boxscore/security
Friday, May 29, 2026 · all times UTC← 2026-05-28 · archive · 2026-05-30 →

249 CVEs published May 29, 2026: 44 critical, 105 high, 83 medium, 16 low; 1 in KEV; 17 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 224 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published3140427010262563
KEV catalog size1670

126 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux6399657961526912720.27.8.0013+476
microsoft170490433281020378275.57.8.0045-17
google168174101203567442.38.3.0023+167
red hat4164827263400.07.2.0037+30
apple204701227193714.96.2.0034+20
canonical14140455000.05.5.0009+14
freebsd770520000.07.8.0020+7
suse220200000.08.2.0020+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco513312096861.58.6.1247+2
checkpoint660330300.06.5.0338+6
fortinet16130028350.07.9.4330-2
ivanti25010033480.08.8.8056+1
f52320007133.39.2.0996+2
ubiquiti231200400.08.8.0068+2
palo alto networks220000142100.0.6299+2
broadcom02000042100.0.19900
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache21324151204013.17.4.0064+12
gitlab7901604222.24.3.0032+7
mozilla6632101300.08.8.0042+6
drupal5511305120.05.1.0026+5
docker330300100.08.8.0022+3
github221100000.08.1.0347+2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm49491024150700.07.5.0028+49
oracle2527815404000.08.1.0027+25
progress440400900.07.5.0036+4
adobe14010075375.08.6.2776-2
veeam331200400.08.6.0040+3
solarwinds031000113100.09.8.83620
zohocorp220110000.07.1.0104+2
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology181823103000.05.6.0025+18
d-link23011026133.37.3.0059+1
hitachi energy220020000.05.7.0014+2
siemens110100100.08.7.0032+1
hikvision01000021100.01.00000
dahua000000200
qnap000000800
schneider electric000000100
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44
edimax4444027017100.07.4.0059+44
open ises4444221210000.07.1.0021+44
helmholz424203930000.07.1.0026+42
mb connect line424203930000.07.1.0026+42
totolink343402509000.08.9.0191+34
netatalk3333113910000.06.4.0030+33
nvidia333381870000.07.8.0038+33

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2008-4250.987599.9
CVE-2026-41940.979399.99.3
CVE-2026-0257.939199.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4684010.0.0073
Most disclosures (vendor)
VendorCVEs
linux641
microsoft170
google168
ibm49
concrete cms44
edimax44
open ises44
red hat44
helmholz42
mb connect line42
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google4
ivanti4
synacor4
adobe3
fortinet3
smartertools3
solarwinds3
Most-affected ecosystems
EcosystemAdvisories
Maven12
Packagist7
PyPI2
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2025-34291Langflow0
CVE-2026-0257Palo Alto Networks0
CVE-2026-0300Palo Alto Networks0
CVE-2026-20182Cisco0
CVE-2026-31431Linux0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171654
CVE-2021-27102Accellion2021-11-171654
CVE-2021-27101Accellion2021-11-171654
CVE-2021-27103Accellion2021-11-171654
CVE-2021-21017Adobe2021-11-171654
CVE-2021-28550Adobe2021-11-171654
CVE-2021-42013Apache2021-11-171654
CVE-2021-41773Apache2021-11-171654
CVE-2021-30858Apple2021-11-171654
CVE-2021-30860Apple2021-11-171654

Transactions

EXPLOIT PUBLISHEDCVE-2026-39276. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44421 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44422 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45352 (yhirose cpp-httplib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45372 (yhirose cpp-httplib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45700 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45731 (WWBN AVideo). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46337 (WWBN AVideo). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46527 (yhirose cpp-httplib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47694 (WWBN AVideo). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47696 (WWBN AVideo). Public exploit reference added.

Yesterday's Results

249 CVEs published. 25 box scores, 224 table rows — nothing truncated.

CVE-2026-0257AWAITING ENRICHMENT
Palo Alto Networks PAN-OS
  CVSS   EPSS    %ile   KEV
  —      .9391   99.8   YES
AFFECTED
  Product  Versions     Fixed
  PAN-OS   unspecified  —
TIMELINE
  May 29  Added to CISA KEV, due Jun 1
  May 29  Published
0 references · KEV due June 1, 2026
flippercode WP Maps Pro — WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1927   97.1     —
AFFECTED
  Product      Versions     Fixed
  WP Maps Pro  unspecified  —
TIMELINE
  May 16  Reserved by CNA
  May 29  Published (CNA: Wordfence)
CWE-306 · CNA: Wordfence · 2 references · NVD status: Deferred
JetBrains TeamCity — In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .1303   96.0     —
AFFECTED
  Product   Versions     Fixed
  TeamCity  unspecified  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: JetBrains)
CWE-88 · CNA: JetBrains · 1 reference · NVD status: Analyzed
TRENDnet TEW-432BRP formSetRoute command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0501   91.5     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 4 references · NVD status: Analyzed
TRENDnet TEW-432BRP formWPS command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0501   91.5     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 4 references · NVD status: Analyzed
FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0367   88.7     —
AFFECTED
  Product  Versions    Fixed
  FreeRDP  < 3.26.0 –  —
TIMELINE
  May 6   Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-122, CWE-131 · CNA: GitHub_M · 7 references · NVD status: Modified
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   69.8     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   69.8     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   69.8     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   69.8     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   69.8     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   69.8     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   69.8     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Acer Predator Connect W6x — Predator Connect W6x: RCE via MQTT
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0134   68.9     —
AFFECTED
  Product               Versions               Fixed
  Predator Connect W6x  W6x_GBL_2.00.000005 –  —
TIMELINE
  May 28  Reserved by CNA
  May 29  Published (CNA: Acer)
CWE-77 · CNA: Acer · 1 reference · NVD status: Analyzed
Dokploy: Command Injection in /docker-container-logs Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0092   57.4     —
AFFECTED
  Product  Versions     Fixed
  dokploy  <= 0.26.6 –  —
TIMELINE
  May 12  Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0088   56.2     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0088   56.2     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0088   56.2     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   H   H   H    8.5   .0088   56.2     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Libsoup: libsoup: http request smuggling via unsigned to signed conversion error
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  L  L  N    4.8   .0087   55.9     —
AFFECTED
  Product                      Versions     Fixed
  Red Hat Enterprise Linux 10  unspecified  —
  Red Hat Enterprise Linux 6   unspecified  —
  Red Hat Enterprise Linux 7   unspecified  —
  Red Hat Enterprise Linux 8   unspecified  —
  Red Hat Enterprise Linux 9   unspecified  —
TIMELINE
  Apr 14  Reserved by CNA
  May 29  Published (CNA: redhat)
CWE-444 · CNA: redhat · 4 references · NVD status: Awaiting Analysis
Dokploy: Remote Code Execution via destinationPath in Container File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0087   55.7     —
AFFECTED
  Product  Versions     Fixed
  dokploy  <= 0.29.1 –  —
TIMELINE
  May 12  Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-77 · CNA: GitHub_M · 1 reference · NVD status: Deferred
SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  L  N    8.5   .0087   55.7     —
AFFECTED
  Product      Versions    Fixed
  SillyTavern  < 1.18.0 –  —
TIMELINE
  May 13  Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · 1 reference · NVD status: Deferred
TRENDnet TEW-432BRP formWPS stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0085   55.3     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 4 references · NVD status: Analyzed
Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0084   54.9     —
AFFECTED
  Product  Versions     Fixed
  dokploy  <= 0.29.0 –  —
TIMELINE
  May 12  Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 1 reference · NVD status: Deferred
TRENDnet TEW-432BRP formSetRoute stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0083   54.7     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 4 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-392767.253.0n/an/aCWE-22The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerab…
CVE-2026-456309.052.4DokploydokployCWE-78Dokploy: Authenticated Remote Code Execution via Command Injection in updateT…
CVE-2026-456299.952.2DokploydokployCWE-78Dokploy: Authenticated Remote Code Execution via Command Injection in /listen…
CVE-2026-493774.350.0JetBrainsTeamCityCWE-526In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default…
CVE-2026-449629.949.7WebProsPleskCWE-643Plesk contains an XPath injection vulnerability in the APS Application Catalo…
CVE-2026-456619.948.6DokploydokployCWE-22Dokploy: Remote Code Execution through Path Traversal
CVE-2026-457007.747.2FreeRDPFreeRDPCWE-787Heap-buffer-overflow write in planar bitmap decoder
CVE-2026-53869.147.1KMWKM-IP521CWE-620KMW CCTV Security Cameras Unverified Password Change
CVE-2026-90519.347.0NISystemLink EnterpriseCWE-306Authentication Bypass Vulnerability in NI SystemLink Enterprise
CVE-2026-100429.246.9zyddnysmanga-image-translatorCWE-502manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model
CVE-2026-95599.945.1mautic/coreCWE-22A path traversal vulnerability exists in the campaign import feature of Mauti…
CVE-2026-95589.944.5mautic/coreCWE-1336A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's them…
CVE-2026-446509.144.3SillyTavernSillyTavernCWE-22SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Pa…
CVE-2018-253937.144.2NavigatecmsNavigate CMSCWE-22Navigate CMS 2.8.5 Path Traversal via navigate_download.php
CVE-2026-463848.742.3iskorotkovavroCWE-190iskorotkov/avro: Integer Overflow in Avro Decoder
CVE-2018-253888.741.8SitejoHaPe PKHCWE-434HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php
CVE-2026-4920010.041.7AcerWave 7 routerCWE-532Acer Wave 7 router: Broken Access Control
CVE-2026-101088.741.4hanxixiaomusicCWE-22xiaomusic 0.5.7 Path Traversal via GET /music endpoint
CVE-2026-36559.841.2glboyOTP Login With Phone Number, OTP VerificationCWE-287OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Aut…
CVE-2026-100719.341.0InterinfoDreamMakerCWE-434Interinfo|DreamMaker - Arbitrary File Upload
CVE-2026-444218.841.0FreeRDPFreeRDPCWE-122FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle vali…
CVE-2025-412817.540.9WaterfallWF-500CWE-78Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special …
CVE-2026-463858.740.8iskorotkovavroCWE-400iskorotkov/avro: CPU Exhaustion in Avro Decoder
CVE-2026-456979.839.1verbbformieCWE-94Formie: Pre-authenticated server-side template injection in Hidden fields
CVE-2026-392927.338.8n/an/aCWE-434Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload v…
CVE-2026-457316.938.6WWBNAVideoCWE-22WWBN AVideo: Authenticated Arbitrary File Read in view/update.php
CVE-2026-100728.637.8InterinfoDreamMakerCWE-434Interinfo|DreamMaker - Arbitrary File Upload
CVE-2026-493667.837.7JetBrainsIntelliJ IDEACWE-78In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via…
CVE-2026-463376.937.8WWBNAVideoCWE-22WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view…
CVE-2026-485578.736.6spatielaravel-medialibraryCWE-184Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via Fil…
CVE-2026-100658.736.5ShibbyTomatoCWE-119Shibby Tomato tomatodata.cgi get_ups_field stack-based overflow
CVE-2026-100668.736.5ShibbyTomatoCWE-119Shibby Tomato UPS Service tomatoups.cgi sub_9068 stack-based overflow
CVE-2026-100678.736.5ShibbyTomatoCWE-119Shibby Tomato multimon.cgi sub_90F0 stack-based overflow
CVE-2026-100698.736.5ShibbyTomatoCWE-400Shibby Tomato miniupnpd resource consumption
CVE-2025-412688.836.4WaterfallWF-500CWE-23Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Admi…
CVE-2025-412718.736.2WaterfallWF-500CWE-23Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Cons…
CVE-2026-444228.835.9FreeRDPFreeRDPCWE-415FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and typ…
CVE-2026-463769.335.4FreePBXsecurity-reportingCWE-798FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreeP…
CVE-2026-77869.834.6Jinan USR IOT Technology Limited (PUSR)USR-W610 RS232/485 to Wi-Fi/Ethernet ConverterCWE-798Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet …
CVE-2025-127145.334.2rankmathRank Math SEO – AI SEO Tools to Dominate SEO RankingsCWE-862Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Au…
CVE-2025-412739.333.9WaterfallWF-500CWE-288Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alt…
CVE-2026-100642.133.0TRENDnetTEW-432BRPCWE-119TRENDnet TEW-432BRP formSetPortTr stack-based overflow
CVE-2026-411595.333.0mermaid-jsmermaidCWE-94Mermaid: Improper sanitization of configuration leads to CSS injection
CVE-2026-446487.532.6SillyTavernSillyTavernCWE-613SillyTavern: Existing sessions are not invalidated after password change, all…
CVE-2026-456259.931.9getarcaneapparcaneCWE-862Arcane: Missing admin authorization on git repository endpoints allows non-ad…
CVE-2026-100756.931.8InterinfoDreamMakerCWE-36Interinfo|DreamMaker - Path Traversal
CVE-2026-411505.331.6mermaid-jsmermaidCWE-835Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS
CVE-2026-425005.331.6golang.org/x/imagegolang.org/x/image/bmpPanic when reading out of bound palette index in golang.org/x/image/bmp
CVE-2026-446978.631.1klever-ioklever-goCWE-409Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payload
CVE-2026-832610.030.9Remote Spark (https://www.remotespark.com/)SparkViewCWE-23Remote Spark SparkView Path Traversal in RDP Drive Redirection leading to RCE
CVE-2025-119938.830.9sbthemesWooCommerce Infinite Scroll and Ajax PaginationCWE-502WooCommerce Infinite Scroll and Ajax Pagination <= 1.8 - Authenticated (Subsc…
CVE-2026-404256.930.7DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-552MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to E…
CVE-2026-446526.930.6SillyTavernSillyTavernCWE-918SillyTavern: SSRF vulnerability in the CORS proxy middleware
CVE-2026-68248.430.4CP PlusCP-UNR-108F1 HardwareCWE-79CP Plus 8 Ch. Network Video Recorder Cross-site Scripting
CVE-2026-491968.630.1AcerPredator Connect W6xCWE-77Predator Connect W6x: Web Interface Command Injection
CVE-2026-100738.728.4InterinfoDreamMakerCWE-23Interinfo|DreamMaker - Arbitrary File Read
CVE-2026-465997.528.4golang.org/x/imagegolang.org/x/image/tiffCWE-770Excessive resource consumption in PackBits decompression in golang.org/x/imag…
CVE-2026-465797.528.3Red HatRed Hat OpenShift Container Platform 4.12CWE-287Openshift/router: openshift/router: mtls client certificate spoofing via unst…
CVE-2026-4563110.028.2DokploydokployCWE-798Dokploy: Pre-Auth Admin Takeover via Hardcoded Authentication Secret
CVE-2026-95098.728.2SupremaBioStar 2 (server)CWE-248Uncaught exception vulnerability in Suprema's BioStar
CVE-2026-100746.927.8InterinfoDreamMakerCWE-23Interinfo|DreamMaker - Arbitrary File Read
CVE-2026-950810.027.1SupremaBioStar 2 (server)CWE-732Incorrect Permission Assignment for Critical Resource vulnerability in Suprem…
CVE-2018-253828.826.3BylancerZechatCWE-89Zechat 1.5 SQL Injection via uname Parameter
CVE-2018-253858.826.3eregistrasi-kejuaraan-silatRegistrasi Pencak SilatCWE-89E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai
CVE-2018-253868.826.3SitejoHaPe PKHCWE-89HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php
CVE-2018-253898.826.3SitejoHaPe PKHCWE-89HaPe PKH 1.1 SQL Injection via nama_kelompok Parameter
CVE-2018-253908.826.3SitejoHaPe PKHCWE-89HaPe PKH 1.1 SQL Injection via desa Parameter
CVE-2018-253948.826.3KadosKados R10 GreenBeeCWE-89Kados R10 GreenBee SQL Injection via update_release.php
CVE-2018-253958.826.3KadosKados R10 GreenBeeCWE-89Kados R10 GreenBee SQL Injection via update_feature.php
CVE-2018-253988.826.3Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via main.php
CVE-2018-253998.826.3Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via nearby.php
CVE-2018-254008.826.3Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via form_post.php
CVE-2018-254018.826.3Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via sever_graph.php
CVE-2018-254028.826.3Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via inc_types_graph.php
CVE-2018-254038.826.3Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via city_graph.php
CVE-2026-4919710.026.1AcerPredator Connect W6xCWE-287Predator Connect W6x: Improper Authentication
CVE-2026-493678.826.0JetBrainsIntelliJ IDEACWE-862In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via…
CVE-2018-253918.726.1SitejoHaPe PKHCWE-862HaPe PKH 1.1 Missing Authorization Allows Unauthenticated Record Deletion
CVE-2026-465278.725.6yhirosecpp-httplibCWE-476cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Tr…
CVE-2026-453527.525.6yhirosecpp-httplibCWE-20cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding
CVE-2026-446516.925.1SillyTavernSillyTavernCWE-79SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware
CVE-2026-477449.924.9shopperlabsshopperCWE-269Shopper: Authorization bypass and RBAC privilege escalation in team settings
CVE-2026-101058.724.7agno-agiagnoCWE-89agno 2.6.5 SQL Injection via ClickHouse delete_by_metadata()
CVE-2026-455788.824.5WWBNAVideoCWE-78WWBN AVideo Live: OS command injection in on_publish.php execAsync via unesca…
CVE-2018-253968.724.0HeatmiserHeatmiser Wifi ThermostatCWE-256Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm
CVE-2026-472668.723.8verbbformieCWE-639Formie: Unauthenticated front-end submission editing can overwrite existing s…
CVE-2026-471797.723.3getarcaneapparcaneCWE-22Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Dir…
CVE-2026-62756.423.1statcounterStatCounter – Free Real Time Visitor StatsCWE-79StatCounter <= 2.1.1 - Authenticated (Author+) Stored Cross-Site Scripting vi…
CVE-2026-445185.323.1open-quantum-safeliboqsCWE-20liboqs: XMSS Buffer Overread Bug
CVE-2026-463445.323.1open-quantum-safeliboqsCWE-125liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled par…
CVE-2026-451497.522.5juliangruberbrace-expansionCWE-400brace-expansion: Large numeric range defeats documented `max` DoS protection
CVE-2026-493727.522.4JetBrainsTeamCityCWE-918In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build…
CVE-2026-453729.922.0yhirosecpp-httplibCWE-93cpp-httplib: HTTP header value percent-decoding in server-side `parse_header`…
CVE-2026-453129.921.9infiniflowragflowCWE-1336RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote C…
CVE-2026-485019.121.4clicliCWE-863GitHub CLI tokens leak via `gh attestation` commands
CVE-2026-442388.521.4FreePBXsecurity-reportingCWE-89FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports
CVE-2026-100394.921.3shabtiFrontend Admin by DynamiAppsCWE-89Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL …
CVE-2026-89954.320.8ays-proPoll Maker by AYS – Versus Polls, Anonymous Polls, Image PollsCWE-200Poll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Informatio…
CVE-2026-465108.220.7kaspernjform-data-objectizerCWE-1321Prototype pollution in form-data-objectizer via bracket-notation form keys
CVE-2026-57688.820.5Fourth FrontierFrontier X Android applicationCWE-306Fourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentica…
CVE-2026-100686.920.3ShibbyTomatoCWE-918Shibby Tomato SUBSCRIBE Call miniupnpd send server-side request forgery
CVE-2018-253927.119.7TalagasoftMaxOn ERPCWE-89MaxOn ERP Software 8.x-9.x SQL Injection via nomor Parameter
CVE-2026-92436.419.7posimyththemesThe Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerceCWE-79The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored…
CVE-2026-21285.319.7cloudwaysBreeze CacheCWE-200Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to …
CVE-2026-442397.619.6FreePBXsecurity-reportingCWE-98FreePBX: Authenticated Local File Inclusion in Dashboard Module
CVE-2018-254048.819.3Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via add_facnote.php
CVE-2026-442857.718.2labringFastGPTCWE-918FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API
CVE-2026-4920110.018.1AcerWave 7 routerCWE-798Acer Wave 7 router: Hardcoded Cryptographic Key
CVE-2026-493718.218.1JetBrainsTeamCityCWE-79In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was…
CVE-2026-455826.518.0czlonkowskin8n-mcpCWE-201n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-sh…
CVE-2026-94937.117.7BankPro E-Service TechnologyService CenterCWE-639BankPro E-Service Technology|Service Center - Insecure Direct Object Reference
CVE-2026-42909.117.6WPTravelWP Travel ProCWE-862WP Travel Pro <= 10.6.0 - Missing Authorization to Unauthenticated Arbitrary …
CVE-2026-477408.117.6shopperlabsshopperCWE-285Shopper: Authorization bypass in multiple Livewire admin components
CVE-2026-493866.517.6JetBrainsYouTrackCWE-639In JetBrains YouTrack before 2026.1.13570 improper access control allowed enu…
CVE-2026-493796.517.5JetBrainsTeamCityCWE-522In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
CVE-2026-456329.917.4DokploydokployCWE-78Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution
CVE-2026-356748.717.0OpenClawOpenClawCWE-863OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
CVE-2026-101077.016.6jxxghpMoviePilotCWE-918MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint
CVE-2026-455776.916.5markmhendricksonneotomaCWE-288Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth…
CVE-2026-493707.516.3JetBrainsYouTrackCWE-201In JetBrains YouTrack before 2026.1.13162 information disclosure was possible…
CVE-2026-485555.316.4spatielaravel-medialibraryCWE-918Spatie Laravel Media Library < 11.23.0 SSRF via addMediaFromUrl()
CVE-2026-471258.816.0getarcaneapparcaneCWE-862Arcane: Missing admin authorization on global variables endpoint
CVE-2026-74304.415.8saadiqbalPost Snippets – Custom WordPress Code Snippets CustomizerCWE-79Post Snippets <= 4.0.19 - Authenticated (Administrator+) Stored Cross-Site Sc…
CVE-2026-100567.515.6Network OptixNx Witness VMSCWE-942CORS misconfiguration in Nx Witness VMS allows session token exfiltration via…
CVE-2025-112627.215.6linkwhsprLink Whisper FreeCWE-79Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-392296.515.4n/an/aCWE-89Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the c…
CVE-2026-329058.715.1OpenClawOpenClawCWE-862OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via…
CVE-2026-442876.315.2labringFastGPTCWE-94FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypass…
CVE-2026-477415.915.2shopperlabsshopperCWE-362Shopper: Race condition on Discount.usage_limit allows silent over-redemption
CVE-2026-341275.315.2TP-Link Systems Inc.TL-SG108PE v5CWE-79Stored Cross-Site Scripting (XSS) via Configuration File Import on TP-Link's …
CVE-2026-457078.114.7czlonkowskin8n-mcpCWE-284n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials…
CVE-2026-493747.614.6JetBrainsTeamCityCWE-862In JetBrains TeamCity before 2026.1 improper permission checks exposed build …
CVE-2026-456289.614.0DokploydokployCWE-20Dokploy: Command Injection via Unescaped Branch Fields in Deployment Pipeline
CVE-2026-455515.114.0IntermeshgroupofficeCWE-79Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary…
CVE-2026-485278.713.8haxthewebhaxcms-nodejsCWE-79HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpoint
CVE-2026-451512.913.6nanomqnanomqCWE-476NanoMQ: NULL Pointer Dereference
CVE-2026-450439.313.6rustfsrustfsCWE-269RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Pare…
CVE-2026-429298.713.5DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-798MacGregor Voyage Data Recorder (VDR) G4e Use of Hard-coded Credentials
CVE-2026-429418.713.5DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-1392MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials
CVE-2026-429656.513.6Red HatRed Hat OpenShift Container Platform 4CWE-918Openshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpoi…
CVE-2026-439175.313.4DokploydokployCWE-639Dokploy: Cross-Organization IDOR - Multiple tRPC endpoints missing activeOrga…
CVE-2026-47767.113.3mautic/coreCWE-89An SQL injection vulnerability exists in Mautic's API contact filtering mecha…
CVE-2026-493756.113.1JetBrainsTeamCityCWE-79In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on …
CVE-2026-477426.512.8shopperlabsshopperCWE-862Shopper: Missing authorization on Product admin Livewire sub-form components
CVE-2026-477456.512.8shopperlabsshopperCWE-862Shopper: Missing per-action authorization on PaymentMethods, Currencies and C…
CVE-2026-493856.512.8JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.1.13570 improper access control allowed low…
CVE-2026-493784.312.6JetBrainsTeamCityCWE-862In JetBrains TeamCity before 2026.1 credentials parameters were exposed via p…
CVE-2026-446499.812.5SillyTavernSillyTavernCWE-290SillyTavern: Authentication Bypass via SSO Header Injection
CVE-2026-100705.112.5macrozhengmallCWE-266macrozheng mall Super Admin Password update improper authorization
CVE-2026-493766.512.3JetBrainsTeamCityCWE-863In JetBrains TeamCity before 2026.1 insufficient username validation in the S…
CVE-2026-405101.012.3OpenSCOpenSCCWE-121OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-p…
CVE-2026-491958.712.2AcerPredator Connect W6xCWE-306Predator Connect W6x: unauthenticated Debug Service
CVE-2018-253845.112.1wikidforumWikidforumCWE-79Wikidforum 2.20 Cross-Site Scripting via reply_text Parameter
CVE-2026-493814.811.9JetBrainsTeamCityCWE-79In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was pos…
CVE-2026-60758.111.6dglingrenMedia Library AssistantCWE-352Media Library Assistant <= 3.35 - Cross-Site Request Forgery via Bulk Action …
CVE-2026-456266.311.5getarcaneapparcaneCWE-78Arcane: OS Command Injection in Volume Browser ListDirectory via path query p…
CVE-2026-452945.311.6freescout-help-deskfreescoutCWE-203FreeScout: User Account Enumeration via Password Reset Response Differentiation
CVE-2026-491988.311.2AcerPredator Connect W6xCWE-284Predator Connect W6x: MQTT Broker Access Control
CVE-2026-456096.511.1spring-ai-communitymcp-securityCWE-918mcp-security: Unvalidated URL Fetching (SSRF)
CVE-2026-356307.511.0OpenClawOpenClawCWE-862OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native …
CVE-2026-493685.411.0JetBrainsYouTrackCWE-79In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification …
CVE-2026-493694.310.8JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2026.1.13162 information disclosure was possible…
CVE-2026-91895.310.7scottpatersonContact Form 7 – PayPal & Stripe Add-onCWE-345Contact Form 7 – PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment By…
CVE-2026-442377.610.3FreePBXsecurity-reportingCWE-1390FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication By…
CVE-2026-98087.110.4mautic/coreCWE-863An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints…
CVE-2026-456158.29.8mouse07410asn1cCWE-20mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via …
CVE-2026-97146.49.8creaweb2bSimple Divi ShortcodeCWE-79Simple Divi Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site…
CVE-2026-100782.79.7Red HatRed Hat Quay 3CWE-598Quay/config-tool: quay/config-tool: gitlab oauth client_secret exposed in url…
CVE-2026-456205.39.3WWBNAVideoCWE-204AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an un…
CVE-2026-100524.18.5Red HatRed Hat Quay 3CWE-918Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config …
CVE-2026-456278.28.3getarcaneapparcaneCWE-79Arcane: Unauthenticated reflected XSS via SVG color parameter in /api/app-ima…
CVE-2026-333862.38.4OpenSolutionQuickCMSCWE-79XSS in QuickCMS
CVE-2026-101016.38.1Red HatMulticluster Engine for KubernetesCWE-201Assisted-service: assisted-service: infraenv status leaks referenced pull-sec…
CVE-2018-253838.68.0CommentcamarcheFree MP3 CD RipperCWE-121Free MP3 CD Ripper 2.8 Buffer Overflow SEH DEP Bypass
CVE-2026-493846.18.0JetBrainsPyCharmCWE-79In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown …
CVE-2026-493164.17.9Indian MotorcycleScout Bobber + TechCWE-440Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft …
CVE-2026-100574.87.5ITP TechnologyITS Intelligent SCADA SystemCWE-79ITP Technology|ITS Intelligent SCADA System - Stored Cross-Site Scripting
CVE-2026-100584.87.5ITP TechnologyITS Intelligent SCADA SystemCWE-79ITP Technology|ITS Intelligent SCADA System - Stored Cross-Site Scripting
CVE-2018-253876.97.3SitejoHaPe PKHCWE-352HaPe PKH 1.1 Cross-Site Request Forgery via aksi_user.php
CVE-2026-493244.17.2Indian MotorcycleScout Bobber + TechCWE-307Indian Scout Bobber 2025 WCM brute-force
CVE-2026-329062.37.1OpenClawOpenClawCWE-863OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exe…
CVE-2026-98316.37.0Extreme NetworksExtreme Platform ONECWE-362ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentic…
CVE-2026-456689.36.7TriliumNextTriliumCWE-22Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import E…
CVE-2026-493806.16.8JetBrainsTeamCityCWE-601In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was poss…
CVE-2026-429515.96.6DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-522MacGregor Voyage Data Recorder (VDR) G4e Insufficiently Protected Credentials
CVE-2026-98097.66.0mautic/coreCWE-79A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects comp…
CVE-2018-253976.95.8joeyrushPHP-SHOP masterCWE-352PHP-SHOP 1.0 Cross-Site Request Forgery via users.php
CVE-2026-476945.45.9WWBNAVideoCWE-79WWBN AVideo: Stored XSS via unescaped Gallery category description
CVE-2026-493254.15.7Indian MotorcycleScout Bobber + TechCWE-693Indian Scout Bobber 2025 WCM voltage-based shutdown
CVE-2025-140426.45.6themesuiteAutomotive Car Dealership Business WordPress ThemeCWE-79Automotive Car Dealership Business WordPress Theme <= 13.4.1 - Authenticated …
CVE-2026-363246.15.1n/an/aCWE-79SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scri…
CVE-2026-356735.95.2OpenClawOpenClawCWE-863OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes
CVE-2026-488104.35.2freescout-help-deskfreescoutCWE-285FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check
CVE-2026-488114.35.2freescout-help-deskfreescoutCWE-862FreeScout: Thread Deletion Bypasses Mailbox Access Revocation
CVE-2026-333844.85.1OpenSolutionQuickCMSCWE-384Session Fixation in QuickCMS
CVE-2026-456605.44.8statamiccmsCWE-918Statamic: Server-Side Request Forgery via Glide
CVE-2026-345072.34.5OpenClawOpenClawCWE-863OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and …
CVE-2025-412807.54.4WaterfallWF-500CWE-23Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) …
CVE-2026-95576.44.4mautic/coreCWE-918A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus c…
CVE-2026-405281.04.4OpenSCOpenSCCWE-121OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c
CVE-2026-471237.54.3freescout-help-deskfreescoutCWE-290FreeScout: Agent Impersonation via Missing HMAC Verification on Notification …
CVE-2026-455557.84.1MarcelRoozekransroslyn-codelens-mcpCWE-94Roslyn CodeLens MCP Server: Untrusted Roslyn Analyzer Execution via get_diagn…
CVE-2026-493171.04.1Indian MotorcycleScout Bobber + TechCWE-636Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM …
CVE-2026-493181.04.1Indian MotorcycleScout Bobber + TechCWE-636Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM …
CVE-2026-446115.94.0DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-916MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficie…
CVE-2026-446988.33.5home-assistantcoreCWE-94Home Assistant: Cross-origin iframe access token exfiltration via WebView JS …
CVE-2026-456196.53.5WWBNAVideoCWE-367AVideo CVE-2026-43884 incomplete fix - `isSSRFSafeURL()` call sites still dis…
CVE-2026-455805.43.5WWBNAVideoCWE-79WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php …
CVE-2026-493827.83.4JetBrainsIntelliJ IDEACWE-1336In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via temp…
CVE-2026-74807.33.5ASUSASUS System Control InterfaceCWE-732An Incorrect Permission Assignment for Critical Resource vulnerability in ASU…
CVE-2026-98115.43.3mautic/coreCWE-79A stored Cross-Site Scripting (XSS) vulnerability exists in the project selec…
CVE-2026-43872.03.2StrongDMStrongDM Desktop ApplicationCWE-312Unencrypted storage of authentication state in StrongDM Desktop Application s…
CVE-2026-100995.12.6XX-netXX-NetCWE-1286XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py
CVE-2026-68925.12.5Canon Inc.Canon PIXUS iX6800 Series CUPS Printer Driver for macOSCWE-59Improper handling of symbolic links in the installer of CUPS Printer Driver f…
CVE-2025-412787.52.2WaterfallWF-500CWE-125Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF…
CVE-2026-476967.12.2WWBNAVideoCWE-345WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPaymen…
CVE-2026-456133.31.5rizinorgrizinCWE-125Rizin: Heap-buffer-overflow in OMF parser
CVE-2026-456106.51.5WWBNAVideoCWE-306WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF…
CVE-2026-493833.31.4JetBrainsIntelliJ IDEACWE-611In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser w…
CVE-2026-493234.11.3Indian MotorcycleScout Bobber + TechCWE-327Indian Scout Bobber 2025 WCM-to-ECM weak authentication
CVE-2026-493224.11.1Indian MotorcycleScout Bobber + TechCWE-294Indian Scout Bobber 2025 Infotainment-to-WCM weak authentication allows recov…
CVE-2026-453243.31.0rizinorgrizinCWE-415Rizin: Double free in cmd_search.c
CVE-2026-446404.50.8nanomqnanomqCWE-843NanoMQ: QUIC Dialer Close Type Confusion
CVE-2026-80707.30.5ASUSArmoury CrateCWE-732Incorrect permission assignment for a critical resource in Armoury Crate allo…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-29 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.