boxscore/security
Wednesday, May 27, 2026 · all times UTC← 2026-05-26 · archive · 2026-05-28 →

715 CVEs published May 27, 2026: 49 critical, 296 high, 357 medium, 12 low; 3 in KEV; 30 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 690 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published2349347910212563
KEV catalog size1670

105 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux5048307254920712720.27.8.0014+341
microsoft170490433281020378275.57.8.0045-16
apple204701227193714.96.2.0034+20
red hat2144722132400.07.5.0041+10
google17231136074417.48.6.0034+16
freebsd770520000.07.8.0020+7
suse220200000.08.2.0020+2
android0000001500
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco513312096861.58.6.1247+2
checkpoint660330300.06.5.0338+6
fortinet16130028350.07.9.4330-2
ivanti25010033480.08.8.8056+1
f52320007133.39.2.0996+2
ubiquiti231200400.08.8.0068+2
broadcom02000042100.0.19900
palo alto networks110000141100.0.3207+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache19304141104013.37.4.0065+16
gitlab6801504225.04.8.0033+6
mozilla6632101300.08.8.0042+6
docker330300100.08.8.0022+3
drupal3310205133.35.1.0021+3
github221100000.08.1.0347+2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm49491024150700.07.5.0028+49
progress440400900.07.5.0036+4
adobe14010075375.08.6.2776-2
solarwinds031000113100.09.8.83620
zohocorp220110000.07.1.0104+2
oracle0202004000.07.5.00650
atlassian0000001300
sap0000001200
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology181823103000.05.6.0025+18
hitachi energy220020000.05.7.0014+2
d-link12010026150.08.7.45110
siemens110100100.08.7.0032+1
hikvision01000021100.01.00000
dahua000000200
qnap000000800
schneider electric000000100
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44
edimax4444027017100.07.4.0059+44
helmholz424203930000.07.1.0026+42
mb connect line424203930000.07.1.0026+42
open ises3737214210000.06.9.0021+37
totolink343402509000.08.9.0191+34
netatalk3333113910000.06.4.0030+33
nvidia333381870000.07.8.0038+33

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2008-4250.987599.9
CVE-2026-41940.979399.99.3
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2024-1708.875699.78.4
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4659510.0.0050
CVE-2026-4282210.0.0049
Most disclosures (vendor)
VendorCVEs
linux506
microsoft171
ibm49
concrete cms44
edimax44
helmholz42
mb connect line42
open ises37
totolink34
netatalk33
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google4
ivanti4
synacor4
adobe3
fortinet3
smartertools3
solarwinds3
Most-affected ecosystems
EcosystemAdvisories
Maven10
PyPI2
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2024-1708ConnectWise0
CVE-2025-34291Langflow0
CVE-2026-0300Palo Alto Networks0
CVE-2026-20182Cisco0
CVE-2026-31431Linux0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171652
CVE-2021-27102Accellion2021-11-171652
CVE-2021-27101Accellion2021-11-171652
CVE-2021-27103Accellion2021-11-171652
CVE-2021-21017Adobe2021-11-171652
CVE-2021-28550Adobe2021-11-171652
CVE-2021-42013Apache2021-11-171652
CVE-2021-41773Apache2021-11-171652
CVE-2021-30858Apple2021-11-171652
CVE-2021-30860Apple2021-11-171652

Transactions

EXPLOIT PUBLISHEDCVE-2026-42081 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42082 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42083 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42184 (tauri-apps tauri). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42459 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44315 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44316 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44317 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44318 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44319 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44320 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44321 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44322 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44323 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44324 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44325 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44326 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44327 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44328 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44329 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44330 (free5gc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44345 (BentoML). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44346 (BentoML). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44353 (streamlink). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44660 (ultrajson). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44681 (authlib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45104 (MapServer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45136 (cnighswonger claude-code-cache-fix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48027 (nrwl nx-console). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-9617 (DALIBO PostgreSQL Anonymizer). Public exploit reference added.

Yesterday's Results

715 CVEs published. 25 box scores and 375 table rows below; the remaining 315 continue on page 2 — every CVE is listed, nothing truncated.

@tanstack arktype-adapter — Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0234   82.2   YES
AFFECTED
  Product                 Versions    Fixed
  arktype-adapter         1.166.12 –  —
  eslint-plugin-router    1.161.9 –   —
  eslint-plugin-start     0.0.4 –     —
  history                 1.161.9 –   —
  nitro-v2-vite-plugin    1.154.12 –  —
  react-router            1.169.5 –   —
  react-router-devtools   1.166.16 –  —
  react-router-ssr-query  1.166.15 –  —
  react-start             1.167.68 –  —
  react-start-client      1.166.51 –  —
  + 32 more
TIMELINE
  May 11  Reserved by CNA
  May 27  Added to CISA KEV, due Jun 10
  May 27  Published (CNA: GitHub_M)
CWE-506 · CNA: GitHub_M · 5 references · KEV due June 10, 2026
nrwl nx-console — Compromised Nx Console version 18.95.0
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0185   77.3   YES
AFFECTED
  Product     Versions     Fixed
  nx-console  = 18.95.0 –  —
TIMELINE
  May 20  Reserved by CNA
  May 27  Public exploit reference published
  May 27  Added to CISA KEV, due Jun 10
  May 27  Published (CNA: GitHub_M)
CWE-506 · CNA: GitHub_M · 5 references · NVD status: Analyzed · KEV due June 10, 2026
CVE-2026-8398AWAITING ENRICHMENT
Daemon Daemon Tools Lite
  CVSS   EPSS    %ile   KEV
  —      .0146   71.3   YES
AFFECTED
  Product            Versions     Fixed
  Daemon Tools Lite  unspecified  —
TIMELINE
  May 27  Added to CISA KEV, due May 30
  May 27  Published
0 references · KEV due May 30, 2026
GitHub Enterprise Server — Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0655   93.2     —
AFFECTED
  Product            Versions  Fixed
  Enterprise Server  3.16.0 –  3.16.20
TIMELINE
  May 22  Reserved by CNA
  May 27  Published (CNA: GitHub_P)
CWE-918 · CNA: GitHub_P · 5 references · NVD status: Modified
Synology BeeStation OS — Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Syno…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0276   85.0     —
AFFECTED
  Product        Versions  Fixed
  BeeStation OS  1.3 –     —
TIMELINE
  Nov 4   Reserved by CNA
  May 27  Published (CNA: synology)
CWE-120 · CNA: synology · 1 reference · NVD status: Analyzed
TP-Link Systems Inc. Archer BE7200 V1 — Arbitrary Command Injection via Browser Developer Console in TP-Link Archer BE450 and BE7200
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   H   H   H    8.5   .0246   83.1     —
AFFECTED
  Product           Versions     Fixed
  Archer BE7200 V1  unspecified  —
  Archer BE450 v1   unspecified  —
TIMELINE
  Apr 3   Reserved by CNA
  May 27  Published (CNA: TPLink)
CWE-77, CWE-20 · CNA: TPLink · 5 references · NVD status: Modified
smub WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager — WPCode <= 2.3.5 - Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPost
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0186   77.5     —
AFFECTED
  Product                                                                              Versions     Fixed
  WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  May 27  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · 8 references · NVD status: Deferred
microsoft UFO — OS Command Injection in Microsoft UFO Shell Action Replay via Stored Session JSON
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0172   75.6     —
AFFECTED
  Product  Versions    Fixed
  UFO      <= 3.0.0 –  —
TIMELINE
  May 11  Reserved by CNA
  May 27  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 1 reference · NVD status: Deferred
dotCMS dotCMS Core — Unauthenticated SQL Injection in dotCMS Publish Audit API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0158   73.5     —
AFFECTED
  Product      Versions      Fixed
  dotCMS Core  25.11.04-1 –  26.04.28-03
TIMELINE
  May 6   Reserved by CNA
  May 27  Published (CNA: dotCMS)
CWE-89 · CNA: dotCMS · 2 references · NVD status: Deferred
hahwul dalfox — Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0147   71.6     —
AFFECTED
  Product  Versions    Fixed
  dalfox   < 2.13.0 –  —
TIMELINE
  May 8   Reserved by CNA
  May 27  Published (CNA: GitHub_M)
CWE-15, CWE-78, CWE-306 · CNA: GitHub_M · 2 references · NVD status: Deferred
OALDERS HTTP::Daemon — HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0140   70.2     —
AFFECTED
  Product       Versions     Fixed
  HTTP::Daemon  unspecified  —
TIMELINE
  May 12  Reserved by CNA
  May 27  Published (CNA: CPANSec)
CWE-73, CWE-78 · CNA: CPANSec · 11 references · NVD status: Deferred
n/a n/a — Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/sk…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0132   68.4     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 27  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Deferred
n/a n/a — picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/s…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0131   68.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 27  Published (CNA: mitre)
CWE-78 · CNA: mitre · 2 references · NVD status: Deferred
sherlock-project sherlock — Sherlock: Command Injection via pull_request_target in validate_modified_targets.yml
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  H  N    9.3   .0114   64.0     —
AFFECTED
  Product   Versions    Fixed
  sherlock  < 0.16.1 –  —
TIMELINE
  May 6   Reserved by CNA
  May 27  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Red Hat Red Hat Enterprise Linux 10 — Samba: vfs_worm does not block directory modification
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .0094   58.0     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:4.23.5-109.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:4.21.3-114.el10_0.1
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:4.15.5-16.el8_6.1
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:4.15.5-16.el8_6.1
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:4.17.5-7.el8_8.1
  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions         unspecified  0:4.17.5-7.el8_8.1
  Red Hat Enterprise Linux 9                                             unspecified  0:4.23.5-10.el9_8
  Red Hat Enterprise Linux 9                                             unspecified  0:4.23.5-10.el9_8
  + 7 more
TIMELINE
  Feb 11  Reserved by CNA
  May 27  Published (CNA: redhat)
CWE-280 · CNA: redhat · 13 references · NVD status: Modified
Red Hat Red Hat Enterprise Linux 10 — Samba: missing access check on reparse point operations
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .0086   55.6     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:4.23.5-109.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:4.21.3-114.el10_0.1
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:4.15.5-16.el8_6.1
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:4.15.5-16.el8_6.1
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:4.17.5-7.el8_8.1
  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions         unspecified  0:4.17.5-7.el8_8.1
  Red Hat Enterprise Linux 9                                             unspecified  0:4.23.5-10.el9_8
  Red Hat Enterprise Linux 9                                             unspecified  0:4.23.5-10.el9_8
  + 10 more
TIMELINE
  Feb 4   Reserved by CNA
  May 27  Published (CNA: redhat)
CWE-284 · CNA: redhat · 17 references · NVD status: Modified
n/a n/a — Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversar…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0083   54.4     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 9   Reserved by CNA
  May 27  Published (CNA: mitre)
CWE-77 · CNA: mitre · 3 references · NVD status: Awaiting Analysis
n/a n/a — Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0081   54.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 27  Published (CNA: mitre)
CWE-121 · CNA: mitre · 3 references · NVD status: Deferred
n/a n/a — Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0080   53.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 27  Published (CNA: mitre)
CWE-77 · CNA: mitre · 4 references · NVD status: Awaiting Analysis
IBM Langflow OSS — Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0079   53.1     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Apr 30  Reserved by CNA
  May 27  Published (CNA: ibm)
CWE-22 · CNA: ibm · 1 reference · NVD status: Analyzed
uniget-org cli — uniget: Command Injection in tool.Check Leading to Arbitrary Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0072   50.7     —
AFFECTED
  Product  Versions    Fixed
  cli      < 0.27.1 –  —
TIMELINE
  May 8   Reserved by CNA
  May 27  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Linux Linux — netfilter: nf_conncount: increase the connection clean up limit to 64
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0069   49.7     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f106694733c66a48740c25bc4e212e9b2ea364ce –  —
  Linux    5.19 –                                      5.10.252
TIMELINE
  May 13  Reserved by CNA
  May 27  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Analyzed
Microsoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directory
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0067   49.2     —
AFFECTED
  Product  Versions             Fixed
  UFO      3.0.1-4-ge2626659 –  —
TIMELINE
  May 13  Reserved by CNA
  May 27  Published (CNA: GitHub_M)
CWE-22, CWE-73 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Slican IPx — Authentication Bypass in Slican telephone exchanges
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0066   48.7     —
AFFECTED
  Product   Versions     Fixed
  IPx       unspecified  —
  CCT-1668  unspecified  —
  MAC-6400  unspecified  —
  CXS-0424  unspecified  —
  NCP       unspecified  —
TIMELINE
  Apr 1   Reserved by CNA
  May 27  Published (CNA: CERT-PL)
CWE-288 · CNA: CERT-PL · 1 reference · NVD status: Deferred
Slican CCT-1668 — Authentication Bypass in Slican telephone exchanges
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0063   47.1     —
AFFECTED
  Product   Versions     Fixed
  CCT-1668  unspecified  —
  MAC-6400  unspecified  —
  CXS-0424  unspecified  —
  IPL-256   unspecified  —
  IPM-032   unspecified  —
TIMELINE
  Apr 1   Reserved by CNA
  May 27  Published (CNA: CERT-PL)
CWE-288 · CNA: CERT-PL · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-447247.846.8sebhildebrandtsysteminformationCWE-78systeminformation: Linux command injection in networkInterfaces() via unsanit…
CVE-2026-87609.846.7india-web-developerLogin with OTPCWE-307Login with OTP <= 1.6 - Unauthenticated Authentication Bypass via OTP Brute F…
CVE-2026-384267.346.6n/an/aCWE-120Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows…
CVE-2026-458597.546.4LinuxLinuxnetfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation
CVE-2026-61697.246.0cservitaffiliate-toolkit – Multi-Network Affiliate & Amazon Product DisplayCWE-94affiliate-toolkit <= 3.8.5 - Authenticated (Editor+) Remote Code Execution
CVE-2026-33667.545.7IBMInfoSphere Optim Test Data FabricationCWE-22InfoSphere Optim Test Data Fabrication is affected by Arbitrary File Read
CVE-2026-350898.745.4SlicanIPxCWE-1391Use of Weak Credentials in Slican telephone exchanges
CVE-2026-81759.845.0IBMAspera High-Speed Transfer EndpointCWE-122Multiple vulnerabilities in Aspera applications.
CVE-2026-448879.843.2leiweibauPi.AlertCWE-94Unauthenticated RCE via Python Config File Injection in SaveConfigFile() (Path)
CVE-2025-133929.842.5SynologyDiskStation Manager (DSM)CWE-754Improper check for unusual or exceptional conditions vulnerability in SSO in …
CVE-2026-464148.842.4microsoftUFOCWE-290Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking
CVE-2026-490093.141.8n/an/aCWE-22Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and…
CVE-2026-460439.141.4LinuxLinuxRDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
CVE-2026-460277.540.6LinuxLinuxnet/smc: avoid early lgr access in smc_clc_wait_msg
CVE-2026-460527.540.6LinuxLinuxceph: only d_add() negative dentries when they are unhashed
CVE-2026-461027.540.6LinuxLinuxCWE-401net: strparser: fix skb_head leak in strp_abort_strp()
CVE-2026-44107.540.6IBMWebSphere Application Server - LibertyCWE-400IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-96277.440.4UTTHiPER 1200GWCWE-119UTT HiPER 1200GW Web Management setSysAdm strcpy buffer overflow
CVE-2026-92007.540.3shazdehQuery ShortcodeCWE-98Query Shortcode <= 0.2.1 - Authenticated (Contributor+) Local File Inclusion …
CVE-2026-460247.540.0LinuxLinuxCWE-476libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()
CVE-2026-471618.739.9inducerrelateCWE-502RELATE Vulnerable to Remote Code Execution (RCE) via Insecure Celery Pickle D…
CVE-2025-147137.539.0SynologyC2 Identity Edge ServerCWE-749An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity…
CVE-2026-96287.438.8UTTHiPER 1200GWCWE-119UTT HiPER 1200GW Web Management formPptpClientConfig stack-based overflow
CVE-2026-14026.538.7GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-458989.838.4LinuxLinuxCWE-1341RDMA/iwcm: Fix workqueue list corruption by removing work_list
CVE-2024-564628.838.3IBMQRadarCWE-552IBM QRadar SIEM is vulnerable to using components with known vulnerabilities
CVE-2026-96327.438.2UTTHiPER 1250GWCWE-119UTT HiPER 1250GW Web Management formGroupConfig strcpy stack-based overflow
CVE-2026-384277.337.9n/an/aCWE-122An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 a…
CVE-2026-459889.837.9LinuxLinuxrxrpc: Fix re-decryption of RESPONSE packets
CVE-2026-449027.537.7open-telemetryopentelemetry-jsCWE-755opentelemetry-js: Prometheus exporter process crash via malformed HTTP request
CVE-2026-460399.836.8LinuxLinuxCWE-190rxgk: Fix potential integer overflow in length check
CVE-2026-450477.536.7xddxddbird-lg-goCWE-400bird-lg-go: Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON De…
CVE-2026-460857.536.7LinuxLinuxrxrpc: Fix rxkad crypto unalignment handling
CVE-2026-96317.436.5UTTHiPER 1250GWCWE-119UTT HiPER 1250GW Web Management formConfigFastDirectionW strcpy stack-based o…
CVE-2026-460378.236.1LinuxLinuxipv4: icmp: validate reply type before using icmp_pointers
CVE-2026-465445.335.3microsoftUFOCWE-639Microsoft UFO reuses client-supplied WebSocket session IDs and replays stale …
CVE-2026-92088.835.1TaniumConnectCWE-78Tanium addressed an unauthorized code execution vulnerability in Connect.
CVE-2026-446608.735.1ultrajsonultrajsonCWE-401UltraJSON: Memory Leak in ujson.dump() on Write Failure
CVE-2026-43916.935.0n/aTeamSpeak 3 ServerCWE-119TeamSpeak 3 Server ECC Key heap-based overflow
CVE-2026-443246.535.0free5gcfree5gcCWE-704free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via …
CVE-2026-450839.834.1intrandagoobi-viewer-coreCWE-306Goobi viewer: Unauthenticated Solr Streaming Expression Proxy
CVE-2026-485448.734.0AvaigataipyCWE-22Taipy 4.1.1 Path Traversal via ElementLibrary.get_resource()
CVE-2025-701164.333.9n/an/aCWE-476A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4…
CVE-2026-443167.533.6free5gcfree5gcCWE-476free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/…
CVE-2026-443197.533.6free5gcfree5gcCWE-20free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (a…
CVE-2026-460108.133.6LinuxLinuxrxrpc: Fix error handling in rxgk_extract_token()
CVE-2026-43926.933.4n/aTeamSpeak 3 ServerCWE-617TeamSpeak 3 Server clientek Handshake assertion
CVE-2026-36766.533.4IBMCloud APM, Base PrivateCWE-1284There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Pe…
CVE-2026-81798.833.3IBMAspera High-Speed Transfer EndpointCWE-121Multiple vulnerabilities in Aspera applications.
CVE-2026-491039.432.8WebminWebminCWE-24Webmin before 2.640 does not safely construct a filename for saving of an att…
CVE-2026-408508.732.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in getAccountData function
CVE-2026-443257.532.5free5gcfree5gcCWE-20free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic f…
CVE-2026-92078.832.3TaniumConnectCWE-78Tanium addressed an unauthorized code execution vulnerability in Connect.
CVE-2026-89948.132.2learnnearclubLogin with NEARCWE-287Login with NEAR <= 0.3.3 - Authentication Bypass via 'account' Parameter
CVE-2026-443227.532.2free5gcfree5gcCWE-476free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR acc…
CVE-2024-287655.331.6IBMSDICWE-209Security vulnerability was found in IBM Security Directory Integrator
CVE-2026-377117.331.6n/an/aCWE-94An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha all…
CVE-2026-377127.331.6n/an/aCWE-94An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha all…
CVE-2026-377137.331.6n/an/aCWE-94An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha all…
CVE-2026-30016.130.9jegstudioGutenverse – WordPress Blocks, Page Builder & Site EditorCWE-79Gutenverse <= 3.4.6 - Reflected Cross-Site Scripting via 's' Parameter
CVE-2026-471187.130.63clyp50agent-zeroCWE-22Agent Zero < 1.15 Path Traversal File Read via image_get API
CVE-2026-489597.530.5PMQSIO::Uncompress::UnzipCWE-407IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via…
CVE-2026-460317.530.1LinuxLinuxCWE-667net: ks8851: Reinstate disabling of BHs around IRQ handler
CVE-2026-408527.230.1MB connect linembNET/mbNET.rokeyCWE-78Command injection via malicious configuration
CVE-2025-300288.629.9SynologyActive Backup for BusinessCWE-89A vulnerability in Active Backup for Business allows unauthorized remote atta…
CVE-2025-701037.329.8n/an/aCWE-122Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to…
CVE-2026-455702.329.6go-gitgo-gitCWE-116go-git: Improper single-quote escaping in go-git SSH transport
CVE-2026-443217.529.5free5gcfree5gcCWE-306free5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlappi…
CVE-2026-17187.529.3IBMDb2CWE-770IBM® Db2® is vulnerable to a denial of service with a specially crafted query…
CVE-2026-446357.529.3kysely-orgkyselyCWE-22Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters…
CVE-2024-406849.829.0IBMOperations Analytics - Log AnalysisCWE-521IBM Operations Analytics - Log Analysis is affected by Weak Password Policy a…
CVE-2026-427579.929.0Saleswonder Team: TobiasWebinarIgnitionCWE-22WordPress WebinarIgnition plugin < 4.08.253 - Arbitrary File Deletion vulnera…
CVE-2026-33757.228.9litespeedtechLiteSpeed CacheCWE-79LiteSpeed Cache <= 7.7 - Unauthenticated Stored Cross-Site Scripting via QUIC…
CVE-2026-427378.628.9e4jvikwpVikBooking Hotel Booking Engine & PMSCWE-22WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Arbitrary F…
CVE-2026-365397.328.9n/an/aCWE-200Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.…
CVE-2026-458438.228.6LinuxLinuxslip: bound decode() reads against the compressed packet length
CVE-2026-83617.528.1GladinetTriofoxCWE-23Gladinet Triofox Path Traversal in WOSDefaultHttpModule.dll
CVE-2026-485457.628.1gradio-appgradioCWE-384Gradio < 6.15.0 Cookie Injection via Shared Proxy Client
CVE-2026-489227.528.1Jenkins ProjectJenkins Credentials Binding PluginCWE-20Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not pr…
CVE-2026-443176.528.1free5gcfree5gcCWE-476free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1…
CVE-2026-443236.528.1free5gcfree5gcCWE-476free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when U…
CVE-2026-74935.328.1croixhaugAppointment Booking Calendar — Simply Schedule Appointments Booking PluginCWE-400Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <=…
CVE-2026-443536.527.5streamlinkstreamlinkCWE-22Streamlink: Arbitrary local file read via file:// URI in HLS and DASH
CVE-2026-480648.127.3mcdopepam_usbCWE-863pam_usb: PAM_RHOST check skipped when deny_remote=false allows XDMCP authenti…
CVE-2026-388078.827.1n/an/aCWE-639Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attack…
CVE-2026-48688.227.1GitLabGitLabCWE-639Authorization Bypass Through User-Controlled Key in GitLab
CVE-2024-472684.927.0SynologySurveillance StationCWE-862Missing authorization vulnerability in AddOns functionality in Synology Surve…
CVE-2024-472714.927.0SynologySurveillance StationCWE-522Insufficiently protected credentials vulnerability in IPSpeaker component in …
CVE-2026-427907.626.8ErlangOTPCWE-295nameConstraints DNS bypass via subject CommonName fallback in public_key host…
CVE-2026-427569.926.5Ludwig YouQuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO FriendlyCWE-22WordPress QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendl…
CVE-2026-83639.826.4GladinetTriofoxCWE-121Gladinet Triofox Stack-based Buffer Overflow in WOSDeviceDropFolder.dll
CVE-2026-427319.826.2miniOrangeminiorange otp verificationCWE-266WordPress miniorange otp verification plugin <= 5.4.9 - Privilege Escalation …
CVE-2026-459729.826.2LinuxLinuxCWE-416smb: client: fix potential UAF and double free in smb2_open_file()
CVE-2026-4432910.025.9free5gcfree5gcCWE-306free5GC: SMF UPI management interface lacks auth middleware; unauthenticated …
CVE-2026-427897.025.9ErlangOTPCWE-295Non-CA certificate accepted as intermediate issuer in public_key path validation
CVE-2026-481285.125.8BudibasebudibaseCWE-918Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step
CVE-2026-90356.525.3IBMAspera High-Speed Transfer EndpointCWE-22Multiple vulnerabilities in Aspera applications.
CVE-2024-472672.725.4SynologySurveillance StationCWE-22Improper limitation of a pathname to a restricted directory ('Path Traversal'…
CVE-2026-443288.225.2free5gcfree5gcCWE-306free5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion…
CVE-2026-424597.725.2free5gcfree5gcCWE-20free5GC: Improper Input Validation and Generation of Error Message Containing…
CVE-2026-408317.125.2MB connect linembCONNECT24CWE-89Authenticated SQLi in Easy View
CVE-2026-443786.925.3randombitbotanCWE-407Botan: Quadratic complexity decoding BER indefinite length encodings
CVE-2026-420838.225.1free5gcfree5gcCWE-862free5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows un…
CVE-2025-713115.525.2LinuxLinuxCWE-908fs/ntfs3: Initialize new folios before use
CVE-2026-490177.125.0OpenStackSwiftCWE-835In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infin…
CVE-2026-67135.325.0GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-96894.225.0Red HatRed Hat build of Keycloak 26.4CWE-1288Keycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redire…
CVE-2026-443468.824.9bentomlBentoMLCWE-78BentoML: Dockerfile command injection via envs[*].name in bentofile.yaml
CVE-2026-460998.124.9LinuxLinuxCWE-911net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
CVE-2026-427589.824.8Saleswonder Team: TobiasWebinarIgnitionCWE-266WordPress WebinarIgnition plugin < 4.08.253 - Privilege Escalation vulnerability
CVE-2026-97048.824.8Red HatRed Hat build of Keycloak 26.4CWE-1284Keycloak: keycloak: privilege escalation due to oversized subject_token jwt
CVE-2026-408108.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in userinfo Endpoint
CVE-2026-408118.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in ssoabstractservice
CVE-2026-408128.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in getLiveValues function
CVE-2026-408138.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in getLiveValues
CVE-2026-408148.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in _mb24confi_getTagAlarm function
CVE-2026-408158.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in _mb24api_getUserAccount function
CVE-2026-408168.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in _mb24confi_getTagAlarm function
CVE-2026-408178.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in getAlarmProfiles function
CVE-2026-408188.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in _mb24confi_getDevice function function
CVE-2026-408198.724.7MB connect linembCONNECT24CWE-89Unauthenticated SQLi in sync_data24 task
CVE-2026-451047.524.8MapServerMapServerCWE-476MapServer: NULL pointer dereference in SLD `<ElseFilter>` rule parsing reacha…
CVE-2026-81807.524.6IBMAspera High-Speed Transfer EndpointCWE-476Multiple vulnerabilities in Aspera applications.
CVE-2026-443458.824.4bentomlBentoMLCWE-78BentoML: Dockerfile command injection via docker.base_image
CVE-2026-83629.824.4GladinetTriofoxCWE-121Gladinet Triofox Stack-based Buffer Overflow in WOSDefaultHttpModule.dll
CVE-2026-427916.324.3ErlangOTPCWE-295OCSP responder certificate validity period not checked in public_key
CVE-2026-448889.824.1leiweibauPi.AlertCWE-94Unauthenticated RCE via Python Config File Injection in SaveConfigFile() (Int…
CVE-2026-443159.424.1free5gcfree5gcCWE-862free5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens…
CVE-2026-78769.123.9IBMAspera HSTS for CP4ICWE-287Authentication bypass vulnerability found in Aspera High-Speed Transfer Serve…
CVE-2026-421846.123.9tauri-appstauriCWE-918Tauri: Origin Confusion Allows Remote Pages to Invoke Local-Only IPC Commands
CVE-2026-4432710.023.8free5gcfree5gcCWE-306free5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach…
CVE-2026-443269.423.8free5gcfree5gcCWE-862free5GC: NEF 3gpp-traffic-influence API is unauthenticated; missing or forged…
CVE-2026-421978.723.6inducerrelateCWE-79RELATE Vulnerable to Stored XSS via Unprivileged User Profile
CVE-2025-36338.223.7IBMCognos AnalyticsCWE-79IBM Cognos Analytics is affected by multiple security vulnerabilities
CVE-2026-489727.523.5SeedProd LLCSeedProd ProCWE-98WordPress SeedProd Pro plugin < 6.19.5 - Local File Inclusion vulnerability
CVE-2026-472697.423.3mcdopepam_usbCWE-284pam_usb: deny_remote feature incorrectly classifies IPv4-mapped IPv6 remote c…
CVE-2026-83649.823.1GladinetTriofoxCWE-306Gladinet Triofox Missing Authentication for Critical Functions
CVE-2026-490468.522.9Arjun ThakurDuplicate Page and PostCWE-89WordPress Duplicate Page and Post plugin <= 2.9.5 - SQL Injection vulnerability
CVE-2026-425537.122.8cinnyappcinnyCWE-20Cinny: Access token disclosure via invalidated emoji pack avatar URL in servi…
CVE-2026-365387.322.6n/an/aCWE-798Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential st…
CVE-2026-488776.522.4TomGenerateBlocksCWE-201WordPress GenerateBlocks plugin <= 2.1.0 - Sensitive Data Exposure vulnerability
CVE-2026-455715.422.3go-gitgo-gitCWE-22go-git: Crafted repositories may modify main and submodule .git directories
CVE-2026-69574.922.1MattermostMattermostCWE-22Path traversal in Mattermost Legal Hold plugin via unsanitized file name from…
CVE-2026-408277.022.1MB connect linembCONNECT24CWE-89Authenticated SQLi in _RemoveRequest function
CVE-2026-408287.022.1MB connect linembCONNECT24CWE-89Authenticated SQLi in DeleteSysLogEntry function
CVE-2026-408297.022.1MB connect linembCONNECT24CWE-89Authenticated SQLi in UpdateParam function
CVE-2026-408307.022.1MB connect linembCONNECT24CWE-89Authenticated SQLi in UpdateParam function
CVE-2026-427279.321.9RealMag777Active Products Tables for WooCommerceCWE-89WordPress Active Products Tables for WooCommerce plugin <= 1.0.8 - SQL Inject…
CVE-2026-76184.922.0dattateccomEnvíaloSimple: Email Marketing y NewslettersCWE-89EnvíaloSimple: Email Marketing y Newsletters <= 2.4.5 - Authenticated (Admini…
CVE-2026-490029.121.8ZTEZXUniPOS NDS-LTECWE-284Broken Access Control Vulnerabily in ZTE ZXUniPOS NDS-LTE product
CVE-2026-481509.021.8BudibasebudibaseCWE-915Budibase: Workspace-scoped builder escalates to global admin via /api/public/…
CVE-2026-489627.321.7PMQSIO::CompressCWE-95IO::Compress versions before 2.220 for Perl can execute arbitrary code in Fil…
CVE-2026-427607.521.6revmakxBackup and Staging by WP Time CapsuleCWE-288WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.25 - Broken Au…
CVE-2026-489217.521.4Jenkins ProjectJenkins Pipeline: Groovy Libraries PluginCWE-59Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier d…
CVE-2026-489208.821.3Jenkins ProjectJenkins Email Extension PluginCWE-73Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining…
CVE-2026-388085.321.3n/an/aCWE-89SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker t…
CVE-2025-144814.321.3yoastYoast SEO – Advanced SEO with real-time guidance and built-in AICWE-862Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contri…
CVE-2026-4433010.021.2free5gcfree5gcCWE-863free5GC: NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens …
CVE-2026-464259.921.1BudibasebudibaseCWE-862Budibase: SCIM endpoints lack role-based authorization, BASIC users CRUD tena…
CVE-2026-87878.820.8devsabbirahmedFirebase Support & Chat ManagementCWE-269Firebase Support & Chat Management <= 3.1.1 - Missing Authorization to Authen…
CVE-2026-75287.520.8IBMLangflow OSSCWE-400Unauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Pa…
CVE-2026-312667.320.8n/an/aCWE-862Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in…
CVE-2026-408216.920.6MB connect linembCONNECT24CWE-89Authenticated SQLi in getAccountByID function
CVE-2026-408226.920.6MB connect linembCONNECT24CWE-89Authenticated SQLi in DevSerialReset function
CVE-2026-408266.920.6MB connect linembCONNECT24CWE-89Authenticated SQLi in dsgvo_contracts view
CVE-2025-08986.520.6WPXproXpro Elementor Addons - ProCWE-73Xpro Elementor Addons - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary…
CVE-2026-97399.420.4GoogleMCP Toolbox for DatabasesCWE-942Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). Duri…
CVE-2026-32796.520.2clorithEnable jQuery Migrate HelperCWE-862Enable jQuery Migrate Helper <= 1.4.1 - Missing Authorization to Authenticate…
CVE-2026-427489.920.1WPifyWPify Woo CzechCWE-434WordPress WPify Woo Czech plugin <= 5.4.1 - Arbitrary File Upload vulnerability
CVE-2026-464166.320.1microsoftUFOCWE-284Microsoft UFO shared WebSocket handler state causes cross-client response hij…
CVE-2026-83597.519.9GladinetTriofoxCWE-476Gladinet Triofox WOSHttpStatusModule.dll NULL Function Pointer Call DoS
CVE-2026-83607.519.9GladinetTriofoxCWE-476Gladinet Triofox Unchecked Return Value to NULL Pointer Dereference DOS
CVE-2026-489166.619.9Jenkins ProjectJenkins LDAP PluginCWE-918Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
CVE-2026-48884.319.9wpeverestEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form BuilderCWE-862Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builde…
CVE-2026-427256.519.7WP WhamCheckout Files Upload for WooCommerceCWE-639WordPress Checkout Files Upload for WooCommerce plugin <= 2.2.5 - Insecure Di…
CVE-2026-472736.519.6mcdopepam_usbCWE-91pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuratio…
CVE-2026-444838.219.4airjp73rvfCWE-1321RVF: Prototype pollution in @rvf/set-get reachable via @rvf/core preprocessFo…
CVE-2026-90145.319.0rahulbhangaleWP PromoterCWE-862WP Promoter <= 1.3 - Missing Authorization to Unauthenticated Statistics Rese…
CVE-2026-443185.319.0free5gcfree5gcCWE-362free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes…
CVE-2026-489069.318.9tassos.grNovarain/Tassos Framework (plg_system_nrframework)CWE-284Extension - tassos.gr - Arbitrary File Deletion in Novarain/Tassos Framework …
CVE-2026-451029.918.8OneUptimeoneuptimeCWE-693OneUptime: RCE due to Node.js' vm module escape via error objects and infinit…
CVE-2026-420817.118.8free5gcfree5gcCWE-358free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
CVE-2026-444607.418.4error311FileRiseCWE-200FileRise: TOTP Bypass via Setup Endpoint Disclosing Existing Secret
CVE-2025-104665.918.4SynologySafe AccessCWE-79Improper neutralization of input during web page generation ('Cross-site Scri…
CVE-2026-450617.718.2BudibasebudibaseCWE-918Budibase: SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`…
CVE-2026-457196.518.2BudibasebudibaseCWE-94Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V…
CVE-2026-460568.818.1LinuxLinuxCWE-416Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
CVE-2026-427308.518.1StylemixMasterStudy LMSCWE-89WordPress MasterStudy LMS plugin <= 3.7.29 - SQL Injection vulnerability
CVE-2026-489617.318.1PMQSIO::CompressCWE-755IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI …
CVE-2026-408327.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in getDevicegroups function
CVE-2026-408357.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in saveObjectFromData function
CVE-2026-408377.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in getProjectScalings function
CVE-2026-408387.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in getDeviceScalings function
CVE-2026-408397.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in getComponentScalings function
CVE-2026-408407.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in VerifyCreateLicences function
CVE-2026-408417.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in getProjectTags function
CVE-2026-408427.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in getWidgetTags function
CVE-2026-408437.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in alarming view
CVE-2026-408447.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in dashboard view
CVE-2026-408457.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in devices_configuration view
CVE-2026-408467.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in system view
CVE-2026-408477.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in system_tag view
CVE-2026-408487.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in tag view
CVE-2026-408497.118.1MB connect linembCONNECT24CWE-89Authenticated SQLi in user_alarmprofile view
CVE-2026-457168.818.0BudibasebudibaseCWE-269Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Wit…
CVE-2026-30126.818.0Red HatRed Hat Enterprise Linux 10CWE-345Samba: group policy certificate enrollment uses http:// without validation
CVE-2026-489176.617.9Jenkins ProjectJenkins LDAP PluginCWE-502Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP…
CVE-2026-489196.617.9Jenkins ProjectJenkins Active Directory PluginCWE-502Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP …
CVE-2026-43905.317.8n/aTeamSpeak 3 ServerCWE-119TeamSpeak 3 Server Connection State Management process_resend_queue use after…
CVE-2026-448868.717.6leiweibauPi.AlertCWE-89Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL Injection
CVE-2026-455487.717.6BudibasebudibaseCWE-918Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Va…
CVE-2026-457157.717.6BudibasebudibaseCWE-918Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration
CVE-2026-481528.117.5BudibasebudibaseCWE-863Budibase: Basic app users can exfiltrate stored REST datasource auth by rewri…
CVE-2026-427367.517.3wordplusBP Better MessagesCWE-639WordPress BP Better Messages plugin <= 2.14.16 - Insecure Direct Object Refer…
CVE-2026-33496.117.4minhnhutMinhNhut Link GatewayCWE-79MinhNhut Link Gateway <= 3.6.1 - Reflected Cross-Site Scripting via 'url' Par…
CVE-2026-427358.217.2Iqonic DesignKiviCareCWE-288WordPress KiviCare plugin <= 4.3.0 - Broken Authentication vulnerability
CVE-2025-131675.417.1SynologySynology ContactsCWE-79Improper neutralization of input during web page generation ('Cross-site Scri…
CVE-2026-427497.116.9ThemeisleDisable Comments for Any Post Types (Remove comments)CWE-288WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3…
CVE-2026-457178.816.7BudibasebudibaseCWE-862Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/RE…
CVE-2026-450887.516.7hahwuldalfoxCWE-73Dalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via…
CVE-2026-420825.416.7free5gcfree5gcCWE-358free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover
CVE-2026-335523.716.8n/an/aCWE-269Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Cont…
CVE-2026-96178.816.6DALIBOPostgreSQL AnonymizerCWE-89PostgreSQL Anonymizer: malicious column name allows SQL injection via anon.k_…
CVE-2026-389306.516.6n/an/aCWE-89OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass …
CVE-2026-448385.316.6rabbitmqrabbitmq-serverCWE-863RabbitMQ MQTT Topic Permission Authorization Bypass
CVE-2026-446816.116.5authlibauthlibCWE-601Authlib: Open Redirect in Authlib OIDC Implicit/Hybrid Authorization
CVE-2024-472702.716.5SynologySurveillance StationCWE-281Improper preservation of permissions vulnerability in Archiving Push function…
CVE-2024-472722.716.5SynologySurveillance StationCWE-863Incorrect authorization vulnerability in IO Module functionality in Synology …
CVE-2026-427326.516.3Ads by WPQuadsAds by WPQuadsCWE-1284WordPress Ads by WPQuads plugin <= 3.0.2 - Broken Authentication vulnerability
CVE-2026-451088.416.1himmelblau-idmhimmelblauCWE-863Himmelblau: Authentication Bypass via Cross-User Local Session Impersonation …
CVE-2026-451378.216.1solana-foundationanchorCWE-20Anchor: Program<'info, System> is not properly validated
CVE-2026-427409.316.0tainacanTainacanCWE-89WordPress Tainacan plugin <= 1.0.3 - SQL Injection vulnerability
CVE-2026-427479.316.0hassantafreshiEasy Form BuilderCWE-89WordPress Easy Form Builder plugin <= 4.0.6 - SQL Injection vulnerability
CVE-2026-445218.815.7Studio-42elFinderCWE-89elFinder: SQL Injection MySQL Volume Driver (elFinderVolumeMySQL)
CVE-2026-450898.215.7hahwuldalfoxCWE-73Dalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in D…
CVE-2026-60527.515.7IBMDb2CWE-400IBM® Db2® is vulnerable to running out of memory when executing certain queri…
CVE-2026-26014.315.7GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-449888.815.6LibVNClibvncserverCWE-787LibVNCClient Tight Gradient decoding allows malicious server-triggered heap/s…
CVE-2026-427266.515.6Strategy11 TeamAWP ClassifiedsCWE-862WordPress AWP Classifieds plugin <= 4.4.5 - Broken Access Control vulnerability
CVE-2026-443207.315.4free5gcfree5gcCWE-306free5GC: NEF nnef-callback route group is unauthenticated; forged callback re…
CVE-2026-69366.515.3IBMiCWE-674IBM i is Affected by a Denial of Service Vulnerability []
CVE-2026-428785.315.4NeoRazorXfacturascriptsCWE-200FacturaScripts: Unauthenticated phpinfo() Disclosure via Installer Endpoint i…
CVE-2026-408237.015.2MB connect linembCONNECT24CWE-89Authenticated SQLi in DevSerialReset function
CVE-2026-408247.015.2MB connect linembCONNECT24CWE-89Authenticated SQLi in accountstatus view
CVE-2026-408257.015.2MB connect linembCONNECT24CWE-89Authenticated SQLi in accountstatus view
CVE-2026-427457.315.0ZAYTECHSmart Online Order for CloverCWE-288WordPress Smart Online Order for Clover plugin <= 1.6.0 - Broken Authenticati…
CVE-2026-72545.315.0IBMOPENBMCCWE-1284Open BMC Denial of Service
CVE-2026-33484.415.0minhnhutMinhNhut Link GatewayCWE-79MinhNhut Link Gateway <= 3.6.1 - Authenticated (Admin+) Stored Cross-Site Scr…
CVE-2026-427559.314.9RealMag777TableOnCWE-89WordPress TableOn plugin <= 1.0.5.1 - SQL Injection vulnerability
CVE-2026-471195.314.83clyp50agent-zeroCWE-79Agent Zero < 1.15 Stored XSS via image_get API Endpoint
CVE-2026-91567.514.6TaniumTanium ServerCWE-772Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-20306.414.7livemeshWPBakery Page Builder Addons by LivemeshCWE-79WPBakery Page Builder Addons by Livemesh <= 3.9.4 - Authenticated (Contributo…
CVE-2026-88666.414.7bradyholtjQuery googleslidesCWE-79jQuery googleslides <= 1.3 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-88686.414.7jonathan-robrechtSingle MailchimpCWE-79Single Mailchimp <= 1.4 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-88696.414.7mutualfunddataMutual Funds DataCWE-79Mutual Funds Data <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-88776.414.7esiteqResponsive Video EmbedderCWE-79Responsive Video Embedder <= 0.1 - Authenticated (Contributor+) Stored Cross-…
CVE-2026-88876.414.7konfortiListen ShortcodeCWE-79Listen Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-88976.414.7vincentastolfiShortcode BuddyCWE-79Shortcode Buddy <= 0.1.9.5 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-88986.414.7ruchit47Events In CityCWE-79Events In City <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-450907.514.2hahwuldalfoxCWE-362Dalfox: Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnal…
CVE-2026-490594.714.2FacebookFacebook for WooCommerceCWE-601WordPress Facebook for WooCommerce plugin <= 3.7.0 - Open Redirection vulnera…
CVE-2026-489714.314.2WebToffeeProduct Import Export for WooCommerceCWE-862WordPress Product Import Export for WooCommerce plugin <= 2.5.6 - Broken Acce…
CVE-2024-472694.914.1SynologySurveillance StationCWE-319Cleartext transmission of sensitive information vulnerability in Export Key f…
CVE-2026-22804.814.1larsdrasmussenrexCrawlerCWE-79rexCrawler <= 1.0.15 - Authenticated (Administrator+) Stored Cross-Site Scrip…
CVE-2026-22884.814.1silvercovermyLinksDumpCWE-79myLinksDump <= 1.6 - Authenticated (Administrator+) Stored Cross-Site Scripti…
CVE-2026-427619.314.0RealMag777Active Products Tables for WooCommerceCWE-89WordPress Active Products Tables for WooCommerce plugin <= 1.0.9 - SQL Inject…
CVE-2026-428796.314.0NeoRazorXfacturascriptsCWE-94FacturaScripts: Authenticated Remote Code Execution (RCE) via GIF Image Uploa…
CVE-2026-84056.513.8IBMGuardium Data ProtectionCWE-200IBM Guardium Data Protection is affected by Exposure of Sensitive Information…
CVE-2026-481498.113.5BudibasebudibaseCWE-79Budibase: Stored XSS in Text component: BASIC users execute JS in admin sessi…
CVE-2026-481485.313.6BudibasebudibaseCWE-918Budibase: Unvalidated VectorDB Host Parameter Enables SSRF
CVE-2026-465385.913.4microsoftUFOCWE-294Microsoft UFO accepts cross-device TASK_END messages by session_id only, allo…
CVE-2026-481517.513.3BudibasebudibaseCWE-862Budibase: Webhook schema endpoint authorization bypass allows unauthenticated…
CVE-2026-464277.713.2BudibasebudibaseCWE-200Budibase: Snowflake private key returned unmasked from datasource API to BASI…
CVE-2026-408337.113.2MB connect linembCONNECT24CWE-89Authenticated SQLi in saveDashboardLayout function
CVE-2026-408347.113.2MB connect linembCONNECT24CWE-89Authenticated SQLi in saveDashboardLayout function
CVE-2026-408367.113.2MB connect linembCONNECT24CWE-89Authenticated SQLi in inmessage model
CVE-2026-489186.613.1Jenkins ProjectJenkins Active Directory PluginCWE-918Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by de…
CVE-2026-38956.413.1livemeshWPBakery Page Builder Addons by LivemeshCWE-862WPBakery Page Builder Addons by Livemesh <= 3.9.4 - Missing Authorization to …
CVE-2026-38966.413.1livemeshLivemesh SiteOrigin WidgetsCWE-862Livemesh SiteOrigin Widgets <= 3.9.2 - Missing Authorization to Authenticated…
CVE-2026-38976.413.1livemeshLivemesh Addons for Beaver BuilderCWE-862Livemesh Addons for Beaver Builder <= 3.9.2 - Authenticated (Subscriber+) Sto…
CVE-2026-96092.013.1QianFoxFoxCMSCWE-640QianFox FoxCMS Admin.php edit password recovery
CVE-2026-490514.312.8Prasad KirpekarWP Meta and Date RemoverCWE-862WordPress WP Meta and Date Remover plugin <= 2.3.6 - Broken Access Control vu…
CVE-2026-12484.312.7IBMBusiness Automation Workflow containers and traditionalCWE-209IBM Business Automation Workflow information leak
CVE-2026-97123.812.6pretixpretixCWE-639Insecure direct object reference
CVE-2025-416698.712.5Phoenix ContactAXC F 1152CWE-347Insufficient Verification of Data Authenticity
CVE-2022-416564.312.6BizswoopAccount Manager for WooCommerceCWE-862WordPress Account Manager for WooCommerce plugin <= 2.1.2 - Broken Access Con…
CVE-2026-481467.712.3BudibasebudibaseCWE-918Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Prot…
CVE-2026-88846.412.4neilmccutcheonInstant-Quote.co Quotation PageCWE-79Instant-Quote.co Quotation Page <= 1.3.4 - Authenticated (Contributor+) Store…
CVE-2026-491026.112.3WebminWebminCWE-79Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attac…
CVE-2026-448308.712.1Dataojitorinocturne_memoryCWE-306Empty API_TOKEN disables authentication on network-reachable HTTP/SSE transport
CVE-2026-55165.911.9IBMWebSphere Application Server - LibertyCWE-362IBM WebSphere Application Server Liberty is affected by a security bypass vul…
CVE-2026-490454.311.8WP MediaAdminimizeCWE-862WordPress Adminimize plugin <= 1.11.11 - Broken Access Control vulnerability
CVE-2026-490544.311.8Mamunur RashidThe Post GridCWE-862WordPress The Post Grid plugin <= 7.9.2 - Broken Access Control vulnerability
CVE-2026-422807.111.6auth0auth0.jsCWE-863Improper Permission Checking in Auth.js SDK
CVE-2026-87076.111.6nsthemesNS Product icon badgeCWE-79NS Product icon badge <= 1.2.4 - Reflected Cross-Site Scripting via PHP_SELF
CVE-2026-489244.311.2Jenkins ProjectJenkins Bitbucket OAuth PluginCWE-601Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirec…
CVE-2026-447206.911.1th30d4yOpenLearnXCWE-287OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Dis…
CVE-2026-427446.511.1Ads by WPQuadsAds by WPQuadsCWE-1284WordPress Ads by WPQuads plugin <= 3.0.2 - Bypass Vulnerability vulnerability
CVE-2026-96081.911.0QianFoxFoxCMSCWE-79QianFox FoxCMS Administrator Backend edit cross site scripting
CVE-2026-88446.410.7kevin1804Responsive CheckCWE-79Responsive Check <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Sc…
CVE-2026-427547.110.6phbernardFaviconCWE-79WordPress Favicon plugin <= 1.3.46 - Cross Site Scripting (XSS) vulnerability
CVE-2026-22537.710.3Hitachi VantaraPentaho Data Integration and AnalyticsCWE-611Hitachi Vantara Pentaho Data Integration & Analytics - Improper Restriction o…
CVE-2026-450816.510.3frappehrmsCWE-863Frappe HR: Permission Bypass in HRMS Leave Details API
CVE-2026-489734.310.2BenbodhiSVG SupportCWE-862WordPress SVG Support plugin <= 2.5.14 - Broken Access Control vulnerability
CVE-2026-451347.110.1langchain-ailangsmith-sdkCWE-502LangSmith Client SDK: Public prompt pull deserializes untrusted manifests wit…
CVE-2026-449718.29.9DataDogguarddogCWE-918GuardDog: Blind GitHub URL rewrite in remote project scanning causes SSRF and…
CVE-2026-88426.49.9morettolssGoogle+ Link NameCWE-79Google+ Link Name <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-88476.49.9mshomaliDideoCWE-79Dideo <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via S…
CVE-2026-88676.49.9fides-itPost Categories GalleryCWE-79Post Categories Gallery <= 1.0.0 - Authenticated (Contributor+) Stored Cross-…
CVE-2026-88866.49.9huankonghk_shortcodeCWE-79hk_shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-88996.49.9gapgag55Auto ThumbnailsCWE-79Auto Thumbnails <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scrip…
CVE-2026-90226.49.8dkjensenSplide Carousel BlockCWE-79Splide Carousel Block <= 1.7.1 - Authenticated (Contributor+) Stored Cross-Si…
CVE-2026-62875.49.8devitemsllcShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-79ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authent…
CVE-2026-52964.39.6GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-427467.39.5ZAYTECHSmart Online Order for CloverCWE-201WordPress Smart Online Order for Clover plugin <= 1.6.0 - Sensitive Data Expo…
CVE-2026-88726.49.3fides-itAnimate Your ContentCWE-79Animate Your Content <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Sit…
CVE-2026-88916.49.3bitformBitForm – Data management solution for WordPressCWE-79BitForm <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting v…
CVE-2026-96072.19.2itsourcecodeCourier Management SystemCWE-74itsourcecode Courier Management System parcel_list.php sql injection
CVE-2026-80426.49.1octalmageGithub ShortcodeCWE-79Github Shortcode <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-50658.89.0IBMControllerCWE-798IBM Controller is affected by vulnerabilities
CVE-2025-416708.78.9Phoenix ContactAXC F 1152CWE-427Untrusted Search Path
CVE-2026-81437.29.0omnivoBooking Calendar – Event CalendarCWE-79Booking Calendar – Event Calendar <= 2.1.6 - Unauthenticated Stored Cross-Sit…
CVE-2026-88706.49.0adnanmoqsoodTeam Master – A Modern WordPress Team ShowcaseCWE-79Team Master <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-451368.68.7cnighswongerclaude-code-cache-fixCWE-78claude-code-cache-fix: Local code execution via Python triple-quote injection…
CVE-2026-80406.48.6yehudahfaq shortocdeCWE-79faq shortocde <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-80486.48.6paulpelaMy Email ShortcodeCWE-79My Email Shortcode <= 0.91 - [Improper Neutralization of Input During Web Pag…
CVE-2026-86986.48.6cryptoprijzenCryptocurrency Prijsvergelijking WidgetCWE-79Cryptocurrency Prijsvergelijking Widget <= 1.0 - Authenticated (Contributor+)…
CVE-2026-87016.48.6golzarrahmanGNTT Post Title TickerCWE-79GNTT Post Title Ticker <= 1.0 - Authenticated (Contributor+) Stored Cross-Sit…
CVE-2026-87036.48.6codycaveEndless ScrollCWE-79Endless Scroll <= 1.0.0 - [Improper Neutralization of Input During Web Page G…
CVE-2026-88376.48.6ektorcabaWP Iframe Geo Style for Amazon affiliatesCWE-79WP Iframe Geo Style for Amazon affiliates <= 1.1 - Authenticated (Contributor…
CVE-2026-88456.48.6samiullah-kaifiIslamic DatabaseCWE-79Islamic Database <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-88466.48.6eldougoTuxquoteCWE-79Tuxquote <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…
CVE-2026-88716.48.6thomstarkFormidable KineticCWE-79Formidable Kinetic <= 1.1.01 - Authenticated (Contributor+) Stored Cross-Site…
CVE-2026-88736.48.6celloexpressionsContent SlideshowCWE-79Content Slideshow <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-88756.48.6cuamckuyEasy Prism Syntax HighlighterCWE-79Easy Prism Syntax Highlighter <= 1.0.2 - Authenticated (Contributor+) Stored …
CVE-2026-88946.48.6vinaysankhyaniWR TooltipCWE-79iWR Tooltip <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-490535.38.6WpmetElementsKit Elementor addons LiteCWE-862WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access C…
CVE-2026-87164.38.7GitLabGitLabCWE-706Use of Incorrectly-Resolved Name or Reference in GitLab
CVE-2026-69387.58.3IBMDb2CWE-285IBM® Db2® is vulnerable to authorization bypass when uploading to a remote ob…
CVE-2026-459847.88.3LinuxLinuxCWE-416gfs2: Fix use-after-free in iomap inline data write path
CVE-2026-427537.38.3WC LoversWCFM MembershipCWE-862WordPress WCFM Membership plugin <= 2.11.10 - Broken Access Control vulnerabi…
CVE-2026-236796.98.3libusblibusbCWE-125libusb < 1.0.30 NULL Pointer Dereference in parse_interface()
CVE-2025-679035.38.1n/an/aCWE-347Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature v…
CVE-2026-458787.88.0LinuxLinuxdrm/amdkfd: Fix watch_id bounds checking in debug address watch v2
CVE-2026-489686.58.0AvertaMaster SliderCWE-79WordPress Master Slider plugin <= 3.10.8 - Cross Site Scripting (XSS) vulnera…
CVE-2026-490446.58.0Justin KruitAdvanced Custom Fields: Font Awesome FieldCWE-79WordPress Advanced Custom Fields: Font Awesome Field plugin <= 5.0.2 - Cross …
CVE-2026-427287.18.0HT PluginsHT Contact Form 7CWE-79WordPress HT Contact Form 7 plugin <= 2.8.2 - Cross Site Scripting (XSS) vuln…
CVE-2026-427297.18.0Property HivePropertyHiveCWE-79WordPress PropertyHive plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerabi…
CVE-2025-227417.17.8RiceThemeFelan FrameworkCWE-79WordPress Felan Framework plugin <= 1.1.3 - Reflected Cross Site Scripting (X…
CVE-2025-527477.17.8JthemesThemebox - Digital Products EcommerceCWE-79WordPress Themebox - Digital Products Ecommerce theme <= 1.4.2 - Cross Site S…
CVE-2026-427337.17.8RealMag777WPCSCWE-79WordPress WPCS plugin <= 1.3.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-427347.17.8Dylan KuhnGeo MashupCWE-79WordPress Geo Mashup plugin <= 1.13.19 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-448395.67.9rabbitmqrabbitmq-serverCWE-80RabbitMQ: Unsanitized vhost names allow for XSS in management UI
CVE-2026-489234.37.9Jenkins ProjectJenkins AppSpider PluginCWE-269Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission che…
CVE-2026-447104.67.6mcdopepam_usbCWE-476pam_usb: NULL pointer dereference from UDisks device fields causes PAM crash …
CVE-2026-459337.87.5LinuxLinuxbpf: Preserve id of register in sync_linked_regs()
CVE-2026-60517.57.6IBMDb2CWE-400IBM® Db2® is vulnerable to a denial of service when executing a specially cra…
CVE-2026-460185.57.6LinuxLinuxALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES
CVE-2026-489275.57.4Jenkins ProjectJenkins buildgraph-view PluginCWE-79Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL,…
CVE-2026-481538.57.2BudibasebudibaseCWE-918Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud…
CVE-2026-458527.87.2LinuxLinuxCWE-415RDMA/rxe: Fix double free in rxe_srq_from_init
CVE-2026-464267.67.3BudibasebudibaseCWE-79Budibase: Unrestricted Upload of File with Dangerous Type
CVE-2026-459317.87.1LinuxLinuxaccel/amdxdna: Hold mm structure across iommu_sva_unbind_device()
CVE-2026-442477.47.0volcano-shvolcanoCWE-400Volcano: Webhook server vulnerable to OOM due to unbounded HTTP request body …
CVE-2026-489264.36.8Jenkins ProjectJenkins Job Import PluginCWE-269Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a …
CVE-2026-459917.86.6LinuxLinuxCWE-787udf: fix partition descriptor append bookkeeping
CVE-2026-489995.76.6ZTEZXUniPOS NDS-LTECWE-79Stored Cross-Site Scripting (XSS) vulnerability in ZTE ZXUniPOS NDS-LTE product
CVE-2026-447117.96.3mcdopepam_usbCWE-59pam_usb: Symlink attacks on pad directory and pad files enable authentication…
CVE-2026-460817.86.3LinuxLinuxCWE-787crypto: acomp - fix wrong pointer stored by acomp_save_req()
CVE-2026-444737.16.3ellanetworkscoreCWE-358Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
CVE-2026-458725.56.3LinuxLinuxCWE-401scsi: smartpqi: Fix memory leak in pqi_report_phys_luns()
CVE-2026-458755.56.3LinuxLinuxCWE-401mfd: arizona: Fix regulator resource leak on wm5102_clear_write_sequencer() f…
CVE-2026-458567.16.1LinuxLinuxCWE-125RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send
CVE-2026-428775.46.2NeoRazorXfacturascriptsCWE-79FacturaScripts: Stored XSS via product reference in sales/purchases
CVE-2026-22554.36.2Hitachi VantaraPentaho Data Integration and AnalyticsCWE-522Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protect…

Results continue: ranks 401–715.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-27 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.