boxscore/security
Thursday, May 28, 2026 · all times UTC← 2026-05-27 · archive · 2026-05-29 →

542 CVEs published May 28, 2026: 56 critical, 278 high, 194 medium, 14 low; 0 in KEV; 30 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 517 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published2891402110212563
KEV catalog size1670

115 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux6399657961526912720.27.8.0013+476
microsoft170490433281020378275.57.8.0045-17
google168174101203567442.38.3.0023+167
red hat3558826222400.07.4.0040+24
apple204701227193714.96.2.0034+20
canonical14140455000.05.5.0009+14
freebsd770520000.07.8.0020+7
suse220200000.08.2.0020+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco513312096861.58.6.1247+2
checkpoint660330300.06.5.0338+6
fortinet16130028350.07.9.4330-2
ivanti25010033480.08.8.8056+1
f52320007133.39.2.0996+2
ubiquiti231200400.08.8.0068+2
broadcom02000042100.0.19900
palo alto networks110000141100.0.3207+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache21324151204013.17.4.0064+12
gitlab7901604222.24.3.0032+7
mozilla6632101300.08.8.0042+6
drupal5511305120.05.1.0026+5
docker330300100.08.8.0022+3
github221100000.08.1.0347+2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm49491024150700.07.5.0028+49
oracle2527815404000.08.1.0027+25
progress440400900.07.5.0036+4
adobe14010075375.08.6.2776-2
veeam331200400.08.6.0040+3
solarwinds031000113100.09.8.83620
zohocorp220110000.07.1.0104+2
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology181823103000.05.6.0025+18
d-link23011026133.37.3.0059+1
hitachi energy220020000.05.7.0014+2
siemens110100100.08.7.0032+1
hikvision01000021100.01.00000
dahua000000200
qnap000000800
schneider electric000000100
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44
edimax4444027017100.07.4.0059+44
helmholz424203930000.07.1.0026+42
mb connect line424203930000.07.1.0026+42
open ises3737214210000.06.9.0021+37
totolink343402509000.08.9.0191+34
netatalk3333113910000.06.4.0030+33
nvidia333381870000.07.8.0038+33

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2008-4250.987599.9
CVE-2026-41940.979399.99.3
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4684010.0.0073
CVE-2026-4659510.0.0050
Most disclosures (vendor)
VendorCVEs
linux641
microsoft170
google168
ibm49
concrete cms44
edimax44
helmholz42
mb connect line42
red hat38
open ises37
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google4
ivanti4
synacor4
adobe3
fortinet3
smartertools3
solarwinds3
Most-affected ecosystems
EcosystemAdvisories
Maven12
PyPI2
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2025-34291Langflow0
CVE-2026-0300Palo Alto Networks0
CVE-2026-20182Cisco0
CVE-2026-31431Linux0
CVE-2026-34926Trend Micro, Inc.0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171653
CVE-2021-27102Accellion2021-11-171653
CVE-2021-27101Accellion2021-11-171653
CVE-2021-27103Accellion2021-11-171653
CVE-2021-21017Adobe2021-11-171653
CVE-2021-28550Adobe2021-11-171653
CVE-2021-42013Apache2021-11-171653
CVE-2021-41773Apache2021-11-171653
CVE-2021-30858Apple2021-11-171653
CVE-2021-30860Apple2021-11-171653

Transactions

EXPLOIT PUBLISHEDCVE-2026-32847 (HKUDS DeepCode). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42998 (OpenStack Keystone). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42999 (OpenStack Keystone). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-43000 (OpenStack Keystone). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-43898 (nyariv SandboxJS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44394 (OpenStack Keystone). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44461 (zed-industries zed). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44462 (zed-industries zed). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44463 (zed-industries zed). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44465 (zed-industries zed). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44466 (zed-industries zed). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44848 (portainer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44849 (portainer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44850 (portainer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44881 (portainer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44882 (portainer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44883 (portainer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44884 (portainer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44885 (portainer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45323 (jpettitt meshcore-card). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45403 (Mintplex-Labs anything-llm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47713 (Mintplex-Labs anything-llm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48116 (Mintplex-Labs anything-llm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48522 (jpadilla pyjwt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48523 (jpadilla pyjwt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48525 (jpadilla pyjwt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48526 (jpadilla pyjwt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49237 (Canonical Multipass). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49238 (Canonical Multipass). Public exploit reference added.

DUE DATE PASSEDCVE-2026-9082 (Drupal core). CISA remediation deadline was May 27, 2026; still in catalog.

Yesterday's Results

542 CVEs published. 25 box scores and 375 table rows below; the remaining 142 continue on page 2 — every CVE is listed, nothing truncated.

Red Hat Red Hat Enterprise Linux 10 — Samba: remote code execution in samr
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0250   83.4     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:4.23.5-109.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:4.21.3-114.el10_0.1
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:4.10.16-26.el7_9.1
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:4.10.16-26.el7_9.1
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:4.13.3-12.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:4.13.3-12.el8_4.1
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:4.15.5-16.el8_6.1
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:4.15.5-16.el8_6.1
  + 12 more
TIMELINE
  Mar 18  Reserved by CNA
  May 28  Published (CNA: redhat)
CWE-78 · CNA: redhat · 18 references · NVD status: Modified
Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0140   70.3     —
AFFECTED
  Product         Versions     Fixed
  SysTrack Agent  unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  May 28  Published (CNA: VulnCheck)
CWE-125, CWE-754 · CNA: VulnCheck · 5 references · NVD status: Awaiting Analysis
n/a n/a — A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0127   67.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 28  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Analyzed
n/a n/a — A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0124   66.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 28  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Analyzed
n/a n/a — A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0124   66.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 28  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Analyzed
n/a n/a — A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.10…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0124   66.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 28  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Analyzed
open-telemetry opentelemetry-java — opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0110   62.8     —
AFFECTED
  Product                                    Versions    Fixed
  opentelemetry-java                         < 1.62.0 –  —
  opentelemetry-api                          1.62.0 –    —
  opentelemetry-extension-trace-propagators  1.62.0 –    —
TIMELINE
  May 11  Reserved by CNA
  May 28  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · 11 references · NVD status: Awaiting Analysis
marcantondahmen automad — Automad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0107   62.1     —
AFFECTED
  Product  Versions                             Fixed
  automad  >= 2.0.0-alpha.1, < 2.0.0-beta.28 –  —
TIMELINE
  May 11  Reserved by CNA
  May 28  Published (CNA: GitHub_M)
CWE-200, CWE-306 · CNA: GitHub_M · 1 reference · NVD status: Deferred
hwk-fr Advanced Custom Fields: Extended — Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0080   53.5     —
AFFECTED
  Product                           Versions     Fixed
  Advanced Custom Fields: Extended  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  May 28  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · 6 references · NVD status: Deferred
vllm-project vllm-project/vllm — Hardcoded trust_remote_code=True in vllm-project/vllm Bypasses User Security Control
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0075   51.8     —
AFFECTED
  Product            Versions       Fixed
  vllm-project/vllm  unspecified –  —
TIMELINE
  Mar 26  Reserved by CNA
  May 28  Published (CNA: @huntr_ai)
CWE-22 · CNA: @huntr_ai · 1 reference · NVD status: Deferred
shabti Frontend Admin by DynamiApps — Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0074   51.6     —
AFFECTED
  Product                       Versions     Fixed
  Frontend Admin by DynamiApps  unspecified  —
TIMELINE
  Apr 13  Reserved by CNA
  May 28  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · 10 references · NVD status: Deferred
Oracle Corporation Oracle REST Data Services — Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are a…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0073   51.1     —
AFFECTED
  Product                    Versions  Fixed
  Oracle REST Data Services  24.2.0 –  —
TIMELINE
  May 18  Reserved by CNA
  May 28  Published (CNA: oracle)
CWE-284, CWE-287, CWE-306 · CNA: oracle · 1 reference · NVD status: Analyzed
cssigniterteam GutenBee – Gutenberg Blocks — GutenBee <= 2.20.1 - Authenticated (Author+) Arbitrary File Upload via wp_check_filetype_and_ext Filter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0068   49.6     —
AFFECTED
  Product                      Versions     Fixed
  GutenBee – Gutenberg Blocks  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  May 28  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 9 references · NVD status: Deferred
Linux Linux — smb: client: validate dacloffset before building DACL pointers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 –  —
  Linux    5.12 –                                      5.15.210
TIMELINE
  May 13  Reserved by CNA
  May 28  Published (CNA: Linux)
CWE-476, CWE-787 · CNA: Linux · 13 references · NVD status: Modified
Mennekes Amtron — Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0061   46.4     —
AFFECTED
  Product  Versions     Fixed
  Amtron   unspecified  5.33.11-21500
TIMELINE
  May 19  Reserved by CNA
  May 28  Published (CNA: CyberDanube)
CWE-287 · CNA: CyberDanube · 1 reference · NVD status: Deferred
Portainer: Path traversal in backup archive extraction allows arbitrary file write
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  H  L    5.5   .0061   46.2     —
AFFECTED
  Product    Versions               Fixed
  portainer  >= 2.33.0, < 2.33.8 –  —
TIMELINE
  May 7   Reserved by CNA
  May 28  Public exploit reference published
  May 28  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 2 references · NVD status: Analyzed
Usagi-org ai-goofish-monitor — ai-goofish-monitor Unauthenticated Arbitrary File Read via GET /api/prompts/
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   N   N    8.2   .0060   45.9     —
AFFECTED
  Product             Versions     Fixed
  ai-goofish-monitor  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  May 28  Published (CNA: VulnCheck)
CWE-36 · CNA: VulnCheck · 4 references · NVD status: Deferred
Linux Linux — RDMA/rxe: Reject unknown opcodes before ICRC processing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0057   44.7     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    8700e3e7c4857d28ebaa824509934556da0b3e76 –  —
  Linux    4.8 –                                       5.10.258
TIMELINE
  May 13  Reserved by CNA
  May 28  Published (CNA: Linux)
CWE-125 · CNA: Linux · 8 references · NVD status: Undergoing Analysis
Red Hat Red Hat Hardened Images — Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   H   N   R  U  H  H  H    7.0   .0057   44.3     —
AFFECTED
  Product                                  Versions     Fixed
  Red Hat Hardened Images                  unspecified  6.0.1-6.1.hum1
  Pen Drive Powered by Red Hat Lightspeed  unspecified  —
  Red Hat build of Quarkus Native builder  unspecified  —
  Red Hat Enterprise Linux 10              unspecified  —
  Red Hat Enterprise Linux 10              unspecified  —
  Red Hat Enterprise Linux 6               unspecified  —
  Red Hat Enterprise Linux 7               unspecified  —
  Red Hat Enterprise Linux 8               unspecified  —
  Red Hat Enterprise Linux 9               unspecified  —
  Red Hat Enterprise Linux 9               unspecified  —
  + 4 more
TIMELINE
  May 7   Reserved by CNA
  May 28  Published (CNA: redhat)
CWE-78 · CNA: redhat · 3 references · NVD status: Awaiting Analysis
croixhaug Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin — Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0056   44.0     —
AFFECTED
  Product                                                                     Versions     Fixed
  Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  May 28  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 11 references · NVD status: Deferred
croixhaug Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin — Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0055   43.6     —
AFFECTED
  Product                                                                     Versions     Fixed
  Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  May 28  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 11 references · NVD status: Deferred
SDMC NE6037 Hardcoded Password via mgmt.php/npcmd.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0053   42.7     —
AFFECTED
  Product  Versions      Fixed
  NE6037   7.1.6.0.25 –  —
TIMELINE
  Jan 22  Reserved by CNA
  May 28  Published (CNA: VulnCheck)
CWE-798 · CNA: VulnCheck · 2 references · NVD status: Deferred
Apache Ignite: REST HTTP arbitrary file read vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    8.5   .0053   42.2     —
AFFECTED
  Product        Versions  Fixed
  Apache Ignite  2.0.0 –   —
TIMELINE
  May 29  Reserved by CNA
  May 28  Published (CNA: apache)
CWE-23 · CNA: apache · 2 references · NVD status: Analyzed
Linux Linux — libceph: Fix slab-out-of-bounds access in auth message processing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0053   42.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc –  —
  Linux    2.6.34 –                                    5.15.209
TIMELINE
  May 13  Reserved by CNA
  May 28  Published (CNA: Linux)
CWE-125 · CNA: Linux · 7 references · NVD status: Undergoing Analysis
Red Hat Red Hat Container Native Virtualization 4.17 — Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0052   41.6     —
AFFECTED
  Product                                       Versions     Fixed
  Red Hat Container Native Virtualization 4.17  unspecified  1781757410
  Red Hat Container Native Virtualization 4.18  unspecified  1781928221
  Red Hat Container Native Virtualization 4.19  unspecified  1781590993
  Red Hat Container Native Virtualization 4.2   unspecified  1781838712
  Red Hat Container Native Virtualization 4.21  unspecified  1782012918
  Red Hat OpenShift Virtualization 4            unspecified  —
TIMELINE
  May 28  Reserved by CNA
  May 28  Published (CNA: redhat)
CWE-59 · CNA: redhat · 8 references · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-452619.341.5gitbutlerappgitbutlerCWE-94GitButler: Link injection via forge integration enables arbitrary script exec…
CVE-2026-329978.641.4VeeamBackup and ReplicationCWE-36A vulnerability allowing an authenticated user with the Backup Administrator …
CVE-2026-461859.141.3LinuxLinuxCWE-125smb/client: fix out-of-bounds read in symlink_data()
CVE-2026-491278.841.2MusicPlayerDaemonMPDCWE-193Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be
CVE-2026-86978.741.2TP-Link Systems Inc.Archer C64 v1.0CWE-306Improper Authentication Rate Limiting on TP-Link's Archer C64
CVE-2026-492388.440.9CanonicalMultipassCWE-22SFTP Server VM Escape in Canonical Multipass
CVE-2026-70486.540.810webPhoto Gallery by 10Web – Mobile-Friendly Image GalleryCWE-89Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection…
CVE-2026-411846.040.8TigeraCalicoCWE-532ServiceAccount token disclosure via install-cni container logs
CVE-2026-491288.740.6MusicPlayerDaemonMPDCWE-22Music Player Daemon < 0.24.11 Path Traversal via LocalStorage URI Handling
CVE-2026-461777.540.6LinuxLinuxipmi: Add limits to event and receive message requests
CVE-2026-461107.540.6LinuxLinuxCWE-476net: stmmac: Prevent NULL deref when RX memory exhausted
CVE-2026-461159.840.0LinuxLinuxblock: add pgmap check to biovec_phys_mergeable
CVE-2026-444779.439.3cloudnative-pgcloudnative-pgCWE-250CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL sup…
CVE-2026-461559.139.2LinuxLinuxCWE-125smb/client: fix out-of-bounds read in smb2_compound_op()
CVE-2026-98014.939.2Red HatRed Hat build of Keycloak 26.4CWE-1284Keycloak: keycloak: denial of service via malformed ldap password policy resp…
CVE-2026-4389810.038.8nyarivSandboxJSCWE-94SandboxJS: Sandbox escape via Function.caller leakage of internal call op
CVE-2026-415657.538.6MIKCryptXCWE-121CryptX versions before 0.088_001 for Perl have a stack buffer overflow in fou…
CVE-2026-461147.538.5LinuxLinuxCWE-476RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads
CVE-2026-343119.838.1Oracle CorporationOracle Hospitality OPERA 5 Property ServicesVulnerability in the Oracle Hospitality OPERA 5 Property Services product of …
CVE-2026-453448.137.8KovahLinkAceCWE-74LinkAce: Setup database password newline injection enables pre-auth RCE on un…
CVE-2026-335908.537.5PortainerPortainer Community EditionCWE-276Insecure default permissions in Portainer CE
CVE-2026-90098.837.1CodeRevolutionCrawlomatic Multipage Scraper Post GeneratorCWE-434Crawlomatic Multipage Scraper Post Generator <= 2.7.2 - Authenticated (Author…
CVE-2026-444628.836.5zed-industrieszedCWE-184Zed: Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Perm…
CVE-2026-76347.236.3veronalabsSlimStat AnalyticsCWE-79SlimStat Analytics <= 5.4.11 - Unauthenticated Stored Cross-Site Scripting vi…
CVE-2026-467759.935.9Oracle CorporationOracle REST Data ServicesCWE-400Vulnerability in Oracle REST Data Services (component: Core). Supported versi…
CVE-2026-461379.835.5LinuxLinuxCWE-362mptcp: pm: ADD_ADDR rtx: fix potential data-race
CVE-2026-461247.535.5LinuxLinuxisofs: validate block number from NFS file handle in isofs_export_iget
CVE-2026-90949.835.0CasdoorCasdoorCVE-2026-9094
CVE-2026-78028.834.8shabtiFrontend Admin by DynamiAppsCWE-862Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticat…
CVE-2026-98035.334.8Red HatRed Hat build of Keycloak 26.4CWE-125Keycloak: keycloak: denial of service via malformed authorization header
CVE-2026-448818.534.7portainerportainerCWE-59Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update
CVE-2026-99398.834.3GoogleChromeCWE-122Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 al…
CVE-2026-90979.833.7CasdoorCasdoorCVE-2026-9097
CVE-2026-329989.433.5VeeamService Provider ConsoleCWE-233This vulnerability in Veeam Service Provider Console allows for remote code e…
CVE-2026-461359.832.9LinuxLinuxCWE-362nvmet-tcp: fix race between ICReq handling and queue teardown
CVE-2026-485267.432.7jpadillapyjwtCWE-287PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens whe…
CVE-2026-356728.731.5thorstenphpMyFAQCWE-1188phpMyFAQ - Authentication Bypass via Empty API Token
CVE-2026-99528.831.5GoogleChromeCWE-416Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a…
CVE-2026-328478.730.7HKUDSDeepCodeCWE-22DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.py
CVE-2026-75264.330.8smubPDF EmbedderCWE-200PDF Embedder <= 4.9.3 - Authenticated (Contributor+) Information Exposure via…
CVE-2026-452889.830.6JasperFxmartenCWE-89Marten has an SQL injection vulnerability in its full-text search regConfig p…
CVE-2026-453119.630.6HmbownCodeWhaleCWE-94CodeWhale: run_tests Tool Enables RCE via Malicious Repository Without Approval
CVE-2026-98729.630.5GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.21…
CVE-2026-409144.330.3Apache Software FoundationApache Artemis Stomp ProtocolCWE-863Apache Artemis Stomp Protocol, Apache ActiveMQ Artemis Stomp Protocol: Addres…
CVE-2026-485255.330.1jpadillapyjwtCWE-400PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload…
CVE-2026-98282.930.1QOS.CH SarllogbackCWE-502Logback deserialization whitelist bypass for java.lang and java.util
CVE-2026-450765.129.9element-hqsynapseCWE-20Synapse pagination denial of service
CVE-2026-98848.829.9GoogleChromeCWE-416Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 all…
CVE-2026-445438.729.9rancherlocal-path-provisionerCWE-269Local Path Provisioner: HelperPod Template Injection
CVE-2026-481168.829.7Mintplex-Labsanything-llmCWE-77AnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-fi…
CVE-2026-57376.529.7bensibleyIndependent Analytics – WordPress Analytics PluginCWE-918Independent Analytics <= 2.14.9 - Unauthenticated Server-Side Request Forgery…
CVE-2026-90939.829.6CasdoorCasdoorCVE-2026-9093
CVE-2026-445938.729.3esm-devesm.shCWE-22esm.sh: Legacy Route Path Traversal Can Lead to RCE
CVE-2026-307617.328.9n/an/aCWE-434An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php co…
CVE-2026-99628.828.6GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a r…
CVE-2026-97957.328.5Red HatRed Hat build of Keycloak 26.4CWE-266Keycloak: keycloak: privilege escalation via improper scope mapping enforcement
CVE-2026-468399.928.3Oracle CorporationOracle REST Data ServicesCWE-284Vulnerability in Oracle REST Data Services (component: Core). Supported versi…
CVE-2026-76515.328.0wpeverestUser Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-639User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecur…
CVE-2026-446577.528.0mantisbtmantisbtCWE-79MantisBT: Stored XSS in File Download
CVE-2026-97984.327.8Red HatRed Hat build of Keycloak 26.4CWE-305Keycloak: keycloak: brute-force protection bypass in ciba flow
CVE-2026-448499.427.7portainerportainerCWE-862Portainer: Endpoint security bypass via Swarm service create/update
CVE-2026-23747.227.6robertpeakeLogin No Captcha reCAPTCHACWE-79Login No Captcha reCAPTCHA <= 1.8.0 - Unauthenticated Stored Cross-Site Scrip…
CVE-2026-411416.527.6espocrmespocrmCWE-639EspoCRM: IDOR in EmailTemplate Prepare Endpoint Leaks Entity Data via Email A…
CVE-2026-450178.226.5jg-rpliquidCWE-22Python Liquid: Absolute paths escape filesystem loader search path
CVE-2026-485243.726.5jpadillapyjwtCWE-460PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled k…
CVE-2026-448828.126.4portainerportainerCWE-863Portainer: Kubernetes middleware continues after token validation failure, by…
CVE-2026-372668.026.2n/an/aCWE-98An issue in Responsive File Manager Responsive FileManager Version 9.14.0 all…
CVE-2026-75525.326.2cyberhoboGeo MashupCWE-862Geo Mashup <= 1.13.19 - Missing Authorization to Unauthenticated Plugin Setti…
CVE-2026-423996.526.1ElasticKibanaCWE-400Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-424006.526.1ElasticKibanaCWE-400Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-89809.326.0MennekesAmtronCWE-269Privilege Escalation
CVE-2026-97945.326.0Red HatRed Hat build of Keycloak 26.4CWE-209Keycloak: keycloak: information disclosure via saml ecp endpoint
CVE-2026-468199.125.9Oracle CorporationOracle Internet Procurement ConnectorCWE-284Vulnerability in the Oracle Internet Procurement Connector product of Oracle …
CVE-2026-90967.525.9CasdoorCasdoorCVE-2026-9096
CVE-2026-429998.825.8OpenStackKeystoneCWE-863An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBA…
CVE-2026-448489.425.7portainerportainerCWE-862Portainer: Missing authorization on Docker plugin endpoints allows host RCE
CVE-2026-468339.025.7Oracle CorporationOracle Database ServerVulnerability in the Net Service component of Oracle Database Server. Support…
CVE-2026-430008.825.6OpenStackKeystoneCWE-863An issue was discovered in OpenStack Keystone before 29.0.2. When combined wi…
CVE-2026-446729.325.4mapfishmapfish-printCWE-94mapfish-print: Remote Code Injection (RCE) in Dynamic table
CVE-2026-99108.825.4GoogleChromeCWE-125Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216…
CVE-2026-89158.825.2Samsung Open SourceEscargotCWE-787Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Over…
CVE-2026-356758.825.2thorstenphpMyFAQCWE-307phpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/use…
CVE-2026-411856.025.1TigeraCalicoCWE-532ServiceAccount token disclosure via Azure IPAM CNI plugin logs
CVE-2026-90915.325.0CasdoorCasdoorCVE-2026-9091
CVE-2026-445947.524.9esm-devesm.shCWE-22esm.sh: Path Traversal via package.json browser field allows reading arbitrar…
CVE-2026-68165.124.8DrupalTFA Basic PluginsCWE-267TFA Basic Plugins - Access Bypass
CVE-2026-99388.824.7GoogleChromeCWE-94Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 a…
CVE-2026-100138.824.7GoogleChromeCWE-416Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed …
CVE-2024-470965.124.7Follet School SolutionsDestinyCWE-79Reflected Cross-Site Scripting in Follet School Solutions Destiny
CVE-2024-470975.124.7Follet School SolutionsDestinyCWE-79Reflected Cross-Site Scripting in Follet School Solutions Destiny
CVE-2026-453239.624.4jpettittmeshcore-cardCWE-79MeshCore Card: XSS vulnerability through meshcore node name
CVE-2026-96459.924.3ScadaBRScadaBRCWE-78ScadaBR Authenticated Remote Code Execution
CVE-2026-90929.124.3CasdoorCasdoorCVE-2026-9092
CVE-2026-465098.224.4ranfdevdeepobjCWE-1321deepobj: Improperly Controlled Modification of Object Prototype Attributes ('…
CVE-2026-448837.724.3portainerportainerCWE-598Portainer: JWT accepted in URL query leaks tokens to logs and referers
CVE-2026-329999.024.0WebProsComet BackupCWE-94Insufficient character filtering in backup agent signing module on Comet Back…
CVE-2026-98788.823.9GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-447966.523.9nautobotnautobotCWE-400Nautobot: Object bulk rename UI actions vulnerable to denial of service by cr…
CVE-2026-450448.823.7rustfsrustfsCWE-306RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unau…
CVE-2026-449738.123.7go-gitgo-billyCWE-22Billy: Path traversal vulnerabilities
CVE-2026-471366.923.7rustfsrustfsCWE-200RustFS: Unauthenticated RustFS console license endpoint exposes license metadata
CVE-2026-307607.323.5n/an/aCWE-20An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attacke…
CVE-2026-453438.523.2KovahLinkAceCWE-79LinkAce - Stored XSS via Unsanitized SSO User's Name Rendered in Admin Audit …
CVE-2026-99278.822.9GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-99288.822.9GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.2…
CVE-2026-99418.822.9GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-99458.822.9GoogleChromeCWE-416Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 a…
CVE-2026-99478.822.9GoogleChromeCWE-416Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remo…
CVE-2026-429988.822.9OpenStackKeystoneCWE-863An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone app…
CVE-2026-356718.722.9thorstenphpMyFAQCWE-266phpMyFAQ - Insecure Direct Object Reference in User Password API
CVE-2026-461258.822.8LinuxLinuxCWE-416wifi: mac80211: remove station if connection prep fails
CVE-2026-98738.822.6GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a …
CVE-2026-423987.722.5ElasticKibanaCWE-918Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network …
CVE-2026-98026.822.6Red HatRed Hat build of Keycloak 26.4CWE-613Keycloak: keycloak: unauthorized account access via replayed refresh tokens a…
CVE-2026-90154.322.6equalizedigitalEqualize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 complianceCWE-862Equalize Digital Accessibility Checker <= 1.42.0 - Missing Authorization to A…
CVE-2026-446558.622.3mantisbtmantisbtCWE-79MantisBT: Stored XSS on Move Attachments Admin Page
CVE-2026-90958.122.4CasdoorCasdoorCWE-294CVE-2026-9095
CVE-2026-444658.622.2zed-industrieszedCWE-78Zed: Zed IDE Arbitrary Code Execution via untrusted repository with poisoned …
CVE-2026-99768.822.1GoogleChromeCWE-94Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 …
CVE-2026-99958.822.1GoogleChromeCWE-416Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-453647.322.0better-authbetter-authCWE-307Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable …
CVE-2026-492995.322.0OpenStackNeutronCWE-863In OpenStack Neutron before 28.0.1, the tagging controller enforces plural po…
CVE-2026-70527.221.8htpluginsHT Contact Form – Drag & Drop Form Builder for WordPressCWE-79HT Contact Form <= 2.8.2 - Unauthenticated Stored Cross-Site Scripting via Fi…
CVE-2026-411604.321.7espocrmespocrmCWE-284EspoCRM: Broken Access Control / IDOR in Note Pinning API allows unauthorized…
CVE-2026-98798.821.6GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed…
CVE-2026-98838.821.6GoogleChromeCWE-416Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a rem…
CVE-2026-98968.821.6GoogleChromeCWE-787Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a …
CVE-2026-98978.821.6GoogleChromeCWE-416Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remo…
CVE-2026-99698.821.6GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-64276.421.6a3reva3 Lazy LoadCWE-79a3 Lazy Load <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-375797.321.5n/an/aCWE-502An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute ar…
CVE-2026-468229.920.8Oracle CorporationOracle iAssetsCWE-284Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (compo…
CVE-2026-468268.820.8Oracle CorporationOracle PayrollCWE-306Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo…
CVE-2026-329957.520.8Rocket.ChatRocket.ChatCWE-284The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0,…
CVE-2026-461988.820.6LinuxLinuxCWE-190batman-adv: fix integer overflow on buff_pos
CVE-2026-491296.920.6MusicPlayerDaemonMPDCWE-918Music Player Daemon < 0.24.11 SSRF via CurlInputPlugin
CVE-2026-477595.420.6tinymcetinymceCWE-79TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- pref…
CVE-2026-477625.420.6tinymcetinymceCWE-79TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comm…
CVE-2026-418975.320.6mantisbtmantisbtCWE-79MantisBT: Reflected XSS in Rendering Dynamic Custom Textarea Field
CVE-2026-99578.820.4GoogleChromeCWE-416Use after free in PDF in Google Chrome prior to 148.0.7778.216 allowed a remo…
CVE-2026-99688.820.5GoogleChromeCWE-472Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a rem…
CVE-2026-99738.820.5GoogleChromeCWE-787Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a …
CVE-2026-99637.520.2GoogleChromeCWE-457Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allo…
CVE-2026-461388.120.1LinuxLinuxCWE-125Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_com…
CVE-2026-447987.120.1nautobotnautobotCWE-471Nautobot: GitRepository.current_head field should not be writable through RES…
CVE-2026-334646.519.9ElasticKibanaCWE-400Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-462128.819.8LinuxLinuxCWE-416batman-adv: bla: prevent use-after-free when deleting claims
CVE-2026-468347.519.8Oracle CorporationOracle Database ServerCWE-400Vulnerability in the Net Service component of Oracle Database Server. Support…
CVE-2026-468357.519.8Oracle CorporationOracle Database ServerCWE-400Vulnerability in the Net Service component of Oracle Database Server. Support…
CVE-2026-468297.519.7Oracle CorporationOracle REST Data ServicesCWE-400Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported v…
CVE-2026-99176.519.2GoogleChromeCWE-457Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.21…
CVE-2026-490946.519.2ElasticKibanaCWE-400Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-450399.819.0rustfsrustfsCWE-798RustFS: Internode RPC HMAC secret falls back to public default credential, en…
CVE-2026-468378.819.0Oracle CorporationOracle Flow ManufacturingCWE-269Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business S…
CVE-2026-97926.519.0Red HatRed Hat build of Keycloak 26.4CWE-280Keycloak: keycloak: security restriction bypass allows unauthorized ropc toke…
CVE-2026-98938.318.9GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a rem…
CVE-2026-352778.118.9Oracle CorporationOracle REST Data ServicesCWE-400Vulnerability in Oracle REST Data Services (component: Core). Supported versi…
CVE-2026-468249.918.4Oracle CorporationOracle Universal Work QueueCWE-269Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business…
CVE-2026-477615.418.4tinymcetinymceCWE-79TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce…
CVE-2026-439795.018.3LearningCircuitlocal-deep-researchCWE-79Local Deep Research: HTML Injection via Unescaped User Input in PDF Export (`…
CVE-2026-462388.818.1LinuxLinuxbatman-adv: stop caching unowned originator pointers in BAT IV
CVE-2026-490956.518.1ElasticKibanaCWE-20Improper Input Validation in Kibana Fleet Leading to Privilege Escalation
CVE-2026-468217.718.0Oracle CorporationOracle Financials Common ModulesCWE-284Vulnerability in the Oracle Financials Common Modules product of Oracle E-Bus…
CVE-2026-100057.517.9GoogleChromeCWE-416Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.…
CVE-2026-468187.417.9Oracle CorporationOracle PaymentsCWE-284Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp…
CVE-2026-453749.617.8HmbownCodeWhaleCWE-94CodeWhale: task_create Insecure Defaults Enable RCE via Prompt Injection in P…
CVE-2026-420717.217.9mantisbtmantisbtCWE-862MantisBT: Private Bugnote Attachment Content Leak via REST API
CVE-2026-491306.917.8MusicPlayerDaemonMPDCWE-93Music Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxx
CVE-2026-476765.317.8honojshonoCWE-444Hono: app.mount() strips mount prefix using undecoded path, causing incorrect…
CVE-2026-99408.817.7GoogleChromeCWE-122Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowe…
CVE-2026-462328.117.6LinuxLinuxHID: playstation: Clamp num_touch_reports
CVE-2026-98066.317.6mispcti-transmuteCWE-79Stored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Mal…
CVE-2026-420705.317.7mantisbtmantisbtCWE-863MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API
CVE-2026-468435.317.6Oracle CorporationOracle REST Data ServicesCWE-400Vulnerability in Oracle REST Data Services (component: Core). Supported versi…
CVE-2026-444618.617.5zed-industrieszedCWE-78Zed: Remote Command Injection via Unquoted Environment Variable Keys (SSH / W…
CVE-2026-53437.417.5DrupalSAML SSO - Service ProviderCWE-754SAML SSO - Service Provider - Critical - Authentication bypass - SA-CONTRIB-2…
CVE-2026-448846.017.5portainerportainerCWE-862Portainer: Missing authorization on custom template file endpoint exposes tem…
CVE-2026-99838.817.2GoogleChromeCWE-843Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a rem…
CVE-2026-99017.517.2GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-99097.517.2GoogleChromeCWE-472Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a r…
CVE-2026-99227.517.2GoogleChromeCWE-416Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed…
CVE-2026-99347.517.2GoogleChromeCWE-416Use after free in Aura in Google Chrome prior to 148.0.7778.216 allowed a rem…
CVE-2026-99567.517.2GoogleChromeCWE-416Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed…
CVE-2026-99238.817.0GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a rem…
CVE-2026-100078.816.9GoogleChromeCWE-416Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remo…
CVE-2026-100158.816.9GoogleChromeCWE-472Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-100168.816.9GoogleChromeCWE-416Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remo…
CVE-2026-468278.816.6Oracle CorporationOracle PayrollCWE-269Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo…
CVE-2026-76214.316.6smtp2goSMTP2GO for WordPress – Email Made EasyCWE-862SMTP2GO for WordPress <= 1.16.0 - Missing Authorization to Authenticated (Sub…
CVE-2026-443948.116.5OpenStackKeystoneCWE-863An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone fed…
CVE-2026-64558.116.3yudizWP Contact Form 7 DB HandlerCWE-352WP Contact Form 7 DB Handler <= 3.0 - Cross-Site Request Forgery to Arbitrary…
CVE-2026-99126.516.3GoogleChromeCWE-200Inappropriate implementation in GPU in Google Chrome on Android prior to 148.…
CVE-2026-99536.516.3GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed …
CVE-2026-465265.016.3LearningCircuitlocal-deep-researchCWE-918Local Deep Research: SSRF bypass in `safe_get`
CVE-2026-90379.316.1XChargeC6CWE-494Download of code without integrity check in XCharge C6
CVE-2026-99158.316.0GoogleChromeCWE-122Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowe…
CVE-2026-99248.316.0GoogleChromeCWE-122Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778…
CVE-2026-99268.316.0GoogleChromeCWE-122Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowe…
CVE-2026-98919.016.0GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed…
CVE-2026-476745.315.8honojshonoCWE-185Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
CVE-2026-98759.615.7GoogleChromeCWE-125Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.2…
CVE-2026-98769.615.7GoogleChromeCWE-416Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 a…
CVE-2026-98869.615.7GoogleChromeCWE-416Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowe…
CVE-2026-99189.615.8GoogleChromeCWE-269Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216…
CVE-2026-99679.615.7GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a…
CVE-2026-99618.815.7GoogleChromeCWE-416Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 all…
CVE-2026-99658.815.7GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed…
CVE-2026-31736.515.8mr2pMeta Field Block – Display custom fields in the Block Editor without codingCWE-639Meta Field Block <= 1.5.1 - Insecure Direct Object Reference to Authenticated…
CVE-2026-86894.315.7themeisleVisualizer: Tables and Charts Manager for WordPressCWE-862Visualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Auth…
CVE-2026-356768.815.5thorstenphpMyFAQCWE-640phpMyFAQ - Unauthenticated Password Reset via User Password Update Endpoint
CVE-2026-450418.715.3rustfsrustfsCWE-321RustFS: Hard-coded RSA private key in license verifier permits arbitrary lice…
CVE-2026-453737.415.2HmbownCodeWhaleCWE-918CodeWhale: SSRF‌ IPV6 bypass
CVE-2026-99086.515.0GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed …
CVE-2026-334635.315.0ElasticKibanaCWE-672Operation on a Resource after Expiration or Termination in Kibana Leading to …
CVE-2026-99214.315.0GoogleChromeCWE-457Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.21…
CVE-2026-99354.315.0GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a…
CVE-2026-99148.315.0GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-334627.314.8ElasticKibanaCWE-22Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts
CVE-2026-447978.514.7nautobotnautobotCWE-918Nautobot: Webhook definitions could be used for server-side request forgery (…
CVE-2026-99607.514.7GoogleChromeCWE-472Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a…
CVE-2026-98749.614.6GoogleChromeCWE-416Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a rem…
CVE-2026-450589.414.5electermelectermCWE-94electerm: Import unsafe bookmark data could lead to unsafe operation when cli…
CVE-2026-99788.814.5GoogleChromeCWE-416Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a rem…
CVE-2026-99848.814.5GoogleChromeCWE-416Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allo…
CVE-2026-99928.814.5GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a …
CVE-2026-100218.814.5GoogleChromeCWE-20Insufficient validation of untrusted input in USB in Google Chrome prior to 1…
CVE-2026-453066.514.6pyloadpyloadCWE-706pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session …
CVE-2026-99134.314.6GoogleChromeCWE-125Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.21…
CVE-2026-99648.114.4GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 a…
CVE-2026-444668.614.2zed-industrieszedCWE-78Zed: Allowlist Bypass via Bash Arithmetic Expansion in Terminal Tool Permissions
CVE-2026-444637.814.3zed-industrieszedCWE-78Zed: Allowlist Bypass via Environment Variable Injection in Terminal Tool Per…
CVE-2026-98136.214.3flowintelflowintelCWE-918FlowIntel external reference URL probe allows server-side request forgery
CVE-2026-86824.314.3hasanazizul3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try OnCWE-8623D Viewer <= 2.0.1 - Missing Authorization to Authenticated (Subscriber+) Arb…
CVE-2026-452967.714.1openreplayopenreplayCWE-284OpenReplay: Cross-tenant information disclosure in app_apikey projectKey rout…
CVE-2026-90989.114.1CasdoorCasdoorCVE-2026-9098
CVE-2026-90388.614.1XChargeC6CWE-121Stack-based buffer overflow in XCharge C6
CVE-2026-100067.514.1GoogleChromeCWE-362Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote at…
CVE-2026-98808.313.8GoogleChromeCWE-20Insufficient validation of untrusted input in WebGL in Google Chrome prior to…
CVE-2026-98858.313.8GoogleChromeCWE-20Insufficient validation of untrusted input in UI in Google Chrome on Mac prio…
CVE-2026-98988.313.8GoogleChromeCWE-20Insufficient validation of untrusted input in GPU in Google Chrome on Android…
CVE-2026-468208.513.7Oracle CorporationOracle Financials Common ModulesCWE-284Vulnerability in the Oracle Financials Common Modules product of Oracle E-Bus…
CVE-2026-462157.813.7LinuxLinuxCWE-416drm: Set old handle to NULL before prime swap in change_handle
CVE-2026-470748.713.5ex-awsex_aws_snsCWE-295ex_aws_sns SigningCertURL not validated in verify_message/1
CVE-2026-99728.313.6GoogleChromeCWE-457Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 …
CVE-2026-453107.413.5HmbownCodeWhaleCWE-918CodeWhale: SSRF via HTTP Redirect Bypass in fetch_url Tool
CVE-2026-96587.313.6RRWOPlack::Middleware::Security::CommonCWE-113Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not b…
CVE-2026-99998.813.4GoogleChromeCWE-269Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.…
CVE-2026-453427.113.4KovahLinkAceCWE-639LinkAce: IDOR in Update Policies Allows Any Authenticated User to Overwrite O…
CVE-2026-99588.813.3GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a r…
CVE-2026-67207.213.3TigeraCalicoCWE-532Calicoctl leaks cluster credentials to stderr when verbose logging is enabled
CVE-2026-100086.513.3GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 …
CVE-2026-98778.313.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-99168.313.1GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed…
CVE-2026-99258.313.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-99318.313.1GoogleChromeCWE-416Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remo…
CVE-2026-99328.313.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 a…
CVE-2026-99368.313.1GoogleChromeCWE-416Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed…
CVE-2026-99378.313.1GoogleChromeCWE-416Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allo…
CVE-2026-99488.313.1GoogleChromeCWE-416Use after free in Views in Google Chrome on Mac prior to 148.0.7778.216 allow…
CVE-2026-99498.313.1GoogleChromeCWE-416Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 al…
CVE-2026-99518.313.1GoogleChromeCWE-416Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remot…
CVE-2026-99337.513.1GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-43346.413.03uuShariff WrapperCWE-79Shariff Wrapper <= 4.6.20 - Authenticated (Contributor+) Cross-Site Scripting
CVE-2026-450235.413.0Significant-GravitasAutoGPTCWE-770AutoGPT: Credit system bypassed via direct block execution in POST /api/block…
CVE-2026-485224.213.0jpadillapyjwtCWE-441PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file:/…
CVE-2026-100037.512.9GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-100097.512.9GoogleChromeCWE-472Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a r…
CVE-2026-98826.512.8GoogleChromeCWE-190Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a …
CVE-2026-477134.312.7Mintplex-Labsanything-llmCWE-285AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping …
CVE-2026-98878.812.5GoogleChromeCWE-416Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-92284.312.5jetmonstersTimetable and Event Schedule by MotoPressCWE-639Timetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object …
CVE-2026-99194.312.5GoogleChromeCWE-125Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.2…
CVE-2026-468288.112.3Oracle CorporationOracle PayrollCWE-284Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (compo…
CVE-2026-476755.312.3honojshonoCWE-113Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Coo…
CVE-2026-78628.612.2UnknownEupago Gateway For WoocommerceCWE-284Eupago Gateway For Woocommerce < 4.7.2 - Unauthenticated Arbitrary Refund Ini…
CVE-2026-468415.312.1Oracle CorporationOracle REST Data ServicesCWE-200Vulnerability in Oracle REST Data Services (component: General). Supported ve…
CVE-2026-97914.312.1Red HatRed Hat build of Keycloak 26.4CWE-863Keycloak-rhel9: organization data leak after feature disabled in keycloak
CVE-2026-98888.311.9GoogleChromeCWE-416Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216…
CVE-2026-98898.311.9GoogleChromeCWE-125Out of bounds read and write in Dawn in Google Chrome on Android prior to 148…
CVE-2026-98908.311.9GoogleChromeCWE-416Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allo…
CVE-2026-98948.311.9GoogleChromeCWE-416Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remo…
CVE-2026-98958.311.9GoogleChromeCWE-125Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a …
CVE-2026-98998.311.9GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-99008.311.9GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed…
CVE-2026-99028.311.9GoogleChromeCWE-416Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allo…
CVE-2026-99048.311.9GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-99058.311.9GoogleChromeCWE-416Use after free in Accessibility in Google Chrome on Windows prior to 148.0.77…
CVE-2026-99068.311.9GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a…
CVE-2026-99668.311.9GoogleChromeCWE-472Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 a…
CVE-2026-99708.311.9GoogleChromeCWE-416Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-99758.311.9GoogleChromeCWE-125Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.21…
CVE-2026-99547.511.9GoogleChromeCWE-416Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a…
CVE-2026-92414.311.9realmag777FOX – Currency Switcher Professional for WooCommerceCWE-639FOX – Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated…
CVE-2026-468237.711.7Oracle CorporationOracle Public Sector Financials (International)CWE-863Vulnerability in the Oracle Public Sector Financials (International) product …
CVE-2026-99203.111.7GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 …
CVE-2026-99074.311.4GoogleChromeCWE-125Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.21…
CVE-2026-99114.311.4GoogleChromeCWE-472Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a …
CVE-2026-99294.311.4GoogleChromeCWE-200Inappropriate implementation in WebGL in Google Chrome on Android prior to 14…
CVE-2026-99434.311.4GoogleChromeCWE-125Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.2…
CVE-2026-99468.311.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-99748.311.1GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a…
CVE-2026-450427.111.1rustfsrustfsCWE-863RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source
CVE-2026-89905.311.1View ConceptKidsviewCWE-288Authentication Bypass in Kidsview
CVE-2026-452975.311.1openreplayopenreplayCWE-285Cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} ca…
CVE-2026-448508.510.9portainerportainerCWE-863Portainer: Bind-mount restriction bypass via HostConfig.Mounts
CVE-2026-98928.310.9GoogleChromeCWE-269Inappropriate implementation in Skia in Google Chrome on Android prior to 148…
CVE-2026-76606.110.8davidandersonEasy Updates ManagerCWE-79Easy Updates Manager <= 9.0.20 - Reflected Cross-Site Scripting via 'paged' P…
CVE-2026-454105.310.8mauriceboeTREKCWE-203Time-based user enumeration in TREK authentication endpoint
CVE-2026-468305.310.9Oracle CorporationOracle REST Data ServicesCWE-200Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported v…
CVE-2026-450215.110.7kumahqkumaCWE-346Kuma: Default kuma-cp leaks admin token cross-origin via CORS wildcard + Loca…
CVE-2026-98819.010.5GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 a…
CVE-2026-461668.810.5LinuxLinuxCWE-416wifi: mac80211: use safe list iteration in radar detect work
CVE-2026-90909.110.3CasdoorCasdoorCVE-2026-9090
CVE-2026-453488.710.0pyloadpyloadCWE-79pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js …
CVE-2026-490937.710.1ElasticKibanaCWE-918Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network …
CVE-2026-476736.510.0honojshonoCWE-285Hono: JWT middleware accepts any Authorization scheme, not only Bearer
CVE-2026-99425.010.0GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a…
CVE-2026-99503.110.1GoogleChromeCWE-20Insufficient validation of untrusted input in iOS in Google Chrome on iOS pri…
CVE-2026-100208.39.9GoogleChromeCWE-20Insufficient validation of untrusted input in Skia in Google Chrome on Androi…
CVE-2026-99443.19.8GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a…
CVE-2026-99554.39.4GoogleChromeCWE-200Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.77…
CVE-2026-98074.39.3GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-454032.59.3Mintplex-Labsanything-llmCWE-59AnythingLLM: filesystem-copy-file follows nested symlinks and copies files fr…
CVE-2026-99816.59.0GoogleChromeCWE-200Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216…
CVE-2026-99966.59.0GoogleChromeCWE-125Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 …
CVE-2026-100186.59.0GoogleChromeCWE-472Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a …
CVE-2026-477605.49.1tinymcetinymceCWE-79TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass th…
CVE-2026-99304.39.0GoogleChromeCWE-787Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 a…
CVE-2026-100198.88.9GoogleChromeCWE-472Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a …
CVE-2026-97966.58.5Red HatRed Hat build of Keycloak 26.6CWE-367Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (to…
CVE-2026-90398.68.4XChargeC6CWE-1188Initialization of a resource with an insecure default in XCharge C6
CVE-2026-100008.38.4GoogleChromeCWE-416Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.2…
CVE-2026-100148.38.4GoogleChromeCWE-416Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216…
CVE-2026-100178.38.4GoogleChromeCWE-125Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allow…
CVE-2026-99778.38.3GoogleChromeCWE-20Insufficient validation of untrusted input in WebShare in Google Chrome on An…
CVE-2026-99828.38.3GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-468425.38.2Oracle CorporationOracle REST Data ServicesCWE-284Vulnerability in Oracle REST Data Services (component: Core). Supported versi…
CVE-2026-99948.38.0GoogleChromeCWE-416Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 al…
CVE-2026-99855.38.1GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome on Chrom…
CVE-2026-443588.28.0espressifshared-github-dangerjsCWE-427Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action En…
CVE-2026-100284.37.9Red HatRed Hat Enterprise Linux 10CWE-835Glib-networking: infinite loop in glib-networking gnutls backend allows remot…
CVE-2026-100028.87.9GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a r…
CVE-2026-99978.37.6GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-447945.47.5nautobotnautobotCWE-862Nautobot: REST API permits creation of GenericForeignKey references to object…
CVE-2026-465615.07.3pyloadpyloadCWE-918pyLoad: SSRF via HTTP Redirect Bypass in parse_urls API
CVE-2026-99888.37.0GoogleChromeCWE-416Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 al…
CVE-2026-99988.37.0GoogleChromeCWE-472Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a r…
CVE-2026-100018.37.0GoogleChromeCWE-416Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216…
CVE-2026-100128.37.0GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a rem…
CVE-2026-99907.57.0GoogleChromeCWE-416Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.…
CVE-2026-461528.86.4LinuxLinuxCWE-1058wifi: mac80211: drop stray 'static' from fast-RX rx_result
CVE-2026-96735.56.3n/ajson-2-csvCWE-1236Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerab…
CVE-2026-99938.36.1GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a re…
CVE-2026-100046.56.1GoogleChromeCWE-20Insufficient validation of untrusted input in Passwords in Google Chrome prio…
CVE-2026-100113.16.0GoogleChromeCWE-200Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216…
CVE-2026-99035.05.8GoogleChromeCWE-20Insufficient validation of untrusted input in Site Isolation in Google Chrome…
CVE-2026-99715.45.6GoogleChromeCWE-79Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.77…
CVE-2026-97937.55.4Red HatRed Hat build of Keycloak 26.4CWE-347Keycloak: keycloak: security policy bypass in jwe-encrypted request object pr…
CVE-2026-96466.15.5ScadaBRScadaBRCWE-80ScadaBR Unauthenticated Reflected Cross-Site Scripting
CVE-2026-96446.45.3nhadjidimitrovLiveSmart Video Chat Live Video ChatCWE-79LiveSmart Video Chat <= 1.2 - Authenticated (Contributor+) Stored Cross-Site …
CVE-2026-461138.85.1LinuxLinuxCWE-416KVM: x86: Fix shadow paging use-after-free due to unexpected GFN
CVE-2026-329967.35.0VeeamBackup and ReplicationCWE-532This vulnerability in Veeam Agent for Microsoft Windows allows for Local Priv…
CVE-2026-453076.15.0murtaza-nasirspeakrCWE-601Speakr: Open redirect in is_safe_url via parser mismatch on next parameter
CVE-2026-97898.54.8AcerNitrorSense V3CWE-22NitroSense V3: Security Vulnerability Information
CVE-2026-450405.34.9rustfsrustfsCWE-312RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in R…
CVE-2026-100227.54.8GoogleChromeCWE-843Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an atta…
CVE-2026-99864.24.2GoogleChromeCWE-20Insufficient validation of untrusted input in OptimizationGuide in Google Chr…
CVE-2026-461897.84.2LinuxLinuxCWE-415RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
CVE-2026-461457.84.0LinuxLinuxCWE-787RDMA/mana: Validate rx_hash_key_len
CVE-2026-461767.84.0LinuxLinuxCWE-825RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()
CVE-2026-461237.74.0LinuxLinuxCWE-787Bluetooth: virtio_bt: clamp rx length before skb_put
CVE-2026-461507.14.0LinuxLinuxfanotify: fix false positive on permission events
CVE-2026-462057.83.9LinuxLinuxstaging: media: atomisp: Disallow all private IOCTLs
CVE-2026-492377.84.0CanonicalMultipassCWE-276Local Privilege Escalation in Canonical Multipass
CVE-2026-43776.03.9D-Link CorporationDWR-X1820CWE-1391Use of Weak Credentials in D-Link DWR-X1820 router

Results continue: ranks 401–542.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-28 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.