boxscore/security
Wednesday, June 3, 2026 · all times UTC← 2026-06-02 · archive · 2026-06-04 →

151 CVEs published June 3, 2026: 8 critical, 68 high, 61 medium, 14 low; 1 in KEV; 14 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 126 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published754512610412563
KEV catalog size1670

229 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux3410008163028612730.37.8.0013-27
microsoft1491433291020378275.57.8.0045+1
google612351114961117452.18.0.0021+61
red hat569830274400.07.3.0035+5
apple04701227193714.96.2.00340
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco215314096853.37.0.0694+2
ivanti16020033466.78.8.5751+1
checkpoint060330300.06.5.03380
fortinet06130028350.07.9.43300
zyxel2300301100.06.5.0017+2
f50320007133.39.2.09960
ubiquiti031200400.08.8.00680
broadcom02000042100.0.19900
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache31637262724011.67.2.0053+31
mozilla41033401300.07.4.0035+4
gitlab0901604222.24.3.00320
drupal0511305120.05.1.00260
docker140400100.08.8.0022+1
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm5541326150700.07.5.0031+5
oracle128815404013.68.1.0027+1
progress591710900.07.5.0036+5
solarwinds14110011375.08.7.7758+1
adobe04010075375.08.6.27760
veeam031200400.08.6.00400
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link25031026120.07.4.0059+2
abb440400000.07.3.0024+4
siemens120110100.07.3.0026+1
hitachi energy020020000.05.7.00140
hikvision01000021100.01.00000
dahua000000200
qnap000000800
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax051032019100.07.4.00590
concrete cms1451101321000.06.0.0015+1
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
sourcecodester1840001327000.02.1.0025+18
nvidia23582070000.07.8.0029+2
totolink03502609000.08.9.01910

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4684010.0.0073
Most disclosures (vendor)
VendorCVEs
linux613
google229
microsoft171
ibm54
apache51
edimax51
concrete cms45
open ises44
red hat44
helmholz42
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google5
ivanti4
synacor4
adobe3
fortinet3
linux3
smartertools3
Most-affected ecosystems
EcosystemAdvisories
Maven23
PyPI10
Packagist7
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171659
CVE-2021-27102Accellion2021-11-171659
CVE-2021-27101Accellion2021-11-171659
CVE-2021-27103Accellion2021-11-171659
CVE-2021-21017Adobe2021-11-171659
CVE-2021-28550Adobe2021-11-171659
CVE-2021-42013Apache2021-11-171659
CVE-2021-41773Apache2021-11-171659
CVE-2021-30858Apple2021-11-171659
CVE-2021-30860Apple2021-11-171659

Transactions

EXPLOIT PUBLISHEDCVE-2025-70100. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-70101. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-26378. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-26379. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-26824. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-26825. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-40290 (OP-TEE optee_os). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-4035 (mlflow/mlflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45614 (OP-TEE optee_os). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45702 (OP-TEE optee_os). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5241 (huggingface/transformers). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-6657 (jupyter/jupyter). Public exploit reference added.

Yesterday's Results

151 CVEs published. 25 box scores, 126 table rows — nothing truncated.

Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .2755   97.9   YES
AFFECTED
  Product                               Versions     Fixed
  Full Page Cache Warmer for Magento 2  unspecified  —
TIMELINE
  May 11  Reserved by CNA
  Jun 3   Added to CISA KEV, due Jun 6
  Jun 3   Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 5 references · NVD status: Analyzed · KEV due June 6, 2026
n/a n/a — An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to comm…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0149   71.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 3   Published (CNA: mitre)
CWE-78 · CNA: mitre · 4 references · NVD status: Deferred
huggingface huggingface/transformers — Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0055   43.3     —
AFFECTED
  Product                   Versions       Fixed
  huggingface/transformers  unspecified –  —
TIMELINE
  Mar 31  Reserved by CNA
  Jun 3   Public exploit reference published
  Jun 3   Published (CNA: @huntr_ai)
CWE-829 · CNA: @huntr_ai · 8 references · NVD status: Modified
Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0050   40.6     —
AFFECTED
  Product      Versions  Fixed
  Apache MINA  2.2.0 –   —
TIMELINE
  May 18  Reserved by CNA
  Jun 3   Published (CNA: apache)
CWE-502 · CNA: apache · 1 reference · NVD status: Analyzed
MBS Single-A — Local file inclusion vulnerability and deletion in ugw-logread method
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0049   40.2     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-22 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
Python Software Foundation CPython — Potential DoS via quadratic complexity in unicodedata.normalize()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0049   39.7     —
AFFECTED
  Product  Versions     Fixed
  CPython  unspecified  —
TIMELINE
  Feb 26  Reserved by CNA
  Jun 3   Published (CNA: PSF)
CWE-407 · CNA: PSF · 12 references · NVD status: Awaiting Analysis
MBS Single-A — Hardcoded default Password for Service Account
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0047   38.5     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-1393 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
MBS Single-A — Stack buffer overflow in method gdv-serverconfig
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0047   38.4     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-121 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
MBS Single-A — Stack buffer overflow in method bac-deviceobject
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0046   37.8     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-121 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
MBS Single-A — Stack buffer overflow in method dali-devconfig
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0046   37.8     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-121 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
mlflow mlflow/mlflow — Environment Variable Resolution Vulnerability in mlflow/mlflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0043   36.3     —
AFFECTED
  Product        Versions       Fixed
  mlflow/mlflow  unspecified –  —
TIMELINE
  Mar 12  Reserved by CNA
  Jun 3   Public exploit reference published
  Jun 3   Published (CNA: @huntr_ai)
CWE-201 · CNA: @huntr_ai · 5 references · NVD status: Modified
Securly Securly Chrome Extension — CVE-2026-8888
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0043   36.0     —
AFFECTED
  Product                   Versions     Fixed
  Securly Chrome Extension  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jun 3   Published (CNA: certcc)
CWE-917, CWE-1333 · CNA: certcc · 1 reference · NVD status: Analyzed
ealpha072 Student-Management-System Administrative Backend config.php improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0040   33.7     —
AFFECTED
  Product                    Versions                                    Fixed
  Student-Management-System  01451bd7a2f58cdda07bd0b86e3967582e3ecd08 –  —
TIMELINE
  Jun 3   Reserved by CNA
  Jun 3   Published (CNA: VulDB)
CWE-287 · CNA: VulDB · 6 references · NVD status: Deferred
The Vinyl Cache Project Vinyl Cache — In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be e…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   P   L   N   N    2.3   .0040   32.9     —
AFFECTED
  Product                            Versions  Fixed
  Vinyl Cache                        9.0.0 –   9.0.1
  Varnish Cache (pre split)          7.6.0 –   8.0.2
  Varnish Cache by Varnish Software  9.0.0 –   9.0.3
TIMELINE
  Jun 3   Reserved by CNA
  Jun 3   Published (CNA: mitre)
CWE-444 · CNA: mitre · 2 references · NVD status: Awaiting Analysis
FreeIPMI FreeIPMI — ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent P…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0039   32.1     —
AFFECTED
  Product   Versions  Fixed
  FreeIPMI  0.7.12 –  —
TIMELINE
  Jun 3   Reserved by CNA
  Jun 3   Published (CNA: mitre)
CWE-121 · CNA: mitre · 3 references · NVD status: Awaiting Analysis
Linux Linux — ibmveth: Disable GSO for packets with small MSS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  N  H    8.6   .0039   32.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    8641dd85799f85bef5f0d1f87356aaa12cb2195e –  —
  Linux    4.2 –                                       5.10.258
TIMELINE
  May 13  Reserved by CNA
  Jun 3   Published (CNA: Linux)
CWE-400 · CNA: Linux · 8 references · NVD status: Modified
Securly Securly Chrome Extension — CVE-2026-8879
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0037   30.5     —
AFFECTED
  Product                   Versions     Fixed
  Securly Chrome Extension  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jun 3   Published (CNA: certcc)
CWE-829 · CNA: certcc · 1 reference · NVD status: Analyzed
Linux Linux — RDMA/hns: Fix WQ_MEM_RECLAIM warning
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0037   30.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    ffd541d45726341c1830ff595fd7352b6d1cfbcd –  —
  Linux    5.7 –                                       6.1.165
TIMELINE
  May 13  Reserved by CNA
  Jun 3   Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Analyzed
MBS Single-A — Arbitrary file delete vulnerability in method bac-scanresult
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0037   30.1     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-73 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
MBS Single-A — Arbitrary file delete vulnerability in method ugw-delete-file
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0037   30.1     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-73 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
MBS Single-A — Arbitrary file delete vulnerability in method ugw-logstop
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0037   30.1     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-73 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
MBS Single-A — Arbitrary file delete vulnerability in method ugw-restore
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0037   30.1     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-73 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
MBS Single-A — Arbitrary file delete vulnerability in method ugw-restoreinfo
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0037   30.1     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-73 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
MBS Single-A — Arbitrary process termination vulnerability in method ugw-logstop
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0037   30.1     —
AFFECTED
  Product            Versions    Fixed
  Single-A           V1_00_00 –  —
  Double-A Profibus  V1_00_00 –  —
  Double-A x-link    V1_00_00 –  —
  Single-X           V1_00_00 –  —
  Double-X CAN       V1_00_00 –  —
  Double-X DALI      V1_00_00 –  —
  Double-X KNX       V1_00_00 –  —
  Double-X LON       V1_00_00 –  —
  Double-X M-Bus     V1_00_00 –  —
  Double-X PROFINET  V1_00_00 –  —
  + 8 more
TIMELINE
  Apr 1   Reserved by CNA
  Jun 3   Published (CNA: CERTVDE)
CWE-20 · CNA: CERTVDE · 1 reference · NVD status: Analyzed
RURBAN Cpanel::JSON::XS — Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0036   29.1     —
AFFECTED
  Product           Versions     Fixed
  Cpanel::JSON::XS  unspecified  —
TIMELINE
  May 25  Reserved by CNA
  Jun 3   Published (CNA: CPANSec)
CWE-755, CWE-763 · CNA: CPANSec · 3 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-351932.329.0djangoprojectDjangoCWE-524Potential exposure of private data via missing Vary: Authorization in UpdateC…
CVE-2026-485872.328.5djangoprojectDjangoCWE-1023Potential exposure of private data via whitespace padding in Vary header
CVE-2025-147717.327.8ABBT-MAC PlusCWE-552File Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Serve…
CVE-2026-462669.127.6LinuxLinuxinet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
CVE-2026-423177.027.6glpi-projectglpiCWE-862GLPI vulnerable to arbitrary files deletion by technician
CVE-2026-423218.427.3glpi-projectglpiCWE-79GLPI has stored XSS in asset locks
CVE-2026-374607.526.4n/an/aCWE-20Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRR…
CVE-2026-445457.525.6djangoprojectdaphneCWE-770Unbounded WebSocket message and frame sizes can cause unauthenticated remote …
CVE-2026-50785.325.4morganmorganCWE-117morgan vulnerable to Log Forging via unneutralized control characters in :rem…
CVE-2026-462449.125.0LinuxLinuxCWE-823netfilter: nft_inner: Fix IPv6 inner_thoff desync
CVE-2022-311145.122.9Laravel-BackpackCRUDCWE-79backpack/crud Vulnerable to Cross-site Scripting
CVE-2026-106945.522.8SourceCodesterOnline Food Ordering SystemCWE-73SourceCodester Online Food Ordering System index.php include file inclusion
CVE-2026-263785.422.6n/an/aCWE-79Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote a…
CVE-2026-367489.022.2n/an/aCWE-79RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS…
CVE-2024-472634.122.3SynologyHyper BackupCWE-22An improper limitation of a pathname to a restricted directory ('Path Travers…
CVE-2026-107715.521.9crmebcrmeb_javaCWE-918crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.ge…
CVE-2025-147727.321.7ABBT-MAC PlusCWE-639Broken Access Control in ABB T-MAC Plus web application
CVE-2025-701016.521.7n/an/aCWE-125An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_exte…
CVE-2026-423187.021.7glpi-projectglpiCWE-862GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint
CVE-2026-473245.121.6ProjectsAndProgramsschool-management-systemCWE-79Stored XSS in Multiple Points in ProjectsAndPrograms school-management-system
CVE-2026-107052.321.2n/adaskCWE-400dask HLL hyperloglog.py nunique_approx resource consumption
CVE-2026-84042.320.9djangoprojectDjangoCWE-178Potential exposure of private data via case-sensitive Cache-Control directive…
CVE-2026-107045.520.5SourceCodesterPizzafy E-Commerce SystemCWE-74SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_c…
CVE-2026-374627.520.4n/an/aCWE-190An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) …
CVE-2026-404956.920.3FOSSBillingFOSSBillingCWE-200FOSSBilling version exposed via asset cache buster
CVE-2024-472734.320.2SynologyHyper BackupCWE-22An improper limitation of a pathname to a restricted directory ('Path Travers…
CVE-2026-391076.319.2n/an/aCWE-79A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface…
CVE-2026-464477.718.1OpenStackIronicCWE-669OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script…
CVE-2026-428394.817.9FrappeERPNextCWE-79ERPNext 16.16.0 - Stored XSS in POS cart item rendering
CVE-2026-410327.517.8Phoenix ContactCHARX SEC-3150CWE-200Phoenix Contact: Unauthenticated log download vulnerability in the firmware o…
CVE-2026-439244.817.7FOSSBillingFOSSBillingCWE-601FOSSBilling has an open redirect via administrator-configured redirect targets
CVE-2026-366046.517.1n/an/aCWE-350Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not vali…
CVE-2026-93347.316.9RURBANCpanel::JSON::XSCWE-843Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via dupli…
CVE-2026-442817.016.7glpi-projectglpiCWE-862GLPI vulnerable to unauthorized reading of a specific asset object
CVE-2026-88897.516.5SecurlySecurly Chrome ExtensionCWE-407CVE-2026-8889
CVE-2026-473256.916.5ProjectsAndProgramsschool-management-systemCWE-1391Weak password policy in ProjectsAndPrograms school-management-system
CVE-2026-68732.316.0djangoprojectDjangoCWE-347Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_…
CVE-2026-263796.515.7n/an/aCWE-918Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulner…
CVE-2026-428405.115.7FrappeERPNextCWE-79ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template l…
CVE-2026-107032.115.8EIPStackGroupOpENerCWE-119EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequest…
CVE-2026-88767.315.5SecurlySecurly Chrome ExtensionCWE-798CVE-2026-8876
CVE-2026-423205.915.2glpi-projectglpiCWE-862GLPI vulnerable to arbitrary file access
CVE-2026-220545.314.9NETAPPActive IQ Config AdvisorCWE-259Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that c…
CVE-2026-220555.314.9NETAPPActive IQ OneCollectCWE-259Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could…
CVE-2025-156568.814.3MojoomlaSchool ManagementCWE-266WordPress School Management plugin <= 93.2.0 - Privilege Escalation vulnerabi…
CVE-2025-156557.614.1MojoomlaSchool ManagementCWE-89WordPress School Management plugin <= 93.2.0 - SQL Injection vulnerability
CVE-2026-366117.314.2n/an/aCWE-200Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of…
CVE-2026-268246.513.8n/an/aCWE-457libxls through version 1.6.3 contains a use of uninitialized memory vulnerabi…
CVE-2026-268255.312.0n/an/aCWE-908A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsi…
CVE-2026-106932.112.0SourceCodesterOnline Boat Reservation SystemCWE-266SourceCodester Online Boat Reservation System Administrative Endpoint imprope…
CVE-2026-366038.111.6n/an/aCWE-306Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of…
CVE-2026-88787.511.6SecurlySecurly Chrome ExtensionCWE-326CVE-2026-8878
CVE-2026-107291.210.7Thinkst Applied ResearchCanarytokensCWE-74HTML injection in the notification email for "Slow Redirect" and "Cloned Webs…
CVE-2026-87226.510.6TEAMNet::Async::Statsd::ClientCWE-93Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injec…
CVE-2019-257207.110.1DrägerSC 6002XLCWE-1286Dräger SC Monitoring Devices DoS via Malformed Network Packet
CVE-2026-66578.89.7jupyterjupyter/jupyterCWE-346CORS Origin Validation Bypass in jupyter-server
CVE-2026-402907.88.6OP-TEEoptee_osCWE-416OP-TEE has a Use-After-Free race in FF-A shared-memory teardown
CVE-2026-377004.18.5n/an/aCWE-79Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote att…
CVE-2026-202336.18.3CiscoCisco Webex MeetingsCWE-79Cisco Webex Meetings Cross-Site Scripting Vulnerability
CVE-2026-366078.88.0n/an/aCWE-307Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauth…
CVE-2026-366088.88.0n/an/aCWE-441Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP A…
CVE-2025-147737.27.9ABBT-MAC PlusCWE-79Stored Cross-Site Scripting in ABB T-MAC Plus web application
CVE-2025-147747.27.9ABBT-MAC PlusCWE-863Communication analysis between the Card Reader and TP2CardReaderService daemon
CVE-2026-201756.17.8CiscoCisco FinesseCWE-73Cisco Finesse File Inclusion Vulnerability
CVE-2026-364604.87.9n/an/aCWE-79Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Sit…
CVE-2026-107221.97.7ciliumebpfCWE-189cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpe…
CVE-2026-366056.57.5n/an/aCWE-400Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable…
CVE-2026-78888.47.2Concrete CMSConcrete CMSCWE-502Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserializ…
CVE-2026-445465.37.0djangoprojectdaphneCWE-444Header injection via WebSocket upgrade parser differential allows ASGI scope …
CVE-2026-366097.36.2n/an/aCWE-327Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static…
CVE-2026-366024.36.3n/an/aCWE-200Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses ker…
CVE-2026-366154.36.3n/an/aCWE-200Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumen…
CVE-2026-88817.55.9SecurlySecurly Chrome ExtensionCVE-2026-8881
CVE-2025-701005.55.8n/an/aCWE-369A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/…
CVE-2026-366134.35.5n/an/aCWE-125Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of…
CVE-2026-366184.35.5n/an/aCWE-200Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.…
CVE-2026-457025.55.2OP-TEEoptee_osCWE-843OP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic
CVE-2026-76662.34.7djangoprojectDjangoCWE-319Potential unencrypted email transmission via STARTTLS in the SMTP backend
CVE-2026-366105.94.5n/an/aCWE-319Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS crede…
CVE-2025-713145.54.4LinuxLinuxdrm/panthor: Recover from panthor_gpu_flush_caches() failures
CVE-2025-156547.14.4Fox-themesPragueCWE-79WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-366126.43.8n/an/aCWE-307Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by d…
CVE-2026-88747.13.6SecurlySecurly Chrome ExtensionCWE-319CVE-2026-8874
CVE-2026-365747.83.6n/an/aCWE-427A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 al…
CVE-2026-366165.93.6n/an/aCWE-798Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded W…
CVE-2026-462537.83.5LinuxLinuxCWE-787pstore/ram: fix buffer overflow in persistent_ram_save_old()
CVE-2026-462518.43.2LinuxLinuxbtrfs: fix block_group_tree dirty_list corruption
CVE-2023-529515.93.1SynologySynology Note Station ClientCWE-319A cleartext transmission of sensitive information vulnerability in Synology N…
CVE-2026-462708.43.0LinuxLinuxCWE-416power: supply: rt9455: Fix use-after-free in power_supply_changed()
CVE-2026-462507.32.9LinuxLinuxMIPS: Work around LLVM bug when gp is used as global register variable
CVE-2026-462467.82.7LinuxLinuxCWE-416power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler
CVE-2022-490367.82.5SynologySynology Active Backup for Business Recovery Media CreatorCWE-829An inclusion of functionality from untrusted control sphere vulnerability in …
CVE-2022-490427.82.5SynologySynology Hyper Backup ExplorerCWE-829An inclusion of functionality from untrusted control sphere vulnerability in …
CVE-2026-462475.52.5LinuxLinuxclk: qcom: gfx3d: add parent to parent request map
CVE-2026-462677.82.3LinuxLinuxCWE-416nfc: hci: shdlc: Stop timers and work before freeing context
CVE-2026-462485.52.3LinuxLinuxwifi: ath12k: clear stale link mapping of ahvif->links_map
CVE-2026-462597.82.2LinuxLinuxprocfs: fix missing RCU protection when reading real_parent in do_task_stat()
CVE-2026-462607.82.1LinuxLinuxCWE-125ipv6: Fix out-of-bound access in fib6_add_rt2node().
CVE-2026-462637.82.1LinuxLinuxCWE-125drm/amd/display: Fix out-of-bounds stream encoder index v3
CVE-2026-107751.12.2sgl-projectSGLangCWE-404sgl-project SGLang Cache data_hash denial of service
CVE-2026-462717.82.1LinuxLinuxwifi: ath12k: do WoW offloads only on primary link
CVE-2026-446827.31.8AcronisAcronis DeviceLock DLPCWE-427Local privilege escalation due to DLL hijacking vulnerability. The following …
CVE-2026-500337.31.8AcronisAcronis DeviceLock DLPCWE-427Local privilege escalation due to DLL hijacking vulnerability. The following …
CVE-2026-462495.51.8LinuxLinuxocteontx2-af: Fix PF driver crash with kexec kernel booting
CVE-2026-462545.51.7LinuxLinuxAppArmor: Allow apparmor to handle unaligned dfa tables
CVE-2026-462555.51.7LinuxLinuxdmaengine: fsl-edma: don't explicitly disable clocks in .remove()
CVE-2026-462615.51.7LinuxLinuxCWE-476spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe()
CVE-2026-462685.51.6LinuxLinuxPCI/P2PDMA: Fix p2pmem_alloc_mmap() warning condition
CVE-2026-462695.51.6LinuxLinuxCWE-476pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree
CVE-2026-462648.81.6LinuxLinuxCWE-416drm/xe/pf: Fix sysfs initialization
CVE-2026-462455.51.4LinuxLinuxCWE-476drm/amd/display: Fix dc_link NULL handling in HPD init
CVE-2025-713135.51.3LinuxLinuxCWE-476PCI: endpoint: Add missing NULL check for alloc_workqueue()
CVE-2025-604775.01.3n/an/aCWE-476A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex func…
CVE-2026-420617.31.2AcronisAcronis DeviceLock DLPCWE-250Local privilege escalation due to excessive permissions assigned to child pro…
CVE-2026-446097.31.2AcronisAcronis DeviceLock DLPCWE-427Local privilege escalation due to EXE hijacking vulnerability. The following …
CVE-2026-107831.11.3gradio-appgradioCWE-327gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
CVE-2026-366067.11.2n/an/aCWE-798Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts conf…
CVE-2025-412597.31.0sbabicSWUpdateCWE-367SWUpdate Untrusted Script Execution via Signed Update TOCTOU
CVE-2026-462575.51.0LinuxLinuxCWE-908clocksource/drivers/timer-sp804: Fix an Oops when read_current_timer is calle…
CVE-2026-462585.51.0LinuxLinuxCWE-476gpio: cdev: Avoid NULL dereference in linehandle_create()
CVE-2026-462565.51.0LinuxLinuxCWE-667NFS/localio: prevent direct reclaim recursion into NFS via nfs_writepages
CVE-2026-456144.70.8OP-TEEoptee_osCWE-347OP-TEE vulnerable to ECDH private key recovery
CVE-2026-462525.50.6LinuxLinuxCWE-667regulator: core: fix locking in regulator_resolve_supply() error path
CVE-2026-462625.50.6LinuxLinuxCWE-667ASoC: fsl_xcvr: Revert fix missing lock in fsl_xcvr_mode_put()
CVE-2026-462724.70.5LinuxLinuxCWE-362coresight: tmc-etr: Fix race condition between sysfs and perf mode
CVE-2026-107661.10.1n/amlrunCWE-327mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash …

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-03 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.