boxscore/security
Wednesday, May 20, 2026 · all times UTC← 2026-05-19 · archive · 2026-05-21 →

207 CVEs published May 20, 2026: 29 critical, 72 high, 98 medium, 3 low; 7 in KEV; 1 with a public exploit reference; 5 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 182 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published732186210092563
KEV catalog size1670

29 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux216542664403502720.47.8.0014+164
microsoft15247237319990378275.77.8.0044-23
apple134001022193717.56.2.0037+13
red hat93251782400.07.5.00410
google16220136074418.28.4.0035+15
suse220200000.08.2.0020+2
android0000001500
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco513312096861.58.6.1247+2
fortinet16130028350.07.9.4330-2
ivanti140000334100.0.81040
f51210007150.09.2.3413+1
broadcom02000042100.0.19900
palo alto networks110000141100.0.3207+1
citrix010000191100.0.84470
ubiquiti010100400.08.8.00360
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache415210304016.77.5.0093+1
mozilla5532001300.09.6.0045+5
gitlab02000042100.0.44510
docker000000100
drupal000000500
jenkins000000600
joomla000000100
wordpress000000500
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
progress440400900.07.5.0036+4
adobe14010075375.08.6.2776-2
solarwinds031000113100.09.8.83620
oracle0202004000.07.5.00650
atlassian0000001300
ibm000000700
sap0000001200
servicenow000000200
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
siemens110100100.08.7.0032+1
d-link010000261100.0.89640
hikvision01000021100.01.00000
dahua000000200
qnap000000800
schneider electric000000100
tp-link000000600
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
grafana102727162000.06.5.0033+7
nvidia16167900000.08.4.0059+16
givanz11152760000.08.3.0028+7
python software foundation2141391000.06.0.0042-2
nlnet labs11111280000.06.9.0058+11
patriksimek11118300000.09.8.0081+11
watchguard5110920400.07.1.0025+4
openises101000100000.05.1.0022+10

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2008-4250.987599.9
CVE-2026-41940.979399.99.3
CVE-2026-39987.965899.9
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2024-7399.919499.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2025-29635.896499.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4399710.0.0098
CVE-2026-3381910.0.0084
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-3543110.0.0051
CVE-2026-4282210.0.0049
CVE-2026-4544410.0.0028
CVE-2024-577269.9.6660KEV
Most disclosures (vendor)
VendorCVEs
linux329
microsoft164
google16
nvidia16
red hat14
apple13
givanz11
grafana11
nlnet labs11
patriksimek11
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google4
ivanti4
synacor4
adobe3
fortinet3
smartertools3
solarwinds3
Most-affected ecosystems
EcosystemAdvisories
Maven1
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2024-1708ConnectWise0
CVE-2024-57726n/a0
CVE-2024-57728n/a0
CVE-2024-7399Samsung0
CVE-2025-29635D-Link0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171645
CVE-2021-27102Accellion2021-11-171645
CVE-2021-27101Accellion2021-11-171645
CVE-2021-27103Accellion2021-11-171645
CVE-2021-21017Adobe2021-11-171645
CVE-2021-28550Adobe2021-11-171645
CVE-2021-42013Apache2021-11-171645
CVE-2021-41773Apache2021-11-171645
CVE-2021-30858Apple2021-11-171645
CVE-2021-30860Apple2021-11-171645

Transactions

EXPLOIT PUBLISHEDCVE-2026-40102 (makeplane plane). Public exploit reference added.

Yesterday's Results

207 CVEs published. 25 box scores, 182 table rows — nothing truncated.

CVE-2008-4250AWAITING ENRICHMENT
Microsoft Windows
  CVSS   EPSS    %ile   KEV
  —      .9875   99.9   YES
AFFECTED
  Product  Versions     Fixed
  Windows  unspecified  —
TIMELINE
  May 20  Added to CISA KEV, due Jun 3
  May 20  Published
0 references · KEV due June 3, 2026
CVE-2010-0249AWAITING ENRICHMENT
Microsoft Internet Explorer
  CVSS   EPSS    %ile   KEV
  —      .9188   99.8   YES
AFFECTED
  Product            Versions     Fixed
  Internet Explorer  unspecified  —
TIMELINE
  May 20  Added to CISA KEV, due Jun 3
  May 20  Published
0 references · KEV due June 3, 2026
CVE-2009-3459AWAITING ENRICHMENT
Adobe Acrobat and Reader
  CVSS   EPSS    %ile   KEV
  —      .8658   99.7   YES
AFFECTED
  Product             Versions     Fixed
  Acrobat and Reader  unspecified  —
TIMELINE
  May 20  Added to CISA KEV, due Jun 3
  May 20  Published
0 references · KEV due June 3, 2026
CVE-2010-0806AWAITING ENRICHMENT
Microsoft Internet Explorer
  CVSS   EPSS    %ile   KEV
  —      .8217   99.6   YES
AFFECTED
  Product            Versions     Fixed
  Internet Explorer  unspecified  —
TIMELINE
  May 20  Added to CISA KEV, due Jun 3
  May 20  Published
0 references · KEV due June 3, 2026
Microsoft Defender Denial of Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .6308   99.1   YES
AFFECTED
  Product                                  Versions   Fixed
  Microsoft Defender Antimalware Platform  4.0.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  May 20  Added to CISA KEV, due Jun 3
  May 20  Published (CNA: microsoft)
CWE-400 · CNA: microsoft · 2 references · NVD status: Analyzed · KEV due June 3, 2026
CVE-2009-1537AWAITING ENRICHMENT
Microsoft DirectX
  CVSS   EPSS    %ile   KEV
  —      .5121   98.8   YES
AFFECTED
  Product  Versions     Fixed
  DirectX  unspecified  —
TIMELINE
  May 20  Added to CISA KEV, due Jun 3
  May 20  Published
0 references · KEV due June 3, 2026
Microsoft Defender Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0964   95.1   YES
AFFECTED
  Product                              Versions   Fixed
  Microsoft Malware Protection Engine  1.1.0.0 –  —
TIMELINE
  Apr 16  Reserved by CNA
  May 20  Added to CISA KEV, due Jun 3
  May 20  Published (CNA: microsoft)
CWE-59 · CNA: microsoft · 2 references · NVD status: Analyzed · KEV due June 3, 2026
XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .1956   97.2     —
AFFECTED
  Product        Versions                          Fixed
  xwiki-commons  >= 4.2-milestone-2, < 16.10.17 –  —
TIMELINE
  Jan 15  Reserved by CNA
  May 20  Published (CNA: GitHub_M)
CWE-23 · CNA: GitHub_M · 3 references · NVD status: Deferred
HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   H   H   H    8.5   .0411   89.9     —
AFFECTED
  Product                                 Versions     Fixed
  HP Linux Imaging and Printing Software  unspecified  —
TIMELINE
  May 14  Reserved by CNA
  May 20  Published (CNA: hp)
CWE-77, CWE-78 · CNA: hp · 14 references · NVD status: Modified
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication byp…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0255   83.7     —
AFFECTED
  Product                  Versions                        Fixed
  Triton Inference Server  All versions prior to r26.03 –  —
TIMELINE
  Jan 21  Reserved by CNA
  May 20  Published (CNA: nvidia)
CWE-288 · CNA: nvidia · 3 references · NVD status: Analyzed
ISC BIND 9 — Invalid handling of CLASS != IN
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0187   77.6     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.11.0 –  —
TIMELINE
  Apr 9   Reserved by CNA
  May 20  Published (CNA: isc)
CWE-20, CWE-125, CWE-617, CWE-754, CWE-843, CWE-1287 · CNA: isc · 14 references · NVD status: Modified
HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0181   76.8     —
AFFECTED
  Product                                 Versions     Fixed
  HP Linux Imaging and Printing Software  unspecified  —
TIMELINE
  May 14  Reserved by CNA
  May 20  Published (CNA: hp)
CWE-190, CWE-122 · CNA: hp · 14 references · NVD status: Modified
ISC BIND 9 — Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0154   72.8     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.20.0 –  9.18.0
TIMELINE
  Mar 5   Reserved by CNA
  May 20  Published (CNA: isc)
CWE-416, CWE-825 · CNA: isc · 7 references · NVD status: Modified
ISC BIND 9 — SIG(0) validation during query flood may lead to undefined behavior
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  N  H    5.9   .0139   69.9     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.20.0 –  9.18.28
TIMELINE
  Apr 9   Reserved by CNA
  May 20  Published (CNA: isc)
CWE-362, CWE-416, CWE-367 · CNA: isc · 7 references · NVD status: Modified
Frappe has an Arbitrary File Read via Path Traversal in render_include
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0128   67.6     —
AFFECTED
  Product  Versions      Fixed
  frappe   < 15.105.0 –  —
TIMELINE
  Apr 6   Reserved by CNA
  May 20  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 2 references · NVD status: Deferred
NLnet Labs Unbound — Possible arbitrary code execution during DNSSEC validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.1   .0127   67.4     —
AFFECTED
  Product  Versions  Fixed
  Unbound  1.19.1 –  —
TIMELINE
  May 7   Reserved by CNA
  May 20  Published (CNA: NLnet Labs)
CWE-416, CWE-672 · CNA: NLnet Labs · 7 references · NVD status: Modified
memcached memcached — In memcached before 1.6.42, username data for SASL password database authentication has a timing side chann…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0126   67.2     —
AFFECTED
  Product    Versions     Fixed
  memcached  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  May 20  Published (CNA: mitre)
CWE-208 · CNA: mitre · 8 references · NVD status: Modified
ISC BIND 9 — BIND 9 server memory exhaustion during GSS-API TKEY negotiation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0105   61.4     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.0.0 –   —
TIMELINE
  Feb 23  Reserved by CNA
  May 20  Published (CNA: isc)
CWE-771, CWE-770 · CNA: isc · 14 references · NVD status: Modified
ProSolution WP Client <= 2.0.0 - Unauthenticated Arbitrary File Upload via 'files'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0098   59.2     —
AFFECTED
  Product                Versions     Fixed
  ProSolution WP Client  unspecified  —
TIMELINE
  Apr 17  Reserved by CNA
  May 20  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 10 references · NVD status: Deferred
phenixdigital phoenix_storybook — Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0091   57.0     —
AFFECTED
  Product            Versions                                    Fixed
  phoenix_storybook  0.5.0 –                                     —
  phoenix_storybook  e35379dfe2ef1a71b141899e36f431017c55265d –  —
TIMELINE
  May 13  Reserved by CNA
  May 20  Published (CNA: EEF)
CWE-94 · CNA: EEF · 4 references · NVD status: Deferred
Microsoft Defender Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0085   55.2     —
AFFECTED
  Product                              Versions   Fixed
  Microsoft Malware Protection Engine  1.1.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  May 20  Published (CNA: microsoft)
CWE-122 · CNA: microsoft · 1 reference · NVD status: Analyzed
NLnet Labs Unbound — Heap overflow with multiple NSID, COOKIE, PADDING EDNS options
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0084   54.9     —
AFFECTED
  Product  Versions  Fixed
  Unbound  1.14.0 –  —
TIMELINE
  May 7   Reserved by CNA
  May 20  Published (CNA: NLnet Labs)
CWE-197, CWE-787 · CNA: NLnet Labs · 8 references · NVD status: Modified
Cisco Secure Workload Unauthorized API Access Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  N   10.0   .0083   54.7     —
AFFECTED
  Product                Versions    Fixed
  Cisco Secure Workload  2.2.1.41 –  —
TIMELINE
  Oct 8   Reserved by CNA
  May 20  Published (CNA: cisco)
CWE-306 · CNA: cisco · 1 reference · NVD status: Analyzed
Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8 — 389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0081   54.1     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Directory Server 11.5 E4S for RHEL 8                           unspecified  8060020260609102432.0ca98e7e
  Red Hat Directory Server 11.7 E4S for RHEL 8                           unspecified  8080020260610130252.f969626e
  Red Hat Directory Server 11.9 for RHEL 8                               unspecified  8100020260601104139.37ed7c03
  Red Hat Directory Server 12.2 E4S for RHEL 9                           unspecified  9020020260615123354.1674d574
  Red Hat Directory Server 12.4 E4S for RHEL 9                           unspecified  9040020260611130021.1674d574
  Red Hat Enterprise Linux 10                                            unspecified  0:3.2.0-7.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.0.6-18.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.3.11.1-12.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  8100020260601102239.25e700aa
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  8040020260609102422.96015a92
  + 13 more
TIMELINE
  May 20  Reserved by CNA
  May 20  Published (CNA: redhat)
CWE-770 · CNA: redhat · 20 references · NVD status: Modified
Google Chrome — Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to exe…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0080   53.4     —
AFFECTED
  Product  Versions          Fixed
  Chrome   148.0.7778.179 –  —
TIMELINE
  May 20  Reserved by CNA
  May 20  Published (CNA: Chrome)
CWE-416 · CNA: Chrome · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-436186.152.9RsyncProjectrsyncCWE-125Rsync < 3.4.3 Integer Overflow Information Disclosure
CVE-2026-429598.752.9NLnet LabsUnboundCWE-824Crash during DNSSEC validation of malicious content
CVE-2026-242178.852.4NVIDIABioNeMo FrameworkCWE-29NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cau…
CVE-2026-244258.752.2twigphpTwigCWE-693Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface
CVE-2026-75228.852.1SigmaPluginAdvanced Database Cleaner – PremiumCWE-98Advanced Database Cleaner – Premium <= 4.1.0 - Authenticated (Subscriber+) Lo…
CVE-2026-242149.850.8NVIDIATriton Inference ServerCWE-190NVIDIA Triton Inference Server contains a vulnerability in the DALI backend w…
CVE-2026-242139.850.8NVIDIATriton Inference ServerCWE-125NVIDIA Triton Inference Server contains a vulnerability in the DALI backend w…
CVE-2026-59505.348.6ISCBIND 9CWE-606Unbounded resend loop in BIND 9 resolver
CVE-2026-242087.548.2NVIDIATriton Inference ServerCWE-22NVIDIA Triton Inference Server contains a vulnerability where an attacker cou…
CVE-2026-242097.548.2NVIDIATriton Inference ServerCWE-22NVIDIA Triton Inference Server contains a vulnerability where an attacker cou…
CVE-2026-390477.548.1n/an/aCWE-121Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker…
CVE-2026-400927.547.1nimiqcore-rs-albatrossCWE-252nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify cau…
CVE-2026-443906.947.1NLnet LabsUnboundCWE-407Unbounded name compression in certain cases causes degradation of service
CVE-2026-412926.647.1NLnet LabsUnboundCWE-407Long list of incoming EDNS options degrades performance
CVE-2026-242107.546.0NVIDIATriton Inference ServerCWE-190NVIDIA Triton Inference Server contains a vulnerability where an attacker cou…
CVE-2026-241639.845.6NVIDIATensorRT-LLMCWE-502NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, wher…
CVE-2026-331379.345.6xwikixwiki-platformCWE-862XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
CVE-2026-242188.145.2NVIDIADGX SparkCWE-321NVIDIA DGX OS contains a vulnerability in the factory provisioning process, w…
CVE-2026-425346.945.1NLnet LabsUnboundCWE-440Jostle logic bypass degrades resolution performance
CVE-2026-76379.844.6PixelYourSiteBoostCWE-502Boost <= 2.0.3 - Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_…
CVE-2025-332559.844.3NVIDIATensorRT-LLMCWE-502NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where…
CVE-2026-91029.444.2AltiumAltium Enterprise ServerCWE-22Path Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary…
CVE-2026-477848.143.4memcachedmemcachedCWE-208In memcached before 1.6.42, password data for SASL password database authenti…
CVE-2026-242069.843.4NVIDIATriton Inference ServerCWE-288NVIDIA Triton Inference Server contains a vulnerability where an attacker cou…
CVE-2026-90038.742.9TONNETTPR7308CWE-89TONNET|E-LAN Hybrid Recording System - SQL Injection
CVE-2026-91198.842.8GoogleChromeCWE-122Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 al…
CVE-2026-84698.242.7phenixdigitalphoenix_storybookCWE-770Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_s…
CVE-2026-85989.141.0ZKTecoSSC335-GC2063-Face-0b77 Solution CameraCWE-288Unauthenticated Export Service in ZKTeco CCTV Cameras
CVE-2026-401658.740.7goauthentikauthentikCWE-91authentik: SAML NameID XML Comment Injection Enables Authentication Bypass vi…
CVE-2026-91208.840.6GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a r…
CVE-2026-72849.840.2themewantEasy Elements for Elementor – Addons & Website TemplatesCWE-269Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation v…
CVE-2026-202396.539.6SplunkSplunk EnterpriseCWE-532Sensitive Information Disclosure through Log Files in Splunk Enterprise
CVE-2026-91419.339.4Taiko Network Communications Pte Ltd.AG1000-01A SMS Alert GatewayCWE-306Taiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web Interface
CVE-2026-60726.539.0oliverposOliver POS – A WooCommerce Point of Sale (POS)CWE-639Oliver POS <= 2.4.2.6 - Unauthenticated Authorization Bypass Through User-Con…
CVE-2026-241607.538.5NVIDIATensorRT-LLMCWE-690NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker co…
CVE-2026-201716.838.5CiscoCisco NX-OS SoftwareCWE-670Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vu…
CVE-2026-398507.437.7yiisoftyii2CWE-20Yii 2: Local file inclusion via view parameter name collision
CVE-2026-91399.337.6Taiko Network Communications Pte Ltd.AG1000-01A SMS Alert GatewayCWE-798Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml
CVE-2026-350706.737.5DellSmartFabric Storage SoftwareCWE-77Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Impro…
CVE-2026-470682.337.3phenixdigitalphoenix_storybookCWE-639Cross-session PubSub topic injection via URL parameter in phoenix_storybook
CVE-2026-74724.937.2edmonparkerRead More & AccordionCWE-89Read More & Accordion <= 3.5.7 - Authenticated (Administrator+) SQL Injection…
CVE-2026-91448.436.7Taiko Network Communications Pte Ltd.AG1000-01A SMS Alert GatewayCWE-79Taiko AG1000-01A Rev 7.3/8 Stored XSS via Web Configuration Interface
CVE-2026-201997.236.5CiscoCisco ThousandEyes Enterprise AgentCWE-74A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual…
CVE-2026-436206.935.7RsyncProjectrsyncCWE-125Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()
CVE-2026-202066.334.7CiscoCisco ThousandEyes Enterprise AgentCWE-78Cisco ThousandEyes BrowserBot Command Injection Vulnerability
CVE-2026-242157.534.2NVIDIATriton Inference ServerCWE-400NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, …
CVE-2026-91015.334.3MongoDB, Inc.CompassCWE-1321Prototype pollution in csv parsing
CVE-2026-91506.534.0Red HatRed Hat Enterprise Linux 10CWE-121Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when…
CVE-2026-428347.834.0MicrosoftWindows Admin Center in Azure PortalCWE-59Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
CVE-2026-35925.333.8ISCBIND 9CWE-408Amplification vulnerabilities via self-pointed glue records
CVE-2026-39857.533.7constantcontactCreative Mail – Easier WordPress & WooCommerce Email MarketingCWE-89Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Una…
CVE-2026-473729.132.9RRWOCrypt::SaltedHashCWE-338Crypt::SaltedHash versions through 0.09 for Perl generate insecure random val…
CVE-2026-91128.832.8GoogleChromeCWE-416Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 all…
CVE-2026-91188.832.8GoogleChromeCWE-416Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allo…
CVE-2026-91268.832.8GoogleChromeCWE-416Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a r…
CVE-2026-202406.532.8SplunkSplunk EnterpriseCWE-20Denial of Service through coldToFrozen.sh Script in Splunk Enterprise
CVE-2026-84867.532.7Progress SoftwareMOVEit AutomationCWE-770Allocation of resources without limits or throttling vulnerability in Progres…
CVE-2026-473737.532.5RRWOCrypt::SaltedHashCWE-208Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing att…
CVE-2026-393108.632.3TriliumNextTriliumCWE-284Trilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) Bu…
CVE-2026-223149.031.8MesalvoMeona Client Launcher ComponentCWE-94Improper Control of Generation of Code ('Code Injection') vulnerability in Me…
CVE-2026-64568.831.7beycanpressAccount SwitcherCWE-287Account Switcher <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass…
CVE-2026-241887.531.6NVIDIATensorRTCWE-787NVIDIA TensorRT contains a vulnerability where an attacker could cause an out…
CVE-2026-241429.831.1NVIDIATensorRT-LLMCWE-502NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and …
CVE-2026-449268.830.6n/an/aCWE-284InfoScale CmdServer before 7.4.2 mishandles access control.
CVE-2026-90107.529.7PixelYourSiteBoostCWE-89Boost <= 2.0.3 - Unauthenticated Blind SQL Injection via Multiple Parameters
CVE-2026-91148.829.6GoogleChromeCWE-416Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a …
CVE-2026-91375.129.6mispmispCWE-400CSP Report Endpoint Log Flooding in MISP via Incorrect Size Limit
CVE-2026-84887.529.5Progress SoftwareMOVEit AutomationCWE-770Allocation of resources without limits or throttling vulnerability in Progres…
CVE-2026-28125.329.1EsriArcGIS ServerCWE-287Improper Authentication issue in ArcGIS Server
CVE-2026-86856.528.9infilityInfility GlobalCWE-89Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'o…
CVE-2026-470992.128.9storybookjstelejsonCWE-79TeleJSON < 6.0.0 DOM-based XSS via parse() Function
CVE-2026-74678.828.7edmonparkerRead More & AccordionCWE-269Read More & Accordion <= 3.5.7 - Privilege Escalation via importData
CVE-2025-327507.528.0DellPowerFlex Manager (Appliance)CWE-548Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Informa…
CVE-2026-223157.228.0MesalvoMeona Client Launcher ComponentCWE-266Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher…
CVE-2026-84857.527.8Progress SoftwareMOVEit AutomationCWE-789Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Auto…
CVE-2026-91338.327.4AWSRabbitMQ AWSCWE-489Arbitrary file read in rabbitmq-aws plugin
CVE-2026-429236.926.8NLnet LabsUnboundCWE-407Degradation of service with unbounded NSEC3 hash calculations
CVE-2026-90659.326.7brainstormforceSurecartCWE-89Surecart - SQL Injection
CVE-2026-327924.626.6NLnet LabsUnboundCWE-125Packet of death with DNSCrypt
CVE-2026-91104.226.7GoogleChromeCWE-451Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0…
CVE-2026-452322.126.7RsyncProjectrsyncCWE-193Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy
CVE-2026-52008.826.5acybaAcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressCWE-862AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) P…
CVE-2026-67285.326.0Revolution SliderSlider RevolutionCWE-200Slider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure v…
CVE-2026-91218.825.9GoogleChromeCWE-125Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed…
CVE-2026-74607.424.8mailcowmailcow-dockerizedCWE-79mailcow-dockerized 2026-03b - Stored XSS in Queue Manager via unescaped
CVE-2026-202386.524.8SplunkSplunk AI ToolkitCWE-863Improper Access Control through Role Inheritance in Splunk AI Toolkit app
CVE-2026-63945.424.3wpdiveNexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSECWE-918Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via …
CVE-2026-90878.123.8Red HatRed Hat build of Keycloak 26.4CWE-639Keycloak: cross-session email verification proof not bound to upstream identi…
CVE-2026-91496.523.9Red HatRed Hat Enterprise Linux 10CWE-122Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize f…
CVE-2026-449236.523.5n/an/aCWE-89SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to esca…
CVE-2026-52936.423.5olivesystem診断ジェネレータ作成プラグインCWE-79診断ジェネレータ作成プラグイン <= 1.4.16 - Authenticated (Subscriber+) Stored Cross-Site Scr…
CVE-2026-274056.523.3Magepeople inc.WpBookinglyCWE-862WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability
CVE-2026-394059.422.9frappelmsCWE-22Frappe has Path Transversal via SCORM
CVE-2026-400944.322.8nimiqcore-rs-albatrossCWE-754nimiq-blockchain: network-libp2p untrusted peer can crash address book via em…
CVE-2026-28134.122.6EsriArcGIS ServerCWE-601Unvalidated Redirect in ArcGIS Server
CVE-2026-306916.122.4n/an/aCWE-79Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1…
CVE-2026-401026.522.1makeplaneplaneCWE-943Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics
CVE-2026-91006.022.0MongoDB, Inc.C DriverCWE-1285Heap memory out of bounds read and crash in C Driver legacy GridFS file reader
CVE-2026-86104.321.9conohaTypeSquare Webfonts for ConoHaCWE-862TypeSquare Webfonts for ConoHa <= 2.0.4 - Missing Authorization to Authentica…
CVE-2026-242167.821.4NVIDIABioNeMo FrameworkCWE-502NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a …
CVE-2026-423837.621.4YITHYITH WooCommerce Product Add-OnsCWE-89WordPress YITH WooCommerce Product Add-Ons plugin <= 4.29.0 - SQL Injection v…
CVE-2026-393116.821.2TriliumNextTriliumCWE-79Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) v…
CVE-2026-90599.321.2awesomemotiveNextGEN GalleryCWE-89NextGEN Gallery - SQL Injection
CVE-2026-50754.321.0smubAll in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase TrafficCWE-200All in One SEO <= 4.9.7 - Authenticated (Contributor+) Sensitive Information …
CVE-2026-4544410.020.7WP SwingsGift Cards For WooCommerce ProCWE-434WordPress Gift Cards For WooCommerce Pro plugin <= 4.2.6 - Arbitrary File Upl…
CVE-2026-436176.320.6RsyncProjectrsyncCWE-289Rsync < 3.4.3 Authorization Bypass via Hostname Resolution
CVE-2026-84877.520.5Progress SoftwareMOVEit AutomationCWE-276Incorrect default permissions vulnerability in Progress Software MOVEit Autom…
CVE-2026-74626.119.9vatanyazilimVatanSMS WP SMSCWE-79VatanSMS WP SMS <= 1.01 - Reflected Cross-Site Scripting via 'page' Parameter
CVE-2026-73855.819.3UnknownDecent CommentsDecent Comments < 3.0.2 - Unauthenticated Email Address Disclosure
CVE-2026-42935.319.4Kieback & PeterDDC4002CWE-79Kieback & Peter DDC Building Controllers Cross-site Scripting
CVE-2026-91226.519.1GoogleChromeCWE-125Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 all…
CVE-2026-86246.118.8etspringLJ comments import: reloadedCWE-79LJ comments import: reloaded <= 0.97.1 - Reflected Cross-Site Scripting via P…
CVE-2026-86266.118.8owencutajarSponsorMeCWE-79SponsorMe <= 0.5.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter
CVE-2026-91177.518.5GoogleChromeCWE-843Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778…
CVE-2026-218366.518.4HCLSoftwareDominoIQCWE-862HCL DominoIQ is affected by broken access control
CVE-2026-65664.318.4smubPhoto Gallery, Sliders, Proofing and Themes – NextGEN GalleryCWE-639Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object…
CVE-2026-90578.217.9TalendTalend Administration CenterSecurity fix for Qlik Talend Administration Center URL access control vulnera…
CVE-2026-91245.317.9GoogleChromeCWE-20Insufficient validation of untrusted input in Input in Google Chrome on prior…
CVE-2026-76137.217.3pixelyoursiteCost of Goods by PixelYourSiteCWE-79Cost of Goods by PixelYourSite <= 1.2.12 - Unauthenticated Stored Cross-Site …
CVE-2026-446084.617.3NLnet LabsUnboundCWE-413Use after free and crash under special conditions in RPZ code
CVE-2026-57766.116.8UnknownEmail EncoderEmail Encoder < 2.4.7 - Unauthenticated Stored XSS
CVE-2026-429605.716.5NLnet LabsUnboundCWE-349Possible cache poisoning via promiscuous records for the authority section
CVE-2026-443925.316.5Six Apart Ltd.Movable TypeCWE-862Missing authorization vulnerability exists in Movable Type. Under certain con…
CVE-2025-153695.316.4xproXpro Addons — 140+ Widgets for ElementorCWE-862Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 - Missing Authorization to …
CVE-2026-80386.416.0mcinvaleFaces of UsersCWE-79Faces of Users <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-63976.416.0cvmhStickyCWE-79Sticky <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…
CVE-2026-65496.416.0goback2Logo Manager For EnamadCWE-79Logo Manager For Enamad <= 0.7.4 - Authenticated (Contributor+) Stored Cross-…
CVE-2026-260286.115.6cryptpadcryptpadCWE-79CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection a…
CVE-2026-91299.415.2AltiumAltium Enterprise ServerCWE-22Path Traversal in Altium Enterprise Server Viewer StorageController Allows Ar…
CVE-2026-64044.415.2simonhollidayAnomify AI – Anomaly Detection and AlertingCWE-79Anomify AI <= 0.3.6 - Authenticated (Administrator+) Stored Cross-Site Script…
CVE-2026-399605.414.0mantisbtmantisbtCWE-79MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Values
CVE-2026-63994.414.0yog2515General OptionsCWE-79General Options <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site S…
CVE-2026-91368.314.0mispmispCWE-639Unauthorized ShadowAttribute modification in MISP via client-supplied identifier
CVE-2026-350145.113.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter
CVE-2026-57837.613.5Beyaz Computer Software Design Industry and Trade Ltd. Co.CityPLusCWE-79Reflected XSS in Beyaz Computer's CityPLus
CVE-2026-91154.313.3GoogleChromeCWE-693Insufficient policy enforcement in Service Worker in Google Chrome on prior t…
CVE-2026-29556.413.2wupsalesAI Chatbot & Workflow Automation by AIWUCWE-79AI Chatbot & Workflow Automation by AIWU <= 1.4.14 - Unauthenticated Stored C…
CVE-2026-86276.112.9lykichCorrect PricesCWE-79Correct Prices <= 1.0 - Reflected Cross-Site Scripting via PHP_SELF Parameter
CVE-2026-350075.112.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parameter
CVE-2026-350085.112.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter
CVE-2026-350095.112.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter
CVE-2026-350105.112.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter
CVE-2026-350115.112.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter
CVE-2026-350125.112.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter
CVE-2026-350135.112.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via street_view.php thelat and theln…
CVE-2026-350155.112.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Para…
CVE-2026-350165.112.9openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter
CVE-2026-449338.512.7SUSESUSE Linux EnterpriseCWE-35Path Traversal in Plugin Loading in libzypp
CVE-2026-91134.312.5GoogleChromeCWE-125Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 all…
CVE-2026-91164.312.5GoogleChromeCWE-693Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to…
CVE-2026-449245.411.2n/an/aCWE-79InfoScale VIOM 9.1.3 allows XSS.
CVE-2026-274244.311.0WP ChillImage Photo Gallery Final Tiles GridCWE-862WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Broken Acce…
CVE-2026-225547.810.2MediaAreaMediaInfoLibCWE-122MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerabi…
CVE-2026-449258.810.0n/an/aCWE-352Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operatio…
CVE-2026-454435.09.5ADD-ONS.ORGPDF for Elementor Forms + Drag And Drop Template BuilderCWE-862WordPress PDF for Elementor Forms + Drag And Drop Template Builder plugin <= …
CVE-2026-84194.39.1submoneAmazon ScraperCWE-352Amazon Scraper <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scrip…
CVE-2026-91237.58.6GoogleChromeCWE-122Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, Chrome…
CVE-2026-64014.38.6svil4okBottom BarCWE-352Bottom Bar <= 0.1.7 - Cross-Site Request Forgery to Settings Update
CVE-2026-410547.88.3SUSEContainer suse/sle-micro-rancher/5.3:latestCWE-305Missing exit out of permission check in haveged could lead to root exploit
CVE-2026-90846.08.1mispmispCWE-287MISP OIDC authentication bypass via automatic email-based account linking und…
CVE-2026-84234.37.7javibolaJaviBola Custom Theme TestCWE-352JaviBola Custom Theme Test <= 2.0.5 - Cross-Site Request Forgery
CVE-2025-319739.87.6HCLBigFix Service Management (SM)CWE-1395HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insec…
CVE-2026-90565.47.7TalendTalend Administration CenterSecurity fix for Qlik Talend Administration Center cross-site scripting vulne…
CVE-2026-63916.17.1eazyserverSentence To SEO (keywords, description and tags)CWE-352Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request …
CVE-2026-84206.17.1rdbeachBLOGCHAT Chat SystemCWE-352BLOGCHAT Chat System <= 1.3.6.3 - Cross-Site Request Forgery to Stored Cross-…
CVE-2026-64054.36.5simonhollidayAnomify AI – Anomaly Detection and AlertingCWE-352Anomify AI <= 0.3.6 - Cross-Site Request Forgery
CVE-2025-119548.06.3Sitemio Information Technologies Trade Ltd. Co.WISECPCWE-352CSRF in Sitemio's WISECP
CVE-2026-245736.56.4ThemeisleVisualizerCWE-79WordPress Visualizer plugin < 4.0.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-64004.36.0helpstringChild Height Predictor by OstheimerCWE-352Child Height Predictor by Ostheimer <= 1.3 - Cross-Site Request Forgery to Se…
CVE-2026-84184.36.0askywhaleGames CatalogCWE-352Games Catalog <= 1.2.0 - Cross-Site Request Forgery to Arbitrary Game/Post De…
CVE-2026-64524.35.5ktulhuBigfishgames SyndicateCWE-352Bigfishgames Syndicate <= 1.2 - Cross-Site Request Forgery to Settings Reset …
CVE-2026-84244.35.5jay_patelRemove Yellow BGBOXCWE-352Remove Yellow BGBOX <= 1.0 - Cross-Site Request Forgery
CVE-2025-319856.55.4HCLBigFix Service Management (SM)CWE-200HCL BigFix Service Management (SM) is affected by a security misconfiguration…
CVE-2026-63956.15.0winkingWord 2 CashCWE-352Word 2 Cash <= 0.9.2 - Cross-Site Request Forgeryto Stored Cross-Site Scripti…
CVE-2026-295187.34.9RsyncProjectrsyncCWE-367Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
CVE-2023-73464.13.9LedgerLedger Bitcoin appCWE-682Ledger Bitcoin App 2.1.0 Address Derivation Error via Miniscript
CVE-2026-436197.23.5RsyncProjectrsyncCWE-59Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls
CVE-2026-406226.63.5NLnet LabsUnboundCWE-346Another 'ghost domain names' attack variant
CVE-2026-477824.63.2Siber Systems, Inc.Android App "RoboForm Password Manager"CWE-357Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handl…
CVE-2026-08567.82.7MesalvoMeona Client Launcher ComponentCWE-284Improper Access Control vulnerability in Mesalvo Meona Client Launcher Compon…
CVE-2026-08576.01.0MesalvoMeona Client Launcher ComponentCWE-316Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo…
CVE-2026-256024.40.5MesalvoMeona Client Launcher ComponentCWE-345Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-20 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.