boxscore/security
Tuesday, May 26, 2026 · all times UTC← 2026-05-25 · archive · 2026-05-27 →

275 CVEs published May 26, 2026: 30 critical, 94 high, 119 medium, 32 low; 1 in KEV; 22 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 250 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1634276410152563
KEV catalog size1670

77 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux229555674483902720.47.8.0014+66
microsoft16448443325990378275.67.8.0045-22
apple204701227193714.96.2.0034+20
red hat163972192400.07.5.0041+5
google16220136074418.28.4.0035+15
freebsd770520000.07.8.0020+7
suse220200000.08.2.0020+2
android0000001500
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco513312096861.58.6.1247+2
checkpoint660330300.06.5.0338+6
fortinet16130028350.07.9.4330-2
ivanti25010033480.08.8.8056+1
f52320007133.39.2.0996+2
ubiquiti231200400.08.8.0068+2
broadcom02000042100.0.19900
palo alto networks110000141100.0.3207+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache19304141104013.37.4.0065+16
mozilla6632101300.08.8.0042+6
docker330300100.08.8.0022+3
drupal3310205133.35.1.0021+3
gitlab02000042100.0.44510
github110100000.07.0.0039+1
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm202061040700.07.5.0027+20
progress440400900.07.5.0036+4
adobe14010075375.08.6.2776-2
solarwinds031000113100.09.8.83620
zohocorp220110000.07.1.0104+2
oracle0202004000.07.5.00650
atlassian0000001300
sap0000001200
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
hitachi energy220020000.05.7.0014+2
d-link12010026150.08.7.45110
siemens110100100.08.7.0032+1
hikvision01000021100.01.00000
dahua000000200
qnap000000800
schneider electric000000100
tp-link000000600
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44
edimax4444027017100.07.4.0059+44
open ises3737214210000.06.9.0021+37
totolink343402509000.08.9.0191+34
netatalk3333113910000.06.4.0030+33
nvidia333381870000.07.8.0038+33
grafana102727162000.06.5.0033+6
joomla! project202118120000.06.9.0024+19

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2008-4250.987599.9
CVE-2026-41940.979399.99.3
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2024-1708.875699.78.4
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4659510.0.0050
CVE-2026-4282210.0.0049
CVE-2026-3371210.0.0035
CVE-2026-915210.0.0034
Most disclosures (vendor)
VendorCVEs
linux231
microsoft165
concrete cms44
edimax44
open ises37
totolink34
netatalk33
nvidia33
apache25
apple20
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google4
ivanti4
synacor4
adobe3
fortinet3
smartertools3
solarwinds3
Most-affected ecosystems
EcosystemAdvisories
Maven10
crates.io2
npm2
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2024-1708ConnectWise0
CVE-2025-34291Langflow0
CVE-2026-0300Palo Alto Networks0
CVE-2026-20182Cisco0
CVE-2026-31431Linux0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171651
CVE-2021-27102Accellion2021-11-171651
CVE-2021-27101Accellion2021-11-171651
CVE-2021-27103Accellion2021-11-171651
CVE-2021-21017Adobe2021-11-171651
CVE-2021-28550Adobe2021-11-171651
CVE-2021-42013Apache2021-11-171651
CVE-2021-41773Apache2021-11-171651
CVE-2021-30858Apple2021-11-171651
CVE-2021-30860Apple2021-11-171651

Transactions

EXPLOIT PUBLISHEDCVE-2026-25104 (MediaArea MediaInfoLib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-25713 (MediaArea MediaInfoLib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-40033 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44214 (rexxars eventsource-encoder). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44708 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44723 (VowpalWabbit vowpal_wabbit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44729 (twentyhq twenty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44788 (adamhathcock sharpcompress). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44837 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44897 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44898 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44899 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44966 (shepherdwind velocity.js). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44985 (amir20 dozzle). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45298 (amir20 dozzle). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46624 (twentyhq twenty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48687. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48689. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48710 (Kludex starlette). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.

Yesterday's Results

275 CVEs published. 25 box scores, 250 table rows — nothing truncated.

LiteSpeed cPanel Plugin
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .1891   97.1   YES
AFFECTED
  Product        Versions     Fixed
  cPanel Plugin  2.3 –        —
  WHM Plugin     unspecified  —
TIMELINE
  May 21  Reserved by CNA
  May 26  Added to CISA KEV, due May 29
  May 26  Published (CNA: mitre)
CWE-266 · CNA: mitre · 4 references · NVD status: Analyzed · KEV due May 29, 2026
Red Hat Red Hat Enterprise Linux 10 — Samba: samba: remote code execution in printing subsystem via unescaped job description
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  H    9.0   .1393   96.2     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:4.23.5-109.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:4.21.3-114.el10_0.1
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:4.10.16-26.el7_9.1
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:4.10.16-26.el7_9.1
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:4.13.3-12.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:4.13.3-12.el8_4.1
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:4.15.5-16.el8_6.1
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:4.15.5-16.el8_6.1
  + 10 more
TIMELINE
  Mar 19  Reserved by CNA
  May 26  Published (CNA: redhat)
CWE-78 · CNA: redhat · 15 references · NVD status: Modified
Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
mossdef-org luci-app-https-dns-proxy — luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0658   93.2     —
AFFECTED
  Product                   Versions     Fixed
  luci-app-https-dns-proxy  unspecified  —
TIMELINE
  May 13  Reserved by CNA
  May 26  Published (CNA: VulnCheck)
CWE-77 · CNA: VulnCheck · 3 references · NVD status: Deferred
checkpoint Quantum Security Gateway — Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0475   91.1     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-98 · CNA: checkpoint · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — SQL injection issue in UserCheck Portal when DLP Software Blade is active
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  L  L  L    5.6   .0436   90.4     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-89 · CNA: checkpoint · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Management — Authenticated Administrator Role-Based Access Control Bypass in Compliance
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  L  L  L    4.1   .0410   89.9     —
AFFECTED
  Product                      Versions                                    Fixed
  Quantum Security Management  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-89 · CNA: checkpoint · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0266   84.4     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-122 · CNA: checkpoint · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — HTTP service can incorrectly process malformed HTTP requests
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0261   84.1     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-122 · CNA: checkpoint · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0214   80.5     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-125 · CNA: checkpoint · 1 reference · NVD status: Awaiting Analysis
Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0213   80.4     —
AFFECTED
  Product  Versions               Fixed
  N300RH   6.1c.1353_B20190305 –  —
TIMELINE
  May 26  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Kludex starlette — Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0184   77.2     —
AFFECTED
  Product    Versions   Fixed
  starlette  < 1.0.1 –  —
TIMELINE
  May 22  Reserved by CNA
  May 26  Public exploit reference published
  May 26  Published (CNA: GitHub_M)
CWE-444, CWE-1289 · CNA: GitHub_M · 24 references · NVD status: Modified
n/a n/a — FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper ro…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0164   74.4     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  May 22  Reserved by CNA
  May 26  Public exploit reference published
  May 26  Published (CNA: mitre)
CWE-78 · CNA: mitre · 3 references · NVD status: Modified
amir20 dozzle — Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0149   71.9     —
AFFECTED
  Product  Versions    Fixed
  dozzle   < 10.5.2 –  —
TIMELINE
  May 11  Reserved by CNA
  May 26  Public exploit reference published
  May 26  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · 2 references · NVD status: Analyzed
mikro-orm mikro-orm — MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  L  L    7.6   .0145   71.2     —
AFFECTED
  Product    Versions                   Fixed
  mikro-orm  >= 7.0.0-rc.0, < 7.0.14 –  —
  knex       < 6.6.14 –                 —
  sql        < 7.0.14 –                 —
TIMELINE
  May 7   Reserved by CNA
  May 26  Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · 5 references · NVD status: Deferred
n/a n/a — FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik r…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0107   62.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  May 22  Reserved by CNA
  May 26  Published (CNA: mitre)
CWE-78 · CNA: mitre · 3 references · NVD status: Analyzed
haojing8312 WorkClaw Blacklist bash.rs is_dangerous os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0105   61.4     —
AFFECTED
  Product   Versions  Fixed
  WorkClaw  0.6.0 –   —
TIMELINE
  May 26  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0104   61.1     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.26.0
TIMELINE
  Apr 8   Reserved by CNA
  May 26  Public exploit reference published
  May 26  Published (CNA: VulnCheck)
CWE-122, CWE-787 · CNA: VulnCheck · 9 references · NVD status: Modified
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0085   55.1     —
AFFECTED
  Product                                                                     Versions    Fixed
  Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty  8.5, 9.0 –  —
TIMELINE
  May 14  Reserved by CNA
  May 26  Published (CNA: ibm)
CWE-94 · CNA: ibm · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Gnutls: gnutls: information disclosure via heap overread in rsa key exchange
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  H    8.2   .0073   51.2     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:3.8.10-4.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.8.9-9.el10_0.19
  Red Hat Enterprise Linux 8                                             unspecified  0:3.6.16-8.el8_10.6
  Red Hat Enterprise Linux 8                                             unspecified  0:3.6.16-8.el8_10.6
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:3.6.14-10.el8_4.1
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:4.13-3.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:3.6.14-10.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:4.13-3.el8_4.1
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:3.6.16-5.el8_6.5
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:4.13-3.el8_6.2
  + 22 more
TIMELINE
  Mar 31  Reserved by CNA
  May 26  Published (CNA: redhat)
CWE-126 · CNA: redhat · 17 references · NVD status: Awaiting Analysis
Red Hat Red Hat Enterprise Linux 10 — Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0073   51.1     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:3.8.10-4.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.8.9-9.el10_0.19
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:3.3.29-9.el7_9.2
  Red Hat Enterprise Linux 8                                             unspecified  0:3.6.16-8.el8_10.6
  Red Hat Enterprise Linux 8                                             unspecified  0:3.6.16-8.el8_10.6
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:3.6.14-10.el8_4.1
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:4.13-3.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:3.6.14-10.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:4.13-3.el8_4.1
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:3.6.16-5.el8_6.5
  + 22 more
TIMELINE
  Apr 23  Reserved by CNA
  May 26  Published (CNA: redhat)
CWE-193 · CNA: redhat · 17 references · NVD status: Awaiting Analysis
OpenKM 6.3.12 Remote Code Execution via Administrative Scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0068   49.4     —
AFFECTED
  Product                      Versions     Fixed
  OpenKM Community Edition     unspecified  —
  OpenKM Professional Edition  unspecified  —
TIMELINE
  Apr 29  Reserved by CNA
  May 26  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 7 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-486899.849.3n/an/aCWE-787FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based …
CVE-2026-242129.848.4NVIDIAIsaac LaunchableCWE-319NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive in…
CVE-2026-424258.647.8OpenkmOpenKM Community EditionCWE-89OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery
CVE-2026-73749.945.7Red HatRed Hat Container Native Virtualization 4.12CWE-59Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via…
CVE-2026-36609.844.9IBMEngineering Lifecycle ManagementCWE-863IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authe…
CVE-2026-95609.444.7OpenVPN IncOpenVPN ConnectCWE-78Privilege escalation via background service of OpenVPN Connect 3.5.1 through …
CVE-2026-486869.844.2n/an/aCWE-120FastNetMon Community Edition through 1.2.9 contains a stack-based buffer over…
CVE-2026-442097.542.9mascibanksCWE-1336Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVE-2026-414017.141.7libyanglibyangCWE-416libyang - Heap Use-After-Free Write in XML Metadata Parsing
CVE-2026-95505.541.7Acrel ElectricalEEMS Enterprise Power Operation and Maintenance Cloud PlatformCWE-22Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platfo…
CVE-2026-449669.840.9shepherdwindvelocity.jsCWE-1321Velocity.js: Prototype Pollution in #set path assignment
CVE-2026-403837.540.6Joomla! ProjectJoomla! CMSCWE-22Joomla! Core - [20260509] - LFI in HTMLView layout parameter
CVE-2026-485925.340.6oban-bgoban_webCWE-862Missing authorization check on save-job event handler in oban_web
CVE-2026-72519.340.5EppendorfBioFlo 320CWE-259Eppendorf BioFlo 320 Use of hard-coded password
CVE-2026-88908.840.0code100xcode100xCWE-639code100x Mobile API Authentication Bypass via Header Spoofing
CVE-2026-405646.540.0Apache Software FoundationApache Flink Kubernetes OperatorCWE-552Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file …
CVE-2026-91709.839.9IBMHTTP ServerCWE-94IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-466249.939.5twentyhqtwentyCWE-78Twenty: SQL Injection via the timeZone field
CVE-2026-447239.938.6VowpalWabbitvowpal_wabbitCWE-78Vowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allo…
CVE-2026-88559.837.8IBMHTTP ServerCWE-94IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-444499.137.5prolix-ocLumiverseCWE-88Lumiverse: SMB `exists()` basename injection via smbclient `!cmd` escape
CVE-2026-95387.537.3BINGOSArchive::TarCWE-789Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attack…
CVE-2026-80478.737.0CODESYSCODESYS Control RTE (SL)CWE-1284Out-of-bounds Write in CODESYS Control
CVE-2026-403845.937.0Joomla! ProjectJoomla! CMSCWE-22Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint
CVE-2026-457219.036.4xyprotoalgernonCWE-20Algernon: handler.lua discovery walks parent directories above the server root
CVE-2026-424969.135.8BINGOSArchive::TarCWE-59Archive::Tar versions before 3.08 for Perl extract symlinks with attacker con…
CVE-2026-95405.535.6vllm-projectvllmCWE-404vllm-project vllm OpenAI-compatible Serving Path denial of service
CVE-2026-420138.235.3Red HatRed Hat Enterprise Linux 10CWE-295Gnutls: gnutls: certificate validation bypass due to oversized subject altern…
CVE-2026-396617.534.8MagentechSW CoreCWE-98WordPress SW Core plugin <= 1.7.18 - Local File Inclusion vulnerability
CVE-2026-424977.534.8BINGOSArchive::TarCWE-59Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker cont…
CVE-2026-485935.934.8oban-bgoban_webCWE-400Unbounded range expansion in cron describe causes memory exhaustion in oban_web
CVE-2026-241627.834.7NVIDIAMerlin Transformers4RecCWE-502NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker …
CVE-2026-448377.534.3ViewComponentview_componentCWE-187view_component: System Test Entry Point Path Check Allows Sibling Directory E…
CVE-2026-448438.233.8langchain-ailangchainCWE-502LangChain: Unsafe deserialization of attacker-controlled LangChain objects th…
CVE-2026-95212.933.3frailltbitseryCWE-20fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of sp…
CVE-2026-448446.332.8GOVCERT-LUeml_parserCWE-674eml_parser: Recursion DoS via nested message/rfc822 attachments
CVE-2026-448959.232.4yoda-digitalmcp-gitlab-serverCWE-306GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exp…
CVE-2026-95175.532.1hemant6488CodeIgniter-StudentManagementSystemCWE-266hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentV…
CVE-2026-419176.931.9OpenkmOpenKM Community EditionCWE-22OpenKM 6.3.12 Local File Inclusion via Admin Scripting
CVE-2026-86067.031.8GitHubEnterprise ServerCWE-918Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package …
CVE-2026-88507.531.1IBMHTTP ServerCWE-476IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-444509.930.8prolix-ocLumiverseCWE-88Lumiverse: RCE via MCP stdio argument injection
CVE-2026-81745.730.2ZohocorpZoho Mail wordpress pluginCWE-352Cross-site Request Forgery
CVE-2026-444449.130.1prolix-ocLumiverseCWE-78Lumiverse: Spindle extension install runs untrusted lifecycle scripts before …
CVE-2026-40517.229.9IBMEngineering Lifecycle ManagementCWE-749IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Serve…
CVE-2026-446689.829.5factionsecurityfactionCWE-306Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates
CVE-2026-22649.229.0Google CloudApigee-XCWE-918Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apige…
CVE-2026-94955.529.1n/a@koa/routerCWE-284Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnera…
CVE-2026-88547.529.0IBMHTTP ServerCWE-825IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-36037.128.6IBMEngineering Lifecycle ManagementCWE-611IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML e…
CVE-2026-420127.128.5Red HatRed Hat Enterprise Linux 10CWE-295Gnutls: gnutls: certificate validation bypass due to improper handling of uri…
CVE-2026-400348.528.2gitoxidegitoxideCWE-77gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule
CVE-2026-352238.627.8Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260508] - Improper access check in com_config webservice en…
CVE-2026-80467.227.8CODESYSCODESYS Control RTE (SL)CWE-863Incorrect Authorization in CODESYS Control
CVE-2026-94967.727.6n/apacoteCWE-1333Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable t…
CVE-2026-439828.727.4xyprotoalgernonCWE-22Algernon: Path traversal file write via savein()
CVE-2026-447076.827.4chatwootchatwootCWE-283Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts
CVE-2026-448366.527.3ViewComponentview_componentCWE-749view_component: Preview Route Can Dispatch Inherited Helper Methods
CVE-2026-96055.526.9GNUlibredwgCWE-119GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow
CVE-2026-95182.126.5hemant6488CodeIgniter-StudentManagementSystemCWE-79hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_stude…
CVE-2026-95192.126.5stonith404pingvin-shareCWE-79stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps …
CVE-2026-95202.126.5blitz-jsblitzCWE-79blitz-js blitz Sign-in LoginForm.tsx cross site scripting
CVE-2026-95272.126.5itsourcecodeElectronic Judging SystemCWE-79itsourcecode Electronic Judging System judges.php cross site scripting
CVE-2026-481268.226.4xyprotoalgernonCWE-22Algernon: Host header path traversal in --domain mode reads files and runs Lu…
CVE-2026-486836.526.0n/an/aCWE-125FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vul…
CVE-2026-95235.525.8Acrel ElectricalEEMS Enterprise Power Operation and Maintenance Cloud PlatformCWE-74Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platfo…
CVE-2026-467405.325.4RRWOMojolicious::Plugin::StatsdCWE-93Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric inj…
CVE-2026-96035.525.4SourceCodestereDoc Doctor Appointment SystemCWE-862SourceCodester eDoc Doctor Appointment System delete-session.php authorization
CVE-2025-114828.724.9B&R Industrial Automation GmbHPPT30 Operating SystemCWE-770Allocation of Resources Without Limits or Throttling in the OPC-UA Server
CVE-2026-352216.925.0Joomla! ProjectJoomla! CMSCWE-89Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder
CVE-2026-95255.524.7itsourcecodeElectronic Judging SystemCWE-74itsourcecode Electronic Judging System edit_judge.php sql injection
CVE-2026-95265.524.7itsourcecodeElectronic Judging SystemCWE-74itsourcecode Electronic Judging System edit_team.php sql injection
CVE-2026-95285.524.7itsourcecodeElectronic Judging SystemCWE-74itsourcecode Electronic Judging System delete_judge.php sql injection
CVE-2026-95515.524.6DasParking Management System 停车场管理系统CWE-74Das Parking Management System 停车场管理系统 API Endpoint ExportParkingRecords xp_cm…
CVE-2026-95525.524.6DasParking Management System 停车场管理系统CWE-74Das Parking Management System 停车场管理系统 Search API Endpoint sql injection
CVE-2026-447307.224.4OpenCTI-PlatformopenctiCWE-284OpenCTI: Privilege escalation via graphQL API abusable by organization admins…
CVE-2026-448328.724.2grokabilitysnipe-itCWE-281Snipe-IT: Privilege Escalation via API Permissions Assignment
CVE-2026-447886.524.0adamhathcocksharpcompressCWE-22SharpCompress: Directory traversal via directory entries in WriteToDirectory …
CVE-2025-362209.823.6IBMCloud Pak for Data System - CyclopsCWE-89Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.
CVE-2026-352226.923.7Joomla! ProjectJoomla! CMSCWE-89Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
CVE-2026-486919.823.4n/an/aCWE-190FastNetMon Community Edition through 1.2.9 contains an integer overflow in th…
CVE-2026-457287.522.8xyprotoalgernonCWE-209Algernon: Single-file mode unconditionally enables debug mode
CVE-2026-450827.622.6karakeep-appkarakeepCWE-918Karakeep has a SSRF Protection Bypass via Redirect Handling
CVE-2026-488968.222.2Joomla! ProjectJoomla! CMSCWE-287Joomla! Core - [20260511] - MFA Authentication Bypass
CVE-2026-439358.122.3e107ince107CWE-20e107: Host Header Injection in e107 password reset enables phishing
CVE-2026-486856.522.1n/an/aCWE-130FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access be…
CVE-2026-489048.221.7Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260514] - Privilege escalation through com_users webservice…
CVE-2026-95805.521.6n/aJeecgBootCWE-266JeecgBoot selectDepart LoginController.selectDepart access control
CVE-2026-95625.521.3sambitrajSTUDENT-MANAGEMENT-SYSTEMCWE-266sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control
CVE-2026-445024.321.1bugsinkbugsinkCWE-918Bugsink: SSRF bypass in `validate_webhook_url`
CVE-2026-486887.520.8n/an/aCWE-125FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds re…
CVE-2026-95662.120.7teableioteableCWE-79teableio teable Sign-up LoginPage.tsx cross site scripting
CVE-2026-447756.920.5KareaditaKavitaCWE-306Kavita: No authentication at /api/Reader/image
CVE-2026-86207.520.4IBMWeb Server Plug-ins for WebSphere Application Server and WebSphere LibertyCWE-444IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-442145.320.1rexxarseventsource-encoderCWE-93eventsource-encoder: SSE event injection via unsanitized event and id fields
CVE-2026-448477.519.31Panel-devMaxKBCWE-287MaxKB: Webhook Trigger Authentication Bypass
CVE-2025-362217.519.1IBMCloud Pak for Data System - CyclopsCWE-1392Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.
CVE-2026-488988.219.0Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260513] - Privilege escalation through com_users batch task
CVE-2026-486846.518.4n/an/aCWE-125FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in …
CVE-2025-713101.818.4BackdropCMSGDPR cookies module for Backdrop CMSCWE-80The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficien…
CVE-2026-88348.017.8IBMHTTP ServerCWE-122IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-95445.517.8Shenzhen Sixun SoftwareSixun Shanghui Group Business Management SystemCWE-74Shenzhen Sixun Software Sixun Shanghui Group Business Management System PayCo…
CVE-2026-95735.517.8itsourcecodeStudent Transcript Processing SystemCWE-74itsourcecode Student Transcript Processing System index.php sql injection
CVE-2026-95745.517.8itsourcecodeStudent Transcript Processing SystemCWE-74itsourcecode Student Transcript Processing System trans.php sql injection
CVE-2026-95755.517.8itsourcecodeStudent Transcript Processing SystemCWE-74itsourcecode Student Transcript Processing System index.php sql injection
CVE-2026-447298.717.6twentyhqtwentyCWE-79Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Con…
CVE-2026-447494.317.6SAP_SESAP GatewayCWE-497Information Disclosure vulnerability in SAP Gateway
CVE-2026-396425.317.3SpabRiceNylaCWE-80WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability
CVE-2026-95845.517.1code-projectsProject Management SystemCWE-74code-projects Project Management System Login chk.php sql injection
CVE-2026-96065.517.1itsourcecodeCourier Management SystemCWE-74itsourcecode Courier Management System manage_user.php sql injection
CVE-2026-489029.816.8Joomla! ProjectJoomla! CMSCWE-319Joomla! Core - [20260518] - Transport encryption downgrade for password and u…
CVE-2026-88357.316.9IBMHTTP ServerCWE-822IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-447765.916.7KareaditaKavitaCWE-639Kavita: IDOR in /api/Download/*
CVE-2025-143617.116.3AA-TeamWoocommerce Envato AffiliatesCWE-862WordPress Woocommerce Envato Affiliates plugin <= 1.2.1 - Settings Change vul…
CVE-2026-362394.316.3n/an/aCWE-79PbootCMS v.3.2.11 contains a code injection vulnerability in its site configu…
CVE-2026-95245.316.1xianrendzwEasyReportCWE-74xianrendzw EasyReport REST Endpoint execute sql injection
CVE-2026-245905.316.1VideoWhisper.comPaid Videochat Turnkey SiteCWE-862WordPress Paid Videochat Turnkey Site plugin <= 7.3.23 - Broken Access Contro…
CVE-2026-489017.516.0Joomla! ProjectJoomla! CMSCWE-524Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter …
CVE-2026-95832.115.6SourceCodesterCET Automated Grading System with AI Predictive AnalyticsCWE-200SourceCodester CET Automated Grading System with AI Predictive Analytics SQL …
CVE-2026-486948.114.5n/an/aCWE-77FastNetMon Community Edition through 1.2.9 contains a configuration injection…
CVE-2026-47956.514.5ZyxelGS1200-5v3 firmwareCWE-862A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions t…
CVE-2026-488995.314.6Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins
CVE-2026-486928.114.4n/an/aCWE-306FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port …
CVE-2026-423356.314.31Panel-devMaxKBCWE-918MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy
CVE-2026-396555.314.2TeconceThemeMayosis CoreCWE-862WordPress Mayosis Core plugin <= 5.4.7 - Broken Access Control vulnerability
CVE-2026-444519.314.0prolix-ocLumiverseCWE-693Lumiverse: TSX component sandbox escape via DOM ref and string-split identifi…
CVE-2026-447086.113.8lepturemistuneCWE-79Mistune Math Plugin XSS Escape Bypass
CVE-2026-448976.113.8lepturemistuneCWE-79Mistune Heading ID Attribute Injection XSS
CVE-2026-448986.113.8lepturemistuneCWE-79Mistune TOC Anchor Injection XSS
CVE-2026-448996.113.8lepturemistuneCWE-79Mistune Image Directive CSS Injection Vulnerability
CVE-2026-447068.513.6chatwootchatwootCWE-89Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribu…
CVE-2026-488647.813.6Red HatRed Hat Enterprise Linux 10CWE-787Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompre…
CVE-2026-86474.813.0MIKCrypt::ScryptKDFCWE-338Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number …
CVE-2026-96042.113.0n/aJeecgBootCWE-266JeecgBoot AiragModelController access control
CVE-2026-241907.812.9NVIDIAGeForceCWE-862NVIDIA Display Driver for Windows and Linux contains a vulnerability in the k…
CVE-2026-385874.312.9n/an/aCWE-639An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ON…
CVE-2026-464314.312.6xyprotoalgernonCWE-942Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
CVE-2026-95682.312.6n/aThingsBoardCWE-74ThingsBoard YAML provision getGatewayDockerComposeFile code injection
CVE-2026-448315.412.5grokabilitysnipe-itCWE-79Snipe-IT: XSS vulnerability in component notes
CVE-2026-246384.312.4Webful CreationsRepairBuddyCWE-862WordPress RepairBuddy plugin <= 4.1121 - Broken Access Control vulnerability
CVE-2026-446678.711.6factionsecurityfactionCWE-79Faction: Stored XSS in Remediation Verification Attachment Filename Preview R…
CVE-2026-446698.711.6factionsecurityfactionCWE-79Faction: Stored XSS in Assessment Attachment Filename Preview Rendering
CVE-2026-488978.211.7Joomla! ProjectJoomla! CMSCWE-287Joomla! Core - [20260512] - MFA Authentication Bypass
CVE-2026-95792.111.4n/aJeecgBootCWE-266JeecgBoot SysUser userEdit user.getUsername access control
CVE-2026-95812.111.4n/aJeecgBootCWE-266JeecgBoot add access control
CVE-2026-251047.811.0MediaAreaMediaInfoLibCWE-191MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability
CVE-2026-257137.811.0MediaAreaMediaInfoLibCWE-122MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability
CVE-2026-442136.511.1open-telemetryopentelemetry-dotnet-contribCWE-295OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a pro…
CVE-2026-454126.311.11Panel-devMaxKBCWE-918MaxKB: Unauthenticated SSRF via Workflow Template Import
CVE-2026-423375.311.11Panel-devMaxKBCWE-862MaxKB: Broken Access Control in MaxKB OSS URL Fetch API
CVE-2026-241927.810.9NVIDIAGeForceCWE-681NVIDIA Display Driver for Linux contains a vulnerability where an attacker co…
CVE-2026-86768.810.5silabs.comSimplicity SDKCWE-290An attacker is able to downgrade the security of a Bluetooth LE connection by…
CVE-2026-449057.510.5rieblvanetzaCWE-248Vanetza: Remote Denial of Service via Uncaught OER Encoding Exception in Cryp…
CVE-2026-95641.910.4SourceCodesterHospitals Patient Records Management SystemCWE-79SourceCodester/oretnom23 Hospitals Patient Records Management System view_pat…
CVE-2026-448965.310.0lepturemistuneCWE-79Mistune: XSS via unescaped figclass/figwidth in Figure directive
CVE-2026-88569.19.7IBMHTTP ServerCWE-400IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-241937.89.9NVIDIAGeForceCWE-787NVIDIA Display Driver for Windows and Linux contains a vulnerability where an…
CVE-2026-88527.59.8IBMHTTP ServerCWE-617IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-464304.39.8xyprotoalgernonCWE-668Algernon: Auto-refresh SSE event server binds to all interfaces by default on…
CVE-2026-424483.59.7magic-wormholemagic-wormholeCWE-22wormhole receive, with --output pointing at an existing directory can be path…
CVE-2026-95422.19.7CodeAstroLeave Management SystemCWE-74CodeAstro Leave Management System add_staff.php sql injection
CVE-2026-449858.79.6amir20dozzleCWE-346Dozzle: Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpoints bypas…
CVE-2025-361486.19.3IBMFinancial Transaction Manager for SWIFT Services for MultiplatformsCWE-79IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vu…
CVE-2026-439364.39.3e107ince107CWE-918e107: Server-Side Request Forgery (SSRF) in the remote file fetcher
CVE-2026-254265.39.1Magepeople inc.Taxi Booking Manager for WooCommerceCWE-862WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.1 - Broken Acces…
CVE-2025-687082.48.9n/an/aCWE-288SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local a…
CVE-2026-241878.88.7NVIDIAGeForceCWE-416NVIDIA Display Driver for Linux contains a vulnerability where an attacker co…
CVE-2026-423365.18.61Panel-devMaxKBCWE-367MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch
CVE-2025-687112.48.5n/an/aCWE-288AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz)…
CVE-2025-361267.68.3IBMCognos AnalyticsCWE-79IBM Cognos Analytics is affected by Cross-site scripting.
CVE-2026-443145.38.4traccartraccarCWE-863Traccar: Missing edit authorization on device image upload allows read-only u…
CVE-2026-439887.58.2rieblvanetzaCWE-248Vanetza: Remote Denial of Service via Uncaught Exception in ASN.1/OER Parsing
CVE-2026-439818.28.1xyprotoalgernonCWE-362Algernon: Race Condition in handle() shared LState
CVE-2026-259006.98.0Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260501] - XSS in feed modules
CVE-2026-308946.98.0Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260503] - XSS in com_contenthistory
CVE-2025-142905.48.1IBMwebMethods Integration (on prem) -Integration ServerCWE-918IBM webMethods Integration Sever is vulnerable to server-side request forgery
CVE-2026-449035.18.1prometheusprometheusCWE-79Prometheus: Stored XSS via crafted histogram bucket label values in the heatm…
CVE-2026-439346.58.0e107ince107CWE-284e107: Broken Access Control in e107 comment edit allows cross-user comment mo…
CVE-2025-687102.47.7n/an/aCWE-288Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9…
CVE-2026-477284.37.6bugsinkbugsinkCWE-862Bugsink: Project scoping missing in sourcemap and debug-file lookup
CVE-2025-687095.27.5n/an/aCWE-79SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local a…
CVE-2026-259016.97.3Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260502] - XSS in com_associations
CVE-2026-308956.97.3Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260504] - XSS in readmore links
CVE-2025-332216.07.3NVIDIAGeForceCWE-20NVIDIA Display Driver for Windows and Linux contains a vulnerability in the k…
CVE-2026-33144.67.3HitachiHitachi Ops Center AnalyzerCWE-549Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi…
CVE-2026-472029.36.8KareaditaKavitaCWE-287Kavita: Pre-Auth Account Takeover
CVE-2026-274276.56.9Dylan KuhnGeo MashupCWE-79WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-84796.96.7Hitachi EnergyRTU500 series CMU firmwareCWE-476IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL…
CVE-2026-95411.96.7n/aSquirrelCWE-119Squirrel Cnut File sqobject.cpp ReadObject heap-based overflow
CVE-2026-242007.06.5NVIDIAVirtual GPU ManagerCWE-416NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, whe…
CVE-2026-74517.86.3Autodesk3ds MaxCWE-787TIF File Parsing Out-of-Bounds Write in Autodesk 3ds Max
CVE-2026-74527.86.3Autodesk3ds MaxCWE-120WRL File Parsing Memory Corruption in Autodesk 3ds Max
CVE-2026-241967.16.4NVIDIAGeForceCWE-125NVIDIA Display Driver for Linux contains a vulnerability where a user could c…
CVE-2025-361455.36.3IBMwatsonx.dataCWE-923Multiple Vulnerabilities in watsonx.data
CVE-2026-486977.46.0n/an/aCWE-295FastNetMon Community Edition through 1.2.9 does not verify TLS certificates o…
CVE-2026-448337.16.0grokabilitysnipe-itCWE-601Snipe-IT: Open redirect vulnerability
CVE-2026-476726.55.9oviva-agepa4all-clientCWE-306epa4all-client: Unauthenticated REST API for Patient Record Writes
CVE-2026-241955.55.9NVIDIAGuest driverCWE-20NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user…
CVE-2026-95721.95.8n/aGPACCWE-401GPAC MP4Box media.c Media_GetSample memory leak
CVE-2026-241976.55.6NVIDIAGeForceCWE-1188NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instanc…
CVE-2026-489006.45.7Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler
CVE-2026-95822.15.5SourceCodesterCET Automated Grading System with AI Predictive AnalyticsCWE-352SourceCodester CET Automated Grading System with AI Predictive Analytics cros…
CVE-2026-273316.35.4Magepeople inc.WpTravellyCWE-862WordPress WpTravelly plugin <= 2.1.5 - Broken Access Control vulnerability
CVE-2026-241985.65.2NVIDIAGeForceCWE-200NVIDIA GPU Display Driver for Linux contains a vulnerability where an advance…
CVE-2026-74505.55.1Autodesk3ds MaxCWE-476PAR File Parsing NULL Pointer Dereference in Autodesk 3ds Max
CVE-2026-74535.55.1Autodesk3ds MaxCWE-674WRL File Parsing Memory Exhaustion in Autodesk 3ds Max
CVE-2026-245204.35.2bPluginsTiktok FeedCWE-862WordPress Tiktok Feed plugin <= 1.0.24 - Broken Access Control vulnerability
CVE-2026-254444.35.2Magepeople inc.WpBookinglyCWE-862WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability
CVE-2026-477153.15.1bugsinkbugsinkCWE-639Bugsink: Issue event views can show an event from another project if its UUID…
CVE-2026-241947.84.9NVIDIAGeForceCWE-281NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode lay…
CVE-2026-449837.34.8servosmallbitvecCWE-122smallbitvec: Safe API Triggered Heap Buffer Overflow via Integer Overflow
CVE-2025-463075.54.7ApplemacOSCWE-284A logic issue was addressed with improved restrictions. This issue is fixed i…
CVE-2026-489036.94.6Joomla! ProjectJoomla! Framework Filter packageCWE-79Joomla! Framework - [20260519] - Inadequate content filtering within the chec…
CVE-2026-489056.94.6Joomla! ProjectJoomla! Framework Filter packageCWE-79Joomla! Framework - [20260520] - Inadequate content filtering within the clea…
CVE-2026-477163.14.4bugsinkbugsinkCWE-639Bugsink: Issue bulk actions can affect another project’s issue if its UUID is…
CVE-2026-251127.84.3Genetec Inc.Genetec RabbitMQCWE-732A high-severity vulnerability in the deployment of Genetec RabbitMQ that allo…
CVE-2026-242015.84.1NVIDIAVirtual GPU ManagerCWE-787NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, whe…
CVE-2026-95291.94.1GNULibreDWGCWE-404GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer derefe…
CVE-2026-95301.94.1GNULibreDWGCWE-119GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds
CVE-2025-432895.53.7ApplemacOSCWE-285A logic issue was addressed with improved validation. This issue is fixed in …
CVE-2026-455748.13.7oviva-agepa4all-clientCWE-295epa4all-client: TLS Certificate Validation Disabled in Production
CVE-2026-241917.83.7NVIDIAGeForceCWE-367NVIDIA Display Driver for Windows contains a vulnerability where an attacker …
CVE-2025-462805.53.5ApplemacOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2025-433067.83.4ApplemacOSCWE-269A logic issue was addressed with improved checks. This issue is fixed in macO…
CVE-2025-434515.53.4ApplemacOSCWE-284A permissions issue was addressed by removing the vulnerable code. This issue…
CVE-2026-466206.53.2e107ince107CWE-285e107: CSRF in comment.php moderation endpoints via token-optional validation …
CVE-2026-74547.83.2Autodesk3ds MaxCWE-120WRL File Parsing Memory Corruption in Autodesk 3ds Max
CVE-2026-444103.83.2ZTEZXUniPOS NDS-LTECWE-1240Function Abusement Vulnerability in ZTE ZXUniPOS NDS-LTE
CVE-2025-432905.53.0ApplemacOSCWE-732A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-486935.52.7n/an/aCWE-59FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink a…
CVE-2026-447287.82.6babelbabelCWE-94Improper Control of Generation of Code when compiling specifically crafted ma…
CVE-2026-241826.52.6NVIDIAGeForceCWE-667NVIDIA Display Driver for Windows and Linux contains a vulnerability where an…
CVE-2026-486966.22.6n/an/aCWE-120FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different…
CVE-2026-444688.52.5CODESYSCODESYS Development SystemCWE-276Incorrect Default Permissions in CODESYS Development System
CVE-2026-458345.52.4LinuxLinuxCWE-476Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
CVE-2026-458355.52.4LinuxLinuxCWE-476Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
CVE-2026-458365.52.4LinuxLinuxCWE-476Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
CVE-2026-449008.12.2oviva-agepa4all-clientCWE-295epa4all-client: VAU Signature bypass
CVE-2026-455757.42.0oviva-agepa4all-clientCWE-347epa4all-client: Improper Verification of Cryptographic Signature
CVE-2026-444434.82.0prolix-ocLumiverseCWE-362Lumiverse: Sign-up nonce race condition allows unauthorized account registration
CVE-2026-486907.11.9n/an/aCWE-122FastNetMon Community Edition through 1.2.9 contains an integer overflow vulne…
CVE-2026-95671.91.8n/aGPACCWE-404GPAC MP4Box isom_intern.c MergeFragment null pointer dereference
CVE-2025-137555.51.4IBMDb2CWE-532IBM® Db2® is vulnerable to credential exposure in db2diag when executing spec…
CVE-2026-352204.61.4Joomla! ProjectJoomla! CMSCWE-352Joomla! Core - [20260505] - CSRF in user activation endpoint
CVE-2026-444698.51.2CODESYSCODESYS Development SystemCWE-276Incorrect Default Permissions in CODESYS Development System
CVE-2025-462847.01.1ApplemacOSCWE-362A race condition was addressed with additional validation. This issue is fixe…
CVE-2026-73104.41.1Hitachi EnergyMACH HiDrawCWE-122A heap-based buffer overflow vulnerability exists in XML parser functionality…
CVE-2026-241994.70.6NVIDIAGeForceCWE-362NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, …
CVE-2026-454136.90.31Panel-devMaxKBCWE-328MaxKB: Unsalted MD5 Password Hashing
CVE-2026-411644.40.1nuts-foundationnuts-nodeCWE-345nuts-node: JWT type confusion in v1 access token introspection allows VP repl…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-26 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.