boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, July 21, 2026 · all times UTC← 2026-07-20 · archive · 2026-07-22 →

Security Box Score — July 21, 2026

1477 CVEs published, led by Oracle Corporation (1097).

1477 CVEs published July 21, 2026: 310 critical, 658 high, 417 medium, 92 low; 4 in the KEV catalog at press time; 26 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 1077 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published689419297——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

819 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux4791959178107959611120.17.8.0016+379 ▲
microsoft64614039697531814286231.67.8.0047+426 ▲
google1151380156629556397760.47.8.0024-569 ▼
red hat933151612415421200.06.5.0032+18 ▲
apple01042287228876.76.5.0032-14 ▼
canonical72738115000.05.6.0014+6 ▲
suse82141241000.08.5.0039+4 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1537818110561129.77.5.0057+6 ▲
ubiquiti2536142110338.38.8.0049+20 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear62300221000.04.6.0024-11 ▼
fortinet13226610028522.77.3.0039+11 ▲
f58165830416.38.6.0057+2 ▲
vmware8121821718.38.2.0039+5 ▲
ivanti211452025545.58.8.3445-2 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache92247559585113310.47.5.0059+6 ▲
mozilla701265141340900.08.1.0031+21 ▲
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-4 ▼
github5111280000.06.0.0042+5 ▲
docker070520000.08.2.0016-4 ▼
wordpress22101022100.07.9.8879+2 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle10981368339646322612730.28.1.0036+856 ▲
adobe952392610410541931.37.7.0026-34 ▼
ibm361605254540600.07.5.0036+25 ▲
solarwinds15221633010418.29.1.0058+12 ▲
progress112031520600.07.5.0037+6 ▲
zohocorp251220000.07.1.0121+2 ▲
veeam042200100.09.0.0052-1 ▼
atlassian3303001300.08.0.0026+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
d-link8200596300.05.5.0105-1 ▼
siemens7161870000.07.6.00240
abb170430000.07.2.0018-4 ▼
schneider electric060420000.07.8.0042-1 ▼
moxa050320000.07.0.0029-5 ▼
dahua030111000.06.9.0036-3 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester49120006258000.05.5.0034+12 ▲
openclaw441110583914000.07.0.0026-17 ▼
dell3793542433211.17.0.0021+10 ▲
capgo2283242381000.07.1.0037-2 ▼
nvidia41801252160000.07.8.0037+35 ▲
imagemagick3273155512000.05.3.0019+2 ▲
spring073231391000.06.5.0024-71 ▼
itsourcecode1770001951000.02.1.0033-5 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.977999.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-45659.760899.58.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-1540910.0.8366KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
Most disclosures (vendor)
VendorCVEs
oracle1098
linux892
microsoft647
google521
red hat146
apache127
adobe108
ibm100
mozilla71
sourcecodester61
Most KEV additions (YTD)
VendorKEV
microsoft23
cisco11
apple7
google6
fortinet5
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
npm5
NuGet3
Packagist1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2026-0770Langflow0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-25089Fortinet0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171707
CVE-2021-27102n/a2021-11-171707
CVE-2021-27101n/a2021-11-171707
CVE-2021-27103n/a2021-11-171707
CVE-2021-21017Adobe2021-11-171707
CVE-2021-28550Adobe2021-11-171707
CVE-2021-42013Apache Software Foundation2021-11-171707
CVE-2021-41773Apache Software Foundation2021-11-171707
CVE-2021-30858Apple2021-11-171707
CVE-2021-30860Apple2021-11-171707

Transactions

EXPLOIT PUBLISHED — netty: 5 CVEs (CVE-2026-55831, CVE-2026-55833, CVE-2026-56816, CVE-2026-56819, CVE-2026-56820). Public exploit references added.

EXPLOIT PUBLISHED — strukturag libheif: 5 CVEs (CVE-2026-47178, CVE-2026-47247, CVE-2026-47251, CVE-2026-47254, CVE-2026-47709). Public exploit references added.

EXPLOIT PUBLISHED — fogproject: 4 CVEs (CVE-2026-47685, CVE-2026-47687, CVE-2026-47688, CVE-2026-47689). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2023-4692 (grub). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-4693 (Red Hat Enterprise Linux 8). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-11816 (keras-team/keras). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-13142 (Unknown Social Login, Passkeys, Magic Link & Email OTP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16324 (Metasoft 美特软件 MetaCRM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16372 (Mozilla Firefox). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24779 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25048 (mlc-ai xgrammar). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25960 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33236 (nltk). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47143 (capstone-engine capstone). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49978 (cure53 DOMPurify). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59197 (python-pillow Pillow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59204 (python-pillow Pillow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59732 (rclone). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63730 (hyperdxio hyperdx). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63731 (hyperdxio hyperdx). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63767 (kvcache-ai ktransformers). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63768 (calcom cal.diy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63770 (glanceapp glance). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63771 (vrana adminer). Public exploit reference added.

RESCORED — Microsoft Windows 10 Version 1607: 4 CVEs (CVE-2026-50377, CVE-2026-50485, CVE-2026-50489, CVE-2026-50500). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-3640 (Red Hat Enterprise Linux 6). CVSS 7 → 7.8 (NVD).

RESCORED — CVE-2023-4692 (grub). CVSS 7.5 → 7.8 (NVD).

RESCORED — CVE-2023-4693 (Red Hat Enterprise Linux 8). CVSS 5.3 → 4.6 (NVD).

RESCORED — CVE-2026-16014 (code-projects Hospital Bed Management System). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-16075 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16084 (Sipeed PicoClaw). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-16119 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16125 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-16131 (itsourcecode Hospital Management System). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16155 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).

RESCORED — CVE-2026-16156 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).

RESCORED — CVE-2026-16198 (Sipeed PicoClaw). CVSS 6.3 → 2.9 (NVD).

RESCORED — CVE-2026-16204 (zevorn rt-claw). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16210 (newpanjing simpleui). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-16216 (geex-arts django-jet). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16223 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16229 (itsourcecode Courier Management System). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16327 (D-Link DNS-320). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-22807 (vllm-project vllm). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2026-25960 (vllm-project vllm). CVSS 7.1 → 9.8 (NVD).

RESCORED — CVE-2026-56169 (Microsoft Windows Admin Center). CVSS 8.1 → 8.8 (NVD).

RESCORED — CVE-2026-7754 (IBM Langflow OSS). CVSS 7.7 → 6.5 (NVD).

ENRICHED — CVE-2026-46817 (Oracle E-Business Suite). Received CVSS 9.8 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

1477 CVEs published. 25 box scores and 375 table rows below; the remaining 1077 continue on page 2 · page 3 — every CVE is listed, nothing truncated.

WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9779   99.9   YES
AFFECTED
  Product    Versions  Fixed
  WordPress  6.9.0 –   —
TIMELINE
  Jul 17  Reserved by CNA
  Jul 21  Added to CISA KEV, due Jul 24
  Jul 21  Published (CNA: WPScan)
CWE-436 · CNA: WPScan · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due July 24, 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  N  N    5.9   .7979   99.6   YES
AFFECTED
  Product    Versions  Fixed
  WordPress  6.8.0 –   —
TIMELINE
  Jul 17  Reserved by CNA
  Jul 21  Added to CISA KEV, due Aug 4
  Jul 21  Published (CNA: WPScan)
CWE-89 · CNA: WPScan · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due August 4, 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .6342   99.1   YES
AFFECTED
  Product   Versions  Fixed
  Langflow  1.4.2 –   —
TIMELINE
  Jan 8   Reserved by CNA
  Jul 21  Added to CISA KEV, due Jul 24
  Jul 21  Published (CNA: zdi)
CWE-829 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Analyzed · KEV due July 24, 2026
DD-WRT DD-WRT
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0399   89.7   YES
AFFECTED
  Product  Versions     Fixed
  DD-WRT   unspecified  —
TIMELINE
  Feb 10  Reserved by CNA
  Jul 21  Added to CISA KEV, due Jul 24
  Jul 21  Published (CNA: mitre)
CWE-121 · CNA: mitre · CVSS v3.1 · 6 references · NVD status: Analyzed · KEV due July 24, 2026
Autel MaxiCharger Single — Unauthenticated Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0660   93.3     —
AFFECTED
  Product             Versions     Fixed
  MaxiCharger Single  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jul 21  Published (CNA: CyberDanube)
CWE-78 · CNA: CyberDanube · CVSS v4.0 · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 8 — Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   H   N   N  U  H  H  H    7.5   .0291   85.9     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat Enterprise Linux 8              unspecified  0:049-244.git20260529.el8_10
  Red Hat Hardened Images                 unspecified  109-7.hum1
  Red Hat Enterprise Linux 10             unspecified  —
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 7              unspecified  —
  Red Hat Enterprise Linux 9              unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: redhat)
CWE-78 · CNA: redhat · CVSS v3.1 · 6 references · NVD status: Awaiting Analysis
Autel MaxiCharger Single — Command Injection via Malicious OCPP Server
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0229   81.9     —
AFFECTED
  Product             Versions     Fixed
  MaxiCharger Single  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jul 21  Published (CNA: CyberDanube)
CWE-78 · CNA: CyberDanube · CVSS v4.0 · 1 reference · NVD status: Analyzed
Tenable, Inc. Security Center — Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0226   81.6     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  Patch SC202607.1
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: tenable)
CWE-78 · CNA: tenable · CVSS v4.0 · 1 reference · NVD status: Analyzed
Tenable, Inc. Security Center — Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0223   81.4     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  Patch SC202607.1
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: tenable)
CWE-78 · CNA: tenable · CVSS v4.0 · 1 reference · NVD status: Analyzed
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0213   80.6     —
AFFECTED
  Product  Versions                Fixed
  Serv-U   15.5.4 HF1 and below –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jul 21  Published (CNA: SolarWinds)
CWE-639 · CNA: SolarWinds · CVSS v3.1 · 2 references · NVD status: Analyzed
Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Gateway (ECOS) — Authenticated Command Injection allows arbitrary command execution in CLI Interface
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0165   74.7     —
AFFECTED
  Product                            Versions   Fixed
  EdgeConnect SD-WAN Gateway (ECOS)  9.4.0.0 –  —
TIMELINE
  May 7   Reserved by CNA
  Jul 21  Published (CNA: hpe)
CWE-77 · CNA: hpe · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
D-Link DNS-320 uploadify.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0157   73.5     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
D-Link DNS-320 save_ajax.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0157   73.5     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
D-Link DNS-320 multi_uploadify.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0157   73.5     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Zyxel AX7501-B1 firmware — A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Z…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0152   72.6     —
AFFECTED
  Product             Versions               Fixed
  AX7501-B1 firmware  <= 5.17(ABPC.7.2)C0 –  —
TIMELINE
  Apr 24  Reserved by CNA
  Jul 21  Published (CNA: Zyxel)
CWE-78 · CNA: Zyxel · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
QUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   P   L   L   L    1.3   .0149   72.0     —
AFFECTED
  Product          Versions  Fixed
  MiniCode-Python  0.1.0 –   0.1.0-rc1
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 10 references · NVD status: Deferred
D-Link DNS-320 uploadify.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0145   71.3     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
D-Link DNS-320 multi_uploadify.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0145   71.3     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Zohocorp ManageEngine ADSelfService Plus — Multi Factor Auth Bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  H  N    7.1   .0121   66.2     —
AFFECTED
  Product                          Versions     Fixed
  ManageEngine ADSelfService Plus  unspecified  —
TIMELINE
  Feb 25  Reserved by CNA
  Jul 21  Published (CNA: Zohocorp)
CWE-290 · CNA: Zohocorp · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
MervinPraison PraisonAI — PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0117   64.9     —
AFFECTED
  Product    Versions    Fixed
  PraisonAI  < 4.6.40 –  —
TIMELINE
  May 19  Reserved by CNA
  Jul 21  Published (CNA: GitHub_M)
CWE-95, CWE-306 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
oyatek MapSVG – Vector maps, Image maps, Google Maps — MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0109   63.0     —
AFFECTED
  Product                                        Versions     Fixed
  MapSVG – Vector maps, Image maps, Google Maps  unspecified  —
TIMELINE
  Feb 2   Reserved by CNA
  Jul 21  Published (CNA: Wordfence)
CWE-20 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
n/a jsforce — jsforce SFDX Connection Registry sfdx.js _execCommand os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0108   62.6     —
AFFECTED
  Product  Versions  Fixed
  jsforce  3.10.0 –  —
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0106   61.8     —
AFFECTED
  Product    Versions    Fixed
  DNS-120    20260205 –  —
  DNR-202L   20260205 –  —
  DNS-315L   20260205 –  —
  DNS-320    20260205 –  —
  DNS-320L   20260205 –  —
  DNS-320LW  20260205 –  —
  DNS-321    20260205 –  —
  DNR-322L   20260205 –  —
  DNS-323    20260205 –  —
  DNS-325    20260205 –  —
  + 10 more
TIMELINE
  Jul 21  Reserved by CNA
  Jul 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
frangoteam FUXA — FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0091   57.2     —
AFFECTED
  Product  Versions   Fixed
  FUXA     = 1.3.0 –  —
TIMELINE
  May 4   Reserved by CNA
  Jul 21  Published (CNA: GitHub_M)
CWE-863 · CNA: GitHub_M · CVSS v4.0 · 4 references · NVD status: Deferred
n/a n/a — Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and upd…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0089   56.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jul 21  Published (CNA: mitre)
CWE-22 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-473929.956.5MervinPraisonPraisonAICWE-184PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module l…
CVE-2026-477319.155.8NASA-AMMOSAIT-CoreCWE-22NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file app…
CVE-2026-439458.955.1frangoteamFUXACWE-94FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
CVE-2026-650089.355.0getgravgravCWE-94Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
CVE-2026-653158.754.1OllamaOllamaCWE-789Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Me…
CVE-2026-646089.854.0Apache Software FoundationApache ForyCWE-502Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatib…
CVE-2026-648789.453.7Tenable, Inc.Security CenterCWE-78Command Injection
CVE-2026-648249.353.7home-assistantHome Assistant CoreCWE-22Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
CVE-2026-283049.153.4SolarWindsServ-UCWE-284SolarWinds Serv-U Remote Code Execution Vulnerability
CVE-2026-283059.153.4SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-283089.153.4SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-473939.853.1MervinPraisonPraisonAICWE-306PraisonAI `deploy --type api` emits a Flask server with authentication disabl…
CVE-2026-646099.153.1Apache Software FoundationApache ForyCWE-125Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy…
CVE-2026-898410.052.7AutelMaxiCharger SingleCWE-94Unauthenticated RCE
CVE-2026-448808.852.3Hewlett Packard Enterprise (HPE)AOS-CXCWE-120Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Co…
CVE-2026-159578.752.2AWSaws-sdk-rustCWE-770Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserialize…
CVE-2026-306319.851.3n/an/aCWE-78An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309a…
CVE-2026-646069.851.2Apache Software FoundationApache ForyCWE-502Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted …
CVE-2026-507588.151.2n/an/aCWE-79Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allo…
CVE-2026-283029.151.0SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-600807.349.8Apache Software FoundationApache ForyCWE-416Apache Fory: Rust MetaString heap use-after-free
CVE-2026-507597.549.4n/an/aCWE-306An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privi…
CVE-2016-200969.349.3Kunshi Network Technology Co., Ltd.Linknat VOS3000CWE-89Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp
CVE-2026-306327.548.8n/an/aCWE-22Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted fol…
CVE-2026-31824.348.2ZohocorpManageEngine Endpoint CentralCWE-319Sensitive Data Exposure
CVE-2026-653179.248.0WeaviateVerbaCWE-918Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Ori…
CVE-2026-473969.848.0MervinPraisonPraisonAICWE-284PraisonAI call server exposes unauthenticated agent listing, invocation, and …
CVE-2026-474109.847.8MervinPraisonpraisonai-platformCWE-321praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-…
CVE-2026-507577.847.3n/an/aCWE-22Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allow…
CVE-2026-507559.847.0n/an/aCWE-290An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to ob…
CVE-2026-283149.147.1SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-634537.247.0Hewlett Packard Enterprise (HPE)AOS-CXCWE-120Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution i…
CVE-2026-163959.847.0MozillaFirefoxCWE-190Integer overflow in the Audio/Video component
CVE-2026-558518.746.6nettynettyCWE-400Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder …
CVE-2026-567458.746.6nettynettyCWE-400Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native M…
CVE-2026-449077.546.1Metareact-server-dom-turbopack—A denial of service vulnerability could be triggered by sending specially cra…
CVE-2026-448787.246.0Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateway (ECOS)CWE-377Authenticated Path Traversal allows Unauthorized Access in Web Interface
CVE-2026-591449.846.0EGORData::RingBuffer::SharedCWE-121Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer o…
CVE-2026-653189.245.8WeaviateVerbaCWE-918Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket…
CVE-2026-550828.745.1dhis2dhis2-coreCWE-89DHIS2 SQL injection in SQL View filter values
CVE-2026-650528.745.1Saturday DriveNinja FormsCWE-472Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_va…
CVE-2026-648259.045.1home-assistantHome Assistant CoreCWE-22Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload
CVE-2026-283129.144.9SolarWindsServ-UCWE-285SolarWinds Serv-U Privilege Escalation Vulnerability
CVE-2026-283219.144.9SolarWindsServ-UCWE-284SolarWinds Serv-U Broken Access Control Vulnerability
CVE-2026-473988.144.7MervinPraisonPraisonAICWE-94PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` i…
CVE-2026-439467.744.4frangoteamFUXACWE-863FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue
CVE-2026-163899.844.3MozillaFirefoxCWE-190Incorrect boundary conditions, integer overflow in the Libraries component in…
CVE-2026-524699.844.0n/an/aCWE-89SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to es…
CVE-2026-524709.844.0n/an/aCWE-89SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to es…
CVE-2026-524729.844.0n/an/aCWE-89SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to esca…
CVE-2026-591479.843.7EGORData::DisjointSet::SharedCWE-125Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds r…
CVE-2026-1636710.043.6MozillaFirefoxCWE-119Sandbox escape due to invalid pointer in the Disability Access APIs component
CVE-2026-163889.843.6MozillaFirefoxCWE-693Sandbox escape in the DOM: Networking component
CVE-2026-164109.843.6MozillaFirefoxCWE-843JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-602649.843.5Oracle CorporationOracle CoherenceCWE-200Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-466007.543.5Go standard librarynetCWE-125Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
CVE-2026-634547.243.4Hewlett Packard Enterprise (HPE)AOS-CXCWE-22Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in …
CVE-2026-602069.943.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-591399.142.9EGORData::ReqRep::SharedCWE-125Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds rea…
CVE-2026-591409.142.9EGORData::SortedSet::SharedCWE-125Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds …
CVE-2026-591419.142.9EGORData::RadixTree::SharedCWE-125Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds …
CVE-2026-591429.142.9EGORData::HashMap::SharedCWE-125Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds re…
CVE-2026-591459.142.9EGORData::Intern::SharedCWE-125Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds rea…
CVE-2026-650489.342.9Saturday DriveNinja FormsCWE-79Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fields…
CVE-2026-163939.142.8MozillaFirefoxCWE-119Incorrect boundary conditions in the Graphics: WebGPU component
CVE-2026-598436.542.2Red HatRed Hat Enterprise Linux 10CWE-835Libssh: libssh: denial of service via zero advertised channel packet size
CVE-2026-598446.542.2Red HatRed Hat Enterprise Linux 10CWE-789Libssh: libssh: denial of service via oversized sftp read length
CVE-2026-477089.342.1SepineTamstata-mcpCWE-77MCP-for-Stata: Command injection via log_file_name parameter in Stata command…
CVE-2026-474098.142.1MervinPraisonpraisonai-platformCWE-269praisonai-platform: Any workspace member can remove any other member (includi…
CVE-2026-474128.142.1MervinPraisonpraisonai-platformCWE-269praisonai-platform: Any workspace member can delete the entire workspace via …
CVE-2026-157248.742.0ProgressShareFile Storage Zones ControllerCWE-20Path traversal in Progress ShareFile Storage Zones Controller (SZC)
CVE-2026-476907.542.1meltanohubCWE-77MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Ac…
CVE-2026-94996.342.0QtQtCWE-125Out-of-bounds read in QTextCodec::codecForName() in Qt
CVE-2026-568167.541.9nettynettyCWE-400Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
CVE-2026-164129.841.8MozillaFirefoxCWE-119Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
CVE-2026-163539.841.6MozillaFirefoxCWE-416Invalid pointer in the DOM: Bindings (WebIDL) component
CVE-2026-163767.541.6MozillaFirefoxCWE-400Denial-of-service in the Graphics: WebGPU component
CVE-2026-164097.541.6MozillaFirefoxCWE-824Invalid pointer in the Security: PSM component
CVE-2026-524747.541.5n/an/aCWE-200An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive inf…
CVE-2026-283156.241.5SolarWindsServ-UCWE-79SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability
CVE-2026-89879.441.3AutelMaxiCharger SingleCWE-122Authenticated Heap Overflow
CVE-2026-653167.141.1xuxuelixxl-jobCWE-639xxl-job Cross-Job-Group Log Disclosure via Missing Authorization Check in /jo…
CVE-2026-4705610.041.0Oracle CorporationOracle Data IntegratorCWE-306Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa…
CVE-2026-6021710.041.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-6035810.041.0Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-6036010.041.0Oracle CorporationOracle Unified DirectoryCWE-306Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-6037910.041.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-6038910.041.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-6064410.041.0Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-352909.841.0Oracle CorporationOracle Application Testing SuiteCWE-284Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-468769.841.0Oracle CorporationOracle Application Testing SuiteCWE-284Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-469249.841.0Oracle CorporationOracle Application Testing SuiteCWE-284Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-469829.841.0Oracle CorporationOracle Retail Integration BusCWE-284Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail A…
CVE-2026-469839.841.0Oracle CorporationOracle Retail Integration BusCWE-284Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail A…
CVE-2026-470369.841.0Oracle CorporationSiebel CRM DevelopmentCWE-306Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (com…
CVE-2026-601739.841.0Oracle CorporationOracle BI PublisherCWE-284Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone…
CVE-2026-601979.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-601989.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-601999.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602009.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602029.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602049.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602059.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602099.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602109.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602129.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602159.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602169.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602199.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602219.841.0Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602249.841.0Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602259.841.0Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602269.841.0Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602279.841.0Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602289.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602299.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602309.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602329.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602349.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602369.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602409.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602419.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602429.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602449.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602469.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602479.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602509.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602519.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602539.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602549.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602569.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602579.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602589.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602599.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602629.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602699.841.0Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602729.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602749.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602759.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602769.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602789.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602799.841.0Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602809.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602859.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602869.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602879.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602889.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602899.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602909.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602919.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602929.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602949.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602969.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602979.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602989.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602999.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603009.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603029.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603069.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603089.841.0Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603289.841.0Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-603299.841.0Oracle CorporationOracle Identity ManagerCWE-306Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-603559.841.0Oracle CorporationOracle Access ManagerCWE-306Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-603629.841.0Oracle CorporationOracle Unified DirectoryCWE-306Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-603639.841.0Oracle CorporationOracle HTTP ServerCWE-284Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (…
CVE-2026-603649.841.0Oracle CorporationOracle HTTP ServerCWE-284Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle F…
CVE-2026-603749.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603759.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603769.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603789.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603809.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603849.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603859.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603869.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603879.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-603889.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-604359.841.0Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-604419.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-604429.841.0Oracle CorporationService Delivery PlatformCWE-306Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-604469.841.0Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604609.841.0Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604639.841.0Oracle CorporationWebCenter Content: ImagingCWE-306Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-605329.841.0Oracle CorporationOracle Identity Manager ConnectorCWE-269Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-605359.841.0Oracle CorporationOracle Identity Manager ConnectorCWE-306Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-605389.841.0Oracle CorporationOracle SOA SuiteCWE-306Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-605419.841.0Oracle CorporationOracle SOA SuiteCWE-284Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-605559.841.0Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-605669.841.0Oracle CorporationOracle WebCenter PortalCWE-269Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-609999.841.0Oracle CorporationOracle Data IntegratorCWE-284Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa…
CVE-2026-610659.841.0Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-611009.841.0Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-611299.841.0Oracle CorporationOracle Commerce PlatformCWE-287Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com…
CVE-2026-611319.841.0Oracle CorporationOracle Commerce PlatformCWE-284Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com…
CVE-2026-611459.841.0Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-611549.841.0Oracle CorporationOracle Commerce Guided Search Platform ServicesCWE-269Vulnerability in the Oracle Commerce Guided Search Platform Services product …
CVE-2026-611619.841.0Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-611679.841.0Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-611789.841.0Oracle CorporationOracle Agile Product Lifecycle Management for ProcessCWE-287Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr…
CVE-2026-611839.841.0Oracle CorporationOracle Agile Product Lifecycle Management for ProcessCWE-287Vulnerability in the Oracle Agile Product Lifecycle Management for Process pr…
CVE-2026-611969.841.0Oracle CorporationOracle Identity ManagerCWE-306Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-612339.841.0Oracle CorporationPeopleSoft Enterprise FIN Common Objects BrazilCWE-200Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product …
CVE-2026-612459.841.0Oracle CorporationPeopleSoft Enterprise FIN Manufacturing BrazilCWE-284Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product o…
CVE-2026-507567.540.9n/an/aCWE-1390An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to ob…
CVE-2026-524767.540.9n/an/aCWE-89SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to o…
CVE-2026-473998.840.9MervinPraisonpraisonai-platformCWE-284PraisonAI Platform workspace-scoped routes allow cross-workspace object acces…
CVE-2026-474058.840.9MervinPraisonpraisonai-platformCWE-284PraisonAI Platform missing role checks let any workspace member become owner …
CVE-2026-653198.740.9FeedbinFeedbinCWE-306Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/…
CVE-2026-117678.840.8UnknownFree Theme Builder for ElementorCWE-79CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form
CVE-2026-159276.840.7Red HatRed Hat Quay 3.1CWE-918Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference wit…
CVE-2026-283069.140.2SolarWindsServ-UCWE-284SolarWinds Serv-U Privilege Escalation Vulnerability
CVE-2026-283079.140.2SolarWindsServ-UCWE-284SolarWinds Serv-U Privilege Escalation Vulnerability
CVE-2026-283099.140.2SolarWindsServ-UCWE-862SolarWinds Serv-U Broken Access Control Vulnerability
CVE-2026-283109.140.2SolarWindsServ-UCWE-862SolarWinds Serv-U Privilege Escalation Vulnerability
CVE-2026-283139.140.2SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-283179.140.2SolarWindsServ-UCWE-639SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-611309.140.2Oracle CorporationOracle Commerce PlatformCWE-284Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com…
CVE-2026-611559.140.2Oracle CorporationOracle Commerce Guided Search Platform ServicesCWE-284Vulnerability in the Oracle Commerce Guided Search Platform Services product …
CVE-2026-164119.840.1MozillaFirefoxCWE-119Memory safety bugs fixed in Firefox 153
CVE-2026-650516.940.0Saturday DriveNinja FormsCWE-602Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadat…
CVE-2026-473948.739.9MervinPraisonPraisonAICWE-22PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.…
CVE-2026-612359.139.6Oracle CorporationPeopleSoft Enterprise HCM Global Payroll SwitzerlandCWE-284Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland pro…
CVE-2026-625469.139.6Oracle CorporationOracle Applications FrameworkCWE-284Vulnerability in the Oracle Applications Framework product of Oracle E-Busine…
CVE-2026-469547.239.6Oracle CorporationOracle Human ResourcesCWE-284Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit…
CVE-2026-469887.239.6Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-470057.239.6Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-470067.239.6Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-601537.239.6Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-603357.239.6Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-603407.239.6Oracle CorporationOracle Project CostingCWE-269Vulnerability in the Oracle Project Costing product of Oracle E-Business Suit…
CVE-2026-603457.239.6Oracle CorporationOracle JDeveloperCWE-284Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c…
CVE-2026-603967.239.6Oracle CorporationOracle GoldenGateCWE-306Vulnerability in Oracle GoldenGate (component: Distribution Server executable…
CVE-2026-604187.239.6Oracle CorporationOracle Unified DirectoryCWE-269Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-604667.239.6Oracle CorporationWebCenter Content: ImagingCWE-284Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-605027.239.6Oracle CorporationWebCenter Content: ImagingCWE-284Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Midd…
CVE-2026-605197.239.6Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-605467.239.6Oracle CorporationOracle SOA SuiteCWE-269Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-605767.239.6Oracle CorporationOracle Enterprise Command Center FrameworkCWE-269Vulnerability in the Oracle Enterprise Command Center Framework product of Or…
CVE-2026-607347.239.6Oracle CorporationOracle Trading CommunityCWE-284Vulnerability in the Oracle Trading Community product of Oracle E-Business Su…
CVE-2026-607557.239.6Oracle CorporationOracle AssetsCWE-284Vulnerability in the Oracle Assets product of Oracle E-Business Suite (compon…
CVE-2026-607867.239.6Oracle CorporationOracle ReceivablesCWE-284Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c…
CVE-2026-607877.239.6Oracle CorporationOracle ReceivablesCWE-284Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (c…
CVE-2026-608137.239.6Oracle CorporationOracle iStoreCWE-284Vulnerability in the Oracle iStore product of Oracle E-Business Suite (compon…
CVE-2026-608287.239.6Oracle CorporationOracle Interaction BlendingCWE-284Vulnerability in the Oracle Interaction Blending product of Oracle E-Business…
CVE-2026-608367.239.6Oracle CorporationOracle HCM Common ArchitectureCWE-269Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Busin…
CVE-2026-608457.239.6Oracle CorporationOracle Mobile Application ServerCWE-284Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus…
CVE-2026-609007.239.6Oracle CorporationOracle HCM Configuration WorkbenchCWE-269Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-B…
CVE-2026-609107.239.6Oracle CorporationOracle Property ManagerCWE-284Vulnerability in the Oracle Property Manager product of Oracle E-Business Sui…
CVE-2026-609187.239.6Oracle CorporationOracle Shipping ExecutionCWE-269Vulnerability in the Oracle Shipping Execution product of Oracle E-Business S…
CVE-2026-609257.239.6Oracle CorporationOracle Public Sector PayrollCWE-269Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines…
CVE-2026-609267.239.6Oracle CorporationOracle Public Sector PayrollCWE-284Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Busines…
CVE-2026-610067.239.6Oracle CorporationOracle Process Manufacturing LogisticsCWE-269Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle…
CVE-2026-610257.239.6Oracle CorporationOracle iRecruitmentCWE-284Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (…
CVE-2026-610277.239.6Oracle CorporationOracle Cost ManagementCWE-284Vulnerability in the Oracle Cost Management product of Oracle E-Business Suit…
CVE-2026-610357.239.6Oracle CorporationOracle Financials for the AmericasCWE-284Vulnerability in the Oracle Financials for the Americas product of Oracle E-B…
CVE-2026-610397.239.6Oracle CorporationOracle Advanced Supply Chain PlanningCWE-284Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle …
CVE-2026-610687.239.6Oracle CorporationPeopleSoft Enterprise FIN Billing ArgentinaCWE-284Vulnerability in the PeopleSoft Enterprise FIN Billing Argentina product of O…
CVE-2026-611077.239.6Oracle CorporationOracle Applications DBACWE-269Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui…
CVE-2026-611157.239.6Oracle CorporationOracle Order ManagementCWE-284Vulnerability in the Oracle Order Management product of Oracle E-Business Sui…
CVE-2026-612857.239.6Oracle CorporationOracle Process Manufacturing SystemsCWE-306Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E…
CVE-2026-613147.239.6Oracle CorporationOracle EDI GatewayCWE-284Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (c…
CVE-2026-613367.239.6Oracle CorporationOracle Lease and Finance ManagementCWE-269Vulnerability in the Oracle Lease and Finance Management product of Oracle E-…
CVE-2026-624667.239.6Oracle CorporationOracle Human ResourcesCWE-284Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit…
CVE-2026-625487.239.6Oracle CorporationOracle HRMS (US)CWE-269Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com…
CVE-2026-611409.839.5Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-466817.239.3nevware21ts-utilsCWE-1321@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for.…
CVE-2026-568527.538.9golang.org/x/textgolang.org/x/text/unicode/normCWE-835Infinite loop on invalid input in golang.org/x/text
CVE-2026-605519.838.8Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-470409.138.8Oracle CorporationOracle Net ServicesCWE-306Vulnerability in the Oracle Net Services component of Oracle Database Server.…
CVE-2026-646276.938.7parse-communityparse-serverCWE-209Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion
CVE-2026-631396.538.7ElasticKibanaCWE-400Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-632606.538.7ElasticKibanaCWE-400Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-632616.538.7ElasticKibanaCWE-400Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-470187.538.6Oracle CorporationSiebel CRM Cloud ApplicationsCWE-400Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-602527.538.6Oracle CorporationOracle CoherenceCWE-400Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603017.538.6Oracle CorporationOracle CoherenceCWE-400Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603827.538.6Oracle CorporationService Delivery PlatformCWE-400Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-604257.538.6Oracle CorporationOracle Unified DirectoryCWE-400Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-604367.538.6Oracle CorporationOracle Unified DirectoryCWE-400Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-164852.138.6SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System class.php cross site scripting
CVE-2026-164862.138.6SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting
CVE-2026-16179.838.4Turkmesh Communication Services Inc.Turkhotspot 5651 LoglamaCWE-89SQLi in Turkmesh's Turkhotspot 5651 Loglama
CVE-2026-163609.838.4MozillaFirefoxCWE-119Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefo…
CVE-2026-476957.138.4cc-tweakedCC-TweakedCWE-918CC-Tweaked has an SSRF Protection Bypass with NAT64
CVE-2026-625168.838.3Oracle CorporationOracle Demantra Demand ManagementCWE-89Vulnerability in the Oracle Demantra Demand Management product of Oracle Supp…
CVE-2026-605297.238.2Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-610947.238.2Oracle CorporationMySQL ServerCWE-269Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-470577.538.1Oracle CorporationOracle Java SECWE-400Vulnerability in Oracle Java SE (component: Scripting). Supported versions th…
CVE-2026-601807.538.1Oracle CorporationMySQL ConnectorsCWE-400Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con…
CVE-2026-602089.138.0Oracle CorporationOracle WebLogic ServerCWE-400Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-473977.137.8MervinPraisonPraisonAICWE-22PraisonAI has an Arbitrary File Write in Python API
CVE-2026-550848.837.6dhis2dhis2-coreCWE-89SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read
CVE-2026-612039.437.5Oracle CorporationPeopleSoft Enterprise FIN ExpensesCWE-269Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle Peo…
CVE-2026-606457.237.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-470084.937.2Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-601714.937.2Oracle CorporationMySQL ClusterCWE-400Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server…
CVE-2026-611284.937.2Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-611444.937.2Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-472477.537.0strukturaglibheifCWE-200libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninit…
CVE-2026-601689.137.0Oracle CorporationOracle Hospitality SimphonyCWE-284Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B…
CVE-2026-624159.136.9joomdonation.comMembership Pro extension for JoomlaCWE-1188Joomla Extension - joomdonation.com - Insecure default configuration Membersh…
CVE-2026-163365.336.9trinodbtrinoCWE-601trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect
CVE-2026-80827.536.9Unknownbpost-shipping-platformCWE-89Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection
CVE-2026-464036.336.9klever-ioklever-goCWE-693Klever-Go KVM read-only execution can commit contract delete and upgrade side…
CVE-2026-611759.336.7Oracle CorporationOracle Product Lifecycle AnalyticsCWE-200Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup…
CVE-2026-605448.236.7Oracle CorporationOracle SOA SuiteCWE-306Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-568197.536.7nettynettyCWE-400Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompress…
CVE-2026-470524.936.7Oracle CorporationMySQL ServerCWE-400Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (com…
CVE-2026-650498.436.6Saturday DriveNinja FormsCWE-863Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via …
CVE-2026-612119.936.4Oracle CorporationOracle Database ServerCWE-284Vulnerability in the RDBMS component of Oracle Database Server. Supported ver…
CVE-2026-602938.636.2Oracle CorporationOracle WebLogic ServerCWE-200Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-604318.636.2Oracle CorporationOracle HTTP ServerCWE-200Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (…
CVE-2026-605568.636.2Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-601677.536.2Oracle CorporationOracle Hospitality SimphonyCWE-200Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B…
CVE-2026-605547.536.2Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-611167.536.2Oracle CorporationOracle Application Object LibraryCWE-200Vulnerability in the Oracle Application Object Library product of Oracle E-Bu…
CVE-2026-611337.536.2Oracle CorporationOracle Commerce PlatformCWE-200Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (com…
CVE-2026-611597.536.2Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-200Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-650507.136.2Saturday DriveNinja FormsCWE-862Ninja Forms Missing Authorization in submissions-table Gutenberg Block Disclo…
CVE-2026-163639.836.1MozillaFirefoxCWE-682JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-163699.836.1MozillaFirefoxCWE-190Integer overflow in the JavaScript: WebAssembly component
CVE-2026-550817.336.1dhis2dhis2-coreCWE-79DHIS2 Reflected XSS in OpenAPI HTML scope parameter
CVE-2026-164089.836.1MozillaFirefoxCWE-190Integer overflow in the Audio/Video: Playback component
CVE-2026-602237.536.0Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-611766.736.0Oracle CorporationOracle Product Lifecycle AnalyticsCWE-269Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup…
CVE-2026-625036.736.0Oracle CorporationOracle Time and LaborCWE-284Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite…
CVE-2026-603339.935.8Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-603619.935.8Oracle CorporationOracle Unified DirectoryCWE-306Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-603819.935.8Oracle CorporationService Delivery PlatformCWE-284Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-604029.935.8Oracle CorporationTimesTen In-Memory DatabaseCWE-284Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen I…
CVE-2026-604299.935.8Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-604459.935.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604479.935.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604569.935.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604579.935.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604589.935.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604599.935.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-604619.935.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-306Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-605249.935.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-605319.935.8Oracle CorporationOracle Identity Manager ConnectorCWE-306Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-605379.935.8Oracle CorporationOracle Managed File TransferCWE-306Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi…
CVE-2026-605429.935.8Oracle CorporationOracle Business Process Management SuiteCWE-284Vulnerability in the Oracle Business Process Management Suite product of Orac…
CVE-2026-605479.935.8Oracle CorporationOracle Managed File TransferCWE-284Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi…
CVE-2026-605529.935.8Oracle CorporationOracle WebCenter SitesCWE-200Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-605619.935.8Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-605629.935.8Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-605689.935.8Oracle CorporationOracle WebCenter PortalCWE-287Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-606279.935.8Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-306Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-606639.935.8Oracle CorporationOracle WebCenter ContentCWE-269Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-607119.935.7Oracle CorporationSiebel CRM Cloud ApplicationsCWE-306Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-610419.935.8Oracle CorporationOracle Demantra Demand ManagementCWE-284Vulnerability in the Oracle Demantra Demand Management product of Oracle Supp…
CVE-2026-610729.935.8Oracle CorporationPeopleSoft Enterprise FIN Staffing Front Office BrazilCWE-284Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil p…
CVE-2026-610769.935.8Oracle CorporationPeopleSoft Enterprise HCM Talent Acquisition ManagerCWE-269Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager pro…
CVE-2026-611469.935.8Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-269Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-612099.935.8Oracle CorporationPeopleSoft In-Memory Project DiscoveryCWE-269Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle…
CVE-2026-612429.935.8Oracle CorporationPeopleSoft Enterprise FIN Common Objects ArgentinaCWE-284Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina produ…
CVE-2026-163809.135.8MozillaFirefoxCWE-693Mitigation bypass in the Networking component
CVE-2026-163949.135.8MozillaFirefoxCWE-693Mitigation bypass in the DOM: Security component
CVE-2026-469928.835.8Oracle CorporationOracle Enterprise Manager Base PlatformCWE-306Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-469958.835.8Oracle CorporationOracle Enterprise Manager Base PlatformCWE-269Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-470048.835.8Oracle CorporationOracle Enterprise Manager Base PlatformCWE-306Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-470318.835.8Oracle CorporationOracle Bills of MaterialCWE-284Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su…
CVE-2026-470378.835.8Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-601578.835.8Oracle CorporationOracle GoldenGateCWE-284Vulnerability in Oracle GoldenGate (component: Service Manager). Supported ve…
CVE-2026-602038.835.8Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602078.835.8Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-602188.835.8Oracle CorporationOracle CoherenceCWE-306Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-602688.835.8Oracle CorporationOracle CoherenceCWE-284Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-603138.835.8Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-603348.835.8Oracle CorporationOracle WebCenter ContentCWE-306Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-603438.835.8Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-603988.835.8Oracle CorporationOracle GoldenGateCWE-306Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservice…
CVE-2026-604008.835.8Oracle CorporationOracle GoldenGateCWE-284Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supp…
CVE-2026-604198.835.8Oracle CorporationOracle Unified DirectoryCWE-269Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-604238.835.8Oracle CorporationOracle Unified DirectoryCWE-287Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-604308.835.8Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…

Results continue: ranks 401–1477.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-21 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.