boxscore/security
Friday, May 22, 2026 · all times UTC← 2026-05-21 · archive · 2026-05-23 →

148 CVEs published May 22, 2026: 25 critical, 52 high, 61 medium, 10 low; 1 in KEV; 5 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 123 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1067219710102563
KEV catalog size1670

38 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux224550674463602720.47.8.0014+129
microsoft16448443325990378275.67.8.0045-14
apple134001022193717.56.2.0037+13
red hat93251782400.07.5.0041-2
google16220136074418.28.4.0035+15
freebsd770520000.07.8.0020+7
suse220200000.08.2.0020+2
android0000001500
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco513312096861.58.6.1247+2
fortinet16130028350.07.9.4330-2
ivanti25010033480.08.8.8056+1
f52320007133.39.2.0996+2
ubiquiti231200400.08.8.0068+2
broadcom02000042100.0.19900
palo alto networks110000141100.0.3207+1
citrix010000191100.0.84470
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache920412404015.07.5.0090+6
mozilla5532001300.09.6.0045+5
docker330300100.08.8.0022+3
drupal3310205133.35.1.0021+3
gitlab02000042100.0.44510
jenkins000000600
joomla000000100
wordpress000000500
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
progress440400900.07.5.0036+4
adobe14010075375.08.6.2776-2
solarwinds031000113100.09.8.83620
oracle0202004000.07.5.00650
zohocorp110100000.08.4.0170+1
atlassian0000001300
ibm000000700
sap0000001200
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
siemens110100100.08.7.0032+1
d-link010000261100.0.89640
hikvision01000021100.01.00000
dahua000000200
qnap000000800
schneider electric000000100
tp-link000000600
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44
open ises3737214210000.06.9.0021+37
netatalk3333113910000.06.4.0030+33
grafana102727162000.06.5.0033+7
dell121806110215.66.7.0019+7
nvidia16167900000.08.4.0059+16
trend micro1616213101216.37.8.0030+16
givanz11152760000.08.3.0028+7

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2008-4250.987599.9
CVE-2026-41940.979399.99.3
CVE-2026-39987.965899.9
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2024-7399.919499.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2025-29635.896499.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4399710.0.0098
CVE-2026-3381910.0.0084
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-3543110.0.0051
CVE-2026-4659510.0.0050
CVE-2026-4282210.0.0049
CVE-2026-3371210.0.0035
Most disclosures (vendor)
VendorCVEs
linux294
microsoft173
concrete cms44
open ises37
netatalk33
google16
nvidia16
trend micro16
apache15
apple13
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google4
ivanti4
synacor4
adobe3
fortinet3
smartertools3
solarwinds3
Most-affected ecosystems
EcosystemAdvisories
Maven4
PyPI1
npm1
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2024-1708ConnectWise0
CVE-2024-57726n/a0
CVE-2024-57728n/a0
CVE-2024-7399Samsung0
CVE-2025-29635D-Link0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171647
CVE-2021-27102Accellion2021-11-171647
CVE-2021-27101Accellion2021-11-171647
CVE-2021-27103Accellion2021-11-171647
CVE-2021-21017Adobe2021-11-171647
CVE-2021-28550Adobe2021-11-171647
CVE-2021-42013Apache2021-11-171647
CVE-2021-41773Apache2021-11-171647
CVE-2021-30858Apple2021-11-171647
CVE-2021-30860Apple2021-11-171647

Transactions

EXPLOIT PUBLISHEDCVE-2026-32253 (LizardByte Sunshine). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-40610 (BentoML). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-41069 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-41071 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5072 (zephyrproject-rtos Zephyr). Public exploit reference added.

Yesterday's Results

148 CVEs published. 25 box scores, 123 table rows — nothing truncated.

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .8832   99.8   YES
AFFECTED
  Product      Versions  Fixed
  Drupal core  8.9.0 –   —
TIMELINE
  May 20  Reserved by CNA
  May 22  Added to CISA KEV, due May 27
  May 22  Published (CNA: drupal)
CWE-89 · CNA: drupal · 2 references · NVD status: Analyzed · KEV due May 27, 2026
F5 NGINX Plus — NGINX ngx_http_rewrite_module vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0996   95.2     —
AFFECTED
  Product            Versions  Fixed
  NGINX Plus         37.0 –    —
  NGINX Open Source  1.31.0 –  —
TIMELINE
  May 21  Reserved by CNA
  May 22  Published (CNA: f5)
CWE-122 · CNA: f5 · 14 references · NVD status: Analyzed
cssigniterteam AudioIgniter Music Player — AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference to 'audioigniter_playlist_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0157   73.2     —
AFFECTED
  Product                    Versions     Fixed
  AudioIgniter Music Player  unspecified  —
TIMELINE
  May 15  Reserved by CNA
  May 22  Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · 5 references · NVD status: Deferred
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network and high privileges could exploit an Improper Input Validation…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0125   66.8     —
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
TIMELINE
  Mar 17  Reserved by CNA
  May 22  Published (CNA: hackerone)
CWE-20 · CNA: hackerone · 1 reference · NVD status: Analyzed
Microsoft Planetary Computer Pro Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0092   57.4     —
AFFECTED
  Product                                        Versions  Fixed
  Microsoft Planetary Computer Pro (GeoCatalog)  - –       —
TIMELINE
  Apr 16  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-502 · CNA: microsoft · 1 reference · NVD status: Analyzed
n/a n/a — Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive info…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0087   55.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 22  Published (CNA: mitre)
CWE-22 · CNA: mitre · 1 reference · NVD status: Deferred
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0085   55.1     —
AFFECTED
  Product      Versions  Fixed
  shell-quote  1.1.0 –   —
TIMELINE
  May 22  Reserved by CNA
  May 22  Published (CNA: harborist)
CWE-77, CWE-78 · CNA: harborist · 34 references · NVD status: Deferred
n/a n/a — Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0072   50.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 22  Reserved by CNA
  May 22  Published (CNA: mitre)
CWE-22 · CNA: mitre · 1 reference · NVD status: Awaiting Analysis
techjewel FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution — FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  L  L  N    5.4   .0069   50.0     —
AFFECTED
  Product                                                                                                      Versions     Fixed
  FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  May 22  Published (CNA: Wordfence)
CWE-918 · CNA: Wordfence · 8 references · NVD status: Deferred
Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   50.0     —
AFFECTED
  Product     Versions  Fixed
  Apache CXF  4.2.0 –   —
TIMELINE
  May 8   Reserved by CNA
  May 22  Published (CNA: apache)
CWE-90 · CNA: apache · 6 references · NVD status: Modified
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerabilit…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0068   49.4     —
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
  UDM              unspecified  —
  UDM-Pro          unspecified  —
  UDM-SE           unspecified  —
  UDM-Pro-Max      unspecified  —
  UDM-Beast        unspecified  —
  EFG              unspecified  —
  UDW              unspecified  —
  UDR              unspecified  —
  UDR7             unspecified  —
  + 21 more
TIMELINE
  Mar 31  Reserved by CNA
  May 22  Published (CNA: hackerone)
CWE-22 · CNA: hackerone · 1 reference · NVD status: Analyzed
Go standard library net/http — Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  N    9.6   .0066   48.4     —
AFFECTED
  Product                  Versions     Fixed
  net/http                 unspecified  —
  net/http/internal/http2  unspecified  —
  golang.org/x/net/idna    unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  May 22  Published (CNA: Go)
CWE-1289 · CNA: Go · 120 references · NVD status: Modified
Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0064   47.7     —
AFFECTED
  Product     Versions  Fixed
  Apache CXF  4.2.0 –   —
TIMELINE
  May 6   Reserved by CNA
  May 22  Published (CNA: apache)
CWE-20, CWE-15 · CNA: apache · 5 references · NVD status: Modified
golang.org/x/crypto golang.org/x/crypto/ssh — Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0062   46.9     —
AFFECTED
  Product                  Versions     Fixed
  golang.org/x/crypto/ssh  unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  May 22  Published (CNA: Go)
CWE-119, CWE-772 · CNA: Go · 51 references · NVD status: Modified
golang.org/x/crypto golang.org/x/crypto/ssh/agent — Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0060   45.9     —
AFFECTED
  Product                        Versions     Fixed
  golang.org/x/crypto/ssh/agent  unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  May 22  Published (CNA: Go)
CWE-502, CWE-281 · CNA: Go · 36 references · NVD status: Modified
Microsoft Azure Stack HCI — Azure Stack HCI Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0058   44.9     —
AFFECTED
  Product          Versions  Fixed
  Azure Stack HCI  - –       —
TIMELINE
  Feb 11  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-20 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Power Pages Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0058   44.8     —
AFFECTED
  Product                Versions  Fixed
  Microsoft Power Pages  - –       —
TIMELINE
  Jan 14  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-77 · CNA: microsoft · 1 reference · NVD status: Analyzed
golang.org/x/crypto golang.org/x/crypto/ssh/knownhosts — Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0057   44.4     —
AFFECTED
  Product                             Versions     Fixed
  golang.org/x/crypto/ssh/knownhosts  unspecified  —
TIMELINE
  Apr 28  Reserved by CNA
  May 22  Published (CNA: Go)
CWE-295 · CNA: Go · 41 references · NVD status: Modified
ivanti Secure Access Client — An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remo…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0056   44.2     —
AFFECTED
  Product               Versions     Fixed
  Secure Access Client  unspecified  22.8R6
TIMELINE
  May 19  Reserved by CNA
  May 22  Published (CNA: ivanti)
CWE-295 · CNA: ivanti · 1 reference · NVD status: Analyzed
Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0055   43.5     —
AFFECTED
  Product                               Versions  Fixed
  Microsoft Global Secure Access (GSA)  - –       —
TIMELINE
  Jan 14  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-269 · CNA: microsoft · 1 reference · NVD status: Analyzed
themewant Easy Elements for Elementor – Addons & Website Templates — Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0054   43.0     —
AFFECTED
  Product                                                   Versions     Fixed
  Easy Elements for Elementor – Addons & Website Templates  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  May 22  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · 5 references · NVD status: Deferred
goauthentik authentik — authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuser
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0053   42.6     —
AFFECTED
  Product    Versions       Fixed
  authentik  < 2025.12.5 –  —
TIMELINE
  Apr 9   Reserved by CNA
  May 22  Published (CNA: GitHub_M)
CWE-269 · CNA: GitHub_M · 3 references · NVD status: Deferred
Microsoft Azure Orbital Spatio — Azure Orbital Spatio Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.6     —
AFFECTED
  Product               Versions  Fixed
  Azure Orbital Spatio  - –       —
TIMELINE
  Apr 13  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-434 · CNA: microsoft · 1 reference · NVD status: Analyzed
golang.org/x/crypto golang.org/x/crypto/ssh — Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0053   42.1     —
AFFECTED
  Product                  Versions     Fixed
  golang.org/x/crypto/ssh  unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  May 22  Published (CNA: Go)
CWE-190 · CNA: Go · 4 references · NVD status: Analyzed
Microsoft Azure Virtual Network Gateway — Azure Virtual Network Gateway Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0053   42.1     —
AFFECTED
  Product                        Versions  Fixed
  Azure Virtual Network Gateway  - –       —
TIMELINE
  Apr 13  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-20 · CNA: microsoft · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-398355.340.8golang.org/x/cryptogolang.org/x/crypto/sshCWE-295Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto…
CVE-2026-4659510.040.8golang.org/x/cryptogolang.org/x/crypto/sshCWE-863Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org…
CVE-2026-428277.540.7MicrosoftMicrosoft 365 CopilotCWE-77M365 Copilot Information Disclosure Vulnerability
CVE-2026-405977.640.5mantisbtmantisbtCWE-79MantisBT has a Content Security Policy bypass via attachments
CVE-2026-472809.840.2MicrosoftAzure Resource ManagerCWE-287Azure Resource Manager Elevation of Privilege Vulnerability
CVE-2026-467278.139.2ruby-langRubyCWE-362An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a…
CVE-2026-338439.838.9MicrosoftMicrosoft EntraCWE-288Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
CVE-2026-465977.538.9golang.org/x/cryptogolang.org/x/crypto/sshCWE-704Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
CVE-2026-398297.538.5golang.org/x/cryptogolang.org/x/crypto/sshCWE-347Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto…
CVE-2026-90117.538.3metaphorcreationsDitty – Responsive News Tickers, Sliders, and ListsCWE-862Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Informat…
CVE-2026-401667.138.1goauthentikauthentikCWE-200authentik: Non-admin user can retrieve confidential OAuth client_secret via /…
CVE-2026-405986.937.2mantisbtmantisbtCWE-79MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Up…
CVE-2026-354308.835.5MicrosoftAzure Privileged Identity Management (PIM)CWE-639Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability
CVE-2026-362287.335.4n/an/aCWE-120Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacke…
CVE-2026-405967.235.4mantisbtmantisbtCWE-79MantisBT is vulnerable to XSS and potential account takeover via user font fa…
CVE-2026-410909.335.1MicrosoftMicrosoft 365 Copilot for iOSCWE-77Microsoft Copilot Tampering Vulnerability
CVE-2026-398319.135.1golang.org/x/cryptogolang.org/x/crypto/sshCWE-862Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/…
CVE-2026-406077.534.9mantisbtmantisbtCWE-79MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Column
CVE-2026-398339.134.4golang.org/x/cryptogolang.org/x/crypto/ssh/agentCWE-862Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
CVE-2026-465985.334.4golang.org/x/cryptogolang.org/x/crypto/ssh/agentCWE-129Invoking pathological inputs can lead to client panic in golang.org/x/crypto/…
CVE-2026-411495.333.3mermaid-jsmermaidCWE-94Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML …
CVE-2026-32948.733.0TP-Link Systems Inc.Archer RE650 v1CWE-862Authentication Logic Vulnerability on Multiple TP-Link Range Extenders
CVE-2026-410768.132.3bestpracticalrtCWE-287RT: LDAP authentication bypass via empty password
CVE-2026-92917.531.2AWSAmazon Braket Python SDKCWE-502Insecure Deserialization in Amazon Braket SDK Job Results Processing
CVE-2026-398286.330.0golang.org/x/cryptogolang.org/x/crypto/sshCWE-295Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
CVE-2026-411478.728.0nukevietnukevietCWE-79NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side …
CVE-2026-3371210.027.7baptisteArnotypebot.ioCWE-862TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint …
CVE-2022-312317.527.6DellECSCWE-284Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Ide…
CVE-2026-410758.827.4bestpracticalrtCWE-89RT: SQL injection via entry_aggregator parameter in JSON search
CVE-2026-57407.527.0MattermostMattermostCWE-789Unauthenticated WebSocket binary frame causes denial of service in Mattermost…
CVE-2026-411485.326.7mermaid-jsmermaidCWE-94Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection
CVE-2026-256806.525.5golang.org/x/netgolang.org/x/net/htmlCWE-400Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
CVE-2026-374707.325.2n/an/aCWE-1021An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary cod…
CVE-2026-90477.624.6DevolutionsServerCWE-305Improper handling of factor key state in the multi-factor authentication mana…
CVE-2026-284446.524.4baptisteArnotypebot.ioCWE-639Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure
CVE-2026-446185.322.9Apache Software FoundationApache CXFCWE-611Apache CXF: XXE vulnerability in WS-Transfer functionality
CVE-2026-410715.122.7strukturaglibheifCWE-125libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequen…
CVE-2026-4290110.022.7MicrosoftMicrosoft EntraCWE-346Microsoft Entra ID Elevation of Privilege Vulnerability
CVE-2026-50726.522.6zephyrproject-rtosZephyrCWE-1335ptp: Potential Denial of Service via PTP Interval Shift
CVE-2026-322539.821.6LizardByteSunshineCWE-287Sunshine: Authentication bypass via improper client certificate validation
CVE-2026-90549.221.79front9frontCWE-130Invalid IP packets cause a kernel panic
CVE-2026-406105.520.9bentomlBentoMLCWE-59BentoML has Information Disclosure in `bentoml build` via symlink traversal i…
CVE-2026-398276.520.4golang.org/x/cryptogolang.org/x/crypto/sshCWE-924Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/…
CVE-2026-86845.320.3jetmonstersMotoPress Hotel BookingCWE-862MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated A…
CVE-2026-399708.520.1baptisteArnotypebot.ioCWE-79TypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Pic…
CVE-2026-90536.920.19front9frontCWE-434Mothra would respect a default value given by a website for HTML file upload …
CVE-2026-48347.519.7weDevsWP ERP ProCWE-89WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter
CVE-2026-399687.119.3baptisteArnotypebot.ioCWE-284TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint
CVE-2026-68646.118.4manchumaharaCBX 5 Star Rating & ReviewCWE-79CBX 5 Star Rating & Review <= 1.0.7 - Reflected Cross-Site Scripting via 'pag…
CVE-2026-284458.717.5baptisteArnotypebot.ioCWE-79Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in…
CVE-2026-399666.517.4baptisteArnotypebot.ioCWE-863TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTyp…
CVE-2026-362266.117.3n/an/aCWE-79Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.1…
CVE-2026-53087.517.1MattermostMattermostCWE-400Missing request body size limits on Zoom plugin HTTP endpoints
CVE-2026-410696.516.9strukturaglibheifCWE-125libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)
CVE-2026-46464.316.6MattermostMattermostCWE-1287Insufficient input validation in GitHub plugin API causes denial of service
CVE-2026-75096.416.6helgathevikingKIA SubtitleCWE-79KIA Subtitle <= 4.0.1 - [Improper Neutralization of Input During Web Page Gen…
CVE-2026-34816.116.5burlingtonbytesWP Blockade – Visual Page BuilderCWE-79WP Blockade <= 0.9.14 - Reflected Cross-Site Scripting via 'shortcode' Parameter
CVE-2026-84772.716.4DevolutionsServerCWE-841Improper enforcement of the sealed-entry workflow in the entry sensitive-data…
CVE-2026-72494.316.3shapedpluginLocation Weather – WordPress Weather Forecast, AQI, Temperature and Weather WidgetCWE-862Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contribut…
CVE-2022-343637.516.3DellUnisphere for PowerMaxCWE-285Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an autho…
CVE-2026-73257.116.2DevolutionsServerCWE-918Improper authorization in the Active Directory browsing feature in Devolution…
CVE-2026-57556.516.0MattermostMattermostCWE-400Denial of service via crafted TIFF file upload
CVE-2026-402956.115.5heartcombodeviseCWE-601Devise: Open Redirect via Unvalidated `request.referrer` in Timeoutable Sessi…
CVE-2026-399645.415.5baptisteArnotypebot.ioCWE-79TypeBot: Stored XSS via javascript: URI in text bubble links — bot author exe…
CVE-2026-399657.715.2baptisteArnotypebot.ioCWE-918TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks
CVE-2026-342077.615.1baptisteArnotypebot.ioCWE-20TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP …
CVE-2026-76364.314.8smubSlider by Soliloquy – Responsive Image Slider for WordPressCWE-200Slider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclo…
CVE-2026-425066.114.7golang.org/x/netgolang.org/x/net/htmlCWE-79Invoking incorrect handling of namespaced elements in foreign content in gola…
CVE-2026-51714.314.5DevolutionsServerCWE-284Improper access control in the entry activity log feature in Devolutions Serv…
CVE-2026-92649.314.2TrimbleSketchUpCWE-94Cross-Site Scripting in SketchUp Dynamic Components
CVE-2026-92455.014.0DevolutionsServerCWE-601Improper input validation in the external authentication provider flow in Dev…
CVE-2026-25184.314.1wpxpoFastXCWE-862FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited…
CVE-2026-256068.713.3Centralny Instytut Ochrony Pracy - Państwowy Instytut BadawczySTERCWE-89SQL Injection in STER
CVE-2026-86924.313.5registrationformbuilderVedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form BuilderCWE-862Vedrixa Forms <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+)…
CVE-2026-58178.813.3DockerDocker DesktopCWE-829Docker Model Runner container-to-host code execution via unsandboxed trust_re…
CVE-2026-58438.813.3DockerDocker DesktopCWE-829Docker Model Runner container-to-host code execution via MLX-LM model_file im…
CVE-2026-256816.113.2golang.org/x/netgolang.org/x/net/htmlCWE-1021Invoking incorrect handling of character references in DOCTYPE nodes in golan…
CVE-2026-271366.113.2golang.org/x/netgolang.org/x/net/htmlCWE-1021Invoking duplicate attributes can cause XSS in golang.org/x/net/html
CVE-2026-425026.113.2golang.org/x/netgolang.org/x/net/htmlCWE-1021Invoking incorrect handling of HTML elements in foreign content in golang.org…
CVE-2026-91046.412.7dartissDraft ListCWE-79Draft List <= 2.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via…
CVE-2026-92472.412.6DevolutionsServerCWE-778Insufficient logging in the entry export feature in Devolutions Server allows…
CVE-2026-86709.612.3syslink software AGAvantraCWE-613Insecure session handling on metrics web server
CVE-2026-86717.512.3syslink software AGAvantraCWE-532Log Files contain encrypted secrets
CVE-2026-444097.512.3ZTEMU5250CWE-862Information disclosure vulnerability in ZTE MU5250
CVE-2026-92234.311.9DevolutionsServerCWE-284Missing authorization in the vault import feature in Devolutions Server 2026.…
CVE-2026-92244.311.9DevolutionsServerCWE-862Missing authorization in the user profile update feature in Devolutions Serve…
CVE-2026-92464.311.9DevolutionsServerCWE-862Improper access control in the entry documentation and attachment features in…
CVE-2026-64068.811.6DockerDocker DesktopCWE-863Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag
CVE-2026-256082.311.2Centralny Instytut Ochrony Pracy - Państwowy Instytut BadawczySTERCWE-319Lack of traffic encryption in STER
CVE-2026-92515.49.4DevolutionsServerCWE-862Missing authorization in the entry status management feature in Devolutions S…
CVE-2026-86739.19.2syslink software AGAvantraCWE-523Password re-initialization mechanism sends passwords in plain text
CVE-2026-92493.18.5DevolutionsServerCWE-620Unverified password change in Devolutions Server allows an attacker to change…
CVE-2026-399673.18.5baptisteArnotypebot.ioCWE-639TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter
CVE-2026-92482.68.5DevolutionsServerCWE-639Authorization bypass in the entry duplication feature in Devolutions Server a…
CVE-2026-36364.38.3MattermostMattermostCWE-200Sanitize team member data returned by API
CVE-2026-83472.37.3Concrete CMSConcrete CMSCWE-639Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-leve…
CVE-2025-264838.27.0DellPowerFlex Manager (Appliance)CWE-601Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect V…
CVE-2026-46355.37.0MattermostMattermostCWE-362Persistent notification timing attack causing server denial of service
CVE-2026-76154.36.6kasparsdWidget ContextCWE-352Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via '…
CVE-2026-410734.66.3bestpracticalrtCWE-1236RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Ex…
CVE-2026-40704.36.0pftoolAlfie – Feed PluginCWE-352Alfie <= 1.2.1 - Cross-Site Request Forgery to Feed Deletion via 'delete' Par…
CVE-2026-426265.95.7n/an/aCWE-400HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage co…
CVE-2026-408644.35.5jupyterhubjupyterhubCWE-352JupyterHub: Cross-origin form POSTs bypass XSRF
CVE-2026-34737.14.6MattermostMattermostCWE-639Improper file ownership validation in the Boards API allows unauthorised file…
CVE-2026-83532.14.6Concrete CMSConcrete CMSCWE-79Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name i…
CVE-2026-83815.43.9TeamViewerDEX (On-premises)CWE-862Broken Access Control in TeamViewer DEX Platform (On Premises)
CVE-2026-399696.53.9baptisteArnotypebot.ioCWE-287TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification
CVE-2026-89974.83.9vifmvifmCWE-122Heap Buffer Overflow in vifm
CVE-2026-287355.43.7MattermostMattermostCWE-863GitHub OAuth Scope Validation
CVE-2026-426276.23.2n/an/aCWE-190In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumEl…
CVE-2025-327497.52.8DellPowerFlex Manager (Appliance)CWE-276Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Informa…
CVE-2026-92558.42.1AWSKiro CLICWE-862Tool Execution Without Authorization via Piped Stdin in Kiro CLI
CVE-2026-410747.11.9bestpracticalrtCWE-352RT has broken CSRF protection for authenticated users
CVE-2021-215086.71.9DellVxRailCWE-532Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vul…
CVE-2026-398243.31.7golang.org/x/sysgolang.org/x/sys/windowsCWE-190Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-86725.11.2syslink software AGAvantraCWE-1393Default credentials for internal DB
CVE-2025-327465.51.1DellPowerFlex Manager (Appliance)CWE-922Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of…
CVE-2026-83402.31.1Concrete CMSConcrete CMSCWE-352Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveV…
CVE-2025-327515.51.1DellPowerFlex Manager (Appliance)CWE-922Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of…
CVE-2026-256075.70.8Centralny Instytut Ochrony Pracy - Państwowy Instytut BadawczySTERCWE-261Weak password encoding in STER
CVE-2025-327477.80.5DellPowerFlex Manager (Appliance)CWE-266Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege…
CVE-2025-327456.50.3DellPowerFlex Manager (Appliance)CWE-295Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificat…
CVE-2025-463715.50.0DellPowerFlex Manager (Appliance)CWE-327Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or R…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-22 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.