boxscore/security
Friday, June 5, 2026 · all times UTC← 2026-06-04 · archive · 2026-06-06 →

167 CVEs published June 5, 2026: 28 critical, 65 high, 61 medium, 13 low; 1 in KEV; 18 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 142 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1545591710442563
KEV catalog size1670

255 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux3410008163028612730.37.8.0013-33
google48866258331255157450.87.8.0023+488
microsoft7497443331030378275.47.8.0046+7
red hat1983840305400.07.4.0033+17
apple04701227193714.96.2.00340
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco215314096853.37.0.0694+2
ivanti16020033466.78.8.5751+1
checkpoint060330300.06.5.03380
fortinet06130028350.07.9.43300
zyxel2300301100.06.5.0017+2
f50320007133.39.2.09960
ubiquiti031200400.08.8.00680
broadcom02000042100.0.19900
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache32648262724011.67.2.0053+28
mozilla41033401300.07.4.0035+4
gitlab0901604222.24.3.00320
docker250500100.08.8.0021+2
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm5541326150700.07.5.0031+5
oracle128815404013.68.1.0027+1
progress591710900.07.5.0036+5
solarwinds25120011480.07.5.7155+2
adobe04010075375.08.6.27760
veeam031200400.08.6.00400
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link58031326112.56.0.0087+5
abb440400000.07.3.0024+4
siemens120110100.07.3.0026+1
hitachi energy020020000.05.7.00140
hikvision01000021100.01.00000
dahua000000200
qnap000000800
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax051032019100.07.4.00590
concrete cms1451101321000.06.0.0015+1
open ises044221210000.07.1.00210
sourcecodester2143001429000.02.1.0025+21
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
acer2636111960000.08.7.0024+26
nvidia23582070000.07.8.0029+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
Most disclosures (vendor)
VendorCVEs
google656
linux528
microsoft177
red hat58
ibm54
edimax51
apache49
concrete cms45
open ises44
sourcecodester43
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google5
ivanti4
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven24
PyPI10
Packagist7
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171661
CVE-2021-27102Accellion2021-11-171661
CVE-2021-27101Accellion2021-11-171661
CVE-2021-27103Accellion2021-11-171661
CVE-2021-21017Adobe2021-11-171661
CVE-2021-28550Adobe2021-11-171661
CVE-2021-42013Apache2021-11-171661
CVE-2021-41773Apache2021-11-171661
CVE-2021-30858Apple2021-11-171661
CVE-2021-30860Apple2021-11-171661

Transactions

EXPLOIT PUBLISHEDCVE-2026-45300 (AsyncHttpClient async-http-client). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45743 (Termix-SSH Termix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45744 (Termix-SSH Termix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45745 (Termix-SSH Termix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45746 (Termix-SSH Termix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45748 (Termix-SSH Termix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45749 (Termix-SSH Termix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45750 (Termix-SSH Termix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48092 (mcmilk 7-Zip). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48095 (mcmilk 7-Zip). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48101 (mcmilk 7-Zip). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48102 (mcmilk 7-Zip). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48103 (mcmilk 7-Zip). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48104 (mcmilk 7-Zip). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48111 (mcmilk 7-Zip). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48112 (mcmilk 7-Zip). Public exploit reference added.

DUE DATE PASSEDCVE-2024-21182 (Oracle WebLogic Server). CISA remediation deadline was June 4, 2026; still in catalog.

DUE DATE PASSEDCVE-2025-34291 (Langflow). CISA remediation deadline was June 4, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-34926 (Trend Micro, Inc. TrendAI Apex One). CISA remediation deadline was June 4, 2026; still in catalog.

Yesterday's Results

167 CVEs published. 25 box scores, 142 table rows — nothing truncated.

SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0835   94.5   YES
AFFECTED
  Product  Versions                        Fixed
  Serv-U   15.5.4 and previous versions –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jun 5   Added to CISA KEV, due Jun 19
  Jun 5   Published (CNA: SolarWinds)
CWE-400 · CNA: SolarWinds · 3 references · NVD status: Analyzed · KEV due June 19, 2026
Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   L   L    7.0   .0988   95.2     —
AFFECTED
  Product                                                                 Versions  Fixed
  Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)  17.4.0 –  —
TIMELINE
  Feb 3   Reserved by CNA
  Jun 5   Published (CNA: Arista)
CWE-78 · CNA: Arista · 1 reference · NVD status: Analyzed
Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   L   L    7.0   .0988   95.2     —
AFFECTED
  Product                                                                 Versions     Fixed
  Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)  unspecified  —
TIMELINE
  Feb 3   Reserved by CNA
  Jun 5   Published (CNA: Arista)
CWE-78 · CNA: Arista · 1 reference · NVD status: Analyzed
Arista Edge Threat Management NGFW UI Arbitrary Command Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   L   L    7.0   .0595   92.6     —
AFFECTED
  Product                                                                 Versions     Fixed
  Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)  unspecified  —
TIMELINE
  Feb 3   Reserved by CNA
  Jun 5   Published (CNA: Arista)
CWE-78 · CNA: Arista · 1 reference · NVD status: Analyzed
D-Link DWR-M920 formSmsManage sub_41C8E8 command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0424   90.2     —
AFFECTED
  Product   Versions  Fixed
  DWR-M920  1.1.50 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 5   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 6 references · NVD status: Analyzed
D-Link DWR-M920 formUSSDSetup sub_41CF20 command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0313   86.8     —
AFFECTED
  Product   Versions  Fixed
  DWR-M920  1.1.0 –   —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 5   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 6 references · NVD status: Analyzed
hippooo Hippoo Mobile App for WooCommerce — Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0295   86.0     —
AFFECTED
  Product                            Versions     Fixed
  Hippoo Mobile App for WooCommerce  unspecified  —
TIMELINE
  Jun 1   Reserved by CNA
  Jun 5   Published (CNA: Wordfence)
CWE-285 · CNA: Wordfence · 9 references · NVD status: Deferred
wpusermanager WP User Manager – User Profile Builder & Membership — WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0250   83.4     —
AFFECTED
  Product                                              Versions     Fixed
  WP User Manager – User Profile Builder & Membership  unspecified  —
TIMELINE
  May 22  Reserved by CNA
  Jun 5   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 13 references · NVD status: Deferred
Termix-SSH Termix — Termix has an OS Command Injection in File Manager resolvePath endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0201   79.2     —
AFFECTED
  Product  Versions   Fixed
  Termix   < 2.3.2 –  —
TIMELINE
  May 13  Reserved by CNA
  Jun 5   Public exploit reference published
  Jun 5   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 2 references · NVD status: Modified
Termix-SSH Termix — Termix Vulnerable to Remote Code Execution via SSH Tunnel Forward Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0173   75.6     —
AFFECTED
  Product  Versions   Fixed
  Termix   < 2.3.2 –  —
TIMELINE
  May 13  Reserved by CNA
  Jun 5   Public exploit reference published
  Jun 5   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 2 references · NVD status: Modified
ShapedPlugin, LLC Product Slider Pro for WooCommerce — WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0166   74.6     —
AFFECTED
  Product                             Versions  Fixed
  Product Slider Pro for WooCommerce  n/a –     3.5.4
TIMELINE
  Jun 1   Reserved by CNA
  Jun 5   Published (CNA: Patchstack)
CWE-1284 · CNA: Patchstack · 1 reference · NVD status: Deferred
Altium Altium Enterprise Server — Path Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0115   64.0     —
AFFECTED
  Product                   Versions       Fixed
  Altium Enterprise Server  unspecified    —
  Altium 365                unspecified –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 5   Published (CNA: Altium)
CWE-22, CWE-306 · CNA: Altium · 1 reference · NVD status: Awaiting Analysis
mcmilk 7-Zip — GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0112   63.3     —
AFFECTED
  Product  Versions    Fixed
  7-Zip    <= 26.00 –  —
TIMELINE
  May 20  Reserved by CNA
  Jun 5   Public exploit reference published
  Jun 5   Published (CNA: GitHub_M)
CWE-190, CWE-787 · CNA: GitHub_M · 2 references · NVD status: Modified
D-Link DWR-M920 formIMEISetup sub_412DA0 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0104   61.3     —
AFFECTED
  Product   Versions  Fixed
  DWR-M920  1.1.0 –   —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 5   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
HCLSoftware Digital Experience — HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0092   57.3     —
AFFECTED
  Product             Versions  Fixed
  Digital Experience  9.5 –     —
TIMELINE
  Jan 5   Reserved by CNA
  Jun 5   Published (CNA: HCL)
CWE-78 · CNA: HCL · 1 reference · NVD status: Analyzed
codepress Admin Columns — Admin Columns <= 7.0.18 - Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0091   56.9     —
AFFECTED
  Product        Versions     Fixed
  Admin Columns  unspecified  —
TIMELINE
  May 1   Reserved by CNA
  Jun 5   Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · 10 references · NVD status: Deferred
haxtheweb haxcms-php — HAX CMS Vulnerable to Command Injection using Git.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   H   H    7.7   .0077   52.6     —
AFFECTED
  Product     Versions    Fixed
  haxcms-php  < 26.0.0 –  —
TIMELINE
  May 13  Reserved by CNA
  Jun 5   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Altium Altium Enterprise Server — Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File Read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0071   50.5     —
AFFECTED
  Product                   Versions     Fixed
  Altium Enterprise Server  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 5   Published (CNA: Altium)
CWE-22, CWE-306 · CNA: Altium · 1 reference · NVD status: Analyzed
n/a n/a — An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0069   49.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 5   Published (CNA: mitre)
CWE-22 · CNA: mitre · 2 references · NVD status: Deferred
LMS Community Lyrion Music Server — Lyrion Music Server 9.2.0 Path Traversal File Read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0064   47.7     —
AFFECTED
  Product              Versions  Fixed
  Lyrion Music Server  9.2.0 –   —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 5   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 2 references · NVD status: Deferred
webfactory Advanced Google reCAPTCHA — WP Captcha PRO <= 5.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0061   46.4     —
AFFECTED
  Product                    Versions     Fixed
  Advanced Google reCAPTCHA  unspecified  —
TIMELINE
  Apr 2   Reserved by CNA
  Jun 5   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 2 references · NVD status: Deferred
Morse Micro HaLowLink 2 — Heap buffer overflow in dot11ah.ko S1G Capabilities IE processing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0057   44.3     —
AFFECTED
  Product      Versions     Fixed
  HaLowLink 2  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  Jun 5   Published (CNA: Bugcrowd)
CNA: Bugcrowd · 1 reference · NVD status: Awaiting Analysis
Altium Altium Enterprise Server — Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0055   43.3     —
AFFECTED
  Product                   Versions     Fixed
  Altium Enterprise Server  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 5   Published (CNA: Altium)
CWE-22, CWE-434 · CNA: Altium · 1 reference · NVD status: Analyzed
Teltonika Networks RUTOS — Command injection in Profile change function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   H   N   H   H   H    8.4   .0054   43.0     —
AFFECTED
  Product  Versions  Fixed
  RUTOS    7.22 –    —
  TSWOS    1.09 –    —
TIMELINE
  May 19  Reserved by CNA
  Jun 5   Published (CNA: tlt_net)
CWE-95 · CNA: tlt_net · 1 reference · NVD status: Awaiting Analysis
webfactory Advanced Google reCAPTCHA — WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0054   42.9     —
AFFECTED
  Product                    Versions     Fixed
  Advanced Google reCAPTCHA  unspecified  —
TIMELINE
  Apr 2   Reserved by CNA
  Jun 5   Published (CNA: Wordfence)
CWE-288 · CNA: Wordfence · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-77639.842.7Morse MicroHaLowLink 2Heap buffer overflow in morse.ko TIM IE processing
CVE-2025-713189.342.6Riello UPSNetMan 204CWE-306NetMan 204 Missing Authentication for Administrative Functions
CVE-2026-107325.641.8n/adecompressCWE-29All versions of the package decompress are vulnerable to Arbitrary File Write…
CVE-2026-114318.341.6AltiumAltium Enterprise ServerCWE-22Path Traversal in Altium Projects Service Allows Arbitrary File Read
CVE-2026-108799.839.6HMBRANDDBICWE-787DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL s…
CVE-2026-457799.339.3ubccrxdmodCWE-89Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Databa…
CVE-2026-1141410.039.2AltiumAltium Enterprise ServerCWE-22Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service v…
CVE-2026-114167.238.6jxxghpMoviePilotCWE-22MoviePilot Path Traversal via Cloud Storage Download Handlers
CVE-2026-62749.838.0DTS Electronics Industry and Trade Ltd. Co.Redline WR3200CWE-287Authentication Bypass in DTS Electronics' Redline WR3200
CVE-2026-463918.737.9haxtheweb@haxtheweb/open-apisCWE-183HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in ope…
CVE-2026-113629.837.1BINARYDataDog::DogStatsdCWE-93DataDog::DogStatsd versions through 0.07 for Perl allow metric injections fro…
CVE-2025-713179.336.0Riello UPSNetMan 204CWE-798NetMan 204 Hard-coded Backdoor Credentials
CVE-2026-113456.934.5linqi GmbHlinqiCWE-287Improper Authentication Bypass in linqi CDN File Access
CVE-2026-454096.934.0kjdidnaCWE-1333Internationalized Domain Names in Applications (IDNA): Specially crafted inpu…
CVE-2026-502305.133.8LMS CommunityLyrion Music ServerCWE-79Lyrion Music Server 9.2.0 Reflected XSS via server.log
CVE-2025-126563.832.1wpvividpluginsWPvivid — Backup, Migration & StagingCWE-73Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenti…
CVE-2026-457779.332.0ubccrxdmodCWE-78Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS C…
CVE-2026-457469.031.9Termix-SSHTermixCWE-284Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
CVE-2026-464008.731.8haxthewebhaxcms-phpCWE-434HAXCMS PHP has a File Upload Validation Bypass
CVE-2026-113445.529.7code-projectsVehicle Management SystemCWE-284code-projects Vehicle Management System New Driver Registration Form newdrive…
CVE-2026-507338.629.3shd101wyyMarkdown Preview EnhancedCWE-95Markdown Preview Enhanced Arbitrary Code Execution via WaveDrom eval()
CVE-2026-453278.228.7DatanoiseTVtinyiceCWE-306TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized…
CVE-2026-367857.528.8n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to con…
CVE-2026-64484.928.3expresstechQuiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-89Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection…
CVE-2026-90882.727.9Red HatRed Hat build of Keycloak 26.4CWE-1220Keycloak: keycloak: information disclosure due to user profile permission bypass
CVE-2026-463899.827.1defenseunicornsuds-identity-configCWE-287UDS Identity Config has a client authentication bypass in `ClientIdAndKuberne…
CVE-2026-494928.627.0shd101wyyMarkdown Preview EnhancedCWE-78Markdown Preview Enhanced OS Command Injection in External File and Link Opening
CVE-2026-92709.126.0BINARYDataDog::DogStatsdCWE-93DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
CVE-2026-494938.625.5shd101wyyMarkdown Preview EnhancedCWE-94Markdown Preview Enhanced Arbitrary Code Execution via Bitfield interpretJS()
CVE-2026-457498.125.3Termix-SSHTermixCWE-308Termix's TOTP two-factor authentication can be disabled or bypassed using onl…
CVE-2026-480928.125.2mcmilk7-ZipCWE-1257-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)
CVE-2025-50888.725.1Arista NetworksEOS / CloudVision eXchange (CVX)CWE-269Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis …
CVE-2026-453007.425.0AsyncHttpClientasync-http-clientCWE-200async-http-client: Cookie header not stripped on cross-origin redirect
CVE-2026-114239.424.9AltiumAltium Enterprise ServerCWE-22Path Traversal in Altium Enterprise Server Collaboration Service Allows Privi…
CVE-2026-464015.323.8haxthewebissuesCWE-613HAX CMS PHP has Insufficient Session Expiration
CVE-2026-114008.623.1AWSAWS Advanced JDBC WrapperCWE-426Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL
CVE-2026-114018.623.1AWSAWS Advanced Go WrapperCWE-426Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL
CVE-2026-210356.522.4Samsung MobileSamsung Plus TVImproper input validation in Samsung Plus TV prior to version 1.0.28.6 allows…
CVE-2026-463959.322.0haxthewebhaxcms-nodejsCWE-200HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-457509.021.9Termix-SSHTermixCWE-78Termix Vulnerable to Arbitrary Command Execution in File Manager
CVE-2026-502336.921.9LMS CommunityLyrion Music ServerCWE-548Lyrion Music Server 9.2.0 Arbitrary Directory Listing
CVE-2026-463999.421.5haxthewebhaxcms-nodejsCWE-15Authenticated Remote Code Execution via File Overwrite
CVE-2026-89764.321.5themeisleRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds AggregatorCWE-862RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (C…
CVE-2026-463976.521.4haxthewebhaxcms-phpCWE-22haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0
CVE-2026-464937.521.3haxthewebhaxcms-phpCWE-338haxtheweb/haxcms-php uses insecure method for generating salt
CVE-2026-100384.321.0smubCharitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & MoreCWE-639Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object R…
CVE-2026-113345.520.9tittuvargheseCollegeManagementSystemCWE-74tittuvarghese CollegeManagementSystem fetch.php sql injection
CVE-2026-457438.120.7Termix-SSHTermixCWE-639Termix has a File-Manager Session Hijack via Missing Ownership Check (IDOR)
CVE-2026-365017.520.3n/an/aCWE-20An issue in the Externalizable.readExternal() component of Controller v12.0.5…
CVE-2026-452907.520.2CloudburstMCNetworkCWE-770Cloudburst Network has DoS in RakNet connection handling due to missing bound…
CVE-2026-481016.520.1mcmilk7-ZipCWE-908GHSL-2026-117: 7-Zip UEFI Capsule uninitialized heap memory disclosure
CVE-2026-457589.620.0guardrails-aiguardrailsCWE-506Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
CVE-2026-465118.719.9haxthewebhaxcms-nodejsCWE-79HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
CVE-2026-113372.119.7tittuvargheseCollegeManagementSystemCWE-79tittuvarghese CollegeManagementSystem fetch.php cross site scripting
CVE-2026-75234.319.5alejo30Alba BoardCWE-862Alba Board <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Se…
CVE-2026-463906.919.2haxthewebhaxcms-phpCWE-639HAX CMS has Unauthenticated Git Access via User-Controlled Key
CVE-2026-481126.518.9mcmilk7-ZipCWE-125GHSL-2026-122 7-Zip Ar SYMDEF OOB Read
CVE-2026-452917.518.2CloudburstMCNetworkCWE-20Cloudburst Network erroneously handles invalid connections
CVE-2026-113425.518.2code-projectsHotel and Tourism Reservation SystemCWE-74code-projects Hotel and Tourism Reservation System details.php sql injection
CVE-2026-463576.515.3haxthewebhaxcms-nodejsCWE-20HAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Im…
CVE-2026-463937.115.1haxthewebhaxcms-nodejsCWE-918HAXcms createSite SSRF Enables Arbitrary File Read
CVE-2026-457765.314.9ubccrxdmodCWE-284Open XDMoD has Broken Access Control via Client-Controlled Session Variable
CVE-2025-50897.114.6Arista NetworksEOS / CloudVision eXchange (CVX)CWE-20Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Mess…
CVE-2025-50907.114.6Arista NetworksEOS / CloudVision eXchange (CVX)CWE-20Arista CloudVision Exchange Cluster Instability via Unexpected Switch Messages
CVE-2026-113352.114.3tittuvargheseCollegeManagementSystemCWE-384tittuvarghese CollegeManagementSystem login-form.php session_start session fi…
CVE-2026-463969.314.1haxthewebhaxcms-nodejsCWE-79HAX CMS has a stored XSS via <iframe> that allows access to sensitive client-…
CVE-2026-464969.314.1haxthewebhaxcms-nodejsCWE-79HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScrip…
CVE-2026-114248.313.5AltiumAltium Enterprise ServerCWE-200Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows …
CVE-2026-23798.213.5Arista NetworksEOSCWE-672Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Ant…
CVE-2026-113465.313.5linqi GmbHlinqiCWE-918Server-Side Request Forgery (SSRF) allowing Internal Network Probing in linqi
CVE-2026-481037.113.4mcmilk7-ZipCWE-125GHSL-2026-119 7-Zip WIM SecurityId OOB read
CVE-2026-481117.113.4mcmilk7-ZipCWE-125GHSL-2026-121 7-Zip UEFI DEPEX OOB Read
CVE-2026-463928.713.2haxthewebhaxcms-phpCWE-178HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Val…
CVE-2026-256217.013.0Arista NetworksArista Edge Threat Management - Arista Next Generation Firewall (NGFW)CWE-78Arista Edge Threat Management NGFW Reports Application Insecure Input Validation
CVE-2026-113327.811.9Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-88Ansible-core: argument injection in ansible-galaxy role install leads to arbi…
CVE-2026-113266.012.0OpenAIOpenAI AtlasCWE-284OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web cont…
CVE-2026-113332.112.0tittuvargheseCollegeManagementSystemCWE-284tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_stu…
CVE-2026-113362.112.0tittuvargheseCollegeManagementSystemCWE-266tittuvarghese CollegeManagementSystem Admin admin_page.php improper authoriza…
CVE-2026-113381.911.5SourceCodesterShip Ferry Ticket Reservation SystemCWE-79SourceCodester Ship Ferry Ticket Reservation System manage_user cross site sc…
CVE-2026-113697.111.1linqi GmbHlinqiCWE-639IDOR in Comment API Allows Cross-Process Comment Read and Write
CVE-2026-87147.111.0TP-Link Systems Inc.Tapo C520WS v2CWE-20Denial-of-Service Vulnerability in RTSP Input Handling on TP-Link's Tapo C520WS
CVE-2026-97194.311.0latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-352LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status A…
CVE-2020-259005.310.4HelloTalkHelloTalkCWE-359HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the u…
CVE-2026-385796.110.0n/an/aCWE-79Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thai…
CVE-2026-502325.19.8LMS CommunityLyrion Music ServerCWE-79Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags
CVE-2026-89006.49.1spyrosvlSimple SEO SlideshowCWE-79Simple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Sit…
CVE-2026-481024.38.9mcmilk7-ZipCWE-125GHSL-2026-118: 7-Zip UDF Field OOB Read
CVE-2026-88936.48.7payaddonsExpress Payment For StripeCWE-79Express Payment For Stripe <= 1.28.0 - Authenticated (Contributor+) Stored Cr…
CVE-2026-463988.88.2haxthewebhaxcms-phpCWE-614HAX CMS Missing Secure Flag on Cookie
CVE-2026-502315.18.2LMS CommunityLyrion Music ServerCWE-79Lyrion Music Server 9.2.0 Unauthenticated Stored XSS via server.log
CVE-2026-62396.87.9TP-Link Systems Inc.Tapo C520WS v2CWE-121Authenticated Stack-based Buffer Overflow in ONVIF CreateUsers Service in TP-…
CVE-2026-62406.87.9TP-Link Systems Inc.Tapo C520WS v2CWE-121Authenticated Stack-based Buffer Overflow in ONVIF DeleteUsers Service on TP-…
CVE-2026-481044.27.7mcmilk7-ZipCWE-125GHSL-2026-120: 7-Zip SquashFS BlockToNode uninitialized heap read
CVE-2026-62426.87.2TP-Link Systems Inc.Tapo C520WS v2CWE-134Authenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Li…
CVE-2026-457458.06.5Termix-SSHTermixCWE-295Termix has improper certificate validation in Electron desktop client that en…
CVE-2026-502597.86.1Red HatRed Hat Enterprise Linux 10CWE-121Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer over…
CVE-2025-591747.16.2EricssonPacket Core ControllerCWE-228Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulner…
CVE-2026-256577.16.2EricssonPacket Core Gateway (PCG)CWE-228Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Inval…
CVE-2026-256587.16.2EricssonPacket Core Gateway (PCG)CWE-230Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vuln…
CVE-2026-256597.16.2EricssonPacket Core Gateway (PCG)CWE-230Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vuln…
CVE-2026-86085.36.2awordpresslifeEvent Monster – Event Manager, Ticket Booking & RegistrationCWE-345Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Au…
CVE-2026-377376.56.1n/an/aCWE-346sanic-cors version 2.2.0 and prior contains an improper regular expression in…
CVE-2026-62416.86.0TP-Link Systems Inc.Tapo C520WS v2CWE-134Authenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Lin…
CVE-2026-502587.85.8Red HatRed Hat Enterprise Linux 10CWE-121Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer over…
CVE-2026-415677.25.8mobymoby/v2/daemonCWE-427Docker: `PUT /containers/{id}/archive` executes container binary on the host
CVE-2026-114228.45.6shd101wyyMarkdown Preview EnhancedCWE-95Markdown Preview Enhanced 0.8.x Code Injection via WaveDrom Rendering
CVE-2026-502355.15.4LMS CommunityLyrion Music ServerCWE-79Lyrion Music Server 9.2.0 Reflected XSS via search Parameters
CVE-2026-502567.85.4Red HatRed Hat Enterprise Linux 10CWE-121Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer over…
CVE-2026-502607.85.1Red HatRed Hat Enterprise Linux 10CWE-416Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in…
CVE-2026-502617.85.1Red HatRed Hat Enterprise Linux 10CWE-416Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in…
CVE-2026-256245.85.1Arista NetworksArista Edge Threat Management - Arista Next Generation Firewall (NGFW)CWE-79Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting
CVE-2026-218256.14.9HCLSoftwareDX ComposeCWE-79HCL Digital Experience Compose is affected by a reflected cross-site scriptin…
CVE-2026-341237.04.8TP-Link Systems Inc.Tapo C520WS v2CWE-287Whitelist Validation Bypass in TP-Link Tapo C520WS
CVE-2026-502647.84.5Red HatRed Hat Enterprise Linux 10CWE-787Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds hea…
CVE-2026-505926.44.5ZnunyZnunyCWE-79In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in …
CVE-2026-457788.64.4ubccrxdmodCWE-79Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset
CVE-2026-218266.14.2HCLSoftwareDigital Experience & DX ComposeCWE-601HCL Digital Experience and HCL Digital Experience Compose could be susceptibl…
CVE-2026-502577.84.0Red HatRed Hat Enterprise Linux 10CWE-416Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in…
CVE-2026-502635.53.9Red HatRed Hat Enterprise Linux 10CWE-416Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in…
CVE-2026-505915.43.3ZnunyZnunyCWE-79In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored u…
CVE-2026-502625.53.2Red HatRed Hat Enterprise Linux 10CWE-125Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds rea…
CVE-2026-70474.33.2absikandarFrontend User NotesCWE-352Frontend User Notes <= 2.1.1 - Cross-Site Request Forgery to Note Content Mod…
CVE-2026-505937.31.6Graphite projectGraphiteCWE-191Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds w…
CVE-2026-113121.91.6bytedanceInfiniStoreCWE-404bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
CVE-2026-210376.91.2Samsung MobileSamsung MembersImproper input validation in Samsung Members prior to version 5.8.01.5 allows…
CVE-2026-210385.91.0Samsung MobileSamsung Android USB Driver for WindowsCWE-125Improper input validation in Samsung Android USB Driver for Windows prior to …
CVE-2026-210306.40.7Samsung MobileSamsung Mobile DevicesImproper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1…
CVE-2026-210366.30.7Samsung MobileSamsung InternetCWE-863Improper authorization in Samsung Internet prior to version 30.0.0.39 allows …
CVE-2026-210256.90.6Samsung MobileSamsung Mobile DevicesIncorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 a…
CVE-2026-210326.90.6Samsung MobileSamsung AssistantImproper export of android application components in SmartHomeWidgetReceiver …
CVE-2026-210336.90.6Samsung MobileSamsung AssistantImproper export of android application components in ExpressHomeWidgetReceive…
CVE-2026-210296.80.7Samsung MobileSamsung Mobile DevicesImproper export of android application components in Galaxy Editing Service p…
CVE-2026-210266.40.6Samsung MobileSamsung Mobile DevicesImproper export of android application components in SpriteWallpaper prior to…
CVE-2026-210315.20.6Samsung MobileSamsung Mobile DevicesCWE-863Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows loc…
CVE-2026-210285.10.6Samsung MobileSamsung Mobile DevicesImproper access control in AuditLogService prior to SMR Jun-2026 Release 1 al…
CVE-2026-210174.60.6Samsung MobileSamsung Mobile DevicesImproper handling of insufficient privileges in SecTelephonyProvider prior to…
CVE-2026-505904.50.5MimecastIncydrCWE-732In Mimecast Incydr before 2.6.0, arbitrary file access can occur.
CVE-2026-210274.80.3Samsung MobileSamsung Mobile DevicesImproper export of android application components in ImsSettings prior to SMR…
CVE-2026-210344.80.3Samsung MobileSamsung AutoImproper export of android application components in Samsung Auto prior to ve…
CVE-2026-113292.00.2onnxonnx-mlirCWE-327onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash
CVE-2026-113302.00.1thedotmackclaude-memCWE-327thedotmack claude-mem Observation Content Hash store.ts computeObservationCon…
CVE-2026-113478.50.1linqi GmbHlinqiCWE-321Hardcoded Cryptographic Keys and Weak IV Generation in linqi

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-05 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.