AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .1081 95.5 —
AFFECTED Product Versions Fixed CA750-PoE 6.2c.510 – —
TIMELINE May 25 Reserved by CNA May 25 Published (CNA: VulDB)
187 CVEs published May 25, 2026: 5 critical, 72 high, 56 medium, 53 low; 0 in KEV; 11 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 162 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1359 | 2489 | 1015 | 2563 |
| KEV catalog size | 1670 | |||
46 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 226 | 552 | 67 | 448 | 36 | 0 | 27 | 2 | 0.4 | 7.8 | .0014 | +63 |
| microsoft | 164 | 484 | 43 | 325 | 99 | 0 | 378 | 27 | 5.6 | 7.8 | .0045 | -22 |
| apple | 13 | 40 | 0 | 10 | 22 | 1 | 93 | 7 | 17.5 | 6.2 | .0037 | +13 |
| red hat | 9 | 32 | 5 | 17 | 8 | 2 | 4 | 0 | 0.0 | 7.5 | .0041 | -2 |
| 16 | 22 | 0 | 13 | 6 | 0 | 74 | 4 | 18.2 | 8.4 | .0035 | +15 | |
| freebsd | 7 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | +7 |
| suse | 2 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.2 | .0020 | +2 |
| android | 0 | 0 | 0 | 0 | 0 | 0 | 15 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 5 | 13 | 3 | 1 | 2 | 0 | 96 | 8 | 61.5 | 8.6 | .1247 | +2 |
| fortinet | 1 | 6 | 1 | 3 | 0 | 0 | 28 | 3 | 50.0 | 7.9 | .4330 | -2 |
| ivanti | 2 | 5 | 0 | 1 | 0 | 0 | 33 | 4 | 80.0 | 8.8 | .8056 | +1 |
| f5 | 2 | 3 | 2 | 0 | 0 | 0 | 7 | 1 | 33.3 | 9.2 | .0996 | +2 |
| ubiquiti | 2 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.8 | .0068 | +2 |
| broadcom | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .1990 | 0 |
| palo alto networks | 1 | 1 | 0 | 0 | 0 | 0 | 14 | 1 | 100.0 | — | .3207 | +1 |
| citrix | 0 | 1 | 0 | 0 | 0 | 0 | 19 | 1 | 100.0 | — | .8447 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 18 | 29 | 4 | 14 | 10 | 0 | 40 | 1 | 3.4 | 7.5 | .0065 | +15 |
| mozilla | 6 | 6 | 3 | 2 | 1 | 0 | 13 | 0 | 0.0 | 8.8 | .0042 | +6 |
| docker | 3 | 3 | 0 | 3 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0022 | +3 |
| drupal | 3 | 3 | 1 | 0 | 2 | 0 | 5 | 1 | 33.3 | 5.1 | .0021 | +3 |
| gitlab | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .4451 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 5 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| progress | 4 | 4 | 0 | 4 | 0 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +4 |
| adobe | 1 | 4 | 0 | 1 | 0 | 0 | 75 | 3 | 75.0 | 8.6 | .2776 | -2 |
| solarwinds | 0 | 3 | 1 | 0 | 0 | 0 | 11 | 3 | 100.0 | 9.8 | .8362 | 0 |
| oracle | 0 | 2 | 0 | 2 | 0 | 0 | 40 | 0 | 0.0 | 7.5 | .0065 | 0 |
| zohocorp | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | +1 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| ibm | 0 | 0 | 0 | 0 | 0 | 0 | 7 | 0 | — | — | — | 0 |
| sap | 0 | 0 | 0 | 0 | 0 | 0 | 12 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 1 | 2 | 0 | 1 | 0 | 0 | 26 | 1 | 50.0 | 8.7 | .4511 | 0 |
| siemens | 1 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | +1 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| tp-link | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| concrete cms | 44 | 44 | 1 | 9 | 13 | 21 | 0 | 0 | 0.0 | 5.7 | .0015 | +44 |
| edimax | 44 | 44 | 0 | 27 | 0 | 17 | 1 | 0 | 0.0 | 7.4 | .0059 | +44 |
| open ises | 37 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | +37 |
| netatalk | 33 | 33 | 1 | 13 | 9 | 10 | 0 | 0 | 0.0 | 6.4 | .0030 | +33 |
| totolink | 29 | 29 | 0 | 24 | 0 | 5 | 0 | 0 | 0.0 | 8.9 | .0173 | +29 |
| grafana | 10 | 27 | 2 | 7 | 16 | 2 | 0 | 0 | 0.0 | 6.5 | .0033 | +6 |
| dell | 12 | 18 | 0 | 6 | 11 | 0 | 2 | 1 | 5.6 | 6.7 | .0019 | +7 |
| nvidia | 16 | 16 | 7 | 9 | 0 | 0 | 0 | 0 | 0.0 | 8.4 | .0059 | +16 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-31431 | .9991 | 100.0 | 7.8 |
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-41940 | .9793 | 99.9 | 9.3 |
| CVE-2026-43284 | .9324 | 99.8 | 8.8 |
| CVE-2026-43500 | .9285 | 99.8 | 7.8 |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2026-42208 | .8942 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2024-1708 | .8756 | 99.7 | 8.4 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-43997 | 10.0 | .0098 | |
| CVE-2026-42826 | 10.0 | .0084 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-44005 | 10.0 | .0083 | |
| CVE-2026-44006 | 10.0 | .0081 | |
| CVE-2026-46595 | 10.0 | .0050 | |
| CVE-2026-42822 | 10.0 | .0049 | |
| CVE-2026-33712 | 10.0 | .0035 | |
| CVE-2026-9152 | 10.0 | .0034 | |
| CVE-2026-42901 | 10.0 | .0030 |
| Vendor | CVEs |
|---|---|
| linux | 228 |
| microsoft | 165 |
| concrete cms | 44 |
| edimax | 44 |
| open ises | 37 |
| netatalk | 33 |
| totolink | 29 |
| apache | 24 |
| 16 | |
| nvidia | 16 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 8 |
| apple | 7 |
| 4 | |
| ivanti | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| smartertools | 3 |
| solarwinds | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 10 |
| crates.io | 2 |
| npm | 2 |
| PyPI | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2024-1708 | ConnectWise | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2026-0300 | Palo Alto Networks | 0 |
| CVE-2026-20182 | Cisco | 0 |
| CVE-2026-31431 | Linux | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1650 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1650 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1650 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1650 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1650 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1650 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1650 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1650 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1650 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1650 |
EXPLOIT PUBLISHED — CVE-2026-2651 (mlflow/mlflow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47066 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47067 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47069 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47070 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47071 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47072 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47073 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47075 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47076 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47077 (benoitc hackney). Public exploit reference added.
187 CVEs published. 25 box scores, 162 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .1081 95.5 —
AFFECTED Product Versions Fixed CA750-PoE 6.2c.510 – —
TIMELINE May 25 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .1081 95.5 —
AFFECTED Product Versions Fixed CA750-PoE 6.2c.510 – —
TIMELINE May 25 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0209 80.1 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0209 80.1 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0208 79.9 —
AFFECTED Product Versions Fixed BR-6675nD 1.12 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0200 79.2 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0191 78.0 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0191 78.0 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0191 78.0 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0191 78.0 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0191 78.0 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0191 78.0 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0191 78.0 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0191 78.0 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0173 75.7 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0173 75.7 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0173 75.7 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0173 75.7 —
AFFECTED Product Versions Fixed A8000RU 7.1cu.643_b20200521 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0138 69.9 —
AFFECTED Product Versions Fixed miniclawd 2d65665046e2222eeea76cafc8570ed546a8c125 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0138 69.9 —
AFFECTED Product Versions Fixed miniclawd 2d65665046e2222eeea76cafc8570ed546a8c125 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0136 69.5 —
AFFECTED Product Versions Fixed Taier 1.4.0 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0136 69.5 —
AFFECTED Product Versions Fixed BR-6478AC 1.23 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0135 69.2 —
AFFECTED Product Versions Fixed BR-6478AC 1.23 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.4 —
AFFECTED Product Versions Fixed EW-7438RPn 1.31 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.4 —
AFFECTED Product Versions Fixed BR-6675nD 1.12 – —
TIMELINE May 24 Reserved by CNA May 25 Published (CNA: VulDB)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-9511 | 2.1 | 61.6 | Totolink | CA750-PoE | CWE-77 | Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection |
| CVE-2026-9512 | 2.1 | 61.6 | Totolink | CA750-PoE | CWE-77 | Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection |
| CVE-2026-9513 | 2.1 | 61.6 | Totolink | CA750-PoE | CWE-77 | Totolink CA750-PoE Setting cstecgi.cgi NTPSyncWithHost os command injection |
| CVE-2026-47073 | 8.7 | 55.3 | benoitc | hackney | CWE-400 | Unbounded memory consumption in WebSocket client in hackney |
| CVE-2018-25365 | 8.7 | 53.1 | PCViewer | PCViewer | CWE-22 | PCViewer vt1000 Directory Traversal via GET Request |
| CVE-2018-25374 | 8.7 | 53.1 | Softneta | MedDream PACS Server Premium | CWE-22 | Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal |
| CVE-2026-48842 | 8.1 | 52.4 | Roundcube | Webmail | CWE-89 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenti… |
| CVE-2026-47066 | 8.7 | 52.1 | benoitc | hackney | CWE-835 | Infinite loop in Alt-Svc header parser in hackney |
| CVE-2026-47067 | 8.7 | 52.1 | benoitc | hackney | CWE-770 | Atom table exhaustion via unrecognized URL schemes in hackney |
| CVE-2026-47071 | 8.2 | 52.1 | benoitc | hackney | CWE-400 | SOCKS5 TLS upgrade ignores caller timeout in hackney |
| CVE-2026-9459 | 7.4 | 52.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formConnectionSetting stack-based overflow |
| CVE-2026-9460 | 7.4 | 52.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formAccept stack-based overflow |
| CVE-2026-9461 | 7.4 | 52.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formRadius stack-based overflow |
| CVE-2026-45249 | 6.1 | 51.9 | Apache Software Foundation | Apache ECharts | CWE-79 | Apache ECharts: XSS in Lines series tooltip rendering |
| CVE-2026-8652 | 8.5 | 50.9 | NEC Platforms, Ltd. | Aterm MR51FN | CWE-78 | An OS Command Injection vulnerability exists in Aterm. If a malicious third p… |
| CVE-2026-47077 | 8.2 | 50.3 | benoitc | hackney | CWE-400 | Unbounded body accumulation in HTTP/3 response loop in hackney |
| CVE-2026-42782 | 7.2 | 48.3 | Apache Software Foundation | Apache Syncope | CWE-653 | Apache Syncope: Post-auth RCE via Groovy static |
| CVE-2026-9480 | 7.4 | 48.1 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formrefresh stack-based overflow |
| CVE-2026-45361 | 8.1 | 45.4 | Apache Software Foundation | Apache Airflow Google provider | CWE-322 | Apache Airflow Google provider: SSH host key verification disabled in Compute… |
| CVE-2026-9442 | 7.4 | 45.4 | Edimax | BR-6478AC | CWE-119 | Edimax BR-6478AC POST Request formiNICSiteSurvey buffer overflow |
| CVE-2026-9443 | 7.4 | 45.4 | Edimax | BR-6478AC | CWE-119 | Edimax BR-6478AC POST Request formL2TPSetup buffer overflow |
| CVE-2026-9462 | 7.4 | 45.4 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formWpsProxyEnable stack-based overflow |
| CVE-2026-9463 | 7.4 | 45.4 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formLicence stack-based overflow |
| CVE-2026-9479 | 7.4 | 45.4 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formLogout stack-based overflow |
| CVE-2026-9481 | 7.4 | 45.4 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formStats stack-based overflow |
| CVE-2026-9482 | 7.4 | 45.4 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formSDHCP stack-based overflow |
| CVE-2026-9428 | 7.4 | 44.9 | Tenda | F1202 | CWE-119 | Tenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflow |
| CVE-2026-9429 | 7.4 | 44.9 | Tenda | F1202 | CWE-119 | Tenda F1202 WrlExtraSet formWrlExtraSet stack-based overflow |
| CVE-2026-46745 | 5.3 | 44.7 | Apache Software Foundation | Apache Airflow FAB provider | CWE-90 | Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _searc… |
| CVE-2026-47072 | 6.9 | 43.0 | benoitc | hackney | CWE-93 | CRLF injection in WebSocket upgrade request in hackney |
| CVE-2026-47075 | 6.8 | 39.3 | benoitc | hackney | CWE-93 | CR/LF injection in query parameter in hackney |
| CVE-2026-5222 | 2.3 | 39.2 | Rust | Cargo | CWE-647 | Cargo can be coerced to share credentials between registries |
| CVE-2026-9425 | 7.4 | 37.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formWlanMP stack-based overflow |
| CVE-2026-9426 | 7.4 | 37.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn formHwSet stack-based overflow |
| CVE-2026-9427 | 7.4 | 37.0 | Edimax | EW-7438RPn | CWE-119 | Edimax EW-7438RPn webs formWlSiteSurvey stack-based overflow |
| CVE-2026-8376 | 9.8 | 36.8 | SHAY | perl | CWE-680 | Perl versions through 5.43.10 have a heap buffer overflow when compiling regu… |
| CVE-2026-9430 | 7.4 | 36.5 | Tenda | F1202 | CWE-119 | Tenda F1202 GstDhcpSetSerof formGstDhcpSetSer stack-based overflow |
| CVE-2026-9431 | 7.4 | 36.5 | Tenda | F1202 | CWE-119 | Tenda F1202 PptpUserAdd fromPptpUserAdd stack-based overflow |
| CVE-2026-9467 | 2.1 | 36.5 | debugmcp | mcp-debugger | CWE-22 | debugmcp mcp-debugger server.ts handleGetSourceContext path traversal |
| CVE-2026-42797 | 4.9 | 36.4 | Apache Software Foundation | Apache Syncope | CWE-202 | Apache Syncope: JexlContextBuilder Information Disclosure |
| CVE-2026-48847 | 3.7 | 36.1 | Roundcube | Webmail | CWE-669 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-auth… |
| CVE-2026-47069 | 2.1 | 35.5 | benoitc | hackney | CWE-93 | CRLF injection in cookie domain/path options in hackney |
| CVE-2026-48844 | 7.5 | 34.5 | Roundcube | Webmail | CWE-670 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure cod… |
| CVE-2026-43827 | 5.9 | 34.4 | Apache Software Foundation | Apache Shiro | CWE-384 | Apache Shiro: Session fixation: new session is not created after login by def… |
| CVE-2026-24937 | 7.2 | 34.0 | VideoWhisper.com | Broadcast Live Video | CWE-94 | WordPress Broadcast Live Video plugin < 7.1.3 - Remote Code Execution (RCE) v… |
| CVE-2026-48846 | 6.5 | 33.7 | Roundcube | Webmail | CWE-669 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote i… |
| CVE-2026-41863 | 6.5 | 33.0 | Spring | Spring AI | CWE-22 | LLM-influenced filename used unsanitized in Path.resolve before file write in… |
| CVE-2018-25379 | 8.8 | 32.1 | Ourenergy | Collectric CMU | CWE-89 | Collectric CMU 1.0 SQL Injection via lang Parameter |
| CVE-2026-45216 | 8.8 | 32.1 | StoreApps | Smart Manager | CWE-266 | WordPress Smart Manager plugin <= 8.85.0 - Privilege Escalation vulnerability |
| CVE-2026-48848 | 7.2 | 32.0 | Roundcube | Webmail | CWE-79 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient H… |
| CVE-2018-25368 | 8.7 | 31.7 | Nordvpn | NordVPN | CWE-789 | Nord VPN 6.14.31 Denial of Service via Password Field |
| CVE-2026-48845 | 6.5 | 30.9 | Roundcube | Webmail | CWE-669 | In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, … |
| CVE-2026-48837 | 8.5 | 30.4 | Unlimited Elements | Unlimited Elements For Elementor | CWE-89 | WordPress Unlimited Elements For Elementor plugin <= 2.0.8 - SQL Injection vu… |
| CVE-2026-42773 | 9.3 | 30.3 | eMagicOne | eMagicOne Store Manager | CWE-89 | WordPress eMagicOne Store Manager plugin <= 1.3.2 - SQL Injection vulnerability |
| CVE-2026-42774 | 9.3 | 30.3 | Crocoblock | JetEngine | CWE-89 | WordPress JetEngine plugin <= 3.8.8.1 - SQL Injection vulnerability |
| CVE-2026-47070 | 6.0 | 30.3 | benoitc | hackney | CWE-601 | HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origi… |
| CVE-2026-44598 | 5.1 | 29.8 | Apache Software Foundation | Apache Shiro Jakarta EE module | CWE-601 | Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid creden… |
| CVE-2026-9464 | 2.0 | 29.1 | YunaiV | yudao-cloud | CWE-918 | YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-sid… |
| CVE-2026-45217 | 6.5 | 28.3 | ThemeHigh | Stripe Payment Gateway for WooCommerce | CWE-288 | WordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Aut… |
| CVE-2026-9466 | 5.5 | 28.2 | Tiandy | Easy7 Integrated Management Platform | CWE-640 | Tiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword p… |
| CVE-2026-48589 | 0.0 | 28.3 | Apache Software Foundation | Apache Shiro | CWE-601 | Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login re… |
| CVE-2026-40127 | 5.3 | 28.1 | OutSystems | Lifetime | CWE-639 | Authorization Bypass Through User-Controlled Key in OutSystems Lifetime |
| CVE-2018-25371 | 8.8 | 27.8 | Moosocial | mooSocial Store Plugin | CWE-89 | mooSocial Store Plugin 2.6 SQL Injection via product parameter |
| CVE-2026-2651 | 9.0 | 27.5 | mlflow | mlflow/mlflow | CWE-862 | Missing Authorization Validation in mlflow/mlflow |
| CVE-2026-27768 | 6.6 | 27.0 | Genetec Inc. | Genetec Security Center | CWE-89 | SQL Injection affecting the Access Manager role. |
| CVE-2026-9497 | 2.1 | 26.7 | changmingxie | tcc-transaction | CWE-20 | changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject … |
| CVE-2018-25364 | 8.8 | 26.6 | Fyffe | PHP-Twitter-Clone | CWE-89 | Twitter-Clone 1 SQL Injection via search.php |
| CVE-2026-9468 | 2.1 | 26.6 | dazeb | cline-mcp-memory-bank | CWE-22 | dazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversal |
| CVE-2026-9472 | 2.1 | 26.6 | dazeb | markdown-downloader | CWE-22 | dazeb markdown-downloader index.ts create_subdirectory path traversal |
| CVE-2026-9473 | 2.1 | 26.6 | c-rick | jimeng-mcp | CWE-22 | c-rick jimeng-mcp api.ts generateVideo path traversal |
| CVE-2026-9448 | 2.1 | 26.5 | code-projects | Employee Management System | CWE-79 | code-projects Employee Management System applyleave.php cross site scripting |
| CVE-2026-9438 | 2.1 | 25.2 | yashpokharna2555 | StudentManagementSystem | CWE-99 | yashpokharna2555 StudentManagementSystem courseDel.php resource injection |
| CVE-2026-48850 | 5.9 | 24.8 | PuTTY | PuTTY | CWE-415 | PuTTY 0.72 before 0.84 has a double free in RSA KEX. |
| CVE-2026-9447 | 5.5 | 24.7 | SourceCodester | Simple POS and Inventory System | CWE-74 | SourceCodester Simple POS and Inventory System search.php sql injection |
| CVE-2026-9465 | 5.5 | 24.7 | Tiandy | Easy7 Integrated Management Platform | CWE-74 | Tiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection |
| CVE-2026-9469 | 5.5 | 24.7 | yashpokharna2555 | StudentManagementSystem | CWE-74 | yashpokharna2555 StudentManagementSystem success.php sql injection |
| CVE-2026-9470 | 5.5 | 24.7 | yashpokharna2555 | StudentManagementSystem | CWE-74 | yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in … |
| CVE-2026-9474 | 5.5 | 24.7 | yashpokharna2555 | StudentManagementSystem | CWE-74 | yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql… |
| CVE-2026-9058 | 9.3 | 23.6 | Krajowa Izba Rozliczeniowa | Szafir SDK | CWE-295 | Improper Certificate Verification in Szafir SDK |
| CVE-2018-25362 | 8.8 | 23.5 | Fyffe | PHP-Twitter-Clone | CWE-89 | Twitter-Clone 1 SQL Injection via follow.php |
| CVE-2018-25372 | 8.8 | 23.1 | MedDream | PACS Server Premium | CWE-89 | MedDream PACS Server Premium 6.7.1.1 SQL Injection via email |
| CVE-2026-45209 | 7.5 | 23.1 | edward_plainview | MyCryptoCheckout | CWE-862 | WordPress MyCryptoCheckout plugin <= 2.161 - Broken Access Control vulnerability |
| CVE-2026-9422 | 5.5 | 23.0 | n/a | KLiK SocialMediaWebsite | CWE-74 | KLiK SocialMediaWebsite HTTP POST Request Parameter injection |
| CVE-2026-24546 | 5.3 | 22.0 | Ruben Garcia | GamiPress | CWE-862 | WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability |
| CVE-2026-9498 | 2.1 | 22.1 | Dromara | lamp-cloud | CWE-791 | Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elem… |
| CVE-2026-5223 | 6.5 | 22.0 | Rust Project | Cargo | CWE-61 | Crates in third party registries can override the cached source of other crates |
| CVE-2026-9421 | 5.5 | 21.8 | n/a | KLiK SocialMediaWebsite | CWE-284 | KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload |
| CVE-2026-45438 | 7.5 | 21.4 | WebToffee | Smart Coupons for WooCommerce | CWE-862 | WordPress Smart Coupons for WooCommerce plugin < 2.3.0 - Broken Access Contro… |
| CVE-2018-25380 | 7.1 | 20.9 | Extro | eXtroForms | CWE-89 | Joomla Component eXtroForms 2.1.5 SQL Injection via filter parameters |
| CVE-2018-25381 | 7.1 | 20.9 | Extro | Responsive Portfolio | CWE-89 | Joomla Responsive Portfolio 1.6.1 SQL Injection via filter parameters |
| CVE-2026-4915 | 6.5 | 20.2 | Mattermost | Mattermost | CWE-754 | Server panic via outgoing webhook responses |
| CVE-2026-48852 | 3.7 | 19.8 | PuTTY | PuTTY | CWE-617 | PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification. |
| CVE-2026-43828 | 5.9 | 19.6 | Apache Software Foundation | Apache Shiro | CWE-614 | Apache Shiro: Shiro's native session and rememberMe cookies do not have secur… |
| CVE-2026-9484 | 2.1 | 19.5 | SourceCodester | Student Grades Management System | CWE-266 | SourceCodester Student Grades Management System classroom.php removeStudentFr… |
| CVE-2026-48843 | 7.2 | 19.0 | Roundcube | Webmail | CWE-918 | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has … |
| CVE-2026-42763 | 6.5 | 18.4 | SePay team | SePay Gateway | CWE-862 | WordPress SePay Gateway plugin <= 1.1.20 - Sensitive Data Exposure vulnerability |
| CVE-2026-9413 | 2.1 | 18.3 | SourceCodester | Indian Invoicing System | CWE-79 | SourceCodester Indian Invoicing System category.php cross site scripting |
| CVE-2026-9415 | 2.1 | 18.3 | code-projects | Employee Management System | CWE-79 | code-projects Employee Management System eloginwel.php cross site scripting |
| CVE-2026-9416 | 2.1 | 18.3 | code-projects | Employee Management System | CWE-79 | code-projects Employee Management System myprofile.php cross site scripting |
| CVE-2026-9417 | 2.1 | 18.3 | code-projects | Employee Management System | CWE-79 | code-projects Employee Management System myprofileup.php cross site scripting |
| CVE-2026-9418 | 2.1 | 18.3 | code-projects | Employee Management System | CWE-79 | code-projects Employee Management System changepassemp.php cross site scripting |
| CVE-2026-9419 | 2.1 | 18.3 | code-projects | Employee Management System | CWE-79 | code-projects Employee Management System empproject.php cross site scripting |
| CVE-2026-9445 | 2.1 | 18.0 | SourceCodester | Simple POS and Inventory System | CWE-284 | SourceCodester Simple POS and Inventory System File Extension addproduct.php … |
| CVE-2026-9483 | 2.1 | 18.0 | SourceCodester | Student Grades Management System | CWE-266 | SourceCodester Student Grades Management System grades.php improper authoriza… |
| CVE-2026-7766 | 8.3 | 17.6 | Kenik | KG-5230TAS-IL-3 | CWE-22 | Path Traversal in Kenik cameras |
| CVE-2026-9444 | 2.0 | 17.6 | SourceCodester | Simple POS and Inventory System | CWE-74 | SourceCodester Simple POS and Inventory System GET Parameter deleteproduct.ph… |
| CVE-2026-9446 | 2.0 | 17.6 | SourceCodester | Simple POS and Inventory System | CWE-74 | SourceCodester Simple POS and Inventory System edit_customer.php sql injection |
| CVE-2026-24586 | 5.4 | 17.2 | Themeansar | Newses | CWE-862 | WordPress Newses theme <= 2.0.0.77 - Broken Access Control vulnerability |
| CVE-2026-27346 | 4.9 | 17.1 | Kings Plugins | B2BKing | CWE-862 | WordPress B2BKing plugin < 5.2.10 - Broken Access Control vulnerability |
| CVE-2026-9471 | 2.0 | 16.3 | yashpokharna2555 | StudentManagementSystem | CWE-79 | yashpokharna2555 StudentManagementSystem student.php cross site scripting |
| CVE-2026-9485 | 2.0 | 16.3 | SourceCodester | Student Grades Management System | CWE-79 | SourceCodester Student Grades Management System students.php cross site scrip… |
| CVE-2026-9449 | 2.1 | 16.1 | code-projects | Employee Management System | CWE-74 | code-projects Employee Management System changepassemp.php sql injection |
| CVE-2026-9450 | 2.1 | 16.1 | code-projects | Employee Management System | CWE-74 | code-projects Employee Management System psubmit.php sql injection |
| CVE-2026-9451 | 2.1 | 16.1 | code-projects | Employee Management System | CWE-74 | code-projects Employee Management System applyleaveprocess.php sql injection |
| CVE-2026-9420 | 2.1 | 15.6 | n/a | KLiK SocialMediaWebsite | CWE-74 | KLiK SocialMediaWebsite HTTP GET Request Parameter injection |
| CVE-2026-48849 | 4.4 | 15.1 | Roundcube | Webmail | CWE-79 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitiz… |
| CVE-2026-24592 | 5.3 | 14.2 | Lucian Apostol | Auto Affiliate Links | CWE-862 | WordPress Auto Affiliate Links plugin <= 6.8.8.3 - Broken Access Control vuln… |
| CVE-2026-27357 | 5.3 | 14.2 | Cornel Raiu | WP Search Analytics | CWE-862 | WordPress WP Search Analytics plugin < 1.5.0 - Broken Access Control vulnerab… |
| CVE-2026-27398 | 5.3 | 14.2 | WP Chill | RSVP and Event Management | CWE-862 | WordPress RSVP and Event Management plugin <= 2.7.16 - Broken Access Control … |
| CVE-2026-47076 | 6.9 | 13.9 | benoitc | hackney | CWE-436 | SSRF allowlist bypass via percent-encoded host in hackney |
| CVE-2026-48851 | 3.1 | 13.2 | PuTTY | PuTTY | CWE-451 | PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication fo… |
| CVE-2026-32389 | 5.4 | 13.2 | Linethemes | NanoCare | CWE-862 | WordPress NanoCare theme < 1.2.2 - Broken Access Control vulnerability |
| CVE-2026-42776 | 6.3 | 10.4 | WP Sunshine | Sunshine Photo Cart | CWE-862 | WordPress Sunshine Photo Cart plugin <= 3.6.7 - Broken Access Control vulnera… |
| CVE-2026-9412 | 2.1 | 10.4 | SourceCodester | Indian Invoicing System | CWE-266 | SourceCodester Indian Invoicing System Backend Endpoint access control |
| CVE-2026-24527 | 4.3 | 10.2 | Patterns in the cloud | Autoship Cloud for WooCommerce Subscription Products | CWE-862 | WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.14… |
| CVE-2026-24545 | 4.3 | 10.2 | Nikki Blight | QR Redirector | CWE-862 | WordPress QR Redirector plugin <= 2.0.3 - Broken Access Control vulnerability |
| CVE-2026-24582 | 4.3 | 10.2 | WPPOOL | FlexTable | CWE-862 | WordPress FlexTable plugin <= 3.24.0 - Broken Access Control vulnerability |
| CVE-2026-9078 | 5.4 | 10.1 | Mozilla | Firefox for iOS | CWE-451 | Firefox iOS RTL Domain Rendering Issue in Link Preview |
| CVE-2018-25363 | 5.3 | 10.0 | Fyffe | PHP-Twitter-Clone | CWE-352 | Twitter-Clone 1 Cross-Site Request Forgery via tweetdel.php |
| CVE-2026-9409 | 2.1 | 9.9 | Sushmi-pal | Invoice-System | CWE-266 | Sushmi-pal Invoice-System User Management user improper authorization |
| CVE-2026-9410 | 2.1 | 9.9 | Sushmi-pal | Invoice-System | CWE-266 | Sushmi-pal Invoice-System Profile Workflow profile improper authorization |
| CVE-2026-45435 | 6.5 | 9.8 | Melapress | WP Activity Log | CWE-79 | WordPress WP Activity Log plugin <= 5.6.3 - Cross Site Scripting (XSS) vulner… |
| CVE-2018-25370 | 6.9 | 9.2 | Admidio | Admidio | CWE-352 | Admidio 3.3.5 Cross-Site Request Forgery via roles_function.php |
| CVE-2026-9411 | 2.1 | 9.2 | SourceCodester | Indian Invoicing System | CWE-74 | SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sq… |
| CVE-2026-9414 | 2.0 | 9.1 | SourceCodester | Indian Invoicing System | CWE-79 | SourceCodester Indian Invoicing System Invoice Template Render Database-Backe… |
| CVE-2018-25360 | 8.6 | 8.8 | Agatasoft | Auto PingMaster | CWE-121 | AgataSoft Auto PingMaster 1.5 Buffer Overflow SEH |
| CVE-2026-9486 | 2.1 | 8.6 | SourceCodester | Student Grades Management System | CWE-352 | SourceCodester Student Grades Management System cross-site request forgery |
| CVE-2018-25366 | 8.6 | 8.1 | globalscape | CuteFTP | CWE-120 | CuteFTP 5.0 XP Buffer Overflow via Site Manager Label Field |
| CVE-2018-25376 | 8.6 | 8.1 | SocuSoft | 3GP Photo Slideshow | CWE-120 | Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH |
| CVE-2018-25373 | 8.6 | 8.1 | SocuSoft | DVD Photo Slideshow Professional | CWE-121 | DVD Photo Slideshow Professional 8.07 Buffer Overflow SEH |
| CVE-2018-25375 | 8.6 | 8.1 | SocuSoft | iPod Photo Slideshow | CWE-121 | SocuSoft iPod Photo Slideshow 8.05 Buffer Overflow SEH |
| CVE-2018-25377 | 8.6 | 8.1 | SocuSoft | Flash Slideshow Maker Professional | CWE-120 | Flash Slideshow Maker Professional 5.20 Buffer Overflow SEH |
| CVE-2026-6059 | 4.8 | 7.7 | NEC Platforms, Ltd. | Aterm WX1800HP | CWE-79 | A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may b… |
| CVE-2026-9504 | 1.9 | 7.5 | GNU | LibreDWG | CWE-119 | GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds |
| CVE-2026-9490 | 6.8 | 7.0 | Acer | Care Center | CWE-269 | Acer Care Center creates a Named Pipe with a weak Security Descriptor |
| CVE-2025-62745 | 6.5 | 6.9 | PickPlugins | Team Showcase | CWE-79 | WordPress Team Showcase plugin <= 1.22.28 - Cross Site Scripting (XSS) vulner… |
| CVE-2018-25369 | 6.9 | 6.8 | scanwith | Visual Ping | CWE-120 | Visual Ping 0.8.0.0 Buffer Overflow Denial of Service |
| CVE-2018-25367 | 6.9 | 6.6 | NASA | openVSP | CWE-120 | NASA openVSP 3.16.1 Denial of Service via Buffer Overflow |
| CVE-2018-25359 | 8.6 | 5.6 | Splinterware | Splinterware System Scheduler Pro | CWE-276 | Splinterware System Scheduler Pro 5.12 Privilege Escalation |
| CVE-2026-9502 | 1.9 | 5.0 | GNU | LibreDWG | CWE-119 | GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based ove… |
| CVE-2026-9501 | 1.9 | 4.2 | GNU | LibreDWG | CWE-617 | GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion |
| CVE-2026-24574 | 6.5 | 3.8 | Recorp | Export WP Page to Static HTML/CSS | CWE-352 | WordPress Export WP Page to Static HTML/CSS plugin <= 6.0.0 - Cross Site Requ… |
| CVE-2026-25193 | 8.6 | 3.5 | Gallagher | Command Centre Server | CWE-532 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Ce… |
| CVE-2018-25378 | 6.9 | 3.5 | Stokedonit | Notebook Pro | CWE-789 | Notebook Pro 2.0 Denial of Service via Notebook Name Field |
| CVE-2026-39436 | 7.1 | 3.1 | bgermann | CformsII | CWE-352 | WordPress CformsII plugin <= 15.1.3 - Cross Site Request Forgery (CSRF) vulne… |
| CVE-2026-9274 | 5.2 | 2.6 | CP Plus | Wi-Fi Camera CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E45Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q, CP-Z45Q | CWE-312 | Information Exposure Vulnerability in CP-Plus Wi-Fi Camera |
| CVE-2026-9500 | 1.9 | 2.5 | GNU | LibreDWG | CWE-119 | GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based… |
| CVE-2018-25361 | 7.0 | 2.3 | Soroush | Soroush IM Desktop App | CWE-290 | Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection |
| CVE-2026-24554 | 4.3 | 2.3 | Convers Lab | WPSubscription | CWE-352 | WordPress WPSubscription plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) … |
| CVE-2026-24597 | 4.3 | 2.3 | WpDevArt | Organization chart | CWE-352 | WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CS… |
| CVE-2026-9489 | 8.5 | 2.2 | Acer | NitrorSense V3 | CWE-22 | NitroSense V3: Local Privilege Escalation (LPE) vulnerability |
| CVE-2026-9503 | 1.9 | 1.6 | GNU | LibreDWG | CWE-404 | GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-05-25 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.