boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, July 31, 2026 · all times UTC← 2026-07-30 · archive · 2026-08-01 →

Security Box Score — July 31, 2026

183 CVEs published, led by Red Hat (16).

183 CVEs published July 31, 2026: 26 critical, 66 high, 76 medium, 15 low; 0 in the KEV catalog at press time; 2 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 158 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published976122164——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1022 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux8352315207123163711120.17.8.0016+322 ▲
google4961761214713781537760.37.5.0025-594 ▼
microsoft665142210698132114286241.77.8.0047+444 ▲
red hat1643861615419125200.06.5.0030+36 ▲
apple167271577813338872.66.5.0027+115 ▲
canonical72738115000.05.6.0014+1 ▲
suse82141241000.08.5.0039-3 ▼
freebsd01601240000.07.8.0016-9 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1638818120561231.67.5.0057+6 ▲
ubiquiti2536142110338.38.8.0049+17 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
fortinet14236611028626.17.2.0040+12 ▲
netgear62300221000.04.6.0024-11 ▼
vmware13174922715.98.3.0040+10 ▲
f58165830416.38.6.0057+2 ▲
checkpoint31236303216.77.7.04550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache18133665143116113310.37.5.0053+60 ▲
mozilla711275142340900.08.1.0031+21 ▲
drupal465165355412.05.9.0026+46 ▲
gitlab205107377423.94.9.0029-4 ▼
github6121380000.06.0.0042+2 ▲
docker070520000.08.2.0016-4 ▼
wordpress3311102266.78.6.7979+3 ▲
kubernetes110001000.02.4.0035+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091379343653322612730.28.1.0036+867 ▲
adobe1082522711610541931.27.8.0026-34 ▼
ibm1052296786760600.07.5.0032+30 ▲
progress334262970600.08.0.0038+28 ▲
solarwinds16231733010417.49.1.0058+12 ▲
zohocorp362220000.07.8.0146+2 ▲
veeam262310100.08.5.0035+1 ▲
atlassian3303001300.08.0.0026+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
d-link8200596300.05.5.0105-2 ▼
siemens7161870000.07.6.0024-1 ▼
schneider electric391620000.08.6.0037-3 ▼
abb170430000.07.2.0018-5 ▼
hikvision660420000.07.2.0040+6 ▲
moxa050320000.07.0.0029-5 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester49120006258000.05.5.00340
openclaw441110583914000.07.0.0026-17 ▼
dell4399547443211.07.1.0021+5 ▲
capgo2283242381000.07.1.0037-39 ▼
nvidia43821254160000.07.8.0037+37 ▲
spring679234412000.06.5.0022-66 ▼
imagemagick3778156012000.05.3.0018-4 ▼
itsourcecode1871001952000.02.1.0033-25 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-0770.634299.19.8
CVE-2026-59310.458898.79.8
CVE-2026-48282.423998.610.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
CVE-2026-898510.0.0660
CVE-2026-651610.0.0486
CVE-2026-4766810.0.0388
Most disclosures (vendor)
VendorCVEs
oracle1109
linux804
microsoft663
google444
apache179
apple167
red hat156
adobe108
ibm105
mozilla69
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco12
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven65
PyPI6
NuGet4
Go3
npm3
Packagist2
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-20316Cisco0
CVE-2026-25089Fortinet0
CVE-2026-46817Oracle Corporation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171717
CVE-2021-27102n/a2021-11-171717
CVE-2021-27101n/a2021-11-171717
CVE-2021-27103n/a2021-11-171717
CVE-2021-21017Adobe2021-11-171717
CVE-2021-28550Adobe2021-11-171717
CVE-2021-42013Apache Software Foundation2021-11-171717
CVE-2021-41773Apache Software Foundation2021-11-171717
CVE-2021-30858Apple2021-11-171717
CVE-2021-30860Apple2021-11-171717

Transactions

EXPLOIT PUBLISHED — CVE-2009-3960. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2017-12615 (Apache Software Foundation Apache Tomcat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-47966. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-47246. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10685 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10686 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56968 (GNU SASL). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66066 (rails). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67206 (wolfcms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67207 (wolfcms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67345 (dromara MaxKey). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67347 (vendurehq vendure). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67348 (julep-ai julep). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67349 (opencost). Public exploit reference added.

DUE DATE PASSED — CVE-2026-16812 (Arista Networks VeloCloud Orchestrator On-Prem). CISA remediation deadline was July 30, 2026; still in catalog.

RESCORED — Dígitro NGC Explorer: 3 CVEs (CVE-2025-4526, CVE-2025-4527, CVE-2025-4528). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-27997 (Fortinet FortiOS-6K7K). CVSS 9.2 → 9.8 (NVD).

RESCORED — CVE-2023-4966 (Citrix NetScaler ADC). CVSS 9.4 → 7.5 (NVD).

RESCORED — CVE-2023-6507 (Python Software Foundation CPython). CVSS 6.1 → 4.9 (NVD).

RESCORED — CVE-2026-56968 (GNU SASL). CVSS 3.7 → 5.3 (NVD).

Yesterday's Results

How to read these box scores · glossary

183 CVEs published. 25 box scores, 158 table rows — nothing truncated.

Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0364   88.7     —
AFFECTED
  Product                                        Versions     Fixed
  Realtyna Organic IDX plugin + WPL Real Estate  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 31  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
n/a n/a — TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0262   84.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
n/a n/a — TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0262   84.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
n/a n/a — TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0262   84.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
n/a n/a — TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the syste…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0255   83.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
TP-Link Systems Inc. AXE75 V1 — Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   H   H   H    8.5   .0116   64.6     —
AFFECTED
  Product   Versions     Fixed
  AXE75 V1  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jul 31  Published (CNA: TPLink)
CWE-78 · CNA: TPLink · CVSS v4.0 · 3 references · NVD status: Analyzed
WebPros cPanel — Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0097   59.1     —
AFFECTED
  Product     Versions     Fixed
  cPanel      unspecified  —
  WP Squared  unspecified  —
TIMELINE
  Jun 27  Reserved by CNA
  Jul 31  Published (CNA: hackerone)
CWE-89 · CNA: hackerone · CVSS v4.0 · 2 references · NVD status: Received
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8 — 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0083   54.8     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Directory Server 11.7 E4S for RHEL 8                           unspecified  8080020260806114250.f969626e
  Red Hat Directory Server 11.9 for RHEL 8                               unspecified  8100020260803140625.37ed7c03
  Red Hat Directory Server 12.2 E4S for RHEL 9                           unspecified  9020020260730155601.1674d574
  Red Hat Directory Server 12.4 E4S for RHEL 9                           unspecified  9040020260810131422.1674d574
  Red Hat Enterprise Linux 10                                            unspecified  0:3.2.0-9.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.0.6-20.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.3.11.1-14.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  8100020260806150504.25e700aa
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  8040020260803141511.96015a92
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  8040020260803141511.96015a92
  + 11 more
TIMELINE
  Jul 14  Reserved by CNA
  Jul 31  Published (CNA: redhat)
CWE-121 · CNA: redhat · CVSS v3.1 · 17 references · NVD status: Modified
Comfy-Org ComfyUI — ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0078   53.2     —
AFFECTED
  Product  Versions     Fixed
  ComfyUI  unspecified  —
TIMELINE
  Jul 31  Reserved by CNA
  Jul 31  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
codeigniter4 CodeIgniter4 — CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.5     —
AFFECTED
  Product       Versions   Fixed
  CodeIgniter4  < 4.7.4 –  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 31  Published (CNA: GitHub_M)
CWE-434 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Received
Comfy-Org ComfyUI — ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0066   48.9     —
AFFECTED
  Product  Versions    Fixed
  ComfyUI  < 0.28.0 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 31  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Received
n/a n/a — An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0066   48.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-94 · CNA: mitre · CVSS v3.1 · 4 references · NVD status: Received
n/a n/a — An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0063   47.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-284 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Authenticated (Subscriber+) Arbitrary File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0061   46.5     —
AFFECTED
  Product                                        Versions     Fixed
  Realtyna Organic IDX plugin + WPL Real Estate  unspecified  —
TIMELINE
  Jul 19  Reserved by CNA
  Jul 31  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
Apache Software Foundation Apache Zeppelin — Path traversal in NotebookRepo note and folder path composition
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0058   44.9     —
AFFECTED
  Product          Versions  Fixed
  Apache Zeppelin  0.9.0 –   —
TIMELINE
  May 7   Reserved by CNA
  Jul 31  Published (CNA: apache)
CWE-22 · CNA: apache · CVSS v3.1 · 4 references · NVD status: Analyzed
WebPros cPanel — HTTP Smuggling in cPanel allows potential leak of credentials.
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   L   L   N    5.6   .0053   42.7     —
AFFECTED
  Product     Versions     Fixed
  cPanel      unspecified  —
  WP Squared  unspecified  —
TIMELINE
  Jun 27  Reserved by CNA
  Jul 31  Published (CNA: hackerone)
CWE-444 · CNA: hackerone · CVSS v4.0 · 2 references · NVD status: Received
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8 — 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0053   42.2     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Directory Server 11.7 E4S for RHEL 8                           unspecified  8080020260806114250.f969626e
  Red Hat Directory Server 11.9 for RHEL 8                               unspecified  8100020260803140625.37ed7c03
  Red Hat Directory Server 12.2 E4S for RHEL 9                           unspecified  9020020260730155601.1674d574
  Red Hat Directory Server 12.4 E4S for RHEL 9                           unspecified  9040020260810131422.1674d574
  Red Hat Enterprise Linux 10                                            unspecified  0:3.2.0-9.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.0.6-20.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.3.11.1-14.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  8100020260806150504.25e700aa
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  8040020260803141511.96015a92
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  8040020260803141511.96015a92
  + 11 more
TIMELINE
  Jun 9   Reserved by CNA
  Jul 31  Published (CNA: redhat)
CWE-90 · CNA: redhat · CVSS v3.1 · 18 references · NVD status: Modified
Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0052   41.9     —
AFFECTED
  Product        Versions  Fixed
  Apache Kyuubi  1.6.0 –   —
TIMELINE
  Jul 14  Reserved by CNA
  Jul 31  Published (CNA: apache)
CWE-22, CWE-27 · CNA: apache · CVSS v3.1 · 1 reference · NVD status: Analyzed
Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0052   41.9     —
AFFECTED
  Product                      Versions     Fixed
  gnome-remote-desktop         unspecified  —
  Red Hat Enterprise Linux 10  unspecified  0:49.3-4.el10_2
  Red Hat Enterprise Linux 8   unspecified  —
  Red Hat Enterprise Linux 9   unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Jul 31  Published (CNA: redhat)
CWE-400 · CNA: redhat · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Hugging Face sentence-transformers — sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0052   41.8     —
AFFECTED
  Product                Versions     Fixed
  sentence-transformers  unspecified  —
TIMELINE
  Jul 31  Reserved by CNA
  Jul 31  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
pgadmin.org pgAdmin 4 — pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0049   39.7     —
AFFECTED
  Product    Versions     Fixed
  pgAdmin 4  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 31  Published (CNA: PostgreSQL)
CWE-78, CWE-115 · CNA: PostgreSQL · CVSS v4.0 · 2 references · NVD status: Analyzed
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0048   39.4     —
AFFECTED
  Product                       Versions     Fixed
  Apache HttpComponents Client  5.0-alpha –  —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 31  Published (CNA: apache)
CWE-772 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Modified
Hikvision DS-3WAP521-SI — Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient in…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0046   38.1     —
AFFECTED
  Product         Versions                             Fixed
  DS-3WAP521-SI   V1.1.6601 build251223 and earlier –  —
  DS-3WAP522-SI   V1.1.6601 build251223 and earlier –  —
  DS-3WAP621E-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WAP622E-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WAP623E-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WAP622G-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WG105G-SI   V1.1.6601 build251223 and earlier –  —
  DS-3WG105GP-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WG210GP-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WG507G-SI   V1.1.6601 build251223 and earlier –  —
TIMELINE
  Jul 24  Reserved by CNA
  Jul 31  Published (CNA: hikvision)
CWE-78 · CNA: hikvision · CVSS v3.1 · 1 reference · NVD status: Received
codeigniter4 CodeIgniter4 — CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0045   37.2     —
AFFECTED
  Product       Versions   Fixed
  CodeIgniter4  < 4.7.4 –  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 31  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Received
pgadmin.org pgAdmin 4 — pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0043   35.9     —
AFFECTED
  Product    Versions  Fixed
  pgAdmin 4  1.0 –     —
  pgAdmin 4  5.0 –     —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 31  Published (CNA: PostgreSQL)
CWE-89 · CNA: PostgreSQL · CVSS v4.0 · 3 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-1845210.035.7Rich SourceDMS+ (Non-Mobile)CWE-798Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials
CVE-2026-566737.535.6Comfy-OrgComfyUICWE-22ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary fil…
CVE-2026-535516.935.5free5gcfree5gcCWE-20free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal serv…
CVE-2026-535108.134.6savonrbsavonCWE-94Savon::Model evaluates WSDL operation names as Ruby source
CVE-2026-535037.534.0thumborthumborCWE-20Thumbor convolution filter allows divide-by-zero in C extension leading to re…
CVE-2026-173519.433.6pgadmin.orgpgAdmin 4CWE-89pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL …
CVE-2026-629598.231.1coturncoturnCWE-125Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme…
CVE-2026-551008.731.0kyndryl-open-sourcehashi-vault-jsCWE-23hashi-vault-js has a path traversal and query parameter injection
CVE-2026-127207.530.5UnknownKirkiCWE-502Kirki < 6.0.13 - Unauthenticated PHP Object Injection
CVE-2026-175675.330.4wpmanageninjaFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-639Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via In…
CVE-2026-535734.830.4geonetworkcore-geonetworkCWE-601core-geonetwork has an Open Redirect Bypass
CVE-2026-632219.429.9codeigniter4CodeIgniter4CWE-89CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when u…
CVE-2026-549095.329.8pionstunCWE-20Pion STUN vulnerable to remote denial of service via panic while parsing a ma…
CVE-2026-133927.228.6UnknownElementsKit Elementor AddonsCWE-94ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Cu…
CVE-2026-535028.728.3thumborthumborCWE-22Thumbor has path traversal via post-validation URL decoding bypass in file_lo…
CVE-2026-165049.827.9VPS.orgZulip templateCWE-321VPS.org one-click Zulip template deployment instance contains multiple vulner…
CVE-2026-465945.127.4PHP JabbersPHP Poll ScriptCWE-79Reflected XSS in PHP Poll Script
CVE-2026-106867.527.1zephyrprojectzephyrCWE-835Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet l…
CVE-2026-453765.526.7decidimdecidimCWE-89Decidim: Admin user search allows SQL injection through similarity-based sorting
CVE-2025-699469.826.1n/an/aCWE-89SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injecti…
CVE-2026-528567.525.9pterodactylwingsCWE-129Wings: Maliciously crafted packet during SFTP connection handshake causes den…
CVE-2026-535047.525.9thumborthumborCWE-400Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
CVE-2026-535057.525.9thumborthumborCWE-400Thumbor proportion filter allows unbounded post-transform resize leading to r…
CVE-2026-547259.625.0bank-vaultsvault-secrets-webhookCWE-918vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker UR…
CVE-2026-165039.124.3VPS.orgSupabase templateCWE-1188VPS.org one-click Supabase template deployment instance contains multiple vul…
CVE-2026-653107.524.0ANDRITZHIPASE-250CWE-306Missing authentication and permissive CORS policy
CVE-2026-658415.323.9xdanjoditCWE-80Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses…
CVE-2026-143197.523.8UnknownGiveWPCWE-200GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure
CVE-2026-175619.823.5Innotim Software, Telecommunications and Consulting Trade Ltd. Co.Logsign SIEMCWE-94Unauthenticated RCE in Innotim Software's Logsign SIEM
CVE-2026-438309.823.5tbctbcCWE-77tbc
CVE-2026-535997.523.6redaxocoreCWE-434Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename t…
CVE-2026-173499.323.5pgadmin.orgpgAdmin 4CWE-522pgAdmin 4: Adhoc server clone leaks another user's stored database credential…
CVE-2026-678229.823.3n/an/aCWE-121Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability …
CVE-2026-181418.223.0Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9CWE-295Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via f…
CVE-2025-699489.822.7n/an/aCWE-89SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injecti…
CVE-2026-592325.322.5RoskusProspero Flow CRMCWE-79Stored Cross-site Scripting in Prospero Flow CRM lead name field
CVE-2026-106857.621.8zephyrprojectzephyrCWE-416Use-after-free of GATT subscribe params in Bluetooth host CCC-write response …
CVE-2026-465938.621.7PHP JabbersPHP Poll ScriptCWE-89Authenticated SQL Injection in PHP Poll Script
CVE-2026-173477.721.6pgadmin.orgpgAdmin 4CWE-78pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted usernam…
CVE-2026-143337.521.6UnknownDemiCWE-269Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticat…
CVE-2026-676078.221.5hfiref0xLightFTPCWE-367LightFTP 2.3.1 Race Condition DoS via worker_thread_cleanup
CVE-2026-554976.521.5cloudrevecloudreveCWE-400Cloudreve: Server crash through image decompression/pixel bomb in thumbnail &…
CVE-2026-629997.521.4copier-orgcopierCWE-22Copier: Percent-encoded dot segments in template URLs can allow trusted-prefi…
CVE-2026-183946.921.4AWSStrands Agents ToolsCWE-863Incorrect authorization in Strands Agents Tools http_request proxy credential…
CVE-2026-547298.721.2HackingRepodssrf-jsCWE-918dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
CVE-2026-126958.121.1UnknownminiOrange 2FACWE-287miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret
CVE-2026-528559.920.9pterodactylwingsCWE-200Wings exposes node configuration secrets through egg configuration-file templ…
CVE-2026-535008.220.6thumborthumborCWE-918Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing h…
CVE-2026-184816.220.1AWSAWS Ops WheelCWE-79Stored XSS in Participant URL Field leads to Account Takeover via Session Tok…
CVE-2026-216624.819.9Johnson ControlsFM Systems EmployeeCWE-434FMS Employee Allows Upload of Unrestricted Files
CVE-2025-676508.619.8PHP JabbersAppointment SchedulerCWE-89Authenticated SQL Injection in PHP Jabbers scripts
CVE-2026-453304.919.8decidimdecidimCWE-639Decidim: Verification admins can access supplied IDs from other organisations
CVE-2026-547686.919.6wp-graphqlwp-graphqlCWE-204WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that l…
CVE-2026-149199.819.6UnknownShopMonitor.ioCWE-287ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via P…
CVE-2026-519537.419.5n/an/aCWE-613An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via th…
CVE-2025-676499.319.2PHP JabbersCar Rental ScriptCWE-89Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script
CVE-2026-453776.519.2decidimdecidimCWE-200Decidim: Private exports can be downloaded through reusable links
CVE-2026-653115.318.5ANDRITZHIPASE-250CWE-284Missing authentication for logging-configuration endpoint
CVE-2026-127218.617.6UnknownKirkiCWE-89Kirki < 6.0.13 - Unauthenticated SQL Injection
CVE-2026-547377.317.6phun-kydefaults-deepCWE-1321@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive P…
CVE-2026-554954.317.3cloudrevecloudreveCWE-22Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation…
CVE-2026-592315.317.2ccyl13PentestifyCWE-918Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs
CVE-2026-150487.516.9UnknownGeeky BotCWE-200GeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat Hi…
CVE-2026-659817.116.0coturncoturnCWE-639Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user…
CVE-2026-438297.515.5tbctbcCWE-121tbc
CVE-2026-438317.515.5tbctbcCWE-121tbc
CVE-2026-438327.515.5tbctbcCWE-121tbc
CVE-2026-547064.815.3onionshareonionshareCWE-59OnionShare follows symlinks in shared directories, allowing unintended disclo…
CVE-2026-181577.814.9RedHatInsightsyggdrasil-worker-package-managerCWE-88Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote co…
CVE-2026-149307.514.8UnknownJS Help DeskCWE-862JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload
CVE-2026-136098.814.7UnknownFrontend Admin by DynamiAppsCWE-79Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scr…
CVE-2026-173486.914.6pgadmin.orgpgAdmin 4CWE-306pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debu…
CVE-2026-566728.214.4Comfy-OrgComfyUICWE-79ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitiza…
CVE-2026-145418.014.0Googlemcp-toolboxCWE-287Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider
CVE-2026-547075.413.6onionshareonionshareCWE-863OnionShare Receive mode writes uploaded files even when file uploads are disa…
CVE-2026-148336.813.4UnknownLightbox with PhotoSwipeCWE-79Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption …
CVE-2026-184365.313.2mailerpressMailerPress – Newsletter, email marketing & AI automationCWE-862MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Mod…
CVE-2026-184375.313.2mailerpressMailerPress – Newsletter, email marketing & AI automationCWE-862MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates
CVE-2026-122518.113.1UnknownUltimate MemberCWE-269Ultimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Sele…
CVE-2026-566708.212.8Comfy-OrgComfyUICWE-79ComfyUI: Stored XSS via SVG file upload on the /view endpoint
CVE-2026-145546.512.8UnknownCheck & Log EmailCWE-89Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters
CVE-2026-523716.512.8n/an/aCWE-918A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger com…
CVE-2026-184467.512.5fast-urifast-uriCWE-436fast-uri vulnerable to host confusion via backslash authority introducer
CVE-2026-143175.312.4UnknownGiveWPCWE-862GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass
CVE-2026-149286.512.2UnknownJS Help DeskCWE-200JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via check…
CVE-2026-149316.512.2UnknownJS Help DeskCWE-200JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure
CVE-2026-145378.111.9Googlemcp-toolboxCWE-863Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints
CVE-2026-173505.311.9pgadmin.orgpgAdmin 4CWE-862pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
CVE-2026-152588.111.7UnknownProduct Feed Manager For WooCommerceCWE-89Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via…
CVE-2026-145396.611.0Googlemcp-toolboxCWE-770Denial of Service via Unrestricted Payload Buffering in MCP Toolbox
CVE-2026-554964.311.1cloudrevecloudreveCWE-200Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search …
CVE-2026-558253.110.9contaocontaoCWE-22Contao: Possible path traversal in job download URIs
CVE-2026-535018.210.8thumborthumborCWE-347Thumbor has HMAC validation bypass via multiple .replace() calls when removin…
CVE-2026-148307.510.8UnknownFlxWooCWE-287FlxWoo < 3.1.1 - Unauthenticated Payment Bypass
CVE-2026-152275.310.7Checkmk GmbHCheckmkCWE-862Missing Authorization Allows Editing of Foreign Reports
CVE-2026-673502.110.3s9ySerendipityCWE-601Serendipity < 2.6.1 Open Redirect via exit.php
CVE-2026-152096.59.9UnknownJS Help DeskCWE-639JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cr…
CVE-2026-182086.59.9Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: inactive out-of-audience token introspe…
CVE-2026-182063.79.9Red HatRed Hat Build of KeycloakCWE-20Keycloak-services: keycloak-services: client policy source-host wildcard doma…
CVE-2026-438335.39.5tbctbc—tbc
CVE-2026-565685.39.3HCL SoftwareHCL iControlCWE-209HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-555027.19.1cloudrevecloudreveCWE-863Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials
CVE-2026-182094.78.9Red HatRed Hat Build of KeycloakCWE-1288Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in ht…
CVE-2026-182174.78.9Red HatRed Hat Build of KeycloakCWE-20Keycloak-services: keycloak-services: saml http-redirect binding response pre…
CVE-2026-554994.39.0cloudrevecloudreveCWE-863Cloudreve: Broken access control in file event stream leaks activity events f…
CVE-2026-161054.98.9Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: missing per-role authorization on rolec…
CVE-2026-182148.18.5Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: google external access-token exchange b…
CVE-2026-182158.18.3Red HatRed Hat Build of KeycloakCWE-287Keycloak-services: keycloak-services: microsoft external access-token exchang…
CVE-2026-145385.78.2Googlemcp-toolboxCWE-285BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox
CVE-2025-623474.38.1HCLHCL iControlCWE-20HCL iControl was affected by Improper Input Validation vulnerability. It is v…
CVE-2026-182036.57.8Red HatRed Hat Build of KeycloakCWE-863Keycloak-services: keycloak-services: group policy extendchildren matches sib…
CVE-2026-148435.37.7UnknownEvents Made EasyCWE-639Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR
CVE-2026-572323.17.8contaocontaoCWE-918Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Fe…
CVE-2026-623245.47.5xdanjoditCWE-79Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement …
CVE-2026-182115.47.3Red HatRed Hat Build of KeycloakCWE-20Keycloak-services: keycloak-services: secure-client-uris policy bypass via lo…
CVE-2026-148493.77.3UnknownPaid Membership SubscriptionsCWE-552Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exp…
CVE-2026-153813.77.4UnknownWP Go MapsCWE-89WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter
CVE-2026-565705.37.3HCL SoftwareHCL iControlCWE-522HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-653138.17.2ANDRITZHIPASE-250CWE-798Use of hard-coded VNC credentials in the engineering-workstation provisioning
CVE-2026-281444.37.1Flipper CodeWP MapsCWE-201WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability
CVE-2026-255526.36.8TryGhostGhost-CLICWE-348Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header
CVE-2026-565715.36.6HCL SoftwareHCL iControlCWE-209HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-623236.36.5cloudrevecloudreveCWE-863Cloudreve: Unauthorized file write via WOPI view sessions whose access token …
CVE-2026-450865.46.6decidimdecidimCWE-862Decidim: Forms admin question editor lacks authorization
CVE-2025-676516.96.1PHP JabbersAppointment SchedulerCWE-352CSRF in PHP Jabbers scripts
CVE-2026-148623.76.1UnknownSupport GenixCWE-862Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via …
CVE-2026-126975.45.9UnknownwpForo ForumCWE-639wpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR
CVE-2026-148346.55.8UnknownMailgun for WordPressCWE-284Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscr…
CVE-2026-148456.15.6UnknownNewStatPressCWE-79NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget
CVE-2026-123764.35.5UnknownAcademy LMSCWE-639Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_…
CVE-2026-148474.35.5UnknownPaid Membership SubscriptionsCWE-639Paid Member Subscriptions < 3.0.7 - Subscriber+ Payment Data Disclosure via IDOR
CVE-2026-149273.75.6UnknownFluentCart A New Era of eCommerceCWE-639FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes
CVE-2026-558242.64.8contaocontaoCWE-200Contao crawler leaks auth credentials to external hosts
CVE-2026-653097.54.6ANDRITZHIPASE-250CWE-257Storage of passwords in a reversible format
CVE-2026-149294.34.6UnknownJS Help DeskCWE-863JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR
CVE-2026-580393.34.5nodejsnodeCWE-284A flaw in Node.js Permission Model enforcement allows process.report writes (…
CVE-2026-547856.24.5eLyiNgemini-bridgeCWE-22gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with…
CVE-2026-149216.14.3UnknownUltimate Addons for WPBakery Page BuilderCWE-79Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS …
CVE-2026-522326.14.3n/an/aCWE-79A reflected cross-site scripting (XSS) vulnerability in the /logo.asp compone…
CVE-2026-149226.13.9UnknownWP Photo Album PlusCWE-79WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment
CVE-2026-656362.13.6ufirstgroupymlrCWE-93YAML injection via unescaped newlines in ymlr document comments
CVE-2026-346417.83.5AdobePremiereCWE-787Premiere Pro | Out-of-bounds Write (CWE-787)
CVE-2026-81555.43.4UnknownBuddyPressCWE-639BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR
CVE-2026-344954.83.4Johnson ControlsFM Systems EmployeeCWE-79FMS Employee vulnerable to XSS
CVE-2026-344974.83.4Johnson ControlsFM Systems EmployeeCWE-80FMS Employee Vulnerable to HTML Injection
CVE-2026-133933.53.4UnknownElementsKit Elementor AddonsCWE-79ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu M…
CVE-2026-100798.53.2Red HatRed Hat Advanced Cluster Security 4CWE-345Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via …
CVE-2026-509868.83.2n/an/aCWE-352PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Sit…
CVE-2026-632204.83.2codeigniter4CodeIgniter4CWE-348CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
CVE-2026-182185.42.9Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: client not-before revocation ignored wh…
CVE-2026-145408.01.7Googlemcp-toolboxCWE-918Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox
CVE-2026-528575.51.6pterodactylwingsCWE-400Wings: Maliciously or erroneously created parsed config files can cause wings…
CVE-2026-281455.31.3StylemixThemesMasterStudy LMSCWE-345WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability
CVE-2026-565673.31.0HCL SoftwareHCL iControlCWE-15HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-565693.31.0HCL SoftwareHCL iControlCWE-497HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-547873.10.5sigstoresigstore-goCWE-324sigstore-go fails to check signature timestamps against a signing key's valid…
CVE-2026-183214.70.3NTPsecntpsecCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec
CVE-2026-344904.80.2Johnson ControlsXAAP ApplicationCWE-312XAAP Android Data Stored in Unencrypted Database

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-31 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.