boxscore/security
Monday, May 25, 2026 · all times UTC← 2026-05-24 · archive · 2026-05-26 →

187 CVEs published May 25, 2026: 5 critical, 72 high, 56 medium, 53 low; 0 in KEV; 11 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 162 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1359248910152563
KEV catalog size1670

46 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux226552674483602720.47.8.0014+63
microsoft16448443325990378275.67.8.0045-22
apple134001022193717.56.2.0037+13
red hat93251782400.07.5.0041-2
google16220136074418.28.4.0035+15
freebsd770520000.07.8.0020+7
suse220200000.08.2.0020+2
android0000001500
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco513312096861.58.6.1247+2
fortinet16130028350.07.9.4330-2
ivanti25010033480.08.8.8056+1
f52320007133.39.2.0996+2
ubiquiti231200400.08.8.0068+2
broadcom02000042100.0.19900
palo alto networks110000141100.0.3207+1
citrix010000191100.0.84470
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache18294141004013.47.5.0065+15
mozilla6632101300.08.8.0042+6
docker330300100.08.8.0022+3
drupal3310205133.35.1.0021+3
gitlab02000042100.0.44510
jenkins000000600
joomla000000100
wordpress000000500
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
progress440400900.07.5.0036+4
adobe14010075375.08.6.2776-2
solarwinds031000113100.09.8.83620
oracle0202004000.07.5.00650
zohocorp110100000.08.4.0170+1
atlassian0000001300
ibm000000700
sap0000001200
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link12010026150.08.7.45110
siemens110100100.08.7.0032+1
hikvision01000021100.01.00000
dahua000000200
qnap000000800
schneider electric000000100
tp-link000000600
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44
edimax4444027017100.07.4.0059+44
open ises3737214210000.06.9.0021+37
netatalk3333113910000.06.4.0030+33
totolink292902405000.08.9.0173+29
grafana102727162000.06.5.0033+6
dell121806110215.66.7.0019+7
nvidia16167900000.08.4.0059+16

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2008-4250.987599.9
CVE-2026-41940.979399.99.3
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2024-1708.875699.78.4
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4659510.0.0050
CVE-2026-4282210.0.0049
CVE-2026-3371210.0.0035
CVE-2026-915210.0.0034
CVE-2026-4290110.0.0030
Most disclosures (vendor)
VendorCVEs
linux228
microsoft165
concrete cms44
edimax44
open ises37
netatalk33
totolink29
apache24
google16
nvidia16
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google4
ivanti4
synacor4
adobe3
fortinet3
smartertools3
solarwinds3
Most-affected ecosystems
EcosystemAdvisories
Maven10
crates.io2
npm2
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2024-1708ConnectWise0
CVE-2025-34291Langflow0
CVE-2026-0300Palo Alto Networks0
CVE-2026-20182Cisco0
CVE-2026-31431Linux0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171650
CVE-2021-27102Accellion2021-11-171650
CVE-2021-27101Accellion2021-11-171650
CVE-2021-27103Accellion2021-11-171650
CVE-2021-21017Adobe2021-11-171650
CVE-2021-28550Adobe2021-11-171650
CVE-2021-42013Apache2021-11-171650
CVE-2021-41773Apache2021-11-171650
CVE-2021-30858Apple2021-11-171650
CVE-2021-30860Apple2021-11-171650

Transactions

EXPLOIT PUBLISHEDCVE-2026-2651 (mlflow/mlflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47066 (benoitc hackney). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47067 (benoitc hackney). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47069 (benoitc hackney). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47070 (benoitc hackney). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47071 (benoitc hackney). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47072 (benoitc hackney). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47073 (benoitc hackney). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47075 (benoitc hackney). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47076 (benoitc hackney). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47077 (benoitc hackney). Public exploit reference added.

Yesterday's Results

187 CVEs published. 25 box scores, 162 table rows — nothing truncated.

Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0209   80.1     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0209   80.1     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Edimax BR-6675nD POST Request mp command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0208   79.9     —
AFFECTED
  Product    Versions  Fixed
  BR-6675nD  1.12 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 4 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0200   79.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.0     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.0     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.0     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.0     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.0     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.0     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.0     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.0     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.7     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.7     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.7     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.7     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
FoundDream miniclawd exec.ts ExecTool.execute os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0138   69.9     —
AFFECTED
  Product    Versions                                    Fixed
  miniclawd  2d65665046e2222eeea76cafc8570ed546a8c125 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
FoundDream miniclawd SkillsLoader skills-loader.ts which command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0138   69.9     —
AFFECTED
  Product    Versions                                    Fixed
  miniclawd  2d65665046e2222eeea76cafc8570ed546a8c125 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
DTStack Taier REST API Runtime.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0136   69.5     —
AFFECTED
  Product  Versions  Fixed
  Taier    1.4.0 –   —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 4 references · NVD status: Deferred
Edimax BR-6478AC POST Request formAccept command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0136   69.5     —
AFFECTED
  Product    Versions  Fixed
  BR-6478AC  1.23 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 4 references · NVD status: Deferred
Edimax BR-6478AC POST Request formiNICbasic command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0135   69.2     —
AFFECTED
  Product    Versions  Fixed
  BR-6478AC  1.23 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 4 references · NVD status: Deferred
Edimax EW-7438RPn Content-Type formWlanMP os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.4     —
AFFECTED
  Product     Versions  Fixed
  EW-7438RPn  1.31 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 4 references · NVD status: Deferred
Edimax BR-6675nD stainfo command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.4     —
AFFECTED
  Product    Versions  Fixed
  BR-6675nD  1.12 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 4 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-95112.161.6TotolinkCA750-PoECWE-77Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection
CVE-2026-95122.161.6TotolinkCA750-PoECWE-77Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection
CVE-2026-95132.161.6TotolinkCA750-PoECWE-77Totolink CA750-PoE Setting cstecgi.cgi NTPSyncWithHost os command injection
CVE-2026-470738.755.3benoitchackneyCWE-400Unbounded memory consumption in WebSocket client in hackney
CVE-2018-253658.753.1PCViewerPCViewerCWE-22PCViewer vt1000 Directory Traversal via GET Request
CVE-2018-253748.753.1SoftnetaMedDream PACS Server PremiumCWE-22Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal
CVE-2026-488428.152.4RoundcubeWebmailCWE-89Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenti…
CVE-2026-470668.752.1benoitchackneyCWE-835Infinite loop in Alt-Svc header parser in hackney
CVE-2026-470678.752.1benoitchackneyCWE-770Atom table exhaustion via unrecognized URL schemes in hackney
CVE-2026-470718.252.1benoitchackneyCWE-400SOCKS5 TLS upgrade ignores caller timeout in hackney
CVE-2026-94597.452.0EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formConnectionSetting stack-based overflow
CVE-2026-94607.452.0EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formAccept stack-based overflow
CVE-2026-94617.452.0EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formRadius stack-based overflow
CVE-2026-452496.151.9Apache Software FoundationApache EChartsCWE-79Apache ECharts: XSS in Lines series tooltip rendering
CVE-2026-86528.550.9NEC Platforms, Ltd.Aterm MR51FNCWE-78An OS Command Injection vulnerability exists in Aterm. If a malicious third p…
CVE-2026-470778.250.3benoitchackneyCWE-400Unbounded body accumulation in HTTP/3 response loop in hackney
CVE-2026-427827.248.3Apache Software FoundationApache SyncopeCWE-653Apache Syncope: Post-auth RCE via Groovy static
CVE-2026-94807.448.1EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formrefresh stack-based overflow
CVE-2026-453618.145.4Apache Software FoundationApache Airflow Google providerCWE-322Apache Airflow Google provider: SSH host key verification disabled in Compute…
CVE-2026-94427.445.4EdimaxBR-6478ACCWE-119Edimax BR-6478AC POST Request formiNICSiteSurvey buffer overflow
CVE-2026-94437.445.4EdimaxBR-6478ACCWE-119Edimax BR-6478AC POST Request formL2TPSetup buffer overflow
CVE-2026-94627.445.4EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formWpsProxyEnable stack-based overflow
CVE-2026-94637.445.4EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formLicence stack-based overflow
CVE-2026-94797.445.4EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formLogout stack-based overflow
CVE-2026-94817.445.4EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formStats stack-based overflow
CVE-2026-94827.445.4EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formSDHCP stack-based overflow
CVE-2026-94287.444.9TendaF1202CWE-119Tenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflow
CVE-2026-94297.444.9TendaF1202CWE-119Tenda F1202 WrlExtraSet formWrlExtraSet stack-based overflow
CVE-2026-467455.344.7Apache Software FoundationApache Airflow FAB providerCWE-90Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _searc…
CVE-2026-470726.943.0benoitchackneyCWE-93CRLF injection in WebSocket upgrade request in hackney
CVE-2026-470756.839.3benoitchackneyCWE-93CR/LF injection in query parameter in hackney
CVE-2026-52222.339.2RustCargoCWE-647Cargo can be coerced to share credentials between registries
CVE-2026-94257.437.0EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formWlanMP stack-based overflow
CVE-2026-94267.437.0EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formHwSet stack-based overflow
CVE-2026-94277.437.0EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn webs formWlSiteSurvey stack-based overflow
CVE-2026-83769.836.8SHAYperlCWE-680Perl versions through 5.43.10 have a heap buffer overflow when compiling regu…
CVE-2026-94307.436.5TendaF1202CWE-119Tenda F1202 GstDhcpSetSerof formGstDhcpSetSer stack-based overflow
CVE-2026-94317.436.5TendaF1202CWE-119Tenda F1202 PptpUserAdd fromPptpUserAdd stack-based overflow
CVE-2026-94672.136.5debugmcpmcp-debuggerCWE-22debugmcp mcp-debugger server.ts handleGetSourceContext path traversal
CVE-2026-427974.936.4Apache Software FoundationApache SyncopeCWE-202Apache Syncope: JexlContextBuilder Information Disclosure
CVE-2026-488473.736.1RoundcubeWebmailCWE-669Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-auth…
CVE-2026-470692.135.5benoitchackneyCWE-93CRLF injection in cookie domain/path options in hackney
CVE-2026-488447.534.5RoundcubeWebmailCWE-670Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure cod…
CVE-2026-438275.934.4Apache Software FoundationApache ShiroCWE-384Apache Shiro: Session fixation: new session is not created after login by def…
CVE-2026-249377.234.0VideoWhisper.comBroadcast Live VideoCWE-94WordPress Broadcast Live Video plugin < 7.1.3 - Remote Code Execution (RCE) v…
CVE-2026-488466.533.7RoundcubeWebmailCWE-669In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote i…
CVE-2026-418636.533.0SpringSpring AICWE-22LLM-influenced filename used unsanitized in Path.resolve before file write in…
CVE-2018-253798.832.1OurenergyCollectric CMUCWE-89Collectric CMU 1.0 SQL Injection via lang Parameter
CVE-2026-452168.832.1StoreAppsSmart ManagerCWE-266WordPress Smart Manager plugin <= 8.85.0 - Privilege Escalation vulnerability
CVE-2026-488487.232.0RoundcubeWebmailCWE-79Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient H…
CVE-2018-253688.731.7NordvpnNordVPNCWE-789Nord VPN 6.14.31 Denial of Service via Password Field
CVE-2026-488456.530.9RoundcubeWebmailCWE-669In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, …
CVE-2026-488378.530.4Unlimited ElementsUnlimited Elements For ElementorCWE-89WordPress Unlimited Elements For Elementor plugin <= 2.0.8 - SQL Injection vu…
CVE-2026-427739.330.3eMagicOneeMagicOne Store ManagerCWE-89WordPress eMagicOne Store Manager plugin <= 1.3.2 - SQL Injection vulnerability
CVE-2026-427749.330.3CrocoblockJetEngineCWE-89WordPress JetEngine plugin <= 3.8.8.1 - SQL Injection vulnerability
CVE-2026-470706.030.3benoitchackneyCWE-601HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origi…
CVE-2026-445985.129.8Apache Software FoundationApache Shiro Jakarta EE moduleCWE-601Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid creden…
CVE-2026-94642.029.1YunaiVyudao-cloudCWE-918YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-sid…
CVE-2026-452176.528.3ThemeHighStripe Payment Gateway for WooCommerceCWE-288WordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Aut…
CVE-2026-94665.528.2TiandyEasy7 Integrated Management PlatformCWE-640Tiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword p…
CVE-2026-485890.028.3Apache Software FoundationApache ShiroCWE-601Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login re…
CVE-2026-401275.328.1OutSystemsLifetimeCWE-639Authorization Bypass Through User-Controlled Key in OutSystems Lifetime
CVE-2018-253718.827.8MoosocialmooSocial Store PluginCWE-89mooSocial Store Plugin 2.6 SQL Injection via product parameter
CVE-2026-26519.027.5mlflowmlflow/mlflowCWE-862Missing Authorization Validation in mlflow/mlflow
CVE-2026-277686.627.0Genetec Inc.Genetec Security CenterCWE-89SQL Injection affecting the Access Manager role.
CVE-2026-94972.126.7changmingxietcc-transactionCWE-20changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject …
CVE-2018-253648.826.6FyffePHP-Twitter-CloneCWE-89Twitter-Clone 1 SQL Injection via search.php
CVE-2026-94682.126.6dazebcline-mcp-memory-bankCWE-22dazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversal
CVE-2026-94722.126.6dazebmarkdown-downloaderCWE-22dazeb markdown-downloader index.ts create_subdirectory path traversal
CVE-2026-94732.126.6c-rickjimeng-mcpCWE-22c-rick jimeng-mcp api.ts generateVideo path traversal
CVE-2026-94482.126.5code-projectsEmployee Management SystemCWE-79code-projects Employee Management System applyleave.php cross site scripting
CVE-2026-94382.125.2yashpokharna2555StudentManagementSystemCWE-99yashpokharna2555 StudentManagementSystem courseDel.php resource injection
CVE-2026-488505.924.8PuTTYPuTTYCWE-415PuTTY 0.72 before 0.84 has a double free in RSA KEX.
CVE-2026-94475.524.7SourceCodesterSimple POS and Inventory SystemCWE-74SourceCodester Simple POS and Inventory System search.php sql injection
CVE-2026-94655.524.7TiandyEasy7 Integrated Management PlatformCWE-74Tiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection
CVE-2026-94695.524.7yashpokharna2555StudentManagementSystemCWE-74yashpokharna2555 StudentManagementSystem success.php sql injection
CVE-2026-94705.524.7yashpokharna2555StudentManagementSystemCWE-74yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in …
CVE-2026-94745.524.7yashpokharna2555StudentManagementSystemCWE-74yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql…
CVE-2026-90589.323.6Krajowa Izba RozliczeniowaSzafir SDKCWE-295Improper Certificate Verification in Szafir SDK
CVE-2018-253628.823.5FyffePHP-Twitter-CloneCWE-89Twitter-Clone 1 SQL Injection via follow.php
CVE-2018-253728.823.1MedDreamPACS Server PremiumCWE-89MedDream PACS Server Premium 6.7.1.1 SQL Injection via email
CVE-2026-452097.523.1edward_plainviewMyCryptoCheckoutCWE-862WordPress MyCryptoCheckout plugin <= 2.161 - Broken Access Control vulnerability
CVE-2026-94225.523.0n/aKLiK SocialMediaWebsiteCWE-74KLiK SocialMediaWebsite HTTP POST Request Parameter injection
CVE-2026-245465.322.0Ruben GarciaGamiPressCWE-862WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability
CVE-2026-94982.122.1Dromaralamp-cloudCWE-791Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elem…
CVE-2026-52236.522.0Rust ProjectCargoCWE-61Crates in third party registries can override the cached source of other crates
CVE-2026-94215.521.8n/aKLiK SocialMediaWebsiteCWE-284KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload
CVE-2026-454387.521.4WebToffeeSmart Coupons for WooCommerceCWE-862WordPress Smart Coupons for WooCommerce plugin < 2.3.0 - Broken Access Contro…
CVE-2018-253807.120.9ExtroeXtroFormsCWE-89Joomla Component eXtroForms 2.1.5 SQL Injection via filter parameters
CVE-2018-253817.120.9ExtroResponsive PortfolioCWE-89Joomla Responsive Portfolio 1.6.1 SQL Injection via filter parameters
CVE-2026-49156.520.2MattermostMattermostCWE-754Server panic via outgoing webhook responses
CVE-2026-488523.719.8PuTTYPuTTYCWE-617PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
CVE-2026-438285.919.6Apache Software FoundationApache ShiroCWE-614Apache Shiro: Shiro's native session and rememberMe cookies do not have secur…
CVE-2026-94842.119.5SourceCodesterStudent Grades Management SystemCWE-266SourceCodester Student Grades Management System classroom.php removeStudentFr…
CVE-2026-488437.219.0RoundcubeWebmailCWE-918Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has …
CVE-2026-427636.518.4SePay teamSePay GatewayCWE-862WordPress SePay Gateway plugin <= 1.1.20 - Sensitive Data Exposure vulnerability
CVE-2026-94132.118.3SourceCodesterIndian Invoicing SystemCWE-79SourceCodester Indian Invoicing System category.php cross site scripting
CVE-2026-94152.118.3code-projectsEmployee Management SystemCWE-79code-projects Employee Management System eloginwel.php cross site scripting
CVE-2026-94162.118.3code-projectsEmployee Management SystemCWE-79code-projects Employee Management System myprofile.php cross site scripting
CVE-2026-94172.118.3code-projectsEmployee Management SystemCWE-79code-projects Employee Management System myprofileup.php cross site scripting
CVE-2026-94182.118.3code-projectsEmployee Management SystemCWE-79code-projects Employee Management System changepassemp.php cross site scripting
CVE-2026-94192.118.3code-projectsEmployee Management SystemCWE-79code-projects Employee Management System empproject.php cross site scripting
CVE-2026-94452.118.0SourceCodesterSimple POS and Inventory SystemCWE-284SourceCodester Simple POS and Inventory System File Extension addproduct.php …
CVE-2026-94832.118.0SourceCodesterStudent Grades Management SystemCWE-266SourceCodester Student Grades Management System grades.php improper authoriza…
CVE-2026-77668.317.6KenikKG-5230TAS-IL-3CWE-22Path Traversal in Kenik cameras
CVE-2026-94442.017.6SourceCodesterSimple POS and Inventory SystemCWE-74SourceCodester Simple POS and Inventory System GET Parameter deleteproduct.ph…
CVE-2026-94462.017.6SourceCodesterSimple POS and Inventory SystemCWE-74SourceCodester Simple POS and Inventory System edit_customer.php sql injection
CVE-2026-245865.417.2ThemeansarNewsesCWE-862WordPress Newses theme <= 2.0.0.77 - Broken Access Control vulnerability
CVE-2026-273464.917.1Kings PluginsB2BKingCWE-862WordPress B2BKing plugin < 5.2.10 - Broken Access Control vulnerability
CVE-2026-94712.016.3yashpokharna2555StudentManagementSystemCWE-79yashpokharna2555 StudentManagementSystem student.php cross site scripting
CVE-2026-94852.016.3SourceCodesterStudent Grades Management SystemCWE-79SourceCodester Student Grades Management System students.php cross site scrip…
CVE-2026-94492.116.1code-projectsEmployee Management SystemCWE-74code-projects Employee Management System changepassemp.php sql injection
CVE-2026-94502.116.1code-projectsEmployee Management SystemCWE-74code-projects Employee Management System psubmit.php sql injection
CVE-2026-94512.116.1code-projectsEmployee Management SystemCWE-74code-projects Employee Management System applyleaveprocess.php sql injection
CVE-2026-94202.115.6n/aKLiK SocialMediaWebsiteCWE-74KLiK SocialMediaWebsite HTTP GET Request Parameter injection
CVE-2026-488494.415.1RoundcubeWebmailCWE-79In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitiz…
CVE-2026-245925.314.2Lucian ApostolAuto Affiliate LinksCWE-862WordPress Auto Affiliate Links plugin <= 6.8.8.3 - Broken Access Control vuln…
CVE-2026-273575.314.2Cornel RaiuWP Search AnalyticsCWE-862WordPress WP Search Analytics plugin < 1.5.0 - Broken Access Control vulnerab…
CVE-2026-273985.314.2WP ChillRSVP and Event ManagementCWE-862WordPress RSVP and Event Management plugin <= 2.7.16 - Broken Access Control …
CVE-2026-470766.913.9benoitchackneyCWE-436SSRF allowlist bypass via percent-encoded host in hackney
CVE-2026-488513.113.2PuTTYPuTTYCWE-451PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication fo…
CVE-2026-323895.413.2LinethemesNanoCareCWE-862WordPress NanoCare theme < 1.2.2 - Broken Access Control vulnerability
CVE-2026-427766.310.4WP SunshineSunshine Photo CartCWE-862WordPress Sunshine Photo Cart plugin <= 3.6.7 - Broken Access Control vulnera…
CVE-2026-94122.110.4SourceCodesterIndian Invoicing SystemCWE-266SourceCodester Indian Invoicing System Backend Endpoint access control
CVE-2026-245274.310.2Patterns in the cloudAutoship Cloud for WooCommerce Subscription ProductsCWE-862WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.14…
CVE-2026-245454.310.2Nikki BlightQR RedirectorCWE-862WordPress QR Redirector plugin <= 2.0.3 - Broken Access Control vulnerability
CVE-2026-245824.310.2WPPOOLFlexTableCWE-862WordPress FlexTable plugin <= 3.24.0 - Broken Access Control vulnerability
CVE-2026-90785.410.1MozillaFirefox for iOSCWE-451Firefox iOS RTL Domain Rendering Issue in Link Preview
CVE-2018-253635.310.0FyffePHP-Twitter-CloneCWE-352Twitter-Clone 1 Cross-Site Request Forgery via tweetdel.php
CVE-2026-94092.19.9Sushmi-palInvoice-SystemCWE-266Sushmi-pal Invoice-System User Management user improper authorization
CVE-2026-94102.19.9Sushmi-palInvoice-SystemCWE-266Sushmi-pal Invoice-System Profile Workflow profile improper authorization
CVE-2026-454356.59.8MelapressWP Activity LogCWE-79WordPress WP Activity Log plugin <= 5.6.3 - Cross Site Scripting (XSS) vulner…
CVE-2018-253706.99.2AdmidioAdmidioCWE-352Admidio 3.3.5 Cross-Site Request Forgery via roles_function.php
CVE-2026-94112.19.2SourceCodesterIndian Invoicing SystemCWE-74SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sq…
CVE-2026-94142.09.1SourceCodesterIndian Invoicing SystemCWE-79SourceCodester Indian Invoicing System Invoice Template Render Database-Backe…
CVE-2018-253608.68.8AgatasoftAuto PingMasterCWE-121AgataSoft Auto PingMaster 1.5 Buffer Overflow SEH
CVE-2026-94862.18.6SourceCodesterStudent Grades Management SystemCWE-352SourceCodester Student Grades Management System cross-site request forgery
CVE-2018-253668.68.1globalscapeCuteFTPCWE-120CuteFTP 5.0 XP Buffer Overflow via Site Manager Label Field
CVE-2018-253768.68.1SocuSoft3GP Photo SlideshowCWE-120Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH
CVE-2018-253738.68.1SocuSoftDVD Photo Slideshow ProfessionalCWE-121DVD Photo Slideshow Professional 8.07 Buffer Overflow SEH
CVE-2018-253758.68.1SocuSoftiPod Photo SlideshowCWE-121SocuSoft iPod Photo Slideshow 8.05 Buffer Overflow SEH
CVE-2018-253778.68.1SocuSoftFlash Slideshow Maker ProfessionalCWE-120Flash Slideshow Maker Professional 5.20 Buffer Overflow SEH
CVE-2026-60594.87.7NEC Platforms, Ltd.Aterm WX1800HPCWE-79A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may b…
CVE-2026-95041.97.5GNULibreDWGCWE-119GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds
CVE-2026-94906.87.0AcerCare CenterCWE-269Acer Care Center creates a Named Pipe with a weak Security Descriptor
CVE-2025-627456.56.9PickPluginsTeam ShowcaseCWE-79WordPress Team Showcase plugin <= 1.22.28 - Cross Site Scripting (XSS) vulner…
CVE-2018-253696.96.8scanwithVisual PingCWE-120Visual Ping 0.8.0.0 Buffer Overflow Denial of Service
CVE-2018-253676.96.6NASAopenVSPCWE-120NASA openVSP 3.16.1 Denial of Service via Buffer Overflow
CVE-2018-253598.65.6SplinterwareSplinterware System Scheduler ProCWE-276Splinterware System Scheduler Pro 5.12 Privilege Escalation
CVE-2026-95021.95.0GNULibreDWGCWE-119GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based ove…
CVE-2026-95011.94.2GNULibreDWGCWE-617GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion
CVE-2026-245746.53.8RecorpExport WP Page to Static HTML/CSSCWE-352WordPress Export WP Page to Static HTML/CSS plugin <= 6.0.0 - Cross Site Requ…
CVE-2026-251938.63.5GallagherCommand Centre ServerCWE-532Insertion of Sensitive Information into Log File (CWE-532) in some Command Ce…
CVE-2018-253786.93.5StokedonitNotebook ProCWE-789Notebook Pro 2.0 Denial of Service via Notebook Name Field
CVE-2026-394367.13.1bgermannCformsIICWE-352WordPress CformsII plugin <= 15.1.3 - Cross Site Request Forgery (CSRF) vulne…
CVE-2026-92745.22.6CP PlusWi-Fi Camera CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E45Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q, CP-Z45QCWE-312Information Exposure Vulnerability in CP-Plus Wi-Fi Camera
CVE-2026-95001.92.5GNULibreDWGCWE-119GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based…
CVE-2018-253617.02.3SoroushSoroush IM Desktop AppCWE-290Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
CVE-2026-245544.32.3Convers LabWPSubscriptionCWE-352WordPress WPSubscription plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) …
CVE-2026-245974.32.3WpDevArtOrganization chartCWE-352WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CS…
CVE-2026-94898.52.2AcerNitrorSense V3CWE-22NitroSense V3: Local Privilege Escalation (LPE) vulnerability
CVE-2026-95031.91.6GNULibreDWGCWE-404GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-25 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.