boxscore/security
Tuesday, June 2, 2026 · all times UTC← 2026-06-01 · archive · 2026-06-03 →

226 CVEs published June 2, 2026: 14 critical, 85 high, 97 medium, 29 low; 2 in KEV; 25 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 201 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published603497510332563
KEV catalog size1670

197 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux29687961726912730.37.8.0013-59
microsoft1491433291020378275.57.8.0045+1
google612351114961117452.18.0.0021+61
red hat569830274400.07.3.0035+5
apple04701227193714.96.2.00340
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco013312096861.58.6.12470
ivanti16020033466.78.8.5751+1
checkpoint060330300.06.5.03380
fortinet06130028350.07.9.43300
zyxel2300301100.06.5.0017+2
f50320007133.39.2.09960
ubiquiti031200400.08.8.00680
broadcom02000042100.0.19900
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache30626262724011.67.2.0055+30
mozilla41033401300.07.4.0035+4
gitlab0901604222.24.3.00320
drupal0511305120.05.1.00260
docker140400100.08.8.0022+1
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm5541326150700.07.5.0031+5
oracle128815404013.68.1.0027+1
progress591710900.07.5.0036+5
solarwinds14110011375.08.7.7758+1
adobe04010075375.08.6.27760
veeam031200400.08.6.00400
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology01823103000.05.6.00250
d-link25031026120.07.4.0059+2
siemens120110100.07.3.0026+1
hitachi energy020020000.05.7.00140
hikvision01000021100.01.00000
dahua000000200
qnap000000800
schneider electric000000100
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax051032019100.07.4.00590
concrete cms044191321000.05.7.00150
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
sourcecodester1537001126000.02.1.0025+15
nvidia23582070000.07.8.0029+2
totolink03502609000.08.9.01910

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4684010.0.0073
Most disclosures (vendor)
VendorCVEs
linux581
google229
microsoft171
ibm54
apache51
edimax51
red hat46
concrete cms44
open ises44
helmholz42
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google5
ivanti4
synacor4
adobe3
fortinet3
linux3
smartertools3
Most-affected ecosystems
EcosystemAdvisories
Maven23
Packagist7
PyPI3
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171658
CVE-2021-27102Accellion2021-11-171658
CVE-2021-27101Accellion2021-11-171658
CVE-2021-27103Accellion2021-11-171658
CVE-2021-21017Adobe2021-11-171658
CVE-2021-28550Adobe2021-11-171658
CVE-2021-42013Apache2021-11-171658
CVE-2021-41773Apache2021-11-171658
CVE-2021-30858Apple2021-11-171658
CVE-2021-30860Apple2021-11-171658

Transactions

EXPLOIT PUBLISHEDCVE-2026-3198 (mlflow/mlflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-32625 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-3514 (prefecthq/prefect). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-35482 (alfio-event alf.io). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42073 (Gitlawb openclaude). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42074 (Gitlawb openclaude). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44653 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44654 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45676 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45678 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45679 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45680 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45681 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45682 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45683 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45684 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45685 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45686 (open-telemetry opentelemetry-ebpf-instrumentation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48594 (elixir-tesla tesla). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48595 (elixir-tesla tesla). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48596 (elixir-tesla tesla). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49443 (goauthentik authentik). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49448 (goauthentik authentik). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5422 (jupyter/jupyter). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-7299 (Appsmith). Public exploit reference added.

DUE DATE PASSEDCVE-2026-0257 (Palo Alto Networks PAN-OS). CISA remediation deadline was June 1, 2026; still in catalog.

Yesterday's Results

226 CVEs published. 25 box scores, 201 table rows — nothing truncated.

CVE-2022-0492AWAITING ENRICHMENT
Linux Kernel
  CVSS   EPSS    %ile   KEV
  —      .0553   92.1   YES
AFFECTED
  Product  Versions     Fixed
  Kernel   unspecified  —
TIMELINE
  Jun 2   Added to CISA KEV, due Jun 5
  Jun 2   Published
0 references · KEV due June 5, 2026
Google Android — Android Framework
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   N  U  H  H  H    8.4   .0171   75.5   YES
AFFECTED
  Product  Versions   Fixed
  Android  16-qpr2 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 2   Added to CISA KEV, due Jun 5
  Jun 2   Published (CNA: google_android)
CWE-190 · CNA: google_android · 2 references · NVD status: Analyzed · KEV due June 5, 2026
danny-avila LibreChat — LibreChat Exfiltrates Server Secrets via MCP Server URL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  N    9.6   .0294   86.0     —
AFFECTED
  Product    Versions       Fixed
  LibreChat  < 0.8.4-rc1 –  —
TIMELINE
  Mar 12  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: GitHub_M)
CWE-200 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0138   69.9     —
AFFECTED
  Product                                                                                               Versions     Fixed
  ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup  unspecified  —
TIMELINE
  Mar 28  Reserved by CNA
  Jun 2   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 2 references · NVD status: Deferred
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0126   67.1     —
AFFECTED
  Product                                                      Versions  Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  6.0.0 –   —
TIMELINE
  May 9   Reserved by CNA
  Jun 2   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · 8 references · NVD status: Deferred
elunez eladmin Application Deployment App.java command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0107   62.0     —
AFFECTED
  Product  Versions  Fixed
  eladmin  2.0 –     —
TIMELINE
  Jun 1   Reserved by CNA
  Jun 2   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 6 references · NVD status: Deferred
maziyarpanahi openmed — OpenMed < 1.5.2 Remote Code Execution via PII Model Loading
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0092   57.2     —
AFFECTED
  Product  Versions     Fixed
  openmed  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jun 2   Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 4 references · NVD status: Deferred
n/a n/a — A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmwar…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0072   51.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 2   Published (CNA: mitre)
CWE-22 · CNA: mitre · 1 reference · NVD status: Modified
Mozilla Firefox — JIT miscompilation in the JavaScript Engine: JIT component
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  N  N  L    4.3   .0072   50.9     —
AFFECTED
  Product  Versions     Fixed
  Firefox  unspecified  151.0.3
TIMELINE
  Jun 2   Reserved by CNA
  Jun 2   Published (CNA: mozilla)
CWE-843, CWE-733 · CNA: mozilla · 5 references · NVD status: Modified
jhorowitz Content Visibility for Divi Builder — Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0071   50.5     —
AFFECTED
  Product                              Versions     Fixed
  Content Visibility for Divi Builder  unspecified  —
TIMELINE
  Feb 3   Reserved by CNA
  Jun 2   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · 3 references · NVD status: Deferred
Spacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET Remoting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0066   48.8     —
AFFECTED
  Product   Versions  Fixed
  Sentinel  10.5.0 –  —
TIMELINE
  Jan 5   Reserved by CNA
  Jun 2   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 3 references · NVD status: Deferred
AWS Kiro IDE — Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    8.6   .0066   48.7     —
AFFECTED
  Product   Versions     Fixed
  Kiro IDE  unspecified  —
TIMELINE
  Jun 1   Reserved by CNA
  Jun 2   Published (CNA: AMZN)
CWE-732 · CNA: AMZN · 2 references · NVD status: Analyzed
n/a n/a — A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpo…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0060   45.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jun 2   Published (CNA: mitre)
CWE-120 · CNA: mitre · 1 reference · NVD status: Modified
Go standard library crypto/x509 — Inefficient candidate hostname parsing in crypto/x509
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  L  H    6.5   .0059   45.5     —
AFFECTED
  Product      Versions     Fixed
  crypto/x509  unspecified  —
TIMELINE
  Feb 17  Reserved by CNA
  Jun 2   Published (CNA: Go)
CWE-606 · CNA: Go · 72 references · NVD status: Awaiting Analysis
Go standard library mime — Quadratic complexity in WordDecoder.DecodeHeader in mime
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0056   44.0     —
AFFECTED
  Product  Versions     Fixed
  mime     unspecified  —
TIMELINE
  Apr 28  Reserved by CNA
  Jun 2   Published (CNA: Go)
CWE-407 · CNA: Go · 4 references · NVD status: Awaiting Analysis
Simple SA Wirtualna Uczelnia — Server-Side Template Injection (SSTI) in Wirtualna Uczelnia
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0056   43.8     —
AFFECTED
  Product             Versions     Fixed
  Wirtualna Uczelnia  unspecified  —
TIMELINE
  Mar 31  Reserved by CNA
  Jun 2   Published (CNA: CERT-PL)
CWE-1336 · CNA: CERT-PL · 2 references · NVD status: Deferred
Gitlawb openclaude — OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0054   43.1     —
AFFECTED
  Product     Versions   Fixed
  openclaude  < 0.5.1 –  —
TIMELINE
  Apr 23  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: GitHub_M)
CWE-284, CWE-306 · CNA: GitHub_M · 3 references · NVD status: Analyzed
n/a n/a — A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interfac…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0052   41.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jun 2   Published (CNA: mitre)
CWE-120 · CNA: mitre · 1 reference · NVD status: Modified
sayan365 student-management-system improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0050   40.5     —
AFFECTED
  Product                    Versions  Fixed
  student-management-system  n/a –     —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 2   Published (CNA: VulDB)
CWE-287 · CNA: VulDB · 12 references · NVD status: Deferred
SolarWinds Web Help Desk Denial-of-Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0049   40.1     —
AFFECTED
  Product        Versions                            Fixed
  Web Help Desk  2026.1 and all previous versions –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jun 2   Published (CNA: SolarWinds)
CWE-770 · CNA: SolarWinds · 2 references · NVD status: Analyzed
elixir-tesla tesla — Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   N   N    8.2   .0049   39.8     —
AFFECTED
  Product  Versions                                    Fixed
  tesla    1.4.0 –                                     —
  tesla    2d937d5813d7cda5cd726f41824985fb655c920f –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: EEF)
CWE-178 · CNA: EEF · 4 references · NVD status: Analyzed
prefecthq prefecthq/prefect — Authentication Bypass in prefecthq/prefect
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0048   39.1     —
AFFECTED
  Product            Versions       Fixed
  prefecthq/prefect  unspecified –  —
TIMELINE
  Mar 4   Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: @huntr_ai)
CWE-863 · CNA: @huntr_ai · 2 references · NVD status: Analyzed
Progress Software Sitefinity — CWE-20: Improper Input Validation in web services in Progress Sitefinity
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  N    8.1   .0047   38.7     —
AFFECTED
  Product     Versions  Fixed
  Sitefinity  14.1.0 –  —
TIMELINE
  Apr 27  Reserved by CNA
  Jun 2   Published (CNA: ProgressSoftware)
CWE-20 · CNA: ProgressSoftware · 1 reference · NVD status: Analyzed
open-telemetry opentelemetry-ebpf-instrumentation — OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   38.2     —
AFFECTED
  Product                             Versions             Fixed
  opentelemetry-ebpf-instrumentation  >= 0.1.0, < 0.9.0 –  —
TIMELINE
  May 13  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: GitHub_M)
CWE-20, CWE-248, CWE-704 · CNA: GitHub_M · 2 references · NVD status: Analyzed
elixir-tesla tesla — Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0046   37.7     —
AFFECTED
  Product  Versions                                    Fixed
  tesla    0.6.0 –                                     —
  tesla    5bd90bb5cf0d15e375edc2a66fa322292940fce2 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: EEF)
CWE-409 · CNA: EEF · 4 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-71989.836.9Progress SoftwareSitefinityCWE-284CWE-284: Improper Access Control in web services in Progress Sitefinity
CVE-2026-106228.236.8CollibraCollibra Platform (on-prem)CVE-2026-10622
CVE-2026-73127.536.7Progress SoftwareSitefinityCWE-522CWE‑522: Insufficiently Protected Credentials in web services in Progress Sit…
CVE-2026-54228.136.4jupyterjupyter/jupyterCWE-23Path Traversal in jupyter/jupyter
CVE-2026-467186.536.3Apache Software FoundationApache CalciteCWE-470Apache Calcite: A user-controled model can load arbitrary classes, leading to…
CVE-2026-106505.535.7warmcatlibwebsocketsCWE-400warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource co…
CVE-2026-50769.834.9armemberARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupCWE-287ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthentica…
CVE-2026-53858.434.8glpi-projectglpiCWE-79GLPI 11.0.0 - Stored XSS in knowledge base
CVE-2026-422118.134.7remix-runreact-routerCWE-502React Router's vendored turbo-stream v2 allows arbitrary constructor invocati…
CVE-2025-534408.134.6AxiomthemesConfidantCWE-98WordPress Confidant theme <= 1.4 - Local File Inclusion vulnerability
CVE-2025-587058.134.6AxiomthemesCraftiCWE-98WordPress Crafti theme <= 1.12 - Local File Inclusion vulnerability
CVE-2026-494489.833.7goauthentikauthentikCWE-287authentik: SourceStage bypass via empty POST
CVE-2026-106217.533.4CollibraCollibra Platform (SaaS)CVE-2026-10621
CVE-2026-106175.533.2nextlevelbuilderGoClawCWE-287nextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing auth…
CVE-2026-491438.732.3browserstackbrowserstack-runnerCWE-94BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler
CVE-2026-488628.231.5elixir-mintmintCWE-770Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMI…
CVE-2026-497548.231.5elixir-mintmintCWE-770HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
CVE-2026-306497.330.8n/an/aCWE-121Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remot…
CVE-2026-425075.330.1Go standard librarynet/textprotoArbitrary inputs are included in errors without any escaping in net/textproto
CVE-2026-428499.328.6goauthentikauthentikCWE-79authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover
CVE-2026-456867.528.5open-telemetryopentelemetry-ebpf-instrumentationCWE-190OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can cra…
CVE-2026-106912.128.5wonderwhy-erDesktopCommanderMCPCWE-400wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos
CVE-2026-106118.228.4mispmispCWE-287OTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authe…
CVE-2026-72018.827.8Progress SoftwareSitefinityCWE-639CWE-639: Authorization Bypass Through User-Controlled Key in web services in …
CVE-2026-455545.327.3zauberzeugniceguiCWE-248NiceGUI: Unauthenticated log-flood DoS via trailing slash on ESM and per-comp…
CVE-2026-456787.527.2open-telemetryopentelemetry-ebpf-instrumentationCWE-20OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malfor…
CVE-2026-72995.427.1AppsmithAppsmithCWE-79CVE-2026-7299
CVE-2025-587078.126.6AxiomthemesSpinCWE-98WordPress Spin theme <= 1.8 - Local File Inclusion vulnerability
CVE-2025-588978.126.6AxiomthemesFermentioCWE-98WordPress Fermentio theme <= 1.5.0 - Local File Inclusion vulnerability
CVE-2025-688868.126.6androThemesCookiteerCWE-98WordPress Cookiteer theme <= 1.4.8 - Local File Inclusion vulnerability
CVE-2026-395528.126.3Code Supply Co.BlueprintCWE-98WordPress Blueprint theme < 1.1.5 - Local File Inclusion vulnerability
CVE-2026-395538.126.3Select-ThemesWaveRideCWE-98WordPress WaveRide theme <= 1.4 - Local File Inclusion vulnerability
CVE-2026-389679.826.1n/an/aCWE-113CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection v…
CVE-2025-693698.125.5AxiomthemesRacquetCWE-98WordPress Racquet theme <= 1.12.0 - Local File Inclusion vulnerability
CVE-2026-357166.325.0n/an/aCWE-121A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8…
CVE-2026-456807.524.6open-telemetryopentelemetry-ebpf-instrumentationCWE-400OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can…
CVE-2026-73134.924.7Progress SoftwareSitefinityCWE-522CWE‑522: Insufficiently Protected Credentials in web services in Progress Sit…
CVE-2026-414124.924.5alfio-eventalf.ioCWE-22alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Exten…
CVE-2026-106075.524.0n/aDedeCMSCWE-74DedeCMS flink.php dede_htmlspecialchars sql injection
CVE-2026-106922.123.7johnhuang316code-index-mcpCWE-400johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos
CVE-2026-395508.123.4Elated-ThemesAperitifCWE-502WordPress Aperitif theme <= 1.6 - PHP Object Injection vulnerability
CVE-2026-395518.123.4Elated-ThemesTöbelCWE-502WordPress Töbel theme <= 1.8.1 - PHP Object Injection vulnerability
CVE-2026-50746.523.5armemberARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupCWE-89ARMember Premium <= 7.3.1 - Authenticated (Subscriber+) SQL Injection via 'sS…
CVE-2026-106085.523.4n/aDedeCMSCWE-74DedeCMS carbuyaction.php RemoveXSS sql injection
CVE-2026-18717.123.1TP-Link Systems Inc.Tapo C200 v5CWE-121Authenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200
CVE-2026-389785.323.1n/an/aCWE-113transmission through 4.1.1 was found to have a clickjacking weakness in the b…
CVE-2025-533458.822.8ThimPressThim CoreCWE-862WordPress Thim Core plugin <= 2.3.3 - Arbitrary Plugin Installation vulnerabi…
CVE-2026-485978.222.7elixir-teslateslaCWE-770Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
CVE-2026-107017.522.7MozillaFirefoxCWE-119Incorrect boundary conditions in the Graphics: Text component
CVE-2026-497536.322.7elixir-mintmintCWE-444HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing
CVE-2025-580247.522.6UnboundStudioAccordion FAQCWE-98WordPress Accordion FAQ Plugin <= 2.2.1 - Local File Inclusion Vulnerability
CVE-2026-499436.322.6NICBIRDCWE-121CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buf…
CVE-2026-426849.322.4AhmadWP Job PortalCWE-89WordPress WP Job Portal plugin <= 2.5.1 - SQL Injection vulnerability
CVE-2026-423427.522.5remix-runreact-routerCWE-400React Router vulnerable to DoS via unbounded path expansion in __manifest end…
CVE-2026-494438.822.4goauthentikauthentikCWE-287authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are …
CVE-2026-340777.521.9remix-runreact-routerCWE-770React Router vulnerable to Denial of Service via reflected user input in sing…
CVE-2026-411154.321.2Apache Software FoundationApache KafkaCWE-285Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API
CVE-2026-456815.921.2open-telemetryopentelemetry-ebpf-instrumentationCWE-125OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffe…
CVE-2026-349075.121.0Simple SAWirtualna UczelniaCWE-79Reflected Cross-Site Scripting (XSS) in Wirtualna Uczelnia
CVE-2024-140368.720.9DrägerCoreCWE-400Dräger Core 1.0.5 Denial of Service via Malformed SDC Message
CVE-2026-354829.120.7alfio-eventalf.ioCWE-863alf.io has an Authenticated RCE via Extension Script Sandbox Escape
CVE-2026-446536.520.0danny-avilaLibreChatCWE-201LibreChat Shared MCP Server View Leaks Decrypted Admin Secrets
CVE-2025-532099.819.9ThemeisleMasteriyo LMS PROCWE-266WordPress Masteriyo LMS PRO plugin <= 2.20.0 - Privilege Escalation Vulnerabi…
CVE-2026-403146.919.6NamelessMCNamelessCWE-862NamelessMC: Reactions on private or blocking profile posts can be read and mo…
CVE-2026-106205.519.6code-projectsStudent Admission SystemCWE-74code-projects Student Admission System index.php sql injection
CVE-2026-401087.119.0glpi-projectglpiCWE-79GLPI Vulnerable to Stored XSS in ITIL Costs
CVE-2026-105495.319.0YandexYandex DatabaseCWE-280Privilege escalation in Yandex Database
CVE-2026-407807.518.9Liquid Web / StellarWPBookItCWE-288WordPress BookIt plugin < 2.5.4.1 - Broken Authentication vulnerability
CVE-2026-486825.918.9n/an/aCWE-125FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in …
CVE-2026-446545.718.5danny-avilaLibreChatCWE-863LibreChat: Shared-agent editor can globally delete owner's file records — bre…
CVE-2026-357176.318.0n/an/aCWE-121A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD…
CVE-2026-37226.417.5arunbasillalAuto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)CWE-79Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Ti…
CVE-2026-395558.117.2Elated-ThemesAskkaCWE-502WordPress Askka theme <= 1.3.1 - PHP Object Injection vulnerability
CVE-2026-455537.517.2zauberzeugniceguiCWE-200NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured…
CVE-2026-106065.517.1n/aDedeCMSCWE-74DedeCMS Feedback feedback.php TrimMsg sql injection
CVE-2026-426707.516.9Etoile Web Design IncorporatedFive Star Restaurant ReservationsCWE-862WordPress Five Star Restaurant Reservations plugin <= 2.7.14 - Payment Bypass…
CVE-2026-450806.916.5Aiven-OpenklawCWE-200Klaw: Improper Access Control Allows Disclosure of Password Hash
CVE-2026-106612.116.3ahujasidblender-mcpCWE-74ahujasid blender-mcp server.py open injection
CVE-2026-36204.416.1takienWord ReplacerCWE-20Word Replacer <= 0.4 - Authenticated (Administrator+) Stored Cross-Site Scrip…
CVE-2026-31986.515.8mlflowmlflow/mlflowCWE-284Improper Access Control in mlflow/mlflow
CVE-2026-40806.415.7zeshanbEasy CartCWE-79Easy Cart <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting v…
CVE-2026-106242.115.6SourceCodesterHuman Resource ManagementCWE-99SourceCodester Human Resource Management Employee View detailview.php resourc…
CVE-2026-40816.415.5jhdscriptZeM STLCWE-79ZeM STL <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…
CVE-2021-44796.315.5DrägerAtlan A350CWE-1286Dräger Atlan A350 1.00 <= 1.01 DoS via Medibus Interface
CVE-2026-98448.815.3Roche Diagnosticsnavify Digital PathologyCWE-1392Vulnerability in navify® Digital Pathology
CVE-2026-105672.015.01Panel-devCordysCRMCWE-791Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross s…
CVE-2026-82937.514.8UnknownReally Simple SecurityCWE-287Really Simple Security < 9.5.10.1 - Authentication Bypass via Two-Factor OTP …
CVE-2019-257236.314.9DrägerPerseus A500CWE-1286Dräger Perseus A500 2.00-2.02 DoS via Medibus Interface
CVE-2026-354475.314.8NamelessMCNamelessCWE-201NamelessMC: Private or blocking profile pages can be bypassed with direct POS…
CVE-2026-443672.714.8Aiven-OpenklawCWE-20Klaw: user lockout due to case sensitivity inconsistency
CVE-2026-350496.514.6wireappwire-iosCWE-20wire-ios has Persistent Remote DoS via Integer Underflow
CVE-2026-354435.314.7NamelessMCNamelessCWE-862NamelessMC: Forum reactions bypass the "view own topics only" restriction
CVE-2026-405715.314.7NamelessMCNamelessCWE-862NamelessMC: Reactions on private or blocking profile posts can be modified wi…
CVE-2026-491206.313.9medplummedplumCWE-918Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint
CVE-2026-105582.113.6SourceCodesterPizzafy Ecommerce SystemCWE-73SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVE-2026-105592.113.6SourceCodesterPizzafy Ecommerce SystemCWE-73SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVE-2026-106622.113.6ahujasidblender-mcpCWE-918ahujasid blender-mcp ZIP File server.py requests.get server-side request forgery
CVE-2026-105832.013.6nextlevelbuilderGoClawCWE-918nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import serve…
CVE-2026-333987.113.4NamelessMCNamelessCWE-285Authenticated users can read hidden forum posts through `/forum/get_quotes`
CVE-2026-89936.513.5Ditec a.s.D.Launcher 2CWE-74Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Discl…
CVE-2026-305866.113.3n/an/aCWE-79Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote…
CVE-2026-105651.313.3n/aOpen5GSCWE-362Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition
CVE-2026-106902.112.9wonderwhy-erDesktopCommanderMCPCWE-918wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl serv…
CVE-2026-420736.512.6GitlawbopenclaudeCWE-352OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
CVE-2026-456796.511.7open-telemetryopentelemetry-ebpf-instrumentationCWE-117OpenTelemetry eBPF Instrumentation: Redis error text is exported in span stat…
CVE-2026-352022.311.8pterodactylpanelCWE-367Pterodactyl has a database resource limit bypass via race condition in Client…
CVE-2026-105291.911.5westboyCicadasCMSCWE-79westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cros…
CVE-2026-491447.111.2browserstackbrowserstack-runnerCWE-22BrowserStack Runner 0.9.5 Path Traversal via _default HTTP Handler
CVE-2026-14516.111.2federicocarrararognoneCWE-79rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'a' Parameter
CVE-2026-24256.111.2den-mediahiWeb Migration SimpleCWE-79hiWeb Migration Simple <= 2.0.0.1 - Reflected Cross-Site Scripting via 'new_d…
CVE-2026-74214.411.3passeumPasseum TicketingCWE-79Passeum Ticketing <= 1.0 - Authenticated (Administrator+) Stored Cross-Site S…
CVE-2026-426547.111.1WP SwingsWallet System for WooCommerceCWE-288WordPress Wallet System for WooCommerce plugin <= 2.7.5 - Broken Authenticati…
CVE-2026-319427.110.9danny-avilaLibreChatCWE-862LibreChat has IDOR in API Keys Management that allows any authenticated user …
CVE-2026-106162.110.9nextlevelbuilderGoClawCWE-862nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTask…
CVE-2026-14506.110.7federicocarrararognoneCWE-79rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'mode' Parameter
CVE-2019-257175.310.5DrägerInfinity DeltaCWE-538Dräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File Disclosure
CVE-2026-426697.510.4EventPrimeEventPrimeCWE-862WordPress EventPrime plugin <= 4.3.2.0 - Broken Access Control vulnerability
CVE-2025-50855.510.3ariyesWP Nano ADCWE-79wp-nano-ad <= 1.31 - Authenticated (Administrator+) Stored Cross-Site Scripti…
CVE-2026-105812.110.4n/aDedeCMSCWE-918DedeCMS download.php base64_decode server-side request forgery
CVE-2026-105682.110.2itsourcecodeFees Management SystemCWE-74itsourcecode Fees Management System manage_payment.php sql injection
CVE-2026-497825.410.0ElementorElementor Website BuilderCWE-862WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control v…
CVE-2026-92344.39.9ntbykJTL-Connector for WooCommerceCWE-862JTL-Connector for WooCommerce <= 2.4.1 - Missing Authorization to Authenticat…
CVE-2026-17848.89.4Red HatRed Hat OpenShift Container Platform 4.13CWE-15Ose-cluster-ingress-operator: remote code execution through haproxy configura…
CVE-2026-419185.99.4SiemensRUGGEDCOM RST2428PCWE-525A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (Al…
CVE-2019-257227.29.3DrägerSC 6002XLCWE-798Dräger SC Monitoring Devices Hard-coded Credentials and DoS
CVE-2026-23826.49.1frankpwFPW Category ThumbnailsCWE-79FPW Category Thumbnails <= 1.9.5 - Authenticated (Subscriber+) Stored Cross-S…
CVE-2026-415696.99.0goauthentikauthentikCWE-601authentik: WS-Federation wreply origin bypass can exfiltrate signed login res…
CVE-2026-485982.18.9elixir-teslateslaCWE-116CRLF injection in Tesla.Multipart disposition parameters allows multipart par…
CVE-2026-332454.78.8remix-runreact-routerCWE-79React Router vulnerable to XSS in unstable RSC redirect handling via javascri…
CVE-2019-257217.18.7DrägerInfinity M300CWE-400Dräger Infinity M300 VG2.3.1 Network-Based Denial of Service
CVE-2025-533025.38.6Anton ShevchukConstructorCWE-862WordPress Constructor theme <= 1.6.5 - Broken Access Control Vulnerability
CVE-2026-485962.18.6elixir-teslateslaCWE-113CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header…
CVE-2026-322504.38.3NamelessMCNamelessCWE-79NamelessMC has Reflected Cross-Site Scripting (XSS) in id parameter of /index…
CVE-2026-95905.38.3DevolutionsServerCWE-284Improper access control in the permission validation component in Devolutions…
CVE-2026-101004.48.2pattihisSimple Custom Login PageCWE-79Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site …
CVE-2026-472018.58.0goauthentikauthentikCWE-347authentik: XML Signature Wrapping in SAML Source ACS allows authentication as…
CVE-2026-88856.48.0marcqueraltDeMomentSomTres ShortcodesCWE-79DeMomentSomTres Shortcodes <= 1.1.1 - Authenticated (Contributor+) Stored Cro…
CVE-2026-349937.37.7aio-libsaiohttpCWE-502AIOHTTP Vulnerable to Deserialization of Untrusted Data
CVE-2026-258618.27.6QloAppsQloAppsCWE-916QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php
CVE-2026-106882.07.6ahujasidblender-mcpCWE-74ahujasid blender-mcp server.py execute_blender_code code injection
CVE-2019-257247.17.2DrägerInfinity M300CWE-400Dräger Infinity M300 VG2.x Network-Based Denial of Service
CVE-2026-106297.47.2VerizonVoLTECVE-2026-10629
CVE-2025-527666.57.2PrinteersPrinteers Print & ShipCWE-862WordPress Printeers Print & Ship plugin <= 1.17.0 - Broken Access Control vul…
CVE-2026-456833.87.2open-telemetryopentelemetry-ebpf-instrumentationCWE-127OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memor…
CVE-2026-456845.36.9open-telemetryopentelemetry-ebpf-instrumentationCWE-126OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and…
CVE-2026-242217.86.7NVIDIANVTabularCWE-502NVIDIA NVTabular contains a vulnerability where an attacker could cause impro…
CVE-2026-242377.86.7NVIDIANVTabularCWE-502NVIDIA NVTabular contains a vulnerability where an attacker could cause impro…
CVE-2025-156537.06.7DrägerZeus IECWE-668Dräger Zeus IE Anesthesia Workstation USB Interface Privilege Escalation
CVE-2026-415776.96.7goauthentikauthentikCWE-345authentik: SAML source does not validate Conditions, timing, or audience on a…
CVE-2026-38706.56.5ZyxelVMG4005-B50B firmwareCWE-120A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel…
CVE-2026-38716.56.5ZyxelVMG4005-B50B firmwareCWE-120A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zy…
CVE-2026-488612.16.4elixir-mintmintCWE-93CRLF injection in HTTP/1 request line via unvalidated method in Mint
CVE-2026-335536.16.3n/an/aCWE-79Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27…
CVE-2026-273515.46.2Sekander BadshaCrew HRMCWE-862WordPress Crew HRM plugin <= 1.2.2 - Broken Access Control vulnerability
CVE-2026-401816.65.9remix-runreact-routerCWE-601React Router's same-origin redirect with path starting // causes open redirec…
CVE-2026-456765.55.9open-telemetryopentelemetry-ebpf-instrumentationCWE-20OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed E…
CVE-2026-456825.55.8open-telemetryopentelemetry-ebpf-instrumentationCWE-401OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after …
CVE-2022-49928.85.7DrägerInfinity Acute Care SystemCWE-345Dräger Infinity M540 VG4.1.1 Spoofed Network Message Handling DoS/Tampering
CVE-2026-105106.15.1TECNO Mobilecom.transsion.aiassistantlifestyleCWE-79GeniexWebView XSS in com.transsion.aiassistantlifestyle
CVE-2026-407136.14.9DellThinOS 10CWE-284Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper …
CVE-2026-439655.64.8GleamGleamCWE-22Path Traversal in build/packages/packages.toml Allows Arbitrary Directory Del…
CVE-2026-326854.64.8GleamGleamCWE-22Path Traversal in gleam docs build via documentation.pages Allows Arbitrary F…
CVE-2025-533464.34.9ThimPressThim CoreCWE-862WordPress Thim Core Plugin <= 2.3.3 - Broken Access Control Vulnerability
CVE-2024-422063.14.8HCLiReflectionCWE-1395HCL iReflection Use of Third party vulnerable and outdated components issue w…
CVE-2026-472656.64.7aio-libsaiohttpCWE-346AIOHTTP vulnerable to cross-origin redirect with per-request cookies
CVE-2026-352125.34.6OpenCTI-PlatformopenctiCWE-79OpenCTI has XSS in the rendering of email-message observable body data
CVE-2025-527597.14.4UnboundStudioAccordion FAQCWE-79WordPress Accordion FAQ plugin <= 2.2.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-426857.14.4AhmadWP Job PortalCWE-79WordPress WP Job Portal plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-332445.44.2remix-runreact-routerCWE-79React Router has stored XSS via unescaped Location header in prerendered redi…
CVE-2026-452895.33.9CloudburstMCProtocolCWE-287CloudburstMC Protocol: Partially missing validation for FULL type authenticat…
CVE-2026-105481.93.8NousResearchhermes-agentCWE-287NousResearch hermes-agent Credential Pool Synchronization credential_pool.py …
CVE-2026-95225.43.7DevolutionsServerCWE-284Improper access control in the PAM account discovery feature in Devolutions S…
CVE-2026-281165.93.5Emilia ProjectsProgress PlannerCWE-79WordPress Progress Planner plugin <= 1.9.0 - Cross Site Scripting (XSS) vulne…
CVE-2026-51915.43.4raja3cTiled Gallery Carousel Without JetPackCWE-79Tiled Gallery Carousel Without JetPack <= 3.1 - Authenticated (Contributor+) …
CVE-2019-257198.83.2DrägerInfinity Acute Care SystemCWE-924Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
CVE-2026-427955.13.2GleamGleamCWE-59Symlink Following in Hex Package Export Allows Embedding Files Outside Projec…
CVE-2026-84224.33.2mr_matRemove meta boxes per user roleCWE-352Remove meta boxes per user role <= 1.01 - Cross-Site Request Forgery to Setti…
CVE-2026-40714.33.1birdseedappBirdSeedCWE-352BirdSeed <= 2.2.0 - Cross-Site Request Forgery via BirdSeed Token Change
CVE-2026-97224.33.1pcisLaiser TagCWE-352Laiser Tag <= 1.2.5 - Cross-Site Request Forgery to Plugin Settings Update vi…
CVE-2026-97304.33.1jamesmugaRemove NoFollow Commenter URLCWE-352Remove NoFollow Commenter URL <= 1.0 - Cross-Site Request Forgery to Settings…
CVE-2026-95994.32.9russellrTectite FormsCWE-352Tectite Forms <= 1.3 - Cross-Site Request Forgery to Settings Update
CVE-2026-97234.32.9ddd2500Google Plus One BottomCWE-352Google Plus One Bottom <= 0.0.2 - Cross-Site Request Forgery to Plugin Settin…
CVE-2026-97324.32.9planetshakerEmergencyWP – Dead Man's switch & legacy deliveranceCWE-352EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update
CVE-2026-105281.92.5OrthancDICOM ServerCWE-119Orthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow
CVE-2021-44788.32.3DrägerCC-Vision BasicCWE-787Dräger CC-Vision Basic and CC-Vision E-Cal Out-of-Bounds Write via Malicious …
CVE-2026-105661.92.3FoundationAgentsMetaGPTCWE-20FoundationAgents MetaGPT schema.py Message.check_instruct_content deserializa…
CVE-2026-100468.52.0BitdefenderNapoca bare-metal hypervisorCWE-787Out-of-bounds write in Napoca BIOS INT 0x15 E820 memory map handler (VA-13905)
CVE-2026-100478.52.0BitdefenderNapoca bare-metal hypervisorCWE-787Out-of-bounds write in Napoca real-mode hook handler via guest-controlled SS:…
CVE-2026-89368.21.8DockerDocker DesktopCWE-674Unbounded recursion in grpcfuse kernel module allows container to crash Docke…
CVE-2026-406197.81.8Genetec Inc.Genetec Security CenterCWE-532A high security vulnerability affecting Security Center main server installat…
CVE-2026-344605.41.7NamelessMCNamelessCWE-302NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / se…
CVE-2026-107184.61.7openSeaChestCWE-787Open Seachest/Seachest NVMe Trim (Deallocate) Vulnerability
CVE-2026-80368.41.3NINI-PALCWE-1285Local privilege escalation in NI-PAL
CVE-2021-44808.31.3DrägerProtector SoftwareCWE-732Dräger Protector Software Local Privilege Escalation via Insecure File Permis…
CVE-2021-44818.31.3DrägerProtector SoftwareCWE-732Dräger Protector Software Local Privilege Escalation via Insecure File Permis…
CVE-2026-107171.81.1openSeaChestCWE-787Open-Seachest/Seachest show SCSI Defect List Vulnerability
CVE-2026-107191.81.1openSeaChestCWE-787Open Seachest/Seachest NVMe show Format Descriptors Vulnerability
CVE-2026-105848.21.1AWSGraph ExplorerCWE-319HTTPS Fallback to HTTP in Graph Explorer
CVE-2026-407157.81.0DellThinOS 10CWE-284Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper …
CVE-2026-80356.90.8NINI-PALCWE-476NULL pointer dereference in NI-PAL
CVE-2025-643907.40.4SonyPS4CWE-367A privilege escalation vulnerability exists in PlayStation 4 firmware version…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-02 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.