AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0137 69.7 —
AFFECTED Product Versions Fixed WRC-X3000GS3-B unspecified — WRC-X3000GS3A-B unspecified —
TIMELINE Jul 13 Reserved by CNA Jul 28 Published (CNA: jpcert)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
243 CVEs published, led by IBM (31).
243 CVEs published July 28, 2026: 21 critical, 117 high, 93 medium, 12 low; 0 in the KEV catalog at press time; 20 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 218 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 8642 | 21045 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
892 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 829 | 2309 | 207 | 1226 | 637 | 1 | 11 | 2 | 0.1 | 7.8 | .0016 | +317 ▲ |
| microsoft | 664 | 1421 | 105 | 981 | 321 | 14 | 286 | 24 | 1.7 | 7.8 | .0047 | +444 ▲ |
| 120 | 1385 | 156 | 634 | 556 | 39 | 77 | 6 | 0.4 | 7.8 | .0025 | -587 ▼ | |
| red hat | 129 | 351 | 16 | 138 | 173 | 24 | 2 | 0 | 0.0 | 6.5 | .0031 | +21 ▲ |
| apple | 167 | 271 | 57 | 78 | 133 | 3 | 88 | 7 | 2.6 | 6.5 | .0027 | +152 ▲ |
| canonical | 7 | 27 | 3 | 8 | 11 | 5 | 0 | 0 | 0.0 | 5.6 | .0014 | +1 ▲ |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0039 | +4 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | -9 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 15 | 37 | 8 | 18 | 11 | 0 | 56 | 11 | 29.7 | 7.5 | .0057 | +5 ▲ |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +17 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| fortinet | 14 | 23 | 6 | 6 | 11 | 0 | 28 | 6 | 26.1 | 7.2 | .0040 | +12 ▲ |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | -11 ▼ |
| f5 | 8 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | +2 ▲ |
| vmware | 8 | 12 | 1 | 8 | 2 | 1 | 7 | 1 | 8.3 | 8.2 | .0039 | +5 ▲ |
| checkpoint | 3 | 12 | 3 | 6 | 3 | 0 | 3 | 2 | 16.7 | 7.7 | .0455 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 124 | 279 | 58 | 113 | 96 | 11 | 33 | 1 | 0.4 | 7.5 | .0058 | +20 ▲ |
| mozilla | 71 | 127 | 51 | 42 | 34 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | +22 ▲ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -17 ▼ |
| github | 6 | 12 | 1 | 3 | 8 | 0 | 0 | 0 | 0.0 | 6.0 | .0042 | +5 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -4 ▼ |
| wordpress | 3 | 3 | 1 | 1 | 1 | 0 | 2 | 2 | 66.7 | 8.6 | .7979 | +3 ▲ |
| kubernetes | 1 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1109 | 1379 | 343 | 653 | 322 | 61 | 27 | 3 | 0.2 | 8.1 | .0036 | +867 ▲ |
| adobe | 105 | 249 | 26 | 114 | 105 | 4 | 19 | 3 | 1.2 | 7.8 | .0026 | -27 ▼ |
| ibm | 68 | 192 | 58 | 68 | 66 | 0 | 6 | 0 | 0.0 | 7.5 | .0034 | +36 ▲ |
| progress | 33 | 42 | 6 | 29 | 7 | 0 | 6 | 0 | 0.0 | 8.0 | .0038 | +28 ▲ |
| solarwinds | 15 | 22 | 16 | 3 | 3 | 0 | 10 | 4 | 18.2 | 9.1 | .0058 | +12 ▲ |
| zohocorp | 3 | 6 | 2 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0146 | +2 ▲ |
| veeam | 1 | 5 | 2 | 3 | 0 | 0 | 1 | 0 | 0.0 | 8.6 | .0051 | 0 |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | +10 ▲ |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| d-link | 8 | 20 | 0 | 5 | 9 | 6 | 3 | 0 | 0.0 | 5.5 | .0105 | -1 ▼ |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| abb | 1 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -5 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -6 ▼ |
| hikvision | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0038 | +5 ▲ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -5 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 49 | 120 | 0 | 0 | 62 | 58 | 0 | 0 | 0.0 | 5.5 | .0034 | +8 ▲ |
| openclaw | 44 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -17 ▼ |
| dell | 43 | 99 | 5 | 47 | 44 | 3 | 2 | 1 | 1.0 | 7.1 | .0021 | +5 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | -24 ▼ |
| nvidia | 43 | 82 | 12 | 54 | 16 | 0 | 0 | 0 | 0.0 | 7.8 | .0037 | +37 ▲ |
| imagemagick | 33 | 74 | 1 | 5 | 56 | 12 | 0 | 0 | 0.0 | 5.3 | .0018 | -2 ▼ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -72 ▼ |
| itsourcecode | 18 | 71 | 0 | 0 | 19 | 52 | 0 | 0 | 0.0 | 2.1 | .0033 | -7 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-63030 | .9779 | 99.9 | 9.8 |
| CVE-2026-16232 | .8912 | 99.8 | 9.3 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-60137 | .7979 | 99.6 | 5.9 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-0770 | .6342 | 99.1 | 9.8 |
| CVE-2026-48282 | .4239 | 98.6 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 | |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-13773 | 10.0 | .0610 | |
| CVE-2026-6516 | 10.0 | .0486 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 830 |
| microsoft | 665 |
| 503 | |
| apple | 204 |
| red hat | 149 |
| apache | 141 |
| adobe | 115 |
| ibm | 111 |
| mozilla | 72 |
| Vendor | KEV |
|---|---|
| microsoft | 24 |
| cisco | 11 |
| apple | 7 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 70 |
| PyPI | 5 |
| NuGet | 4 |
| npm | 4 |
| Go | 3 |
| Packagist | 2 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE-2026-46817 | Oracle Corporation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1714 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1714 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1714 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1714 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1714 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1714 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1714 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1714 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1714 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1714 |
EXPLOIT PUBLISHED — dompdf: 6 CVEs (CVE-2026-55554, CVE-2026-55555, CVE-2026-56722, CVE-2026-59941, CVE-2026-59942, CVE-2026-59943). Public exploit references added.
EXPLOIT PUBLISHED — Creativeitem Ekushey Project Manager CRM: 4 CVEs (CVE-2026-66028, CVE-2026-66029, CVE-2026-66030, CVE-2026-66031). Public exploit references added.
EXPLOIT PUBLISHED — cure53 DOMPurify: 4 CVEs (CVE-2026-65899, CVE-2026-65902, CVE-2026-65904, CVE-2026-65911). Public exploit references added.
EXPLOIT PUBLISHED — koxudaxi datamodel-code-generator: 4 CVEs (CVE-2026-54656, CVE-2026-54690, CVE-2026-55389, CVE-2026-55415). Public exploit references added.
EXPLOIT PUBLISHED — nuxsmin sysPass: 4 CVEs (CVE-2026-65708, CVE-2026-65709, CVE-2026-65710, CVE-2026-65711). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-17531 (unitedbyai droidclaw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-31431 (Linux Kernel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39875 (Apple macOS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4258 (sjcl). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43760 (Apple macOS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43910 (appium java-client). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45711 (axllent mailpit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47427 (github-mcp-server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49477 (facelessuser soupsieve). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53359 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54332 (gopacket). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54345 (gopacket). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-61511 (vBulletin). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64620 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64621 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65917 (usmannasir cyberpanel). Public exploit reference added.
RESCORED — Microsoft Exchange Server 2016 Cumulative Update 23: 4 CVEs (CVE-2026-45501, CVE-2026-45503, CVE-2026-45583, CVE-2026-47631). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2024-21538 (cross-spawn). CVSS 8.7 → 7.7 (NVD).
RESCORED — CVE-2025-68686 (Fortinet FortiOS). CVSS 5.3 → 5.9 (NVD).
RESCORED — CVE-2026-15631 (@fastify/http-proxy). CVSS 8.7 → 10 (NVD).
RESCORED — CVE-2026-4258 (sjcl). CVSS 8.7 → 7.7 (NVD).
ENRICHED — CVE-2026-31431 (Linux Kernel). Received CVSS 7.8 and CPE data from NVD.
How to read these box scores · glossary
243 CVEs published. 25 box scores, 218 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0137 69.7 —
AFFECTED Product Versions Fixed WRC-X3000GS3-B unspecified — WRC-X3000GS3A-B unspecified —
TIMELINE Jul 13 Reserved by CNA Jul 28 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0137 69.7 —
AFFECTED Product Versions Fixed WAB-M1775-PS unspecified — WAB-S1775 unspecified — WAB-M2133 unspecified — WAB-I1750-PS unspecified — WAB-S1167-PS unspecified —
TIMELINE Jul 13 Reserved by CNA Jul 28 Published (CNA: jpcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0104 61.3 —
AFFECTED Product Versions Fixed Aspera Faspex 5 5.0.0 – —
TIMELINE Jul 7 Reserved by CNA Jul 28 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0103 61.2 —
AFFECTED Product Versions Fixed Apache Axis2/Java unspecified —
TIMELINE Jul 27 Reserved by CNA Jul 28 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0083 54.9 —
AFFECTED Product Versions Fixed camaleon-cms 2.1.1 – —
TIMELINE Jul 27 Reserved by CNA Jul 28 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0078 53.3 —
AFFECTED Product Versions Fixed zip-lib unspecified —
TIMELINE Jul 27 Reserved by CNA Jul 28 Published (CNA: snyk)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N L 6.3 .0075 52.1 —
AFFECTED Product Versions Fixed dompdf < 3.1.6 – —
TIMELINE Jul 7 Reserved by CNA Jul 28 Public exploit reference published Jul 28 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0071 50.8 —
AFFECTED Product Versions Fixed Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0057 44.8 —
AFFECTED Product Versions Fixed WebSphere Application Server 9.0 – —
TIMELINE Jul 2 Reserved by CNA Jul 28 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0052 41.8 —
AFFECTED Product Versions Fixed Aspera Faspex 5 5.0.0 – —
TIMELINE Jul 7 Reserved by CNA Jul 28 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0051 41.3 —
AFFECTED Product Versions Fixed gopacket < 1.6.1 – —
TIMELINE Jun 12 Reserved by CNA Jul 28 Public exploit reference published Jul 28 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N L 6.3 .0051 41.3 —
AFFECTED Product Versions Fixed dompdf < 3.1.6 – —
TIMELINE Jul 7 Reserved by CNA Jul 28 Public exploit reference published Jul 28 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0051 41.1 —
AFFECTED Product Versions Fixed Demi – One Click Demo Import, Backup & Site Migration unspecified —
TIMELINE Jul 2 Reserved by CNA Jul 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0050 40.5 —
AFFECTED Product Versions Fixed Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin unspecified —
TIMELINE Jul 8 Reserved by CNA Jul 28 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0050 40.2 —
AFFECTED Product Versions Fixed gopacket < 1.6.1 – —
TIMELINE Jun 12 Reserved by CNA Jul 28 Public exploit reference published Jul 28 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L N 7.8 .0049 40.1 —
AFFECTED Product Versions Fixed misp unspecified —
TIMELINE Jul 28 Reserved by CNA Jul 28 Published (CNA: CIRCL)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H L 9.4 .0049 39.8 —
AFFECTED Product Versions Fixed InspectorP61x unspecified — InspectorP62x unspecified — InspectorP65x all versions – — InspectorP63x all versions – — InspectorP64x all versions – — ICR890-4 unspecified —
TIMELINE Jun 10 Reserved by CNA Jul 28 Published (CNA: SICK AG)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0049 39.8 —
AFFECTED Product Versions Fixed Apache ActiveMQ AMQP unspecified — Apache ActiveMQ unspecified — Apache ActiveMQ All unspecified —
TIMELINE Jul 7 Reserved by CNA Jul 28 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0048 39.0 —
AFFECTED Product Versions Fixed PROCON-WEB SCADA 1.0.0 – —
TIMELINE Jul 21 Reserved by CNA Jul 28 Published (CNA: CERTVDE)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0046 38.2 —
AFFECTED Product Versions Fixed hypequery < 2.5.1 – —
TIMELINE Jun 15 Reserved by CNA Jul 28 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0046 37.8 —
AFFECTED Product Versions Fixed SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery unspecified —
TIMELINE Jul 7 Reserved by CNA Jul 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0046 37.8 —
AFFECTED Product Versions Fixed Xen unspecified —
TIMELINE Apr 27 Reserved by CNA Jul 28 Published (CNA: XEN)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0046 37.6 —
AFFECTED Product Versions Fixed Balbooa Forms component for Joomla 1.0.0-2.4.2.1 – —
TIMELINE Jul 23 Reserved by CNA Jul 28 Published (CNA: Joomla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H L 10.0 .0046 37.5 —
AFFECTED Product Versions Fixed Tooling 0.3.0 – —
TIMELINE Jul 21 Reserved by CNA Jul 28 Published (CNA: HashiCorp)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0045 37.5 —
AFFECTED Product Versions Fixed TrueBooker – Appointment Booking and Scheduler System unspecified —
TIMELINE Jun 24 Reserved by CNA Jul 28 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-67185 | 8.7 | 37.4 | GeneralSandman | TinyWeb | CWE-22 | TinyWeb 0.0.8 Path Traversal via URL Path Component |
| CVE-2026-11756 | 10.0 | 37.3 | Dassault Systèmes | Station Launcher App in 3DEXPERIENCE platform | CWE-502 | Deserialization of Untrusted Data vulnerability affecting Station Launcher Ap… |
| CVE-2026-66299 | 7.5 | 37.3 | Apache Software Foundation | Apache Tomcat | CWE-400 | Apache Tomcat: DoS via WebSocket chat example |
| CVE-2026-42493 | 7.5 | 37.2 | Xen | Xen | CWE-400 | x86 shadow paging is deprecated |
| CVE-2026-54653 | 8.8 | 37.0 | koxudaxi | datamodel-code-generator | CWE-94 | `datamodel-code-generator` vulnerable to code injection in via attacker-contr… |
| CVE-2026-47427 | 7.5 | 36.6 | github | github-mcp-server | CWE-476 | GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler |
| CVE-2026-67184 | 8.7 | 35.7 | GeneralSandman | TinyWeb | CWE-476 | TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request |
| CVE-2026-55389 | 7.5 | 35.6 | koxudaxi | datamodel-code-generator | CWE-22 | datamodel-code-generator vulnerable to arbitrary local file read via JSON-Sch… |
| CVE-2026-54635 | 7.5 | 34.8 | nessshon | tonapi | CWE-287 | pytonapi has a Webhook Custom Path Authentication Bypass |
| CVE-2026-67182 | 6.9 | 34.3 | tomaka | rouille | CWE-444 | Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection |
| CVE-2026-55415 | 7.5 | 34.1 | koxudaxi | datamodel-code-generator | CWE-94 | datamodel-code-generator vulnerable to code injection via `x-python-import` /… |
| CVE-2026-66754 | 8.2 | 33.0 | tomaka | rouille | CWE-617 | Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding |
| CVE-2026-21047 | 8.3 | 32.5 | Samsung Mobile | Samsung Mobile Devices | CWE-787 | Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remo… |
| CVE-2026-61609 | 7.5 | 32.2 | pterodactyl | panel | CWE-770 | Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enable… |
| CVE-2026-63303 | 5.1 | 31.9 | OpenSolution | Quick.CMS | CWE-23 | Path Traversal in Quick.CMS |
| CVE-2026-67174 | 9.2 | 31.3 | pivotick | pivotick | CWE-79 | DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pi… |
| CVE-2026-65624 | 6.9 | 31.1 | ninenines | cowboy | CWE-770 | Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory … |
| CVE-2026-59932 | 7.5 | 30.7 | PHPOffice | PhpSpreadsheet | CWE-400 | PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaus… |
| CVE-2026-59933 | 7.5 | 30.7 | PHPOffice | PhpSpreadsheet | CWE-400 | PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion |
| CVE-2026-14974 | 9.8 | 30.6 | IBM | WebSphere Application Server | CWE-502 | IBM WebSphere Application Server is affected by cross-site scripting and dese… |
| CVE-2026-14869 | 8.6 | 30.7 | HashiCorp | Tooling | CWE-918 | terraform-mcp-server vulnerable to server side request forgery leading to tok… |
| CVE-2026-62434 | 5.3 | 30.4 | Xen | Xen | CWE-787 | PoD: Don't try to reclaim special pages |
| CVE-2026-61487 | 6.5 | 30.4 | Apache Software Foundation | Apache ActiveMQ Broker | CWE-285 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization b… |
| CVE-2026-59931 | 7.7 | 30.0 | PHPOffice | PhpSpreadsheet | CWE-918 | PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist |
| CVE-2026-16496 | 8.9 | 29.6 | HashiCorp | Tooling | CWE-384 | terraform-mcp-server vulnerable to cross-user credential inheritance if an MC… |
| CVE-2026-6879 | 2.0 | 29.5 | Python Software Foundation | CPython | CWE-407 | Quadratic Behavior in xml.etree.ElementPath Index Predicates |
| CVE-2026-54659 | 6.9 | 29.5 | ddnexus | pagy | CWE-22 | Pagy I18n locale option is not validated before being used in a file path |
| CVE-2026-67183 | 8.7 | 29.4 | GeneralSandman | TinyWeb | CWE-401 | TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling |
| CVE-2026-14328 | 8.8 | 29.1 | eazyplugins | Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress | CWE-269 | Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalati… |
| CVE-2026-54603 | 8.6 | 28.8 | ruby-oauth | oauth2 | CWE-200 | OAuth2::Client#request: Protocol-relative redirect Location overrides authori… |
| CVE-2026-54650 | 8.6 | 28.8 | bablilayoub | openhole | CWE-22 | openhole-server vulnerable to path traversal via URL-decoded request path |
| CVE-2026-55390 | 7.5 | 28.8 | koxudaxi | datamodel-code-generator | CWE-22 | Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`)… |
| CVE-2026-62431 | 7.5 | 28.7 | Xen | Xen | CWE-369 | Viridian STIMER division by zero |
| CVE-2026-63301 | 7.0 | 28.7 | OpenSolution | Quick.CMS | CWE-602 | Denial of Service in Quick.CMS |
| CVE-2026-54593 | 8.1 | 28.4 | pterodactyl | panel | CWE-1259 | Pterodactyl's improper JWT scoping allows subuser to upload files when not ex… |
| CVE-2026-64863 | 9.1 | 28.2 | goshs-labs | goshs | CWE-284 | goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite |
| CVE-2026-55555 | 2.3 | 28.0 | dompdf | dompdf | CWE-203 | Dompdf: File existence oracle via font-face stylesheet declaration |
| CVE-2026-16771 | 8.8 | 27.9 | AT&T | Arris BGW210‑700 | CWE-306 | CVE-2026-16771 |
| CVE-2026-54638 | 7.5 | 27.1 | gotd | td | CWE-770 | td has pre-auth denial of service via unbounded memory allocation in proto.Un… |
| CVE-2026-62325 | 9.1 | 26.9 | goshs-labs | goshs | CWE-306 | goshs SFTP authentication bypass via empty password (incomplete fix of CVE-20… |
| CVE-2026-67173 | 5.1 | 26.6 | pivotick | pivotick | CWE-918 | Pivotick Unvalidated Node Image URLs Allow Unintended Client-Side Requests |
| CVE-2026-57510 | 8.7 | 26.3 | superplanehq | superplane | CWE-639 | SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC |
| CVE-2026-15280 | 7.5 | 26.0 | IBM | WebSphere Application Server - Liberty | CWE-22 | IBM WebSphere Application Server Liberty is affected by a remote code executi… |
| CVE-2026-15012 | 5.3 | 26.0 | deveasel | Demi – One Click Demo Import, Backup & Site Migration | CWE-200 | Demi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory Copy |
| CVE-2026-14446 | 9.8 | 25.6 | IBM | WebSphere Application Server | CWE-306 | IBM WebSphere Application Server is affected by a privilege escalation |
| CVE-2026-5114 | 4.9 | 25.3 | softaculous | SpeedyCache – Cache, Optimization, Performance | CWE-22 | SpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File Read |
| CVE-2026-56722 | 6.3 | 25.2 | dompdf | dompdf | CWE-20 | Dompdf: Local file read due to improper file path validation in SVG images en… |
| CVE-2026-55554 | 2.3 | 24.9 | dompdf | dompdf | CWE-20 | Dompdf: Chroot Validation Bypass |
| CVE-2026-15673 | 4.4 | 24.0 | cozyvision1 | SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | CWE-89 | SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checko… |
| CVE-2026-16184 | 9.8 | 23.8 | IBM | WebSphere Application Server | CWE-862 | IBM WebSphere Application Server is affected by an authentication bypass |
| CVE-2026-66745 | 7.5 | 23.8 | ArticaTech | Artica Proxy | CWE-94 | Artica Proxy 4.50 Session Fixation via fw.login.php |
| CVE-2026-66749 | 7.1 | 23.3 | sdelements | lets-chat | CWE-476 | Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup |
| CVE-2026-66064 | 5.3 | 22.9 | goshs-labs | goshs | CWE-41 | goshs has ACL Bypass & Path Traversal |
| CVE-2026-47483 | 8.2 | 22.7 | NVIDIA | DCGM | CWE-770 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug… |
| CVE-2026-63302 | 5.1 | 22.7 | OpenSolution | Quick.CMS | CWE-98 | Local File Inclusion in Quick.CMS |
| CVE-2026-14976 | 9.8 | 22.5 | IBM | WebSphere Application Server - Liberty | CWE-306 | IBM WebSphere Application Server Liberty is affected by a remote code executi… |
| CVE-2026-14973 | 9.3 | 22.4 | IBM | Aspera Desktop App | CWE-22 | Path Traversal in IBM Desktop App |
| CVE-2026-10207 | 7.5 | 22.5 | pickplugins | PickPlugins Question Answer | CWE-89 | PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id… |
| CVE-2026-12741 | 7.5 | 22.5 | epsiloncool | WP Fast Total Search – The Power of Indexed Search | CWE-89 | WP Fast Total Search <= 1.80.280 - Unauthenticated SQL Injection |
| CVE-2026-12800 | 7.5 | 22.5 | codename065 | Premium Packages – Sell Digital Products Securely | CWE-89 | Premium Packages <= 6.2.0 - Unauthenticated SQL Injection |
| CVE-2026-14785 | 7.5 | 22.5 | mihail-chepovskiy | Web Directory Free | CWE-89 | Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection |
| CVE-2026-43910 | 8.2 | 22.2 | appium | java-client | CWE-441 | Appium java-client Allows Network Pivot via Unvalidated directConnect Redirec… |
| CVE-2026-50738 | 7.7 | 22.1 | EnterpriseDB | pglogical | CWE-416 | A use-after-free condition exists in pglogical's worker signaling code, where… |
| CVE-2026-59943 | 6.3 | 21.9 | dompdf | dompdf | CWE-209 | Dompdf: Embedded SVG images can leak existence of files and directories withi… |
| CVE-2026-14528 | 7.5 | 21.5 | IBM | WebSphere Application Server | CWE-532 | IBM WebSphere Application Server is affected by an unsafe deserialization and… |
| CVE-2026-14545 | 9.8 | 21.2 | Unknown | TrueBooker | CWE-269 | TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via… |
| CVE-2026-59248 | 8.7 | 21.1 | ninenines | cowlib | CWE-770 | Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhau… |
| CVE-2026-48025 | 6.9 | 21.1 | juev | nebula-mesh | CWE-244 | nebula-mesh: Decrypted CA private key persists in heap after signing |
| CVE-2026-67181 | 6.3 | 21.1 | tomaka | rouille | CWE-444 | Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header |
| CVE-2026-49332 | 8.5 | 20.9 | Red Hat | Red Hat OpenShift Container Platform 4.12 | CWE-436 | Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling ena… |
| CVE-2026-14516 | 7.5 | 20.9 | ladela | Online Scheduling and Appointment Booking System – Bookly | CWE-89 | Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQ… |
| CVE-2026-1918 | 4.9 | 20.9 | IBM | Sterling B2B Integrator | CWE-532 | IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive inf… |
| CVE-2026-14169 | 8.1 | 20.7 | ads-tec Industrial IT | DVG-IRF1401 | CWE-696 | ads-tec Industrial IT: Account lockout via non-atomic user creation |
| CVE-2026-48060 | 8.1 | 20.4 | litestar-org | litestar | CWE-79 | Litestar: HTML Injection Through CSRF Token |
| CVE-2026-66922 | 5.1 | 20.3 | pivotick | pivotick | CWE-1321 | Pivotick Prototype-Key Collision in Tree Layout and Cycle Detection Allows Gr… |
| CVE-2026-49258 | 8.8 | 20.2 | juev | nebula-mesh | CWE-639 | Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to… |
| CVE-2026-54719 | 7.5 | 20.3 | goshs-labs | goshs | CWE-862 | goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download … |
| CVE-2026-7521 | 5.5 | 20.3 | Mattermost | Mattermost | CWE-22 | SAML certificate deletion allows path traversal to delete arbitrary files out… |
| CVE-2026-18047 | 6.5 | 20.1 | Red Hat | Red Hat Certificate System 10 | CWE-288 | Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint aut… |
| CVE-2026-15444 | 4.9 | 19.9 | themeum | Tutor LMS – eLearning and online course solution | CWE-89 | Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon… |
| CVE-2026-15671 | 4.9 | 19.9 | cozyvision1 | SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | CWE-89 | SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Pa… |
| CVE-2026-14168 | 8.8 | 19.5 | ads-tec Industrial IT | DVG-IRF1401 | CWE-862 | ads-tec Industrial IT: Vertical privilege escalation via configuration table … |
| CVE-2026-14167 | 8.7 | 19.5 | ads-tec Industrial IT | DVG-IRF1401 | CWE-863 | ads-tec Industrial IT: Privilege escalation during configuration import |
| CVE-2026-66918 | 8.2 | 19.6 | pivotick | pivotick | CWE-79 | DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons |
| CVE-2026-66921 | 6.3 | 19.6 | pivotick | pivotick | CWE-79 | Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node … |
| CVE-2026-7769 | 8.1 | 19.4 | IBM | Sterling B2B Integrator | CWE-89 | SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM S… |
| CVE-2024-14041 | 8.2 | 19.3 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-208 | ML-KEM (Kyber) decapsulation leaks private key information through non-consta… |
| CVE-2026-16773 | 5.3 | 19.2 | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | CWE-200 | WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_sen… |
| CVE-2026-15992 | 8.8 | 18.1 | teydeastudio | WP Password Policy | CWE-269 | WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation |
| CVE-2026-16347 | 8.7 | 18.0 | MikroTik | RouterOS | CWE-307 | Improper restriction of excessive authentication attempts in MikroTik RouterO… |
| CVE-2026-13440 | 7.2 | 17.9 | wedevs | StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce | CWE-79 | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Chec… |
| CVE-2026-54609 | 8.6 | 17.6 | Quiet-Terminal-Interactive | QTINeon | CWE-400 | QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNE… |
| CVE-2026-14981 | 7.5 | 17.7 | IBM | WebSphere Application Server | CWE-400 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-15057 | 7.5 | 17.7 | IBM | WebSphere Application Server - Liberty | CWE-787 | IBM WebSphere Application Server Liberty is affected by a denial of service v… |
| CVE-2026-47219 | 7.5 | 17.7 | delvedor | find-my-way | CWE-20 | find-my-way is Vulnerable to DDoS with HTTP2 |
| CVE-2026-16192 | 6.5 | 17.7 | IBM | WebSphere Application Server - Liberty | CWE-674 | IBM WebSphere Application Server Liberty is affected by a denial of service |
| CVE-2026-66750 | 5.3 | 17.8 | sdelements | lets-chat | CWE-862 | Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files… |
| CVE-2026-66919 | 6.9 | 17.6 | Pivotick | Pivotick | CWE-79 | Stored DOM-Based Cross-Site Scripting in Node Modal Headers |
| CVE-2026-63727 | 8.7 | 17.3 | Anchore | Anchore Enterprise | CWE-648 | Anchore Enterprise Privilege Escalation via User Management API |
| CVE-2026-15411 | 5.3 | 17.4 | wedevs | StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce | CWE-862 | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Chec… |
| CVE-2026-15670 | 4.9 | 17.2 | cozyvision1 | SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | CWE-89 | SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderb… |
| CVE-2026-16811 | 4.9 | 17.2 | devitemsllc | ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin | CWE-89 | ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'order… |
| CVE-2026-54690 | 8.2 | 16.8 | koxudaxi | datamodel-code-generator | CWE-918 | datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP UR… |
| CVE-2026-15267 | 6.5 | 16.5 | taskbuilder | Taskbuilder – Project Management & Task Management Tool With Kanban Board | CWE-89 | Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection |
| CVE-2026-66920 | 8.2 | 16.4 | Pivotick | Pivotick | CWE-400 | Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data |
| CVE-2026-14924 | 7.5 | 16.5 | Unknown | Tablesome Table | CWE-862 | Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification |
| CVE-2026-62433 | 7.3 | 16.4 | Xen | Xen | CWE-665 | correct buffer checks for DM_OP hypercalls |
| CVE-2026-66913 | 6.9 | 16.4 | lookyloo | lookyloo | CWE-400 | Zip Bomb in Lookyloo Capture Upload Allows Denial of Service |
| CVE-2026-59921 | 6.5 | 15.7 | netty | netty | CWE-93 | Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder |
| CVE-2026-65881 | 7.5 | 15.5 | joomdle.com | Joomdle component for Joomla | CWE-1188 | Joomla Extension - joomdle.com - Insecure default configuration allows read/w… |
| CVE-2026-62432 | 7.3 | 15.4 | Xen | Xen | CWE-362 | evtchn: Race between FIFO expand and reset |
| CVE-2026-62430 | 7.5 | 15.2 | Xen | Xen | CWE-362 | x86: Out-of-bounds read in vRTC emulation |
| CVE-2026-15393 | 6.4 | 15.2 | cozythemes | Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates | CWE-79 | Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Script… |
| CVE-2026-6251 | 6.5 | 15.0 | Chaty | Chaty Pro | CWE-89 | Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id… |
| CVE-2026-15304 | 6.5 | 15.0 | foomagoo | Plugin Organizer | CWE-89 | Plugin Organizer <= 10.2.4 - Authenticated (Subscriber+) SQL Injection |
| CVE-2026-66746 | 5.3 | 15.0 | tomaka | rouille | CWE-113 | Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection |
| CVE-2026-62427 | 8.8 | 14.8 | Xen | Xen | CWE-284 | sysctl and platform-op locks open to abuse |
| CVE-2026-9680 | 5.8 | 14.9 | Alibaba | Alibaba Cloud RDS OpenAPI MCP Server | CWE-1188 | MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-… |
| CVE-2026-4912 | 4.1 | 14.9 | tigroumeow | Media Cleaner: Clean your WordPress! | CWE-918 | Media Cleaner: Clean your WordPress! <= 7.0.3 - Authenticated (Administrator+… |
| CVE-2026-16313 | 7.6 | 14.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-93 | Sg3_utils: sg3_utils: arbitrary command execution via udev property injection… |
| CVE-2026-47726 | 7.1 | 14.6 | juev | nebula-mesh | CWE-285 | nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator |
| CVE-2026-66752 | 6.3 | 14.5 | tiny-http | tiny-http | CWE-444 | tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling |
| CVE-2026-55391 | 7.5 | 14.4 | koxudaxi | datamodel-code-generator | CWE-350 | datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding |
| CVE-2026-57511 | 6.3 | 14.3 | superplanehq | superplane | CWE-93 | SuperPlane < 0.30.0 SMTP Header Injection via Webhook Event Title |
| CVE-2026-62828 | 5.4 | 14.2 | Microsoft | Microsoft Edge for Android | CWE-20 | Microsoft Edge for Android (Chromium-based) Tampering Vulnerability |
| CVE-2026-13110 | 5.3 | 14.2 | wedevs | StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce | CWE-862 | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Chec… |
| CVE-2026-16774 | 5.3 | 14.2 | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | CWE-862 | WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpc… |
| CVE-2026-66063 | 6.5 | 13.9 | goshs-labs | goshs | CWE-22 | goshs has a Path Traversal issue |
| CVE-2026-48396 | 8.6 | 13.8 | Adobe | Adobe Bridge | CWE-863 | Bridge | Incorrect Authorization (CWE-863) |
| CVE-2026-48374 | 7.8 | 13.8 | Adobe | Adobe Bridge | CWE-22 | Bridge | Improper Limitation of a Pathname to a Restricted Directory ('Path T… |
| CVE-2026-15328 | 8.1 | 13.6 | IBM | WebSphere Application Server | CWE-444 | IBM WebSphere Application Server and WebSphere Application Server Liberty is … |
| CVE-2026-16797 | 4.3 | 13.6 | devitemsllc | ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin | CWE-639 | ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Cont… |
| CVE-2026-48395 | 8.6 | 13.4 | Adobe | Adobe Bridge | CWE-426 | Bridge | Untrusted Search Path (CWE-426) |
| CVE-2026-14171 | 6.1 | 13.2 | ads-tec Industrial IT | DVG-IRF1401 | CWE-601 | ads-tec Industrial IT: Post-login open redirect in the web interface |
| CVE-2026-14996 | 8.2 | 12.9 | IBM | Aspera Faspex 5 | CWE-613 | Multiple vulnerabilities in IBM Aspera Faspex |
| CVE-2026-16581 | 6.9 | 13.0 | igloohome | Smart Lock Mobile Application | CWE-540 | Inclusion of sensitive information in source code in igloohome Smart Lock Mob… |
| CVE-2026-54656 | 7.8 | 12.8 | koxudaxi | datamodel-code-generator | CWE-94 | `datamodel-code-generator` vulnerable to code execution on import via unescap… |
| CVE-2026-13463 | 7.5 | 12.9 | IBM | Cloud Pak System | CWE-798 | Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulner… |
| CVE-2026-62429 | 6.5 | 12.8 | Xen | Xen | CWE-362 | vNUMA domain cleanup may race other operations |
| CVE-2026-49447 | 5.3 | 12.8 | azukaar | Cosmos-Server | CWE-287 | Cosmos-Server's constellation public-devices endpoint accepts arbitrary beare… |
| CVE-2026-18038 | 2.1 | 12.5 | nextlevelbuilder | GoClaw | CWE-200 | nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute informati… |
| CVE-2026-62426 | 8.8 | 12.3 | Xen | Xen | CWE-412 | sysctl and platform-op locks open to abuse |
| CVE-2026-15064 | 8.7 | 12.3 | IBM | WebSphere Application Server | CWE-444 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-3157 | 4.3 | 12.2 | IBM | Sterling B2B Integrator | CWE-615 | Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File G… |
| CVE-2026-66753 | 6.3 | 12.1 | tiny-http | tiny-http | CWE-113 | tiny-http 0.12.0 HTTP Response Splitting via Header Injection |
| CVE-2026-17528 | 5.3 | 12.0 | n/a | nice-select2 | CWE-79 | Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-sit… |
| CVE-2026-7187 | 8.8 | 11.8 | Universal Software Inc. | UKBS | CWE-306 | Improper Authentication in Universal Sotware's UKBS |
| CVE-2026-16587 | 4.3 | 11.8 | nasirahmed | Advanced Form Integration — Connect Forms to 200+ Apps | CWE-862 | Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (… |
| CVE-2026-66751 | 5.3 | 11.5 | sdelements | lets-chat | CWE-862 | Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room |
| CVE-2026-55403 | 3.7 | 11.3 | koxudaxi | datamodel-code-generator | CWE-200 | datamodel-code-generator: Authorization / request headers leaked to cross-ori… |
| CVE-2026-54691 | 8.2 | 11.0 | koxudaxi | datamodel-code-generator | CWE-918 | datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation,… |
| CVE-2026-15730 | 6.4 | 11.0 | rubengc | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | CWE-79 | GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripti… |
| CVE-2026-12124 | 5.3 | 11.0 | wpeverest | PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer | CWE-862 | PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Di… |
| CVE-2026-15325 | 8.7 | 10.8 | IBM | WebSphere Application Server | CWE-444 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-48391 | 8.2 | 10.6 | Adobe | Adobe Bridge | CWE-426 | Bridge | Untrusted Search Path (CWE-426) |
| CVE-2026-18029 | 6.3 | 10.7 | pretix GmbH | pretix-girosolution | CWE-841 | Insufficient validation of payment status in pretix-girosolution |
| CVE-2026-8058 | 4.5 | 10.7 | IBM | OPENBMC | CWE-200 | This Power System update is being released to address a sensitive information… |
| CVE-2026-18028 | 2.3 | 10.7 | pretix GmbH | pretix | CWE-639 | Missing authorization check in event quick setup view |
| CVE-2026-11598 | 5.0 | 10.3 | lrnz | Shortcodify | CWE-79 | Shortcodify <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripti… |
| CVE-2026-6881 | 9.4 | 10.2 | Ellucian | Advance Web | CWE-89 | Authenticated SQL Injection Enables Unauthorized Access to Sensitive Informat… |
| CVE-2026-48372 | 7.8 | 10.1 | Adobe | Format Plugins | CWE-787 | Format Plugins | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-14893 | 7.3 | 10.0 | IBM | Observability with Instana (Agent) | CWE-1321 | IBM Instana Observability is affected by multiple Prototype Pollution within … |
| CVE-2026-42495 | 5.5 | 9.5 | Xen | Xen | CWE-191 | buffer overruns in libfsimage iso9660 handling |
| CVE-2026-62423 | 5.5 | 9.5 | Xen | Xen | CWE-130 | buffer overruns in libfsimage iso9660 handling |
| CVE-2026-62424 | 5.5 | 9.5 | Xen | Xen | CWE-130 | buffer overruns in libfsimage iso9660 handling |
| CVE-2026-62425 | 5.5 | 9.5 | Xen | Xen | CWE-20 | buffer overruns in libfsimage iso9660 handling |
| CVE-2026-48392 | 7.8 | 9.5 | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-48393 | 7.8 | 9.5 | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-48394 | 7.8 | 9.5 | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-50736 | 9.0 | 9.1 | EnterpriseDB | pglogical | CWE-89 | The pglogical queue mechanism, used to convey out-of-band commands such as re… |
| CVE-2026-50737 | 9.0 | 9.1 | EnterpriseDB | pglogical | CWE-250 | When applying replicated changes for a row that is missing one or more column… |
| CVE-2026-50735 | 6.1 | 9.1 | EnterpriseDB | pglogical | CWE-125 | pglogical's apply worker does not sufficiently validate the length of certain… |
| CVE-2026-48058 | 4.6 | 9.0 | juev | nebula-mesh | CWE-614 | nebula-mesh: Session and OIDC state cookies lack the Secure attribute |
| CVE-2026-48390 | 8.2 | 8.8 | Adobe | Adobe Bridge | CWE-863 | Bridge | Incorrect Authorization (CWE-863) |
| CVE-2026-62435 | 6.5 | 8.4 | Xen | Xen | CWE-362 | grant-table: version change racing with other operations |
| CVE-2026-62436 | 6.5 | 8.4 | Xen | Xen | CWE-362 | grant-table: version change racing with other operations |
| CVE-2026-11391 | 6.3 | 8.2 | Tanium | Patch | CWE-89 | Tanium addressed a SQL injection vulnerability in Patch. |
| CVE-2026-45293 | 8.6 | 8.0 | WordPress | WordPress-Coding-Standards | CWE-95 | WordPress Coding Standards (WordPressCS) contains an arbitrary code execution… |
| CVE-2026-44387 | 5.1 | 7.9 | ELECOM CO.,LTD. | WAB-M1775-PS | CWE-79 | ELECOM wireless LAN routers and access points devices contain a reflected cro… |
| CVE-2026-3158 | 4.3 | 7.6 | IBM | Sterling B2B Integrator | CWE-615 | Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File G… |
| CVE-2026-15016 | 6.4 | 7.4 | strangerstudios | Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions | CWE-79 | Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscri… |
| CVE-2026-7362 | 6.5 | 7.3 | IBM | Sterling B2B Integrator | CWE-284 | Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator… |
| CVE-2026-14515 | 6.1 | 7.3 | IBM | WebSphere Application Server | CWE-79 | IBM WebSphere Application Server is affected by cross-site scripting and dese… |
| CVE-2026-13442 | 7.1 | 6.9 | IBM | Langflow OSS | CWE-520 | Langflow is affected by NET Misconfiguration: Use of Impersonation due to mul… |
| CVE-2026-7868 | 6.5 | 6.9 | IBM | OPENBMC | CWE-863 | This Power System update is being released to address incorrect authorization |
| CVE-2026-48388 | 8.6 | 6.7 | Adobe | Adobe Photoshop Installer | CWE-427 | Photoshop Installer | CWE-427: Uncontrolled Search Path Element |
| CVE-2026-14821 | 2.7 | 6.3 | Unknown | Quiz and Survey Master (QSM) | CWE-862 | Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion |
| CVE-2026-56821 | 7.4 | 5.8 | netty | netty | CWE-299 | Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator |
| CVE-2026-16107 | 5.9 | 5.2 | IBM | TS4500 CLI tool | CWE-295 | TS4500 CLI tool addresses security vulnerability |
| CVE-2026-18085 | 5.9 | 5.0 | BlackBerry | UEM | CWE-74 | Improper Input Validation Leads to Arbitrary File Download and Potential Deni… |
| CVE-2026-47725 | 6.9 | 4.8 | juev | nebula-mesh | CWE-352 | nebula-mesh: Web UI lacks CSRF tokens on /ui/* mutating endpoints |
| CVE-2026-58246 | 4.3 | 4.4 | SAP_SE | SAP NetWeaver Application Server for ABAP | CWE-497 | Information Disclosure vulnerability in SAP NetWeaver Application Server for … |
| CVE-2026-18084 | 8.6 | 4.3 | BlackBerry | UEM | CWE-79 | Cross-Site Scripting (XSS) in Management Console of BlackBerry UEM |
| CVE-2026-54545 | 7.1 | 4.3 | pionxzh | wakaru | CWE-22 | @wakaru/cli arbitrary file write during bundle unpack |
| CVE-2026-8167 | 6.1 | 4.3 | THEWP Digital Solutions | News Theme V8 | CWE-79 | Reflected XSS in theWP's News Theme V8 |
| CVE-2026-65882 | 6.1 | 4.3 | joomdle.com | Joomdle component for Joomla | CWE-79 | Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 |
| CVE-2026-54655 | 7.8 | 4.0 | koxudaxi | datamodel-code-generator | CWE-94 | `datamodel-code-generator` vulnerable to code execution on import via `x-pyth… |
| CVE-2026-14926 | 4.2 | 3.9 | Unknown | FluentCart A New Era of eCommerce | CWE-284 | FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR |
| CVE-2026-54621 | 7.8 | 3.7 | koxudaxi | datamodel-code-generator | CWE-94 | `datamodel-code-generator` vulnerable to code injection via unescaped carriag… |
| CVE-2026-54654 | 7.8 | 3.7 | koxudaxi | datamodel-code-generator | CWE-94 | `datamodel-code-generator` vulnerable to code injection via unescaped carriag… |
| CVE-2026-14870 | 7.1 | 3.7 | Unknown | Database for Contact Form 7, WPforms, Elementor forms | CWE-79 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS… |
| CVE-2026-7775 | 4.8 | 3.8 | IBM | Sterling B2B Integrator | CWE-79 | Cross-site Scripting Security Vulnerability in IBM Sterling B2B Integrator an… |
| CVE-2026-14819 | 3.5 | 3.8 | Unknown | Event Tickets and Registration | CWE-79 | Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move |
| CVE-2026-41874 | 6.8 | 3.0 | OpenSolution | Quick.Cart | CWE-256 | Hard-coded admin credentials in Quick.Cart |
| CVE-2026-54605 | 7.2 | 3.0 | ruby-oauth | oauth | CWE-200 | OAuth: Cross-origin token-request redirects can expose signed request metadata |
| CVE-2026-15136 | 4.3 | 2.8 | wplegalpages | WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode | CWE-352 | Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Req… |
| CVE-2026-4648 | 6.8 | 1.9 | CasfID Servicios Tecnológicos | NFC Wristbands | CWE-326 | Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands |
| CVE-2026-17072 | 3.3 | 1.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matro… |
| CVE-2026-62428 | 7.8 | 1.7 | Xen | Xen | CWE-367 | grant-table: type confusion in grant-copy |
| CVE-2026-18107 | 7.8 | 1.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-269 | Criu: criu: container escape via rseq critical section hijack during checkpoi… |
| CVE-2026-56822 | 7.4 | 1.5 | netty | netty | CWE-367 | Netty: TOCTOU in OcspServerCertificateValidator |
| CVE-2026-42494 | 6.1 | 1.4 | Xen | Xen | CWE-125 | buffer overruns in libfsimage iso9660 handling |
| CVE-2026-47768 | 5.5 | 1.3 | juev | nebula-mesh | CWE-598 | nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, … |
| CVE-2026-54619 | 2.0 | 1.2 | sparklemotion | sqlite3-ruby | CWE-416 | sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Differe… |
| CVE-2026-54620 | 2.0 | 1.2 | sparklemotion | sqlite3-ruby | CWE-416 | sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks |
| CVE-2026-8164 | 7.3 | 1.2 | ArkSigner Software and Hardware Industry and Trade Inc. | ArkSigner Desktop Client | CWE-427 | Search Order Hijacking in ArkSigner's ArkSigner Desktop Client |
| CVE-2026-55977 | 3.3 | 0.8 | EShare | ESharePro | CWE-307 | Bypass of application rate-limiting mechanism |
| CVE-2026-4932 | 4.2 | 0.2 | IBM | PowerVM Hypervisor | CWE-331 | This Power System update is being released to address Insufficient Entropy |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-28 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.