CVSS EPSS %ile KEV — .8301 99.6 YES
AFFECTED Product Versions Fixed LiteLLM unspecified —
TIMELINE Jun 8 Added to CISA KEV, due Jun 22 Jun 8 Published
286 CVEs published June 8, 2026: 23 critical, 132 high, 82 medium, 48 low; 2 in KEV; 11 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 261 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1893 | 6265 | 1049 | 2563 |
| KEV catalog size | 1670 | |||
263 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 75 | 1041 | 82 | 649 | 307 | 1 | 27 | 3 | 0.3 | 7.8 | .0013 | -135 |
| 561 | 735 | 65 | 381 | 267 | 19 | 74 | 5 | 0.7 | 8.1 | .0023 | +561 | |
| microsoft | 7 | 497 | 44 | 333 | 103 | 0 | 378 | 27 | 5.4 | 7.8 | .0046 | -5 |
| red hat | 22 | 86 | 8 | 41 | 32 | 5 | 4 | 0 | 0.0 | 7.3 | .0033 | +18 |
| apple | 0 | 47 | 0 | 12 | 27 | 1 | 93 | 7 | 14.9 | 6.2 | .0034 | 0 |
| canonical | 0 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | 0 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| suse | 0 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.2 | .0020 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 2 | 15 | 3 | 1 | 4 | 0 | 96 | 8 | 53.3 | 7.0 | .0694 | +2 |
| checkpoint | 2 | 8 | 1 | 4 | 3 | 0 | 3 | 1 | 12.5 | 7.5 | .0423 | +2 |
| ivanti | 1 | 6 | 0 | 2 | 0 | 0 | 33 | 4 | 66.7 | 8.8 | .5751 | 0 |
| fortinet | 0 | 6 | 1 | 3 | 0 | 0 | 28 | 3 | 50.0 | 7.9 | .4330 | 0 |
| vmware | 3 | 3 | 0 | 1 | 2 | 0 | 21 | 0 | 0.0 | 5.4 | .0031 | +3 |
| zyxel | 2 | 3 | 0 | 0 | 3 | 0 | 11 | 0 | 0.0 | 6.5 | .0017 | +2 |
| f5 | 0 | 3 | 2 | 0 | 0 | 0 | 7 | 1 | 33.3 | 9.2 | .0996 | 0 |
| ubiquiti | 0 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.8 | .0068 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 46 | 78 | 12 | 33 | 30 | 2 | 40 | 1 | 1.3 | 7.3 | .0056 | +42 |
| mozilla | 4 | 10 | 3 | 3 | 4 | 0 | 13 | 0 | 0.0 | 7.4 | .0035 | 0 |
| gitlab | 0 | 9 | 0 | 1 | 6 | 0 | 4 | 2 | 22.2 | 4.3 | .0032 | 0 |
| docker | 2 | 5 | 0 | 5 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0021 | +2 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ibm | 5 | 54 | 13 | 26 | 15 | 0 | 7 | 0 | 0.0 | 7.5 | .0031 | +5 |
| oracle | 1 | 28 | 8 | 15 | 4 | 0 | 40 | 1 | 3.6 | 8.1 | .0027 | +1 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +5 |
| solarwinds | 2 | 5 | 1 | 2 | 0 | 0 | 11 | 4 | 80.0 | 7.5 | .7155 | +2 |
| adobe | 0 | 4 | 0 | 1 | 0 | 0 | 75 | 3 | 75.0 | 8.6 | .2776 | 0 |
| veeam | 0 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.6 | .0040 | 0 |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 8 | 11 | 0 | 3 | 2 | 5 | 26 | 1 | 9.1 | 4.2 | .0059 | +8 |
| abb | 4 | 4 | 0 | 4 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0024 | +4 |
| siemens | 1 | 2 | 0 | 1 | 1 | 0 | 1 | 0 | 0.0 | 7.3 | .0026 | +1 |
| hitachi energy | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | 0 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 35 | 57 | 0 | 0 | 24 | 33 | 0 | 0 | 0.0 | 2.1 | .0026 | +35 |
| edimax | 0 | 51 | 0 | 32 | 0 | 19 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| concrete cms | 1 | 45 | 1 | 10 | 13 | 21 | 0 | 0 | 0.0 | 6.0 | .0015 | +1 |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | 0 |
| helmholz | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| mb connect line | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| totolink | 2 | 37 | 0 | 26 | 0 | 11 | 0 | 0 | 0.0 | 8.9 | .0191 | +2 |
| acer | 26 | 36 | 11 | 19 | 6 | 0 | 0 | 0 | 0.0 | 8.7 | .0024 | +26 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2026-43500 | .9285 | 99.8 | 7.8 |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2009-3459 | .8658 | 99.7 | — |
| CVE-2025-34291 | .8384 | 99.7 | — |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-43997 | 10.0 | .0098 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-44005 | 10.0 | .0083 | |
| CVE-2026-44006 | 10.0 | .0081 |
| Vendor | CVEs |
|---|---|
| 729 | |
| linux | 505 |
| microsoft | 165 |
| apache | 63 |
| red hat | 59 |
| sourcecodester | 57 |
| ibm | 54 |
| edimax | 51 |
| concrete cms | 45 |
| open ises | 44 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 8 |
| apple | 7 |
| 5 | |
| ivanti | 4 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 24 |
| PyPI | 10 |
| Packagist | 9 |
| npm | 3 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1664 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1664 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1664 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1664 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1664 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1664 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1664 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1664 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1664 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1664 |
EXPLOIT PUBLISHED — CVE-2026-35058 (OpenVPN). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42861 (FlowiseAI Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42862 (FlowiseAI Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42863 (FlowiseAI Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46441 (FlowiseAI Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46442 (FlowiseAI Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46443 (FlowiseAI Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46490 (tngan samlify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49755 (wojtekmach req). Public exploit reference added.
286 CVEs published. 25 box scores, 261 table rows — nothing truncated.
CVSS EPSS %ile KEV — .8301 99.6 YES
AFFECTED Product Versions Fixed LiteLLM unspecified —
TIMELINE Jun 8 Added to CISA KEV, due Jun 22 Jun 8 Published
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H L N 9.3 .8255 99.6 YES
AFFECTED Product Versions Fixed Quantum Security Gateway R82.10 with Jumbo Hotfix Take 19 or below – — Spark Firewalls R80.20.X, R81.10.X, and R82.00.X – —
TIMELINE Jun 7 Reserved by CNA Jun 8 Added to CISA KEV, due Jun 11 Jun 8 Published (CNA: checkpoint)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .2798 97.9 —
AFFECTED Product Versions Fixed Apache HTTP Server 2.4.17 – —
TIMELINE Jun 2 Reserved by CNA Jun 8 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0656 93.2 —
AFFECTED Product Versions Fixed HG7HG9 300001138_en_xpon – — HG10 300001138_en_xpon – —
TIMELINE Jun 7 Reserved by CNA Jun 8 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H N 7.4 .0455 90.8 —
AFFECTED Product Versions Fixed Quantum Security Gateway R82.10 with Jumbo Hotfix Take 19 or below – — Spark Firewalls R80.20.X, R81.10.X, and R82.00.X – —
TIMELINE Jun 7 Reserved by CNA Jun 8 Published (CNA: checkpoint)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0380 89.1 —
AFFECTED Product Versions Fixed HG7HG9 300001138_en_xpon – — HG10 300001138_en_xpon – —
TIMELINE Jun 7 Reserved by CNA Jun 8 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0349 88.1 —
AFFECTED Product Versions Fixed Flowise < 3.1.2 – —
TIMELINE May 13 Reserved by CNA Jun 8 Public exploit reference published Jun 8 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0267 84.5 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 10 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified — Red Hat Enterprise Linux 8 unspecified — Red Hat Enterprise Linux 9 unspecified — Red Hat OpenShift Container Platform 4 unspecified —
TIMELINE Feb 26 Reserved by CNA Jun 8 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0182 77.0 —
AFFECTED Product Versions Fixed openbullet2 unspecified —
TIMELINE Feb 2 Reserved by CNA Jun 8 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0161 73.9 —
AFFECTED Product Versions Fixed F451 1.0.0.7 – —
TIMELINE Jun 8 Reserved by CNA Jun 8 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0124 66.6 —
AFFECTED Product Versions Fixed Bagisto version v2.4.1 – —
TIMELINE May 25 Reserved by CNA Jun 8 Published (CNA: CERT-In)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0112 63.4 —
AFFECTED Product Versions Fixed Apache HTTP Server 2.4.0 – —
TIMELINE Mar 27 Reserved by CNA Jun 8 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0099 59.5 —
AFFECTED Product Versions Fixed Apache HTTP Server 2.4.0 – —
TIMELINE Apr 28 Reserved by CNA Jun 8 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0092 57.4 —
AFFECTED Product Versions Fixed Neovim 0.12.0 – —
TIMELINE Jun 7 Reserved by CNA Jun 8 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 7.7 .0092 57.4 —
AFFECTED Product Versions Fixed nginx-proxy-manager 2.9.14 – a5db5ed156355e3088e7d1ceb0533d4bae922def
TIMELINE Apr 13 Reserved by CNA Jun 8 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N H N H H H 8.5 .0091 56.9 —
AFFECTED Product Versions Fixed Archer MR600 v5 unspecified —
TIMELINE May 18 Reserved by CNA Jun 8 Published (CNA: TPLink)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0084 54.8 —
AFFECTED Product Versions Fixed Background Image Cropper 1.2 – —
TIMELINE Jun 5 Reserved by CNA Jun 8 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H H H 9.5 .0072 51.0 —
AFFECTED Product Versions Fixed Cordova Plugin InAppBrowser 3.1.0 – —
TIMELINE May 19 Reserved by CNA Jun 8 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L L 7.3 .0071 50.6 —
AFFECTED Product Versions Fixed Apache HTTP Server 2.4.0 – —
TIMELINE May 5 Reserved by CNA Jun 8 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0071 50.5 —
AFFECTED Product Versions Fixed Apache HTTP Server 2.4.0 – —
TIMELINE Mar 27 Reserved by CNA Jun 8 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 49.7 —
AFFECTED Product Versions Fixed Apache HTTP Server 2.4.0 – —
TIMELINE Mar 4 Reserved by CNA Jun 8 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0067 49.2 —
AFFECTED Product Versions Fixed Travelscape 1.0.3 – —
TIMELINE Jun 6 Reserved by CNA Jun 8 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0061 46.5 —
AFFECTED Product Versions Fixed Travelscape 1.0.3 – —
TIMELINE Jan 10 Reserved by CNA Jun 8 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0060 45.9 —
AFFECTED Product Versions Fixed HiPER 2610G 3.0.0-171107 – —
TIMELINE Jun 7 Reserved by CNA Jun 8 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L L 7.3 .0058 45.1 —
AFFECTED Product Versions Fixed Apache HTTP Server 2.4.0 – —
TIMELINE May 5 Reserved by CNA Jun 8 Published (CNA: apache)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-25855 | 8.7 | 44.5 | openbullet | openbullet2 | CWE-78 | OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload |
| CVE-2026-25559 | 8.7 | 44.3 | openbullet | openbullet2 | CWE-22 | OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint |
| CVE-2026-52778 | 9.8 | 44.0 | YesWiki | yeswiki | CWE-94 | YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE)… |
| CVE-2026-43951 | 6.5 | 43.2 | Apache Software Foundation | Apache HTTP Server | CWE-125 | Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash |
| CVE-2026-41448 | 9.2 | 43.0 | AdguardTeam | AdGuardHome | CWE-22 | AdGuard Home Authentication Bypass via Path Traversal in Admin-Token Cookie |
| CVE-2026-42535 | 9.1 | 42.8 | Apache Software Foundation | Apache HTTP Server | CWE-668 | Apache HTTP Server: mod_dav_fs protected directory access |
| CVE-2023-54350 | 8.7 | 42.5 | webandprint | Augmented Reality | CWE-306 | WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated |
| CVE-2026-36789 | 7.5 | 42.3 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered t… |
| CVE-2026-29170 | 6.1 | 42.0 | Apache Software Foundation | Apache HTTP Server | CWE-79 | Apache HTTP Server: mod_proxy_ftp XSS |
| CVE-2026-11492 | 2.1 | 41.2 | D-Link | DIR-823G | CWE-266 | D-Link DIR-823G vsftpd vsftpd.conf least privilege violation |
| CVE-2026-44631 | 9.8 | 40.8 | Apache Software Foundation | Apache HTTP Server | CWE-124 | Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow |
| CVE-2026-48913 | 7.3 | 39.3 | Apache Software Foundation | Apache HTTP Server | CWE-416 | Apache HTTP Server: mod_http2 memory corruption when file handles exhausted |
| CVE-2026-11553 | 7.4 | 39.2 | Tenda | HG7HG9 | CWE-119 | Tenda HG7HG9/HG10 formPPPEdit stack-based overflow |
| CVE-2026-11557 | 7.4 | 39.1 | Tenda | F451 | CWE-119 | Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow |
| CVE-2026-25856 | 8.7 | 38.9 | openbullet | openbullet2 | CWE-94 | OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface |
| CVE-2026-46490 | 8.7 | 38.6 | tngan | samlify | CWE-91 | samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signe… |
| CVE-2026-11503 | 7.4 | 38.4 | Tenda | CX12L | CWE-119 | Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_sett… |
| CVE-2026-11504 | 7.4 | 38.4 | Tenda | CX12L | CWE-119 | Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi … |
| CVE-2026-11522 | 7.4 | 38.4 | Tenda | W20E | CWE-119 | Tenda W20E setPortMirror formSetPortMirror stack-based overflow |
| CVE-2026-11523 | 7.4 | 38.4 | Tenda | W20E | CWE-119 | Tenda W20E Web Management PortalAuth formPortalAuth stack-based overflow |
| CVE-2026-11524 | 7.4 | 38.4 | Tenda | W20E | CWE-119 | Tenda W20E Web Management modifyWifiFilterRules stack-based overflow |
| CVE-2026-11528 | 7.4 | 38.4 | Tenda | AC18 | CWE-119 | Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow |
| CVE-2026-46289 | 9.8 | 37.9 | Linux | Linux | CWE-401 | lib/scatterlist: fix length calculations in extract_kvec_to_sg |
| CVE-2026-49233 | 8.3 | 37.0 | NLnet Labs | Routinator | CWE-22 | Routinator cache path traversal using rogue rsync URIs |
| CVE-2026-49755 | 8.2 | 36.5 | wojtekmach | req | CWE-409 | Decompression bomb DoS in Req via auto-decoded archive and compressed respons… |
| CVE-2026-11497 | 5.5 | 36.0 | D-Link | DCS-5615 | CWE-266 | D-Link DCS-5615 Boa Webserver boa.conf least privilege violation |
| CVE-2026-9669 | 8.2 | 35.7 | Python Software Foundation | CPython | CWE-121 | bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow |
| CVE-2026-36786 | 7.5 | 34.6 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to con… |
| CVE-2026-11555 | 2.9 | 33.7 | D-Link | DGS-1100-08PD | CWE-266 | D-Link DGS-1100-08PD Web boa.conf least privilege violation |
| CVE-2026-41723 | 8.0 | 33.1 | VMware | VCF operations | CWE-79 | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple v… |
| CVE-2026-35058 | 6.9 | 32.4 | OpenVPN | OpenVPN | CWE-617 | Improper validation of packet length during tls-crypt-v2 key extraction in Op… |
| CVE-2026-46304 | 7.5 | 32.0 | Linux | Linux | — | nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free |
| CVE-2026-46306 | 7.5 | 32.0 | Linux | Linux | — | flow_dissector: do not dissect PPPoE PFC frames |
| CVE-2026-11518 | 2.1 | 32.0 | SourceCodester | Inventory System | CWE-79 | SourceCodester Inventory System User Management users.php cross site scripting |
| CVE-2026-40215 | 6.1 | 31.8 | OpenVPN | OpenVPN | CWE-125 | A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1… |
| CVE-2026-43973 | 8.7 | 31.2 | ninenines | gun | CWE-770 | gun HTTP/1.1 response buffer has no size limit allowing server-controlled mem… |
| CVE-2026-43974 | 8.7 | 31.2 | ninenines | gun | CWE-841 | gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allo… |
| CVE-2026-46486 | 5.3 | 30.8 | mvt-project | mvt | CWE-22 | Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identi… |
| CVE-2026-46484 | 8.1 | 30.5 | tale | headplane | CWE-22 | Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OI… |
| CVE-2026-11516 | 2.0 | 30.1 | UTT | HiPER 2610G | CWE-119 | UTT HiPER 2610G formNatStaticMap strcpy buffer overflow |
| CVE-2026-49235 | 8.7 | 29.8 | NLnet Labs | Routinator | CWE-755 | Routinator crashes on specifically crafted RRDP XML files |
| CVE-2026-47345 | 5.1 | 29.7 | TYPO3 | HTML Sanitizer | CWE-79 | TYPO3 HTML Sanitizer allows Cross-Site Scripting |
| CVE-2026-11662 | 8.8 | 29.0 | Chrome | CWE-843 | Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a… | |
| CVE-2026-49232 | 8.7 | 27.2 | NLnet Labs | Routinator | CWE-755 | Routinator exits when accepting an incoming HTTP or RTR connection fails |
| CVE-2026-46478 | 7.7 | 27.2 | FlowiseAI | Flowise | CWE-915 | Flowise: DatasetRow create+update mass-assignment allows cross-workspace row … |
| CVE-2022-50953 | 6.9 | 27.2 | brooks24 | admin-word-count-column | CWE-22 | WordPress Plugin admin-word-count-column 2.2 Local File Read |
| CVE-2026-22164 | 7.5 | 26.8 | Imagination Technologies | Graphics DDK | CWE-122 | GPU DDK - Kernel heap OOB write in DevmemIntComputeVirtualIndicesFromLogical |
| CVE-2026-11651 | 9.6 | 26.6 | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a … | |
| CVE-2026-46475 | 7.7 | 26.4 | FlowiseAI | Flowise | CWE-915 | Flowise: Assistant create+update mass-assignment allows cross-workspace assis… |
| CVE-2026-46476 | 7.7 | 26.4 | FlowiseAI | Flowise | CWE-915 | Flowise: CustomTemplate create+update mass-assignment allows cross-workspace … |
| CVE-2026-46477 | 7.7 | 26.4 | FlowiseAI | Flowise | CWE-915 | Flowise: Dataset create+update mass-assignment allows cross-workspace dataset… |
| CVE-2026-46479 | 7.7 | 26.4 | FlowiseAI | Flowise | CWE-915 | Flowise: Evaluation create+update mass-assignment allows cross-workspace eval… |
| CVE-2026-46480 | 7.7 | 26.4 | FlowiseAI | Flowise | CWE-915 | Flowise: Evaluator create+update mass-assignment allows cross-workspace evalu… |
| CVE-2026-46444 | 8.7 | 25.6 | FlowiseAI | Flowise | CWE-862 | Flowise: Vector Store No Permission Checks |
| CVE-2026-11530 | 5.5 | 25.7 | imvks786 | student_management_system | CWE-74 | imvks786 student_management_system Login index.ph sql injection |
| CVE-2026-11531 | 5.5 | 25.7 | imvks786 | student_management_system | CWE-74 | imvks786 student_management_system Administrator Login Endpoint admin_login.p… |
| CVE-2026-11393 | 8.8 | 24.9 | AWS | AgentCore CLI | CWE-94 | Code injection via improper triple-quote escaping in AgentCore CLI Bedrock Ag… |
| CVE-2026-11649 | 8.8 | 24.2 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remot… | |
| CVE-2026-11650 | 8.8 | 24.2 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remot… | |
| CVE-2026-39908 | 7.1 | 24.1 | openbullet | openbullet2 | CWE-522 | OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source |
| CVE-2026-41724 | 5.4 | 24.0 | VMware | VCF operations | CWE-79 | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple v… |
| CVE-2026-11683 | 8.8 | 23.3 | Chrome | CWE-416 | Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed … | |
| CVE-2026-11477 | 2.1 | 22.9 | hs-web | hsweb-framework | CWE-601 | hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect |
| CVE-2026-39910 | 9.3 | 22.8 | STACKIT | IaaS API | CWE-862 | STACKIT IaaS API Privilege Escalation via Service Account Attachment |
| CVE-2026-41722 | 5.4 | 22.8 | VMware | VCF operations | CWE-79 | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple v… |
| CVE-2026-11470 | 2.1 | 22.7 | hs-web | hsweb-framework | CWE-22 | hs-web hsweb-framework File Upload FileUploadProperties.java denied path trav… |
| CVE-2026-44541 | 7.0 | 22.3 | ethyca | fides | CWE-79 | Fides: DOM-based XSS vulnerability in fides.js via fides_description override |
| CVE-2026-46656 | 8.8 | 21.9 | bludit | bludit | CWE-285 | Bludit CMS has improper authorization and mediation failure leading to persis… |
| CVE-2026-11482 | 5.5 | 21.5 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive5.php sql injection |
| CVE-2026-11490 | 5.5 | 21.5 | code-projects | Online Music Site | CWE-74 | code-projects Online Music Site Search.php sql injection |
| CVE-2026-11474 | 5.5 | 21.3 | Kushan2k | student-management-system | CWE-284 | Kushan2k student-management-system Registration Endpoint RegisterService.php … |
| CVE-2026-11552 | 5.5 | 21.1 | SourceCodester | Onlne Examination & Learning Management System | CWE-255 | SourceCodester Onlne Examination & Learning Management System import_users.ph… |
| CVE-2026-47344 | 2.1 | 20.7 | TYPO3 | HTML Sanitizer | CWE-79 | TYPO3 HTML Sanitizer allows Cross-Site Scripting |
| CVE-2026-11500 | 1.3 | 20.6 | n/a | Weaviate | CWE-285 | Weaviate Static API Key client.go validateConfig authorization |
| CVE-2026-46303 | 8.2 | 20.3 | Linux | Linux | CWE-401 | isofs: validate Rock Ridge CE continuation extent against volume size |
| CVE-2026-11515 | 5.5 | 20.0 | SourceCodester | Barangay Resident Profiling and Information Management System | CWE-255 | SourceCodester Barangay Resident Profiling and Information Management System … |
| CVE-2026-11639 | 7.5 | 19.9 | Chrome | CWE-416 | Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103… | |
| CVE-2026-11641 | 7.5 | 19.9 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.1… | |
| CVE-2026-11483 | 5.5 | 19.9 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive4.php sql injection |
| CVE-2026-11484 | 5.5 | 19.9 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive3.php sql injection |
| CVE-2026-11485 | 5.5 | 19.9 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive2.php sql injection |
| CVE-2026-11486 | 5.5 | 19.9 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System archive1.php sql injection |
| CVE-2026-11488 | 5.5 | 19.9 | code-projects | Simple Flight Ticket Booking System | CWE-74 | code-projects Simple Flight Ticket Booking System POST Parameter checkUser.ph… |
| CVE-2026-11489 | 5.5 | 19.9 | code-projects | Online Music Site | CWE-74 | code-projects Online Music Site AdminDeleteAlbum.php sql injection |
| CVE-2026-46441 | 7.6 | 19.8 | FlowiseAI | Flowise | CWE-284 | Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace … |
| CVE-2026-11512 | 2.1 | 19.7 | itsourcecode | Hospital Management System | CWE-79 | itsourcecode Hospital Management System billing.php cross site scripting |
| CVE-2026-11521 | 2.1 | 19.5 | Mohammed-eid35 | bank-management-system-springboot | CWE-266 | Mohammed-eid35 bank-management-system-springboot Transaction Endpoint Transac… |
| CVE-2026-11643 | 8.1 | 19.5 | Chrome | CWE-416 | Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-46657 | 7.1 | 19.3 | bludit | bludit | CWE-212 | Bludit's persistent authentication tokens not revoked upon account disablement |
| CVE-2026-46443 | 7.0 | 19.4 | FlowiseAI | Flowise | CWE-200 | Flowise: Credential Data Leak |
| CVE-2026-11629 | 8.8 | 19.3 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-11532 | 2.1 | 19.2 | imvks786 | student_management_system | CWE-266 | imvks786 student_management_system Student Record add.php access control |
| CVE-2026-11582 | 5.5 | 19.1 | CodeAstro | Student Attendance Management System | CWE-74 | CodeAstro Student Attendance Management System index.php sql injection |
| CVE-2026-42863 | 7.6 | 19.0 | FlowiseAI | Flowise | CWE-284 | Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace A… |
| CVE-2026-49234 | 8.2 | 18.6 | NLnet Labs | Routinator | CWE-20 | Routinator crashes on specifically crafted ASN strings in the API |
| CVE-2026-11632 | 7.5 | 18.4 | Chrome | CWE-416 | Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a… | |
| CVE-2026-11648 | 8.8 | 18.2 | Chrome | CWE-416 | Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.… | |
| CVE-2026-11471 | 5.5 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System index2.php sql injection |
| CVE-2026-11472 | 5.5 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System index1.php sql injection |
| CVE-2026-11501 | 5.5 | 18.2 | SourceCodester | Hospitals Patient Records Management System | CWE-74 | SourceCodester Hospitals Patient Records Management System Master.php save_pa… |
| CVE-2026-11637 | 8.8 | 18.1 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allow… | |
| CVE-2026-11646 | 8.8 | 18.1 | Chrome | CWE-416 | Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 al… | |
| CVE-2026-11519 | 2.1 | 18.0 | SourceCodester | Inventory System | CWE-266 | SourceCodester Inventory System Account Creation users_handler.php improper a… |
| CVE-2026-11660 | 8.3 | 17.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in New Tab Page in Google Chrome p… | |
| CVE-2026-11688 | 8.8 | 17.3 | Chrome | CWE-94 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 … | |
| CVE-2026-42861 | 7.6 | 17.1 | FlowiseAI | Flowise | CWE-284 | Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace R… |
| CVE-2026-11634 | 9.6 | 16.9 | Chrome | CWE-416 | Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103… | |
| CVE-2026-11638 | 9.6 | 16.9 | Chrome | CWE-416 | Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a… | |
| CVE-2026-11654 | 9.6 | 16.9 | Chrome | CWE-416 | Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.1… | |
| CVE-2026-11659 | 9.6 | 16.9 | Chrome | CWE-20 | Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allo… | |
| CVE-2026-11630 | 8.8 | 16.9 | Chrome | CWE-416 | Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed… | |
| CVE-2026-11657 | 8.8 | 16.8 | Chrome | CWE-416 | Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 al… | |
| CVE-2026-11664 | 8.8 | 16.9 | Chrome | CWE-416 | Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a… | |
| CVE-2026-46440 | 9.1 | 16.8 | FlowiseAI | Flowise | CWE-522 | Flowise: Basic Auth Credentials Exposed via API |
| CVE-2026-43966 | 6.3 | 16.6 | ninenines | cowlib | CWE-113 | HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_stri… |
| CVE-2026-11502 | 1.3 | 16.7 | n/a | JeecgBoot | CWE-601 | JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sen… |
| CVE-2026-11520 | 2.0 | 16.3 | SourceCodester | Inventory System | CWE-79 | SourceCodester Inventory System header.php cross site scripting |
| CVE-2026-11611 | 6.5 | 15.8 | Red Hat | Red Hat Directory Server 11 | CWE-400 | 389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race… |
| CVE-2026-11671 | 9.6 | 15.7 | Chrome | CWE-416 | Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed… | |
| CVE-2026-11673 | 8.8 | 15.7 | Chrome | CWE-416 | Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 all… | |
| CVE-2026-11674 | 8.8 | 15.7 | Chrome | CWE-416 | Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed… | |
| CVE-2026-11680 | 8.8 | 15.7 | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 a… | |
| CVE-2026-11652 | 8.3 | 15.6 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed… | |
| CVE-2026-11655 | 8.3 | 15.6 | Chrome | CWE-472 | Integer overflow in Media in Google Chrome on Mac prior to 149.0.7827.103 all… | |
| CVE-2026-11661 | 8.3 | 15.6 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.103 a… | |
| CVE-2026-46481 | 8.3 | 15.4 | open-metadata | OpenMetadata | CWE-201 | OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database p… |
| CVE-2026-11672 | 8.3 | 15.0 | Chrome | CWE-787 | Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.1… | |
| CVE-2026-11633 | 8.8 | 14.3 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 a… | |
| CVE-2026-11640 | 8.3 | 14.1 | Chrome | CWE-472 | Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a… | |
| CVE-2026-11642 | 8.3 | 14.1 | Chrome | CWE-416 | Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a… | |
| CVE-2026-11676 | 8.3 | 14.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on Linux … | |
| CVE-2026-25558 | 4.8 | 14.0 | QloApps | QloApps | CWE-79 | QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager |
| CVE-2026-11533 | 2.1 | 14.0 | imvks786 | student_management_system | CWE-266 | imvks786 student_management_system Student Deletion Endpoint see.php improper… |
| CVE-2026-11653 | 6.5 | 13.3 | Chrome | CWE-20 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-11658 | 6.5 | 13.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-11670 | 8.8 | 13.3 | Chrome | CWE-416 | Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remo… | |
| CVE-2026-11493 | 1.3 | 13.3 | Tenda | AC15 | CWE-521 | Tenda AC15 Samba smb.conf weak password |
| CVE-2026-11491 | 1.9 | 13.2 | CodeAstro | Human Resource Management System | CWE-79 | CodeAstro Human Resource Management System Notice Board Management All_notice… |
| CVE-2026-11631 | 8.3 | 13.0 | Chrome | CWE-416 | Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 al… | |
| CVE-2026-11635 | 8.3 | 13.0 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 a… | |
| CVE-2026-11647 | 8.3 | 13.0 | Chrome | CWE-416 | Use after free in Printing in Google Chrome on Android prior to 149.0.7827.10… | |
| CVE-2026-11663 | 8.3 | 13.0 | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a rem… | |
| CVE-2026-11636 | 7.5 | 13.0 | Chrome | CWE-416 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.10… | |
| CVE-2026-46307 | 8.3 | 12.8 | Linux | Linux | CWE-125 | wifi: ath5k: do not access array OOB |
| CVE-2026-11689 | 8.1 | 12.5 | Chrome | CWE-20 | Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.… | |
| CVE-2026-11665 | 4.3 | 12.4 | Chrome | CWE-125 | Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.10… | |
| CVE-2026-49141 | 5.1 | 12.2 | ArnasDon | wacrm | CWE-639 | WACRM Authorization Bypass via Automation Engine Endpoint |
| CVE-2026-11667 | 7.5 | 12.2 | Chrome | CWE-125 | Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed… | |
| CVE-2026-43972 | 6.3 | 12.1 | ninenines | gun | CWE-346 | gun HTTP/2 PUSH_PROMISE authority not validated against connection origin all… |
| CVE-2026-11494 | 2.1 | 12.2 | TOTOLINK | AC1200 T8 | CWE-266 | TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation |
| CVE-2026-11690 | 7.5 | 12.0 | Chrome | CWE-125 | Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.… | |
| CVE-2026-11694 | 7.5 | 12.0 | Chrome | CWE-416 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allo… | |
| CVE-2026-11666 | 5.4 | 12.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Input in Google Chrome prior to… | |
| CVE-2026-11669 | 5.3 | 11.9 | Chrome | CWE-472 | Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.… | |
| CVE-2026-11476 | 2.1 | 11.4 | Kushan2k | student-management-system | CWE-266 | Kushan2k student-management-system Profile Update Endpoint AdminController.ph… |
| CVE-2026-11558 | 2.1 | 11.4 | CodeAstro | Payroll System | CWE-74 | CodeAstro Payroll System home_salary.php sql injection |
| CVE-2026-3011 | 6.4 | 11.0 | wpzoom | Recipe Card Blocks Lite | CWE-79 | Recipe Card Blocks Lite <= 3.4.13 - Authenticated (Author+) Stored Cross-Site… |
| CVE-2026-11554 | 2.1 | 10.9 | TOTOLINK | CP450 | CWE-266 | TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation |
| CVE-2026-11529 | 2.1 | 10.8 | designcomputer | mysql-mcp-server | CWE-74 | designcomputer mysql-mcp-server mysql URI server.py read_resource sql injection |
| CVE-2026-11473 | 5.3 | 10.7 | jflyfox | jfinal_cms | CWE-74 | jflyfox jfinal_cms AdvicefeedbackController.java list sql injection |
| CVE-2026-11559 | 2.1 | 10.7 | CodeAstro | Payroll System | CWE-74 | CodeAstro Payroll System view_account.php sql injection |
| CVE-2026-11583 | 2.1 | 10.7 | CodeAstro | Student Attendance Management System | CWE-74 | CodeAstro Student Attendance Management System createClass.php sql injection |
| CVE-2026-11584 | 2.1 | 10.7 | CodeAstro | Student Attendance Management System | CWE-74 | CodeAstro Student Attendance Management System createClass.php edit sql injec… |
| CVE-2026-11697 | 9.6 | 10.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in UI in Google Chrome prior to 14… | |
| CVE-2026-11681 | 8.8 | 10.5 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 all… | |
| CVE-2026-11687 | 8.8 | 10.5 | Chrome | CWE-416 | Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowe… | |
| CVE-2026-11698 | 8.8 | 10.5 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 a… | |
| CVE-2026-11699 | 8.8 | 10.5 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 a… | |
| CVE-2026-11644 | 7.5 | 10.5 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 all… | |
| CVE-2026-11675 | 3.1 | 10.2 | Chrome | CWE-20 | Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a… | |
| CVE-2026-11480 | 2.1 | 10.2 | Chengdu Everbrite Network Technology | BeikeShop | CWE-74 | Chengdu Everbrite Network Technology BeikeShop Admin Design Builder Endpoint … |
| CVE-2026-11495 | 2.1 | 10.2 | CodeAstro | Ingredients Stock Management System | CWE-74 | CodeAstro Ingredients Stock Management System add_stock.php sql injection |
| CVE-2026-11506 | 2.1 | 10.2 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System search_staff_for_deletion.php sql injection |
| CVE-2026-11507 | 2.1 | 10.2 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System delete_leave_type.php sql injection |
| CVE-2026-11508 | 2.1 | 10.2 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection |
| CVE-2026-11510 | 2.1 | 10.2 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System add_leave.php sql injection |
| CVE-2026-11513 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System adminaccount.php sql injection |
| CVE-2026-11514 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System addpatient.php sql injection |
| CVE-2026-11585 | 2.1 | 10.2 | CodeAstro | Student Attendance Management System | CWE-74 | CodeAstro Student Attendance Management System createClassArms.php sql injection |
| CVE-2026-11534 | 2.0 | 10.0 | imvks786 | student_management_system | CWE-79 | imvks786 student_management_system add.php cross site scripting |
| CVE-2026-11505 | 2.3 | 9.8 | GL.iNet | A1300 | CWE-320 | GL.iNet XE3000 glnassys hard-coded key |
| CVE-2026-10544 | 6.5 | 9.7 | Devolutions | Server | CWE-78 | Improper neutralization of special elements in the built-in PAM provider pass… |
| CVE-2026-42862 | 7.6 | 9.5 | FlowiseAI | Flowise | CWE-284 | Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resou… |
| CVE-2026-48507 | 7.1 | 9.5 | grokability | snipe-it | CWE-863 | Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk ed… |
| CVE-2026-11696 | 5.3 | 9.3 | Chrome | CWE-457 | Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.10… | |
| CVE-2026-11668 | 4.3 | 9.4 | Chrome | CWE-457 | Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.… | |
| CVE-2026-11682 | 8.3 | 9.2 | Chrome | CWE-20 | Inappropriate implementation in Views in Google Chrome on Linux prior to 149.… | |
| CVE-2026-11509 | 5.3 | 9.2 | CodeAstro | Leave Management System | CWE-74 | CodeAstro Leave Management System search_staff_for_updation.php sql injection |
| CVE-2026-11511 | 2.0 | 9.1 | Bolt | CMS | CWE-74 | Bolt CMS HTML Attribute TextType.php HTML injection |
| CVE-2026-7765 | 6.3 | 8.6 | Checkmk GmbH | Checkmk | CWE-863 | User Messages widget leaked issuer messages on shared dashboards |
| CVE-2021-47982 | 5.1 | 8.6 | maxfoundry | WP-Paginate | CWE-79 | WordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset |
| CVE-2021-47983 | 5.1 | 8.6 | mra13 | Accept Stripe Payments | CWE-79 | WordPress Plugin Stripe Payments 2.0.39 Stored XSS via currency_code |
| CVE-2021-47984 | 5.1 | 8.6 | WP24 | WP24 Domain Check | CWE-79 | WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS |
| CVE-2020-37248 | 6.5 | 8.5 | OfflineIMAP | OfflineIMAP | CWE-348 | OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability pri… |
| CVE-2026-46275 | 7.8 | 8.4 | Linux | Linux | CWE-362 | Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths |
| CVE-2026-11693 | 8.1 | 8.3 | Chrome | CWE-346 | Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.… | |
| CVE-2023-54351 | 5.1 | 8.3 | Sonaar | Sonaar Music Plugin | CWE-79 | WordPress Sonaar Music Plugin 4.7 Stored XSS via Comments |
| CVE-2026-48488 | 2.7 | 8.1 | thorsten | phpMyFAQ | CWE-328 | phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing |
| CVE-2026-11628 | 6.8 | 7.9 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a lo… | |
| CVE-2026-11679 | 8.3 | 7.8 | Chrome | CWE-416 | Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 … | |
| CVE-2026-11692 | 8.3 | 7.8 | Chrome | CWE-416 | Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allo… | |
| CVE-2026-11700 | 8.3 | 7.8 | Chrome | CWE-416 | Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a … | |
| CVE-2026-11701 | 5.4 | 7.6 | Chrome | CWE-20 | Inappropriate implementation in Guest View in Google Chrome prior to 149.0.78… | |
| CVE-2026-49756 | 2.1 | 7.7 | wojtekmach | req | CWE-93 | Multipart form-data header injection in Req via unescaped name/filename/conte… |
| CVE-2026-44119 | 5.5 | 7.6 | Apache Software Foundation | Apache HTTP Server | CWE-269 | Apache HTTP Server: escalation of privilege through expressions in .htaccess … |
| CVE-2026-11678 | 5.3 | 7.5 | Chrome | CWE-472 | Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a… | |
| CVE-2026-11685 | 4.3 | 7.5 | Chrome | CWE-20 | Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to… | |
| CVE-2026-11695 | 4.3 | 7.5 | Chrome | CWE-693 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-11684 | 3.1 | 6.9 | Chrome | CWE-693 | Insufficient policy enforcement in Network in Google Chrome prior to 149.0.78… | |
| CVE-2026-11686 | 3.1 | 6.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on macOS … | |
| CVE-2026-11656 | 8.3 | 6.7 | Chrome | CWE-416 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allo… | |
| CVE-2026-11691 | 3.1 | 6.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in New Tab Page in Google Chrome p… | |
| CVE-2026-11479 | 1.3 | 5.7 | yoanbernabeu | grepai | CWE-327 | yoanbernabeu grepai Qdrant Backend chunker.go weak hash |
| CVE-2026-10787 | 4.3 | 5.2 | Devolutions | Server | CWE-862 | Missing authorization in the deleted user groups API in Devolutions Server al… |
| CVE-2026-11677 | 8.3 | 4.5 | Chrome | CWE-362 | Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a rem… | |
| CVE-2026-10786 | 6.5 | 4.6 | Devolutions | Server | CWE-312 | Improper access control in the ticketing integration settings in Devolutions … |
| CVE-2026-46294 | 7.8 | 4.1 | Linux | Linux | CWE-787 | dm: fix a buffer overflow in ioctl processing |
| CVE-2026-8078 | 4.8 | 4.1 | Checkmk GmbH | Checkmk | CWE-79 | Fix stored XSS in global settings change log |
| CVE-2026-9549 | 4.8 | 4.1 | Checkmk GmbH | Checkmk | CWE-79 | Fix XSS in service discovery active check output |
| CVE-2026-8833 | 8.5 | 3.9 | Checkmk GmbH | Checkmk | CWE-79 | XSS in urls |
| CVE-2026-46288 | 8.4 | 3.8 | Linux | Linux | CWE-416 | of: unittest: fix use-after-free in of_unittest_changeset() |
| CVE-2026-46281 | 7.8 | 3.9 | Linux | Linux | CWE-787 | vmalloc: fix buffer overflow in vrealloc_node_align() |
| CVE-2026-46274 | 7.8 | 3.7 | Linux | Linux | CWE-416 | io-wq: check that the predecessor is hashed in io_wq_remove_pending() |
| CVE-2026-11569 | 5.4 | 3.7 | Red Hat | Red Hat Quay 3 | CWE-79 | Quay: quay: stored xss via filedrop svg upload |
| CVE-2026-7186 | 8.5 | 3.5 | Checkmk GmbH | Checkmk | CWE-79 | Fix stored XSS in URL dashboard widget via dangerous URI schemes |
| CVE-2026-11475 | 2.1 | 3.3 | Kushan2k | student-management-system | CWE-74 | Kushan2k student-management-system Certificate Verification Endpoint GradeCon… |
| CVE-2026-46279 | 7.8 | 2.8 | Linux | Linux | CWE-415 | mm/alloc_tag: clear codetag for pages allocated before page_ext initialization |
| CVE-2026-46280 | 7.8 | 2.7 | Linux | Linux | CWE-416 | lib: test_hmm: evict device pages on file close to avoid use-after-free |
| CVE-2026-46285 | 7.8 | 2.7 | Linux | Linux | CWE-416 | mtd: docg3: fix use-after-free in docg3_release() |
| CVE-2026-46293 | 7.1 | 2.7 | Linux | Linux | CWE-125 | clk: microchip: mpfs-ccc: fix out of bounds access during output registration |
| CVE-2026-46309 | 7.0 | 2.6 | Linux | Linux | CWE-401 | drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise |
| CVE-2026-46276 | 5.5 | 2.4 | Linux | Linux | — | drm/amdgpu: fix zero-size GDS range init on RDNA4 |
| CVE-2026-46291 | 5.5 | 2.4 | Linux | Linux | — | crypto: caam - guard HMAC key hex dumps in hash_digest_key |
| CVE-2026-46292 | 5.5 | 2.5 | Linux | Linux | CWE-772 | pmdomain: core: Fix detach procedure for virtual devices in genpd |
| CVE-2026-46282 | 5.5 | 2.4 | Linux | Linux | CWE-476 | iio: frequency: admv1013: fix NULL pointer dereference on str |
| CVE-2026-46283 | 5.5 | 2.4 | Linux | Linux | — | tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() |
| CVE-2026-46286 | 5.5 | 2.4 | Linux | Linux | — | leds: qcom-lpg: Check for array overflow when selecting the high resolution |
| CVE-2026-46287 | 5.5 | 2.4 | Linux | Linux | CWE-617 | net: txgbe: fix RTNL assertion warning when remove module |
| CVE-2026-46284 | 5.5 | 2.2 | Linux | Linux | CWE-476 | mm/hugetlb: fix early boot crash on parameters without '=' separator |
| CVE-2026-46290 | 5.5 | 2.2 | Linux | Linux | — | x86/efi: Fix graceful fault handling after FPU softirq changes |
| CVE-2026-46277 | 7.8 | 2.2 | Linux | Linux | — | mm/zone_device: do not touch device folio after calling ->folio_free() |
| CVE-2026-46301 | 7.8 | 1.9 | Linux | Linux | CWE-416 | spi: topcliff-pch: fix use-after-free on unbind |
| CVE-2026-34194 | 7.1 | 1.9 | Imagination Technologies | Graphics DDK | CWE-468 | GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChang… |
| CVE-2026-46308 | 7.8 | 1.8 | Linux | Linux | CWE-416 | pmdomain: mediatek: fix use-after-free in scpsys_get_bus_protection_legacy() |
| CVE-2026-46314 | 5.5 | 1.8 | Linux | Linux | CWE-835 | drm/v3d: Reject empty multisync extension to prevent infinite loop |
| CVE-2026-46296 | 5.5 | 1.7 | Linux | Linux | CWE-476 | spi: s3c64xx: fix NULL-deref on driver unbind |
| CVE-2026-46312 | 5.5 | 1.7 | Linux | Linux | — | media: videobuf2: Set vma_flags in vb2_dma_sg_mmap |
| CVE-2026-46313 | 5.5 | 1.7 | Linux | Linux | CWE-476 | media: intel/ipu6: fix error pointer dereference |
| CVE-2026-11478 | 1.9 | 1.7 | kokke | tiny-regex-c | CWE-400 | kokke tiny-regex-c Pattern re.c matchstar redos |
| CVE-2026-46311 | 7.8 | 1.6 | Linux | Linux | — | drm/amdgpu/userq: fix access to stale wptr mapping |
| CVE-2025-71315 | 5.5 | 1.6 | Linux | Linux | — | drm/vkms: Convert to DRM's vblank timer |
| CVE-2026-46295 | 5.5 | 1.6 | Linux | Linux | — | KVM: x86: Do IRR scan in __kvm_apic_update_irr even if PIR is empty |
| CVE-2026-46297 | 5.5 | 1.6 | Linux | Linux | — | net: libwx: use request_irq for VF misc interrupt |
| CVE-2026-46310 | 5.5 | 1.6 | Linux | Linux | CWE-476 | media: renesas: vsp1: Fix NULL pointer deref on module unload |
| CVE-2026-46278 | 5.5 | 1.3 | Linux | Linux | CWE-476 | drm/imagination: Fix segfault when updating ftrace mask |
| CVE-2026-45581 | 5.5 | 1.3 | hyperledger | fabric-chaincode-java | CWE-532 | fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Log… |
| CVE-2026-46302 | 5.5 | 1.0 | Linux | Linux | — | selinux: allow multiple opens of /sys/fs/selinux/policy |
| CVE-2026-46305 | 5.5 | 1.0 | Linux | Linux | CWE-476 | staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc |
| CVE-2026-46299 | 7.0 | 0.6 | Linux | Linux | CWE-667 | hfsplus: fix held lock freed on hfsplus_fill_super() |
| CVE-2026-11481 | 1.1 | 0.3 | yoanbernabeu | grepai | CWE-327 | yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupB… |
| CVE-2026-46298 | 4.7 | 0.1 | Linux | Linux | CWE-362 | pseries/papr-hvpipe: Fix race with interrupt handler |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-08 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.