boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, July 30, 2026 · all times UTC← 2026-07-29 · archive · 2026-07-31 →

Security Box Score — July 30, 2026

662 CVEs published, led by Google (370).

662 CVEs published July 30, 2026: 110 critical, 199 high, 329 medium, 23 low; 1 in the KEV catalog at press time; 6 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 262 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published957821981——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

975 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux8352315207123163711120.17.8.0016+322 ▲
google4911756214710779537760.37.5.0025-599 ▼
microsoft665142210698132114286241.77.8.0047+444 ▲
red hat1483701614618424200.06.5.0030+20 ▲
apple167271577813338872.66.5.0027+115 ▲
canonical72738115000.05.6.0014+1 ▲
suse82141241000.08.5.0039-3 ▼
freebsd01601240000.07.8.0016-9 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1638818120561231.67.5.0057+6 ▲
ubiquiti2536142110338.38.8.0049+17 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
fortinet14236611028626.17.2.0040+12 ▲
netgear62300221000.04.6.0024-11 ▼
vmware13174922715.98.3.0040+10 ▲
f58165830416.38.6.0057+2 ▲
checkpoint31236303216.77.7.04550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache17833365142114113310.37.5.0053+57 ▲
mozilla711275142340900.08.1.0031+21 ▲
drupal465165355412.05.9.0026+46 ▲
gitlab205107377423.94.9.0029-4 ▼
github6121380000.06.0.0042+2 ▲
docker070520000.08.2.0016-4 ▼
wordpress3311102266.78.6.7979+3 ▲
kubernetes110001000.02.4.0035+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091379343653322612730.28.1.0036+867 ▲
adobe1072512711510541931.27.8.0026-35 ▼
ibm1052296786760600.07.5.0032+30 ▲
progress334262970600.08.0.0038+28 ▲
solarwinds16231733010417.49.1.0058+12 ▲
zohocorp362220000.07.8.0146+2 ▲
veeam262310100.08.5.0035+1 ▲
atlassian3303001300.08.0.0026+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
d-link8200596300.05.5.0105-2 ▼
siemens7161870000.07.6.0024-1 ▼
schneider electric391620000.08.6.0037-3 ▼
abb170430000.07.2.0018-5 ▼
hikvision550320000.07.2.0038+5 ▲
moxa050320000.07.0.0029-5 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester49120006258000.05.5.00340
openclaw441110583914000.07.0.0026-17 ▼
dell4399547443211.07.1.0021+5 ▲
capgo2283242381000.07.1.0037-39 ▼
nvidia43821254160000.07.8.0037+37 ▲
spring679234412000.06.5.0022-66 ▼
imagemagick3778156012000.05.3.0018-4 ▼
itsourcecode1871001952000.02.1.0033-25 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-45659.760899.58.8
CVE-2026-0770.634299.19.8
CVE-2026-59310.458898.79.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
CVE-2026-898510.0.0660
CVE-2026-651610.0.0486
CVE-2026-4766810.0.0388
Most disclosures (vendor)
VendorCVEs
oracle1109
linux835
microsoft665
google491
apache178
apple167
red hat148
adobe107
ibm105
mozilla71
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco12
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven65
PyPI6
NuGet4
Go3
npm3
Packagist2
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-20316Cisco0
CVE-2026-25089Fortinet0
CVE-2026-45659Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171716
CVE-2021-27102n/a2021-11-171716
CVE-2021-27101n/a2021-11-171716
CVE-2021-27103n/a2021-11-171716
CVE-2021-21017Adobe2021-11-171716
CVE-2021-28550Adobe2021-11-171716
CVE-2021-42013Apache Software Foundation2021-11-171716
CVE-2021-41773Apache Software Foundation2021-11-171716
CVE-2021-30858Apple2021-11-171716
CVE-2021-30860Apple2021-11-171716

Transactions

EXPLOIT PUBLISHED — boazsegev facil.io: 3 CVEs (CVE-2026-66729, CVE-2026-66730, CVE-2026-66731). Public exploit references added.

EXPLOIT PUBLISHED — Linux: 3 CVEs (CVE-2025-37899, CVE-2025-38002, CVE-2025-38089). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-12436 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14234 (Unknown WOLF). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14300 (Unknown miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41939 (Care Everywhere LLC Care Everywhere Gateway). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45309 (ronf asyncssh). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47143 (capstone-engine capstone). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54522 (msgpack-ruby). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56819 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56820 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-6267 (GitLab). Public exploit reference added.

DUE DATE PASSED — CVE-2023-4346 (KNX Association KNX Protocol Connection Authorization Option 1). CISA remediation deadline was July 29, 2026; still in catalog.

RESCORED — Linux: 570 CVEs (CVE-2025-21629, CVE-2025-21637, CVE-2025-21638, CVE-2025-21640, CVE-2025-21646, CVE-2025-21647, CVE-2025-21650, CVE-2025-21655, CVE-2025-21659, CVE-2025-21661, CVE-2025-21663, CVE-2025-21664, CVE-2025-21669, CVE-2025-21673, CVE-2025-21676, CVE-2025-21677, CVE-2025-21678, CVE-2025-21682, CVE-2025-21697, CVE-2025-21699, CVE-2025-21701, CVE-2025-21707, CVE-2025-21709, CVE-2025-21710, CVE-2025-21712, CVE-2025-21717, CVE-2025-21718, CVE-2025-21720, CVE-2025-21725, CVE-2025-21730, CVE-2025-21735, CVE-2025-21738, CVE-2025-21748, CVE-2025-21758, CVE-2025-21765, CVE-2025-21766, CVE-2025-21778, CVE-2025-21788, CVE-2025-21789, CVE-2025-21792, CVE-2025-21795, CVE-2025-21801, CVE-2025-21804, CVE-2025-21805, CVE-2025-21808, CVE-2025-21809, CVE-2025-21810, CVE-2025-21823, CVE-2025-21825, CVE-2025-21826, and 520 more — full list in this day's data.json). CVSS rescored — before/after on each CVE page.

RESCORED — Microsoft Windows 10 Version 1607: 3 CVEs (CVE-2026-20816, CVE-2026-20826, CVE-2026-20831). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-4244 (Linux Kernel). CVSS 7.8 → 7 (NVD).

RESCORED — CVE-2026-12086 (IBM UCD - IBM UrbanCode Deploy). CVSS 6.2 → 5.5 (NVD).

RESCORED — CVE-2026-50148 (metabase). CVSS 10 → 9.1 (NVD).

RESCORED — CVE-2026-7364 (IBM Verify Identity Access). CVSS 3.1 → 6.1 (NVD).

ENRICHED — CVE-2021-20322 (kernel). Received CVSS 7.4 and CPE data from NVD.

ENRICHED — CVE-2026-53167 (Linux). Received CVSS 5.5 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

662 CVEs published. 25 box scores and 375 table rows below; the remaining 262 continue on page 2 — every CVE is listed, nothing truncated.

VMware Cloud Foundation — vCenter directory-traversal vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .4588   98.7   YES
AFFECTED
  Product                     Versions   Fixed
  Cloud Foundation            9.1.x.x –  —
  vSphere Foundation          9.1.x.x –  —
  vCenter                     9.1.x.x –  —
  Telco Cloud Infrastructure  3.0 –      —
  Telco Cloud Platform        5.1.x –    —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 30  Published (CNA: vmware)
  Aug 18  Added to CISA KEV, due Aug 21
CWE-22 · CNA: vmware · CVSS v3.1 · 4 references · NVD status: Analyzed · KEV due August 21, 2026
rails rails — Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .1895   97.1     —
AFFECTED
  Product  Versions     Fixed
  rails    < 7.2.3.2 –  —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 30  Published (CNA: GitHub_M)
CWE-1188 · CNA: GitHub_M · CVSS v4.0 · 13 references · NVD status: Received
VMware Cloud Foundation — vCenter authentication-bypass vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0818   94.4     —
AFFECTED
  Product                     Versions   Fixed
  Cloud Foundation            9.1.x.x –  —
  vSphere Foundation          9.1.x.x –  —
  vCenter                     9.1.x.x –  —
  Telco Cloud Infrastructure  3.0 –      —
  Telco Cloud Platform        5.1.x –    —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 30  Published (CNA: vmware)
CWE-303 · CNA: vmware · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
somta Juggle — Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0529   91.9     —
AFFECTED
  Product  Versions     Fixed
  Juggle   unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 30  Published (CNA: VulnCheck)
CWE-306, CWE-1188 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
n/a n/a — TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0267   84.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 30  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
o6 Automation open62541 Integer Underflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   N   N   H    8.2   .0151   72.5     —
AFFECTED
  Product    Versions  Fixed
  open62541  1.3.0 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 30  Published (CNA: icscert)
CWE-191 · CNA: icscert · CVSS v4.0 · 7 references · NVD status: Received
SGLang SGLang — CVE-2026-15969
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0138   69.9     —
AFFECTED
  Product  Versions     Fixed
  SGLang   unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Jul 30  Published (CNA: certcc)
CWE-502 · CNA: certcc · CVSS v3.1 · 2 references · NVD status: Analyzed
Phoenix Contact CHARX SEC-3150 — OS Command Injection in OCPP Agent via charge_box_id
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   H    8.8   .0137   69.7     —
AFFECTED
  Product         Versions  Fixed
  CHARX SEC-3150  1.0.0 –   —
  CHARX SEC-3100  1.0.0 –   —
  CHARX SEC-3050  1.0.0 –   —
  CHARX SEC-3000  1.0.0 –   —
TIMELINE
  May 5   Reserved by CNA
  Jul 30  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v4.0 · 1 reference · NVD status: Deferred
IBM HMC V10.3.1050.0 — This Power Hardware Management Console update is being released to address
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0101   60.5     —
AFFECTED
  Product           Versions       Fixed
  HMC V10.3.1050.0  10.3.1050.0 –  —
  HMC V11.1.1110.0  11.1.1110.0 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 30  Published (CNA: ibm)
CWE-78 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0096   58.8     —
AFFECTED
  Product                 Versions     Fixed
  Adobe Campaign Classic  unspecified  7.4.3 build 9398
TIMELINE
  May 21  Reserved by CNA
  Jul 30  Published (CNA: adobe)
CWE-863 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0089   56.8     —
AFFECTED
  Product                 Versions    Fixed
  App Connect Enterprise  13.0.1.0 –  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 30  Published (CNA: ibm)
CWE-78 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0083   54.8     —
AFFECTED
  Product        Versions  Fixed
  Apache Kyuubi  1.7.0 –   —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 30  Published (CNA: apache)
CWE-22, CWE-73 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
IBM Langflow OSS — Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.8     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 30  Published (CNA: ibm)
CWE-78 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.5     —
AFFECTED
  Product        Versions                            Fixed
  Web Help Desk  2026.1 and all previous versions –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jul 30  Published (CNA: SolarWinds)
CWE-287 · CNA: SolarWinds · CVSS v3.1 · 3 references · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0065   48.5     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat Enterprise Linux 10             unspecified  0:7.0.3-5.el10_2
  Red Hat Enterprise Linux 8              unspecified  0:5.3.7-22.el8_10.5
  Red Hat Enterprise Linux 9              unspecified  0:6.3.7-8.el9_8.4
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 7              unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 30  Published (CNA: redhat)
CWE-78 · CNA: redhat · CVSS v3.1 · 5 references · NVD status: Awaiting Analysis
VMware Cloud Foundation — Out-of-bounds read vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  N  L    7.6   .0063   47.3     —
AFFECTED
  Product               Versions   Fixed
  Cloud Foundation      9.1.x.x –  —
  vSphere Foundation    9.1.x.x –  —
  ESX                   9.1.x.x –  —
  Workstation           25H2 –     —
  Fusion                25H2 –     —
  Telco Cloud Platform  5.1.x –    —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 30  Published (CNA: vmware)
CWE-125 · CNA: vmware · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Red Hat Red Hat Enterprise Linux 10 — Samba: dns signing dos via tkey name cache exhaustion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0062   47.0     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat Enterprise Linux 10             unspecified  —
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 7              unspecified  —
  Red Hat Enterprise Linux 8              unspecified  —
  Red Hat Enterprise Linux 9              unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 30  Published (CNA: redhat)
CWE-410 · CNA: redhat · CVSS v3.1 · 4 references · NVD status: Awaiting Analysis
o6 Automation open62541 Integer Overflow or Wraparound
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0060   46.3     —
AFFECTED
  Product    Versions  Fixed
  open62541  1.3.0 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 30  Published (CNA: icscert)
CWE-190 · CNA: icscert · CVSS v4.0 · 7 references · NVD status: Received
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0059   45.7     —
AFFECTED
  Product                 Versions     Fixed
  Adobe Campaign Classic  unspecified  7.4.3 build 9398
TIMELINE
  May 21  Reserved by CNA
  Jul 30  Published (CNA: adobe)
CWE-89 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
ASE Admin and Site Enhancements (ASE) Pro — Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0058   45.0     —
AFFECTED
  Product                                Versions     Fixed
  Admin and Site Enhancements (ASE) Pro  unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 30  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
wolfcms wolfcms — Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0058   44.9     —
AFFECTED
  Product  Versions     Fixed
  wolfcms  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 30  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
SGLang SGLang — CVE-2026-15971
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0057   44.7     —
AFFECTED
  Product  Versions     Fixed
  SGLang   unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Jul 30  Published (CNA: certcc)
CWE-95 · CNA: certcc · CVSS v3.1 · 2 references · NVD status: Analyzed
Google Chrome — Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0057   44.7     —
AFFECTED
  Product  Versions         Fixed
  Chrome   151.0.7922.72 –  —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 30  Published (CNA: Chrome)
CWE-416 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Google Chrome — Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0057   44.7     —
AFFECTED
  Product  Versions         Fixed
  Chrome   151.0.7922.72 –  —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 30  Published (CNA: Chrome)
CWE-416 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Google Chrome — Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrar…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0057   44.7     —
AFFECTED
  Product  Versions         Fixed
  Chrome   151.0.7922.72 –  —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 30  Published (CNA: Chrome)
CWE-416 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-177058.844.7GoogleChromeCWE-190Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-630357.244.7o6 Automationopen62541CWE-416o6 Automation open62541 Use After Free
CVE-2026-121189.844.4IBMwebMethods Integration (on prem)CWE-502IBM webMethods Integration could allow an unauthenticated remote attacker to …
CVE-2026-176618.844.1GoogleChromeCWE-416Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a re…
CVE-2026-176858.844.1GoogleChromeCWE-416Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-176819.643.9GoogleChromeCWE-20Insufficient validation of untrusted input in Web Authentication in Google Ch…
CVE-2026-13607.543.7buddypressBuddyPressCWE-502BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via X…
CVE-2026-6680310.043.5MicrosoftAzure Cosmos DBCWE-284Azure Cosmos DB Remote Code Execution Vulnerability
CVE-2026-176646.543.5GoogleChromeCWE-20Insufficient validation of untrusted input in Loader in Google Chrome prior t…
CVE-2026-182456.442.7AWSAmplify Codegen UICWE-94Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codege…
CVE-2026-176879.642.6GoogleChromeCWE-843Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176979.642.6GoogleChromeCWE-843Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176809.642.3GoogleChromeCWE-122Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.792…
CVE-2026-685029.842.2grisunoLazyOwnCWE-306LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Disp…
CVE-2026-176569.642.2GoogleChromeCWE-416Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176519.642.1GoogleChromeCWE-20Insufficient validation of untrusted input in Dawn in Google Chrome on Androi…
CVE-2026-176559.642.1GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-146029.042.1UnknownRemote APICWE-94Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query…
CVE-2026-177258.842.0GoogleChromeCWE-843Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-446176.541.6Apache Software FoundationApache ZeppelinCWE-90Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2…
CVE-2026-176529.641.4GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-441089.341.2Phoenix ContactCHARX SEC-3150CWE-696Firewall bypass during shutdown
CVE-2026-165277.340.4Red HatRed Hat Enterprise Linux 10CWE-306Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing …
CVE-2026-154359.840.3IBMApp Connect EnterpriseCWE-22IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability
CVE-2026-176676.540.2GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-176686.540.2GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-177076.540.2GoogleChromeCWE-457Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72…
CVE-2026-177146.540.2GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-159769.839.8SGLangSGLangCWE-502CVE-2026-15976
CVE-2026-176699.639.8GoogleChromeCWE-693Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-176829.639.8GoogleChromeCWE-190Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-176849.639.8GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-176929.639.8GoogleChromeCWE-416Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.792…
CVE-2026-177049.639.8GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-177089.639.8GoogleChromeCWE-416Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-177179.639.8GoogleChromeCWE-190Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-176788.839.8GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a…
CVE-2026-675949.339.3yolanmeesSpiksterCWE-306Spikster Missing Authentication via API Route Group
CVE-2026-177198.839.2GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176709.639.2GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176719.639.2GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-176729.639.2GoogleChromeCWE-20Insufficient validation of untrusted input in Chromecast in Google Chrome pri…
CVE-2026-176739.639.2GoogleChromeCWE-190Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a re…
CVE-2026-176769.639.2GoogleChromeCWE-693Inappropriate implementation in ANGLE in Google Chrome on Android prior to 15…
CVE-2026-176889.639.2GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176919.639.2GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.…
CVE-2026-176959.639.2GoogleChromeCWE-693Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.…
CVE-2026-177109.639.2GoogleChromeCWE-693Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.…
CVE-2026-177139.639.2GoogleChromeCWE-20Insufficient validation of untrusted input in Accessibility in Google Chrome …
CVE-2026-176778.839.2GoogleChromeCWE-693Inappropriate implementation in ANGLE in Google Chrome on Android prior to 15…
CVE-2026-78499.339.0Phoenix ContactCHARX SEC-3150CWE-77Command Injection in SCM (idledisconnect parameter)
CVE-2026-176508.339.1GoogleChromeCWE-416Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed…
CVE-2026-288117.539.0Apache Software FoundationApache JSPWikiCWE-1295Apache JSPWiki: Error Handling - Reveals Error Details
CVE-2026-176608.338.8GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-176638.338.8GoogleChromeCWE-20Insufficient validation of untrusted input in GPU in Google Chrome on Android…
CVE-2026-664218.838.4tugcantopalogluopenclaw-dashboardCWE-79OpenClaw Dashboard Stored XSS via lastMessage Session Field
CVE-2026-177019.638.4GoogleChromeCWE-125Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac p…
CVE-2026-176868.138.3GoogleChromeCWE-20Insufficient validation of untrusted input in Passwords in Google Chrome prio…
CVE-2026-176538.338.2GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remo…
CVE-2026-177518.838.0GoogleChromeCWE-269Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922…
CVE-2026-582228.837.9Red HatRed Hat Enterprise Linux 10CWE-90Samba: samba ad ldap compare filter injection and trusted-request confusion d…
CVE-2026-129966.038.0OpenVPNOpenVPNCWE-125A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4…
CVE-2026-165268.837.5Red HatRed Hat Enterprise Linux 10CWE-403Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability
CVE-2026-176796.537.4GoogleChromeCWE-20Insufficient validation of untrusted input in Print Preview in Google Chrome …
CVE-2026-176836.537.4GoogleChromeCWE-200Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72…
CVE-2026-664189.337.3tugcantopalogluopenclaw-dashboardCWE-79OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field
CVE-2026-446166.537.1Apache Software FoundationApache ZeppelinCWE-90Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
CVE-2026-177128.837.0GoogleChromeCWE-362Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote …
CVE-2026-667566.936.9Apache Software FoundationApache TikaCWE-424Apache Tika: unpack endpoint in tika-server allows configuration with unsecur…
CVE-2026-177589.636.7GoogleChromeCWE-122Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-177788.836.7GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-176578.336.7GoogleChromeCWE-416Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-667555.936.7Apache Software FoundationApache TikaCWE-22Apache Tika: Arbitrary Local File Read in ISArchiveParser
CVE-2026-177298.836.5GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-176894.336.1GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-635598.736.0o6 Automationopen62541CWE-190o6 Automation open62541 Integer Overflow or Wraparound
CVE-2026-159787.535.8SGLangSGLangCWE-306CVE-2026-15978
CVE-2026-181408.735.6AWSaws-smithy-jsonCWE-674Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows un…
CVE-2026-440909.335.4Phoenix ContactCHARX SEC-3150CWE-306Missing authentication for MQTT Broker
CVE-2026-441019.335.4Phoenix ContactCHARX SEC-3150CWE-306OCPP reconfiguration vulnerability
CVE-2026-178818.835.3GoogleChromeCWE-416Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-175448.135.3PHP GroupPHPCWE-787Out-of-bounds write in bccomp() via crafted operand and scale
CVE-2026-177596.535.0GoogleChromeCWE-457Uninitialized Use in Codecs in Google Chrome prior to 151.0.7922.72 allowed a…
CVE-2026-440928.834.7Phoenix ContactCHARX SEC-3150CWE-93Missing input validation / stripping of CRLF characters in SystemConfigManager
CVE-2026-177219.634.6GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-129327.134.4OpenVPNOpenVPNCWE-401A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 thro…
CVE-2026-129427.534.3IBMLangflow OSSCWE-22Langflow is affected by path traversal due to multiple unauthenticated and in…
CVE-2026-145197.534.3IBMApp Connect EnterpriseCWE-22IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitr…
CVE-2026-534319.134.1malach-itborutaCWE-294Boruta accepts expired JWT client assertions due to missing exp claim validation
CVE-2026-176746.534.1GoogleChromeCWE-693Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 …
CVE-2026-177036.534.1GoogleChromeCWE-602Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2026-239855.334.1Apache Software FoundationApache SupersetCWE-1333Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
CVE-2026-176759.633.8GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-177189.633.8GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-177269.633.8GoogleChromeCWE-190Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 …
CVE-2026-177279.633.8GoogleChromeCWE-787Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.…
CVE-2026-177389.633.8GoogleChromeCWE-20Insufficient validation of untrusted input in Payments in Google Chrome prior…
CVE-2026-177689.633.8GoogleChromeCWE-20Insufficient validation of untrusted input in WebSockets in Google Chrome pri…
CVE-2026-178019.633.8GoogleChromeCWE-125Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72…
CVE-2026-178049.633.8GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-177528.833.8GoogleChromeCWE-416Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowe…
CVE-2026-177848.833.8GoogleChromeCWE-416Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowe…
CVE-2026-288147.533.8Apache Software FoundationApache JSPWikiCWE-306Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering
CVE-2026-179228.833.6GoogleChromeCWE-94Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.79…
CVE-2026-288129.833.1Apache Software FoundationApache JSPWikiCWE-290Apache JSPWiki: UserManager does not sanity-check user database at startup
CVE-2026-417092.733.1VMwareCloud FoundationCWE-778ESX insufficient logging vulnerability
CVE-2026-578597.732.7e107ince107CWE-502e107 Second-Order Code Execution via eval()-Based Deserialization in e_array:…
CVE-2026-176964.332.8GoogleChromeCWE-1300Side-channel information leakage in Media in Google Chrome prior to 151.0.792…
CVE-2026-177004.332.8GoogleChromeCWE-20Insufficient validation of untrusted input in Actor in Google Chrome prior to…
CVE-2026-177064.332.8GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome on Windo…
CVE-2026-131176.032.6OpenVPNOpenVPNCWE-416An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.…
CVE-2026-685039.832.4grisunoLazyOwnCWE-1392LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 D…
CVE-2026-543639.332.2GladinetCentreStackCWE-321CentreStack < 17.5 Hardcoded Key Token Forgery RCE
CVE-2026-543688.732.0GladinetCentreStackCWE-89CentreStack < 17.4 SQL Injection via x-glad-filter Header
CVE-2026-107006.531.9IBMLangflow OSSCWE-639Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling…
CVE-2026-177099.631.8GoogleChromeCWE-362Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a re…
CVE-2026-177966.531.6GoogleChromeCWE-1300Side-channel information leakage in WebXR in Google Chrome prior to 151.0.792…
CVE-2026-178006.531.6GoogleChromeCWE-1300Inappropriate implementation in MediaRecording in Google Chrome prior to 151.…
CVE-2026-177119.631.0GoogleChromeCWE-362Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a re…
CVE-2026-685007.531.0SyliusMolliePluginCWE-639Sylius Mollie Plugin: Payment status forgery via the payment webhook
CVE-2026-178368.830.8GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-177228.330.7GoogleChromeCWE-416Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.…
CVE-2026-178039.630.6GoogleChromeCWE-20Insufficient validation of untrusted input in Save to Drive in Google Chrome …
CVE-2026-176987.530.5GoogleChromeCWE-20Insufficient validation of untrusted input in UI in Google Chrome on Android …
CVE-2026-177358.730.5GoogleChromeCWE-20Insufficient validation of untrusted input in BFCache in Google Chrome prior …
CVE-2026-117717.030.2OpenVPNOpenVPNCWE-121OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows atta…
CVE-2026-178078.830.0GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-600747.530.0—Date-ManipCWE-1289Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASC…
CVE-2026-600757.530.0—Date-ManipCWE-1333Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic…
CVE-2026-177404.330.0GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-177574.330.0GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-177714.330.0GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-177854.330.0GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-177904.330.0GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72…
CVE-2026-178084.330.0GoogleChromeCWE-457Uninitialized Use in WebGL in Google Chrome on Android prior to 151.0.7922.72…
CVE-2026-178104.330.0GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-548856.929.9malach-itborutaCWE-918Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri f…
CVE-2026-177238.329.9GoogleChromeCWE-416Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 al…
CVE-2026-673518.729.7s9ySerendipityCWE-304Serendipity < 2.6.1 Authentication Bypass via Username Collision
CVE-2026-358479.829.4n/an/aCWE-77An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbit…
CVE-2026-65407.929.4TigeraCalicoCWE-22L7 policy bypass via unnormalized HTTP path matching
CVE-2026-239815.329.1Apache Software FoundationApache SupersetCWE-285Apache Superset: Improper Authorization in Chart Update allowing Dashboard Mo…
CVE-2026-178967.528.9GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-440918.828.9Phoenix ContactCHARX SEC-3150CWE-501Creation of a new configuration by posting a malicious ID to MQTT
CVE-2026-226208.628.9EatonPADMCWE-89Improper input validation in the authentication component of Eaton's Tripp Li…
CVE-2026-446136.128.8Apache Software FoundationApache ZeppelinCWE-352Apache Zeppelin: Cross-site request forgery in REST and WebSocket request han…
CVE-2026-165297.528.8Red HatRed Hat Enterprise Linux 10CWE-190Pcp: pcp: denial of service due to signed integer overflow
CVE-2026-178167.528.4GoogleChromeCWE-269Insufficient policy enforcement in Speech in Google Chrome on Android prior t…
CVE-2026-165315.328.4Red HatRed Hat Enterprise Linux 10CWE-22Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet
CVE-2026-478769.328.1VMwareCloud FoundationCWE-787VMXNET3 out-of-bounds write vulnerability
CVE-2026-177566.528.0GoogleChromeCWE-602Insufficient policy enforcement in Presentation in Google Chrome prior to 151…
CVE-2026-177646.528.0GoogleChromeCWE-693Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72…
CVE-2026-178146.528.0GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-129469.927.7IBMLangflow OSSCWE-94Remote Code Execution in CUGA Component CodeAgent
CVE-2026-580469.927.7WebProsPleskCWE-89Improper neutralization in the Plesk XML-RPC API allows a remote authenticate…
CVE-2026-178479.627.4GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-489106.527.4Apache Software FoundationApache JSPWikiCWE-80Apache JSPWiki: Markdown parser allows XSS injection in Markdown error proces…
CVE-2026-115368.527.0IBMWebSphere Application ServerCWE-502IBM WebSphere Application Server is affected by a remote code execution vulne…
CVE-2026-177916.526.8GoogleChromeCWE-20Insufficient validation of untrusted input in Payments in Google Chrome prior…
CVE-2026-177926.526.8GoogleChromeCWE-451Inappropriate implementation in Credential Management in Google Chrome prior …
CVE-2026-177936.526.8GoogleChromeCWE-451Inappropriate implementation in Messages in Google Chrome on Android prior to…
CVE-2026-178316.526.8GoogleChromeCWE-20Insufficient validation of untrusted input in Passwords in Google Chrome prio…
CVE-2026-411866.026.8TigeraCalicoCWE-200Unauthenticated Go pprof exposure in Calico debug server
CVE-2026-159777.526.7SGLangSGLangCWE-522CVE-2026-15977
CVE-2026-177304.326.7GoogleChromeCWE-1300Side-channel information leakage in Autofill in Google Chrome prior to 151.0.…
CVE-2026-177604.326.7GoogleChromeCWE-1300Side-channel information leakage in NoStatePrefetch in Google Chrome prior to…
CVE-2026-177674.326.7GoogleChromeCWE-20Insufficient validation of untrusted input in WebView in Google Chrome on And…
CVE-2026-177694.326.7GoogleChromeCWE-20Insufficient validation of untrusted input in Cast in Google Chrome prior to …
CVE-2026-177724.326.7GoogleChromeCWE-125Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a…
CVE-2026-177734.326.7GoogleChromeCWE-20Insufficient validation of untrusted input in Cast in Google Chrome prior to …
CVE-2026-177954.326.7GoogleChromeCWE-20Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.…
CVE-2026-685016.526.6SyliusMolliePluginCWE-639Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII
CVE-2026-178688.826.4GoogleChromeCWE-269Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.7…
CVE-2026-178306.526.5GoogleChromeCWE-284Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-179358.826.4GoogleChromeCWE-122Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowe…
CVE-2026-133958.626.3UnknownOnline Scheduling and Appointment Booking SystemCWE-89Bookly < 27.8 - Unauthenticated SQL Injection via staff_id
CVE-2026-180648.226.3NASACore Flight System (cFS) Health & Safety (HS) ApplicationCWE-476NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer D…
CVE-2026-177795.426.4GoogleChromeCWE-693Inappropriate implementation in Site Isolation in Google Chrome prior to 151.…
CVE-2026-133795.126.3OpenVPNOpenVPNCWE-125The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows re…
CVE-2026-626637.526.0mascibanksCWE-22Banks: Arbitrary File Read via Path Traversal in Media Filters (image/audio/v…
CVE-2026-176624.325.8GoogleChromeCWE-346Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7…
CVE-2026-176934.325.8GoogleChromeCWE-346Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0…
CVE-2026-179678.825.6GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…
CVE-2026-176906.525.5GoogleChromeCWE-20Insufficient validation of untrusted input in PDF in Google Chrome on Android…
CVE-2026-547228.725.1HackingRepodssrf-jsCWE-76dssrf: there a critical security bug with remove_at_symbol_in_string
CVE-2026-179898.824.6GoogleChromeCWE-843Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-175438.124.6PHP GroupPHPCWE-89SQL injection in ext-pgsql via E'...' backslash breakout
CVE-2025-653369.824.3n/an/aCWE-89Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL I…
CVE-2026-178489.624.3GoogleChromeCWE-20Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-176594.224.2GoogleChromeCWE-693Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0…
CVE-2026-178329.624.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-178349.624.1GoogleChromeCWE-20Insufficient validation of untrusted input in Passwords in Google Chrome prio…
CVE-2026-178379.624.1GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-127337.523.5IBMDataPower Gateway 10.6CDCWE-770IBM DataPower Gateway affected by denial of service
CVE-2026-163087.523.5IBMEnterprise Build of QuarkusCWE-770IBM Enterprise Build of Quarkus is affected by a DoS vulnerability
CVE-2026-582165.323.4Red HatRed Hat Enterprise Linux 10CWE-125Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might ca…
CVE-2026-178758.823.3GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a re…
CVE-2026-177474.223.4GoogleChromeCWE-20Insufficient validation of untrusted input in Payments in Google Chrome on An…
CVE-2026-673458.523.2dromaraMaxKeyCWE-183MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
CVE-2026-108427.523.2IBMWebSphere Application ServerCWE-289IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-441078.723.0Phoenix ContactCHARX SEC-3150CWE-749Exposed Reboot via Modbus
CVE-2026-143186.822.8UnknownGiveWPCWE-79GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
CVE-2026-673467.722.8kyegomezswarmsCWE-918Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass
CVE-2026-672466.922.8ASUSTOR Inc.ADMCWE-22A path traversal vulnerability was found in the Wallpaper component of ADM
CVE-2026-441008.822.7Phoenix ContactCHARX SEC-3150CWE-306JupiCore charging point reconfiguration without auth
CVE-2026-226228.822.6EatonPADMCWE-78Improper input validation in one of the session management interface of Eaton…
CVE-2026-93227.522.6IBMWebSphere Application ServerCWE-400IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-153977.222.5wpswingsSubscriptions for WooCommerceCWE-862Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticat…
CVE-2026-226218.322.4EatonPADMCWE-78Improper input validation in one of the session management interface of Eaton…
CVE-2026-118977.522.5IBMWebSphere Application Server - LibertyCWE-770IBM WebSphere Application Server Liberty is affected by a denial of service v…
CVE-2026-178877.522.4GoogleChromeCWE-416Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-525399.122.4n/an/aCWE-798Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_…
CVE-2026-179188.822.3GoogleChromeCWE-416Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remo…
CVE-2026-672477.122.2ASUSTOR Inc.ADMCWE-22A path traversal vulnerability was found in the IHM Log handling of ADM
CVE-2026-598816.922.2aio-libsaiohttpCWE-20AIOHTTP: WebSocket client accepts compressed frames without negotiated permes…
CVE-2026-599526.922.2open-circlevalibotCWE-755Valibot: record() issue paths can make flatten() throw for inherited Object p…
CVE-2026-656358.322.1malach-itborutaCWE-653Boruta dynamic client registration allows creation of over-privileged OAuth c…
CVE-2026-178406.522.1GoogleChromeCWE-451Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 al…
CVE-2026-177868.822.0GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-672078.722.0wolfcmswolfcmsCWE-697Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
CVE-2026-615367.522.0mascibanksCWE-94Banks: Unsafe importlib.import_module of attacker-controlled Tool.import_path…
CVE-2026-165306.522.0Red HatRed Hat Enterprise Linux 10CWE-125Pcp: pcp: remote denial of service and information leakage
CVE-2026-178246.521.9GoogleChromeCWE-284Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 15…
CVE-2026-183639.121.8Enhancesoft LLCosTicketCWE-640Weak password recovery mechanism in osTicket by Enhancesoft LLC
CVE-2026-179568.821.8GoogleChromeCWE-269Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.79…
CVE-2026-177023.121.7GoogleChromeCWE-346Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 …
CVE-2026-177153.121.7GoogleChromeCWE-346Inappropriate implementation in Passwords in Google Chrome prior to 151.0.792…
CVE-2026-126877.521.6UnknownProfileGridCWE-269ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted…
CVE-2026-159746.521.6SGLangSGLangCWE-918CVE-2026-15974
CVE-2026-134359.921.4IBMLangflow OSSCWE-94Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure
CVE-2026-177499.621.3GoogleChromeCWE-20Insufficient validation of untrusted input in Extensions in Google Chrome pri…
CVE-2026-177824.321.4GoogleChromeCWE-451Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.…
CVE-2026-177944.321.4GoogleChromeCWE-20Insufficient validation of untrusted input in Mobile in Google Chrome on Andr…
CVE-2026-578628.421.3KanboardKanboardCWE-918Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation
CVE-2026-119045.321.2IBMVerify Identity AccessCWE-209Security vulnerabilities have been found in IBM Verify Identity Access and IB…
CVE-2026-179698.821.1GoogleChromeCWE-269Inappropriate implementation in Passwords in Google Chrome prior to 151.0.792…
CVE-2026-151536.820.8UnknownWP Hotel BookingCWE-89WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search
CVE-2026-177806.320.9GoogleChromeCWE-284Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 1…
CVE-2026-543668.720.6GladinetCentreStackCWE-611CentreStack < 17.4 XXE via SharePoint Storage Configuration
CVE-2026-177976.120.6GoogleChromeCWE-79Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 a…
CVE-2026-177285.420.6GoogleChromeCWE-79Inappropriate implementation in Extensions in Google Chrome prior to 151.0.79…
CVE-2026-177345.420.6GoogleChromeCWE-79Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922…
CVE-2026-673498.720.5opencostopencostCWE-306OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
CVE-2026-179518.820.4GoogleChromeCWE-122Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowe…
CVE-2026-664158.420.4LeantimeLeantimeCWE-918Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::…
CVE-2026-564288.120.3BoschBSH ELP (Electronic Platform) ModulesCWE-286The SSH service on BSH ELP (Electronic Platform) modules contains a platform-…
CVE-2026-178056.520.3GoogleChromeCWE-602Insufficient policy enforcement in Glic in Google Chrome on Android prior to …
CVE-2026-178136.520.3GoogleChromeCWE-602Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2026-672448.620.3ASUSTOR Inc.ADMCWE-134A format string vulnerability was found in the Notification OAuth settings of…
CVE-2026-177436.520.2GoogleChromeCWE-346Insufficient policy enforcement in ControlledFrame in Google Chrome prior to …
CVE-2026-177486.520.2GoogleChromeCWE-346Inappropriate implementation in Extensions in Google Chrome prior to 151.0.79…
CVE-2026-177546.520.2GoogleChromeCWE-346Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72…
CVE-2026-177876.520.2GoogleChromeCWE-346Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922…
CVE-2026-178848.820.1GoogleChromeCWE-416Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allo…
CVE-2026-672488.720.2ASUSTOR Inc.ADMCWE-121A stack-based buffer overflow vulnerability was found in the File Explorer on…
CVE-2026-177417.120.1GoogleChromeCWE-20Insufficient validation of untrusted input in WebView in Google Chrome on And…
CVE-2026-177507.120.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-177314.320.1GoogleChromeCWE-346Inappropriate implementation in Autofill in Google Chrome on Android prior to…
CVE-2026-177334.320.1GoogleChromeCWE-346Inappropriate implementation in QUIC in Google Chrome on Android prior to 151…
CVE-2026-177424.320.1GoogleChromeCWE-346Insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7…
CVE-2026-177534.320.1GoogleChromeCWE-346Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922…
CVE-2026-177624.320.1GoogleChromeCWE-346Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-177634.320.1GoogleChromeCWE-346Inappropriate implementation in GPU in Google Chrome prior to 151.0.7922.72 a…
CVE-2026-177654.320.1GoogleChromeCWE-346Inappropriate implementation in WebProtect in Google Chrome prior to 151.0.79…
CVE-2026-177754.320.1GoogleChromeCWE-346Inappropriate implementation in PresentationAPI in Google Chrome prior to 151…
CVE-2026-177774.320.1GoogleChromeCWE-346Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922…
CVE-2026-177884.320.1GoogleChromeCWE-346Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72…
CVE-2026-177984.320.1GoogleChromeCWE-346Inappropriate implementation in Cast in Google Chrome prior to 151.0.7922.72 …
CVE-2026-178154.320.1GoogleChromeCWE-346Insufficient policy enforcement in GuestView in Google Chrome prior to 151.0.…
CVE-2026-178204.320.1GoogleChromeCWE-346Insufficient policy enforcement in Autofill in Google Chrome prior to 151.0.7…
CVE-2026-178294.320.1GoogleChromeCWE-346Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.…
CVE-2026-178948.820.1GoogleChromeCWE-416Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allo…
CVE-2026-142276.920.1MikroTikRouterOSCWE-613Insufficient session expiration in MikroTik RouterOS
CVE-2026-178494.320.0GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-557688.719.8allinurlgoaccessCWE-681GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame lengt…
CVE-2026-125628.719.7Toptech SystemsRCU II+CWE-306Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical…
CVE-2026-663608.719.7MZ Automation GmbHlibiec61850CWE-125MZ Automation libiec61850 Out-of-bounds Read
CVE-2026-673476.119.6vendurehqvendureCWE-863Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset …
CVE-2026-178569.619.4GoogleChromeCWE-693Inappropriate implementation in Network in Google Chrome on Mac prior to 151.…
CVE-2026-178659.619.5GoogleChromeCWE-693Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0…
CVE-2026-178868.819.5GoogleChromeCWE-416Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-178196.519.4GoogleChromeCWE-451Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.…
CVE-2026-178286.519.4GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-178356.519.4GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-178386.519.4GoogleChromeCWE-451Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.…
CVE-2026-178396.519.4GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-178024.319.3GoogleChromeCWE-1300Side-channel information leakage in GPU in Google Chrome on Android prior to …
CVE-2026-178256.519.2GoogleChromeCWE-284Insufficient policy enforcement in Passwords in Google Chrome on Android prio…
CVE-2026-177365.819.1GoogleChromeCWE-20Insufficient validation of untrusted input in WebView in Google Chrome on And…
CVE-2026-177995.419.1GoogleChromeCWE-20Insufficient validation of untrusted input in Safe Browsing in Google Chrome …
CVE-2026-179718.819.0GoogleChromeCWE-125Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72…
CVE-2026-177447.119.0GoogleChromeCWE-269Inappropriate implementation in File Input in Google Chrome on Linux prior to…
CVE-2026-580406.319.0nodejsnodeCWE-297An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reu…
CVE-2026-179466.518.6GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-179686.518.6GoogleChromeCWE-457Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72…
CVE-2026-178125.418.7GoogleChromeCWE-451Inappropriate implementation in DigitalCredentials in Google Chrome prior to …
CVE-2026-143568.818.6fleekdashFleekDash V2CWE-862FleekDash V2 <= 2.6.2.2 - Missing Authorization to Authenticated (Subscriber+…
CVE-2026-179508.818.6GoogleChromeCWE-269Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to…
CVE-2026-622468.518.6clastixkamajiCWE-284Kamaji: TenantControlPlane namespace/name collision binds two tenants to the …
CVE-2026-183826.818.5Red HatCost Management Metrics OperatorCWE-918Project-koku/koku-metrics-operator: koku-metrics-operator: service-account cl…
CVE-2026-658346.818.3projectcapsulecapsuleCWE-20Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validati…
CVE-2026-441049.318.3Phoenix ContactCHARX SEC-3150CWE-347ControllerAgent does not perform validation of firmware
CVE-2026-648167.118.3CyberTimonRapidRAWCWE-73RapidRAW < 1.6.0 NTLMv2 Credential Leak via UNC Path in lutPath
CVE-2026-181867.117.9ASUSTOR Inc.ADMCWE-134A stored format string vulnerability was found in the FTP Backup on the ADM
CVE-2026-181877.117.9ASUSTOR Inc.ADMCWE-134A format string vulnerability was found in the Internal Backup on the ADM
CVE-2026-181887.117.9ASUSTOR Inc.ADMCWE-134A format string vulnerability was found in the Rsync Backup on the ADM
CVE-2026-177615.417.9GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-156588.117.8foreUPforeUPCWE-639foreUP customer REST API allows unauthenticated endpoint access
CVE-2026-618936.917.8MZ Automationlib60870CWE-125MZ Automation lib60870 Out-of-bounds Read
CVE-2026-630336.917.8MZ Automationlib60870CWE-125MZ Automation lib60870 Out-of-bounds Read
CVE-2026-156576.517.8foreUPforeUPCWE-522foreUP customer REST API allows authenticated users to read cleartext payment…
CVE-2024-250397.517.7IBMEngineering Requirements Management DOORS and DOORS Web AccessCWE-400IBM Engineering Requirements Management DOORS and DOORS Web Access is affecte…
CVE-2026-547157.117.7allinurlgoaccessCWE-122GoAccess: Heap Out-of-Bounds Write in parse_browser()
CVE-2026-178926.517.7GoogleChromeCWE-200Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72…
CVE-2026-557775.317.7allinurlgoaccessCWE-125GoAccess: Out-of-bounds heap read in parse_ios() via crafted User-Agent leads…
CVE-2026-177896.517.6GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-178698.117.5GoogleChromeCWE-125Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a…
CVE-2025-699309.817.4n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699319.817.3n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699339.817.3n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699349.817.4n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699359.817.4n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in t…
CVE-2025-699369.817.3n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699379.817.3n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699389.817.3n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699419.817.3n/an/aCWE-89SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in…
CVE-2025-699479.817.4n/an/aCWE-89SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in…
CVE-2026-49789.817.3UMAI VisionTraffic Analysis SystemCWE-89SQLi in UMAI Vision's Traffic Analysis System
CVE-2026-149236.517.2UnknownSync Post With Other SiteCWE-863Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modi…
CVE-2026-179926.517.2GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 …
CVE-2026-178514.317.2GoogleChromeCWE-1300Side-channel information leakage in Autofill in Google Chrome prior to 151.0.…
CVE-2026-178594.317.2GoogleChromeCWE-1300Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922…
CVE-2026-179249.617.1GoogleChromeCWE-416Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remot…
CVE-2026-179409.617.1GoogleChromeCWE-20Insufficient validation of untrusted input in Picture-in-Picture in Google Ch…
CVE-2026-179479.617.1GoogleChromeCWE-416Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-440948.317.1Phoenix ContactCHARX SEC-3150CWE-636Fallback to second RAUC slot with default credentials
CVE-2026-177765.817.1GoogleChromeCWE-693Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-177747.516.9GoogleChromeCWE-20Insufficient validation of untrusted input in Variations in Google Chrome pri…
CVE-2026-177455.816.8GoogleChromeCWE-125Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-177465.816.8GoogleChromeCWE-416Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed …
CVE-2026-177705.816.8GoogleChromeCWE-125Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 al…
CVE-2026-177375.016.8GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.7…
CVE-2026-127228.216.7FTC Software IT ServicesFTC E-Commerce Management PanelCWE-306Authentication Bypass in FTC Software's E-Commerce Management Panel
CVE-2026-183625.916.7dfir-irisiris-webCWE-770DFIR-IRIS Missing Brute Force Protection in User Authentication
CVE-2026-177203.116.6GoogleChromeCWE-346Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.…
CVE-2026-673488.616.5julep-aijulepCWE-639Julep Insecure Direct Object Reference via GET /executions/{execution_id}
CVE-2026-125007.516.5UnknownWP Travel EngineCWE-862WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update
CVE-2026-131787.516.5UnknownEventinCWE-639Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
CVE-2026-543646.916.3GladinetCentreStackCWE-116CentreStack < 17.4 Session Injection via SelectProvider.aspx
CVE-2026-177323.116.2GoogleChromeCWE-346Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 a…
CVE-2026-178263.116.2GoogleChromeCWE-346Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-635507.115.9MZ Automation GmbHlibiec61850CWE-125MZ Automation libiec61850 Out-of-bounds Read
CVE-2026-180178.815.8GoogleChromeCWE-416Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remo…
CVE-2026-179135.415.7GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-178426.515.5GoogleChromeCWE-346Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-178466.515.5GoogleChromeCWE-346Inappropriate implementation in Media in Google Chrome on Windows prior to 15…
CVE-2026-178456.115.5GoogleChromeCWE-79Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 a…
CVE-2026-133455.315.5UnknownEssential Addons for ElementorCWE-639Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Privat…
CVE-2026-580669.815.4Rocket.ChatRocket.ChatCWE-287Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2…
CVE-2026-440975.315.3Phoenix ContactCHARX SEC-3150CWE-434File Upload vulnerability
CVE-2026-179344.315.4GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-179919.615.2GoogleChromeCWE-20Insufficient validation of untrusted input in AI in Google Chrome prior to 15…
CVE-2026-176998.615.2GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a loc…
CVE-2026-176669.115.0GoogleChromeCWE-325Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allo…
CVE-2026-675277.615.1opfopenprojectCWE-862OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via…
CVE-2026-160926.515.0labelblancImproved Save ButtonCWE-89Improved Save Button <= 1.2.1 - Authenticated (Author+) Second-Order SQL Inje…
CVE-2025-363745.515.0IBMDataPower Gateway 10.6CDCWE-611IBM DataPower Gateway affected by XML external entity injection
CVE-2026-149808.814.8IBMWebSphere Application Server - LibertyCWE-269IBM WebSphere Application Server Liberty is affected by a cross-site request …
CVE-2026-183538.814.8Eclipse FoundationEclipse CSI - PIACWE-918Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass
CVE-2026-484999.314.6activepiecesactivepiecesCWE-200Activepieces: Cross-tenant data exposure and code injection via the Code piec…
CVE-2026-178506.514.6GoogleChromeCWE-346Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7…
CVE-2026-178526.514.6GoogleChromeCWE-346Inappropriate implementation in Media Router in Google Chrome prior to 151.0.…
CVE-2026-179756.514.5GoogleChromeCWE-200Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.79…
CVE-2026-178434.314.5GoogleChromeCWE-346Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 a…
CVE-2026-179307.514.5GoogleChromeCWE-20Insufficient validation of untrusted input in Extensions in Google Chrome pri…

Results continue: ranks 401–662.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-30 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.