AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0835 94.5 YES
AFFECTED Product Versions Fixed Serv-U 15.5.4 and previous versions – —
TIMELINE Feb 26 Reserved by CNA Jun 5 Added to CISA KEV, due Jun 19 Jun 5 Published (CNA: SolarWinds)
167 CVEs published June 5, 2026: 28 critical, 65 high, 61 medium, 13 low; 1 in KEV; 18 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 142 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1545 | 5917 | 1044 | 2563 |
| KEV catalog size | 1670 | |||
255 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 34 | 1000 | 81 | 630 | 286 | 1 | 27 | 3 | 0.3 | 7.8 | .0013 | -33 |
| 488 | 662 | 58 | 331 | 255 | 15 | 74 | 5 | 0.8 | 7.8 | .0023 | +488 | |
| microsoft | 7 | 497 | 44 | 333 | 103 | 0 | 378 | 27 | 5.4 | 7.8 | .0046 | +7 |
| red hat | 19 | 83 | 8 | 40 | 30 | 5 | 4 | 0 | 0.0 | 7.4 | .0033 | +17 |
| apple | 0 | 47 | 0 | 12 | 27 | 1 | 93 | 7 | 14.9 | 6.2 | .0034 | 0 |
| canonical | 0 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | 0 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| suse | 0 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.2 | .0020 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 2 | 15 | 3 | 1 | 4 | 0 | 96 | 8 | 53.3 | 7.0 | .0694 | +2 |
| ivanti | 1 | 6 | 0 | 2 | 0 | 0 | 33 | 4 | 66.7 | 8.8 | .5751 | +1 |
| checkpoint | 0 | 6 | 0 | 3 | 3 | 0 | 3 | 0 | 0.0 | 6.5 | .0338 | 0 |
| fortinet | 0 | 6 | 1 | 3 | 0 | 0 | 28 | 3 | 50.0 | 7.9 | .4330 | 0 |
| zyxel | 2 | 3 | 0 | 0 | 3 | 0 | 11 | 0 | 0.0 | 6.5 | .0017 | +2 |
| f5 | 0 | 3 | 2 | 0 | 0 | 0 | 7 | 1 | 33.3 | 9.2 | .0996 | 0 |
| ubiquiti | 0 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.8 | .0068 | 0 |
| broadcom | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .1990 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 32 | 64 | 8 | 26 | 27 | 2 | 40 | 1 | 1.6 | 7.2 | .0053 | +28 |
| mozilla | 4 | 10 | 3 | 3 | 4 | 0 | 13 | 0 | 0.0 | 7.4 | .0035 | +4 |
| gitlab | 0 | 9 | 0 | 1 | 6 | 0 | 4 | 2 | 22.2 | 4.3 | .0032 | 0 |
| docker | 2 | 5 | 0 | 5 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0021 | +2 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ibm | 5 | 54 | 13 | 26 | 15 | 0 | 7 | 0 | 0.0 | 7.5 | .0031 | +5 |
| oracle | 1 | 28 | 8 | 15 | 4 | 0 | 40 | 1 | 3.6 | 8.1 | .0027 | +1 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +5 |
| solarwinds | 2 | 5 | 1 | 2 | 0 | 0 | 11 | 4 | 80.0 | 7.5 | .7155 | +2 |
| adobe | 0 | 4 | 0 | 1 | 0 | 0 | 75 | 3 | 75.0 | 8.6 | .2776 | 0 |
| veeam | 0 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.6 | .0040 | 0 |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 5 | 8 | 0 | 3 | 1 | 3 | 26 | 1 | 12.5 | 6.0 | .0087 | +5 |
| abb | 4 | 4 | 0 | 4 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0024 | +4 |
| siemens | 1 | 2 | 0 | 1 | 1 | 0 | 1 | 0 | 0.0 | 7.3 | .0026 | +1 |
| hitachi energy | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | 0 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| edimax | 0 | 51 | 0 | 32 | 0 | 19 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| concrete cms | 1 | 45 | 1 | 10 | 13 | 21 | 0 | 0 | 0.0 | 6.0 | .0015 | +1 |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | 0 |
| sourcecodester | 21 | 43 | 0 | 0 | 14 | 29 | 0 | 0 | 0.0 | 2.1 | .0025 | +21 |
| helmholz | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| mb connect line | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| acer | 26 | 36 | 11 | 19 | 6 | 0 | 0 | 0 | 0.0 | 8.7 | .0024 | +26 |
| nvidia | 2 | 35 | 8 | 20 | 7 | 0 | 0 | 0 | 0.0 | 7.8 | .0029 | +2 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2026-43284 | .9324 | 99.8 | 8.8 |
| CVE-2026-43500 | .9285 | 99.8 | 7.8 |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2026-42208 | .8942 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2009-3459 | .8658 | 99.7 | — |
| CVE-2025-34291 | .8384 | 99.7 | — |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-43997 | 10.0 | .0098 | |
| CVE-2026-42826 | 10.0 | .0084 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-44005 | 10.0 | .0083 |
| Vendor | CVEs |
|---|---|
| 656 | |
| linux | 528 |
| microsoft | 177 |
| red hat | 58 |
| ibm | 54 |
| edimax | 51 |
| apache | 49 |
| concrete cms | 45 |
| open ises | 44 |
| sourcecodester | 43 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 8 |
| apple | 7 |
| 5 | |
| ivanti | 4 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 24 |
| PyPI | 10 |
| Packagist | 7 |
| crates.io | 2 |
| npm | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1661 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1661 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1661 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1661 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1661 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1661 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1661 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1661 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1661 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1661 |
EXPLOIT PUBLISHED — CVE-2026-45300 (AsyncHttpClient async-http-client). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45743 (Termix-SSH Termix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45744 (Termix-SSH Termix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45745 (Termix-SSH Termix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45746 (Termix-SSH Termix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45748 (Termix-SSH Termix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45749 (Termix-SSH Termix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45750 (Termix-SSH Termix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48092 (mcmilk 7-Zip). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48095 (mcmilk 7-Zip). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48101 (mcmilk 7-Zip). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48102 (mcmilk 7-Zip). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48103 (mcmilk 7-Zip). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48104 (mcmilk 7-Zip). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48111 (mcmilk 7-Zip). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48112 (mcmilk 7-Zip). Public exploit reference added.
DUE DATE PASSED — CVE-2024-21182 (Oracle WebLogic Server). CISA remediation deadline was June 4, 2026; still in catalog.
DUE DATE PASSED — CVE-2025-34291 (Langflow). CISA remediation deadline was June 4, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-34926 (Trend Micro, Inc. TrendAI Apex One). CISA remediation deadline was June 4, 2026; still in catalog.
167 CVEs published. 25 box scores, 142 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0835 94.5 YES
AFFECTED Product Versions Fixed Serv-U 15.5.4 and previous versions – —
TIMELINE Feb 26 Reserved by CNA Jun 5 Added to CISA KEV, due Jun 19 Jun 5 Published (CNA: SolarWinds)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H L L 7.0 .0988 95.2 —
AFFECTED Product Versions Fixed Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) 17.4.0 – —
TIMELINE Feb 3 Reserved by CNA Jun 5 Published (CNA: Arista)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H L L 7.0 .0988 95.2 —
AFFECTED Product Versions Fixed Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) unspecified —
TIMELINE Feb 3 Reserved by CNA Jun 5 Published (CNA: Arista)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H L L 7.0 .0595 92.6 —
AFFECTED Product Versions Fixed Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) unspecified —
TIMELINE Feb 3 Reserved by CNA Jun 5 Published (CNA: Arista)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0424 90.2 —
AFFECTED Product Versions Fixed DWR-M920 1.1.50 – —
TIMELINE Jun 4 Reserved by CNA Jun 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0313 86.8 —
AFFECTED Product Versions Fixed DWR-M920 1.1.0 – —
TIMELINE Jun 5 Reserved by CNA Jun 5 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0295 86.0 —
AFFECTED Product Versions Fixed Hippoo Mobile App for WooCommerce unspecified —
TIMELINE Jun 1 Reserved by CNA Jun 5 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0250 83.4 —
AFFECTED Product Versions Fixed WP User Manager – User Profile Builder & Membership unspecified —
TIMELINE May 22 Reserved by CNA Jun 5 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0201 79.2 —
AFFECTED Product Versions Fixed Termix < 2.3.2 – —
TIMELINE May 13 Reserved by CNA Jun 5 Public exploit reference published Jun 5 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0173 75.6 —
AFFECTED Product Versions Fixed Termix < 2.3.2 – —
TIMELINE May 13 Reserved by CNA Jun 5 Public exploit reference published Jun 5 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0166 74.6 —
AFFECTED Product Versions Fixed Product Slider Pro for WooCommerce n/a – 3.5.4
TIMELINE Jun 1 Reserved by CNA Jun 5 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0115 64.0 —
AFFECTED Product Versions Fixed Altium Enterprise Server unspecified — Altium 365 unspecified – —
TIMELINE Jun 5 Reserved by CNA Jun 5 Published (CNA: Altium)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0112 63.3 —
AFFECTED Product Versions Fixed 7-Zip <= 26.00 – —
TIMELINE May 20 Reserved by CNA Jun 5 Public exploit reference published Jun 5 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0104 61.3 —
AFFECTED Product Versions Fixed DWR-M920 1.1.0 – —
TIMELINE Jun 5 Reserved by CNA Jun 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0092 57.3 —
AFFECTED Product Versions Fixed Digital Experience 9.5 – —
TIMELINE Jan 5 Reserved by CNA Jun 5 Published (CNA: HCL)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0091 56.9 —
AFFECTED Product Versions Fixed Admin Columns unspecified —
TIMELINE May 1 Reserved by CNA Jun 5 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N H H H 7.7 .0077 52.6 —
AFFECTED Product Versions Fixed haxcms-php < 26.0.0 – —
TIMELINE May 13 Reserved by CNA Jun 5 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0071 50.5 —
AFFECTED Product Versions Fixed Altium Enterprise Server unspecified —
TIMELINE Jun 5 Reserved by CNA Jun 5 Published (CNA: Altium)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0069 49.7 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 5 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0064 47.7 —
AFFECTED Product Versions Fixed Lyrion Music Server 9.2.0 – —
TIMELINE Jun 4 Reserved by CNA Jun 5 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0061 46.4 —
AFFECTED Product Versions Fixed Advanced Google reCAPTCHA unspecified —
TIMELINE Apr 2 Reserved by CNA Jun 5 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0057 44.3 —
AFFECTED Product Versions Fixed HaLowLink 2 unspecified —
TIMELINE May 4 Reserved by CNA Jun 5 Published (CNA: Bugcrowd)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0055 43.3 —
AFFECTED Product Versions Fixed Altium Enterprise Server unspecified —
TIMELINE Jun 5 Reserved by CNA Jun 5 Published (CNA: Altium)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N H N H H H 8.4 .0054 43.0 —
AFFECTED Product Versions Fixed RUTOS 7.22 – — TSWOS 1.09 – —
TIMELINE May 19 Reserved by CNA Jun 5 Published (CNA: tlt_net)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0054 42.9 —
AFFECTED Product Versions Fixed Advanced Google reCAPTCHA unspecified —
TIMELINE Apr 2 Reserved by CNA Jun 5 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-7763 | 9.8 | 42.7 | Morse Micro | HaLowLink 2 | — | Heap buffer overflow in morse.ko TIM IE processing |
| CVE-2025-71318 | 9.3 | 42.6 | Riello UPS | NetMan 204 | CWE-306 | NetMan 204 Missing Authentication for Administrative Functions |
| CVE-2026-10732 | 5.6 | 41.8 | n/a | decompress | CWE-29 | All versions of the package decompress are vulnerable to Arbitrary File Write… |
| CVE-2026-11431 | 8.3 | 41.6 | Altium | Altium Enterprise Server | CWE-22 | Path Traversal in Altium Projects Service Allows Arbitrary File Read |
| CVE-2026-10879 | 9.8 | 39.6 | HMBRAND | DBI | CWE-787 | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL s… |
| CVE-2026-45779 | 9.3 | 39.3 | ubccr | xdmod | CWE-89 | Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Databa… |
| CVE-2026-11414 | 10.0 | 39.2 | Altium | Altium Enterprise Server | CWE-22 | Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service v… |
| CVE-2026-11416 | 7.2 | 38.6 | jxxghp | MoviePilot | CWE-22 | MoviePilot Path Traversal via Cloud Storage Download Handlers |
| CVE-2026-6274 | 9.8 | 38.0 | DTS Electronics Industry and Trade Ltd. Co. | Redline WR3200 | CWE-287 | Authentication Bypass in DTS Electronics' Redline WR3200 |
| CVE-2026-46391 | 8.7 | 37.9 | haxtheweb | @haxtheweb/open-apis | CWE-183 | HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in ope… |
| CVE-2026-11362 | 9.8 | 37.1 | BINARY | DataDog::DogStatsd | CWE-93 | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections fro… |
| CVE-2025-71317 | 9.3 | 36.0 | Riello UPS | NetMan 204 | CWE-798 | NetMan 204 Hard-coded Backdoor Credentials |
| CVE-2026-11345 | 6.9 | 34.5 | linqi GmbH | linqi | CWE-287 | Improper Authentication Bypass in linqi CDN File Access |
| CVE-2026-45409 | 6.9 | 34.0 | kjd | idna | CWE-1333 | Internationalized Domain Names in Applications (IDNA): Specially crafted inpu… |
| CVE-2026-50230 | 5.1 | 33.8 | LMS Community | Lyrion Music Server | CWE-79 | Lyrion Music Server 9.2.0 Reflected XSS via server.log |
| CVE-2025-12656 | 3.8 | 32.1 | wpvividplugins | WPvivid — Backup, Migration & Staging | CWE-73 | Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenti… |
| CVE-2026-45777 | 9.3 | 32.0 | ubccr | xdmod | CWE-78 | Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS C… |
| CVE-2026-45746 | 9.0 | 31.9 | Termix-SSH | Termix | CWE-284 | Termix Vulnerable to Arbitrary Command Execution via Session Hijacking |
| CVE-2026-46400 | 8.7 | 31.8 | haxtheweb | haxcms-php | CWE-434 | HAXCMS PHP has a File Upload Validation Bypass |
| CVE-2026-11344 | 5.5 | 29.7 | code-projects | Vehicle Management System | CWE-284 | code-projects Vehicle Management System New Driver Registration Form newdrive… |
| CVE-2026-50733 | 8.6 | 29.3 | shd101wyy | Markdown Preview Enhanced | CWE-95 | Markdown Preview Enhanced Arbitrary Code Execution via WaveDrom eval() |
| CVE-2026-45327 | 8.2 | 28.7 | DatanoiseTV | tinyice | CWE-306 | TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized… |
| CVE-2026-36785 | 7.5 | 28.8 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to con… |
| CVE-2026-6448 | 4.9 | 28.3 | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | CWE-89 | Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection… |
| CVE-2026-9088 | 2.7 | 27.9 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-1220 | Keycloak: keycloak: information disclosure due to user profile permission bypass |
| CVE-2026-46389 | 9.8 | 27.1 | defenseunicorns | uds-identity-config | CWE-287 | UDS Identity Config has a client authentication bypass in `ClientIdAndKuberne… |
| CVE-2026-49492 | 8.6 | 27.0 | shd101wyy | Markdown Preview Enhanced | CWE-78 | Markdown Preview Enhanced OS Command Injection in External File and Link Opening |
| CVE-2026-9270 | 9.1 | 26.0 | BINARY | DataDog::DogStatsd | CWE-93 | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections |
| CVE-2026-49493 | 8.6 | 25.5 | shd101wyy | Markdown Preview Enhanced | CWE-94 | Markdown Preview Enhanced Arbitrary Code Execution via Bitfield interpretJS() |
| CVE-2026-45749 | 8.1 | 25.3 | Termix-SSH | Termix | CWE-308 | Termix's TOTP two-factor authentication can be disabled or bypassed using onl… |
| CVE-2026-48092 | 8.1 | 25.2 | mcmilk | 7-Zip | CWE-125 | 7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116) |
| CVE-2025-5088 | 8.7 | 25.1 | Arista Networks | EOS / CloudVision eXchange (CVX) | CWE-269 | Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis … |
| CVE-2026-45300 | 7.4 | 25.0 | AsyncHttpClient | async-http-client | CWE-200 | async-http-client: Cookie header not stripped on cross-origin redirect |
| CVE-2026-11423 | 9.4 | 24.9 | Altium | Altium Enterprise Server | CWE-22 | Path Traversal in Altium Enterprise Server Collaboration Service Allows Privi… |
| CVE-2026-46401 | 5.3 | 23.8 | haxtheweb | issues | CWE-613 | HAX CMS PHP has Insufficient Session Expiration |
| CVE-2026-11400 | 8.6 | 23.1 | AWS | AWS Advanced JDBC Wrapper | CWE-426 | Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL |
| CVE-2026-11401 | 8.6 | 23.1 | AWS | AWS Advanced Go Wrapper | CWE-426 | Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL |
| CVE-2026-21035 | 6.5 | 22.4 | Samsung Mobile | Samsung Plus TV | — | Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows… |
| CVE-2026-46395 | 9.3 | 22.0 | haxtheweb | haxcms-nodejs | CWE-200 | HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation |
| CVE-2026-45750 | 9.0 | 21.9 | Termix-SSH | Termix | CWE-78 | Termix Vulnerable to Arbitrary Command Execution in File Manager |
| CVE-2026-50233 | 6.9 | 21.9 | LMS Community | Lyrion Music Server | CWE-548 | Lyrion Music Server 9.2.0 Arbitrary Directory Listing |
| CVE-2026-46399 | 9.4 | 21.5 | haxtheweb | haxcms-nodejs | CWE-15 | Authenticated Remote Code Execution via File Overwrite |
| CVE-2026-8976 | 4.3 | 21.5 | themeisle | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | CWE-862 | RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (C… |
| CVE-2026-46397 | 6.5 | 21.4 | haxtheweb | haxcms-php | CWE-22 | haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 |
| CVE-2026-46493 | 7.5 | 21.3 | haxtheweb | haxcms-php | CWE-338 | haxtheweb/haxcms-php uses insecure method for generating salt |
| CVE-2026-10038 | 4.3 | 21.0 | smub | Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More | CWE-639 | Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object R… |
| CVE-2026-11334 | 5.5 | 20.9 | tittuvarghese | CollegeManagementSystem | CWE-74 | tittuvarghese CollegeManagementSystem fetch.php sql injection |
| CVE-2026-45743 | 8.1 | 20.7 | Termix-SSH | Termix | CWE-639 | Termix has a File-Manager Session Hijack via Missing Ownership Check (IDOR) |
| CVE-2026-36501 | 7.5 | 20.3 | n/a | n/a | CWE-20 | An issue in the Externalizable.readExternal() component of Controller v12.0.5… |
| CVE-2026-45290 | 7.5 | 20.2 | CloudburstMC | Network | CWE-770 | Cloudburst Network has DoS in RakNet connection handling due to missing bound… |
| CVE-2026-48101 | 6.5 | 20.1 | mcmilk | 7-Zip | CWE-908 | GHSL-2026-117: 7-Zip UEFI Capsule uninitialized heap memory disclosure |
| CVE-2026-45758 | 9.6 | 20.0 | guardrails-ai | guardrails | CWE-506 | Malicious code in guardrails-ai 0.10.1 (supply chain compromise) |
| CVE-2026-46511 | 8.7 | 19.9 | haxtheweb | haxcms-nodejs | CWE-79 | HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack |
| CVE-2026-11337 | 2.1 | 19.7 | tittuvarghese | CollegeManagementSystem | CWE-79 | tittuvarghese CollegeManagementSystem fetch.php cross site scripting |
| CVE-2026-7523 | 4.3 | 19.5 | alejo30 | Alba Board | CWE-862 | Alba Board <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Se… |
| CVE-2026-46390 | 6.9 | 19.2 | haxtheweb | haxcms-php | CWE-639 | HAX CMS has Unauthenticated Git Access via User-Controlled Key |
| CVE-2026-48112 | 6.5 | 18.9 | mcmilk | 7-Zip | CWE-125 | GHSL-2026-122 7-Zip Ar SYMDEF OOB Read |
| CVE-2026-45291 | 7.5 | 18.2 | CloudburstMC | Network | CWE-20 | Cloudburst Network erroneously handles invalid connections |
| CVE-2026-11342 | 5.5 | 18.2 | code-projects | Hotel and Tourism Reservation System | CWE-74 | code-projects Hotel and Tourism Reservation System details.php sql injection |
| CVE-2026-46357 | 6.5 | 15.3 | haxtheweb | haxcms-nodejs | CWE-20 | HAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Im… |
| CVE-2026-46393 | 7.1 | 15.1 | haxtheweb | haxcms-nodejs | CWE-918 | HAXcms createSite SSRF Enables Arbitrary File Read |
| CVE-2026-45776 | 5.3 | 14.9 | ubccr | xdmod | CWE-284 | Open XDMoD has Broken Access Control via Client-Controlled Session Variable |
| CVE-2025-5089 | 7.1 | 14.6 | Arista Networks | EOS / CloudVision eXchange (CVX) | CWE-20 | Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Mess… |
| CVE-2025-5090 | 7.1 | 14.6 | Arista Networks | EOS / CloudVision eXchange (CVX) | CWE-20 | Arista CloudVision Exchange Cluster Instability via Unexpected Switch Messages |
| CVE-2026-11335 | 2.1 | 14.3 | tittuvarghese | CollegeManagementSystem | CWE-384 | tittuvarghese CollegeManagementSystem login-form.php session_start session fi… |
| CVE-2026-46396 | 9.3 | 14.1 | haxtheweb | haxcms-nodejs | CWE-79 | HAX CMS has a stored XSS via <iframe> that allows access to sensitive client-… |
| CVE-2026-46496 | 9.3 | 14.1 | haxtheweb | haxcms-nodejs | CWE-79 | HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScrip… |
| CVE-2026-11424 | 8.3 | 13.5 | Altium | Altium Enterprise Server | CWE-200 | Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows … |
| CVE-2026-2379 | 8.2 | 13.5 | Arista Networks | EOS | CWE-672 | Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Ant… |
| CVE-2026-11346 | 5.3 | 13.5 | linqi GmbH | linqi | CWE-918 | Server-Side Request Forgery (SSRF) allowing Internal Network Probing in linqi |
| CVE-2026-48103 | 7.1 | 13.4 | mcmilk | 7-Zip | CWE-125 | GHSL-2026-119 7-Zip WIM SecurityId OOB read |
| CVE-2026-48111 | 7.1 | 13.4 | mcmilk | 7-Zip | CWE-125 | GHSL-2026-121 7-Zip UEFI DEPEX OOB Read |
| CVE-2026-46392 | 8.7 | 13.2 | haxtheweb | haxcms-php | CWE-178 | HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Val… |
| CVE-2026-25621 | 7.0 | 13.0 | Arista Networks | Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) | CWE-78 | Arista Edge Threat Management NGFW Reports Application Insecure Input Validation |
| CVE-2026-11332 | 7.8 | 11.9 | Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | CWE-88 | Ansible-core: argument injection in ansible-galaxy role install leads to arbi… |
| CVE-2026-11326 | 6.0 | 12.0 | OpenAI | OpenAI Atlas | CWE-284 | OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web cont… |
| CVE-2026-11333 | 2.1 | 12.0 | tittuvarghese | CollegeManagementSystem | CWE-284 | tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_stu… |
| CVE-2026-11336 | 2.1 | 12.0 | tittuvarghese | CollegeManagementSystem | CWE-266 | tittuvarghese CollegeManagementSystem Admin admin_page.php improper authoriza… |
| CVE-2026-11338 | 1.9 | 11.5 | SourceCodester | Ship Ferry Ticket Reservation System | CWE-79 | SourceCodester Ship Ferry Ticket Reservation System manage_user cross site sc… |
| CVE-2026-11369 | 7.1 | 11.1 | linqi GmbH | linqi | CWE-639 | IDOR in Comment API Allows Cross-Process Comment Read and Write |
| CVE-2026-8714 | 7.1 | 11.0 | TP-Link Systems Inc. | Tapo C520WS v2 | CWE-20 | Denial-of-Service Vulnerability in RTSP Input Handling on TP-Link's Tapo C520WS |
| CVE-2026-9719 | 4.3 | 11.0 | latepoint | LatePoint – Calendar Booking Plugin for Appointments and Events | CWE-352 | LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status A… |
| CVE-2020-25900 | 5.3 | 10.4 | HelloTalk | HelloTalk | CWE-359 | HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the u… |
| CVE-2026-38579 | 6.1 | 10.0 | n/a | n/a | CWE-79 | Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thai… |
| CVE-2026-50232 | 5.1 | 9.8 | LMS Community | Lyrion Music Server | CWE-79 | Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags |
| CVE-2026-8900 | 6.4 | 9.1 | spyrosvl | Simple SEO Slideshow | CWE-79 | Simple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Sit… |
| CVE-2026-48102 | 4.3 | 8.9 | mcmilk | 7-Zip | CWE-125 | GHSL-2026-118: 7-Zip UDF Field OOB Read |
| CVE-2026-8893 | 6.4 | 8.7 | payaddons | Express Payment For Stripe | CWE-79 | Express Payment For Stripe <= 1.28.0 - Authenticated (Contributor+) Stored Cr… |
| CVE-2026-46398 | 8.8 | 8.2 | haxtheweb | haxcms-php | CWE-614 | HAX CMS Missing Secure Flag on Cookie |
| CVE-2026-50231 | 5.1 | 8.2 | LMS Community | Lyrion Music Server | CWE-79 | Lyrion Music Server 9.2.0 Unauthenticated Stored XSS via server.log |
| CVE-2026-6239 | 6.8 | 7.9 | TP-Link Systems Inc. | Tapo C520WS v2 | CWE-121 | Authenticated Stack-based Buffer Overflow in ONVIF CreateUsers Service in TP-… |
| CVE-2026-6240 | 6.8 | 7.9 | TP-Link Systems Inc. | Tapo C520WS v2 | CWE-121 | Authenticated Stack-based Buffer Overflow in ONVIF DeleteUsers Service on TP-… |
| CVE-2026-48104 | 4.2 | 7.7 | mcmilk | 7-Zip | CWE-125 | GHSL-2026-120: 7-Zip SquashFS BlockToNode uninitialized heap read |
| CVE-2026-6242 | 6.8 | 7.2 | TP-Link Systems Inc. | Tapo C520WS v2 | CWE-134 | Authenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Li… |
| CVE-2026-45745 | 8.0 | 6.5 | Termix-SSH | Termix | CWE-295 | Termix has improper certificate validation in Electron desktop client that en… |
| CVE-2026-50259 | 7.8 | 6.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer over… |
| CVE-2025-59174 | 7.1 | 6.2 | Ericsson | Packet Core Controller | CWE-228 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulner… |
| CVE-2026-25657 | 7.1 | 6.2 | Ericsson | Packet Core Gateway (PCG) | CWE-228 | Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Inval… |
| CVE-2026-25658 | 7.1 | 6.2 | Ericsson | Packet Core Gateway (PCG) | CWE-230 | Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vuln… |
| CVE-2026-25659 | 7.1 | 6.2 | Ericsson | Packet Core Gateway (PCG) | CWE-230 | Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vuln… |
| CVE-2026-8608 | 5.3 | 6.2 | awordpresslife | Event Monster – Event Manager, Ticket Booking & Registration | CWE-345 | Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Au… |
| CVE-2026-37737 | 6.5 | 6.1 | n/a | n/a | CWE-346 | sanic-cors version 2.2.0 and prior contains an improper regular expression in… |
| CVE-2026-6241 | 6.8 | 6.0 | TP-Link Systems Inc. | Tapo C520WS v2 | CWE-134 | Authenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Lin… |
| CVE-2026-50258 | 7.8 | 5.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer over… |
| CVE-2026-41567 | 7.2 | 5.8 | moby | moby/v2/daemon | CWE-427 | Docker: `PUT /containers/{id}/archive` executes container binary on the host |
| CVE-2026-11422 | 8.4 | 5.6 | shd101wyy | Markdown Preview Enhanced | CWE-95 | Markdown Preview Enhanced 0.8.x Code Injection via WaveDrom Rendering |
| CVE-2026-50235 | 5.1 | 5.4 | LMS Community | Lyrion Music Server | CWE-79 | Lyrion Music Server 9.2.0 Reflected XSS via search Parameters |
| CVE-2026-50256 | 7.8 | 5.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer over… |
| CVE-2026-50260 | 7.8 | 5.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-416 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in… |
| CVE-2026-50261 | 7.8 | 5.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-416 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in… |
| CVE-2026-25624 | 5.8 | 5.1 | Arista Networks | Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) | CWE-79 | Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting |
| CVE-2026-21825 | 6.1 | 4.9 | HCLSoftware | DX Compose | CWE-79 | HCL Digital Experience Compose is affected by a reflected cross-site scriptin… |
| CVE-2026-34123 | 7.0 | 4.8 | TP-Link Systems Inc. | Tapo C520WS v2 | CWE-287 | Whitelist Validation Bypass in TP-Link Tapo C520WS |
| CVE-2026-50264 | 7.8 | 4.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds hea… |
| CVE-2026-50592 | 6.4 | 4.5 | Znuny | Znuny | CWE-79 | In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in … |
| CVE-2026-45778 | 8.6 | 4.4 | ubccr | xdmod | CWE-79 | Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset |
| CVE-2026-21826 | 6.1 | 4.2 | HCLSoftware | Digital Experience & DX Compose | CWE-601 | HCL Digital Experience and HCL Digital Experience Compose could be susceptibl… |
| CVE-2026-50257 | 7.8 | 4.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-416 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in… |
| CVE-2026-50263 | 5.5 | 3.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-416 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in… |
| CVE-2026-50591 | 5.4 | 3.3 | Znuny | Znuny | CWE-79 | In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored u… |
| CVE-2026-50262 | 5.5 | 3.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds rea… |
| CVE-2026-7047 | 4.3 | 3.2 | absikandar | Frontend User Notes | CWE-352 | Frontend User Notes <= 2.1.1 - Cross-Site Request Forgery to Note Content Mod… |
| CVE-2026-50593 | 7.3 | 1.6 | Graphite project | Graphite | CWE-191 | Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds w… |
| CVE-2026-11312 | 1.9 | 1.6 | bytedance | InfiniStore | CWE-404 | bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity |
| CVE-2026-21037 | 6.9 | 1.2 | Samsung Mobile | Samsung Members | — | Improper input validation in Samsung Members prior to version 5.8.01.5 allows… |
| CVE-2026-21038 | 5.9 | 1.0 | Samsung Mobile | Samsung Android USB Driver for Windows | CWE-125 | Improper input validation in Samsung Android USB Driver for Windows prior to … |
| CVE-2026-21030 | 6.4 | 0.7 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1… |
| CVE-2026-21036 | 6.3 | 0.7 | Samsung Mobile | Samsung Internet | CWE-863 | Improper authorization in Samsung Internet prior to version 30.0.0.39 allows … |
| CVE-2026-21025 | 6.9 | 0.6 | Samsung Mobile | Samsung Mobile Devices | — | Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 a… |
| CVE-2026-21032 | 6.9 | 0.6 | Samsung Mobile | Samsung Assistant | — | Improper export of android application components in SmartHomeWidgetReceiver … |
| CVE-2026-21033 | 6.9 | 0.6 | Samsung Mobile | Samsung Assistant | — | Improper export of android application components in ExpressHomeWidgetReceive… |
| CVE-2026-21029 | 6.8 | 0.7 | Samsung Mobile | Samsung Mobile Devices | — | Improper export of android application components in Galaxy Editing Service p… |
| CVE-2026-21026 | 6.4 | 0.6 | Samsung Mobile | Samsung Mobile Devices | — | Improper export of android application components in SpriteWallpaper prior to… |
| CVE-2026-21031 | 5.2 | 0.6 | Samsung Mobile | Samsung Mobile Devices | CWE-863 | Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows loc… |
| CVE-2026-21028 | 5.1 | 0.6 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 al… |
| CVE-2026-21017 | 4.6 | 0.6 | Samsung Mobile | Samsung Mobile Devices | — | Improper handling of insufficient privileges in SecTelephonyProvider prior to… |
| CVE-2026-50590 | 4.5 | 0.5 | Mimecast | Incydr | CWE-732 | In Mimecast Incydr before 2.6.0, arbitrary file access can occur. |
| CVE-2026-21027 | 4.8 | 0.3 | Samsung Mobile | Samsung Mobile Devices | — | Improper export of android application components in ImsSettings prior to SMR… |
| CVE-2026-21034 | 4.8 | 0.3 | Samsung Mobile | Samsung Auto | — | Improper export of android application components in Samsung Auto prior to ve… |
| CVE-2026-11329 | 2.0 | 0.2 | onnx | onnx-mlir | CWE-327 | onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash |
| CVE-2026-11330 | 2.0 | 0.1 | thedotmack | claude-mem | CWE-327 | thedotmack claude-mem Observation Content Hash store.ts computeObservationCon… |
| CVE-2026-11347 | 8.5 | 0.1 | linqi GmbH | linqi | CWE-321 | Hardcoded Cryptographic Keys and Weak IV Generation in linqi |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-05 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.