boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, July 22, 2026 · all times UTC← 2026-07-21 · archive · 2026-07-23 →

Security Box Score — July 22, 2026

198 CVEs published, led by MongoDB (26).

198 CVEs published July 22, 2026: 17 critical, 103 high, 65 medium, 13 low; 1 in the KEV catalog at press time; 3 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 173 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published709219495——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

835 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux4791959178107959611120.17.8.0016+379 ▲
microsoft64614039697531814286241.77.8.0047+426 ▲
google1151380156629556397760.47.8.0024-569 ▼
red hat1023241612715922200.06.5.0032+23 ▲
apple01042287228876.76.5.0032-14 ▼
canonical72738115000.05.6.0014+5 ▲
suse82141241000.08.5.0039+4 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1537818110561129.77.5.0057+6 ▲
ubiquiti2536142110338.38.8.0049+20 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear62300221000.04.6.0024-11 ▼
fortinet13226610028522.77.3.0039+11 ▲
f58165830416.38.6.0057+2 ▲
vmware8121821718.38.2.0039+5 ▲
checkpoint31236303216.77.7.04550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache92247559585113310.47.5.00590
mozilla711275142340900.08.1.0031+22 ▲
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-4 ▼
github5111280000.06.0.0042+5 ▲
docker070520000.08.2.0016-4 ▼
wordpress22101022100.07.9.8879+2 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091379343653322612730.28.1.0036+867 ▲
adobe952392610410541931.37.7.0026-34 ▼
ibm371615254550600.07.5.0036+5 ▲
progress243332460600.07.5.0041+19 ▲
solarwinds15221633010418.29.1.0058+12 ▲
zohocorp251220000.07.1.0121+2 ▲
veeam152300100.08.6.00510
atlassian3303001300.08.0.0026+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
d-link8200596300.05.5.0105-1 ▼
siemens7161870000.07.6.00240
abb170430000.07.2.0018-4 ▼
schneider electric060420000.07.8.0042-1 ▼
hikvision550320000.07.2.0038+5 ▲
moxa050320000.07.0.0029-5 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester49120006258000.05.5.0034+12 ▲
openclaw441110583914000.07.0.0026-17 ▼
dell4399547443211.07.1.0021+12 ▲
capgo2283242381000.07.1.0037-9 ▼
nvidia41801252160000.07.8.0037+35 ▲
imagemagick3273155512000.05.3.0019+2 ▲
spring073231391000.06.5.0024-71 ▼
itsourcecode1871001952000.02.1.0033-4 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-1540910.0.8366KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
Most disclosures (vendor)
VendorCVEs
oracle1109
linux892
microsoft647
google521
red hat151
apache121
adobe108
ibm80
mozilla72
sourcecodester61
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco11
apple7
google6
fortinet5
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven62
PyPI5
npm5
NuGet3
Packagist1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2026-0770Langflow0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-20230Cisco0
CVE-2026-25089Fortinet0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171708
CVE-2021-27102n/a2021-11-171708
CVE-2021-27101n/a2021-11-171708
CVE-2021-27103n/a2021-11-171708
CVE-2021-21017Adobe2021-11-171708
CVE-2021-28550Adobe2021-11-171708
CVE-2021-42013Apache Software Foundation2021-11-171708
CVE-2021-41773Apache Software Foundation2021-11-171708
CVE-2021-30858Apple2021-11-171708
CVE-2021-30860Apple2021-11-171708

Transactions

EXPLOIT PUBLISHED — D-Link DNS-320: 4 CVEs (CVE-2026-16329, CVE-2026-16331, CVE-2026-16332, CVE-2026-16447). Public exploit references added.

EXPLOIT PUBLISHED — SourceCodester Class and Exam Timetabling System: 3 CVEs (CVE-2026-16484, CVE-2026-16485, CVE-2026-16486). Public exploit references added.

EXPLOIT PUBLISHED — zsadmin2025 ZS-Admin: 3 CVEs (CVE-2026-16449, CVE-2026-16450, CVE-2026-16451). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2016-20096 (Kunshi Network Technology Co., Ltd. Linknat VOS3000). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-27137 (DD-WRT). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-60689. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16334 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-20230 (Cisco Unified Communications Manager). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48029 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50475 (Microsoft Windows 10 Version 1607). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5497 (vllm-project/vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58613 (Microsoft Windows 10 Version 1809). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63080 (aptabase). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63107 (LimeSurvey). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64821 (thiagopena djangoSIGE). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64822 (thiagopena djangoSIGE). Public exploit reference added.

RESCORED — Microsoft Windows 10 Version 1607: 45 CVEs (CVE-2026-44806, CVE-2026-49164, CVE-2026-49171, CVE-2026-49184, CVE-2026-49789, CVE-2026-49791, CVE-2026-50312, CVE-2026-50321, CVE-2026-50330, CVE-2026-50358, CVE-2026-50359, CVE-2026-50390, CVE-2026-50432, CVE-2026-50439, CVE-2026-50445, CVE-2026-50451, CVE-2026-50453, CVE-2026-50477, CVE-2026-50482, CVE-2026-50490, CVE-2026-50497, CVE-2026-50502, CVE-2026-50504, CVE-2026-50505, CVE-2026-50661, CVE-2026-50667, CVE-2026-50694, CVE-2026-56186, CVE-2026-56188, CVE-2026-56189, CVE-2026-56649, CVE-2026-57085, CVE-2026-57087, CVE-2026-57090, CVE-2026-57093, CVE-2026-57095, CVE-2026-57097, CVE-2026-57979, CVE-2026-58533, CVE-2026-58534, CVE-2026-58535, CVE-2026-58539, CVE-2026-58594, CVE-2026-58608, CVE-2026-58640). CVSS rescored — before/after on each CVE page.

RESCORED — Microsoft Windows 10 Version 1809: 16 CVEs (CVE-2026-49167, CVE-2026-50307, CVE-2026-50348, CVE-2026-50375, CVE-2026-50378, CVE-2026-50383, CVE-2026-50415, CVE-2026-50450, CVE-2026-50452, CVE-2026-50495, CVE-2026-50680, CVE-2026-54129, CVE-2026-58526, CVE-2026-58528, CVE-2026-58547, CVE-2026-58638). CVSS rescored — before/after on each CVE page.

RESCORED — Microsoft Windows 11 Version 24H2: 15 CVEs (CVE-2026-50340, CVE-2026-50393, CVE-2026-50396, CVE-2026-50398, CVE-2026-50413, CVE-2026-50414, CVE-2026-50418, CVE-2026-50420, CVE-2026-50487, CVE-2026-50674, CVE-2026-50676, CVE-2026-50687, CVE-2026-54127, CVE-2026-54990, CVE-2026-58527). CVSS rescored — before/after on each CVE page.

RESCORED — SourceCodester Class and Exam Timetabling System: 3 CVEs (CVE-2026-16152, CVE-2026-16202, CVE-2026-16227). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2022-2712 (The Eclipse Foundation Eclipse GlassFish). CVSS 6.5 → 7.5 (NVD).

RESCORED — CVE-2026-16073 (AstrBotDevs AstrBot). CVSS 5.1 → 2 (NVD).

RESCORED — CVE-2026-16082 (Sipeed PicoClaw). CVSS 4.8 → 1.9 (NVD).

RESCORED — CVE-2026-16123 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16129 (princezuda SafestClaw). CVSS 4.8 → 1.9 (NVD).

RESCORED — CVE-2026-16196 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16214 (geex-arts django-jet). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16220 (code-projects Online Examination System). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-16488 (QUSETIONS MiniCode-Python). CVSS 2.3 → 1.3 (NVD).

RESCORED — CVE-2026-16489 (jsforce). CVSS 4.8 → 1.9 (NVD).

RESCORED — CVE-2026-28369 (Red Hat JBoss Enterprise Application Platform 8.1). CVSS 8.7 → 9.1 (NVD).

RESCORED — CVE-2026-3833 (gnutls). CVSS 6.5 → 7.4 (NVD).

RESCORED — CVE-2026-50302 (Microsoft Windows 10 Version 21H2). CVSS 4.2 → 6.5 (NVD).

RESCORED — CVE-2026-50428 (Microsoft Windows 11 version 26H1). CVSS 7.1 → 5.5 (NVD).

RESCORED — CVE-2026-50459 (Microsoft Windows 10 Version 21H2). CVSS 7 → 7.8 (NVD).

RESCORED — CVE-2026-50526 (Microsoft .NET 10.0). CVSS 7 → 5.5 (NVD).

RESCORED — CVE-2026-50657 (Microsoft Defender for Endpoint for Mac). CVSS 4.7 → 5.5 (NVD).

RESCORED — CVE-2026-55145 (Microsoft Copilot). CVSS 6.3 → 7.1 (NVD).

RESCORED — CVE-2026-56171 (Microsoft Remote Desktop Web Client). CVSS 7.1 → 7.5 (NVD).

RESCORED — CVE-2026-56178 (Microsoft Defender for Endpoint for Mac). CVSS 5.5 → 7 (NVD).

RESCORED — CVE-2026-62826 (Microsoft SharePoint Enterprise Server 2016). CVSS 4.6 → 5.4 (NVD).

ENRICHED — CVE-2025-48595 (Android Framework). Received CVSS 8.4 and CPE data from NVD.

ENRICHED — CVE-2026-20230 (Cisco Unified Communications Manager). Received CVSS 8.6 and CPE data from NVD.

ENRICHED — CVE-2026-28318 (SolarWinds Serv-U). Received CVSS 7.5 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

198 CVEs published. 25 box scores, 173 table rows — nothing truncated.

checkpoint Quantum Security Management — Authentication Bypass in the SmartConsole Login Process Using an Application Token
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .8912   99.8   YES
AFFECTED
  Product                           Versions                                     Fixed
  Quantum Security Management       R82.10 with Jumbo Hotfix Take 36 or below –  —
  Multi-Domain Security Management  R82.10 with Jumbo Hotfix Take 36 or below –  —
TIMELINE
  Jul 19  Reserved by CNA
  Jul 22  Added to CISA KEV, due Jul 25
  Jul 22  Published (CNA: checkpoint)
CWE-287 · CNA: checkpoint · CVSS v4.0 · 2 references · NVD status: Analyzed · KEV due July 25, 2026
checkpoint Quantum Security Management — Management Authentication Bypass and Privilege Escalation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .2082   97.4     —
AFFECTED
  Product                           Versions                                     Fixed
  Quantum Security Management       R82.10 with Jumbo Hotfix Take 36 or below –  —
  Multi-Domain Security Management  R82.10 with Jumbo Hotfix Take 36 or below –  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 22  Published (CNA: checkpoint)
CWE-287 · CNA: checkpoint · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — Local Privilege Escalation in Gaia Portal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0761   94.1     —
AFFECTED
  Product                      Versions                                     Fixed
  Quantum Security Gateway     R82.10 with Jumbo Hotfix Take 36 or below –  —
  Quantum Security Management  R82.10 with Jumbo Hotfix Take 36 or below –  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 22  Published (CNA: checkpoint)
CWE-269 · CNA: checkpoint · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
umijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   L   N   L   L   L    2.0   .0391   89.5     —
AFFECTED
  Product  Versions  Fixed
  umi      4.6.0 –   4.6.64
TIMELINE
  Jul 21  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
FFmpeg 8.0 - 8.1.2 Stack Buffer Overflow in Vulkan HEVC Decoder
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0085   55.4     —
AFFECTED
  Product  Versions  Fixed
  FFmpeg   8.0 –     —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 22  Published (CNA: VulnCheck)
CWE-121 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
Chimpstudio WP Foodbakery — WP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0082   54.5     —
AFFECTED
  Product        Versions     Fixed
  WP Foodbakery  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 22  Published (CNA: Wordfence)
CWE-23 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Red Hat Red Hat Ansible Automation Platform 2 — Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0082   54.4     —
AFFECTED
  Product                                Versions     Fixed
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
TIMELINE
  May 5   Reserved by CNA
  Jul 22  Published (CNA: redhat)
CWE-78 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Red Hat Red Hat Ansible Automation Platform 2 — Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script setting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0075   52.3     —
AFFECTED
  Product                                Versions     Fixed
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
TIMELINE
  May 5   Reserved by CNA
  Jul 22  Published (CNA: redhat)
CWE-78 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Progress Software Telerik UI for ASP.NET AJAX — RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0067   49.1     —
AFFECTED
  Product                      Versions      Fixed
  Telerik UI for ASP.NET AJAX  2010.1.309 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: ProgressSoftware)
CWE-470 · CNA: ProgressSoftware · CVSS v3.1 · 1 reference · NVD status: Analyzed
Progress Software Telerik UI for ASP.NET AJAX — PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0067   49.1     —
AFFECTED
  Product                      Versions      Fixed
  Telerik UI for ASP.NET AJAX  2011.2.712 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: ProgressSoftware)
CWE-502 · CNA: ProgressSoftware · CVSS v3.1 · 1 reference · NVD status: Analyzed
Fujitsu Linux openFT — Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0065   48.4     —
AFFECTED
  Product                Versions     Fixed
  Linux openFT           unspecified  12.1D00
  Oracle Solaris openFT  unspecified  12.1D00
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: FTI)
CWE-94 · CNA: FTI · CVSS v4.0 · 3 references · NVD status: Deferred
SMCI X14DBG-DAP,X14DBI — Supermicro SMASH service contain an Arbitrary code execution issue
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0064   47.8     —
AFFECTED
  Product            Versions       Fixed
  X14DBG-DAP,X14DBI  01.00.16.00 –  —
TIMELINE
  Mar 9   Reserved by CNA
  Jul 22  Published (CNA: Supermicro)
CWE-78 · CNA: Supermicro · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0063   47.7     —
AFFECTED
  Product                     Versions  Fixed
  ej2-javascript-ui-controls  33.2.0 –  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
n/a publint — publint package-manager pack.js child_process.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0063   47.7     —
AFFECTED
  Product  Versions  Fixed
  publint  0.1.0 –   —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    4.8   .0062   47.1     —
AFFECTED
  Product    Versions  Fixed
  danger-js  13.0.0 –  13.0.8
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
n/a oclif — oclif JIT Plugin Entry child_process.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0062   47.1     —
AFFECTED
  Product  Versions  Fixed
  oclif    4.23.0 –  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
n/a n/a — An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privil…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0057   44.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 22  Published (CNA: mitre)
CWE-693 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Deferred
Oracle Corporation Oracle Platform Security for Java — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Cent…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0055   43.4     —
AFFECTED
  Product                            Versions      Fixed
  Oracle Platform Security for Java  12.2.1.4.0 –  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 22  Published (CNA: oracle)
CWE-269, CWE-284, CWE-306, CWE-502 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Oracle Corporation Oracle Platform Security for Java — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Cent…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0055   43.4     —
AFFECTED
  Product                            Versions      Fixed
  Oracle Platform Security for Java  12.2.1.4.0 –  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 22  Published (CNA: oracle)
CWE-269, CWE-287, CWE-306, CWE-502 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Oracle Corporation Oracle Platform Security for Java — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Cent…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0055   43.4     —
AFFECTED
  Product                            Versions      Fixed
  Oracle Platform Security for Java  12.2.1.4.0 –  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 22  Published (CNA: oracle)
CWE-269, CWE-284, CWE-306, CWE-502 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Oracle Corporation Oracle Platform Security for Java — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Cent…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0055   43.4     —
AFFECTED
  Product                            Versions      Fixed
  Oracle Platform Security for Java  12.2.1.4.0 –  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 22  Published (CNA: oracle)
CWE-1104 · CNA: oracle · CVSS v3.1 · 1 reference · NVD status: Analyzed
Progress Software Telerik UI for ASP.NET AJAX — RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0054   43.2     —
AFFECTED
  Product                      Versions      Fixed
  Telerik UI for ASP.NET AJAX  2010.1.309 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: ProgressSoftware)
CWE-209 · CNA: ProgressSoftware · CVSS v3.1 · 1 reference · NVD status: Analyzed
Progress Software Telerik UI for ASP.NET AJAX — RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0054   43.2     —
AFFECTED
  Product                      Versions      Fixed
  Telerik UI for ASP.NET AJAX  2010.1.309 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: ProgressSoftware)
CWE-208 · CNA: ProgressSoftware · CVSS v3.1 · 1 reference · NVD status: Analyzed
Progress Software Telerik UI for ASP.NET AJAX — SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0054   43.0     —
AFFECTED
  Product                      Versions      Fixed
  Telerik UI for ASP.NET AJAX  2011.2.712 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: ProgressSoftware)
CWE-36 · CNA: ProgressSoftware · CVSS v3.1 · 1 reference · NVD status: Analyzed
ISC BIND 9 — Unnecessary validation of DNSSEC signed records
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0054   42.9     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.20.0 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 22  Published (CNA: isc)
CWE-408 · CNA: isc · CVSS v3.1 · 3 references · NVD status: Undergoing Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-441897.842.8Red HatRed Hat Ansible Automation Platform 2CWE-88Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrar…
CVE-2026-613917.242.8HikvisionDS-2CD SeriesCWE-121There is a stack-based buffer overflow vulnerability in some Hikvision camera…
CVE-2026-131868.142.6Progress SoftwareTelerik UI for ASP.NET AJAXCWE-22AppDataStorageProvider Path Traversal Deserialization Vulnerability in Teleri…
CVE-2026-650138.742.0onlookrepoCWE-639Onlook tRPC Insecure Direct Object Reference via multiple procedures
CVE-2026-116227.542.0ISCBIND 9CWE-770Potential memory usage beyond configured limits
CVE-2026-132047.542.0ISCBIND 9CWE-617Unexpected exit in certain situations with NSEC and NSEC3 both present
CVE-2026-166325.541.9boazsegevfacil.ioCWE-20boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_e…
CVE-2026-129688.840.8UnknownProduct Addons and Product Options With Custom FieldsCWE-79Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrar…
CVE-2026-648348.740.7FFmpegFFmpegCWE-835FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer
CVE-2026-126177.540.6ISCBIND 9CWE-617Record ordering based unexpected exit with CNAME or DNAME
CVE-2026-407147.240.5DellPowerProtect Data ManagerCWE-20Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp…
CVE-2026-130657.140.4MongoDBMongoDB ServerCWE-476MongoDB $linearFill Window Function Improper Input Validation Leading to Proc…
CVE-2026-131858.139.6Progress SoftwareTelerik UI for ASP.NET AJAXCWE-502PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for A…
CVE-2026-162706.939.4Open MercatoOpen MercatoCWE-1333ReDoS in Open Mercato
CVE-2026-655918.939.3n8n-ion8nCWE-917n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
CVE-2026-655958.939.2n8n-ion8nCWE-269n8n before 2.29.8 and 2.30.1 Privilege Escalation via Token Exchange
CVE-2026-47738.138.6Magarsus Consulting Ltd. Co.IDM-MFACWE-1287OTP Bypass in Magarsus' IDM-MFA
CVE-2025-131466.538.6sevensparkContact Form 7 – Dynamic Text ExtensionCWE-94Contact Form 7 – Dynamic Text Extension <= 5.0.6 - Unauthenticated Arbitrary …
CVE-2026-23959.838.4Xpoda Türkiye Informatics Technology Inc.No Code PlatformCWE-89SQLi in Xpoda Türkiye Informatics Technology's No Code Platform
CVE-2026-131878.138.4Progress SoftwareTelerik UI for ASP.NET AJAXCWE-470DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET…
CVE-2026-603699.938.3Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-603738.838.3Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-604398.838.3Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-612468.838.3Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-34825.337.8IBMSterling B2B IntegratorCWE-639IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass
CVE-2026-129877.537.4UnknownEvents ManagerCWE-89Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injecti…
CVE-2026-656038.736.6getgravgravCWE-269Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update
CVE-2026-650126.336.5invoke-aiInvokeAICWE-306InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder
CVE-2026-632645.336.2joomshopping.comJoomShopping extension for JoomlaCWE-79Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3
CVE-2026-604558.835.8Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-148655.335.8Progress SoftwareTelerik UI for ASP.NET AJAXCWE-776XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP…
CVE-2026-113317.535.4ISCBIND 9CWE-790Potential wildcard CNAME RPZ policy bypass
CVE-2026-165516.935.4Thinkst Applied ResearchOpenCanaryCWE-20Denial-of-Service in OpenCanary's MongoDB module
CVE-2026-576007.534.9HikvisionDS-2CD SeriesCWE-20Insufficient validation of input parameters in the firmware of some Hikvision…
CVE-2026-130767.134.8MongoDBMongoDB ServerCWE-770Aggregation Framework Memory Exhaustion Leading to Process Termination
CVE-2026-648299.134.6q2aquestion2answerCWE-613Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow
CVE-2026-157876.434.6brainstormforceUltimate Addons for ElementorCWE-79Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored …
CVE-2026-494998.834.5DellPowerProtect Data ManagerCWE-1270Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Gene…
CVE-2026-81529.334.1Unblu inc.Unblu SparkCWE-79Unblu Spark Open Redirect leading to DOM-Based XSS
CVE-2026-656007.834.0traefiktraefikCWE-22Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex
CVE-2026-97377.133.9MongoDBMongoDB ServerCWE-617Find command with $meta sort can lead to crash
CVE-2026-130729.233.2MongoDBMongoDB ServerCWE-122MongoDB Improper Input Validation in Compute Mode External Data Processing Le…
CVE-2026-130567.133.1MongoDBMongoDB ServerCWE-1325A user with read access can cause a DoS by executing a specifically crafted q…
CVE-2026-130647.133.1MongoDBMongoDB ServerCWE-407MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denia…
CVE-2026-130607.132.8MongoDBMongoDB ServerCWE-863$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Una…
CVE-2026-648337.132.4FFmpegFFmpegCWE-125FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c
CVE-2026-165605.332.4Red HatRed Hat Directory Server 11CWE-1220389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multi…
CVE-2026-117217.532.4ISCBIND 9CWE-1284Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
CVE-2026-630477.532.2joomdonation.comEvents Booking extension for JoomlaCWE-284Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect…
CVE-2026-656504.331.8ElggElggCWE-770Elgg before 7.0.0 does not check image dimensions to prevent denial of servic…
CVE-2025-503278.831.4n/an/aCWE-693An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attac…
CVE-2026-165446.531.2Red HatRed Hat Ansible Automation Platform 2CWE-862Awx: websocket eventconsumer missing authorization for inventory_update_event…
CVE-2026-130598.631.1MongoDBMongoDB ServerCWE-807Improper Validation of Client-Supplied Command Parameters Allowing Role-Based…
CVE-2026-630489.430.9joomlack.frPage Builder CK extension for JoomlaCWE-434Joomla Extension - joomlack.fr - Improper access control in Page Builder CK <…
CVE-2026-108226.530.9ISCBIND 9CWE-617Key Record using PRIVATEDNS algorithm may lead to unexpected exit
CVE-2026-613907.730.5HikvisionDS-2CD SeriesCWE-122There is a heap buffer overflow vulnerability in some Hikvision cameras, whic…
CVE-2026-650115.330.5Graylog2graylog2-serverCWE-862Graylog2 Server Missing Permission Check on Event Definition Duplicate
CVE-2026-655895.129.9n8n-ion8nCWE-532n8n before 1.123.64 Credential Exposure via LLM Node Execution Data
CVE-2026-130667.129.6MongoDBMongoDB ServerCWE-843Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure
CVE-2026-648285.329.5FroidenTableTrackCWE-79Froiden TableTrack 1.3.10 Stored XSS via Order Notes Field
CVE-2025-503248.829.0n/an/aCWE-693An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker …
CVE-2025-503308.829.0n/an/aCWE-693An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote …
CVE-2026-24066.528.8Universe Software Computer Marketing Trade and Industry Inc.Online Registration and Workflow Management SystemCWE-639IDOR in Universe Software's Online Registration and Workflow Management System
CVE-2026-575996.628.4HikvisionDS-2CD SeriesCWE-269There is a privilege escalation vulnerability in some Hikvision cameras. Due …
CVE-2026-149326.528.0Progress SoftwareTelerik UI for ASP.NET AJAXCWE-321Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart
CVE-2026-407127.227.5DellPowerProtect Data ManagerCWE-20Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp…
CVE-2026-467377.227.4DellPowerProtect Data ManagerCWE-20Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp…
CVE-2026-131847.527.2Progress SoftwareTelerik UI for ASP.NET AJAXCWE-321RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.…
CVE-2026-613925.327.0HikvisionDS-2CD SeriesCWE-200There is a information disclosure vulnerability in some Hikvision cameras, al…
CVE-2026-648308.726.8FFmpegFFmpegCWE-122FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer
CVE-2026-467387.226.8DellPowerProtect Data ManagerCWE-20Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp…
CVE-2026-130786.326.5MongoDBMongoDB ServerCWE-862Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader
CVE-2026-648328.725.9FFmpegFFmpegCWE-415FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c
CVE-2026-603707.525.8Oracle CorporationOracle Platform Security for JavaCWE-1021Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-650146.325.8n8n-ion8nCWE-306n8n before 2.28.0 Authentication Bypass via test-webhook
CVE-2026-164902.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System prescription.php sql injection
CVE-2026-648358.725.1FFmpegFFmpegCWE-787FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder
CVE-2026-650157.224.7n8n-ion8nCWE-863n8n before 2.30.1 Privilege Escalation via run_node_tool
CVE-2026-655905.524.4n8n-ion8nCWE-78n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows
CVE-2026-650167.722.9n8n-ion8nCWE-639n8n before 1.123.64, 2.29.8, and 2.30.1 Privilege Escalation via SSO Instance…
CVE-2026-480297.122.5strukturaglibheifCWE-125libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced t…
CVE-2026-143225.322.4UnknownTimeticsCWE-284Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payme…
CVE-2025-440908.821.3n/an/aCWE-693An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary c…
CVE-2026-406917.521.3NLnet LabsUnboundCWE-122Packet of death for DNSCrypt over TCP
CVE-2026-130746.921.0MongoDBMongoDB ServerCWE-770Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to …
CVE-2026-656015.320.9traefiktraefikCWE-863Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef
CVE-2025-440898.820.7n/an/aCWE-693An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitr…
CVE-2026-220498.720.5NETAPPONTAP 9CWE-288ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (M…
CVE-2025-503255.420.5n/an/aCWE-693BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vu…
CVE-2026-647969.820.4regularlabs.comSourcerer extension for JoomlaCWE-284Joomla Extension - regularlabs.com - various code injection vectors in Source…
CVE-2026-326657.520.4NLnet LabsUnboundCWE-1284Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
CVE-2026-130557.120.3MongoDBMongoDB ServerCWE-617Server crash via aggregation pipeline expression with compound wildcard index…
CVE-2026-166249.620.0Cal.comCal.diyCWE-639CVE-2026-16624
CVE-2026-559737.520.0NLnet LabsUnboundCWE-20'dns-error-reporting: yes' leads to stack buffer overflow
CVE-2026-458206.619.7101arrowzfflateCWE-400fflate through 0.8.2 is vulnerable to denial of service via an infinite loop …
CVE-2026-500455.319.7NLnet LabsUnboundCWE-406'max-global-quota' reset by DNSSEC validation restarts
CVE-2026-130777.119.6MongoDBMongoDB ServerCWE-125Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSON…
CVE-2026-130615.319.6MongoDBMongoDB ServerCWE-863Improper Access Control Allowing Cross-User Session Metadata Disclosure in $l…
CVE-2026-148997.519.2MozillaThunderbirdCWE-193Off-by-one out of bounds read in MIME header parser for forwarding
CVE-2026-107236.819.1ISCBIND 9CWE-347Incorrect acceptance of NSEC3 records
CVE-2026-130576.018.6MongoDBMongoDB ServerCWE-20Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauth…
CVE-2026-145865.918.5NLnet LabsUnboundCWE-617Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC …
CVE-2026-655945.118.5n8n-ion8nCWE-863n8n before 2.30.1 Missing OAuth Authorization Check
CVE-2026-603718.018.0Oracle CorporationOracle Platform Security for JavaCWE-200Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-416373.718.0NLnet LabsUnboundCWE-772Degradation of resolution service from improperly accounted client-terminated…
CVE-2026-528635.917.0NLnet LabsUnboundCWE-416Memory corruption could lead to crash and denial of service
CVE-2026-559905.917.0NLnet LabsUnboundCWE-457Packet of death for a DNSCrypt misconfigured Unbound
CVE-2026-564445.917.0NLnet LabsUnboundCWE-772Degradation of resolution service when 'discard-timeout' and 'serve-expired-c…
CVE-2026-166156.816.6GNOMElibrestCWE-338Librest: weak random number generation in pkce implementation
CVE-2026-502515.316.5NLnet LabsUnboundCWE-184Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
CVE-2026-130717.116.2MongoDBMongoDB ServerCWE-416Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to …
CVE-2026-647927.516.0regularlabs.comArticles Anywhere extension for JoomlaCWE-524Joomla Extension - regularlabs.com - disclosure of restricted content via sea…
CVE-2026-446215.915.8NLnet LabsUnboundCWE-754Libunbound applications configured with 'unwanted-reply-threshold' could even…
CVE-2026-647939.115.7regularlabs.comArticles Anywhere extension for JoomlaCWE-284Joomla Extension - regularlabs.com - Content access and publication bypass in…
CVE-2026-655988.915.7n8n-ion8nCWE-367n8n before 1.123.64 Remote Code Execution via Git Clone
CVE-2026-647989.115.5regularlabs.comIP Login extension for JoomlaCWE-338Joomla Extension - regularlabs.com - Insecure login URL keys in IP login exte…
CVE-2026-164734.315.4Red HatRed Hat Enterprise Linux 10CWE-125Sbc: sbc: heap out-of-bounds read via crafted sbc audio frame
CVE-2026-131926.515.3Progress SoftwareTelerik UI for ASP.NET AJAXCWE-918RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX
CVE-2026-647946.515.3regularlabs.comArticles Anywhere extension for JoomlaCWE-284Joomla Extension - regularlabs.com - restricted user-data exposure in Users A…
CVE-2026-130897.514.9RITOUOIDC::LiteCWE-347OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verifica…
CVE-2026-130757.114.9MongoDBMongoDB ServerCWE-770$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggest…
CVE-2026-500465.914.5NLnet LabsUnboundCWE-416Possible heap use-after-free in an error path when a DoT forwarded query is j…
CVE-2026-557175.914.5NLnet LabsUnboundCWE-476'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to…
CVE-2026-559915.914.5NLnet LabsUnboundCWE-195Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
CVE-2026-130587.113.6MongoDBMongoDB ServerCWE-617Transaction Command Insufficient Input Validation Leading to Process Termination
CVE-2026-130635.313.6MongoDBMongoDB ServerCWE-190libmongocrypt Improper Input Validation Leading to Process Termination
CVE-2026-636858.813.5regularlabs.comDB Replacer extension for JoomlaCWE-284Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer exte…
CVE-2026-636837.513.0regularlabs.comAdvanced Module Manager extension for JoomlaCWE-290Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regu…
CVE-2026-133218.612.7ISCBIND 9CWE-346DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVE-2026-446873.712.0NLnet LabsUnboundCWE-193Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward z…
CVE-2026-130735.312.0MongoDBMongoDB ServerCWE-617MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Te…
CVE-2026-655978.211.5n8n-ion8nCWE-79n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe
CVE-2026-655965.110.9n8n-ion8nCWE-863n8n before 1.123.64 Credential Exfiltration via GraphQL Node
CVE-2026-647977.510.0regularlabs.comIP Login extension for JoomlaCWE-290Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login ex…
CVE-2026-441926.69.6Red HatRed Hat Ansible Automation Platform 2CWE-22Ansible-lightspeed: ansible lightspeed mcp server: remote code execution and …
CVE-2026-429553.79.3NLnet LabsUnboundCWE-672Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallow…
CVE-2026-148818.49.1MongoDBMongoDB CompassCWE-78Compass connection import allows to override OIDC browser open command (usual…
CVE-2026-465823.78.5NLnet LabsUnboundCWE-358A wildcard replay, as another piece of data, triggers poisoning in the serve …
CVE-2026-130627.18.4MongoDBMongoDB ServerCWE-441MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption …
CVE-2026-656025.38.1traefiktraefikCWE-863Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass
CVE-2026-544783.77.3NLnet LabsUnboundCWE-290DNS Cookie bypass when combined with proxy-protocol use
CVE-2026-387635.57.1n/an/aCWE-400An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at…
CVE-2026-149857.86.9Analog WayPicturall Quad Compact Mark IICWE-22CVE-2026-14985
CVE-2026-130697.16.7MongoDBMongoDB ServerCWE-770Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Re…
CVE-2026-568448.46.6VeeamBackup and ReplicationCWE-22A vulnerability in the Veeam Updater component of the Veeam Software Applianc…
CVE-2026-655928.46.6n8n-ion8nCWE-79n8n before 1.123.64 Stored DOM XSS via cachedResultUrl
CVE-2026-387657.86.6n/an/aCWE-269An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at…
CVE-2026-387667.86.6n/an/aCWE-269An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at…
CVE-2026-502525.75.7NLnet LabsUnboundCWE-349Possible cache poisoning attack by mapping source port population per thread
CVE-2026-131885.94.9Progress SoftwareTelerik UI for ASP.NET AJAXCWE-345DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX
CVE-2026-655995.14.7n8n-ion8nCWE-312n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header
CVE-2026-557083.14.4NLnet LabsUnboundCWE-1188Privacy/configuration issue when adding local data in views through 'unbound-…
CVE-2025-608357.84.2n/an/aCWE-35An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute…
CVE-2026-130682.34.3MongoDBMongoDB ServerCWE-863MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cr…
CVE-2026-166078.54.2FujitsuLinux openFTCWE-269Authenticated local root privilege escalation vulnerability in openFT for Lin…
CVE-2026-446907.54.1NLnet LabsUnboundCWE-345Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
CVE-2026-655936.33.9n8n-ion8nCWE-918n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters
CVE-2026-632814.83.8regularlabs.comAdvanced Module Manager extension for JoomlaCWE-79Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs condit…
CVE-2026-145518.83.3servereye GmbHservereye Windows Agent (Sensorhub)CWE-73Local Privilege Escalation in servereye client (sensorhub)
CVE-2026-130706.03.0MongoDBMongoDB ServerCWE-476Improper Validation of OCSP Response During Outbound TLS Handshake Leading to…
CVE-2026-647955.43.0regularlabs.comModals extension for JoomlaCWE-79Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in va…
CVE-2026-73286.82.9CaliptraCore Runtime FirmwareCWE-862Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service
CVE-2026-502486.52.7NLnet LabsUnboundCWE-345BOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVE-2026-632808.82.6regularlabs.comAdvanced Module Manager extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-636848.82.6regularlabs.comContent Templater extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-647918.82.6regularlabs.comRegular Labs Extension Manager extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-441873.32.6Red HatRed Hat Ansible Automation Platform 2CWE-256Ansible-lightspeed: ansible lightspeed extension for visual studio code: info…
CVE-2026-564164.82.3NLnet LabsUnboundCWE-354Possible heap buffer overflow when validator canonicalizes RDATA that contain…
CVE-2026-161577.81.9DuplicatiDuplicatiCWE-732Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission a…
CVE-2026-632658.01.7regularlabs.comAdvanced Module Manager extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-442764.41.3DellPowerProtect Data ManagerCWE-200Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exp…
CVE-2026-502436.31.1NLnet LabsUnboundCWE-348'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
CVE-2026-130677.20.8MongoDBMongoDB ServerCWE-863tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domai…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-22 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.