boxscore/security
Monday, June 1, 2026 · all times UTC← 2026-05-31 · archive · 2026-06-02 →

377 CVEs published June 1, 2026: 22 critical, 136 high, 144 medium, 74 low; 1 in KEV; 15 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 352 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published377474910262563
KEV catalog size1670

177 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux19677961726912720.27.8.0013-60
microsoft1491433291020378275.57.8.0045+1
google602341114861117441.78.0.0021+60
red hat468829274400.07.2.0036+4
apple04701227193714.96.2.00340
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco013312096861.58.6.12470
ivanti16020033466.78.8.5751+1
checkpoint060330300.06.5.03380
fortinet06130028350.07.9.43300
f50320007133.39.2.09960
ubiquiti031200400.08.8.00680
broadcom02000042100.0.19900
palo alto networks020000142100.0.62990
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache28606262524011.77.2.0057+28
gitlab0901604222.24.3.00320
mozilla2832301300.07.7.0035+2
drupal0511305120.05.1.00260
docker030300100.08.8.00220
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm5541326150700.07.5.0031+5
oracle128815404013.68.1.0027+1
adobe04010075375.08.6.27760
progress040400900.07.5.00360
solarwinds031000113100.09.8.83620
veeam031200400.08.6.00400
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology01823103000.05.6.00250
d-link25031026120.07.4.0059+2
hitachi energy020020000.05.7.00140
hikvision01000021100.01.00000
siemens010100100.08.7.00320
dahua000000200
qnap000000800
schneider electric000000100
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax051032019100.07.4.00590
concrete cms044191321000.05.7.00150
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
totolink03502609000.08.9.01910
sourcecodester1234001123000.02.1.0025+12
netatalk033113910000.06.4.00300

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4684010.0.0073
Most disclosures (vendor)
VendorCVEs
linux580
google228
microsoft171
ibm54
edimax51
apache49
red hat45
concrete cms44
open ises44
helmholz42
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google4
ivanti4
synacor4
adobe3
fortinet3
smartertools3
solarwinds3
Most-affected ecosystems
EcosystemAdvisories
Maven22
Packagist7
PyPI3
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2026-0257Palo Alto Networks0
CVE-2026-0300Palo Alto Networks0
CVE-2026-20182Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171657
CVE-2021-27102Accellion2021-11-171657
CVE-2021-27101Accellion2021-11-171657
CVE-2021-27103Accellion2021-11-171657
CVE-2021-21017Adobe2021-11-171657
CVE-2021-28550Adobe2021-11-171657
CVE-2021-42013Apache2021-11-171657
CVE-2021-41773Apache2021-11-171657
CVE-2021-30858Apple2021-11-171657
CVE-2021-30860Apple2021-11-171657

Transactions

EXPLOIT PUBLISHEDCVE-2024-40646 (vertex-app vertex). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-22872 (projectcapsule capsule). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-30963 (projectcapsule capsule). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-37226. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-37228. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-37229. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-37230. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-37231. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-37233. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-37234. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-37235. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44211 (cline). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45286 (nextcloud security-advisories). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46243 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49121 (ROCm aiter). Public exploit reference added.

Yesterday's Results

377 CVEs published. 25 box scores, 352 table rows — nothing truncated.

CVE-2024-21182AWAITING ENRICHMENT
Oracle WebLogic Server
  CVSS   EPSS    %ile   KEV
  —      .4997   98.8   YES
AFFECTED
  Product          Versions     Fixed
  WebLogic Server  unspecified  —
TIMELINE
  Jun 1   Added to CISA KEV, due Jun 4
  Jun 1   Published
0 references · KEV due June 4, 2026
HP Inc. poly_trio_8300 — Poly Voice – Possible Remote Control of Certain Poly Devices
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .2447   97.7     —
AFFECTED
  Product         Versions     Fixed
  poly_trio_8300  unspecified  —
  poly_trio_8500  unspecified  —
  poly_trio_8800  unspecified  —
TIMELINE
  Jan 9   Reserved by CNA
  Jun 1   Published (CNA: hp)
CWE-121 · CNA: hp · 1 reference · NVD status: Awaiting Analysis
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0216   80.7     —
AFFECTED
  Product      Versions  Fixed
  Apache Solr  9.4.0 –   —
TIMELINE
  May 7   Reserved by CNA
  Jun 1   Published (CNA: apache)
CWE-798, CWE-1188 · CNA: apache · 2 references · NVD status: Analyzed
Ivanti Neurons for ITSM (On-Premises) — An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0144   70.9     —
AFFECTED
  Product                         Versions     Fixed
  Neurons for ITSM (On-Premises)  unspecified  2025.4 Patch 1
  Neurons for ITSM (Cloud)        unspecified  2026.1 Patch 9
TIMELINE
  May 26  Reserved by CNA
  Jun 1   Published (CNA: ivanti)
CWE-284 · CNA: ivanti · 1 reference · NVD status: Awaiting Analysis
n/a php-censor — php-censor Webhook Endpoint GitBuild.php os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0137   69.5     —
AFFECTED
  Product     Versions  Fixed
  php-censor  2.1.0 –   —
TIMELINE
  May 31  Reserved by CNA
  Jun 1   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 8 references · NVD status: Deferred
zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0134   68.8     —
AFFECTED
  Product            Versions  Fixed
  chatgpt-on-wechat  2.0.0 –   2.0.9
TIMELINE
  May 31  Reserved by CNA
  Jun 1   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 7 references · NVD status: Deferred
nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0134   68.8     —
AFFECTED
  Product  Versions  Fixed
  GoClaw   3.11.0 –  —
TIMELINE
  May 31  Reserved by CNA
  Jun 1   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 7 references · NVD status: Deferred
Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0111   63.1     —
AFFECTED
  Product              Versions     Fixed
  Apache ActiveMQ      unspecified  —
  Apache ActiveMQ Web  unspecified  —
TIMELINE
  Apr 25  Reserved by CNA
  Jun 1   Published (CNA: apache)
CWE-79 · CNA: apache · 2 references · NVD status: Analyzed
ROCm aiter — AI Tensor Engine for ROCm (AITER) 0.1.14 Unauthenticated RCE via MessageQueue.recv() Pickle Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0110   63.0     —
AFFECTED
  Product  Versions     Fixed
  aiter    unspecified  —
TIMELINE
  May 27  Reserved by CNA
  Jun 1   Public exploit reference published
  Jun 1   Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 6 references · NVD status: Modified
hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0109   62.5     —
AFFECTED
  Product      Versions  Fixed
  wezterm-mcp  0.1.0 –   —
TIMELINE
  May 31  Reserved by CNA
  Jun 1   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
Armcode Arm Whois — Arm Whois 3.11 Buffer Overflow via SEH Overwrite
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0092   57.4     —
AFFECTED
  Product    Versions  Fixed
  Arm Whois  3.11 –    —
TIMELINE
  May 31  Reserved by CNA
  Jun 1   Published (CNA: VulnCheck)
CWE-121 · CNA: VulnCheck · 4 references · NVD status: Deferred
OTRS AG OTRS — SQL Injection via MySQL Quote Method
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0074   51.5     —
AFFECTED
  Product                     Versions  Fixed
  OTRS                        7.0.x –   —
  ((OTRS)) Community Edition  6.x –     —
TIMELINE
  May 21  Reserved by CNA
  Jun 1   Published (CNA: OTRS)
CWE-20 · CNA: OTRS · 1 reference · NVD status: Analyzed
Disig Web Signer — Critical RCE vulnerability in Disig Web Signer
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4   .0072   50.9     —
AFFECTED
  Product     Versions  Fixed
  Web Signer  2.0.3 –   2.5.5
TIMELINE
  May 19  Reserved by CNA
  Jun 1   Published (CNA: SK-CERT)
CWE-94 · CNA: SK-CERT · 6 references · NVD status: Deferred
Apache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0069   49.9     —
AFFECTED
  Product         Versions     Fixed
  Apache Airflow  unspecified  —
TIMELINE
  Apr 15  Reserved by CNA
  Jun 1   Published (CNA: apache)
CWE-59 · CNA: apache · 3 references · NVD status: Analyzed
D-Link DI-7001 MINI API httpd_debug.asp sprintf stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0069   49.7     —
AFFECTED
  Product       Versions      Fixed
  DI-7001 MINI  19.09.19A1 –  —
TIMELINE
  May 31  Reserved by CNA
  Jun 1   Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 7 references · NVD status: Analyzed
Apache Airflow: Arbitrary import in custom deadline-reference deserialization
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0068   49.3     —
AFFECTED
  Product         Versions     Fixed
  Apache Airflow  unspecified  —
TIMELINE
  May 11  Reserved by CNA
  Jun 1   Published (CNA: apache)
CWE-502 · CNA: apache · 3 references · NVD status: Analyzed
Kiteworks Secure Data Forms has a SQL Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0067   48.9     —
AFFECTED
  Product            Versions   Fixed
  Secure Data Forms  < 9.3.0 –  —
TIMELINE
  Jan 26  Reserved by CNA
  Jun 1   Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
Microsoft SharePoint Server Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  U  H  H  H    8.0   .0066   48.7     —
AFFECTED
  Product                                           Versions  Fixed
  Microsoft SharePoint Enterprise Server 2016       16.0.0 –  —
  Microsoft SharePoint Server 2019                  16.0.0 –  —
  Microsoft SharePoint Server Subscription Edition  16.0.0 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 1   Published (CNA: microsoft)
CWE-78 · CNA: microsoft · 1 reference · NVD status: Modified
Apache Airflow: Open Redirect Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0065   48.1     —
AFFECTED
  Product         Versions  Fixed
  Apache Airflow  3.0.0 –   —
TIMELINE
  Apr 16  Reserved by CNA
  Jun 1   Published (CNA: apache)
CWE-601 · CNA: apache · 3 references · NVD status: Analyzed
n/a n/a — FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0064   47.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 1   Public exploit reference published
  Jun 1   Published (CNA: mitre)
CWE-476 · CNA: mitre · 2 references · NVD status: Analyzed
n/a n/a — FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0064   47.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 1   Public exploit reference published
  Jun 1   Published (CNA: mitre)
CWE-617 · CNA: mitre · 2 references · NVD status: Analyzed
n/a n/a — FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0064   47.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 1   Public exploit reference published
  Jun 1   Published (CNA: mitre)
CWE-476 · CNA: mitre · 2 references · NVD status: Analyzed
code-projects Smart Parking System Admin Endpoint missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0063   47.2     —
AFFECTED
  Product               Versions  Fixed
  Smart Parking System  1.0 –     —
TIMELINE
  May 31  Reserved by CNA
  Jun 1   Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · 6 references · NVD status: Deferred
n/a n/a — FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0062   47.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 1   Public exploit reference published
  Jun 1   Published (CNA: mitre)
CWE-617 · CNA: mitre · 2 references · NVD status: Analyzed
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0060   45.9     —
AFFECTED
  Product                 Versions     Fixed
  Apache ActiveMQ Broker  unspecified  —
  Apache ActiveMQ All     unspecified  —
  Apache ActiveMQ         unspecified  —
TIMELINE
  May 12  Reserved by CNA
  Jun 1   Published (CNA: apache)
CWE-20, CWE-94 · CNA: apache · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-493617.545.0Apache Software FoundationApache Fluss (incubating)CWE-400Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability
CVE-2026-423598.844.5Apache Software FoundationApache AirflowCWE-502Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody mi…
CVE-2026-372357.544.5n/an/aCWE-284FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without bin…
CVE-2026-425888.144.3Apache Software FoundationApache ActiveMQ BrokerCWE-20Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Exe…
CVE-2026-258799.843.7langroidlangroidCWE-89Langroid has Prompt to SQL Injection, Leading to RCE
CVE-2026-78589.843.1Dassault SystèmesTeamwork Cloud - Standard EditionCWE-502Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from…
CVE-2026-488277.142.2Apache Software FoundationApache MINA SSHDCWE-22Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git
CVE-2026-93308.541.5IBMWebSphere Application ServerCWE-502IBM WebSphere Application Server is affected by remote code execution
CVE-2024-520117.541.4vitejslaunch-editorCWE-77launch-editor vulnerable to command injection via the crafted request on Windows
CVE-2026-93119.041.1IBMWebSphere Application ServerCWE-94IBM WebSphere Application Server is affected by remote code execution
CVE-2026-493285.340.7Apache Software FoundationApache Fesod (Incubating)CWE-918Apache Fesod (Incubating): Improper validation of user-supplied URLs leading …
CVE-2026-102067.440.6D-LinkDI-8400CWE-119D-Link DI-8400 dbsrv.asp stack-based overflow
CVE-2026-102885.540.3code-projectsHotel and Tourism Reservation SystemCWE-287code-projects Hotel and Tourism Reservation System Admin Login login.php pass…
CVE-2026-492988.839.9Apache Software FoundationApache AirflowCWE-538Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
CVE-2026-372317.539.9n/an/aCWE-191FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the …
CVE-2026-102597.439.6H3CMagic B0CWE-119H3C Magic B0 aspForm SetMobileAPInfoById stack-based overflow
CVE-2026-409633.139.2Apache Software FoundationApache AirflowCWE-285Apache Airflow: DAG authorization bypass on /ui/structure/structure_data
CVE-2026-410847.539.1Apache Software FoundationApache AirflowCWE-639Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG…
CVE-2026-457278.839.1CloakHQCloakBrowserCWE-22CloakBrowser: Unauthenticated path traversal via fingerprint parameter in clo…
CVE-2026-102927.438.8UTTHiPER 1200GWCWE-119UTT HiPER 1200GW formTaskEdit strcpy stack-based overflow
CVE-2026-102937.438.8UTTHiPER 1200GWCWE-119UTT HiPER 1200GW formFireWall strcpy stack-based overflow
CVE-2026-488669.638.6Rocketgenius Inc.Gravity FormsCWE-22WordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerab…
CVE-2026-93199.037.9IBMWebSphere Application ServerCWE-502IBM WebSphere Application Server is affected by a remote code execution vulne…
CVE-2026-372337.537.6n/an/aCWE-617FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation …
CVE-2026-405476.437.1SOPlanningSOPlanningCWE-22Path Traversal in SOPlanning
CVE-2026-491578.836.6Apache Software FoundationApache ActiveMQCWE-276Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-…
CVE-2026-77708.836.5IBMi Access FamilyCWE-74IBM i Access Client Solutions (ACS) is vulnerable to remote code execution wh…
CVE-2026-372237.536.4n/an/aCWE-617FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher.…
CVE-2026-204528.036.2MediaTek, Inc.MediaTek chipsetCWE-122In wlan AP driver, there is a possible memory corruption due to a heap buffer…
CVE-2026-228726.935.8projectcapsulecapsuleCWE-20Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability
CVE-2026-372227.535.7n/an/aCWE-617FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE)…
CVE-2026-372247.535.7n/an/aCWE-617FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the s…
CVE-2026-451926.535.5Apache Software FoundationApache AirflowCWE-200Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra …
CVE-2026-491368.734.8Anionexbanana-slidesCWE-22Banana Slides 0.4.0 Path Traversal via generate_image() in ai_service.py
CVE-2026-372257.534.6n/an/aCWE-617FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST…
CVE-2026-372277.534.6n/an/aCWE-617FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers fo…
CVE-2024-406468.634.5vertex-appvertexCWE-22Vertex Vulnerable to Path Traversal
CVE-2019-257167.134.5DrägerInfinity DeltaCWE-15Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet
CVE-2026-451568.134.3nextcloudsecurity-advisoriesCWE-287Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature …
CVE-2026-102815.534.2Enderfgaclaw-orchestratorCWE-287Enderfga claw-orchestrator API Endpoint embedded-server.ts EmbeddedServer mis…
CVE-2026-102162.933.8unitedbyaidroidclawCWE-307unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication
CVE-2026-405455.133.6SOPlanningSOPlanningCWE-79Reflected XSS in SOPlanning
CVE-2026-426747.532.6AAM PluginAdvanced Access ManagerCWE-290WordPress Advanced Access Manager plugin <= 7.1.0 - Bypass Vulnerability vuln…
CVE-2026-436248.832.4SWividF5-TTSCWE-22F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()
CVE-2026-372328.632.5n/an/aCWE-369An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2S…
CVE-2026-409647.532.5Cloud Foundry Foundationlog-cache_releaseCWE-287Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all instal…
CVE-2026-452796.532.3nextcloudsecurity-advisoriesCWE-22Nextcloud: Limited path traversal via template API if using `{lang}` in config
CVE-2025-700997.531.6n/an/aCWE-476A NULL pointer dereference in the ext4_dir_en_get_name_len function in includ…
CVE-2026-422529.131.5Apache Software FoundationApache AirflowCWE-1336Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privileg…
CVE-2026-491397.031.3HKUDSnanobotCWE-918Nanobot < 0.2.1 SSRF via Microsoft Teams Channel serviceUrl Poisoning
CVE-2026-487266.531.3Apache Software FoundationApache AirflowCWE-613Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthMa…
CVE-2026-54193.731.1Red HatRed Hat Enterprise Linux 10CWE-208Gnutls: gnutls: information disclosure via timing side-channel in pkcs#7 padd…
CVE-2026-462437.130.8LinuxLinuxCWE-20smb: client: reject userspace cifs.spnego descriptions
CVE-2026-102245.530.4NousResearchhermes-agentCWE-400NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request …
CVE-2026-102132.130.3AstrBotDevsAstrBotCWE-22AstrBotDevs AstrBot API Endpoint delete path traversal
CVE-2026-102365.530.3SourceCodesterWater Billing Management SystemCWE-266SourceCodester Water Billing Management System User Management Endpoint Users…
CVE-2026-105322.930.1QOS.CH SarllogbackCWE-502Logback deserialization whitelist bypass for Proxy objects
CVE-2026-492705.929.9Apache Software FoundationApache ActiveMQ BrokerCWE-1230Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscri…
CVE-2026-103002.929.8n/aSGLangCWE-617SGLang Inference HTTP Endpoint lora_manager.py assertion
CVE-2026-410144.329.6Apache Software FoundationApache AirflowCWE-862Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints
CVE-2026-467644.329.6Apache Software FoundationApache AirflowCWE-639Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permi…
CVE-2026-452756.528.9nextcloudsecurity-advisoriesCWE-285Nextcloud: Authorization bypass in approval feature allows unauthorized file …
CVE-2026-454263.128.8Apache Software FoundationApache AirflowCWE-863Apache Airflow: Log server JWT authorization bypass via Python lstrip() chara…
CVE-2026-422518.728.7KAMSOFTKS-SOMEDCWE-798Hard-coded credentials in KS-SOMED
CVE-2026-102915.328.5Enderfgaclaw-orchestratorCWE-400Enderfga claw-orchestrator Session Grep Endpoint embedded-server.ts validateR…
CVE-2026-410175.928.1Apache Software FoundationApache AirflowCWE-614Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind…
CVE-2026-423586.527.8Apache Software FoundationApache AirflowCWE-200Apache Airflow: Variable masker depth-limit bypass returns cleartext nested s…
CVE-2026-423606.527.8Apache Software FoundationApache AirflowCWE-200Apache Airflow: Rendered template truncation bypasses nested sensitive-key ma…
CVE-2026-466054.327.9Apache Software FoundationApache ActiveMQ BrokerCWE-285Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete auth…
CVE-2026-372207.527.7n/an/aCWE-617FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_…
CVE-2026-372217.527.7n/an/aCWE-617FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unk…
CVE-2026-4096510.027.6Cloud Foundry Foundationuaa_releaseCWE-200Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a priv…
CVE-2026-372348.227.5n/an/aCWE-400FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by s…
CVE-2026-494918.827.5PixastudioPixa BankCWE-89Pixa Bank 2.0 SQL Injection via agence-ajax.php API
CVE-2018-254288.827.1ParoicielParoicielCWE-89Paroiciel 11.20 SQL Injection via tRecIdListe Parameter
CVE-2018-254338.827.1JoomlaextensionsJE Photo GalleryCWE-89Joomla JE Photo Gallery 1.1 SQL Injection via categoryid
CVE-2018-254348.827.1eliekhouryWP AutoSuggestCWE-89WP AutoSuggest 0.24 SQL Injection via autosuggest.php
CVE-2026-102892.126.7code-projectsHotel and Tourism Reservation SystemCWE-79code-projects Hotel and Tourism Reservation System tour.php cross site scripting
CVE-2026-482086.526.2OTRS AGOTRSCWE-400Denial-of-Service via SVG Rendering in Ticket
CVE-2026-426809.826.0Wasiliy Strecker / ContestGallery developerContest Gallery ProCWE-266WordPress Contest Gallery Pro plugin <= 29.0.1 - Privilege Escalation vulnera…
CVE-2026-86449.125.9IBMWebSphere Application ServerCWE-290IBM WebSphere Application Server is affected by an identity spoofing vulnerab…
CVE-2026-102545.525.7SourceCodesterPet Grooming Management SoftwareCWE-200SourceCodester Pet Grooming Management Software admin file information disclo…
CVE-2026-488799.825.6SergeyAIWUCWE-266WordPress AIWU plugin <= 1.4.17 - Privilege Escalation vulnerability
CVE-2026-86434.124.8Python Packaging AuthoritypipCWE-22pip can extract console_scripts and gui_scripts outside installation directory
CVE-2026-436238.724.5rximicrotarCWE-121microtar 0.1.0 Stack-Based Buffer Overflow via raw_to_header()
CVE-2026-455458.224.6nextcloudsecurity-advisoriesCWE-89Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution
CVE-2026-102905.524.6code-projectsHotel and Tourism Reservation SystemCWE-74code-projects Hotel and Tourism Reservation System GET Parameter tour.php sql…
CVE-2026-453028.224.2milamerparse-nested-form-dataCWE-1321Prototype Pollution in parse-nested-form-data via `__proto__` in FormData fie…
CVE-2026-102555.523.8SourceCodesterPharmacy Sales and Inventory SystemCWE-266SourceCodester Pharmacy Sales and Inventory System ShowForm.php sell_statemen…
CVE-2026-405486.423.6SOPlanningSOPlanningCWE-434Unrestricted Upload of File with Dangerous Type in SOPlanning
CVE-2026-102725.523.4a4m4Student-Management-SystemCWE-266a4m4 Student-Management-System deleteform.php improper authorization
CVE-2026-102805.523.1horizon921mcpilotCWE-918horizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgery
CVE-2026-102205.523.0NousResearchhermes-agentCWE-74NousResearch hermes-agent skills_tool.py skill_view injection
CVE-2026-102215.523.0NousResearchhermes-agentCWE-74NousResearch hermes-agent run_agent.py _compress_context injection
CVE-2026-457227.122.7nextcloudsecurity-advisoriesCWE-89Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort ord…
CVE-2026-102712.122.5a4m4Student-Management-SystemCWE-698a4m4 Student-Management-System Admin Endpoint admin redirect
CVE-2026-102751.322.1n/aOpenSCCWE-119OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer o…
CVE-2026-426796.522.1Mamunur RashidClassified ListingCWE-22WordPress Classified Listing plugin <= 5.3.8 - Arbitrary File Download vulner…
CVE-2026-447406.522.1go-gitgo-billyCWE-674go-billy: Lack of depth and cycle detection in symlink resolution may lead to…
CVE-2026-102835.322.1BotteletDaybydayCRMCWE-287Bottelet DaybydayCRM Setting missing authentication
CVE-2026-405445.122.0SOPlanningSOPlanningCWE-79Stored XSS in SOPlanning
CVE-2026-452826.521.9nextcloudsecurity-advisoriesCWE-284Nextcloud: Logged-in user bypasses share password and download restrictions o…
CVE-2026-102875.521.9SourceCodesterSEO Meta Tag ExtractorCWE-918SourceCodester SEO Meta Tag Extractor index.php get_headers server-side reque…
CVE-2026-452856.421.8nextcloudsecurity-advisoriesCWE-862Nextcloud: Hidden Public Link creation when sharing to a Team External Member
CVE-2026-426829.121.6TomdeverwpForo ForumCWE-862WordPress wpForo Forum plugin <= 3.0.6 - Broken Access Control vulnerability
CVE-2026-452676.521.6nextcloudsecurity-advisoriesCWE-200Nextcloud: Missing permission check for from submissions
CVE-2026-456905.921.5nextcloudsecurity-advisoriesCWE-287Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay
CVE-2026-456915.921.5nextcloudsecurity-advisoriesCWE-287Nextcloud: Bypass of second factor authentication on DAV endpoints
CVE-2026-247518.221.4kiteworksSecure Data FormsCWE-79Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting
CVE-2026-102782.121.3ishayoyoexcel-mcpCWE-22ishayoyo excel-mcp read_file/write_file index.ts path traversal
CVE-2026-491385.321.1HKUDSnanobotCWE-918Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following
CVE-2026-452818.120.9nextcloudsecurity-advisoriesCWE-639Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set …
CVE-2026-247528.220.8kiteworksSecure Data FormsCWE-79Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting
CVE-2026-452864.320.5nextcloudsecurity-advisoriesCWE-200Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint
CVE-2026-102695.320.1decolua9routerCWE-266decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper author…
CVE-2026-102772.120.1j3k0mcp-google-workspaceCWE-266j3k0 mcp-google-workspace MCP Gmail Tool gmail.ts saveToDisk access control
CVE-2026-4513110.019.9CloudPirates-iohelm-chartsCWE-94CloudPirates Open Source Helm Charts: GitHub Actions pull_request_target work…
CVE-2026-102992.019.8code-projectsOnline Hospital Management SystemCWE-99code-projects Online Hospital Management System viewdoctortimings.php resourc…
CVE-2026-405438.819.7SOPlanningSOPlanningCWE-862Missing Authorization in SOPlanning
CVE-2018-254297.119.7ParoicielParoicielCWE-89Paroiciel 11.20 SQL Injection via zProIdPro Parameter
CVE-2018-254307.119.7ParoicielParoicielCWE-89Paroiciel 11.20 SQL Injection via eGeqIdEquipe Parameter
CVE-2018-254317.119.7goFrendiAsgardNo-CMSCWE-89No-Cms 1.0 SQL Injection via order_by Parameter
CVE-2026-103012.119.7itsourcecodeFees Management SystemCWE-79itsourcecode Fees Management System index.php cross site scripting
CVE-2026-491347.519.2steipeteCodexBarCWE-377CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File
CVE-2026-102392.119.2n/aJeecgBootCWE-918JeecgBoot edit WordUtil.addImage server-side request forgery
CVE-2026-102402.119.2n/aJeecgBootCWE-918JeecgBoot test server-side request forgery
CVE-2026-102412.119.2jeecgbootThe server processes these URLsCWE-918jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint de…
CVE-2026-102762.119.2hekmon8Jenkins-server-mcpCWE-918hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index…
CVE-2026-102495.519.1itsourcecodeOnline Blood Bank Management SystemCWE-74itsourcecode Online Blood Bank Management System viewrequest.php sql injection
CVE-2026-102625.519.1code-projectsReal State ServicesCWE-74code-projects Real State Services Login loginuser.php sql injection
CVE-2026-102635.519.1SourceCodesterComputer Repair Shop Management SystemCWE-74SourceCodester Computer Repair Shop Management System manage_product.php sql …
CVE-2026-455435.319.1nextcloudsecurity-advisoriesCWE-552Nextcloud: Deleting a Forms collaborator share leaves uploaded response files…
CVE-2026-491405.319.0HKUDSnanobotCWE-770Nanobot < 0.2.1 Denial of Service via Matrix Media Download Handler
CVE-2026-102222.918.6NousResearchhermes-agentCWE-74NousResearch hermes-agent config.py _sanitize_env_lines injection
CVE-2026-00806.518.5GoogleAndroidCWE-190In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way …
CVE-2026-102642.018.5lharrieswhatsapp-mcpCWE-22lharries whatsapp-mcp Send API Endpoint main.go SendMessageRequest path trave…
CVE-2026-102085.518.2code-projectsOnline Hospital Management SystemCWE-74code-projects Online Hospital Management System login_1.php login_user sql in…
CVE-2026-102255.518.2raisulislamg4student_management_system_by_phpCWE-74raisulislamg4 student_management_system_by_php Login login_check.php sql inje…
CVE-2026-102265.518.2raisulislamg4student_management_system_by_phpCWE-74raisulislamg4 student_management_system_by_php delete.php sql injection
CVE-2026-102275.518.2raisulislamg4student_management_system_by_phpCWE-74raisulislamg4 student_management_system_by_php User Creation add_user_check.p…
CVE-2026-102505.518.2itsourcecodeOnline Blood Bank Management SystemCWE-74itsourcecode Online Blood Bank Management System campsdetails.php sql injection
CVE-2026-102515.518.2itsourcecodeOnline House Rental SystemCWE-74itsourcecode Online House Rental System ajax.php login sql injection
CVE-2026-102525.518.2itsourcecodeOnline House Rental SystemCWE-74itsourcecode Online House Rental System manage_tenant.php sql injection
CVE-2026-102535.518.2itsourcecodeOnline House Rental SystemCWE-74itsourcecode Online House Rental System manage_payment.php sql injection
CVE-2026-102605.518.2CodeAstroOnline Job PortalCWE-74CodeAstro Online Job Portal delete-jobs.php sql injection
CVE-2026-102615.518.2CodeAstroOnline Job PortalCWE-74CodeAstro Online Job Portal application_status.php sql injection
CVE-2026-102372.018.1SourceCodesterWater Billing Management SystemCWE-74SourceCodester Water Billing Management System User Management manage_user sq…
CVE-2026-4513210.017.8CloudPirates-iohelm-chartsCWE-94CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and S…
CVE-2026-102152.117.7DolibarrERP CRMCWE-266Dolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAcces…
CVE-2022-49917.417.1TychonTychonTychon is vulnerable to privilege escalation due to OPENSSLDIR location
CVE-2026-00396.517.0GoogleAndroidCWE-190In multiple functions of ubsan_throwing_runtime.cpp, there is a possible pers…
CVE-2026-00406.517.0GoogleAndroidCWE-190In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way …
CVE-2026-00416.517.0GoogleAndroidCWE-190In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSa…
CVE-2026-00446.517.0GoogleAndroidCWE-190In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way …
CVE-2026-00516.517.0GoogleAndroidCWE-20In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way …
CVE-2026-00526.517.0GoogleAndroidCWE-190In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way …
CVE-2026-101187.816.9Red HatRed Hat Enterprise Linux 10CWE-190Poppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads…
CVE-2026-458106.816.8nextcloudsecurity-advisoriesCWE-639Nextcloud: Propfind requests for file comments allowed to load comments for o…
CVE-2026-105141.916.71Panel-devCordysCRMCWE-791Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting
CVE-2026-102422.116.6itsourcecodeContent Management SystemCWE-74itsourcecode Content Management System instructions.php sql injection
CVE-2026-102962.116.6itsourcecodeFees Management SystemCWE-74itsourcecode Fees Management System ajax.php sql injection
CVE-2026-102482.016.4SourceCodesterPharmacy Sales and Inventory SystemCWE-74SourceCodester Pharmacy Sales and Inventory System Supplier Creation export c…
CVE-2026-426737.516.0Logtivity Activity LogsActivity Logs, User Activity Tracking, Multisite Activity Log from LogtivityCWE-201WordPress Activity Logs, User Activity Tracking, Multisite Activity Log from …
CVE-2026-410138.115.1CloudFoundry Foundationsmb-volume-releaseCWE-88Tenant-controlled comma smuggles arbitrary CIFS mount options
CVE-2026-426729.314.9Wp Directory KitWP Directory KitCWE-89WordPress WP Directory Kit plugin <= 1.5.1 - SQL Injection vulnerability
CVE-2026-457294.314.7thorvgthorvgCWE-476ThorVG: Null pointer dereference in SVG loader causes crash via 6-byte malfor…
CVE-2026-426777.514.3Ben BalterWP Document RevisionsCWE-862WordPress WP Document Revisions plugin <= 3.8.1 - Broken Access Control vulne…
CVE-2026-452786.114.3nextcloudsecurity-advisoriesCWE-601Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL by…
CVE-2026-451576.314.2nextcloudsecurity-advisoriesCWE-284Nextcloud: Valid share tokens allow to access tempory upload files of share o…
CVE-2026-102845.314.0DevaslanPHPproject-managementCWE-266DevaslanPHP project-management Livewire ViewTicket.php doDeleteComment improp…
CVE-2026-102855.314.0DevaslanPHPproject-managementCWE-266DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated imp…
CVE-2026-105335.014.1Red HatRed Hat OpenShift Container Platform 4CWE-770Openshift: openshift: non-admin user can bypass resourcequota and flood etcd …
CVE-2026-102182.114.0nextlevelbuilderGoClawCWE-266nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization
CVE-2026-452644.313.9nextcloudsecurity-advisoriesCWE-284Nextcloud: ACL Rename Permission Bypass in Team Folders Allows Unauthorized F…
CVE-2026-102102.113.7AstrBotDevsAstrBotCWE-74AstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injection
CVE-2026-102232.113.8NousResearchhermes-agentCWE-74NousResearch hermes-agent memory_tool.py _scan_memory_content injection
CVE-2026-102825.313.7BotteletDaybydayCRMCWE-266Bottelet DaybydayCRM DocumentsController.php view improper authorization
CVE-2026-455444.313.0nextcloudsecurity-advisoriesCWE-1230Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive…
CVE-2026-102942.113.0n/aPackageKitCWE-266PackageKit API pk-transaction.c g_file_test improper authorization
CVE-2026-482097.112.6OTRS AGOTRSCWE-79Reflected XSS in authenticated agent context
CVE-2026-488397.111.7VeronaLabsWP StatisticsCWE-79WordPress WP Statistics plugin <= 14.16.6 - Cross Site Scripting (XSS) vulner…
CVE-2026-405468.711.7SOPlanningSOPlanningCWE-89Multiple SQL Injections in SOPlanning
CVE-2026-409896.511.7SpringSpring Cloud FunctionCWE-674Self Routing guard bypassed via function composition
CVE-2026-409906.511.7SpringSpring Cloud FunctionCWE-770Unbounded cache for function definitions
CVE-2026-452834.311.6nextcloudsecurity-advisoriesCWE-287Nextcloud: Files Lock app allows users to lock and unlock files of other users
CVE-2026-102122.111.7AstrBotDevsAstrBotCWE-285AstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization
CVE-2026-102172.111.4nextlevelbuilderGoClawCWE-266nextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges…
CVE-2026-102742.111.4indrasishbanerjeeaem-mcp-serverCWE-918indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMet…
CVE-2026-102652.110.7itsourcecodeContent Management SystemCWE-74itsourcecode Content Management System edit_topic.php sql injection
CVE-2026-102862.110.7CodeAstroPayroll SystemCWE-74CodeAstro Payroll System home_employee.php sql injection
CVE-2026-426787.110.6Liquid Web / StellarWPGiveWPCWE-79WordPress GiveWP plugin <= 4.14.5 - Cross Site Scripting (XSS) vulnerability
CVE-2026-451593.510.5nextcloudsecurity-advisoriesCWE-639Nextcloud: Files drop share links for end-to-end encrypted folders allowed to…
CVE-2026-452663.510.5nextcloudsecurity-advisoriesCWE-284Nextcloud: Unauthorized force-mute from missing permission check when using i…
CVE-2026-309632.710.5projectcapsulecapsuleCWE-20Capsule Namespace Hijacking via subresource
CVE-2026-102342.010.6MettlesendportalCWE-79Mettle sendportal Campaign webview cross site scripting
CVE-2026-102442.010.5SourceCodesterPharmacy Sales and Inventory SystemCWE-79SourceCodester Pharmacy Sales and Inventory System main create_medicine_name …
CVE-2026-102452.010.5SourceCodesterPharmacy Sales and Inventory SystemCWE-79SourceCodester Pharmacy Sales and Inventory System main create_supplier cross…
CVE-2026-481875.710.3OTRS AGOTRSCWE-400Email with special content can lead to DoS
CVE-2026-102052.110.4Metasoft 美特软件MetaCRMCWE-284Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload
CVE-2026-102112.110.4AstrBotDevsAstrBotCWE-285AstrBotDevs AstrBot fs.py _normalize_rw_path authorization
CVE-2026-451552.610.2nextcloudsecurity-advisoriesCWE-639Nextcloud: Private circle can be added to another circle via API
CVE-2026-102092.110.2code-projectsOnline Hospital Management SystemCWE-74code-projects Online Hospital Management System Appointment appointmentdetail…
CVE-2026-102352.110.2CodeAstroIngredients Stock Management SystemCWE-74CodeAstro Ingredients Stock Management System stock_manager.php sql injection
CVE-2026-102562.110.2itsourcecodeContent Management SystemCWE-74itsourcecode Content Management System save_comment.php sql injection
CVE-2026-102572.110.2itsourcecodeContent Management SystemCWE-74itsourcecode Content Management System update_ss_img.php sql injection
CVE-2026-102582.110.2itsourcecodeContent Management SystemCWE-74itsourcecode Content Management System add_sub_topic.php sql injection
CVE-2026-102972.110.2itsourcecodeFees Management SystemCWE-74itsourcecode Fees Management System manage_course.php sql injection
CVE-2026-103022.110.2itsourcecodeFees Management SystemCWE-74itsourcecode Fees Management System manage_fee.php sql injection
CVE-2026-90248.710.0Dassault SystèmesDELMIA Service Process EngineerCWE-79Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience …
CVE-2026-102282.010.0raisulislamg4student_management_system_by_phpCWE-79raisulislamg4 student_management_system_by_php admission_form_check.php cross…
CVE-2026-102462.010.0SourceCodesterPharmacy Sales and Inventory SystemCWE-79SourceCodester Pharmacy Sales and Inventory System main create_medicine_prese…
CVE-2026-102472.010.0SourceCodesterPharmacy Sales and Inventory SystemCWE-79SourceCodester Pharmacy Sales and Inventory System main create_generic_name c…
CVE-2026-488657.19.9ThimPressLearnPressCWE-79WordPress LearnPress plugin <= 4.3.6 - Reflected Cross Site Scripting (XSS) v…
CVE-2026-481895.79.9OTRS AGOTRSCWE-200Bypass DedicatedAgentToCustomerGroups Setting
CVE-2026-426716.59.7PaoloGeoDirectoryCWE-862WordPress GeoDirectory plugin <= 2.8.157 - Broken Access Control vulnerability
CVE-2026-452848.89.3nextcloudsecurity-advisoriesCWE-284Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted…
CVE-2026-457016.99.3sulusuluCWE-327Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens
CVE-2026-451542.68.9nextcloudsecurity-advisoriesCWE-284Nextcloud: Improper Access Control in Collectives
CVE-2026-436258.28.5steipeteCodexBarCWE-319CodexBar < 0.32.0 Session Cookie Exposure via HTTP Redirect
CVE-2026-285114.38.5elabftwelabftwCWE-200elabftw has entry title leakage through autocompletion search
CVE-2026-492675.98.4Apache Software FoundationApache AirflowCWE-295Apache Airflow: No certificate validation on SMTP STARTTLS connections
CVE-2026-236386.58.3kiteworksSecure Data FormsCWE-639Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use…
CVE-2026-84745.38.1StormShieldStormShield Network SecurityCWE-79Possible to run a Cross Site Scripting request on the login API available on …
CVE-2026-355638.88.0Apache Software FoundationApache Directory LDAP APICWE-297Apache Directory LDAP API: LDAP client implementation does not verify if the …
CVE-2026-405495.18.1SOPlanningSOPlanningCWE-352Cross-Site Request Forgery in SOPlanning
CVE-2026-442119.67.9clineclineCWE-306Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
CVE-2026-426757.37.6ThemeficHydra BookingCWE-862WordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerability
CVE-2026-247536.57.2kiteworksSecure Data FormsCWE-639Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use…
CVE-2026-485595.16.8epouponlmsCWE-79Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags
CVE-2026-90484.36.0Revolution SliderSlider RevolutionCWE-863Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (…
CVE-2018-254328.65.9ArmcodeArm WhoisCWE-120Arm Whois 3.11 Buffer Overflow via ASLR Bypass
CVE-2026-85017.85.9SymantecPC Tools Internet SecurityCWE-782CVE-2026-8501
CVE-2025-556645.55.5n/an/aCWE-122A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.…
CVE-2026-93085.45.4MozillaFirefox for iOSCWE-79Arbitrary JavaScript execution in Reader View due to wrong HTML replacement o…
CVE-2026-93095.45.4MozillaFirefox for iOSCWE-79Arbitrary JavaScript execution in internal pages via Reader View JSON-LD inje…
CVE-2018-254356.95.3zeuscartZeusCartCWE-352ZeusCart 4.0 Deactivate Customer Accounts CSRF
CVE-2026-451534.65.0nextcloudsecurity-advisoriesCWE-287Nextcloud: PIN bypass in PassCodeActivity via back button
CVE-2026-90504.35.0Revolution SliderSlider RevolutionCWE-862Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Au…
CVE-2026-247564.34.9kiteworksSecure Data FormsCWE-639Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use…
CVE-2026-389507.84.2n/an/aCWE-502An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrar…
CVE-2025-604815.54.1n/an/aCWE-476A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descri…
CVE-2025-604835.54.1n/an/aCWE-476A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present funct…
CVE-2025-604855.54.1n/an/aCWE-476A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/…
CVE-2026-341934.34.1Imagination TechnologiesGraphics DDKCWE-823GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation…
CVE-2026-481903.54.1OTRS AGOTRSCWE-276Incorrect handling of permissions in External Interface Config Item List module
CVE-2026-481913.54.1OTRS AGOTRSCWE-276Wrong Permission Handling in Document Search Article Meta Filters
CVE-2026-426817.14.0E2Pdf.come2pdfCWE-79WordPress e2pdf plugin <= 1.32.14 - Reflected Cross Site Scripting (XSS) vuln…
CVE-2026-426837.14.0e4jvikwpVikBooking Hotel Booking Engine & PMSCWE-79WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.8 - Cross Site …
CVE-2026-247614.34.0kiteworksSecure Data FormsCWE-639Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use…
CVE-2026-247555.43.6kiteworksSecure Data FormsCWE-639Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through Use…
CVE-2026-247545.43.5kiteworkssecurity-advisoriesCWE-79Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting
CVE-2025-604955.53.3n/an/aCWE-476A segmentation violation in the gf_media_get_color_info function (/media_tool…
CVE-2026-439587.83.2Red HatRed Hat Enterprise Linux 10CWE-121Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial…
CVE-2026-00556.23.2GoogleAndroidCWE-22In createSessionInternal of PackageInstallerService.java, there is a possible…
CVE-2026-426766.53.1myCredmyCredCWE-79WordPress myCred plugin <= 3.0.4 - Cross Site Scripting (XSS) vulnerability
CVE-2025-604865.53.0n/an/aCWE-416A heap use-after-free in the dasher_process function (/filters/dasher.c) of G…
CVE-2026-452773.33.1nextcloudsecurity-advisoriesCWE-200Nextcloud: Information disclosure in Nextcloud Approval app via fileId parame…
CVE-2026-491357.23.0steipeteCodexBarCWE-59CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow
CVE-2026-102301.92.7n/aAssimpCWE-119Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based ove…
CVE-2026-102291.92.6n/aAssimpCWE-119Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflow
CVE-2026-102311.92.5n/aAssimpCWE-119Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based …
CVE-2026-007210.02.4GoogleAndroid XRCWE-285In addInputMethodListener of com.android.server.inputmethod.InputMethodManage…
CVE-2026-00978.02.3GoogleAndroidCWE-693In multiple locations, there is a possible way to bypass user interaction whe…
CVE-2026-102671.92.3janet-langjanetCWE-119janet-lang janet debug.c doframe out-of-bounds
CVE-2026-00466.22.2GoogleAndroidCWE-269In InputInterceptor of Letterbox.java, there is a possible way to trick a use…
CVE-2026-102681.92.2janet-langjanetCWE-189janet-lang janet marsh.c unmarshal_one_fiber integer overflow
CVE-2026-102951.92.2SourceCodesterCustomer Review AppCWE-404SourceCodester Customer Review App review_app.py get_all_reviews denial of se…
CVE-2019-257188.62.0DrägerInfinity Explorer C700CWE-451Dräger Infinity Explorer C700 Privilege Escalation via Kiosk Mode Bypass
CVE-2026-00486.82.0GoogleAndroidCWE-269In hide of WindowState.java, there is a possible way to trick the user into a…
CVE-2026-102321.91.8n/aAssimpCWE-119Assimp ASE File scene.cpp ~aiNode use after free
CVE-2026-00598.01.7GoogleAndroidCWE-122In multiple functions of sdp_discovery.cc, there is a possible way to achieve…
CVE-2026-204536.71.7MediaTek, Inc.MediaTek chipsetCWE-787In geniezone, there is a possible out of bounds write due to a missing bounds…
CVE-2026-255996.31.8Orca EnergyOrca heat pumpCWE-79Missing authentication and clear‑text data transmission affecting Orca heat p…
CVE-2026-102331.91.7n/aAssimpCWE-119Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-bounds
CVE-2026-102981.91.6ggml-orgwhisper.cppCWE-404ggml-org whisper.cpp ggml.c whisper_model_load null pointer dereference
CVE-2026-204557.81.4MediaTek, Inc.MediaTek chipsetCWE-787In geniezone, there is a possible out of bounds write due to a missing bounds…
CVE-2026-00563.31.4GoogleAndroidCWE-120In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to …
CVE-2026-00958.01.3GoogleAndroidCWE-190In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger contro…
CVE-2025-596016.51.3Qualcomm, Inc.SnapdragonCWE-1230Exposure of Sensitive Information Through Metadata in Powerline Communication…
CVE-2026-494332.31.3DeepAIapi.deepai.orgCWE-352DeepAI api.deepai.org/change_user_email CSRF
CVE-2026-204565.51.1MediaTek, Inc.MediaTek chipsetCWE-787In wlan STA driver, there is a possible system crash due to a missing bounds …
CVE-2026-277888.50.9Fsas Technologies Inc.ServerView Agents for WindowsCWE-732Incorrect permission assignment for critical resource issue exists in ServerV…
CVE-2026-323258.50.9Fsas Technologies Inc.ServerView Agents for WindowsCWE-268Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 an…
CVE-2026-240857.20.9Qualcomm, Inc.SnapdragonCWE-121Stack-based Buffer Overflow in Display
CVE-2026-240877.20.9Qualcomm, Inc.SnapdragonCWE-1286Improper Validation of Syntactic Correctness of Input in Kernel
CVE-2026-240897.20.9Qualcomm, Inc.SnapdragonCWE-1286Improper Validation of Syntactic Correctness of Input in Kernel
CVE-2026-240917.20.9Qualcomm, Inc.SnapdragonCWE-1286Improper Validation of Syntactic Correctness of Input in Display
CVE-2026-240927.20.9Qualcomm, Inc.SnapdragonCWE-1286Improper Validation of Syntactic Correctness of Input in Display
CVE-2021-467477.10.9AMDAMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsCWE-1220Insufficient granularity of access control in ASP (AMD Secure Processor) may …
CVE-2026-00755.90.7GoogleAndroidCWE-89In multiple functions, there is a possible way to access the contacts databas…
CVE-2025-596095.50.6Qualcomm, Inc.SnapdragonCWE-126Buffer Over-read in WLAN Host Communication
CVE-2025-224247.80.4GoogleAndroidCWE-20In multiple locations, there is a possible way to reveal images across users …
CVE-2025-224267.80.3GoogleAndroidCWE-284In many functions of ComputerEngine.java, there is a possible way to access U…
CVE-2025-486527.80.3GoogleAndroidCWE-693In performPreInstallChecks of InstallRepository.kt, there is a possible way t…
CVE-2026-00457.80.3GoogleAndroidCWE-693In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bond…
CVE-2026-00777.80.3GoogleAndroidCWE-693In resumeConfigurationDispatch of ActivityRecord.java, there is a possible ba…
CVE-2026-00877.80.3GoogleAndroidCWE-693In approvalLevelForDomainInternal of DomainVerificationService.java, there is…
CVE-2026-00097.80.2GoogleAndroidCWE-269In multiple locations, there is a possible tapjacking due to a logic error in…
CVE-2025-486497.80.2GoogleAndroidCWE-693In multiple locations, there is a possible way to reset user-selected permiss…
CVE-2026-00767.80.2GoogleAndroidCWE-125In validateNode of ResourceTypes.cpp, there is a possible out of bounds read …
CVE-2026-00787.80.2GoogleAndroidCWE-20In setGlobalProxy of DevicePolicyManagerService.java, there is a possible des…
CVE-2026-00887.80.2GoogleAndroidCWE-451In getCallingAppLabel of CertInstaller.java, there is a possible way to hide …
CVE-2025-596116.70.2Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Core Services
CVE-2025-596146.70.2Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Windows Compute
CVE-2025-596126.70.2Qualcomm, Inc.SnapdragonCWE-121Stack-based Buffer Overflow in Windows Compute
CVE-2025-596136.70.2Qualcomm, Inc.SnapdragonCWE-121Stack-based Buffer Overflow in Windows Compute
CVE-2026-204546.40.1MediaTek, Inc.MediaTek chipsetCWE-367In geniezone, there is a possible out of bounds write due to a race condition…
CVE-2026-252768.80.1Qualcomm, Inc.SnapdragonCWE-129Improper Validation of Array Index in Secure Processor
CVE-2025-596047.80.1Qualcomm, Inc.SnapdragonCWE-476NULL Pointer Dereference in SPS Applications
CVE-2025-596057.80.1Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in HLOS
CVE-2025-596067.80.1Qualcomm, Inc.SnapdragonCWE-476NULL Pointer Dereference in HLOS
CVE-2026-01007.80.1GoogleAndroidCWE-122In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a h…
CVE-2026-00866.80.1GoogleAndroidCWE-269In onCreate of DisableSupervisionActivity.kt, there is a possible way to dele…
CVE-2026-252778.80.1Qualcomm, Inc.SnapdragonCWE-120Buffer Copy Without Checking Size of Input in Secure Processor
CVE-2026-00435.50.1GoogleAndroidCWE-190In multiple functions of ubsan_throwing_runtime.cpp, there is a possible pers…
CVE-2026-285814.00.1GoogleAndroidCWE-476In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possi…
CVE-2026-00937.80.1GoogleAndroidCWE-451In multiple locations, there is a possible misleading UI due to obfuscation. …
CVE-2026-00967.80.1GoogleAndroidCWE-451In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick …
CVE-2026-285807.80.1GoogleAndroidCWE-120In multiple functions, there is a possible desync in persistence due to an in…
CVE-2026-00615.90.1GoogleAndroidCWE-1021In multiple functions of WindowState.java, there is a possible way to trick a…
CVE-2025-323487.80.1GoogleAndroidCWE-863In multiple locations, there is a possible background activity launch due to …
CVE-2025-485707.80.1GoogleAndroidCWE-441In multiple functions of PipTaskOrganizer.java, there is a possible way to la…
CVE-2026-00367.80.1GoogleAndroidCWE-1021In startAnimation of StageCoordinator.java, there is a possible tapjacking is…
CVE-2025-486163.30.1GoogleAndroidIn multiple functions of KeyguardViewMediator.java , there is a possible way …
CVE-2026-240888.20.1Qualcomm, Inc.SnapdragonCWE-306Missing Authentication for Critical Function in Boot
CVE-2026-00997.80.0GoogleAndroidCWE-273In onNullBinding of HostEmulationManager.java, there is a possible way to lau…
CVE-2026-00185.50.1GoogleAndroidCWE-20In multiple functions of AccessibilityManagerService.java, there is a possibl…
CVE-2026-00425.50.1GoogleAndroidCWE-400In multiple functions of ubsan_throwing_runtime.cpp, there is a possible pers…
CVE-2026-00605.50.1GoogleAndroidIn updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, the…
CVE-2026-00675.50.1GoogleAndroidIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible way …
CVE-2026-00695.50.1GoogleAndroidCWE-400In verifySignature of ApkChecksums.java, there is a possible way to cause a c…
CVE-2026-00705.50.1GoogleAndroidCWE-20In multiple functions of DevicePolicyManagerService.java, there is a possible…
CVE-2026-00745.50.1GoogleAndroidCWE-400In getPreferredSize of LauncherProcessImageListener.kt, there is a possible d…
CVE-2026-00795.50.1GoogleAndroidCWE-190In multiple functions of ubsan_throwing_runtime.cpp, there is a possible pers…
CVE-2026-00855.50.1GoogleAndroidCWE-20In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to…
CVE-2026-252587.80.0Qualcomm, Inc.SnapdragonCWE-125Out-of-bounds Read in DSP Service
CVE-2026-252597.80.0Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in DSP Service
CVE-2025-264187.80.0GoogleAndroidCWE-862In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a p…
CVE-2026-00987.80.0GoogleAndroidCWE-441In getCallingPackageName of Shared.java, there is a possible way to bypass ac…
CVE-2025-486485.50.0GoogleAndroidCWE-400In isSameApp of NotificationManagerService.java, there is a possible persiste…
CVE-2026-00503.30.0GoogleAndroidCWE-269In handleBondStateChanged of AdapterService.java, there is a possible sensiti…
CVE-2026-00897.80.0GoogleAndroidCWE-269In multiple functions of PackageInstallerService.java, there is a possible wa…
CVE-2026-00917.80.0GoogleAndroidCWE-269In multiple locations, there is a possible way to execute code in the launche…
CVE-2026-285777.80.0GoogleAndroidCWE-1021In addWindow of WindowManagerService.java, there is a possible tapjacking iss…
CVE-2026-285785.50.0GoogleAndroidCWE-20In multiple functions of DevicePolicyManagerService.java, there is a possible…
CVE-2026-256006.40.0Trac d.o.o.PDBMCWE-798Credential Exposure Vulnerability in Trac PDBM
CVE-2026-00163.30.0GoogleAndroidCWE-269In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there …
CVE-2026-285863.30.0GoogleAndroidCWE-269In multiple functions of AppOpsService.java, there is a possible missing perm…
CVE-2026-240907.10.0Qualcomm, Inc.SnapdragonCWE-306Missing Authentication for Critical Function in HLOS
CVE-2026-00947.80.0GoogleAndroidCWE-451In getApplicationLabel of KeyChainActivity.java, there is a possible way to t…
CVE-2025-596106.40.0Qualcomm, Inc.SnapdragonCWE-367Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver
CVE-2026-252607.00.0Qualcomm, Inc.SnapdragonCWE-367Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-01 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.