CVSS EPSS %ile KEV — .4997 98.8 YES
AFFECTED Product Versions Fixed WebLogic Server unspecified —
TIMELINE Jun 1 Added to CISA KEV, due Jun 4 Jun 1 Published
377 CVEs published June 1, 2026: 22 critical, 136 high, 144 medium, 74 low; 1 in KEV; 15 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 352 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 377 | 4749 | 1026 | 2563 |
| KEV catalog size | 1670 | |||
177 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1 | 967 | 79 | 617 | 269 | 1 | 27 | 2 | 0.2 | 7.8 | .0013 | -60 |
| microsoft | 1 | 491 | 43 | 329 | 102 | 0 | 378 | 27 | 5.5 | 7.8 | .0045 | +1 |
| 60 | 234 | 11 | 148 | 61 | 11 | 74 | 4 | 1.7 | 8.0 | .0021 | +60 | |
| red hat | 4 | 68 | 8 | 29 | 27 | 4 | 4 | 0 | 0.0 | 7.2 | .0036 | +4 |
| apple | 0 | 47 | 0 | 12 | 27 | 1 | 93 | 7 | 14.9 | 6.2 | .0034 | 0 |
| canonical | 0 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | 0 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| suse | 0 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.2 | .0020 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 0 | 13 | 3 | 1 | 2 | 0 | 96 | 8 | 61.5 | 8.6 | .1247 | 0 |
| ivanti | 1 | 6 | 0 | 2 | 0 | 0 | 33 | 4 | 66.7 | 8.8 | .5751 | +1 |
| checkpoint | 0 | 6 | 0 | 3 | 3 | 0 | 3 | 0 | 0.0 | 6.5 | .0338 | 0 |
| fortinet | 0 | 6 | 1 | 3 | 0 | 0 | 28 | 3 | 50.0 | 7.9 | .4330 | 0 |
| f5 | 0 | 3 | 2 | 0 | 0 | 0 | 7 | 1 | 33.3 | 9.2 | .0996 | 0 |
| ubiquiti | 0 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.8 | .0068 | 0 |
| broadcom | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .1990 | 0 |
| palo alto networks | 0 | 2 | 0 | 0 | 0 | 0 | 14 | 2 | 100.0 | — | .6299 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 28 | 60 | 6 | 26 | 25 | 2 | 40 | 1 | 1.7 | 7.2 | .0057 | +28 |
| gitlab | 0 | 9 | 0 | 1 | 6 | 0 | 4 | 2 | 22.2 | 4.3 | .0032 | 0 |
| mozilla | 2 | 8 | 3 | 2 | 3 | 0 | 13 | 0 | 0.0 | 7.7 | .0035 | +2 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| docker | 0 | 3 | 0 | 3 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0022 | 0 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ibm | 5 | 54 | 13 | 26 | 15 | 0 | 7 | 0 | 0.0 | 7.5 | .0031 | +5 |
| oracle | 1 | 28 | 8 | 15 | 4 | 0 | 40 | 1 | 3.6 | 8.1 | .0027 | +1 |
| adobe | 0 | 4 | 0 | 1 | 0 | 0 | 75 | 3 | 75.0 | 8.6 | .2776 | 0 |
| progress | 0 | 4 | 0 | 4 | 0 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | 0 |
| solarwinds | 0 | 3 | 1 | 0 | 0 | 0 | 11 | 3 | 100.0 | 9.8 | .8362 | 0 |
| veeam | 0 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.6 | .0040 | 0 |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 18 | 2 | 3 | 10 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | 0 |
| d-link | 2 | 5 | 0 | 3 | 1 | 0 | 26 | 1 | 20.0 | 7.4 | .0059 | +2 |
| hitachi energy | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | 0 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| siemens | 0 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| edimax | 0 | 51 | 0 | 32 | 0 | 19 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| concrete cms | 0 | 44 | 1 | 9 | 13 | 21 | 0 | 0 | 0.0 | 5.7 | .0015 | 0 |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | 0 |
| helmholz | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| mb connect line | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| totolink | 0 | 35 | 0 | 26 | 0 | 9 | 0 | 0 | 0.0 | 8.9 | .0191 | 0 |
| sourcecodester | 12 | 34 | 0 | 0 | 11 | 23 | 0 | 0 | 0.0 | 2.1 | .0025 | +12 |
| netatalk | 0 | 33 | 1 | 13 | 9 | 10 | 0 | 0 | 0.0 | 6.4 | .0030 | 0 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2026-43284 | .9324 | 99.8 | 8.8 |
| CVE-2026-43500 | .9285 | 99.8 | 7.8 |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2026-42208 | .8942 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2009-3459 | .8658 | 99.7 | — |
| CVE-2025-34291 | .8384 | 99.7 | — |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-43997 | 10.0 | .0098 | |
| CVE-2026-42826 | 10.0 | .0084 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-44005 | 10.0 | .0083 | |
| CVE-2026-44006 | 10.0 | .0081 | |
| CVE-2026-46840 | 10.0 | .0073 |
| Vendor | CVEs |
|---|---|
| linux | 580 |
| 228 | |
| microsoft | 171 |
| ibm | 54 |
| edimax | 51 |
| apache | 49 |
| red hat | 45 |
| concrete cms | 44 |
| open ises | 44 |
| helmholz | 42 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 8 |
| apple | 7 |
| 4 | |
| ivanti | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| smartertools | 3 |
| solarwinds | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 22 |
| Packagist | 7 |
| PyPI | 3 |
| crates.io | 2 |
| npm | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE-2026-0300 | Palo Alto Networks | 0 |
| CVE-2026-20182 | Cisco | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1657 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1657 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1657 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1657 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1657 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1657 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1657 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1657 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1657 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1657 |
EXPLOIT PUBLISHED — CVE-2024-40646 (vertex-app vertex). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-22872 (projectcapsule capsule). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-30963 (projectcapsule capsule). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37226. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37228. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37229. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37230. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37231. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37233. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37234. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37235. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44211 (cline). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45286 (nextcloud security-advisories). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46243 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49121 (ROCm aiter). Public exploit reference added.
377 CVEs published. 25 box scores, 352 table rows — nothing truncated.
CVSS EPSS %ile KEV — .4997 98.8 YES
AFFECTED Product Versions Fixed WebLogic Server unspecified —
TIMELINE Jun 1 Added to CISA KEV, due Jun 4 Jun 1 Published
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .2447 97.7 —
AFFECTED Product Versions Fixed poly_trio_8300 unspecified — poly_trio_8500 unspecified — poly_trio_8800 unspecified —
TIMELINE Jan 9 Reserved by CNA Jun 1 Published (CNA: hp)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0216 80.7 —
AFFECTED Product Versions Fixed Apache Solr 9.4.0 – —
TIMELINE May 7 Reserved by CNA Jun 1 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0144 70.9 —
AFFECTED Product Versions Fixed Neurons for ITSM (On-Premises) unspecified 2025.4 Patch 1 Neurons for ITSM (Cloud) unspecified 2026.1 Patch 9
TIMELINE May 26 Reserved by CNA Jun 1 Published (CNA: ivanti)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0137 69.5 —
AFFECTED Product Versions Fixed php-censor 2.1.0 – —
TIMELINE May 31 Reserved by CNA Jun 1 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0134 68.8 —
AFFECTED Product Versions Fixed chatgpt-on-wechat 2.0.0 – 2.0.9
TIMELINE May 31 Reserved by CNA Jun 1 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0134 68.8 —
AFFECTED Product Versions Fixed GoClaw 3.11.0 – —
TIMELINE May 31 Reserved by CNA Jun 1 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L L N 6.1 .0111 63.1 —
AFFECTED Product Versions Fixed Apache ActiveMQ unspecified — Apache ActiveMQ Web unspecified —
TIMELINE Apr 25 Reserved by CNA Jun 1 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0110 63.0 —
AFFECTED Product Versions Fixed aiter unspecified —
TIMELINE May 27 Reserved by CNA Jun 1 Public exploit reference published Jun 1 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0109 62.5 —
AFFECTED Product Versions Fixed wezterm-mcp 0.1.0 – —
TIMELINE May 31 Reserved by CNA Jun 1 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0092 57.4 —
AFFECTED Product Versions Fixed Arm Whois 3.11 – —
TIMELINE May 31 Reserved by CNA Jun 1 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0074 51.5 —
AFFECTED Product Versions Fixed OTRS 7.0.x – — ((OTRS)) Community Edition 6.x – —
TIMELINE May 21 Reserved by CNA Jun 1 Published (CNA: OTRS)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P H H H 9.4 .0072 50.9 —
AFFECTED Product Versions Fixed Web Signer 2.0.3 – 2.5.5
TIMELINE May 19 Reserved by CNA Jun 1 Published (CNA: SK-CERT)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0069 49.9 —
AFFECTED Product Versions Fixed Apache Airflow unspecified —
TIMELINE Apr 15 Reserved by CNA Jun 1 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0069 49.7 —
AFFECTED Product Versions Fixed DI-7001 MINI 19.09.19A1 – —
TIMELINE May 31 Reserved by CNA Jun 1 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L L 7.3 .0068 49.3 —
AFFECTED Product Versions Fixed Apache Airflow unspecified —
TIMELINE May 11 Reserved by CNA Jun 1 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0067 48.9 —
AFFECTED Product Versions Fixed Secure Data Forms < 9.3.0 – —
TIMELINE Jan 26 Reserved by CNA Jun 1 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R U H H H 8.0 .0066 48.7 —
AFFECTED Product Versions Fixed Microsoft SharePoint Enterprise Server 2016 16.0.0 – — Microsoft SharePoint Server 2019 16.0.0 – — Microsoft SharePoint Server Subscription Edition 16.0.0 – —
TIMELINE May 18 Reserved by CNA Jun 1 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0065 48.1 —
AFFECTED Product Versions Fixed Apache Airflow 3.0.0 – —
TIMELINE Apr 16 Reserved by CNA Jun 1 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0064 47.8 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 1 Public exploit reference published Jun 1 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0064 47.8 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 1 Public exploit reference published Jun 1 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0064 47.8 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 1 Public exploit reference published Jun 1 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0063 47.2 —
AFFECTED Product Versions Fixed Smart Parking System 1.0 – —
TIMELINE May 31 Reserved by CNA Jun 1 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0062 47.0 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 1 Public exploit reference published Jun 1 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0060 45.9 —
AFFECTED Product Versions Fixed Apache ActiveMQ Broker unspecified — Apache ActiveMQ All unspecified — Apache ActiveMQ unspecified —
TIMELINE May 12 Reserved by CNA Jun 1 Published (CNA: apache)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-49361 | 7.5 | 45.0 | Apache Software Foundation | Apache Fluss (incubating) | CWE-400 | Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability |
| CVE-2026-42359 | 8.8 | 44.5 | Apache Software Foundation | Apache Airflow | CWE-502 | Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody mi… |
| CVE-2026-37235 | 7.5 | 44.5 | n/a | n/a | CWE-284 | FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without bin… |
| CVE-2026-42588 | 8.1 | 44.3 | Apache Software Foundation | Apache ActiveMQ Broker | CWE-20 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Exe… |
| CVE-2026-25879 | 9.8 | 43.7 | langroid | langroid | CWE-89 | Langroid has Prompt to SQL Injection, Leading to RCE |
| CVE-2026-7858 | 9.8 | 43.1 | Dassault Systèmes | Teamwork Cloud - Standard Edition | CWE-502 | Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from… |
| CVE-2026-48827 | 7.1 | 42.2 | Apache Software Foundation | Apache MINA SSHD | CWE-22 | Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git |
| CVE-2026-9330 | 8.5 | 41.5 | IBM | WebSphere Application Server | CWE-502 | IBM WebSphere Application Server is affected by remote code execution |
| CVE-2024-52011 | 7.5 | 41.4 | vitejs | launch-editor | CWE-77 | launch-editor vulnerable to command injection via the crafted request on Windows |
| CVE-2026-9311 | 9.0 | 41.1 | IBM | WebSphere Application Server | CWE-94 | IBM WebSphere Application Server is affected by remote code execution |
| CVE-2026-49328 | 5.3 | 40.7 | Apache Software Foundation | Apache Fesod (Incubating) | CWE-918 | Apache Fesod (Incubating): Improper validation of user-supplied URLs leading … |
| CVE-2026-10206 | 7.4 | 40.6 | D-Link | DI-8400 | CWE-119 | D-Link DI-8400 dbsrv.asp stack-based overflow |
| CVE-2026-10288 | 5.5 | 40.3 | code-projects | Hotel and Tourism Reservation System | CWE-287 | code-projects Hotel and Tourism Reservation System Admin Login login.php pass… |
| CVE-2026-49298 | 8.8 | 39.9 | Apache Software Foundation | Apache Airflow | CWE-538 | Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments |
| CVE-2026-37231 | 7.5 | 39.9 | n/a | n/a | CWE-191 | FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the … |
| CVE-2026-10259 | 7.4 | 39.6 | H3C | Magic B0 | CWE-119 | H3C Magic B0 aspForm SetMobileAPInfoById stack-based overflow |
| CVE-2026-40963 | 3.1 | 39.2 | Apache Software Foundation | Apache Airflow | CWE-285 | Apache Airflow: DAG authorization bypass on /ui/structure/structure_data |
| CVE-2026-41084 | 7.5 | 39.1 | Apache Software Foundation | Apache Airflow | CWE-639 | Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG… |
| CVE-2026-45727 | 8.8 | 39.1 | CloakHQ | CloakBrowser | CWE-22 | CloakBrowser: Unauthenticated path traversal via fingerprint parameter in clo… |
| CVE-2026-10292 | 7.4 | 38.8 | UTT | HiPER 1200GW | CWE-119 | UTT HiPER 1200GW formTaskEdit strcpy stack-based overflow |
| CVE-2026-10293 | 7.4 | 38.8 | UTT | HiPER 1200GW | CWE-119 | UTT HiPER 1200GW formFireWall strcpy stack-based overflow |
| CVE-2026-48866 | 9.6 | 38.6 | Rocketgenius Inc. | Gravity Forms | CWE-22 | WordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerab… |
| CVE-2026-9319 | 9.0 | 37.9 | IBM | WebSphere Application Server | CWE-502 | IBM WebSphere Application Server is affected by a remote code execution vulne… |
| CVE-2026-37233 | 7.5 | 37.6 | n/a | n/a | CWE-617 | FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation … |
| CVE-2026-40547 | 6.4 | 37.1 | SOPlanning | SOPlanning | CWE-22 | Path Traversal in SOPlanning |
| CVE-2026-49157 | 8.8 | 36.6 | Apache Software Foundation | Apache ActiveMQ | CWE-276 | Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-… |
| CVE-2026-7770 | 8.8 | 36.5 | IBM | i Access Family | CWE-74 | IBM i Access Client Solutions (ACS) is vulnerable to remote code execution wh… |
| CVE-2026-37223 | 7.5 | 36.4 | n/a | n/a | CWE-617 | FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher.… |
| CVE-2026-20452 | 8.0 | 36.2 | MediaTek, Inc. | MediaTek chipset | CWE-122 | In wlan AP driver, there is a possible memory corruption due to a heap buffer… |
| CVE-2026-22872 | 6.9 | 35.8 | projectcapsule | capsule | CWE-20 | Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability |
| CVE-2026-37222 | 7.5 | 35.7 | n/a | n/a | CWE-617 | FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE)… |
| CVE-2026-37224 | 7.5 | 35.7 | n/a | n/a | CWE-617 | FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the s… |
| CVE-2026-45192 | 6.5 | 35.5 | Apache Software Foundation | Apache Airflow | CWE-200 | Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra … |
| CVE-2026-49136 | 8.7 | 34.8 | Anionex | banana-slides | CWE-22 | Banana Slides 0.4.0 Path Traversal via generate_image() in ai_service.py |
| CVE-2026-37225 | 7.5 | 34.6 | n/a | n/a | CWE-617 | FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST… |
| CVE-2026-37227 | 7.5 | 34.6 | n/a | n/a | CWE-617 | FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers fo… |
| CVE-2024-40646 | 8.6 | 34.5 | vertex-app | vertex | CWE-22 | Vertex Vulnerable to Path Traversal |
| CVE-2019-25716 | 7.1 | 34.5 | Dräger | Infinity Delta | CWE-15 | Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet |
| CVE-2026-45156 | 8.1 | 34.3 | nextcloud | security-advisories | CWE-287 | Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature … |
| CVE-2026-10281 | 5.5 | 34.2 | Enderfga | claw-orchestrator | CWE-287 | Enderfga claw-orchestrator API Endpoint embedded-server.ts EmbeddedServer mis… |
| CVE-2026-10216 | 2.9 | 33.8 | unitedbyai | droidclaw | CWE-307 | unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication |
| CVE-2026-40545 | 5.1 | 33.6 | SOPlanning | SOPlanning | CWE-79 | Reflected XSS in SOPlanning |
| CVE-2026-42674 | 7.5 | 32.6 | AAM Plugin | Advanced Access Manager | CWE-290 | WordPress Advanced Access Manager plugin <= 7.1.0 - Bypass Vulnerability vuln… |
| CVE-2026-43624 | 8.8 | 32.4 | SWivid | F5-TTS | CWE-22 | F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project() |
| CVE-2026-37232 | 8.6 | 32.5 | n/a | n/a | CWE-369 | An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2S… |
| CVE-2026-40964 | 7.5 | 32.5 | Cloud Foundry Foundation | log-cache_release | CWE-287 | Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all instal… |
| CVE-2026-45279 | 6.5 | 32.3 | nextcloud | security-advisories | CWE-22 | Nextcloud: Limited path traversal via template API if using `{lang}` in config |
| CVE-2025-70099 | 7.5 | 31.6 | n/a | n/a | CWE-476 | A NULL pointer dereference in the ext4_dir_en_get_name_len function in includ… |
| CVE-2026-42252 | 9.1 | 31.5 | Apache Software Foundation | Apache Airflow | CWE-1336 | Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privileg… |
| CVE-2026-49139 | 7.0 | 31.3 | HKUDS | nanobot | CWE-918 | Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning |
| CVE-2026-48726 | 6.5 | 31.3 | Apache Software Foundation | Apache Airflow | CWE-613 | Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthMa… |
| CVE-2026-5419 | 3.7 | 31.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-208 | Gnutls: gnutls: information disclosure via timing side-channel in pkcs#7 padd… |
| CVE-2026-46243 | 7.1 | 30.8 | Linux | Linux | CWE-20 | smb: client: reject userspace cifs.spnego descriptions |
| CVE-2026-10224 | 5.5 | 30.4 | NousResearch | hermes-agent | CWE-400 | NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request … |
| CVE-2026-10213 | 2.1 | 30.3 | AstrBotDevs | AstrBot | CWE-22 | AstrBotDevs AstrBot API Endpoint delete path traversal |
| CVE-2026-10236 | 5.5 | 30.3 | SourceCodester | Water Billing Management System | CWE-266 | SourceCodester Water Billing Management System User Management Endpoint Users… |
| CVE-2026-10532 | 2.9 | 30.1 | QOS.CH Sarl | logback | CWE-502 | Logback deserialization whitelist bypass for Proxy objects |
| CVE-2026-49270 | 5.9 | 29.9 | Apache Software Foundation | Apache ActiveMQ Broker | CWE-1230 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscri… |
| CVE-2026-10300 | 2.9 | 29.8 | n/a | SGLang | CWE-617 | SGLang Inference HTTP Endpoint lora_manager.py assertion |
| CVE-2026-41014 | 4.3 | 29.6 | Apache Software Foundation | Apache Airflow | CWE-862 | Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints |
| CVE-2026-46764 | 4.3 | 29.6 | Apache Software Foundation | Apache Airflow | CWE-639 | Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permi… |
| CVE-2026-45275 | 6.5 | 28.9 | nextcloud | security-advisories | CWE-285 | Nextcloud: Authorization bypass in approval feature allows unauthorized file … |
| CVE-2026-45426 | 3.1 | 28.8 | Apache Software Foundation | Apache Airflow | CWE-863 | Apache Airflow: Log server JWT authorization bypass via Python lstrip() chara… |
| CVE-2026-42251 | 8.7 | 28.7 | KAMSOFT | KS-SOMED | CWE-798 | Hard-coded credentials in KS-SOMED |
| CVE-2026-10291 | 5.3 | 28.5 | Enderfga | claw-orchestrator | CWE-400 | Enderfga claw-orchestrator Session Grep Endpoint embedded-server.ts validateR… |
| CVE-2026-41017 | 5.9 | 28.1 | Apache Software Foundation | Apache Airflow | CWE-614 | Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind… |
| CVE-2026-42358 | 6.5 | 27.8 | Apache Software Foundation | Apache Airflow | CWE-200 | Apache Airflow: Variable masker depth-limit bypass returns cleartext nested s… |
| CVE-2026-42360 | 6.5 | 27.8 | Apache Software Foundation | Apache Airflow | CWE-200 | Apache Airflow: Rendered template truncation bypasses nested sensitive-key ma… |
| CVE-2026-46605 | 4.3 | 27.9 | Apache Software Foundation | Apache ActiveMQ Broker | CWE-285 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete auth… |
| CVE-2026-37220 | 7.5 | 27.7 | n/a | n/a | CWE-617 | FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_… |
| CVE-2026-37221 | 7.5 | 27.7 | n/a | n/a | CWE-617 | FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unk… |
| CVE-2026-40965 | 10.0 | 27.6 | Cloud Foundry Foundation | uaa_release | CWE-200 | Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a priv… |
| CVE-2026-37234 | 8.2 | 27.5 | n/a | n/a | CWE-400 | FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by s… |
| CVE-2026-49491 | 8.8 | 27.5 | Pixastudio | Pixa Bank | CWE-89 | Pixa Bank 2.0 SQL Injection via agence-ajax.php API |
| CVE-2018-25428 | 8.8 | 27.1 | Paroiciel | Paroiciel | CWE-89 | Paroiciel 11.20 SQL Injection via tRecIdListe Parameter |
| CVE-2018-25433 | 8.8 | 27.1 | Joomlaextensions | JE Photo Gallery | CWE-89 | Joomla JE Photo Gallery 1.1 SQL Injection via categoryid |
| CVE-2018-25434 | 8.8 | 27.1 | eliekhoury | WP AutoSuggest | CWE-89 | WP AutoSuggest 0.24 SQL Injection via autosuggest.php |
| CVE-2026-10289 | 2.1 | 26.7 | code-projects | Hotel and Tourism Reservation System | CWE-79 | code-projects Hotel and Tourism Reservation System tour.php cross site scripting |
| CVE-2026-48208 | 6.5 | 26.2 | OTRS AG | OTRS | CWE-400 | Denial-of-Service via SVG Rendering in Ticket |
| CVE-2026-42680 | 9.8 | 26.0 | Wasiliy Strecker / ContestGallery developer | Contest Gallery Pro | CWE-266 | WordPress Contest Gallery Pro plugin <= 29.0.1 - Privilege Escalation vulnera… |
| CVE-2026-8644 | 9.1 | 25.9 | IBM | WebSphere Application Server | CWE-290 | IBM WebSphere Application Server is affected by an identity spoofing vulnerab… |
| CVE-2026-10254 | 5.5 | 25.7 | SourceCodester | Pet Grooming Management Software | CWE-200 | SourceCodester Pet Grooming Management Software admin file information disclo… |
| CVE-2026-48879 | 9.8 | 25.6 | Sergey | AIWU | CWE-266 | WordPress AIWU plugin <= 1.4.17 - Privilege Escalation vulnerability |
| CVE-2026-8643 | 4.1 | 24.8 | Python Packaging Authority | pip | CWE-22 | pip can extract console_scripts and gui_scripts outside installation directory |
| CVE-2026-43623 | 8.7 | 24.5 | rxi | microtar | CWE-121 | microtar 0.1.0 Stack-Based Buffer Overflow via raw_to_header() |
| CVE-2026-45545 | 8.2 | 24.6 | nextcloud | security-advisories | CWE-89 | Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution |
| CVE-2026-10290 | 5.5 | 24.6 | code-projects | Hotel and Tourism Reservation System | CWE-74 | code-projects Hotel and Tourism Reservation System GET Parameter tour.php sql… |
| CVE-2026-45302 | 8.2 | 24.2 | milamer | parse-nested-form-data | CWE-1321 | Prototype Pollution in parse-nested-form-data via `__proto__` in FormData fie… |
| CVE-2026-10255 | 5.5 | 23.8 | SourceCodester | Pharmacy Sales and Inventory System | CWE-266 | SourceCodester Pharmacy Sales and Inventory System ShowForm.php sell_statemen… |
| CVE-2026-40548 | 6.4 | 23.6 | SOPlanning | SOPlanning | CWE-434 | Unrestricted Upload of File with Dangerous Type in SOPlanning |
| CVE-2026-10272 | 5.5 | 23.4 | a4m4 | Student-Management-System | CWE-266 | a4m4 Student-Management-System deleteform.php improper authorization |
| CVE-2026-10280 | 5.5 | 23.1 | horizon921 | mcpilot | CWE-918 | horizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgery |
| CVE-2026-10220 | 5.5 | 23.0 | NousResearch | hermes-agent | CWE-74 | NousResearch hermes-agent skills_tool.py skill_view injection |
| CVE-2026-10221 | 5.5 | 23.0 | NousResearch | hermes-agent | CWE-74 | NousResearch hermes-agent run_agent.py _compress_context injection |
| CVE-2026-45722 | 7.1 | 22.7 | nextcloud | security-advisories | CWE-89 | Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort ord… |
| CVE-2026-10271 | 2.1 | 22.5 | a4m4 | Student-Management-System | CWE-698 | a4m4 Student-Management-System Admin Endpoint admin redirect |
| CVE-2026-10275 | 1.3 | 22.1 | n/a | OpenSC | CWE-119 | OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer o… |
| CVE-2026-42679 | 6.5 | 22.1 | Mamunur Rashid | Classified Listing | CWE-22 | WordPress Classified Listing plugin <= 5.3.8 - Arbitrary File Download vulner… |
| CVE-2026-44740 | 6.5 | 22.1 | go-git | go-billy | CWE-674 | go-billy: Lack of depth and cycle detection in symlink resolution may lead to… |
| CVE-2026-10283 | 5.3 | 22.1 | Bottelet | DaybydayCRM | CWE-287 | Bottelet DaybydayCRM Setting missing authentication |
| CVE-2026-40544 | 5.1 | 22.0 | SOPlanning | SOPlanning | CWE-79 | Stored XSS in SOPlanning |
| CVE-2026-45282 | 6.5 | 21.9 | nextcloud | security-advisories | CWE-284 | Nextcloud: Logged-in user bypasses share password and download restrictions o… |
| CVE-2026-10287 | 5.5 | 21.9 | SourceCodester | SEO Meta Tag Extractor | CWE-918 | SourceCodester SEO Meta Tag Extractor index.php get_headers server-side reque… |
| CVE-2026-45285 | 6.4 | 21.8 | nextcloud | security-advisories | CWE-862 | Nextcloud: Hidden Public Link creation when sharing to a Team External Member |
| CVE-2026-42682 | 9.1 | 21.6 | Tomdever | wpForo Forum | CWE-862 | WordPress wpForo Forum plugin <= 3.0.6 - Broken Access Control vulnerability |
| CVE-2026-45267 | 6.5 | 21.6 | nextcloud | security-advisories | CWE-200 | Nextcloud: Missing permission check for from submissions |
| CVE-2026-45690 | 5.9 | 21.5 | nextcloud | security-advisories | CWE-287 | Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay |
| CVE-2026-45691 | 5.9 | 21.5 | nextcloud | security-advisories | CWE-287 | Nextcloud: Bypass of second factor authentication on DAV endpoints |
| CVE-2026-24751 | 8.2 | 21.4 | kiteworks | Secure Data Forms | CWE-79 | Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting |
| CVE-2026-10278 | 2.1 | 21.3 | ishayoyo | excel-mcp | CWE-22 | ishayoyo excel-mcp read_file/write_file index.ts path traversal |
| CVE-2026-49138 | 5.3 | 21.1 | HKUDS | nanobot | CWE-918 | Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following |
| CVE-2026-45281 | 8.1 | 20.9 | nextcloud | security-advisories | CWE-639 | Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set … |
| CVE-2026-24752 | 8.2 | 20.8 | kiteworks | Secure Data Forms | CWE-79 | Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting |
| CVE-2026-45286 | 4.3 | 20.5 | nextcloud | security-advisories | CWE-200 | Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint |
| CVE-2026-10269 | 5.3 | 20.1 | decolua | 9router | CWE-266 | decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper author… |
| CVE-2026-10277 | 2.1 | 20.1 | j3k0 | mcp-google-workspace | CWE-266 | j3k0 mcp-google-workspace MCP Gmail Tool gmail.ts saveToDisk access control |
| CVE-2026-45131 | 10.0 | 19.9 | CloudPirates-io | helm-charts | CWE-94 | CloudPirates Open Source Helm Charts: GitHub Actions pull_request_target work… |
| CVE-2026-10299 | 2.0 | 19.8 | code-projects | Online Hospital Management System | CWE-99 | code-projects Online Hospital Management System viewdoctortimings.php resourc… |
| CVE-2026-40543 | 8.8 | 19.7 | SOPlanning | SOPlanning | CWE-862 | Missing Authorization in SOPlanning |
| CVE-2018-25429 | 7.1 | 19.7 | Paroiciel | Paroiciel | CWE-89 | Paroiciel 11.20 SQL Injection via zProIdPro Parameter |
| CVE-2018-25430 | 7.1 | 19.7 | Paroiciel | Paroiciel | CWE-89 | Paroiciel 11.20 SQL Injection via eGeqIdEquipe Parameter |
| CVE-2018-25431 | 7.1 | 19.7 | goFrendiAsgard | No-CMS | CWE-89 | No-Cms 1.0 SQL Injection via order_by Parameter |
| CVE-2026-10301 | 2.1 | 19.7 | itsourcecode | Fees Management System | CWE-79 | itsourcecode Fees Management System index.php cross site scripting |
| CVE-2026-49134 | 7.5 | 19.2 | steipete | CodexBar | CWE-377 | CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File |
| CVE-2026-10239 | 2.1 | 19.2 | n/a | JeecgBoot | CWE-918 | JeecgBoot edit WordUtil.addImage server-side request forgery |
| CVE-2026-10240 | 2.1 | 19.2 | n/a | JeecgBoot | CWE-918 | JeecgBoot test server-side request forgery |
| CVE-2026-10241 | 2.1 | 19.2 | jeecgboot | The server processes these URLs | CWE-918 | jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint de… |
| CVE-2026-10276 | 2.1 | 19.2 | hekmon8 | Jenkins-server-mcp | CWE-918 | hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index… |
| CVE-2026-10249 | 5.5 | 19.1 | itsourcecode | Online Blood Bank Management System | CWE-74 | itsourcecode Online Blood Bank Management System viewrequest.php sql injection |
| CVE-2026-10262 | 5.5 | 19.1 | code-projects | Real State Services | CWE-74 | code-projects Real State Services Login loginuser.php sql injection |
| CVE-2026-10263 | 5.5 | 19.1 | SourceCodester | Computer Repair Shop Management System | CWE-74 | SourceCodester Computer Repair Shop Management System manage_product.php sql … |
| CVE-2026-45543 | 5.3 | 19.1 | nextcloud | security-advisories | CWE-552 | Nextcloud: Deleting a Forms collaborator share leaves uploaded response files… |
| CVE-2026-49140 | 5.3 | 19.0 | HKUDS | nanobot | CWE-770 | Nanobot < 0.2.1 Denial of Service via Matrix Media Download Handler |
| CVE-2026-10222 | 2.9 | 18.6 | NousResearch | hermes-agent | CWE-74 | NousResearch hermes-agent config.py _sanitize_env_lines injection |
| CVE-2026-0080 | 6.5 | 18.5 | Android | CWE-190 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way … | |
| CVE-2026-10264 | 2.0 | 18.5 | lharries | whatsapp-mcp | CWE-22 | lharries whatsapp-mcp Send API Endpoint main.go SendMessageRequest path trave… |
| CVE-2026-10208 | 5.5 | 18.2 | code-projects | Online Hospital Management System | CWE-74 | code-projects Online Hospital Management System login_1.php login_user sql in… |
| CVE-2026-10225 | 5.5 | 18.2 | raisulislamg4 | student_management_system_by_php | CWE-74 | raisulislamg4 student_management_system_by_php Login login_check.php sql inje… |
| CVE-2026-10226 | 5.5 | 18.2 | raisulislamg4 | student_management_system_by_php | CWE-74 | raisulislamg4 student_management_system_by_php delete.php sql injection |
| CVE-2026-10227 | 5.5 | 18.2 | raisulislamg4 | student_management_system_by_php | CWE-74 | raisulislamg4 student_management_system_by_php User Creation add_user_check.p… |
| CVE-2026-10250 | 5.5 | 18.2 | itsourcecode | Online Blood Bank Management System | CWE-74 | itsourcecode Online Blood Bank Management System campsdetails.php sql injection |
| CVE-2026-10251 | 5.5 | 18.2 | itsourcecode | Online House Rental System | CWE-74 | itsourcecode Online House Rental System ajax.php login sql injection |
| CVE-2026-10252 | 5.5 | 18.2 | itsourcecode | Online House Rental System | CWE-74 | itsourcecode Online House Rental System manage_tenant.php sql injection |
| CVE-2026-10253 | 5.5 | 18.2 | itsourcecode | Online House Rental System | CWE-74 | itsourcecode Online House Rental System manage_payment.php sql injection |
| CVE-2026-10260 | 5.5 | 18.2 | CodeAstro | Online Job Portal | CWE-74 | CodeAstro Online Job Portal delete-jobs.php sql injection |
| CVE-2026-10261 | 5.5 | 18.2 | CodeAstro | Online Job Portal | CWE-74 | CodeAstro Online Job Portal application_status.php sql injection |
| CVE-2026-10237 | 2.0 | 18.1 | SourceCodester | Water Billing Management System | CWE-74 | SourceCodester Water Billing Management System User Management manage_user sq… |
| CVE-2026-45132 | 10.0 | 17.8 | CloudPirates-io | helm-charts | CWE-94 | CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and S… |
| CVE-2026-10215 | 2.1 | 17.7 | Dolibarr | ERP CRM | CWE-266 | Dolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAcces… |
| CVE-2022-4991 | 7.4 | 17.1 | Tychon | Tychon | — | Tychon is vulnerable to privilege escalation due to OPENSSLDIR location |
| CVE-2026-0039 | 6.5 | 17.0 | Android | CWE-190 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible pers… | |
| CVE-2026-0040 | 6.5 | 17.0 | Android | CWE-190 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way … | |
| CVE-2026-0041 | 6.5 | 17.0 | Android | CWE-190 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSa… | |
| CVE-2026-0044 | 6.5 | 17.0 | Android | CWE-190 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way … | |
| CVE-2026-0051 | 6.5 | 17.0 | Android | CWE-20 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way … | |
| CVE-2026-0052 | 6.5 | 17.0 | Android | CWE-190 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way … | |
| CVE-2026-10118 | 7.8 | 16.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Poppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads… |
| CVE-2026-45810 | 6.8 | 16.8 | nextcloud | security-advisories | CWE-639 | Nextcloud: Propfind requests for file comments allowed to load comments for o… |
| CVE-2026-10514 | 1.9 | 16.7 | 1Panel-dev | CordysCRM | CWE-79 | 1Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting |
| CVE-2026-10242 | 2.1 | 16.6 | itsourcecode | Content Management System | CWE-74 | itsourcecode Content Management System instructions.php sql injection |
| CVE-2026-10296 | 2.1 | 16.6 | itsourcecode | Fees Management System | CWE-74 | itsourcecode Fees Management System ajax.php sql injection |
| CVE-2026-10248 | 2.0 | 16.4 | SourceCodester | Pharmacy Sales and Inventory System | CWE-74 | SourceCodester Pharmacy Sales and Inventory System Supplier Creation export c… |
| CVE-2026-42673 | 7.5 | 16.0 | Logtivity Activity Logs | Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity | CWE-201 | WordPress Activity Logs, User Activity Tracking, Multisite Activity Log from … |
| CVE-2026-41013 | 8.1 | 15.1 | CloudFoundry Foundation | smb-volume-release | CWE-88 | Tenant-controlled comma smuggles arbitrary CIFS mount options |
| CVE-2026-42672 | 9.3 | 14.9 | Wp Directory Kit | WP Directory Kit | CWE-89 | WordPress WP Directory Kit plugin <= 1.5.1 - SQL Injection vulnerability |
| CVE-2026-45729 | 4.3 | 14.7 | thorvg | thorvg | CWE-476 | ThorVG: Null pointer dereference in SVG loader causes crash via 6-byte malfor… |
| CVE-2026-42677 | 7.5 | 14.3 | Ben Balter | WP Document Revisions | CWE-862 | WordPress WP Document Revisions plugin <= 3.8.1 - Broken Access Control vulne… |
| CVE-2026-45278 | 6.1 | 14.3 | nextcloud | security-advisories | CWE-601 | Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL by… |
| CVE-2026-45157 | 6.3 | 14.2 | nextcloud | security-advisories | CWE-284 | Nextcloud: Valid share tokens allow to access tempory upload files of share o… |
| CVE-2026-10284 | 5.3 | 14.0 | DevaslanPHP | project-management | CWE-266 | DevaslanPHP project-management Livewire ViewTicket.php doDeleteComment improp… |
| CVE-2026-10285 | 5.3 | 14.0 | DevaslanPHP | project-management | CWE-266 | DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated imp… |
| CVE-2026-10533 | 5.0 | 14.1 | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-770 | Openshift: openshift: non-admin user can bypass resourcequota and flood etcd … |
| CVE-2026-10218 | 2.1 | 14.0 | nextlevelbuilder | GoClaw | CWE-266 | nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization |
| CVE-2026-45264 | 4.3 | 13.9 | nextcloud | security-advisories | CWE-284 | Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized F… |
| CVE-2026-10210 | 2.1 | 13.7 | AstrBotDevs | AstrBot | CWE-74 | AstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injection |
| CVE-2026-10223 | 2.1 | 13.8 | NousResearch | hermes-agent | CWE-74 | NousResearch hermes-agent memory_tool.py _scan_memory_content injection |
| CVE-2026-10282 | 5.3 | 13.7 | Bottelet | DaybydayCRM | CWE-266 | Bottelet DaybydayCRM DocumentsController.php view improper authorization |
| CVE-2026-45544 | 4.3 | 13.0 | nextcloud | security-advisories | CWE-1230 | Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive… |
| CVE-2026-10294 | 2.1 | 13.0 | n/a | PackageKit | CWE-266 | PackageKit API pk-transaction.c g_file_test improper authorization |
| CVE-2026-48209 | 7.1 | 12.6 | OTRS AG | OTRS | CWE-79 | Reflected XSS in authenticated agent context |
| CVE-2026-48839 | 7.1 | 11.7 | VeronaLabs | WP Statistics | CWE-79 | WordPress WP Statistics plugin <= 14.16.6 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-40546 | 8.7 | 11.7 | SOPlanning | SOPlanning | CWE-89 | Multiple SQL Injections in SOPlanning |
| CVE-2026-40989 | 6.5 | 11.7 | Spring | Spring Cloud Function | CWE-674 | Self Routing guard bypassed via function composition |
| CVE-2026-40990 | 6.5 | 11.7 | Spring | Spring Cloud Function | CWE-770 | Unbounded cache for function definitions |
| CVE-2026-45283 | 4.3 | 11.6 | nextcloud | security-advisories | CWE-287 | Nextcloud: Files Lock app allows users to lock and unlock files of other users |
| CVE-2026-10212 | 2.1 | 11.7 | AstrBotDevs | AstrBot | CWE-285 | AstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization |
| CVE-2026-10217 | 2.1 | 11.4 | nextlevelbuilder | GoClaw | CWE-266 | nextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges… |
| CVE-2026-10274 | 2.1 | 11.4 | indrasishbanerjee | aem-mcp-server | CWE-918 | indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMet… |
| CVE-2026-10265 | 2.1 | 10.7 | itsourcecode | Content Management System | CWE-74 | itsourcecode Content Management System edit_topic.php sql injection |
| CVE-2026-10286 | 2.1 | 10.7 | CodeAstro | Payroll System | CWE-74 | CodeAstro Payroll System home_employee.php sql injection |
| CVE-2026-42678 | 7.1 | 10.6 | Liquid Web / StellarWP | GiveWP | CWE-79 | WordPress GiveWP plugin <= 4.14.5 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-45159 | 3.5 | 10.5 | nextcloud | security-advisories | CWE-639 | Nextcloud: Files drop share links for end-to-end encrypted folders allowed to… |
| CVE-2026-45266 | 3.5 | 10.5 | nextcloud | security-advisories | CWE-284 | Nextcloud: Unauthorized force-mute from missing permission check when using i… |
| CVE-2026-30963 | 2.7 | 10.5 | projectcapsule | capsule | CWE-20 | Capsule Namespace Hijacking via subresource |
| CVE-2026-10234 | 2.0 | 10.6 | Mettle | sendportal | CWE-79 | Mettle sendportal Campaign webview cross site scripting |
| CVE-2026-10244 | 2.0 | 10.5 | SourceCodester | Pharmacy Sales and Inventory System | CWE-79 | SourceCodester Pharmacy Sales and Inventory System main create_medicine_name … |
| CVE-2026-10245 | 2.0 | 10.5 | SourceCodester | Pharmacy Sales and Inventory System | CWE-79 | SourceCodester Pharmacy Sales and Inventory System main create_supplier cross… |
| CVE-2026-48187 | 5.7 | 10.3 | OTRS AG | OTRS | CWE-400 | Email with special content can lead to DoS |
| CVE-2026-10205 | 2.1 | 10.4 | Metasoft 美特软件 | MetaCRM | CWE-284 | Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload |
| CVE-2026-10211 | 2.1 | 10.4 | AstrBotDevs | AstrBot | CWE-285 | AstrBotDevs AstrBot fs.py _normalize_rw_path authorization |
| CVE-2026-45155 | 2.6 | 10.2 | nextcloud | security-advisories | CWE-639 | Nextcloud: Private circle can be added to another circle via API |
| CVE-2026-10209 | 2.1 | 10.2 | code-projects | Online Hospital Management System | CWE-74 | code-projects Online Hospital Management System Appointment appointmentdetail… |
| CVE-2026-10235 | 2.1 | 10.2 | CodeAstro | Ingredients Stock Management System | CWE-74 | CodeAstro Ingredients Stock Management System stock_manager.php sql injection |
| CVE-2026-10256 | 2.1 | 10.2 | itsourcecode | Content Management System | CWE-74 | itsourcecode Content Management System save_comment.php sql injection |
| CVE-2026-10257 | 2.1 | 10.2 | itsourcecode | Content Management System | CWE-74 | itsourcecode Content Management System update_ss_img.php sql injection |
| CVE-2026-10258 | 2.1 | 10.2 | itsourcecode | Content Management System | CWE-74 | itsourcecode Content Management System add_sub_topic.php sql injection |
| CVE-2026-10297 | 2.1 | 10.2 | itsourcecode | Fees Management System | CWE-74 | itsourcecode Fees Management System manage_course.php sql injection |
| CVE-2026-10302 | 2.1 | 10.2 | itsourcecode | Fees Management System | CWE-74 | itsourcecode Fees Management System manage_fee.php sql injection |
| CVE-2026-9024 | 8.7 | 10.0 | Dassault Systèmes | DELMIA Service Process Engineer | CWE-79 | Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience … |
| CVE-2026-10228 | 2.0 | 10.0 | raisulislamg4 | student_management_system_by_php | CWE-79 | raisulislamg4 student_management_system_by_php admission_form_check.php cross… |
| CVE-2026-10246 | 2.0 | 10.0 | SourceCodester | Pharmacy Sales and Inventory System | CWE-79 | SourceCodester Pharmacy Sales and Inventory System main create_medicine_prese… |
| CVE-2026-10247 | 2.0 | 10.0 | SourceCodester | Pharmacy Sales and Inventory System | CWE-79 | SourceCodester Pharmacy Sales and Inventory System main create_generic_name c… |
| CVE-2026-48865 | 7.1 | 9.9 | ThimPress | LearnPress | CWE-79 | WordPress LearnPress plugin <= 4.3.6 - Reflected Cross Site Scripting (XSS) v… |
| CVE-2026-48189 | 5.7 | 9.9 | OTRS AG | OTRS | CWE-200 | Bypass DedicatedAgentToCustomerGroups Setting |
| CVE-2026-42671 | 6.5 | 9.7 | Paolo | GeoDirectory | CWE-862 | WordPress GeoDirectory plugin <= 2.8.157 - Broken Access Control vulnerability |
| CVE-2026-45284 | 8.8 | 9.3 | nextcloud | security-advisories | CWE-284 | Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted… |
| CVE-2026-45701 | 6.9 | 9.3 | sulu | sulu | CWE-327 | Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens |
| CVE-2026-45154 | 2.6 | 8.9 | nextcloud | security-advisories | CWE-284 | Nextcloud: Improper Access Control in Collectives |
| CVE-2026-43625 | 8.2 | 8.5 | steipete | CodexBar | CWE-319 | CodexBar < 0.32.0 Session Cookie Exposure via HTTP Redirect |
| CVE-2026-28511 | 4.3 | 8.5 | elabftw | elabftw | CWE-200 | elabftw has entry title leakage through autocompletion search |
| CVE-2026-49267 | 5.9 | 8.4 | Apache Software Foundation | Apache Airflow | CWE-295 | Apache Airflow: No certificate validation on SMTP STARTTLS connections |
| CVE-2026-23638 | 6.5 | 8.3 | kiteworks | Secure Data Forms | CWE-639 | Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use… |
| CVE-2026-8474 | 5.3 | 8.1 | StormShield | StormShield Network Security | CWE-79 | Possible to run a Cross Site Scripting request on the login API available on … |
| CVE-2026-35563 | 8.8 | 8.0 | Apache Software Foundation | Apache Directory LDAP API | CWE-297 | Apache Directory LDAP API: LDAP client implementation does not verify if the … |
| CVE-2026-40549 | 5.1 | 8.1 | SOPlanning | SOPlanning | CWE-352 | Cross-Site Request Forgery in SOPlanning |
| CVE-2026-44211 | 9.6 | 7.9 | cline | cline | CWE-306 | Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability |
| CVE-2026-42675 | 7.3 | 7.6 | Themefic | Hydra Booking | CWE-862 | WordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerability |
| CVE-2026-24753 | 6.5 | 7.2 | kiteworks | Secure Data Forms | CWE-639 | Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use… |
| CVE-2026-48559 | 5.1 | 6.8 | epoupon | lms | CWE-79 | Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags |
| CVE-2026-9048 | 4.3 | 6.0 | Revolution Slider | Slider Revolution | CWE-863 | Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (… |
| CVE-2018-25432 | 8.6 | 5.9 | Armcode | Arm Whois | CWE-120 | Arm Whois 3.11 Buffer Overflow via ASLR Bypass |
| CVE-2026-8501 | 7.8 | 5.9 | Symantec | PC Tools Internet Security | CWE-782 | CVE-2026-8501 |
| CVE-2025-55664 | 5.5 | 5.5 | n/a | n/a | CWE-122 | A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.… |
| CVE-2026-9308 | 5.4 | 5.4 | Mozilla | Firefox for iOS | CWE-79 | Arbitrary JavaScript execution in Reader View due to wrong HTML replacement o… |
| CVE-2026-9309 | 5.4 | 5.4 | Mozilla | Firefox for iOS | CWE-79 | Arbitrary JavaScript execution in internal pages via Reader View JSON-LD inje… |
| CVE-2018-25435 | 6.9 | 5.3 | zeuscart | ZeusCart | CWE-352 | ZeusCart 4.0 Deactivate Customer Accounts CSRF |
| CVE-2026-45153 | 4.6 | 5.0 | nextcloud | security-advisories | CWE-287 | Nextcloud: PIN bypass in PassCodeActivity via back button |
| CVE-2026-9050 | 4.3 | 5.0 | Revolution Slider | Slider Revolution | CWE-862 | Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Au… |
| CVE-2026-24756 | 4.3 | 4.9 | kiteworks | Secure Data Forms | CWE-639 | Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use… |
| CVE-2026-38950 | 7.8 | 4.2 | n/a | n/a | CWE-502 | An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrar… |
| CVE-2025-60481 | 5.5 | 4.1 | n/a | n/a | CWE-476 | A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descri… |
| CVE-2025-60483 | 5.5 | 4.1 | n/a | n/a | CWE-476 | A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present funct… |
| CVE-2025-60485 | 5.5 | 4.1 | n/a | n/a | CWE-476 | A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/… |
| CVE-2026-34193 | 4.3 | 4.1 | Imagination Technologies | Graphics DDK | CWE-823 | GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation… |
| CVE-2026-48190 | 3.5 | 4.1 | OTRS AG | OTRS | CWE-276 | Incorrect handling of permissions in External Interface Config Item List module |
| CVE-2026-48191 | 3.5 | 4.1 | OTRS AG | OTRS | CWE-276 | Wrong Permission Handling in Document Search Article Meta Filters |
| CVE-2026-42681 | 7.1 | 4.0 | E2Pdf.com | e2pdf | CWE-79 | WordPress e2pdf plugin <= 1.32.14 - Reflected Cross Site Scripting (XSS) vuln… |
| CVE-2026-42683 | 7.1 | 4.0 | e4jvikwp | VikBooking Hotel Booking Engine & PMS | CWE-79 | WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.8 - Cross Site … |
| CVE-2026-24761 | 4.3 | 4.0 | kiteworks | Secure Data Forms | CWE-639 | Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use… |
| CVE-2026-24755 | 5.4 | 3.6 | kiteworks | Secure Data Forms | CWE-639 | Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use… |
| CVE-2026-24754 | 5.4 | 3.5 | kiteworks | security-advisories | CWE-79 | Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting |
| CVE-2025-60495 | 5.5 | 3.3 | n/a | n/a | CWE-476 | A segmentation violation in the gf_media_get_color_info function (/media_tool… |
| CVE-2026-43958 | 7.8 | 3.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial… |
| CVE-2026-0055 | 6.2 | 3.2 | Android | CWE-22 | In createSessionInternal of PackageInstallerService.java, there is a possible… | |
| CVE-2026-42676 | 6.5 | 3.1 | myCred | myCred | CWE-79 | WordPress myCred plugin <= 3.0.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2025-60486 | 5.5 | 3.0 | n/a | n/a | CWE-416 | A heap use-after-free in the dasher_process function (/filters/dasher.c) of G… |
| CVE-2026-45277 | 3.3 | 3.1 | nextcloud | security-advisories | CWE-200 | Nextcloud: Information disclosure in Nextcloud Approval app via fileId parame… |
| CVE-2026-49135 | 7.2 | 3.0 | steipete | CodexBar | CWE-59 | CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow |
| CVE-2026-10230 | 1.9 | 2.7 | n/a | Assimp | CWE-119 | Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based ove… |
| CVE-2026-10229 | 1.9 | 2.6 | n/a | Assimp | CWE-119 | Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflow |
| CVE-2026-10231 | 1.9 | 2.5 | n/a | Assimp | CWE-119 | Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based … |
| CVE-2026-0072 | 10.0 | 2.4 | Android XR | CWE-285 | In addInputMethodListener of com.android.server.inputmethod.InputMethodManage… | |
| CVE-2026-0097 | 8.0 | 2.3 | Android | CWE-693 | In multiple locations, there is a possible way to bypass user interaction whe… | |
| CVE-2026-10267 | 1.9 | 2.3 | janet-lang | janet | CWE-119 | janet-lang janet debug.c doframe out-of-bounds |
| CVE-2026-0046 | 6.2 | 2.2 | Android | CWE-269 | In InputInterceptor of Letterbox.java, there is a possible way to trick a use… | |
| CVE-2026-10268 | 1.9 | 2.2 | janet-lang | janet | CWE-189 | janet-lang janet marsh.c unmarshal_one_fiber integer overflow |
| CVE-2026-10295 | 1.9 | 2.2 | SourceCodester | Customer Review App | CWE-404 | SourceCodester Customer Review App review_app.py get_all_reviews denial of se… |
| CVE-2019-25718 | 8.6 | 2.0 | Dräger | Infinity Explorer C700 | CWE-451 | Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass |
| CVE-2026-0048 | 6.8 | 2.0 | Android | CWE-269 | In hide of WindowState.java, there is a possible way to trick the user into a… | |
| CVE-2026-10232 | 1.9 | 1.8 | n/a | Assimp | CWE-119 | Assimp ASE File scene.cpp ~aiNode use after free |
| CVE-2026-0059 | 8.0 | 1.7 | Android | CWE-122 | In multiple functions of sdp_discovery.cc, there is a possible way to achieve… | |
| CVE-2026-20453 | 6.7 | 1.7 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In geniezone, there is a possible out of bounds write due to a missing bounds… |
| CVE-2026-25599 | 6.3 | 1.8 | Orca Energy | Orca heat pump | CWE-79 | Missing authentication and clear‑text data transmission affecting Orca heat p… |
| CVE-2026-10233 | 1.9 | 1.7 | n/a | Assimp | CWE-119 | Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-bounds |
| CVE-2026-10298 | 1.9 | 1.6 | ggml-org | whisper.cpp | CWE-404 | ggml-org whisper.cpp ggml.c whisper_model_load null pointer dereference |
| CVE-2026-20455 | 7.8 | 1.4 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In geniezone, there is a possible out of bounds write due to a missing bounds… |
| CVE-2026-0056 | 3.3 | 1.4 | Android | CWE-120 | In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to … | |
| CVE-2026-0095 | 8.0 | 1.3 | Android | CWE-190 | In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger contro… | |
| CVE-2025-59601 | 6.5 | 1.3 | Qualcomm, Inc. | Snapdragon | CWE-1230 | Exposure of Sensitive Information Through Metadata in Powerline Communication… |
| CVE-2026-49433 | 2.3 | 1.3 | DeepAI | api.deepai.org | CWE-352 | DeepAI api.deepai.org/change_user_email CSRF |
| CVE-2026-20456 | 5.5 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In wlan STA driver, there is a possible system crash due to a missing bounds … |
| CVE-2026-27788 | 8.5 | 0.9 | Fsas Technologies Inc. | ServerView Agents for Windows | CWE-732 | Incorrect permission assignment for critical resource issue exists in ServerV… |
| CVE-2026-32325 | 8.5 | 0.9 | Fsas Technologies Inc. | ServerView Agents for Windows | CWE-268 | Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 an… |
| CVE-2026-24085 | 7.2 | 0.9 | Qualcomm, Inc. | Snapdragon | CWE-121 | Stack-based Buffer Overflow in Display |
| CVE-2026-24087 | 7.2 | 0.9 | Qualcomm, Inc. | Snapdragon | CWE-1286 | Improper Validation of Syntactic Correctness of Input in Kernel |
| CVE-2026-24089 | 7.2 | 0.9 | Qualcomm, Inc. | Snapdragon | CWE-1286 | Improper Validation of Syntactic Correctness of Input in Kernel |
| CVE-2026-24091 | 7.2 | 0.9 | Qualcomm, Inc. | Snapdragon | CWE-1286 | Improper Validation of Syntactic Correctness of Input in Display |
| CVE-2026-24092 | 7.2 | 0.9 | Qualcomm, Inc. | Snapdragon | CWE-1286 | Improper Validation of Syntactic Correctness of Input in Display |
| CVE-2021-46747 | 7.1 | 0.9 | AMD | AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics | CWE-1220 | Insufficient granularity of access control in ASP (AMD Secure Processor) may … |
| CVE-2026-0075 | 5.9 | 0.7 | Android | CWE-89 | In multiple functions, there is a possible way to access the contacts databas… | |
| CVE-2025-59609 | 5.5 | 0.6 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in WLAN Host Communication |
| CVE-2025-22424 | 7.8 | 0.4 | Android | CWE-20 | In multiple locations, there is a possible way to reveal images across users … | |
| CVE-2025-22426 | 7.8 | 0.3 | Android | CWE-284 | In many functions of ComputerEngine.java, there is a possible way to access U… | |
| CVE-2025-48652 | 7.8 | 0.3 | Android | CWE-693 | In performPreInstallChecks of InstallRepository.kt, there is a possible way t… | |
| CVE-2026-0045 | 7.8 | 0.3 | Android | CWE-693 | In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bond… | |
| CVE-2026-0077 | 7.8 | 0.3 | Android | CWE-693 | In resumeConfigurationDispatch of ActivityRecord.java, there is a possible ba… | |
| CVE-2026-0087 | 7.8 | 0.3 | Android | CWE-693 | In approvalLevelForDomainInternal of DomainVerificationService.java, there is… | |
| CVE-2026-0009 | 7.8 | 0.2 | Android | CWE-269 | In multiple locations, there is a possible tapjacking due to a logic error in… | |
| CVE-2025-48649 | 7.8 | 0.2 | Android | CWE-693 | In multiple locations, there is a possible way to reset user-selected permiss… | |
| CVE-2026-0076 | 7.8 | 0.2 | Android | CWE-125 | In validateNode of ResourceTypes.cpp, there is a possible out of bounds read … | |
| CVE-2026-0078 | 7.8 | 0.2 | Android | CWE-20 | In setGlobalProxy of DevicePolicyManagerService.java, there is a possible des… | |
| CVE-2026-0088 | 7.8 | 0.2 | Android | CWE-451 | In getCallingAppLabel of CertInstaller.java, there is a possible way to hide … | |
| CVE-2025-59611 | 6.7 | 0.2 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Core Services |
| CVE-2025-59614 | 6.7 | 0.2 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Windows Compute |
| CVE-2025-59612 | 6.7 | 0.2 | Qualcomm, Inc. | Snapdragon | CWE-121 | Stack-based Buffer Overflow in Windows Compute |
| CVE-2025-59613 | 6.7 | 0.2 | Qualcomm, Inc. | Snapdragon | CWE-121 | Stack-based Buffer Overflow in Windows Compute |
| CVE-2026-20454 | 6.4 | 0.1 | MediaTek, Inc. | MediaTek chipset | CWE-367 | In geniezone, there is a possible out of bounds write due to a race condition… |
| CVE-2026-25276 | 8.8 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-129 | Improper Validation of Array Index in Secure Processor |
| CVE-2025-59604 | 7.8 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-476 | NULL Pointer Dereference in SPS Applications |
| CVE-2025-59605 | 7.8 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in HLOS |
| CVE-2025-59606 | 7.8 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-476 | NULL Pointer Dereference in HLOS |
| CVE-2026-0100 | 7.8 | 0.1 | Android | CWE-122 | In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a h… | |
| CVE-2026-0086 | 6.8 | 0.1 | Android | CWE-269 | In onCreate of DisableSupervisionActivity.kt, there is a possible way to dele… | |
| CVE-2026-25277 | 8.8 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-120 | Buffer Copy Without Checking Size of Input in Secure Processor |
| CVE-2026-0043 | 5.5 | 0.1 | Android | CWE-190 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible pers… | |
| CVE-2026-28581 | 4.0 | 0.1 | Android | CWE-476 | In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possi… | |
| CVE-2026-0093 | 7.8 | 0.1 | Android | CWE-451 | In multiple locations, there is a possible misleading UI due to obfuscation. … | |
| CVE-2026-0096 | 7.8 | 0.1 | Android | CWE-451 | In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick … | |
| CVE-2026-28580 | 7.8 | 0.1 | Android | CWE-120 | In multiple functions, there is a possible desync in persistence due to an in… | |
| CVE-2026-0061 | 5.9 | 0.1 | Android | CWE-1021 | In multiple functions of WindowState.java, there is a possible way to trick a… | |
| CVE-2025-32348 | 7.8 | 0.1 | Android | CWE-863 | In multiple locations, there is a possible background activity launch due to … | |
| CVE-2025-48570 | 7.8 | 0.1 | Android | CWE-441 | In multiple functions of PipTaskOrganizer.java, there is a possible way to la… | |
| CVE-2026-0036 | 7.8 | 0.1 | Android | CWE-1021 | In startAnimation of StageCoordinator.java, there is a possible tapjacking is… | |
| CVE-2025-48616 | 3.3 | 0.1 | Android | — | In multiple functions of KeyguardViewMediator.java , there is a possible way … | |
| CVE-2026-24088 | 8.2 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-306 | Missing Authentication for Critical Function in Boot |
| CVE-2026-0099 | 7.8 | 0.0 | Android | CWE-273 | In onNullBinding of HostEmulationManager.java, there is a possible way to lau… | |
| CVE-2026-0018 | 5.5 | 0.1 | Android | CWE-20 | In multiple functions of AccessibilityManagerService.java, there is a possibl… | |
| CVE-2026-0042 | 5.5 | 0.1 | Android | CWE-400 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible pers… | |
| CVE-2026-0060 | 5.5 | 0.1 | Android | — | In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, the… | |
| CVE-2026-0067 | 5.5 | 0.1 | Android | — | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way … | |
| CVE-2026-0069 | 5.5 | 0.1 | Android | CWE-400 | In verifySignature of ApkChecksums.java, there is a possible way to cause a c… | |
| CVE-2026-0070 | 5.5 | 0.1 | Android | CWE-20 | In multiple functions of DevicePolicyManagerService.java, there is a possible… | |
| CVE-2026-0074 | 5.5 | 0.1 | Android | CWE-400 | In getPreferredSize of LauncherProcessImageListener.kt, there is a possible d… | |
| CVE-2026-0079 | 5.5 | 0.1 | Android | CWE-190 | In multiple functions of ubsan_throwing_runtime.cpp, there is a possible pers… | |
| CVE-2026-0085 | 5.5 | 0.1 | Android | CWE-20 | In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to… | |
| CVE-2026-25258 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-125 | Out-of-bounds Read in DSP Service |
| CVE-2026-25259 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in DSP Service |
| CVE-2025-26418 | 7.8 | 0.0 | Android | CWE-862 | In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a p… | |
| CVE-2026-0098 | 7.8 | 0.0 | Android | CWE-441 | In getCallingPackageName of Shared.java, there is a possible way to bypass ac… | |
| CVE-2025-48648 | 5.5 | 0.0 | Android | CWE-400 | In isSameApp of NotificationManagerService.java, there is a possible persiste… | |
| CVE-2026-0050 | 3.3 | 0.0 | Android | CWE-269 | In handleBondStateChanged of AdapterService.java, there is a possible sensiti… | |
| CVE-2026-0089 | 7.8 | 0.0 | Android | CWE-269 | In multiple functions of PackageInstallerService.java, there is a possible wa… | |
| CVE-2026-0091 | 7.8 | 0.0 | Android | CWE-269 | In multiple locations, there is a possible way to execute code in the launche… | |
| CVE-2026-28577 | 7.8 | 0.0 | Android | CWE-1021 | In addWindow of WindowManagerService.java, there is a possible tapjacking iss… | |
| CVE-2026-28578 | 5.5 | 0.0 | Android | CWE-20 | In multiple functions of DevicePolicyManagerService.java, there is a possible… | |
| CVE-2026-25600 | 6.4 | 0.0 | Trac d.o.o. | PDBM | CWE-798 | Credential Exposure Vulnerability in Trac PDBM |
| CVE-2026-0016 | 3.3 | 0.0 | Android | CWE-269 | In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there … | |
| CVE-2026-28586 | 3.3 | 0.0 | Android | CWE-269 | In multiple functions of AppOpsService.java, there is a possible missing perm… | |
| CVE-2026-24090 | 7.1 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-306 | Missing Authentication for Critical Function in HLOS |
| CVE-2026-0094 | 7.8 | 0.0 | Android | CWE-451 | In getApplicationLabel of KeyChainActivity.java, there is a possible way to t… | |
| CVE-2025-59610 | 6.4 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver |
| CVE-2026-25260 | 7.0 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-01 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.