auth  >= 0.1.2, <= 0.1.19 –  —
TIMELINE
  May 13  Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-506 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Apache Syncope: RCE via Groovy Sandbox bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0075   52.2     —
AFFECTED
  Product         Versions    Fixed
  Apache Syncope  3.0.0-M0 –  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-653 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0075   52.0     —
AFFECTED
  Product         Versions    Fixed
  Apache Syncope  3.0.0-M0 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-653 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
n/a n/a — An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and befor…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 20  Published (CNA: mitre)
CWE-94 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Deferred
Apache Syncope: User self-service privilege escalation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   50.0     —
AFFECTED
  Product         Versions    Fixed
  Apache Syncope  3.0.0-M0 –  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-269 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Trilby Media Grav CMS scheduler-webhook plugin — Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   L   L   L    6.3   .0069   49.9     —
AFFECTED
  Product                            Versions     Fixed
  Grav CMS scheduler-webhook plugin  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-303 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
Apache Syncope: Remote Code Execution via Scripted Connector
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.5     —
AFFECTED
  Product         Versions    Fixed
  Apache Syncope  3.0.0-M0 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-653 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-545387.549.3neutrinolabsxrdpCWE-835xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER
CVE-2026-415219.149.2neutrinolabsxrdpCWE-190xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass
CVE-2026-540519.949.1JovancodingNetwork-AICWE-78Network-AI has an an OS Command Injection issue
CVE-2026-586245.447.7Apache Software FoundationApache MINA SSHDCWE-20Apache MINA SSHD: Remote execution of JGit commands can write files on the se…
CVE-2026-488127.547.6freescout-help-deskfreescoutCWE-287FreeScout Allows Unauthenticated Access to Legacy Attachment Files
CVE-2026-573115.347.6JCDWindu CMSCWE-434Unrestricted Upload of File with Dangerous Type in Windu CMS
CVE-2026-510279.946.8n/an/aCWE-200An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive …
CVE-2026-412529.846.4neutrinolabsxrdpCWE-122xrdp: lib_palette_update Heap Buffer Overflow & RCE
CVE-2024-513119.846.0n/an/aCWE-121The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the…
CVE-2024-513129.846.0n/an/aCWE-121The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the…
CVE-2024-513139.846.0n/an/aCWE-121The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the…
CVE-2024-513149.846.0n/an/aCWE-121The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the…
CVE-2024-513159.846.0n/an/aCWE-121The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the…
CVE-2026-646259.346.0WWBNAVideoCWE-78AVideo before 29.0 OS Command Injection via execAsync
CVE-2026-350489.845.0PiwigoPiwigoCWE-20Piwigo RCE via PHP Code Injection into Config File in Installer
CVE-2026-614259.444.7balbooa.comGridbox extension for JoomlaCWE-288Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0
CVE-2026-159038.844.8GoogleChromeCWE-125Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 a…
CVE-2026-566237.144.6Apache Software FoundationApache MINA SSHDCWE-22Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows
CVE-2026-457976.444.6heyformheyformCWE-79HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload
CVE-2026-592386.944.1maalferPentestifyCWE-79Stored XSS in Pentestify via unsanitized finding images and report client logo
CVE-2026-81708.744.1Extreme NetworksSwitch Engine (EXOS)CWE-59ExtremeXOS Privilege Escalation via Symlink Following in File Utilities
CVE-2026-162359.843.7DRSTEVECrypt::PasswordCWE-338Crypt::Password versions through 0.28 for Perl generate insecure random value…
CVE-2026-163379.443.5dotCMSdotCMSCWE-269Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoin…
CVE-2026-250398.843.4Scilleparsec-cloudCWE-40The application evaluate UNC path in workspace name
CVE-2026-260803.743.3HAProxyHAProxyCWE-252HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop o…
CVE-2026-535959.443.1freescout-help-deskfreescoutCWE-178FreeScout vulnerable to anonymous account takeover via /user-setup empty invi…
CVE-2026-637578.742.8surrealdbsurrealdbCWE-306SurrealDB before 3.1.0 Session Hijacking via /rpc sessions
CVE-2026-449785.342.5neutrinolabsxrdpCWE-20xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-…
CVE-2026-573099.342.5JCDWindu CMSCWE-89Blind SQL Injection in Windu CMS
CVE-2026-513856.942.4n/an/aCWE-94An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a …
CVE-2026-600268.942.3themexpert.comQuix Page Builder Pro extension for JoomlaCWE-94Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix …
CVE-2026-535944.942.2freescout-help-deskfreescoutCWE-22FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path
CVE-2026-630917.142.1proftpdproftpdCWE-126ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser
CVE-2026-422105.341.9webminwebminCWE-287Webmin 2FA requirement bypass
CVE-2026-600278.741.7themexpert.comQuix Page Builder Pro extension for JoomlaCWE-22Joomla Extension - themexpert.com - Unauthenticated path traversal / file rea…
CVE-2026-552385.341.6neutrinolabsxrdpCWE-126xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads
CVE-2026-637478.741.5surrealdbsurrealdbCWE-248SurrealDB before 3.1.0 Denial of Service via malformed RPC use
CVE-2026-637608.741.5surrealdbsurrealdbCWE-674SurrealDB before 3.1.0 Denial of Service via JSON Parser
CVE-2026-564527.541.2Apache Software FoundationApache MINA SSHDCWE-22Apache MINA SSHD: Path traversal in SCP file reception
CVE-2026-535938.841.1freescout-help-deskfreescoutCWE-434FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete up…
CVE-2026-634298.640.9heyformheyformCWE-306HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files…
CVE-2026-162776.540.8Red HatRed Hat Enterprise Linux 10CWE-121Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
CVE-2026-637637.540.3surrealdbsurrealdbCWE-639SurrealDB before 2.5.0 Privilege Escalation via Future Fields
CVE-2026-637506.940.1surrealdbsurrealdbCWE-770SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket
CVE-2026-66567.540.0DRSTEVECrypt::PasswordCWE-208Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks
CVE-2026-351989.039.9heyformheyformCWE-79HeyForm vulnerable to stored XSS via form field titles
CVE-2024-513167.539.8n/an/aCWE-400The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in …
CVE-2026-510317.539.8n/an/aCWE-918FlareSolverr before version 3.4.7 contains a server-side request forgery (SSR…
CVE-2026-467155.339.8pallets-ecoFlask-Security-TooCWE-287Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OA…
CVE-2026-637377.139.7surrealdbsurrealdbCWE-674SurrealDB before 3.1.5 Denial of Service via deep operator chains
CVE-2026-451396.539.2ci4-cms-erpci4msCWE-73CI4MS Fileeditor allows deletion and rename of critical application files due…
CVE-2026-556456.539.2neutrinolabsxrdpCWE-125xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_d…
CVE-2026-637398.339.0surrealdbsurrealdbCWE-22SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER
CVE-2026-260814.839.0HAProxyHAProxyCWE-130HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check f…
CVE-2026-624188.138.7Apache Software FoundationApache SyncopeCWE-918Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources…
CVE-2026-637346.938.7surrealdbsurrealdbCWE-20SurrealDB before 3.2.0 Denial of Service via malformed SurrealML import
CVE-2026-163245.538.7Metasoft 美特软件MetaCRMCWE-284Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload
CVE-2026-546855.338.5gtsteffaniakfilebrowserCWE-208FileBrowser Quantum has Username Enumeration via Authentication Timing Side-C…
CVE-2026-342397.538.2chamilochamilo-lmsCWE-285Chamilo Authenticated Remote Code Execution
CVE-2026-128986.538.0UnknownAll-in-One WP Migration and BackupCWE-22All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Locati…
CVE-2026-549107.737.9gtsteffaniakfilebrowserCWE-22FileBrowser Quantum's path traversal issue in subtitle handler allows any aut…
CVE-2026-646229.337.4JovancodingNetwork-AICWE-862Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox
CVE-2026-135778.237.4CROMEDOMEDancer2CWE-338Dancer2 versions through 2.1.0 for Perl generate insecure session ids when re…
CVE-2026-637547.137.2surrealdbsurrealdbCWE-754SurrealDB before 3.1.0 Denial of Service via LIVE Query
CVE-2026-637597.137.2surrealdbsurrealdbCWE-674SurrealDB before 3.1.0 Denial of Service nested type annotations
CVE-2026-637626.037.2surrealdbsurrealdbCWE-476SurrealDB before v2.6.1 Denial of Service via scripting
CVE-2026-6142410.036.8dj-extensions.comDJ-Classifieds extension for JoomlaCWE-434Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload …
CVE-2026-6190010.036.8dj-extensions.comjDownloads extension for JoomlaCWE-434Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload …
CVE-2026-464108.736.8gtsteffaniakfilebrowserCWE-200FileBrowser Quantum: unauthenticated user share share info
CVE-2026-113498.636.9UnknownModern Event Calendar ProCWE-89Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection …
CVE-2026-159019.636.7GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a …
CVE-2026-465164.836.5mwtcmifrogmanCWE-79Frogman vulnerable to stored XSS in chat console formatter (escalation vector…
CVE-2026-558317.536.4nettynettyCWE-400Netty SPDY SETTINGS frame count materializes unbounded settings map
CVE-2026-398789.336.0chamilochamilo-lmsCWE-79Chamilo stored XSS via user registration leads to admin account takeover
CVE-2026-162525.535.7Beijing Shenzhou Shihan TechnologyMultimedia Integrated Business Display SystemCWE-74Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display Sys…
CVE-2026-637716.035.6vranaadminerCWE-113Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
CVE-2026-600316.935.4themexpert.comQuix Page Builder Pro extension for JoomlaCWE-200Joomla Extension - themexpert.com - Information disclosure in Quix Page Build…
CVE-2026-218248.835.1HCLSoftwareCommerceCWE-266A privilege escalation vulnerability affects HCL Commerce
CVE-2026-556395.335.1neutrinolabsxrdpCWE-125xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY process…
CVE-2026-558337.535.1nettynettyCWE-400Netty SPDY zlib header block continues decoded expansion after maxHeaderSize …
CVE-2026-488245.334.9axllentmailpitCWE-770Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /a…
CVE-2026-600349.434.5themexpert.comJMedia extension for JoomlaCWE-79Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extens…
CVE-2026-600288.634.5themexpert.comQuix Page Builder Pro extension for JoomlaCWE-79Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Bui…
CVE-2026-422185.334.5neutrinolabsxrdpCWE-204XRDP is vulnerable to a server timing attack, leading to user enumeration
CVE-2026-600295.134.5themexpert.comQuix Page Builder Pro extension for JoomlaCWE-79Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Bui…
CVE-2026-641947.534.4NLNETLABSNet::DNSCWE-674Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS …
CVE-2026-637316.334.3hyperdxiohyperdxCWE-918HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint
CVE-2026-445835.334.3PaymenterPaymenterCWE-918Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module
CVE-2026-442319.133.9bestpracticalrtCWE-200RT: Privilege escalation and information disclosure via REST 2.0 user collect…
CVE-2026-472766.533.9nanomqnanomqCWE-476NULL Pointer Dereference in REST API properties_parse via Malformed user_prop…
CVE-2026-600329.433.8themexpert.comJMedia extension for JoomlaCWE-434Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JM…
CVE-2026-600308.733.4themexpert.comQuix Page Builder Pro extension for JoomlaCWE-284Joomla Extension - themexpert.com - Broken Access Control for media managemen…
CVE-2026-624149.133.3joomlack.frPage Builder CK extension for JoomlaCWE-284Joomla Extension - joomlack.fr - Improper access control in Page Builder CK <…
CVE-2026-471988.533.1PaymenterPaymenterCWE-20Paymenter: URL parameter injection bypasses paid plan limits at checkout
CVE-2026-637696.333.0huginnhuginnCWE-918Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method
CVE-2026-535965.333.1freescout-help-deskfreescoutCWE-400FreeScout has unrestricted file upload without rate limiting that leads to re…
CVE-2026-471298.132.9pdovhomiljanextcrm-appCWE-862NextCRM has Broken Access Control in Server Actions that allows any authentic…
CVE-2026-637305.332.8hyperdxiohyperdxCWE-918HyperDX < 2.31.0 SSRF via Webhook Test Endpoint
CVE-2026-158999.632.7GoogleChromeCWE-416Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.1…
CVE-2026-159009.632.7GoogleChromeCWE-416Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 all…
CVE-2026-637467.132.7surrealdbsurrealdbCWE-200SurrealDB before 3.1.0 Permission Bypass via Graph Traversal
CVE-2026-88254.932.6UnknownElementor Website BuilderCWE-200Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API
CVE-2026-282209.132.4wazuhwazuhCWE-502Wazuh cluster DAPI arbitrary callable deserialization and RBAC context inject…
CVE-2026-328067.532.2datacycle-enginedataCycle-CORECWE-285dataCycle Authorization Bypass Via /remote_render
CVE-2026-328077.532.2datacycle-enginedataCycle-CORECWE-285dataCycle Public DataLink Text File Download Ignores Validity And Authorization
CVE-2026-457137.531.6axllentmailpitCWE-400Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA…
CVE-2026-600335.131.6themexpert.comJMedia extension for JoomlaCWE-918Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extens…
CVE-2026-131428.131.1UnknownSocial Login, Passkeys, Magic Link & Email OTPCWE-269Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeove…
CVE-2026-81698.730.9Extreme NetworksSwitch Engine (EXOS)CWE-338ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG
CVE-2026-646127.530.9Red HatRed Hat Enterprise Linux 10CWE-248Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort…
CVE-2026-523497.830.8n/an/aCWE-22Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa4…
CVE-2026-535918.630.2freescout-help-deskfreescoutCWE-287FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMA…
CVE-2026-162544.330.1Red HatRed Hat Advanced Cluster Security 4CWE-125Claircore: claircore: denial of service via out-of-bounds slice in claircore'…
CVE-2026-393857.129.9frappelmsCWE-288Frappe LMS enrollment bypass in paid courses via unrelated batch
CVE-2026-574947.129.9agenticmail@agenticmail/apiCWE-639AgenticMail: Cross-agent task authorization bypass in AgenticMail API
CVE-2026-637416.929.6surrealdbsurrealdbCWE-862SurrealDB before 3.1.0 Authentication Bypass via USE statement
CVE-2026-637569.229.5surrealdbsurrealdbCWE-362SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition
CVE-2026-452708.729.3ci4-cms-erpci4msCWE-79CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
CVE-2026-637358.629.4surrealdbsurrealdbCWE-639SurrealDB before 3.2.0 Authentication Bypass via Custom API
CVE-2026-510256.129.1n/an/aCWE-79Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 al…
CVE-2026-574958.228.9agenticmail@agenticmail/coreCWE-306AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume o…
CVE-2026-637557.128.7surrealdbsurrealdbCWE-863SurrealDB before 3.1.0 Permission Bypass via WHERE Clause
CVE-2026-637495.328.7surrealdbsurrealdbCWE-863SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT
CVE-2026-158136.528.6Red HatRed Hat Enterprise Linux 10CWE-787Kronosnet: kronosnet: memory corruption and out-of-bounds access via malforme…
CVE-2026-637407.128.4surrealdbsurrealdbCWE-863SurrealDB before 3.1.4 Array Element Permission Bypass
CVE-2026-631076.328.0LimeSurveyLimeSurveyCWE-918LimeSurvey SSRF via REST API Survey Template Host Header
CVE-2026-125927.527.8UnknownSlimStat AnalyticsCWE-79SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header
CVE-2026-328218.127.6datacycle-enginedataCycle-CORECWE-285API Collection Impersonation Via user_email And Missing Object- Level Authori…
CVE-2026-637535.327.6surrealdbsurrealdbCWE-613SurrealDB before 3.1.0 Authentication Bypass via LIVE Query
CVE-2026-159028.827.5GoogleChromeCWE-416Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a rem…
CVE-2026-328247.326.8datacycle-enginedataCycle-CORECWE-601dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Cont…
CVE-2026-328257.326.8datacycle-enginedataCycle-CORECWE-307dataCycle No Brute-Force Protection On Web And API Login Endpoints
CVE-2026-634285.826.8heyformheyformCWE-20HeyForm: completeSubmission persists submitter-supplied hidden fields verbati…
CVE-2026-637685.326.8calcomcal.diyCWE-601cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State
CVE-2026-127235.326.4UnknownKirkiCWE-862Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderatio…
CVE-2026-555507.126.3pdovhomiljanextcrm-appCWE-269NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users…
CVE-2026-452956.526.3freescout-help-deskfreescoutCWE-639FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and C…
CVE-2026-483897.826.2AdobeDNG SDKCWE-121DNG SDK | Stack-based Buffer Overflow (CWE-121)
CVE-2026-631025.325.9rConfigrConfig v8 CoreCWE-915rConfig Core < 8.2.8 Privilege Escalation via Users API role field
CVE-2026-162442.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System prescriptionorderreport.php sql injec…
CVE-2026-637485.324.9surrealdbsurrealdbCWE-209SurrealDB before 3.1.0 Information Disclosure via Error Messages
CVE-2026-637445.124.7surrealdbsurrealdbCWE-918SurrealDB before 3.1.5 SSRF via JWKS URL Redirect
CVE-2026-129006.424.3brainstormforceSpectra Legacy – Gutenberg BlocksCWE-79Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cro…
CVE-2026-352176.524.2nanomqnanomqCWE-125NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an AS…
CVE-2026-464289.124.1lettrelettreCWE-295lettre has TLS hostname verification disabled when using Boring TLS backend
CVE-2026-261975.924.1HDFGrouphdf5CWE-125Array full size, element count, and element size are not checked to make sure…
CVE-2026-646265.324.1WWBNAVideoCWE-918AVideo Encoder downloadURL SSRF via unpinned retry fallback
CVE-2026-555447.623.5pdovhomiljanextcrm-appCWE-284NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign D…
CVE-2026-637365.123.6surrealdbsurrealdbCWE-918SurrealDB before 3.2.0 SSRF via JWKS URL hostname resolution
CVE-2026-457118.223.3axllentmailpitCWE-22Mailpit: Path traversal & arbitrary file write in mailpit dump --http via att…
CVE-2026-637585.323.0surrealdbsurrealdbCWE-862SurrealDB before 3.1.0 Authorization Bypass via KILL Statement
CVE-2026-646219.322.4FreeRDPFreeRDPCWE-415FreeRDP before 3.28.0 Double-Free via selectedmonitors
CVE-2026-118685.322.4UnknownWP TravelCWE-862WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
CVE-2026-159048.821.8GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 all…
CVE-2026-261995.921.7HDFGrouphdf5CWE-124Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
CVE-2026-646198.721.5vastsaFileCodeBoxCWE-348FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
CVE-2026-637708.221.5glanceappglanceCWE-348Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
CVE-2026-129725.321.4UnknownPayPlus Payment GatewayCWE-284PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tamp…
CVE-2026-637425.321.2surrealdbsurrealdbCWE-863SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT
CVE-2026-637515.321.2surrealdbsurrealdbCWE-863SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch
CVE-2026-100818.821.1UnknownUnlimited Elements For ElementorCWE-79Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Go…
CVE-2026-566247.320.9Apache Software FoundationApache MINA SSHDCWE-295Apache MINA SSHD: SSH certificate options lack validations
CVE-2026-134325.420.7UnknownThumbPressCWE-862ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation
CVE-2026-637335.320.7surrealdbsurrealdbCWE-863SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause
CVE-2026-445855.420.4PaymenterPaymenterCWE-639Paymenter: Broken object level authorization via service reference manipulati…
CVE-2026-637385.320.3surrealdbsurrealdbCWE-863SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal
CVE-2026-98337.120.1UnknownTag Groups is the Advanced Way to Display Your Taxonomy TermsCWE-79Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
CVE-2026-107552.720.1UnknownAll in One SEOCWE-863All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration
CVE-2026-573106.319.9JCDWindu CMSCWE-916Weak password hashing in Windu CMS
CVE-2026-637525.319.9surrealdbsurrealdbCWE-285SurrealDB before 3.1.0 RELATE Statement Record Overwrite
CVE-2026-646238.819.7JovancodingNetwork-AICWE-347Network-AI before 5.13.4 Cryptographic Signature Verification Bypass
CVE-2026-471307.119.6pdovhomiljanextcrm-appCWE-639NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Ten…
CVE-2026-637615.319.6surrealdbsurrealdbCWE-327SurrealDB before 3.1.0 Algorithm Downgrade via ES512
CVE-2026-137244.319.6Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co.Corporate Training Management SystemCWE-602Business Logic Bypass in Gobito's Corporate Training Management System
CVE-2026-328226.119.4datacycle-enginedataCycle-CORECWE-80dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages
CVE-2026-157885.619.2mobyBuildKitCWE-59WCOW cache mount source selector resolves NTFS junctions outside of cache root
CVE-2026-472752.619.2nanomqnanomqCWE-476nanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to R…
CVE-2026-398797.118.6syslog-ngsyslog-ngCWE-150SQL injection in syslog-ng SQL destionation driver
CVE-2026-328194.318.7datacycle-enginedataCycle-CORECWE-285dataCycle User Directory Enumeration Via /users/search
CVE-2026-129736.518.3UnknownPayPlus Payment GatewayCWE-862PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Or…
CVE-2026-457095.818.0axllentmailpitCWE-918Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to…
CVE-2026-264836.117.7n/an/aCWE-79Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (X…
CVE-2026-442276.117.7bestpracticalrtCWE-79RT: Reflected Cross-Site Scripting via URL parameters
CVE-2026-442306.117.7bestpracticalrtCWE-79RT: Reflected Cross-Site Scripting in search results chart
CVE-2026-642068.817.2LinuxLinux—Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
CVE-2026-442285.416.8bestpracticalrtCWE-79RT: Stored Cross-Site Scripting via insufficient template escaping
CVE-2026-24456.116.4WSO2WSO2 API ManagerCWE-79Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products En…
CVE-2026-472558.216.3agenticmail@agenticmail/apiCWE-20AgenticMail API/storage and outbound relay hardening
CVE-2026-129707.116.3UnknownLearnPressCWE-79LearnPress < 4.4.1 - Reflected XSS via c_search
CVE-2026-637435.316.0surrealdbsurrealdbCWE-918SurrealDB before 3.1.0 Port-Specific Deny Rule Bypass via HTTP Redirect
CVE-2026-637455.316.0surrealdbsurrealdbCWE-639SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id
CVE-2026-457125.915.8axllentmailpitCWE-362Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth cr…
CVE-2026-619016.114.8hikashop.comHikashop extension for JoomlaCWE-601Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2
CVE-2026-442295.414.8bestpracticalrtCWE-79RT: Cross-Site Scripting via inline-served uploaded content
CVE-2026-133809.014.2VSeeClinicCWE-201VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTT…
CVE-2026-464158.214.1JasonLovesDoggocaddy-defenderCWE-284Caddy Defender trusted proxy client IP bypass
CVE-2026-67935.413.1Bifra Engineering Consulting Ltd.Q-smart NexT PollCWE-79Stored XSS in Bifra Engineering's Q-smart NexT Poll
CVE-2026-467017.612.7JovancodingNetwork-AICWE-346Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Defaul…
CVE-2026-123419.811.9SailPoint TechnologiesIdentityIQCWE-287SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability
CVE-2026-552195.311.5PaymenterPaymenterCWE-362Paymenter: Race condition in payWithCredit() enables credit double-spend
CVE-2026-133818.710.9VSeeClinicCWE-639VSee Clinic and API Insecure Direct Object Reference in File API Allows Unaut…
CVE-2026-584847.110.7JovancodingNetwork-AICWE-22Network-AI: Poisoned environment backup manifest allows arbitrary recursive d…
CVE-2026-637288.110.6gitleaksgitleaksCWE-1336Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Rep…
CVE-2026-584816.510.1JovancodingNetwork-AICWE-22Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside…
CVE-2026-584136.110.1JovancodingNetwork-AICWE-22EnvironmentManager.restore() backup ID path traversal copies arbitrary direct…
CVE-2026-584145.510.1JovancodingNetwork-AICWE-22Network-AI: EnvironmentManager.backup() follows symlinked directories and cop…
CVE-2026-535924.69.1freescout-help-deskfreescoutCWE-1321FreeScout vulnerable to prototype pollution in getQueryParam
CVE-2026-155885.38.8Red HatRed Hat Enterprise Linux 10CWE-770Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl lin…
CVE-2026-466714.48.8msiemensonenote.rsCWE-22Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows r…
CVE-2026-465557.18.5verygoodpluginswhatsapp-mcpCWE-22WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary…
CVE-2026-471445.58.0BKDDFSshamefileCWE-22Shamefile has an arbitrary file read via shamefile.yaml in shame next
CVE-2026-120807.37.6Red HatRed Hat Enterprise Linux 10CWE-61Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in …
CVE-2026-646248.57.6FreeRDPFreeRDPCWE-88FreeRDP RDP File Parser Remote Code Execution via CLI Options
CVE-2026-642055.56.6LinuxLinux—i2c: i801: fix hardware state machine corruption in error path
CVE-2026-159057.86.4GoogleChromeCWE-416Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a loc…
CVE-2026-333277.06.0libvipslibvipsCWE-190Possible integer overflow leading to potential heap-based buffer overflow
CVE-2026-355917.06.0libvipslibvipsCWE-122Possible heap-based buffer overflow when decoding TIFF image containing well-…
CVE-2026-445844.35.7PaymenterPaymenterCWE-345Paymenter doesn't reset email verification status after email change
CVE-2026-646506.35.5vercel@ai-sdk/harness-codexCWE-863AI SDK Codex Harness Tool Relay Authorization Bypass
CVE-2026-646516.35.5vercel@ai-sdk/harness-opencodeCWE-863AI SDK OpenCode Harness Tool Relay Authorization Bypass
CVE-2026-584825.95.3JovancodingNetwork-AICWE-352Network-AI: ApprovalInbox HTTP server has no authentication — anyone can appr…
CVE-2026-162467.34.9Bizerba SE & Co. KGBRAIN2CWE-276Insecure permission assignment due to execution of LogPathConfig.exe during s…
CVE-2026-471336.94.5craigjbassclearancekitCWE-294ClearanceKit's signed policy tables lack monotonic counter, allowing replay o…
CVE-2026-471346.94.5craigjbassclearancekitCWE-732ClearanceKit: Policy signing key in System Keychain has permissive ACL allowi…
CVE-2026-333286.84.1libvipslibvipsCWE-190Possible integer overflow on 32-bit systems when reading GIF images
CVE-2026-355906.84.1libvipslibvipsCWE-122Possible out-of-bounds read leading to crash when decoding well-crafted EXIF …
CVE-2026-127244.34.1UnknownKirkiCWE-345Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via k…
CVE-2026-507435.44.0ReviveAdserverCWE-352A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserv…
CVE-2026-641905.53.8LinuxLinuxCWE-476net: team: fix NULL pointer dereference in team_xmit during mode change
CVE-2026-162477.33.7Bizerba SE & Co. KG_connect.BRAINCWE-276Insecure permission overwrite due to execution of LogPathConfig.exe while ins…
CVE-2026-328234.33.7datacycle-enginedataCycle-CORECWE-352dataCycle State-Changing GET Endpoints Enable CSRF
CVE-2026-131565.43.4UnknownMailerSendCWE-352MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin…
CVE-2026-471286.12.8always-furthernonoCWE-863nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`
CVE-2026-641917.82.6LinuxLinuxCWE-125i2c: stub: Reject I2C block transfers with invalid length
CVE-2026-556267.32.5neutrinolabsxrdpCWE-287xrdp: No authentication required with Xvnc backend on RHEL 9
CVE-2026-107244.82.5UnknownReviews FeedCWE-345Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution v…
CVE-2026-641925.51.9LinuxLinuxCWE-476bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
CVE-2026-641887.81.9LinuxLinuxCWE-416net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
CVE-2026-641875.51.7LinuxLinuxCWE-476xfs: fail recovery on a committed log item with no regions
CVE-2026-642075.51.6LinuxLinuxCWE-476net/sched: dualpi2: fix GSO backlog accounting
CVE-2026-641897.80.8LinuxLinuxCWE-362netfilter: ipset: fix race between dump and ip_set_list resize

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-20 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.