boxscore/security
Tuesday, June 9, 2026 · all times UTC← 2026-06-08 · archive · 2026-06-10 →

719 CVEs published June 9, 2026: 37 critical, 348 high, 314 medium, 20 low; 3 in KEV; 12 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 694 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published2612698410522563
KEV catalog size1670

329 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9610628466331212730.37.8.0013-114
google56273665382267197460.88.1.0023+562
microsoft207697524661584378273.97.8.0043+195
red hat3195842396400.07.1.0031+27
apple04701227193714.96.2.00340
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161800.04.3.0024+17
cisco316324096956.37.2.0971+3
ivanti38130033450.08.8.4316+2
checkpoint2814303112.57.5.0423+2
fortinet28132028337.57.3.0066+2
vmware3301202100.05.4.0031+3
zyxel2300301100.06.5.0017+2
f50320007133.39.2.09960
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache538512333724011.27.2.0053+49
mozilla51134401300.07.5.0032+1
gitlab0901604222.24.3.00320
docker250500100.08.8.0021+2
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
adobe1231274467227532.45.5.0021+123
ibm5541326150700.07.5.0031+5
oracle229816404013.48.0.0027+2
progress591710900.07.5.0036+5
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link81103252619.14.2.0059+8
siemens780440100.07.5.0020+7
abb440400000.07.3.0024+4
hitachi energy020020000.05.7.00140
schneider electric110100100.07.1.0023+1
hikvision01000021100.01.00000
dahua000000200
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester3557002433000.02.1.0026+35
spring5354121320000.06.5.0025+53
edimax051032019100.07.4.00590
concrete cms1451101321000.06.0.0015+1
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
totolink338026111000.08.9.0191+3

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4399710.0.0098
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
Most disclosures (vendor)
VendorCVEs
google730
linux526
microsoft365
adobe124
apache70
red hat68
sourcecodester57
ibm54
spring54
edimax51
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco9
apple7
google6
ivanti4
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven24
Packagist22
PyPI11
npm3
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171665
CVE-2021-27102Accellion2021-11-171665
CVE-2021-27101Accellion2021-11-171665
CVE-2021-27103Accellion2021-11-171665
CVE-2021-21017Adobe2021-11-171665
CVE-2021-28550Adobe2021-11-171665
CVE-2021-42013Apache2021-11-171665
CVE-2021-41773Apache2021-11-171665
CVE-2021-30858Apple2021-11-171665
CVE-2021-30860Apple2021-11-171665

Transactions

EXPLOIT PUBLISHEDCVE-2025-52292. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-52293. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55657. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55658. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55659. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10520 (ivanti Sentry). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44716 (pipecat-ai pipecat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46492 (commenthol md-fileserver). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46518 (openemr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5067 (zephyrproject-rtos Zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5068 (zephyrproject-rtos Zephyr). Public exploit reference added.

PATCH SHIPPEDCVE-2026-10520 (ivanti Sentry). Fixed in Sentry R10.5.2.

Yesterday's Results

719 CVEs published. 25 box scores and 375 table rows below; the remaining 319 continue on page 2 — every CVE is listed, nothing truncated.

Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .2532   97.8   YES
AFFECTED
  Product                           Versions   Fixed
  Cisco Catalyst SD-WAN Controller  20.6.4 –   —
  Cisco Catalyst SD-WAN Manager     20.1.12 –  —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 9   Added to CISA KEV, due Jun 23
  Jun 9   Published (CNA: cisco)
CWE-116 · CNA: cisco · 3 references · NVD status: Analyzed · KEV due June 23, 2026
Google Chromium V8
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0219   80.9   YES
AFFECTED
  Product  Versions          Fixed
  Chrome   149.0.7827.103 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 9   Added to CISA KEV, due Jun 23
  Jun 9   Published (CNA: Chrome)
CWE-125, CWE-787 · CNA: Chrome · 3 references · NVD status: Analyzed · KEV due June 23, 2026
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   N    6.9   .0111   63.1   YES
AFFECTED
  Product  Versions  Fixed
  EOS      4.36.0 –  —
TIMELINE
  Apr 29  Reserved by CNA
  Jun 9   Added to CISA KEV, due Jun 23
  Jun 9   Published (CNA: Arista)
CWE-1023 · CNA: Arista · 3 references · NVD status: Analyzed · KEV due June 23, 2026
Microsoft Windows 10 Version 1607 — HTTP.sys Denial of Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .5383   98.9     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2016      10.0.14393.0 –  —
  + 6 more
TIMELINE
  May 27  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-400 · CNA: microsoft · 1 reference · NVD status: Analyzed
ivanti Sentry — An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 v…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .5187   98.9     —
AFFECTED
  Product  Versions     Fixed
  Sentry   unspecified  R10.5.2
TIMELINE
  Jun 1   Reserved by CNA
  Jun 9   Published (CNA: ivanti)
CWE-288 · CNA: ivanti · 1 reference · NVD status: Analyzed
Microsoft SharePoint Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .3522   98.3     —
AFFECTED
  Product                                           Versions  Fixed
  Microsoft SharePoint Enterprise Server 2016       16.0.0 –  —
  Microsoft SharePoint Server 2019                  16.0.0 –  —
  Microsoft SharePoint Server Subscription Edition  16.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-502 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Windows 10 Version 1607 — HTTP.sys Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .2275   97.5     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  May 18  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-122, CWE-190 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Exchange Server Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  N  N    5.0   .2026   97.3     —
AFFECTED
  Product                                              Versions     Fixed
  Microsoft Exchange Server 2016 Cumulative Update 23  15.01.0.0 –  —
  Microsoft Exchange Server 2019 Cumulative Update 14  15.02.0.0 –  —
  Microsoft Exchange Server 2019 Cumulative Update 15  15.02.0.0 –  —
  Microsoft Exchange Server Subscription Edition RTM   15.02.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Windows 11 version 23H2 — Windows Kernel Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1548   96.5     —
AFFECTED
  Product                                         Versions        Fixed
  Windows 11 version 23H2                         10.0.22631.0 –  —
  Windows 11 Version 23H2                         10.0.22631.0 –  —
  Windows 11 Version 24H2                         10.0.26100.0 –  —
  Windows 11 Version 25H2                         10.0.26200.0 –  —
  Windows 11 version 26H1                         10.0.28000.0 –  —
  Windows Server 2022                             10.0.20348.0 –  —
  Windows Server 2025                             10.0.26100.0 –  —
  Windows Server 2025 (Server Core installation)  10.0.26100.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-122, CWE-416 · CNA: microsoft · 1 reference · NVD status: Analyzed
Ivanti Endpoint Manager Mobile — An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .1363   96.2     —
AFFECTED
  Product                  Versions     Fixed
  Endpoint Manager Mobile  unspecified  12.9.0.1
TIMELINE
  Jun 3   Reserved by CNA
  Jun 9   Published (CNA: ivanti)
CWE-78 · CNA: ivanti · 1 reference · NVD status: Awaiting Analysis
Microsoft Windows 10 Version 1607 — Windows NTLM Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0868   94.7     —
AFFECTED
  Product                                            Versions        Fixed
  Windows 10 Version 1607                            10.0.14393.0 –  —
  Windows 11 version 22H2                            10.0.22621.0 –  —
  Windows Server 2012                                6.2.9200.0 –    —
  Windows Server 2012 (Server Core installation)     6.2.9200.0 –    —
  Windows Server 2012 R2                             6.3.9600.0 –    —
  Windows Server 2012 R2 (Server Core installation)  6.3.9600.0 –    —
  Windows Server 2016                                10.0.14393.0 –  —
  Windows Server 2016 (Server Core installation)     10.0.14393.0 –  —
  Windows Server 2022                                10.0.20348.0 –  —
  Windows Server version 2004                        10.0.0 –        —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-200 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Windows 10 Version 1607 — NT OS Kernel Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0695   93.6     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  Apr 30  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-122, CWE-191 · CNA: microsoft · 1 reference · NVD status: Analyzed
OpenSSL OpenSSL — Heap Use-After-Free in the PKCS7_verify() Function
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0524   91.8     —
AFFECTED
  Product  Versions  Fixed
  OpenSSL  4.0.0 –   —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: openssl)
CWE-416, CWE-825 · CNA: openssl · 24 references · NVD status: Modified
Microsoft Windows 10 Version 1607 — Windows BitLocker Security Feature Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   P   L   N   N  U  H  H  H    6.8   .0501   91.5     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012 R2   6.3.9600.0 –    —
  + 8 more
TIMELINE
  Jun 4   Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-306 · CNA: microsoft · 1 reference · NVD status: Modified
Microsoft Windows 10 Version 1607 — Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0363   88.6     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-59 · CNA: microsoft · 1 reference · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   R  C  H  H  H    8.8   .0255   83.7     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 9   Published (CNA: adobe)
CWE-22 · CNA: adobe · 1 reference · NVD status: Analyzed
Microsoft .NET 10.0 — ASP.NET Core Denial of Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0243   82.9     —
AFFECTED
  Product                                    Versions  Fixed
  .NET 10.0                                  10.0.0 –  —
  .NET 8.0                                   8.0.0 –   —
  .NET 9.0                                   9.0.0 –   —
  ASP.NET Core 10.0                          10.0 –    —
  ASP.NET Core 8.0                           8.0 –     —
  ASP.NET Core 9.0                           9.0 –     —
  Microsoft Visual Studio 2026 version 18.6  18.6.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-400, CWE-770 · CNA: microsoft · 21 references · NVD status: Modified
Veeam Backup and Replication — A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0235   82.3     —
AFFECTED
  Product                 Versions     Fixed
  Backup and Replication  unspecified  —
TIMELINE
  May 8   Reserved by CNA
  Jun 9   Published (CNA: hackerone)
CWE-502 · CNA: hackerone · 1 reference · NVD status: Awaiting Analysis
Adobe ColdFusion — ColdFusion | Improper Input Validation (CWE-20)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   N  C  H  H  H    9.6   .0232   82.0     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 9   Published (CNA: adobe)
CWE-20 · CNA: adobe · 1 reference · NVD status: Analyzed
Microsoft Windows 10 Version 1607 — Winlogon Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0227   81.6     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  Apr 30  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-59 · CNA: microsoft · 1 reference · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Incorrect Authorization (CWE-863)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   H   N  C  H  H  H    8.4   .0209   80.1     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 9   Published (CNA: adobe)
CWE-863 · CNA: adobe · 1 reference · NVD status: Analyzed
Microsoft Windows 10 Version 1607 — Windows DWM Core Library Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0200   79.1     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  Apr 30  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-416 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Graphics Component Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0200   79.1     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  Apr 30  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-416 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Nuance PowerScribe 360 4.0 — Nuance PowerScribe Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0191   78.1     —
AFFECTED
  Product                               Versions  Fixed
  Nuance PowerScribe 360 4.0            4.0 –     —
  Nuance PowerScribe 360 version 4.0.1  4.0.1 –   —
  Nuance PowerScribe 360 version 4.0.2  4.0.2 –   —
  Nuance PowerScribe 360 version 4.0.3  4.0.3 –   —
  Nuance PowerScribe 360 version 4.0.4  4.0.4 –   —
  Nuance PowerScribe 360 version 4.0.5  4.0.5 –   —
  Nuance PowerScribe 360 version 4.0.6  4.0.6 –   —
  Nuance PowerScribe 360 version 4.0.7  4.0.7 –   —
  Nuance PowerScribe 360 version 4.0.8  4.0.8 –   —
  Nuance PowerScribe 360 version 4.0.9  4.0.9 –   —
  + 12 more
TIMELINE
  Feb 11  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-502 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft SharePoint Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0163   74.2     —
AFFECTED
  Product                                           Versions  Fixed
  Microsoft SharePoint Enterprise Server 2016       16.0.0 –  —
  Microsoft SharePoint Server 2019                  16.0.0 –  —
  Microsoft SharePoint Server Subscription Edition  16.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-22 · CNA: microsoft · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-429858.867.1MicrosoftRemote Desktop client for Windows DesktopCWE-787Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-428358.167.1MicrosoftMicrosoft Teams for AndroidCWE-74Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2026-83658.865.0creativethemeshqBlocksyCWE-502Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Des…
CVE-2026-427647.564.7OpenSSLOpenSSLCWE-476NULL Pointer Dereference in QUIC Server Initial Packet Handling
CVE-2026-456488.863.5MicrosoftWindows Server 2022CWE-121Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-448159.862.9MicrosoftWindows 10 Version 1607CWE-121DHCP Client Service Remote Code Execution Vulnerability
CVE-2026-115727.461.7n/adegitCWE-78Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are v…
CVE-2026-341837.561.4OpenSSLOpenSSLCWE-1325Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
CVE-2026-485737.960.8MicrosoftWindows 10 Version 1607CWE-1329Secure Boot Security Feature Bypass Vulnerability
CVE-2026-485767.960.8MicrosoftWindows 10 Version 1607CWE-1329Secure Boot Security Feature Bypass Vulnerability
CVE-2026-341807.560.7OpenSSLOpenSSLCWE-125Heap Buffer Over-read in ASN.1 Content Parsing
CVE-2026-367238.859.9n/an/aCWE-22An unrestricted file rename vulnerability in the /api/create-user component o…
CVE-2026-427665.959.8OpenSSLOpenSSLCWE-476Possible NULL Dereference in Password-Based CMS Decryption
CVE-2026-472898.858.4MicrosoftWindows 10 Version 1607CWE-122Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-499598.758.2nesquenahermes-webuiCWE-78Hermes WebUI < 0.51.311 RCE via Git Configuration Injection
CVE-2026-485605.457.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-472846.557.3MicrosoftVisual Studio CodeCWE-200Visual Studio Code Information Disclosure Vulnerability
CVE-2026-429036.556.8MicrosoftWindows 10 Version 1607CWE-476Windows Kerberos Denial of Service Vulnerability
CVE-2026-429087.555.9MicrosoftWindows 10 Version 1607CWE-125Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-456397.555.9MicrosoftRemote Desktop client for Windows DesktopCWE-125Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-455048.855.0MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-918Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-410988.454.6MicrosoftAzure Stack EdgeCWE-79Azure Stack Edge Spoofing Vulnerability
CVE-2026-386159.854.1n/an/aCWE-78DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
CVE-2026-429076.554.1MicrosoftWindows 10 Version 1809CWE-200Windows Shell Information Disclosure Vulnerability
CVE-2026-429145.353.4MicrosoftWindows 10 Version 1607CWE-125Windows Kerberos Denial of Service Vulnerability
CVE-2026-472876.553.2MicrosoftVisual Studio CodeCWE-23Visual Studio Code Tampering Vulnerability
CVE-2026-409847.552.7SpringMicrometerCWE-400Micrometer HTTP server instrumentations DoS vulnerability
CVE-2026-472819.652.3MicrosoftVisual Studio CodeCWE-306Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-476439.852.0MicrosoftAzure Stack EdgeCWE-610Azure Stack Edge Remote Code Execution Vulnerability
CVE-2025-713198.751.2image-sizeimage-sizeCWE-835image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser
CVE-2026-498186.550.0Apache Software FoundationApache Airflow Samba providerCWE-22Apache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS o…
CVE-2026-454815.449.7MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-403768.149.0MicrosoftVisual Studio CodeCWE-20Visual Studio Code Elevation of Privilege Vulnerability
CVE-2016-200646.949.0myasuiWP VaultCWE-98WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter
CVE-2026-472988.049.0MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-285Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-50679.847.9zephyrproject-rtosZephyrCWE-787Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Se…
CVE-2017-202488.747.8AppthaApptha Slider GalleryCWE-22WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download
CVE-2017-202508.747.8AppthaMac Photo GalleryCWE-22WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download
CVE-2026-429748.147.7MicrosoftWindows 11 version 23H2CWE-190Windows Performance Monitor Remote Code Execution Vulnerability
CVE-2026-429818.147.7MicrosoftWindows 11 version 23H2CWE-191Windows Performance Monitor Remote Code Execution Vulnerability
CVE-2026-403718.847.3MicrosoftMicrosoft Dynamics 365 (on-premises) version 9.1CWE-755Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
CVE-2026-73838.147.3OpenSSLOpenSSLCWE-787Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion
CVE-2026-454554.347.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Excel Information Disclosure Vulnerability
CVE-2026-409837.547.0SpringMicrometerCWE-400Micrometer gRPC server instrumentation DoS vulnerability
CVE-2026-456504.346.8MicrosoftMicrosoft Bing Search for AndroidCWE-451Microsoft Bing Search Spoofing Vulnerability
CVE-2026-454457.546.0OpenSSLOpenSSLCWE-325AES-OCB IV Ignored on EVP_Cipher() Path
CVE-2026-476538.846.0MicrosoftWindows 10 Version 1607CWE-787Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-429878.145.4MicrosoftWindows Server 2012CWE-416Windows Deployment Services (WDS) Remote Code Execution
CVE-2026-90767.545.4OpenSSLOpenSSLCWE-125Out-of-Bounds Read in CMS Password-Based Decryption
CVE-2026-499556.945.3nesquenahermes-webuiCWE-770Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options
CVE-2026-117887.545.1Red HatRed Hat Directory Server 11.7 E4S for RHEL 8CWE-476389-ds-base: 389-ds-base: null pointer dereference in deref control plugin be…
CVE-2026-427683.745.0OpenSSLOpenSSLCWE-514Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
CVE-2026-301419.844.6n/an/aCWE-120An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in …
CVE-2025-102639.144.5ArmC1-UltraCWE-362Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neove…
CVE-2026-479308.144.4AdobeColdFusionCWE-20ColdFusion | Improper Input Validation (CWE-20)
CVE-2017-202519.343.9ThemeisleWoody Code SnippetsCWE-94WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API
CVE-2026-476345.443.9MicrosoftMicrosoft SharePoint Server 2019CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-427675.943.8OpenSSLOpenSSLCWE-476NULL Pointer Dereference in CRMF EncryptedValue Decryption
CVE-2026-456448.043.6MicrosoftMicrosoft Live Share Canvas SDKCWE-79Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability
CVE-2026-4830310.043.6AdobeAdobe Campaign Classic (ACC)CWE-863Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CVE-2026-96628.143.5plasmatizemediaRecover Exit For WooCommerceCWE-98Recover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion …
CVE-2026-476547.543.4MicrosoftWindows Server 2016CWE-787Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-485637.543.4MicrosoftWindows 10 Version 1809CWE-787Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-448037.841.9MicrosoftMicrosoft Excel for AndroidCWE-190Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-448127.841.9MicrosoftMicrosoft Excel for AndroidCWE-190Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-331136.141.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-455998.141.8MicrosoftWindows 10 Version 1607CWE-416Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-456358.141.8MicrosoftWindows 10 Version 1607CWE-416Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-448228.241.7MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Excel Information Disclosure Vulnerability
CVE-2026-367265.341.2n/an/aCWE-22An arbitrary file deletion vulnerability in the /api/delete-temp-license/{fil…
CVE-2026-417318.141.1SpringSpring for Apache KafkaCWE-502In Spring for Apache Kafka, overly broad trusted-package matching in header m…
CVE-2026-454535.441.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454645.441.1MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454655.441.1MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476365.441.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476395.441.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-427657.541.1OpenSSLOpenSSLCWE-476NULL Dereference in Certificate Verification with OCSP Checking
CVE-2026-454625.440.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454675.440.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454685.440.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454795.440.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454835.440.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft Office Project Server Spoofing Vulnerability
CVE-2026-476375.440.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476385.440.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476405.440.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476415.440.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-20Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-485624.640.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2025-522927.540.5n/an/aCWE-121A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP…
CVE-2026-472887.140.5MicrosoftWindows Server 2012CWE-190Windows Kerberos Key Distribution Center (KDC) Remote Code Execution
CVE-2026-335826.539.3Apache Software FoundationApache AnswerCWE-434Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory…
CVE-2026-455838.139.0MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-94Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2026-429137.538.9MicrosoftRemote Desktop client for Windows DesktopCWE-362Remote Desktop Client Remote Code Execution Vulnerability
CVE-2025-522937.538.5n/an/aCWE-400A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_t…
CVE-2025-556577.538.5n/an/aCWE-476A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descr…
CVE-2026-448215.538.4MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Office Information Disclosure Vulnerability
CVE-2026-96989.838.3HMBRANDDBICWE-787DBI versions before 1.648 for Perl saved errors in a limited-sized buffer
CVE-2026-429927.538.1MicrosoftWindows 10 Version 1607CWE-122Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-447997.538.1MicrosoftRemote Desktop client for Windows DesktopCWE-122Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-448017.538.1MicrosoftRemote Desktop client for Windows DesktopCWE-787Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-440838.738.0QNAP Systems Inc.QuMagieCWE-639QuMagie
CVE-2026-429715.538.0MicrosoftWindows 10 Version 1607CWE-200Windows Push Notification Information Disclosure Vulnerability
CVE-2026-429725.538.0MicrosoftWindows 10 Version 1607CWE-200Windows Hyper-V Information Disclosure Vulnerability
CVE-2026-479607.437.8AdobeColdFusionCWE-611ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (C…
CVE-2026-448197.837.7MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Remote Code Execution Vulnerability
CVE-2026-448247.837.7MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Remote Code Execution Vulnerability
CVE-2026-454717.837.7MicrosoftMicrosoft 365 Apps for EnterpriseCWE-822Microsoft Word Remote Code Execution Vulnerability
CVE-2026-454757.837.7MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Remote Code Execution Vulnerability
CVE-2026-427703.737.7OpenSSLOpenSSLCWE-325FFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2026-401289.037.7SAP_SESAP NetWeaver Application Server Java (Web Container)CWE-35Directory Traversal vulnerability in SAP NetWeaver Application Server Java (W…
CVE-2026-50688.837.5zephyrproject-rtosZephyrCWE-787bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data
CVE-2026-4793810.037.3AdobeAdobe Campaign Classic (ACC)CWE-918Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
CVE-2026-498427.537.3signalwirefreeswitchCWE-400FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-…
CVE-2026-485747.837.0MicrosoftWindows 10 Version 1607CWE-122Windows Media Remote Code Execution Vulnerability
CVE-2026-455036.537.0MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-918Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2025-628585.137.0QNAP Systems Inc.QTSCWE-121QTS, QuTS hero
CVE-2026-463169.336.7LinuxLinuxCWE-911KVM: arm64: vgic-its: Drop the translation cache reference only for the erase…
CVE-2026-472927.836.6MicrosoftVisual Studio Code - MSSQL ExtensionCWE-94Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
CVE-2026-429049.636.5MicrosoftWindows 10 Version 21H2CWE-122Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-454568.436.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-843Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-454588.436.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-416Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-276719.836.4SAP_SESAP NetWeaver AS ABAP and ABAP PlatformCWE-121Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver a…
CVE-2026-454853.336.4MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Office Information Disclosure Vulnerability
CVE-2026-429937.536.2MicrosoftWindows 10 Version 21H2CWE-122Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-467468.736.0SiemensSINEC INSCWE-78A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Upd…
CVE-2026-485657.836.0MicrosoftWindows Narrator BrailleCWE-426Windows Narrator Braille Elevation of Privilege Vulnerability
CVE-2026-347117.535.9AdobeCAI Content CredentialsCWE-190CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
CVE-2026-447167.535.3pipecat-aipipecatCWE-22Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File …
CVE-2026-455955.435.3MicrosoftWindows 10 Version 1607CWE-693Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2026-464918.635.3simplesamlphpsimplesamlphp-module-casserverCWE-22SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ti…
CVE-2026-499576.335.1nesquenahermes-webuiCWE-22Hermes WebUI < 0.51.296 Workspace Boundary Bypass via api/workspace.py
CVE-2026-425675.935.2sveltejssvelteCWE-1333Svelte: ReDoS in `<svelte:element>` Tag Validation
CVE-2026-456497.134.9MicrosoftMicrosoft Excel for AndroidCWE-284Office for Android Spoofing Vulnerability
CVE-2026-498477.534.5signalwirefreeswitchCWE-674FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
CVE-2026-456555.334.4MicrosoftWindows 10 Version 1607CWE-693Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-456367.834.3MicrosoftWindows 10 Version 1607CWE-20Windows NTFS Remote Code Execution Vulnerability
CVE-2026-347127.533.9AdobeCAI Content CredentialsCWE-20CAI Content Credentials | Improper Input Validation (CWE-20)
CVE-2026-347137.533.9AdobeCAI Content CredentialsCWE-400CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVE-2026-256886.133.8Apache Software FoundationApache AnswerCWE-87Apache Answer: XSS in AI Answer Rendering
CVE-2026-256996.133.8Apache Software FoundationApache AnswerCWE-359Apache Answer: Authorization Bypass in Timeline API
CVE-2026-429065.533.6MicrosoftWindows 10 Version 21H2CWE-200Windows Shell Information Disclosure Vulnerability
CVE-2026-429705.533.6MicrosoftWindows 10 Version 1607CWE-200Windows Push Notification Information Disclosure Vulnerability
CVE-2026-429735.533.6MicrosoftWindows 10 Version 1607CWE-200Windows Push Notification Information Disclosure Vulnerability
CVE-2026-455945.533.6MicrosoftWindows 10 Version 1607CWE-200Windows Application Identity (AppID) Information Disclosure Vulnerability
CVE-2026-91857.533.5sixstorage6Storage RentalsCWE-6396Storage Rentals <= 2.22.0 - Unauthenticated Insecure Direct Object Reference…
CVE-2026-340316.533.6Apache Software FoundationApache AnswerCWE-434Apache Answer: The custom avatar was not properly validated
CVE-2026-116185.533.3DTStackTaierCWE-287DTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle…
CVE-2026-427695.333.3OpenSSLOpenSSLCWE-295Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
CVE-2026-418427.533.0SpringSpring FrameworkCWE-400Spring Framework Denial of Service via Versioned Resources in Spring MVC and …
CVE-2026-367797.532.9n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa…
CVE-2026-367837.532.9n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa…
CVE-2026-367917.532.9n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3v3 v1.0.0.5 was discovered to cont…
CVE-2026-367927.532.9n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa…
CVE-2026-367937.532.9n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa…
CVE-2026-367947.532.9n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa…
CVE-2026-367967.532.9n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-367977.532.9n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-367997.532.9n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-429097.532.9MicrosoftRemote Desktop client for Windows DesktopCWE-787Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-92136.932.9NETGEARMR70CWE-20Insufficient input validation in certain NETGEAR routers
CVE-2026-498419.832.6signalwirefreeswitchCWE-122FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST …
CVE-2026-417298.132.5SpringSpring Data RESTCWE-917Spring Data REST SpEL Injection via Map Key in JSON Patch
CVE-2026-425707.532.4sveltejsdevalueCWE-770Svelte devalue: DoS via sparse array deserialization
CVE-2026-454618.432.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-787Microsoft Office Remote Code Execution Vulnerability
CVE-2026-429685.531.9MicrosoftWindows 10 Version 1607CWE-125Windows Telephony Server Information Disclosure Vulnerability
CVE-2026-429695.531.9MicrosoftWindows 10 Version 1607CWE-908Windows Push Notification Information Disclosure Vulnerability
CVE-2026-454915.532.0Microsoft.NET 10.0CWE-59.NET Tampering Vulnerability
CVE-2026-485665.531.9MicrosoftWindows 11 Version 24H2CWE-125Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-454907.831.5Microsoft.NET 10.0CWE-285.NET SDK Elevation of Privilege Vulnerability
CVE-2026-429155.531.4MicrosoftWindows 10 Version 21H2CWE-131Microsoft Windows VMSwitch Denial of Service Vulnerability
CVE-2026-456065.531.4MicrosoftWindows 10 Version 1607CWE-125Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability
CVE-2026-455006.130.6MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-79Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-506358.730.3LimeSurveyLimeSurveyCWE-640LimeSurvey Password Reset Host Header Injection Discloses Reset Token
CVE-2026-448177.830.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-843Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-448207.830.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-448237.830.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-197Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-454577.830.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Word Remote Code Execution Vulnerability
CVE-2026-454697.830.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-454867.830.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-416Microsoft Word Remote Code Execution Vulnerability
CVE-2026-456437.830.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-822Microsoft Word Remote Code Execution Vulnerability
CVE-2026-456457.830.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-787Microsoft Office Remote Code Execution Vulnerability
CVE-2026-340335.430.4Apache Software FoundationApache AnswerCWE-79Apache Answer: HTML Content Injection in Email
CVE-2026-536738.630.2BuddyPressBuddyPressCWE-639BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter
CVE-2026-454593.330.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-693Microsoft Excel Security Feature Bypass Vulnerability
CVE-2026-454663.330.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Word Information Disclosure Vulnerability
CVE-2026-367784.930.1n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa…
CVE-2009-100079.130.0ETHERCatalyst::Plugin::AuthenticationCWE-384Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is suscept…
CVE-2026-97507.129.9MongoDBMongoDB ServerCWE-617Metadata name collision on $-prefixed fields causes post-auth server crash
CVE-2026-536747.129.8BuddyPressBuddyPressCWE-943BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution
CVE-2026-456029.129.7MicrosoftWindows 10 Version 1607CWE-349Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
CVE-2026-367279.129.5n/an/aCWE-287An insecure authentication vulnerability in the /api/social-sign-in endpoint …
CVE-2026-454638.429.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-121Microsoft Office Remote Code Execution Vulnerability
CVE-2026-454728.429.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-787Microsoft Office Remote Code Execution Vulnerability
CVE-2026-454748.429.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-787Microsoft Office Remote Code Execution Vulnerability
CVE-2026-416957.529.4SpringSpring Data CommonsCWE-400Denial of Service in Spring Data Commons Property Path Resolution
CVE-2026-417167.529.4SpringSpring Data CommonsCWE-770Spring Data web support unbounded negative-result cache keyed on attacker-sup…
CVE-2026-454464.829.4OpenSSLOpenSSLCWE-325Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
CVE-2026-456345.529.3MicrosoftWindows 10 Version 1607CWE-125Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-418507.529.1SpringSpring FrameworkCWE-407Spring Framework Algorithmic Denial of Service via SpEL Expressions
CVE-2026-418517.529.1SpringSpring FrameworkCWE-770Spring Framework Denial of Service via Unbounded Cache in SpEL
CVE-2026-482883.529.1AdobeAdobe Experience ManagerCWE-20Adobe Experience Manager | Improper Input Validation (CWE-20)
CVE-2026-346919.328.9AdobeAdobe Experience Manager Forms JEECWE-79Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-506368.728.9LimeSurveyLimeSurveyCWE-89LimeSurvey RemoteControl invite_participants/remind_participants SQL Injection
CVE-2026-456077.828.7MicrosoftWindows 10 Version 1607CWE-125Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-30884.928.8NETGEARRBR860CWE-787Unauthenticated users can disrupt router operation
CVE-2026-454604.728.7MicrosoftMicrosoft 365 Apps for EnterpriseCWE-126Microsoft Office Information Disclosure Vulnerability
CVE-2026-448055.528.7MicrosoftWindows Server 2019CWE-416Windows Network Controller (NC) Host Agent Denial of Service Vulnerability
CVE-2026-497382.128.7TYPO3TYPO3 CMSCWE-22TYPO3 CMS - Broken Access Control in File Abstraction Layer
CVE-2026-456586.828.3MicrosoftWindows 10 Version 1607CWE-284Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-476315.428.4MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-79Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-341829.128.1OpenSSLOpenSSLCWE-354CMS AuthEnvelopedData Processing May Accept Forged Messages
CVE-2026-485695.528.1MicrosoftVisual Studio CodeCWE-20Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-107319.328.0NemonNemon Trade EnergyCWE-89SQL injection in Nemon products
CVE-2026-463259.827.8LinuxLinuxRDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
CVE-2026-97428.227.7MongoDBMongoDB ServerCWE-1287Authenticate command with specific mechanism parameter can trigger server crash
CVE-2026-417328.127.8SpringSpring for Apache PulsarCWE-502In Spring for Apache Pulsar, overly broad trusted-package matching in header …
CVE-2026-465417.527.6nimiqcore-rs-albatrossCWE-754Nimiq network-libp2p: DHT query poisoning via first-record verification failure
CVE-2026-97408.727.5MongoDBMongoDB ServerCWE-674Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack…
CVE-2026-454828.427.5MicrosoftMicrosoft Visual Studio Code CoPilot Chat ExtensionCWE-22Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
CVE-2025-556596.527.5n/an/aCWE-476A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_…
CVE-2026-457717.527.3signalwirefreeswitchCWE-776Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
CVE-2026-476528.227.1MicrosoftWindows 11 version 23H2CWE-122Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-418435.927.1SpringSpring FrameworkCWE-22Spring Framework Path Traversal via Versioned Static Resources in Spring MVC …
CVE-2026-456045.527.1MicrosoftWindows 11 version 23H2CWE-125Windows Managed Installer Information Disclosure Vulnerability
CVE-2026-404047.826.8MicrosoftWindows 10 Version 1607CWE-122Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg…
CVE-2026-465457.526.8nimiqcore-rs-albatrossCWE-248nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
CVE-2026-456086.826.7MicrosoftWindows 10 Version 1607CWE-125Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-321938.826.5MicrosoftAzure Kubernetes ServiceCWE-22Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability
CVE-2026-446348.726.2simpleblesimplebleCWE-121Stack buffer overflows in SimpleBLE
CVE-2026-476358.426.2MicrosoftMicrosoft Office LTSC 2024CWE-122Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-409887.526.0SpringSpring SecurityCWE-400Unbounded DEFLATE Inflation in SAML 2.0 Service Provider
CVE-2026-417215.926.0SpringSpring Data CommonsCWE-400Spring Data Commons Denial of Service via Data Binding
CVE-2026-479127.825.8AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-479137.825.8AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-479147.825.8AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-505117.825.8MicrosoftMicrosoft PC ManagerCWE-59Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2026-367707.525.8n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda US_W3V1.0BR v1.0.0.3 was discovered …
CVE-2026-367717.525.8n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa…
CVE-2026-367847.525.8n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa…
CVE-2026-417178.125.7SpringSpring Data MongoDBCWE-917Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter…
CVE-2026-428287.825.4MicrosoftWindows 10 Version 1809CWE-126Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-428377.825.4MicrosoftWindows 10 Version 1809CWE-125Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-429167.825.4MicrosoftWindows 10 Version 1607CWE-190NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-349056.525.3Apache Software FoundationApache AnswerCWE-200Apache Answer: Unlisted Questions Accessible via Direct API Access
CVE-2026-454768.225.2MicrosoftLinux kernel - Microsoft MANA Network DriverCWE-416Microsoft Azure Network Adapter Elevation of Privilege Vulnerability
CVE-2026-240658.125.1Waves Audio Ltd.Waves CentralCWE-367Local Privilege Escalation via Insecure XPC Client Validation in Waves Centra…
CVE-2026-97487.125.1MongoDBMongoDB ServerCWE-617$_internalConvertBucketIndexStats may crash the mongod server when working on…
CVE-2026-04134.325.0NETGEARRBE370CWE-121Buffer overflow vulnerability in certain NETGEAR Nighthawk routers
CVE-2026-262366.625.0QNAP Systems Inc.QuMagieCWE-862QuMagie
CVE-2026-367197.524.9n/an/aCWE-200An information disclosure vulnerability in the /api/v1/user/info endpoint of …
CVE-2026-425735.324.7sveltejssvelteCWE-79Svelte: XSS via DOM Clobbering of Internal Framework State
CVE-2026-456423.924.7MicrosoftWindows 10 Version 1607CWE-20Microsoft Azure Attestation service and Device Health Attestation Service Spo…
CVE-2026-448145.524.5MicrosoftWindows 11 version 26H1CWE-122Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-418487.524.4SpringSpring FrameworkCWE-1333Spring Framework Denial of Service via AntPathMatcher
CVE-2026-497427.124.0TYPO3TYPO3 CMSCWE-22TYPO3 CMS - Broken Access Control in Media Module
CVE-2026-418415.924.0SpringSpring FrameworkCWE-524Spring Framework Information Disclosure via Static Resource Cache in Spring M…
CVE-2026-498409.123.6signalwirefreeswitchCWE-20FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length…
CVE-2026-338287.823.6MicrosoftWindows 10 Version 1607CWE-501Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability
CVE-2026-456547.923.5MicrosoftWindows 11 Version 24H2CWE-284Secure Boot Security Feature Bypass Vulnerability
CVE-2026-368007.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-368017.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-368027.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to cont…
CVE-2026-368037.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to cont…
CVE-2026-368057.523.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-368067.523.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368077.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368087.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368097.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368107.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368117.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368137.523.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368157.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368167.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368177.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368187.523.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368197.523.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368207.523.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368217.523.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368227.523.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368237.523.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-455016.123.5MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-79Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-456417.823.3MicrosoftWindows 10 Version 21H2CWE-125Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-456567.823.3MicrosoftWindows 10 Version 1607CWE-693UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-479157.823.3AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-479177.823.3AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-97437.123.3MongoDBMongoDB serverCWE-476Aggregation sub-pipeline null dereference may allow DoS via crafted getMore
CVE-2026-417287.523.2SpringSpring Data RESTCWE-284Spring Data REST JSON Patch bypasses Jackson read-only property protection on…
CVE-2026-455887.923.0MicrosoftWindows 10 Version 1607CWE-693Secure Boot Security Feature Bypass Vulnerability
CVE-2026-476567.923.0MicrosoftWindows 10 Version 1607CWE-693Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-485687.923.0MicrosoftWindows 10 Version 1607CWE-693Secure Boot Security Feature Bypass Vulnerability
CVE-2026-485707.923.0MicrosoftWindows 10 Version 1607CWE-693Secure Boot Security Feature Bypass Vulnerability
CVE-2026-485757.923.0MicrosoftWindows 10 Version 1607CWE-693Secure Boot Security Feature Bypass Vulnerability
CVE-2026-351885.022.8OpenSSLOpenSSLCWE-415Double-free When Checking OCSP Stapled Response
CVE-2026-367986.522.7n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-464116.522.7halfgaarFlashMQCWE-248FlashMQ: Client can trigger uncaught exception on FlashMQ 1.26.1 and older
CVE-2026-410077.522.5SpringSpring HATEOASCWE-770Spring HATEOAS heap exhaustion through unbounded internal caching
CVE-2026-346938.022.3AdobeAdobe Experience Manager Forms JEECWE-79Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CW…
CVE-2026-404097.822.3MicrosoftWindows 10 Version 1607CWE-197Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg…
CVE-2026-97537.222.3MongoDBMongoDB ServerCWE-787Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
CVE-2026-479187.822.2AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-479197.822.2AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-445055.322.3nimiqcore-rs-albatrossCWE-755Nimiq network-libp2p: Untrusted peer can wedge DHT
CVE-2025-556586.522.1n/an/aCWE-1077GPAC MP4Box v2.4 was discovered to contain a floating point exception in the …
CVE-2026-417266.522.1SpringSpring for Apache KafkaCWE-770In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled…
CVE-2017-202498.822.0appthaApptha Slider GalleryCWE-89WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection
CVE-2026-473475.322.0TYPO3TYPO3 CMSCWE-601TYPO3 CMS - Open Redirect in Core Utilities
CVE-2026-479245.521.8AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-258605.321.9frankverbekeOpenClinic GACWE-79OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
CVE-2026-410927.821.6MicrosoftWindows 10 Version 1607CWE-284Microsoft Kinect Elevation of Privilege Vulnerability
CVE-2026-428297.821.6MicrosoftWindows 11 Version 24H2CWE-284Windows Administrator Protection Secure Feature Bypass Vulnerability
CVE-2026-429027.821.6MicrosoftMicrosoft PowerToysCWE-285Microsoft PowerToys Elevation of Privilege Vulnerability
CVE-2026-465435.321.6nimiqcore-rs-albatrossCWE-617nimiq-blockchain: Genesis batch set request
CVE-2026-117904.921.6Red HatRed Hat Directory Server 11CWE-400389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration …
CVE-2026-499488.621.5mem0aimem0CWE-862Mem0 0.2.8 Missing Authorization via POST /configure Endpoint
CVE-2026-367246.521.4n/an/aCWE-400An uncaught exception in the /application/job/update/{id} endpoint of Fastapi…
CVE-2026-04194.421.4NETGEARJR6150CWE-20Insufficient input validation vulnerability in NETGEAR JR6150
CVE-2026-429107.821.1MicrosoftWindows 11 Version 24H2CWE-787Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability
CVE-2026-429837.821.1MicrosoftWindows 10 Version 1809CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-455927.821.1MicrosoftWindows 10 Version 1607CWE-190Windows Internet (wininet.dll) Elevation of Privilege Vulnerability
CVE-2026-455937.821.1MicrosoftWindows 10 Version 1809CWE-190Windows SDK Elevation of Privilege Vulnerability
CVE-2026-456007.821.1MicrosoftWindows 11 Version 24H2CWE-843Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-456057.821.1MicrosoftWindows 10 Version 1607CWE-416Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2026-456377.821.1MicrosoftWindows 10 Version 1809CWE-416Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-456387.821.1MicrosoftWindows 10 Version 1607CWE-122Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab…
CVE-2026-116205.521.0TOTOLINKEX200CWE-266TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation
CVE-2026-498435.320.9signalwirefreeswitchCWE-287FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` …
CVE-2026-117896.520.7Red HatRed Hat Directory Server 11CWE-191389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer un…
CVE-2026-479395.420.7AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479415.420.7AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479425.420.7AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479435.420.7AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479455.420.7AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479485.420.7AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479705.420.7AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-117934.920.7Red HatRed Hat Directory Server 11CWE-121389-ds-base: 389-ds-base: stack buffer overflow in checkprefix() algorithm id…
CVE-2026-482917.820.6AdobeFormat PluginsCWE-122Format Plugins | Heap-based Buffer Overflow (CWE-122)
CVE-2026-482927.820.6AdobeFormat PluginsCWE-122Format Plugins | Heap-based Buffer Overflow (CWE-122)
CVE-2026-479235.520.5AdobeAcrobat ReaderCWE-125Acrobat Reader | Out-of-bounds Read (CWE-125)
CVE-2026-417105.920.4SpringSpring RetryCWE-770Cache Exhaustion in Stateful Retries leads to Denial of Service
CVE-2026-417115.920.4SpringSpring Data CommonsCWE-400Potential Denial of Service through crafted Sort Parameters
CVE-2026-64458.720.4EverpureFlashArrayCWE-939A flaw exists in FlashArray Purity where insufficient filtering of certain da…
CVE-2026-64448.620.4EverpureFlashArrayCWE-639A flaw exists in the FlashArray Purity management interface where an authenti…
CVE-2026-494757.520.3signalwirefreeswitchCWE-20FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing
CVE-2026-04114.220.3NETGEARRBE970CWE-200A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi Satellites
CVE-2026-479117.820.0AdobeAcrobat ReaderCWE-787Acrobat Reader | Out-of-bounds Write (CWE-787)
CVE-2026-410067.520.1SpringSpring HATEOASCWE-284Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson config…
CVE-2026-74869.819.9Netcad Software Inc.E-İmarCWE-89SQLi in Netcad's E-İmar
CVE-2026-80259.819.9MOSK Information Technologies Ltd.CBS PlatformCWE-89SQLi in MOSK Informatics' CBS Platform
CVE-2026-116168.819.9stiofansislandEvents Calendar for GeoDirectoryCWE-269Events Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Priv…
CVE-2026-411087.019.8MicrosoftWindows 10 Version 1607CWE-122Windows DNS Client Elevation of Privilege Vulnerability
CVE-2026-84995.319.7helpfulcrowdHelpfulcrowd Product ReviewsCWE-843Helpfulcrowd Product Reviews <= 1.2.9 - Inccorect Authorization via Type Jugg…
CVE-2026-499567.119.6nesquenahermes-webuiCWE-862Hermes WebUI < 0.51.269 Profile Isolation Bypass via sessions search
CVE-2016-200628.819.3Ollie ArmstrongSimply PollCWE-89Simply Poll 1.4.1 Plugin for WordPress SQL Injection
CVE-2016-200658.819.3EvWillProduct Catalog 8CWE-89Product Catalog 8 1.2 Plugin WordPress SQL Injection
CVE-2017-202448.819.3Wow-CompanyWow FormsCWE-89Wow Forms WordPress Plugin 2.1 SQL Injection
CVE-2017-202458.819.3Wow-CompanyWow Viral SignupsCWE-89Wow Viral Signups 2.1 WordPress Plugin SQL Injection
CVE-2017-202468.819.3MissilesiloKittyCatfishCWE-89KittyCatfish 2.2 Plugin for WordPress SQL Injection
CVE-2026-92798.719.2logseqlogseqCWE-78Shell command injection in Logseq
CVE-2026-97467.119.2MongoDBMongoDB ServerCWE-617Server crashes in case of the use of exchange
CVE-2026-97477.119.2MongoDBMongoDB ServerCWE-617Crafted cross-shard merge aggregation crashes MongoDB Server
CVE-2026-97497.119.2MongoDBMongoDB ServerCWE-617Using MaxKey() may crash the server
CVE-2026-97527.119.2MongoDBMongoDB ServerCWE-476GeometryCollection with strict-winding polygon causes server crash during 2ds…
CVE-2026-92125.619.2NETGEARLBR1020CWE-20Insufficient authentication and input validation in certain NETGEAR products
CVE-2026-473485.119.1TYPO3TYPO3 CMSCWE-79TYPO3 CMS - Cross-Site Scripting in Indexed Search
CVE-2026-367219.819.1n/an/aCWE-347A lack of cryptographic signature verification in the validateAccessToken fun…
CVE-2026-418559.819.0SpringSpring FrameworkCWE-502Spring Framework Unsafe Deserialization via Jackson JMS Converters
CVE-2026-485787.919.0MicrosoftWindows 10 Version 1607CWE-284Secure Boot Security Feature Bypass Vulnerability
CVE-2026-448027.818.9MicrosoftWindows 10 Version 1809CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448047.818.9MicrosoftWindows 11 version 26H1CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448077.818.9MicrosoftWindows 11 version 26H1CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448087.818.9MicrosoftWindows 11 version 26H1CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448097.818.9MicrosoftWindows 11 Version 24H2CWE-416Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-448117.818.9MicrosoftWindows 11 version 26H1CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448137.818.9MicrosoftWindows 11 version 26H1CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-485837.818.9MicrosoftWindows 10 Version 1607CWE-416Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-418497.518.2SpringSpring FrameworkCWE-190Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

Results continue: ranks 401–719.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-09 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.