AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H N N 5.9 .2915 98.0 YES
AFFECTED Product Versions Fixed FortiOS 7.6.0 – —
TIMELINE Dec 23 Reserved by CNA Jul 27 Added to CISA KEV, due Aug 10 Jul 27 Published (CNA: fortinet)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
440 CVEs published, led by Apple (164).
440 CVEs published July 27, 2026: 91 critical, 167 high, 162 medium, 14 low; 2 in the KEV catalog at press time; 6 with a public exploit reference; 6 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 40 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 8399 | 20802 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
884 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 829 | 2309 | 207 | 1226 | 637 | 1 | 11 | 2 | 0.1 | 7.8 | .0016 | +317 ▲ |
| microsoft | 663 | 1420 | 105 | 981 | 320 | 14 | 286 | 24 | 1.7 | 7.8 | .0047 | +443 ▲ |
| 120 | 1385 | 156 | 634 | 556 | 39 | 77 | 6 | 0.4 | 7.8 | .0025 | -587 ▼ | |
| red hat | 124 | 346 | 16 | 135 | 172 | 23 | 2 | 0 | 0.0 | 6.5 | .0031 | +16 ▲ |
| apple | 167 | 271 | 57 | 78 | 133 | 3 | 88 | 7 | 2.6 | 6.5 | .0027 | +152 ▲ |
| canonical | 7 | 27 | 3 | 8 | 11 | 5 | 0 | 0 | 0.0 | 5.6 | .0014 | +1 ▲ |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0039 | +4 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | -9 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 15 | 37 | 8 | 18 | 11 | 0 | 56 | 11 | 29.7 | 7.5 | .0057 | +5 ▲ |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +17 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| fortinet | 14 | 23 | 6 | 6 | 11 | 0 | 28 | 6 | 26.1 | 7.2 | .0040 | +12 ▲ |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | -11 ▼ |
| f5 | 8 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | +2 ▲ |
| vmware | 8 | 12 | 1 | 8 | 2 | 1 | 7 | 1 | 8.3 | 8.2 | .0039 | +5 ▲ |
| checkpoint | 3 | 12 | 3 | 6 | 3 | 0 | 3 | 2 | 16.7 | 7.7 | .0455 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 120 | 275 | 57 | 111 | 95 | 11 | 33 | 1 | 0.4 | 7.5 | .0058 | +16 ▲ |
| mozilla | 71 | 127 | 51 | 42 | 34 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | +22 ▲ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -17 ▼ |
| github | 5 | 11 | 1 | 2 | 8 | 0 | 0 | 0 | 0.0 | 6.0 | .0042 | +4 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -4 ▼ |
| wordpress | 2 | 2 | 1 | 0 | 1 | 0 | 2 | 2 | 100.0 | 7.9 | .8879 | +2 ▲ |
| kubernetes | 1 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1109 | 1379 | 343 | 653 | 322 | 61 | 27 | 3 | 0.2 | 8.1 | .0036 | +867 ▲ |
| adobe | 95 | 239 | 26 | 104 | 105 | 4 | 19 | 3 | 1.3 | 7.7 | .0026 | -37 ▼ |
| ibm | 37 | 161 | 52 | 54 | 55 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +5 ▲ |
| progress | 33 | 42 | 6 | 29 | 7 | 0 | 6 | 0 | 0.0 | 8.0 | .0038 | +28 ▲ |
| solarwinds | 15 | 22 | 16 | 3 | 3 | 0 | 10 | 4 | 18.2 | 9.1 | .0058 | +12 ▲ |
| zohocorp | 3 | 6 | 2 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0146 | +2 ▲ |
| veeam | 1 | 5 | 2 | 3 | 0 | 0 | 1 | 0 | 0.0 | 8.6 | .0051 | 0 |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | +10 ▲ |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| d-link | 8 | 20 | 0 | 5 | 9 | 6 | 3 | 0 | 0.0 | 5.5 | .0105 | -1 ▼ |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| abb | 1 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -5 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -6 ▼ |
| hikvision | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0038 | +5 ▲ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -5 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 49 | 120 | 0 | 0 | 62 | 58 | 0 | 0 | 0.0 | 5.5 | .0034 | +12 ▲ |
| openclaw | 44 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -17 ▼ |
| dell | 43 | 99 | 5 | 47 | 44 | 3 | 2 | 1 | 1.0 | 7.1 | .0021 | +5 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | -24 ▼ |
| nvidia | 42 | 81 | 12 | 53 | 16 | 0 | 0 | 0 | 0.0 | 7.8 | .0037 | +36 ▲ |
| imagemagick | 33 | 74 | 1 | 5 | 56 | 12 | 0 | 0 | 0.0 | 5.3 | .0018 | -2 ▼ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -72 ▼ |
| itsourcecode | 18 | 71 | 0 | 0 | 19 | 52 | 0 | 0 | 0.0 | 2.1 | .0033 | -4 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-63030 | .9779 | 99.9 | 9.8 |
| CVE-2026-16232 | .8912 | 99.8 | 9.3 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-60137 | .7979 | 99.6 | 5.9 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-0770 | .6342 | 99.1 | 9.8 |
| CVE-2026-48282 | .4239 | 98.6 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 | |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-13773 | 10.0 | .0610 | |
| CVE-2026-6516 | 10.0 | .0486 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 830 |
| microsoft | 664 |
| 503 | |
| apple | 204 |
| red hat | 144 |
| apache | 137 |
| adobe | 105 |
| ibm | 80 |
| mozilla | 72 |
| Vendor | KEV |
|---|---|
| microsoft | 24 |
| cisco | 11 |
| apple | 7 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 68 |
| PyPI | 5 |
| NuGet | 4 |
| npm | 4 |
| Go | 3 |
| Packagist | 2 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE-2026-46817 | Oracle Corporation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1713 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1713 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1713 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1713 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1713 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1713 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1713 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1713 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1713 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1713 |
EXPLOIT PUBLISHED — strukturag libheif: 5 CVEs (CVE-2026-47178, CVE-2026-47247, CVE-2026-47251, CVE-2026-47254, CVE-2026-47709). Public exploit references added.
EXPLOIT PUBLISHED — FreeRDP: 3 CVEs (CVE-2026-40033, CVE-2026-44421, CVE-2026-44422). Public exploit references added.
EXPLOIT PUBLISHED — GNOME GIMP: 3 CVEs (CVE-2026-66757, CVE-2026-66758, CVE-2026-66759). Public exploit references added.
EXPLOIT PUBLISHED — nuxsmin sysPass: 3 CVEs (CVE-2026-65708, CVE-2026-65709, CVE-2026-65710). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-10682 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10683 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17432 (NousResearch hermes-agent). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17433 (nanocoai NanoClaw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17434 (nanocoai NanoClaw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17457 (mf-yang openclaw-cn). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17458 (mf-yang openclaw-cn). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17459 (perwendel spark). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17573 (The HDF Group HDF5). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45623 (postcss). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63097 (matrix-org dendrite). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63107 (LimeSurvey). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63108 (RooCodeInc Roo-Code). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63720 (koxudaxi datamodel-code-generator). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63731 (hyperdxio hyperdx). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63770 (glanceapp glance). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63771 (vrana adminer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64824 (home-assistant Home Assistant Core). Public exploit reference added.
RESCORED — CVE-2026-40033 (FreeRDP). CVSS 8.6 → 8.7 (NVD).
RESCORED — CVE-2026-44422 (FreeRDP). CVSS 7.5 → 8.8 (NVD).
How to read these box scores · glossary
440 CVEs published. 25 box scores and 375 table rows below; the remaining 40 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H N N 5.9 .2915 98.0 YES
AFFECTED Product Versions Fixed FortiOS 7.6.0 – —
TIMELINE Dec 23 Reserved by CNA Jul 27 Added to CISA KEV, due Aug 10 Jul 27 Published (CNA: fortinet)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0157 73.4 YES
AFFECTED Product Versions Fixed VeloCloud Orchestrator On-Prem 5.2.0 – —
TIMELINE Jul 23 Reserved by CNA Jul 27 Added to CISA KEV, due Jul 30 Jul 27 Published (CNA: Arista)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .3399 98.3 —
AFFECTED Product Versions Fixed vBulletin 5.0.0 – 6.2.2
TIMELINE Jul 10 Reserved by CNA Jul 27 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0585 92.6 —
AFFECTED Product Versions Fixed pheditor >= 2.0.1, < 2.0.4 – —
TIMELINE May 20 Reserved by CNA Jul 27 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H L L 8.5 .0283 85.5 —
AFFECTED Product Versions Fixed VeloCloud Orchestrator On-Prem 5.2.0 – —
TIMELINE Jul 24 Reserved by CNA Jul 27 Published (CNA: Arista)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N N N 6.3 .0234 82.3 —
AFFECTED Product Versions Fixed VeloCloud Orchestrator On-Prem 5.2.0 – —
TIMELINE Jul 24 Reserved by CNA Jul 27 Published (CNA: Arista)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0149 72.1 —
AFFECTED Product Versions Fixed MemberGlut unspecified —
TIMELINE Jun 16 Reserved by CNA Jul 27 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV A L H N C H H H 8.4 .0141 70.7 —
AFFECTED Product Versions Fixed LoadMaster All Previous Versions – — ECS Connection Manager 7.2.60.0 – — Object Scale Connection Manager 7.2.60.0 – — MOVEit WAF 7.2.60.0 – —
TIMELINE Jul 6 Reserved by CNA Jul 27 Published (CNA: ProgressSoftware)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0107 62.4 —
AFFECTED Product Versions Fixed Apache Thrift 0.19.0 – —
TIMELINE May 8 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N H 8.2 .0106 61.8 —
AFFECTED Product Versions Fixed next.js >= 13.0.0, < 15.5.21 – —
TIMELINE Jul 20 Reserved by CNA Jul 27 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H L N 8.3 .0101 60.5 —
AFFECTED Product Versions Fixed next.js >= 16.0.0, < 16.2.11 – —
TIMELINE Jul 20 Reserved by CNA Jul 27 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H L L 8.6 .0097 59.1 —
AFFECTED Product Versions Fixed macOS unspecified —
TIMELINE May 1 Reserved by CNA Jul 27 Published (CNA: apple)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H L N 8.3 .0087 56.1 —
AFFECTED Product Versions Fixed next.js >= 14.1.1, < 15.5.21 – —
TIMELINE Jul 20 Reserved by CNA Jul 27 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0085 55.3 —
AFFECTED Product Versions Fixed macOS unspecified —
TIMELINE Jul 20 Reserved by CNA Jul 27 Published (CNA: apple)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H L N 8.3 .0084 55.0 —
AFFECTED Product Versions Fixed next.js >= 12.0.0 < 15.5.21 – —
TIMELINE Jul 20 Reserved by CNA Jul 27 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0081 54.2 —
AFFECTED Product Versions Fixed macOS unspecified —
TIMELINE May 1 Reserved by CNA Jul 27 Published (CNA: apple)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0078 53.3 —
AFFECTED Product Versions Fixed iOS and iPadOS unspecified — macOS unspecified — tvOS unspecified — visionOS unspecified — watchOS unspecified —
TIMELINE May 1 Reserved by CNA Jul 27 Published (CNA: apple)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0078 53.3 —
AFFECTED Product Versions Fixed iOS and iPadOS unspecified — macOS unspecified — tvOS unspecified — visionOS unspecified — watchOS unspecified —
TIMELINE May 1 Reserved by CNA Jul 27 Published (CNA: apple)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N L H 8.3 .0078 53.1 —
AFFECTED Product Versions Fixed OTP 3.17.1 – 4.9.1 OTP R13B03 – 29.0.4
TIMELINE Jul 4 Reserved by CNA Jul 27 Published (CNA: EEF)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0077 53.0 —
AFFECTED Product Versions Fixed macOS unspecified —
TIMELINE Jul 20 Reserved by CNA Jul 27 Published (CNA: apple)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0077 52.9 —
AFFECTED Product Versions Fixed iOS and iPadOS unspecified — macOS unspecified — tvOS unspecified — visionOS unspecified — watchOS unspecified —
TIMELINE May 1 Reserved by CNA Jul 27 Published (CNA: apple)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N H N 8.7 .0074 51.7 —
AFFECTED Product Versions Fixed nitroshare-desktop unspecified —
TIMELINE Jul 23 Reserved by CNA Jul 27 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.3 —
AFFECTED Product Versions Fixed iOS and iPadOS unspecified — macOS unspecified —
TIMELINE Jul 20 Reserved by CNA Jul 27 Published (CNA: apple)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0072 51.1 —
AFFECTED Product Versions Fixed Realtyna Organic IDX plugin + WPL Real Estate unspecified —
TIMELINE Jun 29 Reserved by CNA Jul 27 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV A L H N C H H H 8.4 .0072 51.1 —
AFFECTED Product Versions Fixed LoadMaster 7.0.8 – — ECS Connection Manager 7.2.60.0 – — Object Scale Connection Manager 7.2.60.0 – — MOVEit WAF 7.2.60.0 – —
TIMELINE Jul 6 Reserved by CNA Jul 27 Published (CNA: ProgressSoftware)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-59688 | 8.4 | 51.1 | Progress Software | LoadMaster | CWE-78 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager,… |
| CVE-2026-43682 | 9.8 | 51.0 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64696 | 9.8 | 51.0 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-54540 | 8.8 | 50.8 | pheditor | pheditor | CWE-78 | Authenticated terminal command whitelist bypass in Pheditor |
| CVE-2026-64771 | 9.8 | 50.4 | Apple | iOS and iPadOS | CWE-119 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-43818 | 8.8 | 50.2 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-43750 | 9.8 | 50.0 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-24252 | 7.8 | 49.9 | NVIDIA | NeMo Framework | CWE-78 | NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS… |
| CVE-2026-64767 | 9.8 | 49.6 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-64644 | 6.3 | 49.4 | vercel | next.js | CWE-407 | Next.js: Denial of Service in the Image Optimization API using SVGs |
| CVE-2026-43769 | 9.8 | 49.3 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-43778 | 9.8 | 48.6 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-43799 | 9.8 | 48.6 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-43822 | 9.8 | 48.6 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-64700 | 9.8 | 48.6 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-64769 | 9.8 | 48.3 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-64770 | 9.8 | 48.3 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-64774 | 9.8 | 48.3 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-66015 | 7.2 | 48.2 | jfrog | artifactory | CWE-269 | JFrog Platform contains an authorization flaw that may allow authenticated pr… |
| CVE-2026-55969 | 8.7 | 48.1 | Apache Software Foundation | Apache Thrift | CWE-190 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap… |
| CVE-2026-49158 | 7.5 | 48.1 | Apache Software Foundation | Apache Thrift | CWE-409 | Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb |
| CVE-2026-64726 | 9.8 | 48.0 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64733 | 9.8 | 48.0 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved data protection. This issue is fixed i… |
| CVE-2026-65921 | 8.8 | 47.9 | jfrog | artifactory | CWE-22 | Potential path traversal leading to unauthorized file writes |
| CVE-2026-58023 | 6.9 | 47.8 | Apache Software Foundation | Apache Thrift | CWE-125 | Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path |
| CVE-2026-58662 | 8.7 | 47.7 | Apache Software Foundation | Apache Thrift | CWE-125 | Apache Thrift: C++ THeaderTransport::readString() info-header length bounds b… |
| CVE-2026-64772 | 9.8 | 47.7 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved input validation. Th… |
| CVE-2026-48586 | 8.7 | 47.5 | Apache Software Foundation | Apache Thrift | CWE-409 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap… |
| CVE-2026-43779 | 9.8 | 47.5 | Apple | macOS | CWE-284 | A logic issue was addressed with improved restrictions. This issue is fixed i… |
| CVE-2026-43812 | 9.8 | 47.2 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-43802 | 9.8 | 47.1 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43809 | 9.8 | 47.1 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-64731 | 9.8 | 46.5 | Apple | macOS | CWE-22 | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-43871 | 8.7 | 46.4 | Apache Software Foundation | Apache Thrift | CWE-835 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol … |
| CVE-2026-55968 | 8.7 | 46.4 | Apache Software Foundation | Apache Thrift | CWE-407 | Apache Thrift: Node.js quadratic-time DoS in server receive transports |
| CVE-2026-58389 | 8.7 | 46.4 | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: Rust binary protocol non-strict path missing string size limit |
| CVE-2026-41608 | 7.5 | 46.4 | Apache Software Foundation | Apache Thrift | CWE-409 | Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport |
| CVE-2026-55579 | 9.8 | 46.2 | pheditor | pheditor | CWE-798 | Pheditor: Hardcoded default password 'admin' with no forced change enables fu… |
| CVE-2026-43694 | 9.8 | 46.1 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43764 | 9.8 | 46.1 | Apple | macOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-43773 | 9.8 | 46.1 | Apple | macOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-43793 | 9.8 | 46.1 | Apple | macOS | CWE-20 | An issue existed in the handling of environment variables. This issue was add… |
| CVE-2026-64694 | 9.8 | 46.1 | Apple | macOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-64697 | 9.8 | 46.1 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64698 | 9.8 | 46.1 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-66729 | 8.7 | 45.8 | boazsegev | facil.io | CWE-125 | facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser |
| CVE-2026-66730 | 8.7 | 45.8 | boazsegev | facil.io | CWE-835 | facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser |
| CVE-2026-66731 | 8.7 | 45.8 | boazsegev | facil.io | CWE-125 | facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS |
| CVE-2026-45623 | 9.1 | 45.4 | postcss | postcss | CWE-22 | PostCSS: Arbitrary file read and information disclosure via attacker-controll… |
| CVE-2026-28928 | 9.8 | 45.1 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-43814 | 9.8 | 45.1 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-64729 | 9.8 | 45.1 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-56748 | 8.7 | 45.0 | Cribl | Cribl Stream | CWE-61 | Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import |
| CVE-2026-65617 | 8.8 | 45.0 | jfrog | artifactory | CWE-502 | Potential remote code execution on an Artifactory package service container. |
| CVE-2026-64738 | 9.8 | 44.8 | Apple | iOS and iPadOS | CWE-284 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-64541 | 9.8 | 44.3 | Linux | Linux | — | net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket |
| CVE-2026-64702 | 9.8 | 43.9 | Apple | macOS | CWE-284 | An access issue was addressed with additional sandbox restrictions. This issu… |
| CVE-2026-64775 | 9.8 | 43.9 | Apple | iOS and iPadOS | CWE-665 | A memory initialization issue was addressed with improved memory handling. Th… |
| CVE-2026-66014 | 9.8 | 43.9 | jfrog | artifactory | CWE-287 | Potential authentication bypass leading to privilege escalation in Artifactory |
| CVE-2026-64746 | 9.8 | 43.7 | Apple | iOS and iPadOS | CWE-862 | An authorization issue was addressed with improved validation. This issue is … |
| CVE-2025-50455 | 9.1 | 43.7 | n/a | n/a | CWE-89 | SQL injection vulnerability exists in the order_by parameter of the /customer… |
| CVE-2026-55971 | 9.3 | 43.6 | Apache Software Foundation | Apache Thrift | CWE-122 | Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::unt… |
| CVE-2026-64535 | 9.8 | 43.4 | Linux | Linux | — | nvmet-tcp: Fix potential UAF when ddgst mismatch |
| CVE-2026-64735 | 6.5 | 43.4 | Apple | iOS and iPadOS | CWE-451 | An inconsistent user interface issue was addressed with improved state manage… |
| CVE-2026-43757 | 9.8 | 42.6 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-64762 | 9.8 | 42.6 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-64646 | 6.3 | 42.4 | vercel | next.js | CWE-770 | Next.js: Unbounded Server Action payload in Edge runtime |
| CVE-2026-64739 | 8.8 | 41.8 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-64643 | 6.3 | 41.6 | vercel | next.js | CWE-201 | Next.js: Unauthenticated Disclosure of Internal Server Function endpoints |
| CVE-2026-39873 | 9.8 | 41.5 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43710 | 9.8 | 41.5 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64551 | 9.1 | 41.4 | Linux | Linux | — | sctp: validate STALE_COOKIE cause length before reading staleness |
| CVE-2026-43730 | 9.8 | 41.3 | Apple | iOS and iPadOS | CWE-200 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-64751 | 9.8 | 40.4 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-28982 | 9.8 | 39.9 | Apple | macOS | CWE-362 | A race condition was addressed with improved locking. This issue is fixed in … |
| CVE-2026-64545 | 7.5 | 39.9 | Linux | Linux | — | net, bpf: check master for NULL in xdp_master_redirect() |
| CVE-2026-43748 | 9.8 | 39.8 | Apple | macOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-64727 | 9.8 | 39.8 | Apple | macOS | CWE-843 | A type confusion issue was addressed with improved memory handling. This issu… |
| CVE-2026-64768 | 8.1 | 39.8 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read issue was addressed with improved input validation. Thi… |
| CVE-2026-64730 | 6.5 | 39.5 | Apple | Safari | CWE-451 | The issue was addressed with improved UI. This issue is fixed in Safari 26.6,… |
| CVE-2026-55970 | 6.9 | 39.2 | Apache Software Foundation | Apache Thrift | CWE-126 | Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFor… |
| CVE-2026-64757 | 8.8 | 38.4 | Apple | Safari | CWE-119 | A memory corruption issue was addressed with improved state management. This … |
| CVE-2026-64713 | 8.1 | 38.3 | Apple | Safari | CWE-203 | This issue was addressed with improved checks. This issue is fixed in Safari … |
| CVE-2026-64720 | 9.8 | 38.0 | Apple | iOS and iPadOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-43821 | 6.5 | 37.4 | Apple | Safari | CWE-284 | An access issue was addressed with improved access restrictions. This issue i… |
| CVE-2026-64691 | 9.8 | 37.1 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved size validation. This issue is … |
| CVE-2026-64743 | 6.5 | 36.6 | Apple | iOS and iPadOS | CWE-285 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-28931 | 8.8 | 36.3 | Apple | iOS and iPadOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-51564 | 4.9 | 36.1 | n/a | n/a | CWE-601 | An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attack… |
| CVE-2026-42792 | 6.3 | 36.1 | Erlang | OTP | CWE-755 | epmd permanent DoS via EMFILE on accept(2) in erts |
| CVE-2026-43804 | 6.5 | 35.9 | Apple | Safari | CWE-400 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-66018 | 6.5 | 35.7 | jfrog | artifactory | CWE-200 | JFrog Artifactory build environment properties exposure |
| CVE-2026-64783 | 8.8 | 35.5 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-54890 | 8.2 | 34.8 | Erlang | OTP | CWE-191 | BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding |
| CVE-2026-64534 | 9.8 | 34.6 | Linux | Linux | — | nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path |
| CVE-2026-65442 | 7.2 | 34.7 | Subtle Web Inc | FormCraft | CWE-918 | WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vul… |
| CVE-2026-17500 | 6.9 | 34.7 | ggml-org | llama.cpp | CWE-404 | ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer der… |
| CVE-2026-17501 | 6.9 | 34.7 | ggml-org | llama.cpp | CWE-404 | ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp … |
| CVE-2026-28911 | 9.8 | 34.6 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64719 | 8.1 | 34.3 | Apple | Safari | CWE-125 | An out-of-bounds access issue was addressed with improved bounds checking. Th… |
| CVE-2026-43805 | 9.8 | 33.7 | Apple | iOS and iPadOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-55685 | 8.7 | 33.1 | remix-run | react-router | CWE-400 | React Router: Unauthenticated Denial of Service via Inefficient Route Matching |
| CVE-2026-66391 | 6.5 | 33.2 | Apache Software Foundation | Apache Wicket | CWE-330 | Apache Wicket: leaked and missing CSP headers |
| CVE-2026-65894 | 8.7 | 32.8 | CP-Plus | EZ-P21 IP Camera | CWE-307 | Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera |
| CVE-2026-59528 | 7.5 | 32.6 | shiptime | ShipTime: Discounted Shipping Rates | CWE-497 | WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Dat… |
| CVE-2026-14289 | 9.0 | 32.5 | Unknown | FacturaONE para WooCommerce con VeriFactu | CWE-94 | WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution |
| CVE-2026-58227 | 8.7 | 31.5 | Erlang | OTP | CWE-674 | TLS/DTLS denial of service via unbounded recursion on cross-signed peer certi… |
| CVE-2026-59239 | 8.6 | 31.1 | Roskus | Prospero Flow CRM | CWE-79 | Stored XSS in Prospero Flow CRM email body allows administrator account takeover |
| CVE-2026-64531 | 7.8 | 30.7 | Linux | Linux | — | net: openvswitch: reject oversized nested action attrs |
| CVE-2026-65924 | 6.5 | 30.3 | jfrog | artifactory | CWE-918 | Server-Side Request Forgery (SSRF) via Terraform Remote repository |
| CVE-2026-64728 | 6.5 | 30.0 | Apple | Safari | CWE-693 | A permissions issue was addressed with improved validation. This issue is fix… |
| CVE-2026-56747 | 8.7 | 29.9 | Cribl | Cribl Stream | CWE-94 | Code Injection in JSON Pointer Processing Component in Cribl Stream |
| CVE-2026-9830 | 8.2 | 29.4 | Unknown | bookingpress-appointment-booking-pro | CWE-287 | BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Bookin… |
| CVE-2026-65925 | 6.5 | 29.1 | jfrog | artifactory | CWE-918 | Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository |
| CVE-2026-55578 | 8.8 | 28.8 | pheditor | pheditor | CWE-78 | Pheditor: Incomplete command sanitization in terminal feature allows RCE via … |
| CVE-2026-13152 | 8.1 | 28.8 | Unknown | Custom Fields Account Registration For Woocommerce | CWE-269 | Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Pr… |
| CVE-2026-59546 | 7.4 | 28.8 | John Darrel | Hide My WP Ghost | CWE-639 | WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability |
| CVE-2026-59730 | 2.1 | 28.5 | withastro | astro | CWE-601 | @astrojs/node: Backslash-prefixed paths not recognized as internal by trailin… |
| CVE-2026-66390 | 6.1 | 28.3 | Apache Software Foundation | Apache Wicket | CWE-79 | Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence |
| CVE-2026-65434 | 6.5 | 28.2 | yoomoney | ЮKassa для WooCommerce | CWE-201 | WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure v… |
| CVE-2026-64647 | 6.3 | 27.7 | vercel | next.js | CWE-116 | Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies |
| CVE-2026-54272 | 6.9 | 27.6 | beaugunderson | ip-address | CWE-20 | ip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass … |
| CVE-2026-17552 | 9.1 | 27.5 | RRWO | Plack::App::Prerender | CWE-918 | Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrar… |
| CVE-2026-43792 | 6.5 | 27.4 | Apple | Safari | CWE-285 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-65923 | 6.8 | 26.7 | jfrog | artifactory | CWE-918 | Potential server-side request forgery in Artifactory Ansible repository handling |
| CVE-2026-59560 | 6.5 | 26.7 | Roxnor | FundEngine | CWE-862 | WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability |
| CVE-2026-64648 | 6.0 | 26.0 | vercel | next.js | CWE-524 | Next.js: Response Body Cache Confusion for Requests Containing Bodies |
| CVE-2026-64725 | 7.1 | 25.8 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-66398 | 9.4 | 25.2 | thorsten | phpMyFAQ | CWE-494 | phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API |
| CVE-2021-32084 | 9.8 | 25.0 | n/a | n/a | CWE-284 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2026-66395 | 9.4 | 25.0 | siyuan-note | siyuan | CWE-79 | SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol |
| CVE-2026-66397 | 8.6 | 24.8 | thorsten | phpMyFAQ | CWE-22 | phpMyFAQ before 4.1.6 Path Traversal via category image deletion |
| CVE-2026-65878 | 8.3 | 24.8 | joomshaper.com | SP Page Builder extension for Joomla | CWE-22 | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP… |
| CVE-2026-65436 | 6.8 | 24.8 | Themeum | Kirki | CWE-22 | WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerability |
| CVE-2026-13597 | 9.1 | 24.5 | Unknown | 微信二维码登陆 | CWE-287 | QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover |
| CVE-2025-15662 | 8.6 | 24.5 | Unknown | Printcart Web to Print Product Designer for WooCommerce | CWE-918 | Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthentic… |
| CVE-2026-59539 | 7.5 | 24.5 | Cozmoslabs | Paid Member Subscriptions | CWE-639 | WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object … |
| CVE-2026-59729 | 5.1 | 24.5 | withastro | astro | CWE-79 | Astro: XSS via unescaped spread attribute names in renderHTMLElement (incompl… |
| CVE-2026-66028 | 7.1 | 24.4 | Creativeitem | Ekushey Project Manager CRM | CWE-303 | Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email |
| CVE-2026-39875 | 7.8 | 24.3 | Apple | macOS | CWE-276 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-59251 | 8.7 | 24.1 | Erlang | OTP | CWE-770 | Denial of service via exponential certificate policy tree growth in path vali… |
| CVE-2026-66476 | 4.9 | 23.7 | Syed Balkhi | Easy Digital Downloads | CWE-22 | WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vu… |
| CVE-2026-51078 | 7.5 | 23.7 | n/a | n/a | CWE-200 | An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive i… |
| CVE-2026-59531 | 7.5 | 23.6 | Anh Tran | Falcon – WordPress Optimizations & Tweaks | CWE-1284 | WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknow… |
| CVE-2026-66412 | 7.1 | 23.5 | Leantime | Leantime | CWE-639 | Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.ge… |
| CVE-2026-65765 | 6.9 | 23.4 | phoca.cz | Phoca Commander extension for Joomla | CWE-22 | Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander… |
| CVE-2026-51077 | 7.5 | 23.2 | n/a | n/a | CWE-89 | SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to… |
| CVE-2026-59727 | 2.1 | 23.1 | withastro | astro | CWE-79 | Astro: Cross-site scripting via unescaped transition:* directive values on hy… |
| CVE-2026-17612 | 6.9 | 22.8 | Honeywell | S35 Series 3M/5M/8M/PinHole Cameras | CWE-200 | Audit Log Exposure through Unauthorized Access |
| CVE-2026-53666 | 6.1 | 22.6 | remix-run | react-router | CWE-470 | React Router: Arbitrary Constructor Injection via deserializeErrors() in Reac… |
| CVE-2026-16554 | 5.1 | 22.2 | DaveGamble | cJSON | CWE-190 | Integer Overflow Leading to Heap Buffer Overflow in cJSON |
| CVE-2026-66396 | 9.3 | 21.6 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL |
| CVE-2026-66758 | 7.8 | 21.6 | GNOME | GIMP | CWE-190 | Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflo… |
| CVE-2026-40000 | 1.8 | 21.6 | ZTE | Blade A75 5G | CWE-22 | Path Traversal Vulnerability in ZTE Blade A75 5G |
| CVE-2026-42017 | 8.8 | 21.4 | jfrog | artifactory | CWE-200 | Privilege escalation via JFrog Worker event token exposure |
| CVE-2026-59548 | 7.5 | 21.3 | Byteflows | Byteflows Travel & Hotel Booking | CWE-497 | WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data E… |
| CVE-2021-32085 | 8.8 | 21.3 | n/a | n/a | CWE-798 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2021-32087 | 8.8 | 21.3 | n/a | n/a | CWE-798 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2026-64742 | 6.5 | 20.9 | Apple | iOS and iPadOS | CWE-319 | This issue was addressed by using HTTPS when sending information over the net… |
| CVE-2026-59240 | 6.9 | 20.8 | Roskus | Prospero Flow CRM | CWE-639 | IDOR in Prospero Flow CRM allows deletion of other users' notifications |
| CVE-2026-55737 | 5.1 | 20.8 | Erlang | OTP | CWE-195 | Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decod… |
| CVE-2021-32088 | 9.8 | 20.6 | n/a | n/a | CWE-384 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2026-43813 | 7.1 | 20.5 | Apple | iOS and iPadOS | CWE-20 | A validation issue was addressed with improved input sanitization. This issue… |
| CVE-2026-14856 | 6.3 | 20.5 | Media Manager | TastyIgniter | CWE-79 | Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager |
| CVE-2026-65879 | 9.8 | 20.4 | joomshaper.com | SP Page Builder extension for Joomla | CWE-798 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcode… |
| CVE-2026-15928 | 8.2 | 20.3 | XMLRPC-C | XMLRPC-C | CWE-79 | XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected … |
| CVE-2026-53668 | 6.9 | 19.9 | remix-run | react-router | CWE-79 | React Router: Open redirect can lead to XSS |
| CVE-2026-65433 | 6.5 | 19.8 | themewant | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | CWE-862 | WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <… |
| CVE-2026-51565 | 6.1 | 19.8 | n/a | n/a | CWE-79 | Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php i… |
| CVE-2026-59529 | 7.5 | 19.7 | motov.net | Ebook Store | CWE-862 | WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability |
| CVE-2026-66824 | 9.2 | 19.6 | lookyloo | lookyloo | CWE-79 | Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding |
| CVE-2026-66825 | 6.9 | 19.6 | pivotick | pivotick | CWE-79 | Cross-Site Scripting via Unsafe URL Schemes in Pivotick Property Links |
| CVE-2026-17529 | 2.1 | 19.5 | AstrBotDevs | AstrBot | CWE-285 | AstrBotDevs AstrBot astr_main_agent.py authorization |
| CVE-2026-12255 | 8.1 | 19.3 | Unknown | MainWP Child | CWE-287 | MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass vi… |
| CVE-2026-48145 | 8.2 | 19.2 | Apache Software Foundation | Apache Thrift | CWE-297 | Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass |
| CVE-2026-64540 | 8.1 | 19.2 | Linux | Linux | — | usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() |
| CVE-2026-64547 | 8.1 | 19.2 | Linux | Linux | — | net: usb: net1080: validate packet_len before pad-byte access in rx_fixup |
| CVE-2026-59537 | 7.6 | 18.8 | Sender | Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | CWE-89 | WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooComm… |
| CVE-2026-59551 | 8.5 | 18.6 | rtCamp | rtMedia for WordPress, BuddyPress and bbPress | CWE-89 | WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQ… |
| CVE-2026-43728 | 7.5 | 18.5 | Apple | macOS | CWE-362 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2025-59181 | 4.8 | 18.4 | Ericsson | Packet Core Controller (PCC) | CWE-35 | Path traversal Vulnerability |
| CVE-2026-66394 | 9.3 | 18.3 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass |
| CVE-2026-59728 | 4.3 | 18.0 | withastro | astro | CWE-91 | @astrojs/rss: XML Injection via Unescaped RSS Feed Fields |
| CVE-2025-63913 | 7.5 | 17.7 | n/a | n/a | CWE-400 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial o… |
| CVE-2026-65764 | 5.1 | 17.1 | phoca.cz | Phoca Commander extension for Joomla | CWE-79 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0… |
| CVE-2026-64554 | 8.8 | 16.7 | Linux | Linux | — | netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() |
| CVE-2026-65922 | 5.4 | 16.5 | jfrog | artifactory | CWE-862 | Potential unauthorized modification of Artifactory internal metadata |
| CVE-2026-59532 | 7.5 | 16.3 | magepeopleteam | Booking and Rental Manager | CWE-1284 | WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vul… |
| CVE-2026-48144 | 9.1 | 16.2 | Apache Software Foundation | Apache Thrift | CWE-297 | Apache Thrift: c_glib TLS Client Missing Hostname Verification |
| CVE-2026-66759 | 7.1 | 16.3 | GNOME | GIMP | CWE-125 | Gimp: out-of-bounds read in file-icns plugin causes information disclosure or… |
| CVE-2026-12001 | 5.2 | 16.2 | TP-Link Systems Inc. | TL-WR850N v3 | CWE-798 | Hardcoded Credential Vulnerability in Multiple TP-Link Router Models |
| CVE-2026-16481 | 8.4 | 15.9 | MCP Toolbox for Databases (googleapis/mcp-toolbox) | CWE-918 | Server-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/… | |
| CVE-2026-64536 | 8.1 | 16.0 | Linux | Linux | — | staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop |
| CVE-2026-43776 | 7.8 | 15.3 | Apple | iOS and iPadOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-64747 | 7.8 | 15.1 | Apple | iOS and iPadOS | CWE-120 | A buffer overflow was addressed with improved size validation. This issue is … |
| CVE-2026-28981 | 7.8 | 15.0 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-13332 | 9.1 | 14.8 | Unknown | Masteriyo LMS | CWE-287 | Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (D… |
| CVE-2026-10819 | 6.5 | 14.8 | Mattermost | Mattermost | CWE-409 | Mattermost Server Denial of Service via Animated GIF Emoji Upload |
| CVE-2026-59530 | 7.5 | 14.6 | Payment Plugins | Stripe For WooCommerce | CWE-862 | WordPress Stripe For WooCommerce plugin <= 4.0.7 - Broken Access Control vuln… |
| CVE-2026-59534 | 7.5 | 14.6 | Aurovrata Venet | Post My CF7 Form | CWE-862 | WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability |
| CVE-2026-59536 | 7.5 | 14.6 | CoCart Headless | CoCart – Headless ecommerce | CWE-862 | WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control… |
| CVE-2026-65766 | 9.2 | 14.4 | joomshaper.com | SP Page Builder extension for Joomla | CWE-89 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page … |
| CVE-2026-43753 | 4.6 | 14.5 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-59557 | 6.5 | 14.2 | Franky | Events Made Easy | CWE-862 | WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability |
| CVE-2026-65435 | 6.5 | 14.2 | Thrive Themes Coupon | Thrive Leads Version | CWE-862 | WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulne… |
| CVE-2026-55953 | 9.1 | 14.0 | Erlang | OTP | CWE-757 | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing s… |
| CVE-2026-42016 | 8.8 | 14.1 | jfrog | artifactory | CWE-863 | Incorrect authorization validation of user token in JFrog Artifactory allows … |
| CVE-2026-17568 | 8.8 | 13.9 | Devolutions | Server | CWE-863 | Improper access control in the role membership management endpoint in Devolut… |
| CVE-2026-14235 | 7.5 | 13.9 | Unknown | Download Manager | CWE-284 | WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download vi… |
| CVE-2026-66757 | 5.5 | 13.9 | GNOME | GIMP | CWE-190 | Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to cras… |
| CVE-2026-53669 | 5.1 | 13.8 | remix-run | react-router | CWE-601 | React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025… |
| CVE-2026-66399 | 8.5 | 13.7 | thorsten | phpMyFAQ | CWE-269 | phpMyFAQ before 4.1.6 Privilege Escalation via Group Membership |
| CVE-2026-43766 | 4.6 | 13.7 | Apple | macOS | CWE-287 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-59527 | 9.3 | 13.5 | RomanCode | MapSVG | CWE-89 | WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
| CVE-2026-59533 | 9.3 | 13.5 | Christoph Vielgrader | Relevanssi Light | CWE-89 | WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability |
| CVE-2026-59538 | 9.3 | 13.5 | Ruben Garcia | GamiPress | CWE-89 | WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability |
| CVE-2026-59549 | 9.3 | 13.5 | rtCamp | rtMedia for WordPress, BuddyPress and bbPress | CWE-89 | WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQ… |
| CVE-2026-59550 | 9.3 | 13.5 | Strategy11 Team | AWP Classifieds | CWE-89 | WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability |
| CVE-2026-14827 | 6.8 | 13.4 | Unknown | Calendar | CWE-79 | Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter |
| CVE-2026-65876 | 9.2 | 13.3 | joomshaper.com | SP Page Builder extension for Joomla | CWE-89 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page … |
| CVE-2026-65893 | 7.0 | 13.3 | CP-Plus | EZ-P21 IP Camera | CWE-489 | Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera |
| CVE-2026-65877 | 8.2 | 13.1 | joomshaper.com | SP Page Builder extension for Joomla | CWE-89 | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Bu… |
| CVE-2026-59690 | 8.0 | 12.9 | Progress Software | LoadMaster | CWE-862 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager,… |
| CVE-2026-14820 | 5.3 | 12.8 | Unknown | Quiz and Survey Master (QSM) | CWE-200 | Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Passwo… |
| CVE-2026-66442 | 5.4 | 12.7 | YayCommerce | YayPricing | CWE-862 | WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability |
| CVE-2026-65616 | 8.8 | 12.4 | jfrog | artifactory | CWE-347 | Potential privilege escalation to JFrog administrator privileges |
| CVE-2026-17527 | 7.7 | 12.5 | Red Hat | Red Hat OpenShift Virtualization 4 | CWE-639 | Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregat… |
| CVE-2026-64740 | 9.3 | 12.3 | Apple | iOS and iPadOS | CWE-22 | A parsing issue in the handling of directory paths was addressed with improve… |
| CVE-2026-66427 | 7.6 | 12.2 | jgwhite33 | WP Google Review Slider | CWE-89 | WordPress WP Google Review Slider plugin <= 18.4 - SQL Injection vulnerability |
| CVE-2026-10683 | 4.6 | 12.2 | zephyrproject | zephyr | CWE-835 | DesignWare I2C target driver can be wedged into a permanent stuck state by an… |
| CVE-2026-10600 | 4.3 | 11.9 | Mattermost | Mattermost | CWE-770 | Denial of service via unbounded document content extraction in Mattermost Server |
| CVE-2026-43771 | 7.1 | 11.6 | Apple | macOS | CWE-121 | A stack overflow was addressed with improved input validation. This issue is … |
| CVE-2026-66053 | 5.9 | 11.5 | Apache Software Foundation | Apache Thrift | CWE-297 | Apache Thrift: Python TSSLSocket Hostname Matcher Import |
| CVE-2026-17530 | 2.1 | 11.6 | AstrBotDevs | AstrBot | CWE-285 | AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset a… |
| CVE-2026-43772 | 8.2 | 11.4 | Apple | macOS | CWE-22 | A path traversal issue was addressed with improved input validation. This iss… |
| CVE-2026-59535 | 7.3 | 11.4 | Thrive Themes Coupon | Thrive Product Manager | CWE-862 | WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vul… |
| CVE-2026-64732 | 4.6 | 11.4 | Apple | iOS and iPadOS | CWE-284 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-48052 | 5.4 | 11.3 | papra-hq | papra | CWE-639 | Papra: Cross-organization tag deletion and modification via authenticated cro… |
| CVE-2026-65618 | 6.5 | 10.9 | jfrog | artifactory | CWE-918 | Improper URL validation when handling specific URLs Pub, Terraform and Docker… |
| CVE-2026-12493 | 7.5 | 10.8 | Unknown | Clover Payment Gateway by Zaytech for WooCommerce | CWE-287 | Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated P… |
| CVE-2026-64722 | 5.5 | 10.7 | Apple | iOS and iPadOS | CWE-120 | A buffer overflow issue was addressed with improved memory handling. This iss… |
| CVE-2026-48051 | 3.5 | 10.7 | papra-hq | papra | CWE-918 | Papra: SSRF via HTTP redirect bypass in webhook delivery |
| CVE-2026-64763 | 7.8 | 10.6 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed by removing the vulnerable code. T… |
| CVE-2026-43698 | 7.8 | 10.4 | Apple | macOS | CWE-88 | An injection issue was addressed with improved validation. This issue is fixe… |
| CVE-2026-59559 | 6.5 | 10.4 | themewant | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | CWE-79 | WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <… |
| CVE-2026-64699 | 5.5 | 10.4 | Apple | macOS | CWE-457 | A memory initialization issue was addressed with improved memory handling. Th… |
| CVE-2026-43765 | 5.5 | 10.2 | Apple | macOS | CWE-59 | This issue was addressed with improved handling of symlinks. This issue is fi… |
| CVE-2026-43723 | 7.8 | 10.1 | Apple | iOS and iPadOS | CWE-22 | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-14568 | 6.5 | 10.1 | Unknown | User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration | CWE-287 | WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion |
| CVE-2026-53667 | 6.1 | 10.1 | remix-run | react-router | CWE-79 | React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler… |
| CVE-2026-64718 | 5.5 | 10.0 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-39877 | 7.8 | 9.7 | Apple | iOS and iPadOS | CWE-119 | A memory corruption issue was addressed with improved memory handling. This i… |
| CVE-2026-43774 | 5.5 | 9.7 | Apple | macOS | CWE-787 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-17531 | 1.3 | 9.7 | unitedbyai | droidclaw | CWE-285 | unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization |
| CVE-2026-43749 | 7.8 | 9.5 | Apple | macOS | CWE-22 | A parsing issue in the handling of directory paths was addressed with improve… |
| CVE-2026-66473 | 7.5 | 9.3 | Xendit | Xendit Payment | CWE-862 | WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability |
| CVE-2026-43738 | 5.5 | 9.3 | Apple | iOS and iPadOS | CWE-125 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-12989 | 8.7 | 9.2 | Ghost Robotics | Vision 60 | CWE-306 | Multiple vulnerabilities in Ghost Robotics' Vision 60 |
| CVE-2026-59689 | 8.0 | 9.2 | Progress Software | LoadMaster | CWE-863 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager,… |
| CVE-2026-64764 | 7.8 | 9.1 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-64765 | 7.8 | 9.1 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-28896 | 7.7 | 9.0 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64710 | 5.5 | 9.0 | Apple | macOS | CWE-200 | A privacy issue was addressed by removing sensitive data. This issue is fixed… |
| CVE-2026-64734 | 5.5 | 8.8 | Apple | iOS and iPadOS | CWE-200 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7… |
| CVE-2026-64741 | 5.5 | 8.8 | Apple | iOS and iPadOS | CWE-200 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-64744 | 5.5 | 8.8 | Apple | iOS and iPadOS | CWE-200 | An information leakage was addressed with additional validation. This issue i… |
| CVE-2026-65564 | 5.3 | 8.8 | chrisvrichardson | MapPress Maps for WordPress | CWE-497 | WordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Expos… |
| CVE-2026-66438 | 5.3 | 8.8 | Tim Strifler | Exclusive Addons Elementor | CWE-497 | WordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposur… |
| CVE-2026-65445 | 6.5 | 8.7 | iSaumya | Ad Invalid Click Protector (AICP) | CWE-862 | WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access C… |
| CVE-2026-43754 | 5.5 | 8.7 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved redaction of sensitive information. Th… |
| CVE-2026-43758 | 5.5 | 8.7 | Apple | macOS | CWE-200 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2021-32086 | 9.8 | 8.7 | n/a | n/a | CWE-321 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2026-28973 | 8.6 | 8.6 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-28912 | 7.8 | 8.6 | Apple | macOS | CWE-693 | A logic issue was addressed with improved restrictions. This issue is fixed i… |
| CVE-2026-43729 | 7.8 | 8.6 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43733 | 7.8 | 8.6 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43780 | 7.8 | 8.6 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-64716 | 7.8 | 8.6 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-28932 | 5.5 | 8.5 | Apple | macOS | CWE-400 | A logic issue existed resulting in memory corruption. This was addressed with… |
| CVE-2026-43768 | 5.5 | 8.5 | Apple | macOS | CWE-400 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-59552 | 7.2 | 8.4 | Shahadat Hossain | 3D Flipbook PDF Viewer & Embedder | CWE-918 | WordPress 3D Flipbook PDF Viewer & Embedder plugin <= 1.4.2 - Server Side Req… |
| CVE-2026-64708 | 5.5 | 8.4 | Apple | macOS | CWE-693 | A file quarantine bypass was addressed with additional checks. This issue is … |
| CVE-2026-43800 | 5.5 | 8.3 | Apple | iOS and iPadOS | CWE-200 | An information disclosure issue was addressed by removing the vulnerable code… |
| CVE-2026-43797 | 5.5 | 8.1 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved checks. This issue is fixed in iOS 18.… |
| CVE-2026-64745 | 2.4 | 8.1 | Apple | macOS | CWE-287 | This issue was addressed with additional restrictions on the lock screen. Thi… |
| CVE-2026-64692 | 7.1 | 8.0 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-43714 | 5.5 | 7.9 | Apple | iOS and iPadOS | CWE-20 | The issue was addressed with improved input sanitization. This issue is fixed… |
| CVE-2026-43796 | 5.5 | 7.9 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved data protection. This issue is fixed i… |
| CVE-2026-43801 | 5.5 | 7.9 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved checks. This issue is fixed in iOS 18.… |
| CVE-2026-64709 | 5.5 | 8.0 | Apple | iOS and iPadOS | CWE-200 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64721 | 5.5 | 7.9 | Apple | iOS and iPadOS | CWE-664 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-64766 | 7.8 | 7.9 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-20672 | 5.5 | 7.9 | Apple | macOS | CWE-200 | An information disclosure issue was addressed with improved privacy controls.… |
| CVE-2026-43763 | 5.5 | 7.9 | Apple | macOS | CWE-284 | A permissions issue was addressed by removing the vulnerable code. This issue… |
| CVE-2026-28945 | 7.1 | 7.8 | Apple | macOS | CWE-284 | A permissions issue was addressed with additional sandbox restrictions. This … |
| CVE-2026-13390 | 5.3 | 7.7 | Unknown | The Events Calendar | CWE-862 | The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Stat… |
| CVE-2026-43747 | 7.1 | 7.6 | Apple | macOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-64723 | 5.5 | 7.7 | Apple | iOS and iPadOS | CWE-284 | A logic issue was addressed with improved checks. This issue is fixed in iOS … |
| CVE-2025-59172 | 8.5 | 7.6 | Ericsson | Packet Core Controller (PCC) | CWE-78 | Improper Neutralization of Special Elements used in an OS Command Vulnerability |
| CVE-2026-43739 | 5.5 | 7.5 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43744 | 5.5 | 7.5 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43782 | 5.5 | 7.5 | Apple | macOS | CWE-200 | This issue was addressed with improved checks. This issue is fixed in macOS S… |
| CVE-2026-43816 | 5.5 | 7.5 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43817 | 5.5 | 7.5 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-64693 | 5.5 | 7.5 | Apple | iOS and iPadOS | CWE-843 | A type confusion issue was addressed with improved checks. This issue is fixe… |
| CVE-2026-64724 | 5.5 | 7.5 | Apple | iOS and iPadOS | CWE-400 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64776 | 5.5 | 7.6 | Apple | macOS | CWE-125 | The issue was addressed with improved bounds checks. This issue is fixed in m… |
| CVE-2026-64549 | await | 7.6 | Linux | Linux | — | Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() |
| CVE-2026-43759 | 5.5 | 7.5 | Apple | macOS | CWE-200 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-43673 | 7.8 | 7.2 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43711 | 7.8 | 7.2 | Apple | iOS and iPadOS | CWE-119 | A memory corruption issue was addressed with improved memory handling. This i… |
| CVE-2026-64749 | 7.8 | 7.3 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64758 | 7.8 | 7.3 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved bounds checks. This issue is fixed in i… |
| CVE-2026-64538 | await | 7.2 | Linux | Linux | — | ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). |
| CVE-2026-64544 | await | 7.2 | Linux | Linux | — | crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents |
| CVE-2026-64553 | await | 7.2 | Linux | Linux | — | net: psample: fix info leak in PSAMPLE_ATTR_DATA |
| CVE-2026-59553 | 7.1 | 7.0 | RexTheme | Product Feed Manager | CWE-79 | WordPress Product Feed Manager plugin <= 7.6.1 - Cross Site Scripting (XSS) v… |
| CVE-2026-59556 | 7.1 | 7.0 | acowebs | Dynamic Pricing With Discount Rules for WooCommerce | CWE-79 | WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.1… |
| CVE-2026-59558 | 7.1 | 7.0 | wpdevelop | Booking Calendar | CWE-79 | WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-64711 | 5.5 | 6.9 | Apple | iOS and iPadOS | CWE-285 | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-43681 | 7.1 | 6.7 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-64755 | 5.5 | 6.8 | Apple | iOS and iPadOS | CWE-200 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-64537 | await | 6.7 | Linux | Linux | — | bridge: cfm: reject invalid CCM interval at configuration time |
| CVE-2026-64542 | await | 6.7 | Linux | Linux | — | ipv6: ndisc: fix NULL deref in accept_untracked_na() |
| CVE-2026-64737 | 8.2 | 6.5 | Apple | macOS | CWE-284 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-65567 | 5.3 | 6.5 | Nexcess | Event Tickets | CWE-862 | WordPress Event Tickets plugin <= 5.29.0.1 - Broken Access Control vulnerability |
| CVE-2026-66477 | 5.3 | 6.5 | Shufflehound | Gillion | CWE-862 | WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability |
| CVE-2026-14236 | 4.7 | 6.5 | Unknown | Contact Form 7 | CWE-601 | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect |
| CVE-2026-43672 | 7.1 | 6.4 | Apple | macOS | CWE-863 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-43756 | 5.5 | 6.5 | Apple | macOS | CWE-200 | A logic issue was addressed with improved validation. This issue is fixed in … |
| CVE-2026-43775 | 5.5 | 6.4 | Apple | macOS | CWE-285 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-64707 | 5.5 | 6.5 | Apple | iOS and iPadOS | CWE-732 | A permissions issue was addressed with improved validation. This issue is fix… |
| CVE-2026-64754 | 5.5 | 6.3 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-12495 | 5.3 | 6.0 | Mercusys | MB115-4G | CWE-121 | Stack-Based Buffer Overflow in the Mercusys MB115-4G |
| CVE-2026-43767 | 5.0 | 6.0 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43819 | 5.5 | 5.9 | Apple | macOS | CWE-284 | An access issue was addressed with additional sandbox restrictions. This issu… |
| CVE-2026-66029 | 5.1 | 5.9 | Creativeitem | Ekushey Project Manager CRM | CWE-79 | Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field |
| CVE-2026-66030 | 5.1 | 5.9 | Creativeitem | Ekushey Project Manager CRM | CWE-79 | Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field |
| CVE-2026-66031 | 5.1 | 5.9 | Creativeitem | Ekushey Project Manager CRM | CWE-79 | Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field |
| CVE-2026-65568 | 5.0 | 5.9 | Visual Composer | Visual Composer Website Builder | CWE-862 | WordPress Visual Composer Website Builder plugin <= 45.15.0 - Broken Access C… |
| CVE-2026-13726 | 7.1 | 5.7 | Unknown | MPG | CWE-79 | Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode |
| CVE-2026-12982 | 6.1 | 5.6 | Unknown | Document Gallery | CWE-79 | Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery |
| CVE-2026-14190 | 6.1 | 5.6 | Unknown | Sina Extension for Elementor | CWE-79 | Sina Extension for Elementor < 3.10.2 - Reflected XSS |
| CVE-2026-17569 | 4.3 | 5.6 | Devolutions | Server | CWE-522 | Improper access control in the NetBox synchronizer in Devolutions Server allo… |
| CVE-2026-17570 | 4.3 | 5.5 | Devolutions | Server | CWE-639 | Improper access control in the PAM password history endpoints in Devolutions … |
| CVE-2026-10682 | 7.8 | 5.4 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable fro… |
| CVE-2026-56537 | 3.5 | 5.3 | HCLSoftware | Connections | CWE-209 | HCL Connections is vulnerable to information disclosure |
| CVE-2026-56538 | 3.5 | 5.3 | HCLSoftware | Connections | CWE-213 | HCL Connections is vulnerable to information disclosure |
| CVE-2026-14189 | 3.8 | 5.2 | Unknown | WPBot | CWE-89 | WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_f… |
| CVE-2026-12383 | 7.5 | 4.9 | Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | CWE-345 | Eda-server: externaleventstreamviewset trusts subject header without validati… |
| CVE-2026-61953 | 7.2 | 4.8 | QuantumCloud | Simple Link Directory Pro | CWE-918 | WordPress Simple Link Directory Pro plugin <= 15.0.6 - Server Side Request Fo… |
| CVE-2026-39874 | 7.8 | 4.5 | Apple | macOS | CWE-276 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-47078 | 4.8 | 4.4 | Erlang | OTP | CWE-23 | Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-co… |
| CVE-2026-43806 | 5.5 | 4.3 | Apple | macOS | CWE-400 | A denial of service issue was addressed by removing the vulnerable code. This… |
| CVE-2026-28849 | 5.5 | 4.2 | Apple | macOS | CWE-290 | The issue was addressed with improved checks. This issue is fixed in macOS Se… |
| CVE-2026-28900 | 5.5 | 4.2 | Apple | macOS | CWE-290 | A file quarantine bypass was addressed with additional checks. This issue is … |
| CVE-2025-59177 | 6.8 | 4.1 | Ericsson | Ericsson Packet Core Controller (PCC) | CWE-209 | Generation of Error Message Containing Sensitive Information Vulnerability |
| CVE-2025-59178 | 4.8 | 4.1 | Ericsson | Packet Core Controller (PCC) | CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere Vu… |
| CVE-2026-10082 | 6.1 | 3.9 | Unknown | Advanced Ads | CWE-79 | Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via th… |
| CVE-2026-13400 | 6.1 | 3.9 | Unknown | Simply Schedule Appointments | CWE-79 | Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Book… |
| CVE-2026-12991 | 8.7 | 3.7 | Ghost Robotics | Vision 60 | CWE-300 | Multiple vulnerabilities in Ghost Robotics' Vision 60 |
| CVE-2026-64548 | 8.4 | 3.7 | Linux | Linux | — | bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() |
| CVE-2026-64552 | 8.4 | 3.7 | Linux | Linux | — | virtio-net: fix len check in receive_big() |
| CVE-2026-61957 | 7.1 | 3.7 | miniOrange | miniorange otp verification | CWE-79 | WordPress miniorange otp verification plugin <= 5.5.1 - Cross Site Scripting … |
| CVE-2026-65437 | 7.1 | 3.7 | CleanTalk Inc | Spam protection, AntiSpam, FireWall by CleanTalk | CWE-79 | WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.82 - C… |
| CVE-2026-65438 | 7.1 | 3.7 | Kofi Mokome | Message Filter for Contact Form 7 | CWE-79 | WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.9 - Cross Site Sc… |
| CVE-2026-65439 | 7.1 | 3.7 | Themefic | Ultimate Addons for Contact Form 7 | CWE-79 | WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scr… |
| CVE-2026-65440 | 7.1 | 3.7 | Roxnor | GetGenie | CWE-79 | WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65441 | 7.1 | 3.7 | Nexcess | GiveWP | CWE-79 | WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65443 | 7.1 | 3.7 | WP Media | BackWPup | CWE-79 | WordPress BackWPup plugin <= 5.7.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65446 | 7.1 | 3.7 | WP Chill | Kali Forms | CWE-79 | WordPress Kali Forms plugin <= 2.4.18 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65447 | 7.1 | 3.7 | Wasiliy Strecker / ContestGallery developer | Contest Gallery | CWE-79 | WordPress Contest Gallery plugin <= 30.0.6 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-14203 | 4.8 | 3.4 | Unknown | Smart Manager | CWE-79 | Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title |
| CVE-2026-43781 | 4.7 | 3.4 | Apple | macOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-28926 | 7.0 | 3.3 | Apple | macOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
Results continue: ranks 401–440.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-27 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.