CVSS EPSS %ile KEV — .9391 99.8 YES
AFFECTED Product Versions Fixed PAN-OS unspecified —
TIMELINE May 29 Added to CISA KEV, due Jun 1 May 29 Published
249 CVEs published May 29, 2026: 44 critical, 105 high, 83 medium, 16 low; 1 in KEV; 17 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 224 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 3140 | 4270 | 1026 | 2563 |
| KEV catalog size | 1670 | |||
126 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 639 | 965 | 79 | 615 | 269 | 1 | 27 | 2 | 0.2 | 7.8 | .0013 | +476 |
| microsoft | 170 | 490 | 43 | 328 | 102 | 0 | 378 | 27 | 5.5 | 7.8 | .0045 | -17 |
| 168 | 174 | 10 | 120 | 35 | 6 | 74 | 4 | 2.3 | 8.3 | .0023 | +167 | |
| red hat | 41 | 64 | 8 | 27 | 26 | 3 | 4 | 0 | 0.0 | 7.2 | .0037 | +30 |
| apple | 20 | 47 | 0 | 12 | 27 | 1 | 93 | 7 | 14.9 | 6.2 | .0034 | +20 |
| canonical | 14 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | +14 |
| freebsd | 7 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | +7 |
| suse | 2 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.2 | .0020 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 5 | 13 | 3 | 1 | 2 | 0 | 96 | 8 | 61.5 | 8.6 | .1247 | +2 |
| checkpoint | 6 | 6 | 0 | 3 | 3 | 0 | 3 | 0 | 0.0 | 6.5 | .0338 | +6 |
| fortinet | 1 | 6 | 1 | 3 | 0 | 0 | 28 | 3 | 50.0 | 7.9 | .4330 | -2 |
| ivanti | 2 | 5 | 0 | 1 | 0 | 0 | 33 | 4 | 80.0 | 8.8 | .8056 | +1 |
| f5 | 2 | 3 | 2 | 0 | 0 | 0 | 7 | 1 | 33.3 | 9.2 | .0996 | +2 |
| ubiquiti | 2 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.8 | .0068 | +2 |
| palo alto networks | 2 | 2 | 0 | 0 | 0 | 0 | 14 | 2 | 100.0 | — | .6299 | +2 |
| broadcom | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .1990 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 21 | 32 | 4 | 15 | 12 | 0 | 40 | 1 | 3.1 | 7.4 | .0064 | +12 |
| gitlab | 7 | 9 | 0 | 1 | 6 | 0 | 4 | 2 | 22.2 | 4.3 | .0032 | +7 |
| mozilla | 6 | 6 | 3 | 2 | 1 | 0 | 13 | 0 | 0.0 | 8.8 | .0042 | +6 |
| drupal | 5 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | +5 |
| docker | 3 | 3 | 0 | 3 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0022 | +3 |
| github | 2 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | +2 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ibm | 49 | 49 | 10 | 24 | 15 | 0 | 7 | 0 | 0.0 | 7.5 | .0028 | +49 |
| oracle | 25 | 27 | 8 | 15 | 4 | 0 | 40 | 0 | 0.0 | 8.1 | .0027 | +25 |
| progress | 4 | 4 | 0 | 4 | 0 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +4 |
| adobe | 1 | 4 | 0 | 1 | 0 | 0 | 75 | 3 | 75.0 | 8.6 | .2776 | -2 |
| veeam | 3 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.6 | .0040 | +3 |
| solarwinds | 0 | 3 | 1 | 0 | 0 | 0 | 11 | 3 | 100.0 | 9.8 | .8362 | 0 |
| zohocorp | 2 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | +2 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 18 | 18 | 2 | 3 | 10 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +18 |
| d-link | 2 | 3 | 0 | 1 | 1 | 0 | 26 | 1 | 33.3 | 7.3 | .0059 | +1 |
| hitachi energy | 2 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | +2 |
| siemens | 1 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | +1 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| concrete cms | 44 | 44 | 1 | 9 | 13 | 21 | 0 | 0 | 0.0 | 5.7 | .0015 | +44 |
| edimax | 44 | 44 | 0 | 27 | 0 | 17 | 1 | 0 | 0.0 | 7.4 | .0059 | +44 |
| open ises | 44 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | +44 |
| helmholz | 42 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | +42 |
| mb connect line | 42 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | +42 |
| totolink | 34 | 34 | 0 | 25 | 0 | 9 | 0 | 0 | 0.0 | 8.9 | .0191 | +34 |
| netatalk | 33 | 33 | 1 | 13 | 9 | 10 | 0 | 0 | 0.0 | 6.4 | .0030 | +33 |
| nvidia | 33 | 33 | 8 | 18 | 7 | 0 | 0 | 0 | 0.0 | 7.8 | .0038 | +33 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-31431 | .9991 | 100.0 | 7.8 |
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-41940 | .9793 | 99.9 | 9.3 |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2026-43284 | .9324 | 99.8 | 8.8 |
| CVE-2026-43500 | .9285 | 99.8 | 7.8 |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2026-42208 | .8942 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-43997 | 10.0 | .0098 | |
| CVE-2026-42826 | 10.0 | .0084 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-44005 | 10.0 | .0083 | |
| CVE-2026-44006 | 10.0 | .0081 | |
| CVE-2026-46840 | 10.0 | .0073 |
| Vendor | CVEs |
|---|---|
| linux | 641 |
| microsoft | 170 |
| 168 | |
| ibm | 49 |
| concrete cms | 44 |
| edimax | 44 |
| open ises | 44 |
| red hat | 44 |
| helmholz | 42 |
| mb connect line | 42 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 8 |
| apple | 7 |
| 4 | |
| ivanti | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| smartertools | 3 |
| solarwinds | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 12 |
| Packagist | 7 |
| PyPI | 2 |
| crates.io | 2 |
| npm | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE-2026-0300 | Palo Alto Networks | 0 |
| CVE-2026-20182 | Cisco | 0 |
| CVE-2026-31431 | Linux | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1654 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1654 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1654 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1654 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1654 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1654 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1654 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1654 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1654 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1654 |
EXPLOIT PUBLISHED — CVE-2026-39276. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44421 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44422 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45352 (yhirose cpp-httplib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45372 (yhirose cpp-httplib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45700 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45731 (WWBN AVideo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46337 (WWBN AVideo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46527 (yhirose cpp-httplib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47694 (WWBN AVideo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47696 (WWBN AVideo). Public exploit reference added.
249 CVEs published. 25 box scores, 224 table rows — nothing truncated.
CVSS EPSS %ile KEV — .9391 99.8 YES
AFFECTED Product Versions Fixed PAN-OS unspecified —
TIMELINE May 29 Added to CISA KEV, due Jun 1 May 29 Published
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1927 97.1 —
AFFECTED Product Versions Fixed WP Maps Pro unspecified —
TIMELINE May 16 Reserved by CNA May 29 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .1303 96.0 —
AFFECTED Product Versions Fixed TeamCity unspecified —
TIMELINE May 29 Reserved by CNA May 29 Published (CNA: JetBrains)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0501 91.5 —
AFFECTED Product Versions Fixed TEW-432BRP 3.10B20 – —
TIMELINE May 29 Reserved by CNA May 29 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0501 91.5 —
AFFECTED Product Versions Fixed TEW-432BRP 3.10B20 – —
TIMELINE May 29 Reserved by CNA May 29 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0367 88.7 —
AFFECTED Product Versions Fixed FreeRDP < 3.26.0 – —
TIMELINE May 6 Reserved by CNA May 29 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0138 69.8 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0138 69.8 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0138 69.8 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0138 69.8 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0138 69.8 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0138 69.8 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0138 69.8 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0134 68.9 —
AFFECTED Product Versions Fixed Predator Connect W6x W6x_GBL_2.00.000005 – —
TIMELINE May 28 Reserved by CNA May 29 Published (CNA: Acer)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0092 57.4 —
AFFECTED Product Versions Fixed dokploy <= 0.26.6 – —
TIMELINE May 12 Reserved by CNA May 29 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0088 56.2 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0088 56.2 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0088 56.2 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H P H H H 8.5 .0088 56.2 —
AFFECTED Product Versions Fixed WF-500 unspecified —
TIMELINE Apr 16 Reserved by CNA May 29 Published (CNA: Nozomi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U L L N 4.8 .0087 55.9 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 10 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified — Red Hat Enterprise Linux 8 unspecified — Red Hat Enterprise Linux 9 unspecified —
TIMELINE Apr 14 Reserved by CNA May 29 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0087 55.7 —
AFFECTED Product Versions Fixed dokploy <= 0.29.1 – —
TIMELINE May 12 Reserved by CNA May 29 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H L N 8.5 .0087 55.7 —
AFFECTED Product Versions Fixed SillyTavern < 1.18.0 – —
TIMELINE May 13 Reserved by CNA May 29 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0085 55.3 —
AFFECTED Product Versions Fixed TEW-432BRP 3.10B20 – —
TIMELINE May 29 Reserved by CNA May 29 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0084 54.9 —
AFFECTED Product Versions Fixed dokploy <= 0.29.0 – —
TIMELINE May 12 Reserved by CNA May 29 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0083 54.7 —
AFFECTED Product Versions Fixed TEW-432BRP 3.10B20 – —
TIMELINE May 29 Reserved by CNA May 29 Published (CNA: VulDB)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-39276 | 7.2 | 53.0 | n/a | n/a | CWE-22 | The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerab… |
| CVE-2026-45630 | 9.0 | 52.4 | Dokploy | dokploy | CWE-78 | Dokploy: Authenticated Remote Code Execution via Command Injection in updateT… |
| CVE-2026-45629 | 9.9 | 52.2 | Dokploy | dokploy | CWE-78 | Dokploy: Authenticated Remote Code Execution via Command Injection in /listen… |
| CVE-2026-49377 | 4.3 | 50.0 | JetBrains | TeamCity | CWE-526 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default… |
| CVE-2026-44962 | 9.9 | 49.7 | WebPros | Plesk | CWE-643 | Plesk contains an XPath injection vulnerability in the APS Application Catalo… |
| CVE-2026-45661 | 9.9 | 48.6 | Dokploy | dokploy | CWE-22 | Dokploy: Remote Code Execution through Path Traversal |
| CVE-2026-45700 | 7.7 | 47.2 | FreeRDP | FreeRDP | CWE-787 | Heap-buffer-overflow write in planar bitmap decoder |
| CVE-2026-5386 | 9.1 | 47.1 | KMW | KM-IP521 | CWE-620 | KMW CCTV Security Cameras Unverified Password Change |
| CVE-2026-9051 | 9.3 | 47.0 | NI | SystemLink Enterprise | CWE-306 | Authentication Bypass Vulnerability in NI SystemLink Enterprise |
| CVE-2026-10042 | 9.2 | 46.9 | zyddnys | manga-image-translator | CWE-502 | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model |
| CVE-2026-9559 | 9.9 | 45.1 | — | mautic/core | CWE-22 | A path traversal vulnerability exists in the campaign import feature of Mauti… |
| CVE-2026-9558 | 9.9 | 44.5 | — | mautic/core | CWE-1336 | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's them… |
| CVE-2026-44650 | 9.1 | 44.3 | SillyTavern | SillyTavern | CWE-22 | SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Pa… |
| CVE-2018-25393 | 7.1 | 44.2 | Navigatecms | Navigate CMS | CWE-22 | Navigate CMS 2.8.5 Path Traversal via navigate_download.php |
| CVE-2026-46384 | 8.7 | 42.3 | iskorotkov | avro | CWE-190 | iskorotkov/avro: Integer Overflow in Avro Decoder |
| CVE-2018-25388 | 8.7 | 41.8 | Sitejo | HaPe PKH | CWE-434 | HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php |
| CVE-2026-49200 | 10.0 | 41.7 | Acer | Wave 7 router | CWE-532 | Acer Wave 7 router: Broken Access Control |
| CVE-2026-10108 | 8.7 | 41.4 | hanxi | xiaomusic | CWE-22 | xiaomusic 0.5.7 Path Traversal via GET /music endpoint |
| CVE-2026-3655 | 9.8 | 41.2 | glboy | OTP Login With Phone Number, OTP Verification | CWE-287 | OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Aut… |
| CVE-2026-10071 | 9.3 | 41.0 | Interinfo | DreamMaker | CWE-434 | Interinfo|DreamMaker - Arbitrary File Upload |
| CVE-2026-44421 | 8.8 | 41.0 | FreeRDP | FreeRDP | CWE-122 | FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle vali… |
| CVE-2025-41281 | 7.5 | 40.9 | Waterfall | WF-500 | CWE-78 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special … |
| CVE-2026-46385 | 8.7 | 40.8 | iskorotkov | avro | CWE-400 | iskorotkov/avro: CPU Exhaustion in Avro Decoder |
| CVE-2026-45697 | 9.8 | 39.1 | verbb | formie | CWE-94 | Formie: Pre-authenticated server-side template injection in Hidden fields |
| CVE-2026-39292 | 7.3 | 38.8 | n/a | n/a | CWE-434 | Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload v… |
| CVE-2026-45731 | 6.9 | 38.6 | WWBN | AVideo | CWE-22 | WWBN AVideo: Authenticated Arbitrary File Read in view/update.php |
| CVE-2026-10072 | 8.6 | 37.8 | Interinfo | DreamMaker | CWE-434 | Interinfo|DreamMaker - Arbitrary File Upload |
| CVE-2026-49366 | 7.8 | 37.7 | JetBrains | IntelliJ IDEA | CWE-78 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via… |
| CVE-2026-46337 | 6.9 | 37.8 | WWBN | AVideo | CWE-22 | WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view… |
| CVE-2026-48557 | 8.7 | 36.6 | spatie | laravel-medialibrary | CWE-184 | Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via Fil… |
| CVE-2026-10065 | 8.7 | 36.5 | Shibby | Tomato | CWE-119 | Shibby Tomato tomatodata.cgi get_ups_field stack-based overflow |
| CVE-2026-10066 | 8.7 | 36.5 | Shibby | Tomato | CWE-119 | Shibby Tomato UPS Service tomatoups.cgi sub_9068 stack-based overflow |
| CVE-2026-10067 | 8.7 | 36.5 | Shibby | Tomato | CWE-119 | Shibby Tomato multimon.cgi sub_90F0 stack-based overflow |
| CVE-2026-10069 | 8.7 | 36.5 | Shibby | Tomato | CWE-400 | Shibby Tomato miniupnpd resource consumption |
| CVE-2025-41268 | 8.8 | 36.4 | Waterfall | WF-500 | CWE-23 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Admi… |
| CVE-2025-41271 | 8.7 | 36.2 | Waterfall | WF-500 | CWE-23 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Cons… |
| CVE-2026-44422 | 8.8 | 35.9 | FreeRDP | FreeRDP | CWE-415 | FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and typ… |
| CVE-2026-46376 | 9.3 | 35.4 | FreePBX | security-reporting | CWE-798 | FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreeP… |
| CVE-2026-7786 | 9.8 | 34.6 | Jinan USR IOT Technology Limited (PUSR) | USR-W610 RS232/485 to Wi-Fi/Ethernet Converter | CWE-798 | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet … |
| CVE-2025-12714 | 5.3 | 34.2 | rankmath | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | CWE-862 | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Au… |
| CVE-2025-41273 | 9.3 | 33.9 | Waterfall | WF-500 | CWE-288 | Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alt… |
| CVE-2026-10064 | 2.1 | 33.0 | TRENDnet | TEW-432BRP | CWE-119 | TRENDnet TEW-432BRP formSetPortTr stack-based overflow |
| CVE-2026-41159 | 5.3 | 33.0 | mermaid-js | mermaid | CWE-94 | Mermaid: Improper sanitization of configuration leads to CSS injection |
| CVE-2026-44648 | 7.5 | 32.6 | SillyTavern | SillyTavern | CWE-613 | SillyTavern: Existing sessions are not invalidated after password change, all… |
| CVE-2026-45625 | 9.9 | 31.9 | getarcaneapp | arcane | CWE-862 | Arcane: Missing admin authorization on git repository endpoints allows non-ad… |
| CVE-2026-10075 | 6.9 | 31.8 | Interinfo | DreamMaker | CWE-36 | Interinfo|DreamMaker - Path Traversal |
| CVE-2026-41150 | 5.3 | 31.6 | mermaid-js | mermaid | CWE-835 | Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS |
| CVE-2026-42500 | 5.3 | 31.6 | golang.org/x/image | golang.org/x/image/bmp | — | Panic when reading out of bound palette index in golang.org/x/image/bmp |
| CVE-2026-44697 | 8.6 | 31.1 | klever-io | klever-go | CWE-409 | Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payload |
| CVE-2026-8326 | 10.0 | 30.9 | Remote Spark (https://www.remotespark.com/) | SparkView | CWE-23 | Remote Spark SparkView Path Traversal in RDP Drive Redirection leading to RCE |
| CVE-2025-11993 | 8.8 | 30.9 | sbthemes | WooCommerce Infinite Scroll and Ajax Pagination | CWE-502 | WooCommerce Infinite Scroll and Ajax Pagination <= 1.8 - Authenticated (Subsc… |
| CVE-2026-40425 | 6.9 | 30.7 | Danelec | MacGregor Voyage Data Recorder (VDR) G4e | CWE-552 | MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to E… |
| CVE-2026-44652 | 6.9 | 30.6 | SillyTavern | SillyTavern | CWE-918 | SillyTavern: SSRF vulnerability in the CORS proxy middleware |
| CVE-2026-6824 | 8.4 | 30.4 | CP Plus | CP-UNR-108F1 Hardware | CWE-79 | CP Plus 8 Ch. Network Video Recorder Cross-site Scripting |
| CVE-2026-49196 | 8.6 | 30.1 | Acer | Predator Connect W6x | CWE-77 | Predator Connect W6x: Web Interface Command Injection |
| CVE-2026-10073 | 8.7 | 28.4 | Interinfo | DreamMaker | CWE-23 | Interinfo|DreamMaker - Arbitrary File Read |
| CVE-2026-46599 | 7.5 | 28.4 | golang.org/x/image | golang.org/x/image/tiff | CWE-770 | Excessive resource consumption in PackBits decompression in golang.org/x/imag… |
| CVE-2026-46579 | 7.5 | 28.3 | Red Hat | Red Hat OpenShift Container Platform 4.12 | CWE-287 | Openshift/router: openshift/router: mtls client certificate spoofing via unst… |
| CVE-2026-45631 | 10.0 | 28.2 | Dokploy | dokploy | CWE-798 | Dokploy: Pre-Auth Admin Takeover via Hardcoded Authentication Secret |
| CVE-2026-9509 | 8.7 | 28.2 | Suprema | BioStar 2 (server) | CWE-248 | Uncaught exception vulnerability in Suprema's BioStar |
| CVE-2026-10074 | 6.9 | 27.8 | Interinfo | DreamMaker | CWE-23 | Interinfo|DreamMaker - Arbitrary File Read |
| CVE-2026-9508 | 10.0 | 27.1 | Suprema | BioStar 2 (server) | CWE-732 | Incorrect Permission Assignment for Critical Resource vulnerability in Suprem… |
| CVE-2018-25382 | 8.8 | 26.3 | Bylancer | Zechat | CWE-89 | Zechat 1.5 SQL Injection via uname Parameter |
| CVE-2018-25385 | 8.8 | 26.3 | eregistrasi-kejuaraan-silat | Registrasi Pencak Silat | CWE-89 | E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai |
| CVE-2018-25386 | 8.8 | 26.3 | Sitejo | HaPe PKH | CWE-89 | HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php |
| CVE-2018-25389 | 8.8 | 26.3 | Sitejo | HaPe PKH | CWE-89 | HaPe PKH 1.1 SQL Injection via nama_kelompok Parameter |
| CVE-2018-25390 | 8.8 | 26.3 | Sitejo | HaPe PKH | CWE-89 | HaPe PKH 1.1 SQL Injection via desa Parameter |
| CVE-2018-25394 | 8.8 | 26.3 | Kados | Kados R10 GreenBee | CWE-89 | Kados R10 GreenBee SQL Injection via update_release.php |
| CVE-2018-25395 | 8.8 | 26.3 | Kados | Kados R10 GreenBee | CWE-89 | Kados R10 GreenBee SQL Injection via update_feature.php |
| CVE-2018-25398 | 8.8 | 26.3 | Open ISES | Open ISES Project | CWE-89 | The Open ISES Project 3.30A SQL Injection via main.php |
| CVE-2018-25399 | 8.8 | 26.3 | Open ISES | Open ISES Project | CWE-89 | The Open ISES Project 3.30A SQL Injection via nearby.php |
| CVE-2018-25400 | 8.8 | 26.3 | Open ISES | Open ISES Project | CWE-89 | The Open ISES Project 3.30A SQL Injection via form_post.php |
| CVE-2018-25401 | 8.8 | 26.3 | Open ISES | Open ISES Project | CWE-89 | The Open ISES Project 3.30A SQL Injection via sever_graph.php |
| CVE-2018-25402 | 8.8 | 26.3 | Open ISES | Open ISES Project | CWE-89 | The Open ISES Project 3.30A SQL Injection via inc_types_graph.php |
| CVE-2018-25403 | 8.8 | 26.3 | Open ISES | Open ISES Project | CWE-89 | The Open ISES Project 3.30A SQL Injection via city_graph.php |
| CVE-2026-49197 | 10.0 | 26.1 | Acer | Predator Connect W6x | CWE-287 | Predator Connect W6x: Improper Authentication |
| CVE-2026-49367 | 8.8 | 26.0 | JetBrains | IntelliJ IDEA | CWE-862 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via… |
| CVE-2018-25391 | 8.7 | 26.1 | Sitejo | HaPe PKH | CWE-862 | HaPe PKH 1.1 Missing Authorization Allows Unauthenticated Record Deletion |
| CVE-2026-46527 | 8.7 | 25.6 | yhirose | cpp-httplib | CWE-476 | cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Tr… |
| CVE-2026-45352 | 7.5 | 25.6 | yhirose | cpp-httplib | CWE-20 | cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding |
| CVE-2026-44651 | 6.9 | 25.1 | SillyTavern | SillyTavern | CWE-79 | SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware |
| CVE-2026-47744 | 9.9 | 24.9 | shopperlabs | shopper | CWE-269 | Shopper: Authorization bypass and RBAC privilege escalation in team settings |
| CVE-2026-10105 | 8.7 | 24.7 | agno-agi | agno | CWE-89 | agno 2.6.5 SQL Injection via ClickHouse delete_by_metadata() |
| CVE-2026-45578 | 8.8 | 24.5 | WWBN | AVideo | CWE-78 | WWBN AVideo Live: OS command injection in on_publish.php execAsync via unesca… |
| CVE-2018-25396 | 8.7 | 24.0 | Heatmiser | Heatmiser Wifi Thermostat | CWE-256 | Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm |
| CVE-2026-47266 | 8.7 | 23.8 | verbb | formie | CWE-639 | Formie: Unauthenticated front-end submission editing can overwrite existing s… |
| CVE-2026-47179 | 7.7 | 23.3 | getarcaneapp | arcane | CWE-22 | Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Dir… |
| CVE-2026-6275 | 6.4 | 23.1 | statcounter | StatCounter – Free Real Time Visitor Stats | CWE-79 | StatCounter <= 2.1.1 - Authenticated (Author+) Stored Cross-Site Scripting vi… |
| CVE-2026-44518 | 5.3 | 23.1 | open-quantum-safe | liboqs | CWE-20 | liboqs: XMSS Buffer Overread Bug |
| CVE-2026-46344 | 5.3 | 23.1 | open-quantum-safe | liboqs | CWE-125 | liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled par… |
| CVE-2026-45149 | 7.5 | 22.5 | juliangruber | brace-expansion | CWE-400 | brace-expansion: Large numeric range defeats documented `max` DoS protection |
| CVE-2026-49372 | 7.5 | 22.4 | JetBrains | TeamCity | CWE-918 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build… |
| CVE-2026-45372 | 9.9 | 22.0 | yhirose | cpp-httplib | CWE-93 | cpp-httplib: HTTP header value percent-decoding in server-side `parse_header`… |
| CVE-2026-45312 | 9.9 | 21.9 | infiniflow | ragflow | CWE-1336 | RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote C… |
| CVE-2026-48501 | 9.1 | 21.4 | cli | cli | CWE-863 | GitHub CLI tokens leak via `gh attestation` commands |
| CVE-2026-44238 | 8.5 | 21.4 | FreePBX | security-reporting | CWE-89 | FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports |
| CVE-2026-10039 | 4.9 | 21.3 | shabti | Frontend Admin by DynamiApps | CWE-89 | Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL … |
| CVE-2026-8995 | 4.3 | 20.8 | ays-pro | Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls | CWE-200 | Poll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Informatio… |
| CVE-2026-46510 | 8.2 | 20.7 | kaspernj | form-data-objectizer | CWE-1321 | Prototype pollution in form-data-objectizer via bracket-notation form keys |
| CVE-2026-5768 | 8.8 | 20.5 | Fourth Frontier | Frontier X Android application | CWE-306 | Fourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentica… |
| CVE-2026-10068 | 6.9 | 20.3 | Shibby | Tomato | CWE-918 | Shibby Tomato SUBSCRIBE Call miniupnpd send server-side request forgery |
| CVE-2018-25392 | 7.1 | 19.7 | Talagasoft | MaxOn ERP | CWE-89 | MaxOn ERP Software 8.x-9.x SQL Injection via nomor Parameter |
| CVE-2026-9243 | 6.4 | 19.7 | posimyththemes | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | CWE-79 | The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored… |
| CVE-2026-2128 | 5.3 | 19.7 | cloudways | Breeze Cache | CWE-200 | Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to … |
| CVE-2026-44239 | 7.6 | 19.6 | FreePBX | security-reporting | CWE-98 | FreePBX: Authenticated Local File Inclusion in Dashboard Module |
| CVE-2018-25404 | 8.8 | 19.3 | Open ISES | Open ISES Project | CWE-89 | The Open ISES Project 3.30A SQL Injection via add_facnote.php |
| CVE-2026-44285 | 7.7 | 18.2 | labring | FastGPT | CWE-918 | FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API |
| CVE-2026-49201 | 10.0 | 18.1 | Acer | Wave 7 router | CWE-798 | Acer Wave 7 router: Hardcoded Cryptographic Key |
| CVE-2026-49371 | 8.2 | 18.1 | JetBrains | TeamCity | CWE-79 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was… |
| CVE-2026-45582 | 6.5 | 18.0 | czlonkowski | n8n-mcp | CWE-201 | n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-sh… |
| CVE-2026-9493 | 7.1 | 17.7 | BankPro E-Service Technology | Service Center | CWE-639 | BankPro E-Service Technology|Service Center - Insecure Direct Object Reference |
| CVE-2026-4290 | 9.1 | 17.6 | WPTravel | WP Travel Pro | CWE-862 | WP Travel Pro <= 10.6.0 - Missing Authorization to Unauthenticated Arbitrary … |
| CVE-2026-47740 | 8.1 | 17.6 | shopperlabs | shopper | CWE-285 | Shopper: Authorization bypass in multiple Livewire admin components |
| CVE-2026-49386 | 6.5 | 17.6 | JetBrains | YouTrack | CWE-639 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enu… |
| CVE-2026-49379 | 6.5 | 17.5 | JetBrains | TeamCity | CWE-522 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
| CVE-2026-45632 | 9.9 | 17.4 | Dokploy | dokploy | CWE-78 | Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution |
| CVE-2026-35674 | 8.7 | 17.0 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route |
| CVE-2026-10107 | 7.0 | 16.6 | jxxghp | MoviePilot | CWE-918 | MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint |
| CVE-2026-45577 | 6.9 | 16.5 | markmhendrickson | neotoma | CWE-288 | Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth… |
| CVE-2026-49370 | 7.5 | 16.3 | JetBrains | YouTrack | CWE-201 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible… |
| CVE-2026-48555 | 5.3 | 16.4 | spatie | laravel-medialibrary | CWE-918 | Spatie Laravel Media Library < 11.23.0 SSRF via addMediaFromUrl() |
| CVE-2026-47125 | 8.8 | 16.0 | getarcaneapp | arcane | CWE-862 | Arcane: Missing admin authorization on global variables endpoint |
| CVE-2026-7430 | 4.4 | 15.8 | saadiqbal | Post Snippets – Custom WordPress Code Snippets Customizer | CWE-79 | Post Snippets <= 4.0.19 - Authenticated (Administrator+) Stored Cross-Site Sc… |
| CVE-2026-10056 | 7.5 | 15.6 | Network Optix | Nx Witness VMS | CWE-942 | CORS misconfiguration in Nx Witness VMS allows session token exfiltration via… |
| CVE-2025-11262 | 7.2 | 15.6 | linkwhspr | Link Whisper Free | CWE-79 | Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting |
| CVE-2026-39229 | 6.5 | 15.4 | n/a | n/a | CWE-89 | Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the c… |
| CVE-2026-32905 | 8.7 | 15.1 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via… |
| CVE-2026-44287 | 6.3 | 15.2 | labring | FastGPT | CWE-94 | FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypass… |
| CVE-2026-47741 | 5.9 | 15.2 | shopperlabs | shopper | CWE-362 | Shopper: Race condition on Discount.usage_limit allows silent over-redemption |
| CVE-2026-34127 | 5.3 | 15.2 | TP-Link Systems Inc. | TL-SG108PE v5 | CWE-79 | Stored Cross-Site Scripting (XSS) via Configuration File Import on TP-Link's … |
| CVE-2026-45707 | 8.1 | 14.7 | czlonkowski | n8n-mcp | CWE-284 | n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials… |
| CVE-2026-49374 | 7.6 | 14.6 | JetBrains | TeamCity | CWE-862 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build … |
| CVE-2026-45628 | 9.6 | 14.0 | Dokploy | dokploy | CWE-20 | Dokploy: Command Injection via Unescaped Branch Fields in Deployment Pipeline |
| CVE-2026-45551 | 5.1 | 14.0 | Intermesh | groupoffice | CWE-79 | Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary… |
| CVE-2026-48527 | 8.7 | 13.8 | haxtheweb | haxcms-nodejs | CWE-79 | HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpoint |
| CVE-2026-45151 | 2.9 | 13.6 | nanomq | nanomq | CWE-476 | NanoMQ: NULL Pointer Dereference |
| CVE-2026-45043 | 9.3 | 13.6 | rustfs | rustfs | CWE-269 | RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Pare… |
| CVE-2026-42929 | 8.7 | 13.5 | Danelec | MacGregor Voyage Data Recorder (VDR) G4e | CWE-798 | MacGregor Voyage Data Recorder (VDR) G4e Use of Hard-coded Credentials |
| CVE-2026-42941 | 8.7 | 13.5 | Danelec | MacGregor Voyage Data Recorder (VDR) G4e | CWE-1392 | MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials |
| CVE-2026-42965 | 6.5 | 13.6 | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-918 | Openshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpoi… |
| CVE-2026-43917 | 5.3 | 13.4 | Dokploy | dokploy | CWE-639 | Dokploy: Cross-Organization IDOR - Multiple tRPC endpoints missing activeOrga… |
| CVE-2026-4776 | 7.1 | 13.3 | — | mautic/core | CWE-89 | An SQL injection vulnerability exists in Mautic's API contact filtering mecha… |
| CVE-2026-49375 | 6.1 | 13.1 | JetBrains | TeamCity | CWE-79 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on … |
| CVE-2026-47742 | 6.5 | 12.8 | shopperlabs | shopper | CWE-862 | Shopper: Missing authorization on Product admin Livewire sub-form components |
| CVE-2026-47745 | 6.5 | 12.8 | shopperlabs | shopper | CWE-862 | Shopper: Missing per-action authorization on PaymentMethods, Currencies and C… |
| CVE-2026-49385 | 6.5 | 12.8 | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low… |
| CVE-2026-49378 | 4.3 | 12.6 | JetBrains | TeamCity | CWE-862 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via p… |
| CVE-2026-44649 | 9.8 | 12.5 | SillyTavern | SillyTavern | CWE-290 | SillyTavern: Authentication Bypass via SSO Header Injection |
| CVE-2026-10070 | 5.1 | 12.5 | macrozheng | mall | CWE-266 | macrozheng mall Super Admin Password update improper authorization |
| CVE-2026-49376 | 6.5 | 12.3 | JetBrains | TeamCity | CWE-863 | In JetBrains TeamCity before 2026.1 insufficient username validation in the S… |
| CVE-2026-40510 | 1.0 | 12.3 | OpenSC | OpenSC | CWE-121 | OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-p… |
| CVE-2026-49195 | 8.7 | 12.2 | Acer | Predator Connect W6x | CWE-306 | Predator Connect W6x: unauthenticated Debug Service |
| CVE-2018-25384 | 5.1 | 12.1 | wikidforum | Wikidforum | CWE-79 | Wikidforum 2.20 Cross-Site Scripting via reply_text Parameter |
| CVE-2026-49381 | 4.8 | 11.9 | JetBrains | TeamCity | CWE-79 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was pos… |
| CVE-2026-6075 | 8.1 | 11.6 | dglingren | Media Library Assistant | CWE-352 | Media Library Assistant <= 3.35 - Cross-Site Request Forgery via Bulk Action … |
| CVE-2026-45626 | 6.3 | 11.5 | getarcaneapp | arcane | CWE-78 | Arcane: OS Command Injection in Volume Browser ListDirectory via path query p… |
| CVE-2026-45294 | 5.3 | 11.6 | freescout-help-desk | freescout | CWE-203 | FreeScout: User Account Enumeration via Password Reset Response Differentiation |
| CVE-2026-49198 | 8.3 | 11.2 | Acer | Predator Connect W6x | CWE-284 | Predator Connect W6x: MQTT Broker Access Control |
| CVE-2026-45609 | 6.5 | 11.1 | spring-ai-community | mcp-security | CWE-918 | mcp-security: Unvalidated URL Fetching (SSRF) |
| CVE-2026-35630 | 7.5 | 11.0 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native … |
| CVE-2026-49368 | 5.4 | 11.0 | JetBrains | YouTrack | CWE-79 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification … |
| CVE-2026-49369 | 4.3 | 10.8 | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible… |
| CVE-2026-9189 | 5.3 | 10.7 | scottpaterson | Contact Form 7 – PayPal & Stripe Add-on | CWE-345 | Contact Form 7 – PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment By… |
| CVE-2026-44237 | 7.6 | 10.3 | FreePBX | security-reporting | CWE-1390 | FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication By… |
| CVE-2026-9808 | 7.1 | 10.4 | — | mautic/core | CWE-863 | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints… |
| CVE-2026-45615 | 8.2 | 9.8 | mouse07410 | asn1c | CWE-20 | mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via … |
| CVE-2026-9714 | 6.4 | 9.8 | creaweb2b | Simple Divi Shortcode | CWE-79 | Simple Divi Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site… |
| CVE-2026-10078 | 2.7 | 9.7 | Red Hat | Red Hat Quay 3 | CWE-598 | Quay/config-tool: quay/config-tool: gitlab oauth client_secret exposed in url… |
| CVE-2026-45620 | 5.3 | 9.3 | WWBN | AVideo | CWE-204 | AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an un… |
| CVE-2026-10052 | 4.1 | 8.5 | Red Hat | Red Hat Quay 3 | CWE-918 | Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config … |
| CVE-2026-45627 | 8.2 | 8.3 | getarcaneapp | arcane | CWE-79 | Arcane: Unauthenticated reflected XSS via SVG color parameter in /api/app-ima… |
| CVE-2026-33386 | 2.3 | 8.4 | OpenSolution | QuickCMS | CWE-79 | XSS in QuickCMS |
| CVE-2026-10101 | 6.3 | 8.1 | Red Hat | Multicluster Engine for Kubernetes | CWE-201 | Assisted-service: assisted-service: infraenv status leaks referenced pull-sec… |
| CVE-2018-25383 | 8.6 | 8.0 | Commentcamarche | Free MP3 CD Ripper | CWE-121 | Free MP3 CD Ripper 2.8 Buffer Overflow SEH DEP Bypass |
| CVE-2026-49384 | 6.1 | 8.0 | JetBrains | PyCharm | CWE-79 | In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown … |
| CVE-2026-49316 | 4.1 | 7.9 | Indian Motorcycle | Scout Bobber + Tech | CWE-440 | Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft … |
| CVE-2026-10057 | 4.8 | 7.5 | ITP Technology | ITS Intelligent SCADA System | CWE-79 | ITP Technology|ITS Intelligent SCADA System - Stored Cross-Site Scripting |
| CVE-2026-10058 | 4.8 | 7.5 | ITP Technology | ITS Intelligent SCADA System | CWE-79 | ITP Technology|ITS Intelligent SCADA System - Stored Cross-Site Scripting |
| CVE-2018-25387 | 6.9 | 7.3 | Sitejo | HaPe PKH | CWE-352 | HaPe PKH 1.1 Cross-Site Request Forgery via aksi_user.php |
| CVE-2026-49324 | 4.1 | 7.2 | Indian Motorcycle | Scout Bobber + Tech | CWE-307 | Indian Scout Bobber 2025 WCM brute-force |
| CVE-2026-32906 | 2.3 | 7.1 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exe… |
| CVE-2026-9831 | 6.3 | 7.0 | Extreme Networks | Extreme Platform ONE | CWE-362 | ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentic… |
| CVE-2026-45668 | 9.3 | 6.7 | TriliumNext | Trilium | CWE-22 | Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import E… |
| CVE-2026-49380 | 6.1 | 6.8 | JetBrains | TeamCity | CWE-601 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was poss… |
| CVE-2026-42951 | 5.9 | 6.6 | Danelec | MacGregor Voyage Data Recorder (VDR) G4e | CWE-522 | MacGregor Voyage Data Recorder (VDR) G4e Insufficiently Protected Credentials |
| CVE-2026-9809 | 7.6 | 6.0 | — | mautic/core | CWE-79 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects comp… |
| CVE-2018-25397 | 6.9 | 5.8 | joeyrush | PHP-SHOP master | CWE-352 | PHP-SHOP 1.0 Cross-Site Request Forgery via users.php |
| CVE-2026-47694 | 5.4 | 5.9 | WWBN | AVideo | CWE-79 | WWBN AVideo: Stored XSS via unescaped Gallery category description |
| CVE-2026-49325 | 4.1 | 5.7 | Indian Motorcycle | Scout Bobber + Tech | CWE-693 | Indian Scout Bobber 2025 WCM voltage-based shutdown |
| CVE-2025-14042 | 6.4 | 5.6 | themesuite | Automotive Car Dealership Business WordPress Theme | CWE-79 | Automotive Car Dealership Business WordPress Theme <= 13.4.1 - Authenticated … |
| CVE-2026-36324 | 6.1 | 5.1 | n/a | n/a | CWE-79 | SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scri… |
| CVE-2026-35673 | 5.9 | 5.2 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes |
| CVE-2026-48810 | 4.3 | 5.2 | freescout-help-desk | freescout | CWE-285 | FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check |
| CVE-2026-48811 | 4.3 | 5.2 | freescout-help-desk | freescout | CWE-862 | FreeScout: Thread Deletion Bypasses Mailbox Access Revocation |
| CVE-2026-33384 | 4.8 | 5.1 | OpenSolution | QuickCMS | CWE-384 | Session Fixation in QuickCMS |
| CVE-2026-45660 | 5.4 | 4.8 | statamic | cms | CWE-918 | Statamic: Server-Side Request Forgery via Glide |
| CVE-2026-34507 | 2.3 | 4.5 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and … |
| CVE-2025-41280 | 7.5 | 4.4 | Waterfall | WF-500 | CWE-23 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) … |
| CVE-2026-9557 | 6.4 | 4.4 | — | mautic/core | CWE-918 | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus c… |
| CVE-2026-40528 | 1.0 | 4.4 | OpenSC | OpenSC | CWE-121 | OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c |
| CVE-2026-47123 | 7.5 | 4.3 | freescout-help-desk | freescout | CWE-290 | FreeScout: Agent Impersonation via Missing HMAC Verification on Notification … |
| CVE-2026-45555 | 7.8 | 4.1 | MarcelRoozekrans | roslyn-codelens-mcp | CWE-94 | Roslyn CodeLens MCP Server: Untrusted Roslyn Analyzer Execution via get_diagn… |
| CVE-2026-49317 | 1.0 | 4.1 | Indian Motorcycle | Scout Bobber + Tech | CWE-636 | Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM … |
| CVE-2026-49318 | 1.0 | 4.1 | Indian Motorcycle | Scout Bobber + Tech | CWE-636 | Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM … |
| CVE-2026-44611 | 5.9 | 4.0 | Danelec | MacGregor Voyage Data Recorder (VDR) G4e | CWE-916 | MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficie… |
| CVE-2026-44698 | 8.3 | 3.5 | home-assistant | core | CWE-94 | Home Assistant: Cross-origin iframe access token exfiltration via WebView JS … |
| CVE-2026-45619 | 6.5 | 3.5 | WWBN | AVideo | CWE-367 | AVideo CVE-2026-43884 incomplete fix - `isSSRFSafeURL()` call sites still dis… |
| CVE-2026-45580 | 5.4 | 3.5 | WWBN | AVideo | CWE-79 | WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php … |
| CVE-2026-49382 | 7.8 | 3.4 | JetBrains | IntelliJ IDEA | CWE-1336 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via temp… |
| CVE-2026-7480 | 7.3 | 3.5 | ASUS | ASUS System Control Interface | CWE-732 | An Incorrect Permission Assignment for Critical Resource vulnerability in ASU… |
| CVE-2026-9811 | 5.4 | 3.3 | — | mautic/core | CWE-79 | A stored Cross-Site Scripting (XSS) vulnerability exists in the project selec… |
| CVE-2026-4387 | 2.0 | 3.2 | StrongDM | StrongDM Desktop Application | CWE-312 | Unencrypted storage of authentication state in StrongDM Desktop Application s… |
| CVE-2026-10099 | 5.1 | 2.6 | XX-net | XX-Net | CWE-1286 | XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py |
| CVE-2026-6892 | 5.1 | 2.5 | Canon Inc. | Canon PIXUS iX6800 Series CUPS Printer Driver for macOS | CWE-59 | Improper handling of symbolic links in the installer of CUPS Printer Driver f… |
| CVE-2025-41278 | 7.5 | 2.2 | Waterfall | WF-500 | CWE-125 | Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF… |
| CVE-2026-47696 | 7.1 | 2.2 | WWBN | AVideo | CWE-345 | WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPaymen… |
| CVE-2026-45613 | 3.3 | 1.5 | rizinorg | rizin | CWE-125 | Rizin: Heap-buffer-overflow in OMF parser |
| CVE-2026-45610 | 6.5 | 1.5 | WWBN | AVideo | CWE-306 | WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF… |
| CVE-2026-49383 | 3.3 | 1.4 | JetBrains | IntelliJ IDEA | CWE-611 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser w… |
| CVE-2026-49323 | 4.1 | 1.3 | Indian Motorcycle | Scout Bobber + Tech | CWE-327 | Indian Scout Bobber 2025 WCM-to-ECM weak authentication |
| CVE-2026-49322 | 4.1 | 1.1 | Indian Motorcycle | Scout Bobber + Tech | CWE-294 | Indian Scout Bobber 2025 Infotainment-to-WCM weak authentication allows recov… |
| CVE-2026-45324 | 3.3 | 1.0 | rizinorg | rizin | CWE-415 | Rizin: Double free in cmd_search.c |
| CVE-2026-44640 | 4.5 | 0.8 | nanomq | nanomq | CWE-843 | NanoMQ: QUIC Dialer Close Type Confusion |
| CVE-2026-8070 | 7.3 | 0.5 | ASUS | Armoury Crate | CWE-732 | Incorrect permission assignment for a critical resource in Armoury Crate allo… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-05-29 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.