boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, July 23, 2026 · all times UTC← 2026-07-22 · archive · 2026-07-24 →

Security Box Score — July 23, 2026

376 CVEs published, led by JetBrains (18).

376 CVEs published July 23, 2026: 63 critical, 137 high, 166 medium, 10 low; 0 in the KEV catalog at press time; 16 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 351 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published746819871——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

843 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux4801960178108059611120.17.8.0016+380 ▲
microsoft65014079897731814286241.77.8.0047+430 ▲
google1191384156633556397760.47.8.0025-565 ▼
red hat1073291612916222200.06.5.0032+16 ▲
apple31072307328876.56.5.0032-11 ▼
canonical72738115000.05.6.0014+5 ▲
suse82141241000.08.5.0039+4 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1537818110561129.77.5.0057+6 ▲
ubiquiti2536142110338.38.8.0049+17 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear62300221000.04.6.0024-11 ▼
fortinet13226610028522.77.3.0039+11 ▲
f58165830416.38.6.0057+2 ▲
vmware8121821718.38.2.0039+5 ▲
checkpoint31236303216.77.7.04550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache92247559585113310.47.5.00590
mozilla711275142340900.08.1.0031+22 ▲
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-4 ▼
github5111280000.06.0.0042+5 ▲
docker070520000.08.2.0016-4 ▼
wordpress22101022100.07.9.8879+2 ▲
kubernetes110001000.02.4.0035+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091379343653322612730.28.1.0036+867 ▲
adobe952392610410541931.37.7.0026-37 ▼
ibm371615254550600.07.5.0036+5 ▲
progress283762470600.07.5.0037+23 ▲
solarwinds15221633010418.29.1.0058+12 ▲
zohocorp362220000.07.8.0146+2 ▲
veeam152300100.08.6.00510
atlassian3303001300.08.0.0026+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
d-link8200596300.05.5.0105-1 ▼
siemens7161870000.07.6.00240
abb170430000.07.2.0018-5 ▼
schneider electric060420000.07.8.0042-1 ▼
hikvision550320000.07.2.0038+5 ▲
moxa050320000.07.0.0029-5 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester49120006258000.05.5.0034+12 ▲
openclaw441110583914000.07.0.0026-17 ▼
dell4399547443211.07.1.0021+12 ▲
capgo2283242381000.07.1.0037-14 ▼
nvidia41801252160000.07.8.0037+35 ▲
imagemagick3273155512000.05.3.0019-1 ▼
spring073231391000.06.5.0024-72 ▼
itsourcecode1871001952000.02.1.0033-4 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-20230.882099.88.6
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-45659.760899.58.8
CVE-2026-0770.634299.19.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
CVE-2026-898510.0.0660
CVE-2026-1377310.0.0610
CVE-2026-651610.0.0486
Most disclosures (vendor)
VendorCVEs
oracle1109
linux893
microsoft651
google525
red hat144
apache121
adobe105
ibm80
mozilla72
sourcecodester61
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco11
apple7
google6
fortinet5
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven62
npm6
PyPI5
NuGet3
Packagist1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2026-0770Langflow0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-20230Cisco0
CVE-2026-25089Fortinet0
CVE-2026-45659Microsoft0
CVE-2026-46817Oracle Corporation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171709
CVE-2021-27102n/a2021-11-171709
CVE-2021-27101n/a2021-11-171709
CVE-2021-27103n/a2021-11-171709
CVE-2021-21017Adobe2021-11-171709
CVE-2021-28550Adobe2021-11-171709
CVE-2021-42013Apache Software Foundation2021-11-171709
CVE-2021-41773Apache Software Foundation2021-11-171709
CVE-2021-30858Apple2021-11-171709
CVE-2021-30860Apple2021-11-171709

Transactions

EXPLOIT PUBLISHED — cure53 DOMPurify: 9 CVEs (CVE-2026-65898, CVE-2026-65899, CVE-2026-65900, CVE-2026-65901, CVE-2026-65902, CVE-2026-65903, CVE-2026-65904, CVE-2026-65911, CVE-2026-65914). Public exploit references added.

EXPLOIT PUBLISHED — Ubiquiti UniFi OS: 3 CVEs (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-16489 (jsforce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16628 (oclif). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16630 (syncfusion ej2-javascript-ui-controls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-20253 (Splunk Enterprise). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26740. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42999 (OpenStack Keystone). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43000 (OpenStack Keystone). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44210 (kata-containers). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44891 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55831 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56292 (acymailing.com AcyMailing extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57827 (rsjoomla.com RSFiles extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57828 (phoca.cz Phoca Download extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64600 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-65012 (invoke-ai InvokeAI). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-65013 (onlook repo). Public exploit reference added.

RESCORED — Microsoft Windows 10 Version 1607: 4 CVEs (CVE-2026-42975, CVE-2026-50491, CVE-2026-54989, CVE-2026-57089). CVSS rescored — before/after on each CVE page.

RESCORED — Microsoft Windows 11 Version 24H2: 3 CVEs (CVE-2026-50317, CVE-2026-50440, CVE-2026-56187). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-10732 (decompress). CVSS 6.1 → 5.6 (NVD).

RESCORED — CVE-2026-13448 (IBM Langflow OSS). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-16631 (publint). CVSS 4.8 → 1.9 (NVD).

RESCORED — CVE-2026-16632 (boazsegev facil.io). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-42010 (Red Hat Enterprise Linux 10). CVSS 7.1 → 9.8 (NVD).

RESCORED — CVE-2026-42999 (OpenStack Keystone). CVSS 6 → 8.8 (NVD).

RESCORED — CVE-2026-43000 (OpenStack Keystone). CVSS 6 → 8.8 (NVD).

RESCORED — CVE-2026-44930 (Apache Software Foundation Apache CXF). CVSS 4.3 → 9.8 (NVD).

RESCORED — CVE-2026-50406 (Microsoft Windows 10 Version 21H2). CVSS 7 → 7.8 (NVD).

ENRICHED — Ubiquiti UniFi OS: 3 CVEs (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910). Received CVSS/CPE analysis.

ENRICHED — CVE-2026-10520 (Ivanti Sentry). Received CVSS 10.0 and CPE data from NVD.

ENRICHED — CVE-2026-11645 (Google Chromium V8). Received CVSS 8.8 and CPE data from NVD.

ENRICHED — CVE-2026-20253 (Splunk Enterprise). Received CVSS 9.8 and CPE data from NVD.

ENRICHED — CVE-2026-25089 (Fortinet FortiSandbox). Received CVSS 9.8 and CPE data from NVD.

ENRICHED — CVE-2026-34926 (Trend Micro Apex One). Received CVSS 6.7 and CPE data from NVD.

ENRICHED — CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools). Received CVSS 9.8 and CPE data from NVD.

ENRICHED — CVE-2026-45498 (Microsoft Defender). Received CVSS 7.5 and CPE data from NVD.

ENRICHED — CVE-2026-45659 (Microsoft SharePoint Server). Received CVSS 8.8 and CPE data from NVD.

ENRICHED — CVE-2026-48172 (LiteSpeed cPanel Plugin). Received CVSS 10.0 and CPE data from NVD.

ENRICHED — CVE-2026-48907 (Widget Factory Joomla Content Editor ). Received CVSS 10.0 and CPE data from NVD.

ENRICHED — CVE-2026-54420 (LiteSpeed cPanel Plugin). Received CVSS 8.5 and CPE data from NVD.

ENRICHED — CVE-2026-9082 (Drupal Core). Received CVSS 9.8 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

376 CVEs published. 25 box scores, 351 table rows — nothing truncated.

Alibaba Fastjson — Remote Code Execution in fastjson 1.2.68–1.2.83
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  H    9.0   .1599   96.6     —
AFFECTED
  Product   Versions  Fixed
  Fastjson  1.2.68 –  —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 23  Published (CNA: alibaba)
CWE-20, CWE-502 · CNA: alibaba · CVSS v3.1 · 1 reference · NVD status: Deferred
Zohocorp ManageEngine ADAudit Plus — Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  L   10.0   .0486   91.4     —
AFFECTED
  Product                    Versions     Fixed
  ManageEngine ADAudit Plus  unspecified  —
TIMELINE
  Apr 17  Reserved by CNA
  Jul 23  Published (CNA: Zohocorp)
CWE-78 · CNA: Zohocorp · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0388   89.4     —
AFFECTED
  Product  Versions   Fixed
  dbgate   < 7.1.9 –  —
TIMELINE
  May 19  Reserved by CNA
  Jul 23  Published (CNA: GitHub_M)
CWE-20, CWE-94, CWE-1188 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0339   87.9     —
AFFECTED
  Product     Versions     Fixed
  microweber  unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0192   78.3     —
AFFECTED
  Product  Versions     Fixed
  meshery  unspecified  —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Deferred
DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0171   75.6     —
AFFECTED
  Product  Versions   Fixed
  dbgate   < 7.1.9 –  —
TIMELINE
  May 19  Reserved by CNA
  Jul 23  Published (CNA: GitHub_M)
CWE-77, CWE-78 · CNA: GitHub_M · CVSS v4.0 · 2 references · NVD status: Deferred
h2oai h2ogpt — h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0152   72.6     —
AFFECTED
  Product  Versions     Fixed
  h2ogpt   unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
localstack serverless-localstack Configuration index.js os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0122   66.5     —
AFFECTED
  Product                Versions  Fixed
  serverless-localstack  1.0 –     —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 23  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
calcom cal.diy — Cal.com before 5.9.9 Remote Code Execution via RSC
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0120   65.8     —
AFFECTED
  Product  Versions     Fixed
  cal.diy  unspecified  5.9.9
TIMELINE
  Jul 16  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
decolua 9router — 9router before 0.4.60 Remote Code Execution via default password
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0101   60.5     —
AFFECTED
  Product  Versions     Fixed
  9router  unspecified  0.4.60
TIMELINE
  Jul 18  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Bold Reports Standalone Report Designer < 14.1.12 Path Traversal RCE via File Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0090   57.0     —
AFFECTED
  Product                     Versions  Fixed
  Standalone Report Designer  6.3 –     14.1.12
TIMELINE
  Jul 22  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0087   55.9     —
AFFECTED
  Product                     Versions  Fixed
  Standalone Report Designer  6.3 –     14.1.12
TIMELINE
  Jul 22  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0087   55.9     —
AFFECTED
  Product                     Versions  Fixed
  Standalone Report Designer  6.3 –     14.1.12
TIMELINE
  Jul 22  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Download
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0087   55.9     —
AFFECTED
  Product                     Versions  Fixed
  Standalone Report Designer  6.3 –     14.1.12
TIMELINE
  Jul 22  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
getgrav grav — Grav before 2.0.9 Remote Code Execution via FlexDirectory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0085   55.4     —
AFFECTED
  Product  Versions  Fixed
  grav     1.7.0 –   2.0.9
TIMELINE
  Jul 22  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-470 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
TUBITAK BILGEM Software Technologies Research Institute pardus-update — Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0084   55.1     —
AFFECTED
  Product        Versions  Fixed
  pardus-update  0.6.6 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 23  Published (CNA: TR-CERT)
CWE-78 · CNA: TR-CERT · CVSS v3.1 · 1 reference · NVD status: Deferred
cyberlord92 SAML Single Sign On – SSO Login — SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0080   53.7     —
AFFECTED
  Product                          Versions     Fixed
  SAML Single Sign On – SSO Login  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Jul 23  Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Awaiting Analysis
siyuan-note siyuan — SiYuan before v3.7.2 Stored XSS to RCE via Attribute View
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4   .0079   53.5     —
AFFECTED
  Product  Versions     Fixed
  siyuan   unspecified  3.7.2
TIMELINE
  Jul 22  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
siyuan-note siyuan — SiYuan before v3.7.2 Cross-Site Scripting to RCE
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4   .0079   53.5     —
AFFECTED
  Product  Versions     Fixed
  siyuan   unspecified  3.7.2
TIMELINE
  Jul 22  Reserved by CNA
  Jul 23  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
WPLake Advanced Views — WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0079   53.5     —
AFFECTED
  Product         Versions  Fixed
  Advanced Views  n/a –     3.9.0
TIMELINE
  Jul 5   Reserved by CNA
  Jul 23  Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
AWS aws-smithy-http-server — Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0075   52.2     —
AFFECTED
  Product                 Versions     Fixed
  aws-smithy-http-server  unspecified  —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 23  Published (CNA: AMZN)
CWE-770 · CNA: AMZN · CVSS v4.0 · 3 references · NVD status: Awaiting Analysis
Microsoft Account Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0072   51.2     —
AFFECTED
  Product            Versions  Fixed
  Microsoft Account  - –       —
TIMELINE
  Jun 19  Reserved by CNA
  Jul 23  Published (CNA: microsoft)
CWE-122 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
cascadiawebservices MountDev AI MCP Connector for WordPress — MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0071   50.8     —
AFFECTED
  Product                                  Versions     Fixed
  MountDev AI MCP Connector for WordPress  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 23  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Appriss Insights VINE SQLI
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0071   50.8     —
AFFECTED
  Product                                          Versions     Fixed
  Victim Information Notification Exchange (VINE)  unspecified  2026-05-07
TIMELINE
  Jul 16  Reserved by CNA
  Jul 23  Published (CNA: cisa-cg)
CWE-89 · CNA: cisa-cg · CVSS v4.0 · 2 references · NVD status: Undergoing Analysis
Microsoft Surface Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0071   50.7     —
AFFECTED
  Product                      Versions  Fixed
  Surface Management Services  - –       —
TIMELINE
  Jun 11  Reserved by CNA
  Jul 23  Published (CNA: microsoft)
CWE-20 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-637658.850.5chatwootchatwootCWE-306Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob …
CVE-2026-657019.350.2svc-develop-teamso-vits-svcCWE-22SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route
CVE-2026-166535.550.0boazsegevfacil.ioCWE-22boazsegev facil.io Public Folder http.c http_sendfile2 path traversal
CVE-2026-167675.549.6Ne-Lexaphp-zipCWE-22Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal
CVE-2026-150747.549.3@fastify/static@fastify/staticCWE-22@fastify/static vulnerable to route guard bypass via path traversal
CVE-2026-142829.849.3rtcampGoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & moreCWE-434GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Uplo…
CVE-2026-167968.447.3AWSbedrock-agentcore 1.18.1CWE-88Improper neutralization of argument delimiters in AWS Bedrock AgentCore Pytho…
CVE-2026-167351.947.1release-itconventional-changelogCWE-77release-it conventional-changelog Changelog File index.js writeChangelog os c…
CVE-2026-490359.246.7MZ AutomationlibIEC61850CWE-122Stack-based Buffer Overflow in MZ Automation libIEC61850
CVE-2026-167331.946.6bahmutovfind-cypress-specsCWE-77bahmutov find-cypress-specs Branch index.js shell.exec os command injection
CVE-2026-258007.546.5quinn-rsquinnCWE-770quinn-proto has remote memory exhaustion from unbounded out-of-order stream r…
CVE-2026-5955510.046.3Roland BarkerParticipants DatabaseCWE-22WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion v…
CVE-2026-160786.545.8kilbotWCPOS – Point of Sale (POS) plugin for WooCommerceCWE-22WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary Fi…
CVE-2026-656077.145.4siyuan-notesiyuanCWE-22SiYuan before v3.7.2 Path Traversal via /export/temp/
CVE-2026-561609.945.3MicrosoftAzure Red Hat OpenShift (ARO)CWE-285Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
CVE-2026-153486.345.1codename065Premium Packages – Sell Digital Products SecurelyCWE-287Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl'…
CVE-2026-657028.845.1vanna-aivannaCWE-22Vanna 2.0.2 Path Traversal via FileSystemConversationStore
CVE-2026-449097.544.8Facebookproxygen—Proxygen lacked a generalized slow-consumer detection mechanism in its core H…
CVE-2026-595449.844.3Thrive Themes CouponThrive Quiz BuilderCWE-502WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulne…
CVE-2024-583548.544.0calcomcal.diyCWE-77cal.com Repository Takeover via pull_request_target Workflow
CVE-2026-654977.243.0ComplianzComplianzCWE-502WordPress Complianz plugin <= 7.5.0 - PHP Object Injection vulnerability
CVE-2026-158275.342.9ataurrGutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block EditorCWE-862GutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Infor…
CVE-2026-6590610.042.7JetBrainsTeamCityCWE-94In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DS…
CVE-2026-142917.542.5Unknownsecurity-ninja-premiumCWE-287Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secni…
CVE-2026-477237.142.2juevnebula-meshCWE-1021nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Opt…
CVE-2026-658978.742.0getgravgravCWE-269Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups
CVE-2026-477529.941.7QuenarytugtainerCWE-1336Tugtainer has Server-Side Template Injection in notification templates that l…
CVE-2026-524399.841.5n/an/aCWE-917An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitra…
CVE-2026-476699.341.5dbgatedbgateCWE-22DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE
CVE-2026-4293310.041.3PronetiqsPanduit IntravueCWE-441Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs
CVE-2026-6481310.041.2JetBrainsIntelliJ IDEACWE-602In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification w…
CVE-2026-659178.740.9usmannasircyberpanelCWE-639CyberPanel IncBackups IDOR via Sequential Backup ID
CVE-2026-442105.840.7kata-containerskata-containersCWE-88Kata Containers have VM Escape via virtiofsd Argument Injection through Defau…
CVE-2024-583307.540.5BoschCamera FirmwareCWE-284A missing authentication check in Bosch IP cameras of families CPP13 and CPP1…
CVE-2026-270649.140.5EverPressMailsterCWE-434WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability
CVE-2026-654559.140.5MapSVGMapSVGCWE-434WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability
CVE-2026-654619.140.5Webの相談所Really Simple CSV ImporterCWE-434WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vu…
CVE-2026-150119.840.2emarket-designCustomer Support Ticket System & HelpdeskCWE-94Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Inj…
CVE-2026-216558.740.0Johnson ControlvictorCWE-502C-CURE 9000 and Victor application server - Deserialization of Untrusted Data
CVE-2026-648005.740.0JetBrainsGoLandCWE-532In JetBrains GoLand before 2026.2 sensitive configuration values written to l…
CVE-2026-659167.239.8usmannasircyberpanelCWE-862CyberPanel Missing Authorization in cancelBackupCreation Handler
CVE-2026-595409.839.4Cozy Vision Technologies Pvt. Ltd.SMS Alert Order NotificationsCWE-266WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalatio…
CVE-2026-619519.839.4themetechmountTrueBookerCWE-266WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability
CVE-2026-656957.639.4GongRzheOffice-Word-MCP-ServerCWE-22Office-Word-MCP-Server 1.1.11 Path Traversal via document tools
CVE-2026-477249.939.3juevnebula-meshCWE-862nebula-mesh: API endpoints lack ownership checks, enabling cross-operator pri…
CVE-2026-658967.139.0getgravgravCWE-73Grav API Plugin before 1.0.10 Path Traversal via move
CVE-2026-6481210.038.8JetBrainsIntelliJ IDEACWE-306In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was pos…
CVE-2026-159066.538.7codename065Premium Packages – Sell Digital Products SecurelyCWE-89Premium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby…
CVE-2026-595427.738.5WP ChillKali FormsCWE-22WordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerability
CVE-2026-656986.038.6voideditorvoidCWE-22Void 1.3.4 Path Traversal via AI Agent File-Reading Tools
CVE-2026-477228.738.4juevnebula-meshCWE-94nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
CVE-2026-646007.838.4LinuxLinuxCWE-362xfs: resample the data fork mapping after cycling ILOCK
CVE-2026-477695.338.4Work90210APIFoldCWE-306APIFold Vulnerable to Unauthenticated Webhook Event Injection
CVE-2026-142577.538.2juliangruberbrace-expansionCWE-400brace-expansion DoS via unbounded expansion length causing an out-of-memory p…
CVE-2026-633138.338.2decolua9routerCWE-9189Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch
CVE-2026-97137.538.1King-ThemeProduct Designer for WooCommerce WordPress | LumiseCWE-89Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticate…
CVE-2026-500328.737.9MZ AutomationlibIEC61850CWE-476NULL Pointer Dereference in MZ Automation libIEC61850
CVE-2026-500398.737.7MZ AutomationlibIEC61850CWE-121Stack-based Buffer Overflow in MZ Automation libIEC61850
CVE-2026-595458.137.6miniOrangeminiOrange Discord IntegrationCWE-288WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authenticat…
CVE-2026-130096.537.3wupsalesAI Copilot – Content GeneratorCWE-89AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0]…
CVE-2026-157616.537.3tickeraTickera – Sell Tickets & Manage EventsCWE-89Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filte…
CVE-2026-69248.736.8Silicon LabsSilicon Labs Matter GithubCWE-336Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path
CVE-2026-123535.336.2Red HatRed Hat Certificate System 9CWE-772Rhcs: memory leak during https connection leads to denial of service
CVE-2026-657625.136.2phoca.czPhoca Guestbook extension for JoomlaCWE-79Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook …
CVE-2026-657635.136.2phoca.czPhoca Maps extension for JoomlaCWE-79Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0…
CVE-2026-657598.736.0joomshaper.comEasy Store extension for JoomlaCWE-284Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in …
CVE-2026-167655.535.7CodeAstroOnline ClassroomCWE-74CodeAstro Online Classroom loginlinkadmin.php sql injection
CVE-2026-654777.535.5Select-ThemesTonda CoreCWE-98WordPress Tonda Core plugin <= 2.1.2 - Local File Inclusion vulnerability
CVE-2026-654817.535.5Elated-ThemesVinoCWE-98WordPress Vino theme <= 1.9 - Local File Inclusion vulnerability
CVE-2026-438237.535.4Appleswift-cryptoCWE-415When initializing an RSA public key from DER or PEM bytes throws an error, th…
CVE-2026-168078.835.4GoogleChromeCWE-787Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowe…
CVE-2026-160028.835.3MZ Automationlib60870CWE-125Out-of-bounds Read in MZ Automation lib60870
CVE-2026-595547.535.3ZiinaZiinaCWE-1390WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability
CVE-2026-654957.535.2Dokan Multivendor PluginDokan ProCWE-862WordPress Dokan Pro plugin <= 5.0.3 - Broken Access Control vulnerability
CVE-2026-657609.234.9joomshaper.comEasy Store extension for JoomlaCWE-284Joomla Extension - joomshaper.com - cross-customer order and personal informa…
CVE-2026-659079.134.8JetBrainsTeamCityCWE-94In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS ro…
CVE-2026-144816.434.6equalizedigitalEqualize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 complianceCWE-79Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor…
CVE-2026-168048.334.6GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a re…
CVE-2026-167458.834.4Red HatRed Hat OpenShift AI 2.25CWE-346Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-tok…
CVE-2026-595418.834.5Hakan OzevinWP BASE BookingCWE-266WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability
CVE-2026-595246.534.5Sandhills Development, LLCEasy Digital DownloadsCWE-288WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vuln…
CVE-2026-286989.234.3PronetiqsPanduit IntravueCWE-497Exposure of Sensitive System Information to an Unauthorized Control Sphere in…
CVE-2024-583539.334.3calcomcal.diyCWE-80Cal.com through 4.7.15 Cross-Site Scripting via booking questions
CVE-2024-583559.334.3calcomcal.diyCWE-80Cal.com through 4.7.15 Cross-Site Scripting via booking questions
CVE-2026-561678.834.2MicrosoftAzure AI SearchCWE-918Azure AI Search Elevation of Privilege Vulnerability
CVE-2026-131196.534.1roundupwpRegistrations for the Events Calendar – Event Registration PluginCWE-89Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) S…
CVE-2026-154486.534.1tickeraTickera – Sell Tickets & Manage EventsCWE-89Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_statu…
CVE-2026-576967.133.7videowhisperPicture GalleryCWE-22WordPress Picture Gallery plugin <= 1.6.5 - Arbitrary File Deletion vulnerabi…
CVE-2026-167642.133.6OWASPDefectDojoCWE-266OWASP DefectDojo API/Web serializers.py UserSerializer privileges management
CVE-2026-120827.533.5UnknownPraison AI SEOCWE-862Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post…
CVE-2026-167685.333.4GNOMEgdk-pixbufCWE-125Gdk-pixbuf: out-of-bounds read in ico parser
CVE-2026-595259.332.9Roland BarkerParticipants DatabaseCWE-89WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability
CVE-2026-595269.332.9RomanCodeMapSVGCWE-89WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability
CVE-2026-619499.332.9BooklyBooklyCWE-89WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability
CVE-2026-619509.332.9themetechmountTrueBookerCWE-89WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability
CVE-2026-654937.532.9DokanDokan ProCWE-502WordPress Dokan Pro plugin <= 5.0.2 - PHP Object Injection vulnerability
CVE-2026-659205.332.6huggingfacediffusersCWE-22Diffusers Path Traversal via weight_map Arbitrary File Read
CVE-2026-157864.432.6gowebsmartyWP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL SecurityCWE-22WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Writ…
CVE-2026-404308.732.2PronetiqsPanduit IntravueCWE-256Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs
CVE-2026-655007.532.2pixelacehqManual - Documentation, Knowledge Base & Education WordPress ThemeCWE-862WordPress Manual - Documentation, Knowledge Base & Education WordPress theme …
CVE-2026-216537.231.6Johnson ControlsCCure 9000 and victor application serverCWE-918CCure and Victor Application Server - Server Side Request Forgery
CVE-2026-168058.831.5GoogleChromeCWE-416Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a re…
CVE-2026-168068.831.5GoogleChromeCWE-416Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a r…
CVE-2026-477438.731.2shopperlabsshopperCWE-79Shopper: Multiple data integrity and disclosure issues in admin Livewire comp…
CVE-2026-654627.631.1Uncanny OwlUncanny AutomatorCWE-89WordPress Uncanny Automator plugin <= 7.3.2 - SQL Injection vulnerability
CVE-2026-655327.631.0PersianScriptPersian Woocommerce SMSCWE-89WordPress Persian Woocommerce SMS plugin <= 7.2.2 - SQL Injection vulnerability
CVE-2026-632266.931.1Ricoh CompanyRicoh printers and Multifunction Printers (MFPs)CWE-923Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do…
CVE-2026-273776.731.1axiomthemesQuickCal - Appointment Booking Calendar for WordPressCWE-862WordPress QuickCal - Appointment Booking Calendar for WordPress plugin <= 1.0…
CVE-2026-273555.330.9metaphorcreationsDittyCWE-862WordPress Ditty plugin <= 3.1.66 - Broken Access Control vulnerability
CVE-2026-654319.830.8regularlabs.comGeoIP extension for JoomlaCWE-22Joomla Extension - regularlabs.com - Zipslip in GeoIP extension
CVE-2026-577165.330.3videowhisperBroadcast Live VideoCWE-22WordPress Broadcast Live Video plugin <= 7.2.4 - Arbitrary File Deletion vuln…
CVE-2026-273726.530.1Pepro Dev. GroupPeproDev Ultimate InvoiceCWE-201WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Sensitive Data Exposure…
CVE-2026-619456.529.8MultiVendorXWooCommerce Product Stock AlertCWE-497WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Ex…
CVE-2026-71205.329.6@fastify/static@fastify/staticCWE-180@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
CVE-2026-480134.129.3shopwareshopwareCWE-918Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation
CVE-2026-150178.828.9mdjmMDJM Event ManagementCWE-269MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Esca…
CVE-2026-82874.328.6BizimHesap Information Systems Industry and Trade Inc.Online Pre-Accounting SoftwareCWE-770Unrestricted File Upload in BizimHesap Information Systems' Online Pre-Accoun…
CVE-2026-156179.128.4LogtoLogtoCWE-178Principal/domain lookup without case normalization
CVE-2026-245528.528.4John-Michael L'AllierCreateCWE-89WordPress Create plugin <= 2.5.3 - SQL Injection vulnerability
CVE-2026-254058.528.4DigitalMEeRoomCWE-89WordPress eRoom plugin <= 1.7.1 - SQL Injection vulnerability
CVE-2026-654508.528.4RomanCodeMapSVGCWE-89WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability
CVE-2026-654518.528.4RomanCodeMapSVGCWE-89WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability
CVE-2026-654548.528.4ExpressTech SystemsQuiz And Survey MasterCWE-89WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerability
CVE-2026-655268.528.4ThemeisleVisualizerCWE-89WordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerability
CVE-2026-477556.528.0itflow-orgitflowCWE-639ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unp…
CVE-2026-156872.427.9Kuberneteskubernetes-client/javaCWE-22Path traversal via non-tar copyDirectoryFromPod
CVE-2026-156119.127.8LogtoLogtoCWE-287Unverified email-based SSO account linking
CVE-2026-657619.327.3joomshaper.comEasy Store extension for JoomlaCWE-89Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Sto…
CVE-2026-595477.527.2Easy PaymentPayment Gateway for PayPal on WooCommerceCWE-862WordPress Payment Gateway for PayPal on WooCommerce plugin <= 9.1.4 - Broken …
CVE-2026-619547.527.2PayU IndiaPayU IndiaCWE-862WordPress PayU India plugin <= 3.8.9 - Broken Access Control vulnerability
CVE-2026-646117.527.1Red HatRed Hat Enterprise Linux 10CWE-835Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loo…
CVE-2026-72327.227.0FormCraftFormCraftCWE-79FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix …
CVE-2026-449556.927.0PronetiqsPanduit IntravueCWE-497Exposure of Sensitive System Information to an Unauthorized Control Sphere in…
CVE-2026-595226.526.5weDevsWP ERPCWE-862WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability
CVE-2026-573677.126.3WP Booking System .WP Booking SystemCWE-862WordPress WP Booking System plugin < 5.12.8.1 - Broken Access Control vulnera…
CVE-2026-657547.526.0regularlabs.comReReplacer PRo extension for JoomlaCWE-22Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro…
CVE-2026-574256.525.6wpdeskAutopay dla WooCommerceCWE-862WordPress Autopay dla WooCommerce plugin <= 2.2.27 - Broken Access Control vu…
CVE-2026-577176.525.6knitpayKnit PayCWE-862WordPress Knit Pay plugin <= 9.6.0.0 - Broken Access Control vulnerability
CVE-2026-97296.425.5webpushrWeb Push Notifications – WebpushrCWE-79Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-…
CVE-2026-153946.425.5mahethekillerHeader Footer Script AdderCWE-79Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site…
CVE-2026-154046.425.5niklaslindemannBulk Page Generator – LPageryCWE-79Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site…
CVE-2026-156466.425.5berocketBrands for WooCommerceCWE-79Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-S…
CVE-2026-157946.425.5berocketGrid/List View for WooCommerceCWE-79Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored…
CVE-2026-648159.825.4JetBrainsIntelliJ IDEACWE-94In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possibl…
CVE-2026-659187.125.3pytorchvisionCWE-125PyTorch torchvision GIF Decoder Out-of-bounds Heap Read
CVE-2026-654745.325.3WPManageNinjaNinja TablesCWE-497WordPress Ninja Tables plugin <= 5.2.10 - Sensitive Data Exposure vulnerability
CVE-2026-654905.325.3mischiefmarmotCreate by MediavineCWE-497WordPress Create by Mediavine plugin <= 2.5.3 - Sensitive Data Exposure vulne…
CVE-2026-654985.325.3ComplianzComplianzCWE-497WordPress Complianz plugin <= 7.5.0 - Sensitive Data Exposure vulnerability
CVE-2026-655055.325.3bdthemesUltimate Store Kit Elementor AddonsCWE-497WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Sensitive Dat…
CVE-2026-655215.325.3Mahmudul Hasan ArifWP Social NinjaCWE-497WordPress WP Social Ninja plugin <= 4.3.0 - Sensitive Data Exposure vulnerabi…
CVE-2026-658958.225.2getgravgravCWE-862Grav API Plugin before 1.0.10 Broken Access Control
CVE-2026-156169.125.2LogtoLogtoCWE-308Local MFA not enforced during SSO sign-in
CVE-2026-217235.325.1GrafanaGrafana OSSCWE-400CVE-2026-21723 Record
CVE-2026-344967.124.9Johnson Controlsvictor WebCWE-269victor Web - Priviledge Escalation
CVE-2026-659035.124.8cure53DOMPurifyCWE-697DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS
CVE-2026-648148.624.4JetBrainsIntelliJ IDEACWE-862In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possibl…
CVE-2026-96356.424.3mythemeshopWP Shortcode by MyThemeShopCWE-79WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored C…
CVE-2026-75347.224.0FantasticPluginsSUMO Reward Points for WooCommerceCWE-79SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-S…
CVE-2026-124217.224.0n/aARformsCWE-79ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password'…
CVE-2026-659135.123.9cure53DOMPurifyCWE-1321DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES
CVE-2026-657588.223.5tassos.grConvert Forms extension for JoomlaCWE-284Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms exten…
CVE-2026-647997.523.4regularlabs.comArticles Anywhere Pro extension for JoomlaCWE-918Joomla Extension - regularlabs.com - SSRF via remote image downloads in Artic…
CVE-2026-254665.323.4WPGMapsWP Go MapsCWE-862WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability
CVE-2026-654525.323.4motov.netEbook StoreCWE-862WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability
CVE-2026-654855.323.4Daniel IserContent ControlCWE-862WordPress Content Control plugin <= 2.6.5 - Broken Access Control vulnerability
CVE-2026-654865.323.4Bastien HoEvent postCWE-862WordPress Event post plugin <= 6.0.1 - Broken Access Control vulnerability
CVE-2026-654895.323.4LA-StudioLA-Studio Element Kit for ElementorCWE-862WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access…
CVE-2026-655015.323.4vendideroShiptastic for WooCommerceCWE-639WordPress Shiptastic for WooCommerce plugin <= 5.1.0 - Insecure Direct Object…
CVE-2026-655295.323.4Iqonic DesignGraphinaCWE-862WordPress Graphina plugin <= 3.1.12 - Broken Access Control vulnerability
CVE-2026-156474.423.2berocketBrands for WooCommerceCWE-79Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-…
CVE-2026-578086.521.9Saad IqbalWP EasyPayCWE-862WordPress WP EasyPay plugin <= 4.5.0 - Arbitrary Content Deletion vulnerability
CVE-2026-654584.321.4ChoubyPolylangCWE-497WordPress Polylang and Polylang Pro plugins <= 3.8.5 - Sensitive Data Exposur…
CVE-2026-655354.321.4Takayuki MiyauchiTinyMCE TemplatesCWE-497WordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnera…
CVE-2026-273995.321.4WebWizardsMarketKingCWE-862WordPress MarketKing plugin <= 2.1.40 - Broken Access Control vulnerability
CVE-2026-274185.321.4EpsiloncoolWP Fast Total SearchCWE-862WordPress WP Fast Total Search plugin <= 1.81.282 - Broken Access Control vul…
CVE-2026-274225.321.4bPluginsYT PlayerCWE-862WordPress YT Player plugin <= 2.0.9 - Broken Access Control vulnerability
CVE-2026-619725.321.4WooLentorShopLentor ProCWE-862WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability
CVE-2026-654535.321.4motov.netEbook StoreCWE-862WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability
CVE-2026-654685.321.4Crocoblock. Jetimpex Inc.JetBookingCWE-862WordPress JetBooking plugin <= 4.1.2 - Broken Access Control vulnerability
CVE-2026-654695.321.4Strategy11 TeamAWP ClassifiedsCWE-862WordPress AWP Classifieds plugin <= 4.4.7 - Broken Access Control vulnerability
CVE-2026-654725.321.4KitKit (formerly ConvertKit)CWE-862WordPress Kit (formerly ConvertKit) plugin <= 3.3.5 - Broken Access Control v…
CVE-2026-654765.321.4uxperCiviCWE-862WordPress Civi theme <= 2.2.4 - Broken Access Control vulnerability
CVE-2026-654875.321.4ThemeGoodsPhotographyCWE-862WordPress Photography theme <= 7.7.6 - Broken Access Control vulnerability
CVE-2026-655065.321.4sonaarMP3 Audio Player for Music, Radio & Podcast by SonaarCWE-862WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.1…
CVE-2026-655255.321.4uxperCivi FrameworkCWE-862WordPress Civi Framework plugin <= 2.2.0 - Broken Access Control vulnerability
CVE-2026-106979.821.1ProgressMOVEit TransferCWE-287MFA Bypass in MOVEit Transfer
CVE-2026-657038.521.1FFmpegFFmpegCWE-787FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder
CVE-2026-648749.820.9regularlabs.comCache Cleaner Pro extension for JoomlaCWE-200Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro…
CVE-2026-656048.821.0zalandoskipperCWE-20Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass
CVE-2026-254275.420.7DigitalMEeRoomCWE-862WordPress eRoom plugin <= 1.7.1 - Broken Access Control vulnerability
CVE-2026-273915.420.7StylemixuListingCWE-862WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability
CVE-2026-654635.420.7masteriyoMasteriyo - LMSCWE-639WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References…
CVE-2026-654795.420.7MVP ThemesReviewerCWE-862WordPress Reviewer plugin <= 3.14.2 - Broken Access Control vulnerability
CVE-2026-654947.120.5DokanDokan ProCWE-89WordPress Dokan Pro plugin <= 5.0.2 - SQL Injection vulnerability
CVE-2026-619489.320.2ShahjadaWPDM – Premium PackagesCWE-89WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability
CVE-2026-619466.520.2Easy AppointmentsEasy AppointmentsCWE-639WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object Refere…
CVE-2026-619437.519.7ShahjadaWPDM – Premium PackagesCWE-862WordPress WPDM – Premium Packages plugin <= 6.2.0 - Broken Access Control vul…
CVE-2026-656992.319.4reworkdAgentGPTCWE-639AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation
CVE-2026-480124.319.3shopwareshopwareCWE-601Shopware SSO referer trust leading to an arbitrary redirect target
CVE-2026-656975.119.1usefathomfathomCWE-79Fathom Lite 1.3.1 Stored XSS via /collect Endpoint
CVE-2026-654564.318.7PickPluginsProduct Slider for WooCommerceCWE-639WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct …
CVE-2026-654914.318.7Jonathan DaggerhartQuery WranglerCWE-862WordPress Query Wrangler plugin <= 1.5.57 - Broken Access Control vulnerability
CVE-2026-655244.318.7ThemeFusionAvada Custom BrandingCWE-862WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnera…
CVE-2026-655304.318.7TemplatespareTemplateSpareCWE-862WordPress TemplateSpare plugin <= 4.2.2 - Broken Access Control vulnerability
CVE-2026-501037.118.5MZ AutomationlibIEC61850CWE-228Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC6…
CVE-2026-648739.818.5regularlabs.comCache Cleaner Pro extension for JoomlaCWE-918Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension
CVE-2026-655167.218.1Pepro Dev. GroupPeproDev Ultimate InvoiceCWE-918WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Server Side Request For…
CVE-2026-654996.518.1Pepro Dev. GroupPeproDev Ultimate InvoiceCWE-862WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Broken Access Control v…
CVE-2026-658995.118.3cure53DOMPurifyCWE-693DOMPurify before 3.4.9 Trusted Types Policy State Contamination
CVE-2026-601228.517.9gpsdgpsdCWE-94gpsd gpsprof Code Injection via SKY.satellites used Field
CVE-2026-150372.917.6QtQtCWE-91XML injection vulnerability in QDom comment, CDATA and processing-instruction…
CVE-2026-577036.317.3sunshinephotocartSunshine Photo CartCWE-862WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vuln…
CVE-2026-654846.317.3AnalogWPStyle KitsCWE-862WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability
CVE-2026-656965.317.3sctoverseerrCWE-639Overseerr 1.35.0 Authorization Bypass via pushSubscriptions API
CVE-2026-254244.316.6mediavineMediavine Control PanelCWE-862WordPress Mediavine Control Panel plugin <= 2.10.10 - Broken Access Control v…
CVE-2026-273924.316.6StylemixuListingCWE-862WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability
CVE-2026-274234.316.6Roland BarkerParticipants DatabaseCWE-862WordPress Participants Database plugin <= 2.7.8.4 - Broken Access Control vul…
CVE-2026-619734.316.6WooLentorShopLentor ProCWE-862WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability
CVE-2026-654574.316.6yoomoneyЮKassa для WooCommerceCWE-862WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Broken Access Control vul…
CVE-2026-655374.316.6ThemeisleCyr to Lat reloaded – transliteration of links and file namesCWE-862WordPress Cyr to Lat reloaded – transliteration of links and file names plugi…
CVE-2026-90666.116.4UnknownWP CompressCWE-79WP Compress < 7.10.04 - Reflected XSS via test_zone
CVE-2026-657566.116.4regularlabs.comKeyboard Shortcuts extension for JoomlaCWE-79Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension
CVE-2026-573707.116.3CODEPRESS IT Solutions LLCVisitor Traffic Real Time Statistics ProCWE-79WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.9.1 - Reflect…
CVE-2026-573747.116.2Wisetr INC.Funnel Kit Funnel Builder PROCWE-79WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.7 - Cross Site Scrip…
CVE-2026-573977.116.3ThimPress.CoachingCWE-79WordPress Coaching theme <= 3.9.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-574277.116.2Download MonitorDownload Monitor - WPForms LockCWE-79WordPress Download Monitor - WPForms Lock plugin <= 1.0.4 - Cross Site Script…
CVE-2026-574287.116.2BoldGridSprout ClientsCWE-79WordPress Sprout Clients plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnera…
CVE-2026-576997.116.3bqworksSlider ProCWE-79WordPress Slider Pro plugin <= 4.8.13 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577017.116.3WebCodingPlaceReal Estate Manager ProCWE-79WordPress Real Estate Manager Pro plugin <= 12.8.5 - Reflected Cross Site Scr…
CVE-2026-577047.116.3StoreAppsSmart ManagerCWE-79WordPress Smart Manager plugin <= 8.90.0 - Cross Site Scripting (XSS) vulnera…
CVE-2026-577357.116.3SoflyyBreakdanceCWE-79WordPress Breakdance plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577677.116.3CodeCabin.ioWP Google Maps ProCWE-79WordPress WP Google Maps Pro plugin <= 10.1.02 - Cross Site Scripting (XSS) v…
CVE-2026-577697.116.3ThemeGoodsGrand PhotographyCWE-79WordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (…
CVE-2026-578097.116.3AffiliateWPAffiliateWPCWE-79WordPress AffiliateWP plugin <= 2.34.0 - Reflected Cross Site Scripting (XSS)…
CVE-2026-595127.116.3PI Web SolutionProduct Enquiry for WooCommerceCWE-79WordPress Product Enquiry for WooCommerce plugin <= 2.2.34.43 - Cross Site Sc…
CVE-2026-595177.116.3hassantafreshiEasy Form BuilderCWE-79WordPress Easy Form Builder plugin <= 4.0.12 - Cross Site Scripting (XSS) vul…
CVE-2026-619447.116.3BooklyBooklyCWE-79WordPress Bookly plugin <= 27.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-619477.116.3WPVibesForm Vibes – Database Manager for FormsCWE-79WordPress Form Vibes – Database Manager for Forms plugin <= 1.5.2 - Cross Sit…
CVE-2026-654927.116.3Dokan WordPress PluginDokan ProCWE-79WordPress Dokan Pro plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-655107.116.3Pepro Dev. GroupPeproDev Ultimate InvoiceCWE-79WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Cross Site Scripting (X…
CVE-2026-655117.116.3pixelacehqManual - Documentation, Knowledge Base & Education WordPress ThemeCWE-79WordPress Manual - Documentation, Knowledge Base & Education WordPress Theme …
CVE-2026-156309.915.6CasdoorCasdoorCWE-269CVE-2026-15630
CVE-2026-654307.515.5regularlabs.comGeoIP extension for JoomlaCWE-200Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP exte…
CVE-2026-657557.515.5regularlabs.comArticles Anywhere extension for JoomlaCWE-524Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Ar…
CVE-2026-95774.815.1UnknownPost Status Notifier LiteCWE-79Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
CVE-2025-680815.914.9Lester ChanWP-PollsCWE-79WordPress WP-Polls plugin <= 2.77.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-246285.914.9SupsysticPhoto Gallery by SupsysticCWE-79WordPress Photo Gallery by Supsystic plugin <= 1.16.3 - Cross Site Scripting …
CVE-2026-654835.914.9hashthemesHashThemes Demo ImporterCWE-79WordPress HashThemes Demo Importer plugin <= 1.4.2 - Cross Site Scripting (XS…
CVE-2026-655345.914.9Charlie EtienneCustom links in Elementor Image CarouselCWE-79WordPress Custom links in Elementor Image Carousel plugin <= 1.1.1 - Cross Si…
CVE-2026-655385.914.9Nilo VelezMacheteCWE-79WordPress Machete plugin <= 5.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-655505.914.9wpshopmartTabsCWE-79WordPress Tabs plugin <= 2.5 - Cross Site Scripting (XSS) vulnerability
CVE-2026-659025.314.5cure53DOMPurifyCWE-501DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags
CVE-2026-118045.214.3TridiumNiagara FrameworkCWE-280Program Module Vulnerability
CVE-2026-485305.114.2GFI SoftwareGFI ArchiverCWE-79GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx
CVE-2026-485315.114.2GFI SoftwareGFI ArchiverCWE-79GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx
CVE-2026-485325.114.2GFI SoftwareGFI ArchiverCWE-79GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx
CVE-2026-485345.114.2GFI SoftwareGFI ArchiverCWE-79GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx
CVE-2026-485355.114.2GFI SoftwareGFI ArchiverCWE-79GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx
CVE-2026-485365.114.2GFI SoftwareGFI ArchiverCWE-79GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx
CVE-2026-485375.114.2GFI SoftwareGFI ArchiverCWE-79GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx
CVE-2026-485385.114.2GFI SoftwareGFI ArchiverCWE-79GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx
CVE-2026-485395.114.2GFI SoftwareGFI ArchiverCWE-79GFI Archiver < 15.13 Stored XSS via MailInsights.aspx
CVE-2026-659115.113.9cure53DOMPurifyCWE-79DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage
CVE-2026-156147.513.5LogtoLogtoCWE-294IdP-initiated SAML sessions not reliably invalidated (replay)
CVE-2026-654785.413.6CridioStudioListingProCWE-862WordPress ListingPro plugin <= 2.9.10 - Broken Access Control vulnerability
CVE-2026-595149.313.5MightyNetworks vs BuddyBossBuddyboss PlatformCWE-89WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability
CVE-2026-165847.313.2AWSaws-api-mcp-serverCWE-455AWS API MCP Server Security Policy Bypass via Startup Failure
CVE-2026-274036.512.9NerdPressHubbub LiteCWE-79WordPress Hubbub Lite plugin <= 1.36.3 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-573736.512.9Wisetr INC.Funnel Kit Funnel Builder PROCWE-79WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.4 - Cross Site Scrip…
CVE-2026-573846.512.9Membership SoftwareWishList Member XCWE-79WordPress WishList Member X plugin <= 3.32.0 - Cross Site Scripting (XSS) vul…
CVE-2026-595136.512.9masteriyoMasteriyo - LMSCWE-79WordPress Masteriyo - LMS plugin <= 2.3.0 - Cross Site Scripting (XSS) vulner…
CVE-2026-648726.512.8regularlabs.comCache Cleaner Pro extension for JoomlaCWE-22Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro exte…
CVE-2026-654496.512.9RomanCodeMapSVGCWE-79WordPress MapSVG plugin <= 8.14.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-654656.512.9Crocoblock. Jetimpex Inc.JetElements For ElementorCWE-79WordPress JetElements For Elementor plugin <= 2.9.1.1 - Cross Site Scripting …
CVE-2026-654706.512.9WPManageNinjaFluent SupportCWE-79WordPress Fluent Support plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnera…
CVE-2026-654736.512.9NexcessVirtue/Ascend/Pinnacle ToolkitCWE-79WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12 - Cross Site Script…
CVE-2026-654756.512.9WP ChillModula Image GalleryCWE-79WordPress Modula Image Gallery plugin 2.14.25-2.14.30 - Cross Site Scripting …
CVE-2026-654806.512.9CodexThemesTheGemCWE-79WordPress TheGem theme < 5.12.1.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-654826.512.9LA-StudioLA-Studio Element Kit for ElementorCWE-79WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Sc…
CVE-2026-655036.512.9bdthemesUltimate Store Kit Elementor AddonsCWE-79WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Cross Site Sc…
CVE-2026-655146.512.9codepeopleAppointment Hour BookingCWE-79WordPress Appointment Hour Booking plugin <= 1.5.86 - Cross Site Scripting (X…
CVE-2026-655186.512.9Scott PatersonAccept Donations with PayPal & StripeCWE-79WordPress Accept Donations with PayPal & Stripe plugin <= 1.5.5 - Cross Site …
CVE-2026-655196.512.9gt3themesPhoto GalleryCWE-79WordPress Photo Gallery plugin <= 2.7.7.29 - Cross Site Scripting (XSS) vulne…
CVE-2026-655226.512.9pixelacehqManual - Documentation, Knowledge Base & Education WordPress ThemeCWE-79WordPress Manual - Documentation, Knowledge Base & Education WordPress theme …
CVE-2026-655276.512.9lqdLIQUID SPEECH BALLOONCWE-79WordPress LIQUID SPEECH BALLOON plugin <= 1.2.5 - Cross Site Scripting (XSS) …
CVE-2026-655286.512.9bannerskyBSK PDF ManagerCWE-79WordPress BSK PDF Manager plugin <= 3.8 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-655336.512.9wbolt.comSmart SEO ToolCWE-79WordPress Smart SEO Tool plugin <= 4.1.2 - Cross Site Scripting (XSS) vulnera…
CVE-2026-657136.512.8regularlabs.comModals Pro extension for JoomlaCWE-22Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro ext…
CVE-2026-655314.812.0ThemeumQubelyCWE-862WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerability
CVE-2026-648756.511.6regularlabs.comGeoIP extension for JoomlaCWE-290Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP exten…
CVE-2026-658985.111.4cure53DOMPurifyCWE-79DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig
CVE-2026-648027.811.2JetBrainsGoLandCWE-94In JetBrains GoLand before 2026.2 arbitrary code execution was possible befor…
CVE-2026-648037.811.2JetBrainsGoLandCWE-94In JetBrains GoLand before 2026.2 arbitrary code execution was possible befor…
CVE-2026-659005.110.9cure53DOMPurifyCWE-79DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM
CVE-2026-246394.410.8Ronald HuerecaPhoto BlockCWE-918WordPress Photo Block plugin <= 1.7.1 - Server Side Request Forgery (SSRF) vu…
CVE-2026-654964.410.8ComplianzComplianzCWE-918WordPress Complianz plugin <= 7.5.0 - Server Side Request Forgery (SSRF) vuln…
CVE-2026-659145.310.7cure53DOMPurifyCWE-79DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization
CVE-2026-659042.310.5cure53DOMPurifyCWE-754DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode
CVE-2026-159669.810.3ProgressMOVEit TransferCWE-942Improper CORS handling in MOVEit Transfer
CVE-2026-159679.810.3ProgressMOVEit TransferCWE-613MOVEit Transfer refresh-token processing does not enforce updated account res…
CVE-2026-577849.69.8Ninja FormsNinja Forms File Uploads ExtensionCWE-352WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Re…
CVE-2026-654719.69.8Avada StudioAvada CoreCWE-352WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vul…
CVE-2026-577858.89.8ApusThemeApusListingCWE-352WordPress ApusListing theme <= 1.2.63 - Cross Site Request Forgery (CSRF) vul…
CVE-2026-648048.48.8JetBrainsWebStormCWE-829In JetBrains WebStorm before 2026.2 arbitrary code execution was possible bef…
CVE-2026-648058.48.8JetBrainsWebStormCWE-829In JetBrains WebStorm before 2026.2 arbitrary code execution was possible bef…
CVE-2026-648068.48.8JetBrainsWebStormCWE-829In JetBrains WebStorm before 2026.2 arbitrary code execution was possible bef…
CVE-2026-648088.48.8JetBrainsPhpStormCWE-829In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible bef…
CVE-2026-648098.48.8JetBrainsPhpStormCWE-829In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible bef…
CVE-2026-659015.18.9cure53DOMPurifyCWE-79DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName
CVE-2026-654664.98.4Crocoblock. Jetimpex Inc.JetBookingCWE-918WordPress JetBooking plugin <= 4.1.2 - Server Side Request Forgery (SSRF) vul…
CVE-2026-654674.98.4Crocoblock. Jetimpex Inc.JetEngineCWE-918WordPress JetEngine plugin <= 3.8.11 - Server Side Request Forgery (SSRF) vul…
CVE-2026-657068.58.3FFmpegFFmpegCWE-131FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing
CVE-2026-657057.38.3FFmpegFFmpegCWE-131FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()
CVE-2026-659088.68.1JetBrainsPyCharmCWE-829In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via mal…
CVE-2026-387647.88.1n/an/aCWE-269An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at…
CVE-2026-648077.88.1JetBrainsWebStormCWE-829In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via…
CVE-2026-156129.17.8LogtoLogtoCWE-345LOIDC nonce validation bypass
CVE-2026-156157.57.8LogtoLogtoCWE-345SAML <Conditions> element not validated
CVE-2026-159685.47.7ProgressMOVEit TransferCWE-79Stored XSS vulnerability in MOVEit Transfer
CVE-2026-647855.37.6Appleswift-nio-http2CWE-444SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR,…
CVE-2026-657047.37.4FFmpegFFmpegCWE-191FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder
CVE-2026-659125.16.9cure53DOMPurifyCWE-79DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR
CVE-2026-650104.46.7huggingfacedatasetsCWE-61Datasets Symlink-following Arbitrary File Write via Extractor.extract()
CVE-2026-655366.56.1Mahdi Yousefiافزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری)CWE-352WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <…
CVE-2026-596787.15.2Linux-GamingPortProtonQtCWE-863portprotonqt allows any users to mount and unmount arbitrary file systems and…
CVE-2026-152128.85.1wpo365WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)CWE-352WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 …
CVE-2026-63906.84.8Red HatRed Hat Enterprise Linux 10CWE-134Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of…
CVE-2026-391556.54.4n/an/aCWE-345Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod…
CVE-2026-648106.14.3JetBrainsIntelliJ IDEACWE-79In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an ID…
CVE-2026-657126.24.0regularlabs.comCDN for Joomla Pro extension for JoomlaCWE-22Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla…
CVE-2026-655125.43.8MelapressWP Activity LogCWE-352WordPress WP Activity Log and WP Activity Log Premium plugins <= 5.6.4 - Cros…
CVE-2026-526843.73.8PowerDNSRecursor—Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack
CVE-2026-245374.33.7Alex VolkovWP Accessibility Helper (WAH)CWE-352WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request …
CVE-2026-654604.33.7zarinpalZarinpal GatewayCWE-352WordPress Zarinpal Gateway plugin <= 5.1.0 - Cross Site Request Forgery (CSRF…
CVE-2026-596776.83.5SELinuxProjectselinuxCWE-862Process Kill Attack Vector in killall() in seunshare
CVE-2026-619815.43.4QuantumCloudSimple Link Directory ProCWE-352WordPress Simple Link Directory Pro plugin <= 15.0.8 - Cross Site Request For…
CVE-2026-654645.43.4NexcessGiveWPCWE-352WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnera…
CVE-2026-657578.12.9regularlabs.comModules Anywhere extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-500447.62.8PronetiqsPanduit IntravueCWE-326Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs
CVE-2026-576267.12.7MailPoetMailPoetCWE-352WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) v…
CVE-2026-654887.12.7LA-StudioLA-Studio Element Kit for ElementorCWE-352WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Re…
CVE-2026-655397.12.7Bimal RekhadiyaKwayy HTML SitemapCWE-352WordPress Kwayy HTML Sitemap plugin <= 4.0 - CSRF to Stored XSS vulnerability
CVE-2026-655407.12.7Metin SaraçPopup for CF7 with Sweet AlertCWE-352WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request…
CVE-2026-648768.82.6regularlabs.comGeoIP extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-648117.82.5JetBrainsIntelliJ IDEACWE-829In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possibl…
CVE-2026-526887.52.2PowerDNSRecursorCWE-295RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
CVE-2024-580238.41.4BoschBosch Configuration ManagerCWE-312Information disclosure in Bosch Configuration Manager in Version 7.72.0106 al…
CVE-2026-526863.71.3PowerDNSRecursorCWE-347Wildcard CNAME proof validation bypass
CVE-2026-648715.40.7regularlabs.comCache Cleaner extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-596765.80.4SELinuxProjectselinuxCWE-367Local File Deletion Attack Vector in rm_rf() in seunshare
CVE-2026-438207.70.1Appleswift-nio-sslCWE-125NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes f…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-23 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.