boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, July 28, 2026 · all times UTC← 2026-07-27 · archive · 2026-07-29 →

Security Box Score — July 28, 2026

243 CVEs published, led by IBM (31).

243 CVEs published July 28, 2026: 21 critical, 117 high, 93 medium, 12 low; 0 in the KEV catalog at press time; 20 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 218 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published864221045——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

892 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux8292309207122663711120.17.8.0016+317 ▲
microsoft664142110598132114286241.77.8.0047+444 ▲
google1201385156634556397760.47.8.0025-587 ▼
red hat1293511613817324200.06.5.0031+21 ▲
apple167271577813338872.66.5.0027+152 ▲
canonical72738115000.05.6.0014+1 ▲
suse82141241000.08.5.0039+4 ▲
freebsd01601240000.07.8.0016-9 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1537818110561129.77.5.0057+5 ▲
ubiquiti2536142110338.38.8.0049+17 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
fortinet14236611028626.17.2.0040+12 ▲
netgear62300221000.04.6.0024-11 ▼
f58165830416.38.6.0057+2 ▲
vmware8121821718.38.2.0039+5 ▲
checkpoint31236303216.77.7.04550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache1242795811396113310.47.5.0058+20 ▲
mozilla711275142340900.08.1.0031+22 ▲
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-17 ▼
github6121380000.06.0.0042+5 ▲
docker070520000.08.2.0016-4 ▼
wordpress3311102266.78.6.7979+3 ▲
kubernetes110001000.02.4.0035+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091379343653322612730.28.1.0036+867 ▲
adobe1052492611410541931.27.8.0026-27 ▼
ibm681925868660600.07.5.0034+36 ▲
progress334262970600.08.0.0038+28 ▲
solarwinds15221633010418.29.1.0058+12 ▲
zohocorp362220000.07.8.0146+2 ▲
veeam152300100.08.6.00510
atlassian3303001300.08.0.0026+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
d-link8200596300.05.5.0105-1 ▼
siemens7161870000.07.6.00240
abb170430000.07.2.0018-5 ▼
schneider electric060420000.07.8.0042-6 ▼
hikvision550320000.07.2.0038+5 ▲
moxa050320000.07.0.0029-5 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester49120006258000.05.5.0034+8 ▲
openclaw441110583914000.07.0.0026-17 ▼
dell4399547443211.07.1.0021+5 ▲
capgo2283242381000.07.1.0037-24 ▼
nvidia43821254160000.07.8.0037+37 ▲
imagemagick3374155612000.05.3.0018-2 ▼
spring073231391000.06.5.0024-72 ▼
itsourcecode1871001952000.02.1.0033-7 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-45659.760899.58.8
CVE-2026-0770.634299.19.8
CVE-2026-48282.423998.610.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
CVE-2026-898510.0.0660
CVE-2026-1377310.0.0610
CVE-2026-651610.0.0486
Most disclosures (vendor)
VendorCVEs
oracle1109
linux830
microsoft665
google503
apple204
red hat149
apache141
adobe115
ibm111
mozilla72
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco11
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven70
PyPI5
NuGet4
npm4
Go3
Packagist2
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-25089Fortinet0
CVE-2026-45659Microsoft0
CVE-2026-46817Oracle Corporation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171714
CVE-2021-27102n/a2021-11-171714
CVE-2021-27101n/a2021-11-171714
CVE-2021-27103n/a2021-11-171714
CVE-2021-21017Adobe2021-11-171714
CVE-2021-28550Adobe2021-11-171714
CVE-2021-42013Apache Software Foundation2021-11-171714
CVE-2021-41773Apache Software Foundation2021-11-171714
CVE-2021-30858Apple2021-11-171714
CVE-2021-30860Apple2021-11-171714

Transactions

EXPLOIT PUBLISHED — dompdf: 6 CVEs (CVE-2026-55554, CVE-2026-55555, CVE-2026-56722, CVE-2026-59941, CVE-2026-59942, CVE-2026-59943). Public exploit references added.

EXPLOIT PUBLISHED — Creativeitem Ekushey Project Manager CRM: 4 CVEs (CVE-2026-66028, CVE-2026-66029, CVE-2026-66030, CVE-2026-66031). Public exploit references added.

EXPLOIT PUBLISHED — cure53 DOMPurify: 4 CVEs (CVE-2026-65899, CVE-2026-65902, CVE-2026-65904, CVE-2026-65911). Public exploit references added.

EXPLOIT PUBLISHED — koxudaxi datamodel-code-generator: 4 CVEs (CVE-2026-54656, CVE-2026-54690, CVE-2026-55389, CVE-2026-55415). Public exploit references added.

EXPLOIT PUBLISHED — nuxsmin sysPass: 4 CVEs (CVE-2026-65708, CVE-2026-65709, CVE-2026-65710, CVE-2026-65711). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-17531 (unitedbyai droidclaw). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-31431 (Linux Kernel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-39875 (Apple macOS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4258 (sjcl). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43760 (Apple macOS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43910 (appium java-client). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45711 (axllent mailpit). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47427 (github-mcp-server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49477 (facelessuser soupsieve). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-53359 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54332 (gopacket). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54345 (gopacket). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-61511 (vBulletin). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64620 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64621 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-65917 (usmannasir cyberpanel). Public exploit reference added.

RESCORED — Microsoft Exchange Server 2016 Cumulative Update 23: 4 CVEs (CVE-2026-45501, CVE-2026-45503, CVE-2026-45583, CVE-2026-47631). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2024-21538 (cross-spawn). CVSS 8.7 → 7.7 (NVD).

RESCORED — CVE-2025-68686 (Fortinet FortiOS). CVSS 5.3 → 5.9 (NVD).

RESCORED — CVE-2026-15631 (@fastify/http-proxy). CVSS 8.7 → 10 (NVD).

RESCORED — CVE-2026-4258 (sjcl). CVSS 8.7 → 7.7 (NVD).

ENRICHED — CVE-2026-31431 (Linux Kernel). Received CVSS 7.8 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

243 CVEs published. 25 box scores, 218 table rows — nothing truncated.

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebU…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0137   69.7     —
AFFECTED
  Product          Versions     Fixed
  WRC-X3000GS3-B   unspecified  —
  WRC-X3000GS3A-B  unspecified  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 28  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Deferred
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Rest…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0137   69.7     —
AFFECTED
  Product       Versions     Fixed
  WAB-M1775-PS  unspecified  —
  WAB-S1775     unspecified  —
  WAB-M2133     unspecified  —
  WAB-I1750-PS  unspecified  —
  WAB-S1167-PS  unspecified  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 28  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Deferred
IBM Aspera Faspex 5 — OS Command Injection in IBM Aspera Faspex
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0104   61.3     —
AFFECTED
  Product          Versions  Fixed
  Aspera Faspex 5  5.0.0 –   —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: ibm)
CWE-78 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
Apache Axis2/Java: deserialization of untrusted Data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0103   61.2     —
AFFECTED
  Product            Versions     Fixed
  Apache Axis2/Java  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 28  Published (CNA: apache)
CWE-502 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Analyzed
owen2345 camaleon-cms — Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0083   54.9     —
AFFECTED
  Product       Versions  Fixed
  camaleon-cms  2.1.1 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 28  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 7 references · NVD status: Deferred
n/a zip-lib — Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanis…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0078   53.3     —
AFFECTED
  Product  Versions     Fixed
  zip-lib  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 28  Published (CNA: snyk)
CWE-22 · CNA: snyk · CVSS v4.0 · 3 references · NVD status: Deferred
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0075   52.1     —
AFFECTED
  Product  Versions   Fixed
  dompdf   < 3.1.6 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Public exploit reference published
  Jul 28  Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · CVSS v4.0 · 4 references · NVD status: Analyzed
wordplus Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots — Better Messages <= 2.15.19 - Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal via 'file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0071   50.8     —
AFFECTED
  Product                                                                    Versions     Fixed
  Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots  unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 28  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0057   44.8     —
AFFECTED
  Product                       Versions  Fixed
  WebSphere Application Server  9.0 –     —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 28  Published (CNA: ibm)
CWE-502 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
IBM Aspera Faspex 5 — OS command injection in IBM Aspera Faspex
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0052   41.8     —
AFFECTED
  Product          Versions  Fixed
  Aspera Faspex 5  5.0.0 –   —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: ibm)
CWE-78 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0051   41.3     —
AFFECTED
  Product   Versions   Fixed
  gopacket  < 1.6.1 –  —
TIMELINE
  Jun 12  Reserved by CNA
  Jul 28  Public exploit reference published
  Jul 28  Published (CNA: GitHub_M)
CWE-191, CWE-770 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Analyzed
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0051   41.3     —
AFFECTED
  Product  Versions   Fixed
  dompdf   < 3.1.6 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Public exploit reference published
  Jul 28  Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Analyzed
deveasel Demi – One Click Demo Import, Backup & Site Migration — Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0051   41.1     —
AFFECTED
  Product                                                Versions     Fixed
  Demi – One Click Demo Import, Backup & Site Migration  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 28  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
uncannyowl Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin — Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0050   40.5     —
AFFECTED
  Product                                                                               Versions     Fixed
  Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 28  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0050   40.2     —
AFFECTED
  Product   Versions   Fixed
  gopacket  < 1.6.1 –  —
TIMELINE
  Jun 12  Reserved by CNA
  Jul 28  Public exploit reference published
  Jul 28  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Analyzed
misp misp — Open Redirect in MISP Installer-Generated Apache Configuration
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   N    7.8   .0049   40.1     —
AFFECTED
  Product  Versions     Fixed
  misp     unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 28  Published (CNA: CIRCL)
CWE-601 · CNA: CIRCL · CVSS v4.0 · 1 reference · NVD status: Deferred
SICK AG InspectorP61x — CVE-2026-11841
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  L    9.4   .0049   39.8     —
AFFECTED
  Product        Versions        Fixed
  InspectorP61x  unspecified     —
  InspectorP62x  unspecified     —
  InspectorP65x  all versions –  —
  InspectorP63x  all versions –  —
  InspectorP64x  all versions –  —
  ICR890-4       unspecified     —
TIMELINE
  Jun 10  Reserved by CNA
  Jul 28  Published (CNA: SICK AG)
CWE-552 · CNA: SICK AG · CVSS v3.1 · 6 references · NVD status: Received
Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0049   39.8     —
AFFECTED
  Product               Versions     Fixed
  Apache ActiveMQ AMQP  unspecified  —
  Apache ActiveMQ       unspecified  —
  Apache ActiveMQ All   unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: apache)
CWE-20 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Weidmueller Interface PROCON-WEB SCADA — SQL injection via unauthenticated GetGridData endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0048   39.0     —
AFFECTED
  Product           Versions  Fixed
  PROCON-WEB SCADA  1.0.0 –   —
TIMELINE
  Jul 21  Reserved by CNA
  Jul 28  Published (CNA: CERTVDE)
CWE-89 · CNA: CERTVDE · CVSS v4.0 · 1 reference · NVD status: Deferred
hypequery hypequery — @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0046   38.2     —
AFFECTED
  Product    Versions   Fixed
  hypequery  < 2.5.1 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jul 28  Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · CVSS v3.1 · 8 references · NVD status: Deferred
cozyvision1 SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery — SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0046   37.8     —
AFFECTED
  Product                                                                               Versions     Fixed
  SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: Wordfence)
CWE-288 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
Xen Xen — vIRQ event channel binding may break Xenstore
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   37.8     —
AFFECTED
  Product  Versions     Fixed
  Xen      unspecified  —
TIMELINE
  Apr 27  Reserved by CNA
  Jul 28  Published (CNA: XEN)
CWE-459 · CNA: XEN · CVSS v3.1 · 3 references · NVD status: Deferred
balbooa.com Balbooa Forms component for Joomla — Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0046   37.6     —
AFFECTED
  Product                             Versions         Fixed
  Balbooa Forms component for Joomla  1.0.0-2.4.2.1 –  —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 28  Published (CNA: Joomla)
CWE-94 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Deferred
HashiCorp Tooling — terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  L   10.0   .0046   37.5     —
AFFECTED
  Product  Versions  Fixed
  Tooling  0.3.0 –   —
TIMELINE
  Jul 21  Reserved by CNA
  Jul 28  Published (CNA: HashiCorp)
CWE-488 · CNA: HashiCorp · CVSS v3.1 · 1 reference · NVD status: Deferred
themetechmount TrueBooker – Appointment Booking and Scheduler System — TrueBooker <= 1.2.2 - Unauthenticated SQL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0045   37.5     —
AFFECTED
  Product                                                Versions     Fixed
  TrueBooker – Appointment Booking and Scheduler System  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 28  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-671858.737.4GeneralSandmanTinyWebCWE-22TinyWeb 0.0.8 Path Traversal via URL Path Component
CVE-2026-1175610.037.3Dassault SystèmesStation Launcher App in 3DEXPERIENCE platformCWE-502Deserialization of Untrusted Data vulnerability affecting Station Launcher Ap…
CVE-2026-662997.537.3Apache Software FoundationApache TomcatCWE-400Apache Tomcat: DoS via WebSocket chat example
CVE-2026-424937.537.2XenXenCWE-400x86 shadow paging is deprecated
CVE-2026-546538.837.0koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code injection in via attacker-contr…
CVE-2026-474277.536.6githubgithub-mcp-serverCWE-476GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler
CVE-2026-671848.735.7GeneralSandmanTinyWebCWE-476TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
CVE-2026-553897.535.6koxudaxidatamodel-code-generatorCWE-22datamodel-code-generator vulnerable to arbitrary local file read via JSON-Sch…
CVE-2026-546357.534.8nessshontonapiCWE-287pytonapi has a Webhook Custom Path Authentication Bypass
CVE-2026-671826.934.3tomakarouilleCWE-444Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
CVE-2026-554157.534.1koxudaxidatamodel-code-generatorCWE-94datamodel-code-generator vulnerable to code injection via `x-python-import` /…
CVE-2026-667548.233.0tomakarouilleCWE-617Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
CVE-2026-210478.332.5Samsung MobileSamsung Mobile DevicesCWE-787Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remo…
CVE-2026-616097.532.2pterodactylpanelCWE-770Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enable…
CVE-2026-633035.131.9OpenSolutionQuick.CMSCWE-23Path Traversal in Quick.CMS
CVE-2026-671749.231.3pivotickpivotickCWE-79DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pi…
CVE-2026-656246.931.1nineninescowboyCWE-770Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory …
CVE-2026-599327.530.7PHPOfficePhpSpreadsheetCWE-400PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaus…
CVE-2026-599337.530.7PHPOfficePhpSpreadsheetCWE-400PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
CVE-2026-149749.830.6IBMWebSphere Application ServerCWE-502IBM WebSphere Application Server is affected by cross-site scripting and dese…
CVE-2026-148698.630.7HashiCorpToolingCWE-918terraform-mcp-server vulnerable to server side request forgery leading to tok…
CVE-2026-624345.330.4XenXenCWE-787PoD: Don't try to reclaim special pages
CVE-2026-614876.530.4Apache Software FoundationApache ActiveMQ BrokerCWE-285Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization b…
CVE-2026-599317.730.0PHPOfficePhpSpreadsheetCWE-918PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
CVE-2026-164968.929.6HashiCorpToolingCWE-384terraform-mcp-server vulnerable to cross-user credential inheritance if an MC…
CVE-2026-68792.029.5Python Software FoundationCPythonCWE-407Quadratic Behavior in xml.etree.ElementPath Index Predicates
CVE-2026-546596.929.5ddnexuspagyCWE-22Pagy I18n locale option is not validated before being used in a file path
CVE-2026-671838.729.4GeneralSandmanTinyWebCWE-401TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling
CVE-2026-143288.829.1eazypluginsEazy Plugin Manager – Powerful Plugin Management Solution for WordPressCWE-269Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalati…
CVE-2026-546038.628.8ruby-oauthoauth2CWE-200OAuth2::Client#request: Protocol-relative redirect Location overrides authori…
CVE-2026-546508.628.8bablilayoubopenholeCWE-22openhole-server vulnerable to path traversal via URL-decoded request path
CVE-2026-553907.528.8koxudaxidatamodel-code-generatorCWE-22Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`)…
CVE-2026-624317.528.7XenXenCWE-369Viridian STIMER division by zero
CVE-2026-633017.028.7OpenSolutionQuick.CMSCWE-602Denial of Service in Quick.CMS
CVE-2026-545938.128.4pterodactylpanelCWE-1259Pterodactyl's improper JWT scoping allows subuser to upload files when not ex…
CVE-2026-648639.128.2goshs-labsgoshsCWE-284goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVE-2026-555552.328.0dompdfdompdfCWE-203Dompdf: File existence oracle via font-face stylesheet declaration
CVE-2026-167718.827.9AT&TArris BGW210‑700CWE-306CVE-2026-16771
CVE-2026-546387.527.1gotdtdCWE-770td has pre-auth denial of service via unbounded memory allocation in proto.Un…
CVE-2026-623259.126.9goshs-labsgoshsCWE-306goshs SFTP authentication bypass via empty password (incomplete fix of CVE-20…
CVE-2026-671735.126.6pivotickpivotickCWE-918Pivotick Unvalidated Node Image URLs Allow Unintended Client-Side Requests
CVE-2026-575108.726.3superplanehqsuperplaneCWE-639SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC
CVE-2026-152807.526.0IBMWebSphere Application Server - LibertyCWE-22IBM WebSphere Application Server Liberty is affected by a remote code executi…
CVE-2026-150125.326.0deveaselDemi – One Click Demo Import, Backup & Site MigrationCWE-200Demi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory Copy
CVE-2026-144469.825.6IBMWebSphere Application ServerCWE-306IBM WebSphere Application Server is affected by a privilege escalation
CVE-2026-51144.925.3softaculousSpeedyCache – Cache, Optimization, PerformanceCWE-22SpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File Read
CVE-2026-567226.325.2dompdfdompdfCWE-20Dompdf: Local file read due to improper file path validation in SVG images en…
CVE-2026-555542.324.9dompdfdompdfCWE-20Dompdf: Chroot Validation Bypass
CVE-2026-156734.424.0cozyvision1SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart RecoveryCWE-89SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checko…
CVE-2026-161849.823.8IBMWebSphere Application ServerCWE-862IBM WebSphere Application Server is affected by an authentication bypass
CVE-2026-667457.523.8ArticaTechArtica ProxyCWE-94Artica Proxy 4.50 Session Fixation via fw.login.php
CVE-2026-667497.123.3sdelementslets-chatCWE-476Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup
CVE-2026-660645.322.9goshs-labsgoshsCWE-41goshs has ACL Bypass & Path Traversal
CVE-2026-474838.222.7NVIDIADCGMCWE-770NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug…
CVE-2026-633025.122.7OpenSolutionQuick.CMSCWE-98Local File Inclusion in Quick.CMS
CVE-2026-149769.822.5IBMWebSphere Application Server - LibertyCWE-306IBM WebSphere Application Server Liberty is affected by a remote code executi…
CVE-2026-149739.322.4IBMAspera Desktop AppCWE-22Path Traversal in IBM Desktop App
CVE-2026-102077.522.5pickpluginsPickPlugins Question AnswerCWE-89PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id…
CVE-2026-127417.522.5epsiloncoolWP Fast Total Search – The Power of Indexed SearchCWE-89WP Fast Total Search <= 1.80.280 - Unauthenticated SQL Injection
CVE-2026-128007.522.5codename065Premium Packages – Sell Digital Products SecurelyCWE-89Premium Packages <= 6.2.0 - Unauthenticated SQL Injection
CVE-2026-147857.522.5mihail-chepovskiyWeb Directory FreeCWE-89Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection
CVE-2026-439108.222.2appiumjava-clientCWE-441Appium java-client Allows Network Pivot via Unvalidated directConnect Redirec…
CVE-2026-507387.722.1EnterpriseDBpglogicalCWE-416A use-after-free condition exists in pglogical's worker signaling code, where…
CVE-2026-599436.321.9dompdfdompdfCWE-209Dompdf: Embedded SVG images can leak existence of files and directories withi…
CVE-2026-145287.521.5IBMWebSphere Application ServerCWE-532IBM WebSphere Application Server is affected by an unsafe deserialization and…
CVE-2026-145459.821.2UnknownTrueBookerCWE-269TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via…
CVE-2026-592488.721.1nineninescowlibCWE-770Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhau…
CVE-2026-480256.921.1juevnebula-meshCWE-244nebula-mesh: Decrypted CA private key persists in heap after signing
CVE-2026-671816.321.1tomakarouilleCWE-444Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
CVE-2026-493328.520.9Red HatRed Hat OpenShift Container Platform 4.12CWE-436Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling ena…
CVE-2026-145167.520.9ladelaOnline Scheduling and Appointment Booking System – BooklyCWE-89Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQ…
CVE-2026-19184.920.9IBMSterling B2B IntegratorCWE-532IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive inf…
CVE-2026-141698.120.7ads-tec Industrial ITDVG-IRF1401CWE-696ads-tec Industrial IT: Account lockout via non-atomic user creation
CVE-2026-480608.120.4litestar-orglitestarCWE-79Litestar: HTML Injection Through CSRF Token
CVE-2026-669225.120.3pivotickpivotickCWE-1321Pivotick Prototype-Key Collision in Tree Layout and Cycle Detection Allows Gr…
CVE-2026-492588.820.2juevnebula-meshCWE-639Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to…
CVE-2026-547197.520.3goshs-labsgoshsCWE-862goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download …
CVE-2026-75215.520.3MattermostMattermostCWE-22SAML certificate deletion allows path traversal to delete arbitrary files out…
CVE-2026-180476.520.1Red HatRed Hat Certificate System 10CWE-288Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint aut…
CVE-2026-154444.919.9themeumTutor LMS – eLearning and online course solutionCWE-89Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon…
CVE-2026-156714.919.9cozyvision1SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart RecoveryCWE-89SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Pa…
CVE-2026-141688.819.5ads-tec Industrial ITDVG-IRF1401CWE-862ads-tec Industrial IT: Vertical privilege escalation via configuration table …
CVE-2026-141678.719.5ads-tec Industrial ITDVG-IRF1401CWE-863ads-tec Industrial IT: Privilege escalation during configuration import
CVE-2026-669188.219.6pivotickpivotickCWE-79DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons
CVE-2026-669216.319.6pivotickpivotickCWE-79Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node …
CVE-2026-77698.119.4IBMSterling B2B IntegratorCWE-89SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM S…
CVE-2024-140418.219.3Legion of the Bouncy Castle Inc.BC-JAVACWE-208ML-KEM (Kyber) decapsulation leaks private key information through non-consta…
CVE-2026-167735.319.2quantumcloudWPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-200WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_sen…
CVE-2026-159928.818.1teydeastudioWP Password PolicyCWE-269WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation
CVE-2026-163478.718.0MikroTikRouterOSCWE-307Improper restriction of excessive authentication attempts in MikroTik RouterO…
CVE-2026-134407.217.9wedevsStoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerceCWE-79StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Chec…
CVE-2026-546098.617.6Quiet-Terminal-InteractiveQTINeonCWE-400QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNE…
CVE-2026-149817.517.7IBMWebSphere Application ServerCWE-400IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-150577.517.7IBMWebSphere Application Server - LibertyCWE-787IBM WebSphere Application Server Liberty is affected by a denial of service v…
CVE-2026-472197.517.7delvedorfind-my-wayCWE-20find-my-way is Vulnerable to DDoS with HTTP2
CVE-2026-161926.517.7IBMWebSphere Application Server - LibertyCWE-674IBM WebSphere Application Server Liberty is affected by a denial of service
CVE-2026-667505.317.8sdelementslets-chatCWE-862Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files…
CVE-2026-669196.917.6PivotickPivotickCWE-79Stored DOM-Based Cross-Site Scripting in Node Modal Headers
CVE-2026-637278.717.3AnchoreAnchore EnterpriseCWE-648Anchore Enterprise Privilege Escalation via User Management API
CVE-2026-154115.317.4wedevsStoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerceCWE-862StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Chec…
CVE-2026-156704.917.2cozyvision1SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart RecoveryCWE-89SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderb…
CVE-2026-168114.917.2devitemsllcShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-89ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'order…
CVE-2026-546908.216.8koxudaxidatamodel-code-generatorCWE-918datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP UR…
CVE-2026-152676.516.5taskbuilderTaskbuilder – Project Management & Task Management Tool With Kanban BoardCWE-89Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection
CVE-2026-669208.216.4PivotickPivotickCWE-400Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data
CVE-2026-149247.516.5UnknownTablesome TableCWE-862Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
CVE-2026-624337.316.4XenXenCWE-665correct buffer checks for DM_OP hypercalls
CVE-2026-669136.916.4lookyloolookylooCWE-400Zip Bomb in Lookyloo Capture Upload Allows Denial of Service
CVE-2026-599216.515.7nettynettyCWE-93Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
CVE-2026-658817.515.5joomdle.comJoomdle component for JoomlaCWE-1188Joomla Extension - joomdle.com - Insecure default configuration allows read/w…
CVE-2026-624327.315.4XenXenCWE-362evtchn: Race between FIFO expand and reset
CVE-2026-624307.515.2XenXenCWE-362x86: Out-of-bounds read in vRTC emulation
CVE-2026-153936.415.2cozythemesCozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & TemplatesCWE-79Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-62516.515.0ChatyChaty ProCWE-89Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id…
CVE-2026-153046.515.0foomagooPlugin OrganizerCWE-89Plugin Organizer <= 10.2.4 - Authenticated (Subscriber+) SQL Injection
CVE-2026-667465.315.0tomakarouilleCWE-113Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
CVE-2026-624278.814.8XenXenCWE-284sysctl and platform-op locks open to abuse
CVE-2026-96805.814.9AlibabaAlibaba Cloud RDS OpenAPI MCP ServerCWE-1188MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-…
CVE-2026-49124.114.9tigroumeowMedia Cleaner: Clean your WordPress!CWE-918Media Cleaner: Clean your WordPress! <= 7.0.3 - Authenticated (Administrator+…
CVE-2026-163137.614.5Red HatRed Hat Enterprise Linux 10CWE-93Sg3_utils: sg3_utils: arbitrary command execution via udev property injection…
CVE-2026-477267.114.6juevnebula-meshCWE-285nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
CVE-2026-667526.314.5tiny-httptiny-httpCWE-444tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
CVE-2026-553917.514.4koxudaxidatamodel-code-generatorCWE-350datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
CVE-2026-575116.314.3superplanehqsuperplaneCWE-93SuperPlane < 0.30.0 SMTP Header Injection via Webhook Event Title
CVE-2026-628285.414.2MicrosoftMicrosoft Edge for AndroidCWE-20Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
CVE-2026-131105.314.2wedevsStoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerceCWE-862StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Chec…
CVE-2026-167745.314.2quantumcloudWPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-862WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpc…
CVE-2026-660636.513.9goshs-labsgoshsCWE-22goshs has a Path Traversal issue
CVE-2026-483968.613.8AdobeAdobe BridgeCWE-863Bridge | Incorrect Authorization (CWE-863)
CVE-2026-483747.813.8AdobeAdobe BridgeCWE-22Bridge | Improper Limitation of a Pathname to a Restricted Directory ('Path T…
CVE-2026-153288.113.6IBMWebSphere Application ServerCWE-444IBM WebSphere Application Server and WebSphere Application Server Liberty is …
CVE-2026-167974.313.6devitemsllcShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-639ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Cont…
CVE-2026-483958.613.4AdobeAdobe BridgeCWE-426Bridge | Untrusted Search Path (CWE-426)
CVE-2026-141716.113.2ads-tec Industrial ITDVG-IRF1401CWE-601ads-tec Industrial IT: Post-login open redirect in the web interface
CVE-2026-149968.212.9IBMAspera Faspex 5CWE-613Multiple vulnerabilities in IBM Aspera Faspex
CVE-2026-165816.913.0igloohomeSmart Lock Mobile ApplicationCWE-540Inclusion of sensitive information in source code in igloohome Smart Lock Mob…
CVE-2026-546567.812.8koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code execution on import via unescap…
CVE-2026-134637.512.9IBMCloud Pak SystemCWE-798Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulner…
CVE-2026-624296.512.8XenXenCWE-362vNUMA domain cleanup may race other operations
CVE-2026-494475.312.8azukaarCosmos-ServerCWE-287Cosmos-Server's constellation public-devices endpoint accepts arbitrary beare…
CVE-2026-180382.112.5nextlevelbuilderGoClawCWE-200nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute informati…
CVE-2026-624268.812.3XenXenCWE-412sysctl and platform-op locks open to abuse
CVE-2026-150648.712.3IBMWebSphere Application ServerCWE-444IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-31574.312.2IBMSterling B2B IntegratorCWE-615Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File G…
CVE-2026-667536.312.1tiny-httptiny-httpCWE-113tiny-http 0.12.0 HTTP Response Splitting via Header Injection
CVE-2026-175285.312.0n/anice-select2CWE-79Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-sit…
CVE-2026-71878.811.8Universal Software Inc.UKBSCWE-306Improper Authentication in Universal Sotware's UKBS
CVE-2026-165874.311.8nasirahmedAdvanced Form Integration — Connect Forms to 200+ AppsCWE-862Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (…
CVE-2026-667515.311.5sdelementslets-chatCWE-862Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
CVE-2026-554033.711.3koxudaxidatamodel-code-generatorCWE-200datamodel-code-generator: Authorization / request headers leaked to cross-ori…
CVE-2026-546918.211.0koxudaxidatamodel-code-generatorCWE-918datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation,…
CVE-2026-157306.411.0rubengcGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-79GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-121245.311.0wpeverestPDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice DesignerCWE-862PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Di…
CVE-2026-153258.710.8IBMWebSphere Application ServerCWE-444IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-483918.210.6AdobeAdobe BridgeCWE-426Bridge | Untrusted Search Path (CWE-426)
CVE-2026-180296.310.7pretix GmbHpretix-girosolutionCWE-841Insufficient validation of payment status in pretix-girosolution
CVE-2026-80584.510.7IBMOPENBMCCWE-200This Power System update is being released to address a sensitive information…
CVE-2026-180282.310.7pretix GmbHpretixCWE-639Missing authorization check in event quick setup view
CVE-2026-115985.010.3lrnzShortcodifyCWE-79Shortcodify <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-68819.410.2EllucianAdvance WebCWE-89Authenticated SQL Injection Enables Unauthorized Access to Sensitive Informat…
CVE-2026-483727.810.1AdobeFormat PluginsCWE-787Format Plugins | Heap-based Buffer Overflow (CWE-122)
CVE-2026-148937.310.0IBMObservability with Instana (Agent)CWE-1321IBM Instana Observability is affected by multiple Prototype Pollution within …
CVE-2026-424955.59.5XenXenCWE-191buffer overruns in libfsimage iso9660 handling
CVE-2026-624235.59.5XenXenCWE-130buffer overruns in libfsimage iso9660 handling
CVE-2026-624245.59.5XenXenCWE-130buffer overruns in libfsimage iso9660 handling
CVE-2026-624255.59.5XenXenCWE-20buffer overruns in libfsimage iso9660 handling
CVE-2026-483927.89.5AdobeAdobe BridgeCWE-787Bridge | Out-of-bounds Write (CWE-787)
CVE-2026-483937.89.5AdobeAdobe BridgeCWE-787Bridge | Out-of-bounds Write (CWE-787)
CVE-2026-483947.89.5AdobeAdobe BridgeCWE-787Bridge | Out-of-bounds Write (CWE-787)
CVE-2026-507369.09.1EnterpriseDBpglogicalCWE-89The pglogical queue mechanism, used to convey out-of-band commands such as re…
CVE-2026-507379.09.1EnterpriseDBpglogicalCWE-250When applying replicated changes for a row that is missing one or more column…
CVE-2026-507356.19.1EnterpriseDBpglogicalCWE-125pglogical's apply worker does not sufficiently validate the length of certain…
CVE-2026-480584.69.0juevnebula-meshCWE-614nebula-mesh: Session and OIDC state cookies lack the Secure attribute
CVE-2026-483908.28.8AdobeAdobe BridgeCWE-863Bridge | Incorrect Authorization (CWE-863)
CVE-2026-624356.58.4XenXenCWE-362grant-table: version change racing with other operations
CVE-2026-624366.58.4XenXenCWE-362grant-table: version change racing with other operations
CVE-2026-113916.38.2TaniumPatchCWE-89Tanium addressed a SQL injection vulnerability in Patch.
CVE-2026-452938.68.0WordPressWordPress-Coding-StandardsCWE-95WordPress Coding Standards (WordPressCS) contains an arbitrary code execution…
CVE-2026-443875.17.9ELECOM CO.,LTD.WAB-M1775-PSCWE-79ELECOM wireless LAN routers and access points devices contain a reflected cro…
CVE-2026-31584.37.6IBMSterling B2B IntegratorCWE-615Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File G…
CVE-2026-150166.47.4strangerstudiosPaid Memberships Pro – Content Restriction, User Registration, & Paid SubscriptionsCWE-79Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscri…
CVE-2026-73626.57.3IBMSterling B2B IntegratorCWE-284Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator…
CVE-2026-145156.17.3IBMWebSphere Application ServerCWE-79IBM WebSphere Application Server is affected by cross-site scripting and dese…
CVE-2026-134427.16.9IBMLangflow OSSCWE-520Langflow is affected by NET Misconfiguration: Use of Impersonation due to mul…
CVE-2026-78686.56.9IBMOPENBMCCWE-863This Power System update is being released to address incorrect authorization
CVE-2026-483888.66.7AdobeAdobe Photoshop InstallerCWE-427Photoshop Installer | CWE-427: Uncontrolled Search Path Element
CVE-2026-148212.76.3UnknownQuiz and Survey Master (QSM)CWE-862Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
CVE-2026-568217.45.8nettynettyCWE-299Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
CVE-2026-161075.95.2IBMTS4500 CLI toolCWE-295TS4500 CLI tool addresses security vulnerability
CVE-2026-180855.95.0BlackBerryUEMCWE-74Improper Input Validation Leads to Arbitrary File Download and Potential Deni…
CVE-2026-477256.94.8juevnebula-meshCWE-352nebula-mesh: Web UI lacks CSRF tokens on /ui/* mutating endpoints
CVE-2026-582464.34.4SAP_SESAP NetWeaver Application Server for ABAPCWE-497Information Disclosure vulnerability in SAP NetWeaver Application Server for …
CVE-2026-180848.64.3BlackBerryUEMCWE-79Cross-Site Scripting (XSS) in Management Console of BlackBerry UEM
CVE-2026-545457.14.3pionxzhwakaruCWE-22@wakaru/cli arbitrary file write during bundle unpack
CVE-2026-81676.14.3THEWP Digital SolutionsNews Theme V8CWE-79Reflected XSS in theWP's News Theme V8
CVE-2026-658826.14.3joomdle.comJoomdle component for JoomlaCWE-79Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1
CVE-2026-546557.84.0koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code execution on import via `x-pyth…
CVE-2026-149264.23.9UnknownFluentCart A New Era of eCommerceCWE-284FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR
CVE-2026-546217.83.7koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code injection via unescaped carriag…
CVE-2026-546547.83.7koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code injection via unescaped carriag…
CVE-2026-148707.13.7UnknownDatabase for Contact Form 7, WPforms, Elementor formsCWE-79Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS…
CVE-2026-77754.83.8IBMSterling B2B IntegratorCWE-79Cross-site Scripting Security Vulnerability in IBM Sterling B2B Integrator an…
CVE-2026-148193.53.8UnknownEvent Tickets and RegistrationCWE-79Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move
CVE-2026-418746.83.0OpenSolutionQuick.CartCWE-256Hard-coded admin credentials in Quick.Cart
CVE-2026-546057.23.0ruby-oauthoauthCWE-200OAuth: Cross-origin token-request redirects can expose signed request metadata
CVE-2026-151364.32.8wplegalpagesWPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent ModeCWE-352Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Req…
CVE-2026-46486.81.9CasfID Servicios TecnológicosNFC WristbandsCWE-326Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands
CVE-2026-170723.31.8Red HatRed Hat Enterprise Linux 10CWE-125Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matro…
CVE-2026-624287.81.7XenXenCWE-367grant-table: type confusion in grant-copy
CVE-2026-181077.81.5Red HatRed Hat Enterprise Linux 10CWE-269Criu: criu: container escape via rseq critical section hijack during checkpoi…
CVE-2026-568227.41.5nettynettyCWE-367Netty: TOCTOU in OcspServerCertificateValidator
CVE-2026-424946.11.4XenXenCWE-125buffer overruns in libfsimage iso9660 handling
CVE-2026-477685.51.3juevnebula-meshCWE-598nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, …
CVE-2026-546192.01.2sparklemotionsqlite3-rubyCWE-416sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Differe…
CVE-2026-546202.01.2sparklemotionsqlite3-rubyCWE-416sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
CVE-2026-81647.31.2ArkSigner Software and Hardware Industry and Trade Inc.ArkSigner Desktop ClientCWE-427Search Order Hijacking in ArkSigner's ArkSigner Desktop Client
CVE-2026-559773.30.8EShareEShareProCWE-307Bypass of application rate-limiting mechanism
CVE-2026-49324.20.2IBMPowerVM HypervisorCWE-331This Power System update is being released to address Insufficient Entropy

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-28 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.