boxscore/security
Wednesday, June 10, 2026 · all times UTC← 2026-06-09 · archive · 2026-06-11 →

250 CVEs published June 10, 2026: 16 critical, 98 high, 116 medium, 20 low; 0 in KEV; 16 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 225 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published2862723410582563
KEV catalog size1670

340 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9610628466331212730.37.8.0013-114
google56373765383267197460.88.1.0023+563
microsoft207697524661584378273.97.8.0043+195
red hat3498844406400.07.1.0032+30
apple24901327293714.36.2.0032+2
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
debian220020000.06.5.0023+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161800.04.3.0024+17
cisco316324096956.37.2.0971+3
palo alto networks911017114218.24.8.0022+8
ivanti38130033450.08.8.4316+2
checkpoint2814303112.57.5.0423+2
fortinet28132028337.57.3.0066+2
broadcom2400204250.05.3.0887+2
vmware3301202100.05.4.0031+3
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache568812363724011.17.3.0053+52
mozilla51134401300.07.5.0032+1
gitlab0901604222.24.3.00320
docker250500100.08.8.0021+2
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
adobe1231274467227532.45.5.0021+123
ibm5541326150700.07.5.0031+5
oracle229816404013.48.0.0027+2
progress591710900.07.5.0036+5
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link81103252619.14.2.0059+8
siemens780440100.07.5.0020+7
abb440400000.07.3.0024+4
dahua330111200.06.9.0036+3
hitachi energy020020000.05.7.00140
schneider electric110100100.07.1.0023+1
hikvision01000021100.01.00000
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester3557002433000.02.1.0026+35
spring5354121320000.06.5.0025+53
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
totolink338026111000.08.9.0191+3

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2010-0806.821799.6
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4399710.0.0098
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
Most disclosures (vendor)
VendorCVEs
google731
linux525
microsoft365
adobe124
apache73
red hat71
sourcecodester57
ibm54
spring54
edimax51
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco9
apple7
google6
ivanti4
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven24
Packagist22
PyPI11
npm3
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171666
CVE-2021-27102Accellion2021-11-171666
CVE-2021-27101Accellion2021-11-171666
CVE-2021-27103Accellion2021-11-171666
CVE-2021-21017Adobe2021-11-171666
CVE-2021-28550Adobe2021-11-171666
CVE-2021-42013Apache2021-11-171666
CVE-2021-41773Apache2021-11-171666
CVE-2021-30858Apple2021-11-171666
CVE-2021-30860Apple2021-11-171666

Transactions

EXPLOIT PUBLISHEDCVE-2026-1220 (Google Chrome). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42542 (taosdata TDengine). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46558 (makeplane plane). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46642 (jgraph drawio). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49495 (nationalsecurityagency ghidra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49496 (nationalsecurityagency ghidra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49497 (nationalsecurityagency ghidra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52751 (nationalsecurityagency ghidra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52752 (nationalsecurityagency ghidra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52753 (nationalsecurityagency ghidra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52755 (nationalsecurityagency ghidra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52756 (nationalsecurityagency ghidra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52757 (nationalsecurityagency ghidra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52759 (Ghidra). Public exploit reference added.

Yesterday's Results

250 CVEs published. 25 box scores, 225 table rows — nothing truncated.

Jenkins Project Jenkins — In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deseria…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .1903   97.1     —
AFFECTED
  Product  Versions     Fixed
  Jenkins  unspecified  2.568
TIMELINE
  Jun 9   Reserved by CNA
  Jun 10  Published (CNA: jenkins)
CWE-502 · CNA: jenkins · 4 references · NVD status: Modified
Splunk Splunk Enterprise — Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .1899   97.1     —
AFFECTED
  Product                Versions     Fixed
  Splunk Enterprise      10.2 –       —
  Splunk Cloud Platform  10.3.2512 –  —
  Splunk Secure Gateway  3.10 –       —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 10  Published (CNA: cisco)
CWE-502 · CNA: cisco · 1 reference · NVD status: Analyzed
Unknown Xstore — XStore < 9.7.3 - Unauthenticated SQLi
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0187   77.5     —
AFFECTED
  Product  Versions     Fixed
  Xstore   unspecified  —
TIMELINE
  Feb 27  Reserved by CNA
  Jun 10  Published (CNA: WPScan)
CWE-89 · CNA: WPScan · 1 reference · NVD status: Deferred
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0185   77.3     —
AFFECTED
  Product      Versions      Fixed
  ImageMagick  < 7.1.2-23 –  —
TIMELINE
  May 14  Reserved by CNA
  Jun 10  Published (CNA: GitHub_M)
CWE-400, CWE-835 · CNA: GitHub_M · 5 references · NVD status: Modified
contrid Newsletters — Newsletters <= 4.13 - Unauthenticated SQL Injection via wpmlsubscriber_id Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0138   69.8     —
AFFECTED
  Product      Versions     Fixed
  Newsletters  unspecified  —
TIMELINE
  Feb 23  Reserved by CNA
  Jun 10  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 3 references · NVD status: Deferred
Palo Alto Networks Cloud NGFW — PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    6.1   .0134   68.9     —
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         12.1.0 –     12.1.4-h7
  Prisma Access  unspecified  All
TIMELINE
  Nov 3   Reserved by CNA
  Jun 10  Published (CNA: palo_alto)
CWE-78 · CNA: palo_alto · 2 references · NVD status: Modified
Red Hat Red Hat Enterprise Linux 10 — Dracut: dracut: root code execution via dhcp options command injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   H   N   N  U  H  H  H    7.5   .0109   62.6     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat Enterprise Linux 10             unspecified  0:107-7.el10_2
  Red Hat Enterprise Linux 8              unspecified  0:049-244.git20260529.el8_10
  Red Hat Enterprise Linux 9              unspecified  0:057-115.git20260527.el9_8
  Red Hat Enterprise Linux 9              unspecified  0:057-115.git20260527.el9_8
  Red Hat Hardened Images                 unspecified  109-6.hum1
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 7              unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  Jun 10  Published (CNA: redhat)
CWE-78 · CNA: redhat · 7 references · NVD status: Awaiting Analysis
QNAP Systems Inc. QTS — QTS, QuTS hero
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0109   62.5     —
AFFECTED
  Product    Versions  Fixed
  QTS        5.2.0 –   —
  QuTS hero  h5.2.0 –  —
TIMELINE
  Jan 13  Reserved by CNA
  Jun 10  Published (CNA: qnap)
CWE-78 · CNA: qnap · 1 reference · NVD status: Analyzed
TP-Link Systems Inc. Archer AX12 V1 — Command Injection Vulnerability in OpenVPN on Multiple TP-Link Archer Routers
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   H   H   H    8.5   .0107   62.0     —
AFFECTED
  Product             Versions     Fixed
  Archer AX12 V1      unspecified  —
  Archer AX18 v1      unspecified  —
  Archer AX17 v1      unspecified  —
  Archer AX1300 v1.6  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 10  Published (CNA: TPLink)
CWE-78 · CNA: TPLink · 5 references · NVD status: Deferred
QNAP Systems Inc. QTS — QTS, QuTS hero
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0105   61.4     —
AFFECTED
  Product    Versions  Fixed
  QTS        5.2.0 –   —
  QuTS hero  h5.2.0 –  —
TIMELINE
  Nov 26  Reserved by CNA
  Jun 10  Published (CNA: qnap)
CWE-78 · CNA: qnap · 1 reference · NVD status: Analyzed
QNAP Systems Inc. QTS — QTS, QuTS hero
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0105   61.4     —
AFFECTED
  Product    Versions  Fixed
  QTS        5.2.0 –   —
  QuTS hero  h5.2.0 –  —
TIMELINE
  Nov 26  Reserved by CNA
  Jun 10  Published (CNA: qnap)
CWE-78 · CNA: qnap · 1 reference · NVD status: Analyzed
Yamcs Vulnerable to LDAP Injection in LdapAuthModule
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  N    4.3   .0103   60.7     —
AFFECTED
  Product  Versions    Fixed
  yamcs    < 5.12.7 –  —
TIMELINE
  Apr 28  Reserved by CNA
  Jun 10  Published (CNA: GitHub_M)
CWE-90 · CNA: GitHub_M · 3 references · NVD status: Deferred
QNAP Systems Inc. QTS — QTS, QuTS hero
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    6.1   .0098   59.2     —
AFFECTED
  Product    Versions  Fixed
  QTS        5.2.0 –   —
  QuTS hero  h5.2.0 –  —
TIMELINE
  Jan 26  Reserved by CNA
  Jun 10  Published (CNA: qnap)
CWE-78 · CNA: qnap · 1 reference · NVD status: Modified
AWS AWS Cloud Development Kit library — OS Command Injection in NodejsFunction Bundling in aws-cdk-lib
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   A   H   H   H    7.0   .0094   57.9     —
AFFECTED
  Product                            Versions     Fixed
  AWS Cloud Development Kit library  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 10  Published (CNA: AMZN)
CWE-78 · CNA: AMZN · 3 references · NVD status: Awaiting Analysis
nationalsecurityagency ghidra — Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    8.6   .0071   50.5     —
AFFECTED
  Product  Versions     Fixed
  ghidra   unspecified  12.1
TIMELINE
  Jun 8   Reserved by CNA
  Jun 10  Public exploit reference published
  Jun 10  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 3 references · NVD status: Analyzed
Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0066   48.5     —
AFFECTED
  Product       Versions     Fixed
  Apache OFBiz  unspecified  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 10  Published (CNA: apache)
CWE-94 · CNA: apache · 2 references · NVD status: Analyzed
jelmer dulwich — Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0063   47.5     —
AFFECTED
  Product  Versions              Fixed
  dulwich  >= 0.10.0, < 1.2.5 –  —
TIMELINE
  Apr 26  Reserved by CNA
  Jun 10  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 4 references · NVD status: Deferred
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0062   46.6     —
AFFECTED
  Product  Versions     Fixed
  GIMP     3.2.0-RC1 –  —
TIMELINE
  Feb 6   Reserved by CNA
  Jun 10  Published (CNA: zdi)
CWE-122, CWE-131 · CNA: zdi · 5 references · NVD status: Deferred
Unknown Schema & Structured Data for WP & AMP — Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0057   44.6     —
AFFECTED
  Product                                Versions     Fixed
  Schema & Structured Data for WP & AMP  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 10  Published (CNA: WPScan)
CWE-434 · CNA: WPScan · 1 reference · NVD status: Deferred
php frankenphp — FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0057   44.4     —
AFFECTED
  Product     Versions               Fixed
  frankenphp  >= 1.11.2, < 1.12.3 –  —
TIMELINE
  May 8   Reserved by CNA
  Jun 10  Published (CNA: GitHub_M)
CWE-20, CWE-176, CWE-178 · CNA: GitHub_M · 2 references · NVD status: Deferred
jelmer dulwich — Dulwich Vulnerable to Command Injection via Merge Driver Path
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   H    7.7   .0056   43.7     —
AFFECTED
  Product  Versions              Fixed
  dulwich  >= 0.24.0, < 1.2.5 –  —
TIMELINE
  Apr 28  Reserved by CNA
  Jun 10  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 3 references · NVD status: Deferred
taosdata TDengine — TDengine has an integer underflow in uvConnMayGetUserInfo() allows unauthenticated remote crash (DoS)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0054   42.9     —
AFFECTED
  Product   Versions                 Fixed
  TDengine  >= 3.4.0.0, < 3.4.1.6 –  —
TIMELINE
  Apr 28  Reserved by CNA
  Jun 10  Public exploit reference published
  Jun 10  Published (CNA: GitHub_M)
CWE-191 · CNA: GitHub_M · 2 references · NVD status: Analyzed
mate-desktop atril — PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   A   H   H   H    8.4   .0053   42.3     —
AFFECTED
  Product  Versions    Fixed
  atril    < 1.26.3 –  —
TIMELINE
  May 14  Reserved by CNA
  Jun 10  Published (CNA: GitHub_M)
CWE-77, CWE-88, CWE-829 · CNA: GitHub_M · 21 references · NVD status: Deferred
Dana Powers kafka-python — kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0052   41.6     —
AFFECTED
  Product       Versions     Fixed
  kafka-python  unspecified  —
TIMELINE
  May 29  Reserved by CNA
  Jun 10  Published (CNA: VulnCheck)
CWE-400, CWE-606 · CNA: VulnCheck · 12 references · NVD status: Modified
js-cookie js-cookie — JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0051   41.3     —
AFFECTED
  Product    Versions   Fixed
  js-cookie  < 3.0.7 –  —
TIMELINE
  May 15  Reserved by CNA
  Jun 10  Published (CNA: GitHub_M)
CWE-1321, CWE-915 · CNA: GitHub_M · 12 references · NVD status: Undergoing Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-527508.440.8nationalsecurityagencyghidraCWE-88Ghidra < 12.1- Command Injection via URL Annotation Click
CVE-2026-497598.840.4ErlangOTPCWE-121Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote V…
CVE-2026-450315.340.3ImageMagickImageMagickCWE-400ImageMagick: Policy Bypass in PSD decoder
CVE-2025-62549.840.2AmentoTechDoctreat CoreCWE-269Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation
CVE-2026-467039.639.5boxlite-aiboxliteCWE-22BoxLite: Path Traversal Vulnerability in boxlite Leads to Arbitrary File Writ…
CVE-2026-490697.139.1WPZOOMWPZOOM PortfolioCWE-79WordPress WPZOOM Portfolio plugin <= 1.4.21 - Cross Site Scripting (XSS) vuln…
CVE-2026-262411.338.0QNAP Systems Inc.File Station 5CWE-121File Station 5
CVE-2026-527566.337.8nationalsecurityagencyghidraCWE-22Ghidra < 12.2 - Unauthenticated Path Traversal in Debugger ISF Server
CVE-2025-662816.937.8QNAP Systems Inc.QTSCWE-476QTS, QuTS hero
CVE-2026-527267.537.3jelmerdulwichCWE-22Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.…
CVE-2026-257007.237.2Apache Software FoundationApache AnswerCWE-1259Apache Answer: AdminToken not invalidated after admin deactivation
CVE-2026-262401.336.8QNAP Systems Inc.File Station 5CWE-121File Station 5
CVE-2026-465207.536.7ImageMagickImageMagickCWE-122ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple imag…
CVE-2026-456645.336.7ImageMagickImageMagickCWE-400ImageMagick: Policy Bypass in MNG coder could
CVE-2026-455589.936.5roxy-wiroxy-wiCWE-20Roxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option…
CVE-2026-455417.536.5espressifesp-idfCWE-476ESF-IDF: Remote Null Pointer Dereference in WebSocket Server
CVE-2025-662805.136.3QNAP Systems Inc.QTSCWE-121QTS, QuTS hero
CVE-2025-713298.735.9image-sizeimage-sizeCWE-835image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser
CVE-2025-713308.735.9image-sizeimage-sizeCWE-835image-size 2.0.2 Denial of Service via Malformed ICNS Image Parsing
CVE-2026-262396.335.1QNAP Systems Inc.File Station 5CWE-121File Station 5
CVE-2026-80718.834.5UnknownAnti-Spam by CleanTalk. Spam protectionCWE-79Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated St…
CVE-2026-202545.734.0SplunkSplunk EnterpriseCWE-20Information Disclosure through External Content Restriction Bypass in Splunk …
CVE-2026-473428.833.9Apache Software FoundationApache OFBizCWE-285Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
CVE-2026-291168.732.7DahuaIPC/SD/NVR/XVR/EVS/VTO/VTH/ASI/TPCCWE-617A vulnerability has been found in some Dahua products could allow an unauthen…
CVE-2026-247171.232.4QNAP Systems Inc.QTSCWE-22QTS, QuTS hero
CVE-2026-228991.331.3QNAP Systems Inc.File Station 5CWE-476File Station 5
CVE-2026-247201.331.3QNAP Systems Inc.File Station 5CWE-770File Station 5
CVE-2026-455569.930.4roxy-wiroxy-wiCWE-20Roxy-WI: Authenticated arbitrary file write on every managed load balancer (a…
CVE-2025-593821.230.0QNAP Systems Inc.QTSCWE-472QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)
CVE-2026-466186.929.5fissionfissionCWE-78Fission builder accepts arbitrary buildcmd strings from Environment.spec.buil…
CVE-2026-534374.329.4Jenkins ProjectJenkinsCWE-601Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that…
CVE-2026-291156.929.3DahuaIPC/SDCWE-617A vulnerability has been found in some Dahua products could allow an authenti…
CVE-2026-202565.729.2SplunkSplunk EnterpriseCWE-20Improper Input Validation through Protocol-Relative URL in Classic Dashboards…
CVE-2026-457837.528.5libp2pjs-libp2pCWE-20libp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT …
CVE-2026-488596.328.5ErlangOTPCWE-208SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenti…
CVE-2026-466149.828.4fissionfissionCWE-284Fission router exposes /fission-function/<ns>/<name> on its public listener, …
CVE-2026-534617.528.4ImageMagickImageMagickCWE-787ImageMagick: Out-of-bounds write in ICON decoder due to incorrect loop
CVE-2026-501318.628.1fedify-devfedifyCWE-918Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validateP…
CVE-2026-202555.728.1SplunkSplunk EnterpriseCWE-20Improper Input Validation through Classic Dashboards in Splunk Enterprise
CVE-2026-118846.528.0Red HatRed Hat Directory Server 11CWE-122389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serializ…
CVE-2026-101428.727.8Dana Powerskafka-pythonCWE-789kafka-python prior to 2.3.2 Denial of Service via Protocol Parser Frame Length
CVE-2026-202527.627.7SplunkSplunk EnterpriseCWE-918Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Spl…
CVE-2026-466178.727.6fissionfissionCWE-250Fission runtime pods automount the fission-fetcher service-account token into…
CVE-2026-492187.527.6ImageMagickImageMagickCWE-20ImageMagick: Policy Bypass in DCM decoder could result in image with invalid …
CVE-2026-534607.527.6ImageMagickImageMagickCWE-770ImageMagick: Policy Bypass can trigger out-of-Memory condition
CVE-2026-466128.827.4fissionfissionCWE-306Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all…
CVE-2026-506389.127.3PEVANSMetrics::Any::Adapter::DogStatsdCWE-93Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not prote…
CVE-2026-116045.626.7OpenVPNovpn-dco-winCWE-122An incorrect buffer size calculation in the epoch key generator in OpenVPN ov…
CVE-2026-247246.226.7QNAP Systems Inc.File Station 5CWE-863File Station 5
CVE-2026-488567.126.5ErlangOTPCWE-601httpc leaks Authorization header to cross-origin redirect targets
CVE-2025-628505.126.0QNAP Systems Inc.QuTS heroCWE-476QuTS hero
CVE-2026-247161.226.0QNAP Systems Inc.QTSCWE-476QTS, QuTS hero
CVE-2026-536986.525.6SilverpeasSilverpeasCWE-36Silverpeas through 6.4.6 mishandles the "Personal space" feature that is sele…
CVE-2026-455427.125.3espressifesp-idfCWE-122ESF-IDF: Heap buffer overflow in protocomm Security2 over Bluetooth
CVE-2026-506378.225.1PEVANSMetrics::Any::Adapter::StatsdCWE-93Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect …
CVE-2026-262376.625.0QNAP Systems Inc.QuMagieCWE-862QuMagie
CVE-2026-466898.724.4kanidmkanidmCWE-248Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion
CVE-2026-118155.324.5BroadcomLayer 7 API GatewayCWE-502Insecure Deserialization via MITM in Layer 7 Policy Manager
CVE-2026-455698.124.3roxy-wiroxy-wiCWE-22Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership…
CVE-2026-527588.723.5nationalsecurityagencyghidraCWE-89Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search
CVE-2026-501275.923.4WeblateOrgweblateCWE-918Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b:…
CVE-2026-455648.823.0roxy-wiroxy-wiCWE-78Roxy-WI: Authenticated RCE via 'configver' URL parameter (os.system sink in /…
CVE-2026-455658.123.0roxy-wiroxy-wiCWE-20Roxy-WI: EscapedString validator skips its '..' block when stripping (root ca…
CVE-2026-505677.722.6fissionfissionCWE-22Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outsi…
CVE-2026-465236.222.7ImageMagickImageMagickCWE-416ImageMagick: Use-After-Free in MSL decoder.
CVE-2026-505459.922.5fissionfissionCWE-269Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster …
CVE-2026-534746.522.3migration-plannerCWE-89Migration-planner: second-order sql injection via rvtools upload
CVE-2026-12207.522.2GoogleChromeCWE-362Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker …
CVE-2026-534698.121.9migration-plannerCWE-306Migration-planner: unprotected delete endpoint wipes all tenant data
CVE-2026-88534.421.9websoudanMW WP FormCWE-79MW WP Form <= 5.1.3 - Authenticated (Editor+) Stored Cross-Site Scripting via…
CVE-2026-446938.821.9pi-holeFTLCWE-362Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global S…
CVE-2026-202575.721.8SplunkSplunk EnterpriseCWE-20Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise
CVE-2026-534769.621.7assisted-migration-agentCWE-22Assisted-migration-agent: vddk tarball chained-symlink arbitrary file write
CVE-2026-107406.921.6AWSs2n-quicCWE-770Excessive memory allocation in s2n-quic
CVE-2026-505669.921.5fissionfissionCWE-250Fission: Environment Runtime.Container and Builder.Container SecurityContext …
CVE-2025-662769.221.5QNAP Systems Inc.QTSQTS
CVE-2026-4669510.021.4boxlite-aiboxliteCWE-284BoxLite: Permission Bypass in boxlite Allows Modification of Read-Only Files
CVE-2026-534717.721.1migration-plannerCWE-639Migration-planner: agent api ignores jwt source_id claim
CVE-2026-464972.321.1apifycrawlee-pythonCWE-918SSRF via sitemap-derived URLs in Crawlee for Python
CVE-2026-02748.121.0Palo Alto NetworksCortex XSIAM CommvaultSecurityIQ MarketplaceCWE-1390Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integ…
CVE-2026-534364.320.6Jenkins ProjectJenkinsCWE-601Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that…
CVE-2026-465588.320.5makeplaneplaneCWE-639Plane: Cross-workspace asset authorization bypass lets any authenticated user…
CVE-2026-534708.120.5migration-plannerCWE-639Migration-planner: getsourcedownloadurl missing organization check
CVE-2026-466454.320.4smithyhqsqladminCWE-862SQLAdmin: Authorization Bypass on `ajax_lookup`
CVE-2026-466797.520.2libp2pjs-libp2pCWE-20libp2p: Memory DoS via subscription flood of unique topics
CVE-2026-536936.920.1mispbsimvisCWE-79MISP BSimVis stored cross-site scripting in tag and cluster rendering paths v…
CVE-2026-481085.320.1EugenyrusshCWE-20Russh: SSH identification parsing accepted non-canonical client banners and d…
CVE-2026-488552.320.1ErlangOTPCWE-200SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured
CVE-2026-466682.320.1authzedspicedbCWE-285SpiceDB: Caveat structures with nested lists can result in improper cache reuse
CVE-2026-505639.919.8fissionfissionCWE-269Fission Container Executor Function PodSpec Injection Leading to Node Escape
CVE-2026-505649.919.8fissionfissionCWE-269Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privi…
CVE-2026-505708.519.8fissionfissionCWE-269Fission: Incomplete capability denylist in Environment/Function PodSpec valid…
CVE-2026-118536.519.1DebiandebusineCWE-59Debusine is an integrated solution to build, distribute and maintain a Debian…
CVE-2026-467027.519.0EugenyrusshCWE-770Russh: Post-decompression SSH packet size was not bounded, allowing remote ov…
CVE-2026-481107.519.0EugenyrusshCWE-20Russh: SSH message fields were decoded through allocation-first parsers befor…
CVE-2026-472136.519.0boxlite-aiboxliteCWE-404BoxLite: Timeout Bypass Vulnerability
CVE-2026-455529.918.9roxy-wiroxy-wiCWE-639Roxy-WI: Cross-tenant authorization bypass on /install/* — guest can run Ansi…
CVE-2026-498237.718.5fissionfissionCWE-284Fission: Cross-namespace Package read via unvalidated PackageRef in Function …
CVE-2026-506396.518.4PEVANSMetrics::Any::Adapter::SignalFxCWE-93Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protec…
CVE-2026-466737.518.2EugenyrusshCWE-770Russh: Unchecked CryptoVec allocation and growth handling is reachable from l…
CVE-2026-446927.718.1code16sharpCWE-639Authenticated Sharp users can download unrelated Laravel Storage objects thro…
CVE-2026-02726.018.0Palo Alto NetworksCloud NGFWCWE-863PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface…
CVE-2026-534415.418.0Jenkins ProjectJenkinsCWE-79Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (bo…
CVE-2026-494988.717.7nationalsecurityagencyghidraCWE-89Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescape…
CVE-2025-628514.617.7QNAP Systems Inc.License CenterCWE-22License Center
CVE-2026-118592.017.6Thinkst Applied ResearchCanarytokensCWE-74HTML injection in the Canarytoken links email
CVE-2026-505654.917.3fissionfissionCWE-250Fission builder pods auto-mount the fission-builder ServiceAccount token in t…
CVE-2026-534757.416.9assisted-migration-agentCWE-295Assisted-migration-agent: tls verification disabled on all vcenter connections
CVE-2026-527548.716.8nationalsecurityagencyghidraCWE-347Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthentication…
CVE-2026-466836.916.5KnpLabssnappyCWE-918Snappy: SSRF and local file read via the xsl-style-sheet option
CVE-2026-537387.216.4InisevCopy & Delete PostsCWE-863Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handlin…
CVE-2026-451606.516.1espressifesp-idfCWE-125ESF-IDF: Out-of-bounds Read in lwIP DHCP Server Option Parser
CVE-2026-455678.315.8roxy-wiroxy-wiCWE-287Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /…
CVE-2026-453585.315.4ImageMagickImageMagickCWE-125ImageMagick: Out-of-Bounds Read of a single byte in meta encoder
CVE-2026-534404.315.2Jenkins ProjectJenkinsCWE-601Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "…
CVE-2026-498248.514.8fissionfissionCWE-284Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef…
CVE-2026-202585.414.8SplunkSplunk EnterpriseCWE-79Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise
CVE-2026-488586.314.6ErlangOTPCWE-918ftp client PASV response IP not validated against control peer, enabling SSRF…
CVE-2026-455594.914.6roxy-wiroxy-wiCWE-90Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only)
CVE-2026-534394.314.6Jenkins ProjectJenkinsCWE-862Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earli…
CVE-2026-481076.514.3EugenyrusshCWE-20Russh: Unchecked keyboard-interactive prompt count in client auth path
CVE-2026-498217.714.2fissionfissionCWE-441Fission: Cross-namespace Environment reference in Package allows build-time c…
CVE-2026-498227.714.2fissionfissionCWE-284Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows pers…
CVE-2026-465324.613.8espressifesp-idfCWE-125ESF-IDF: Heap Out-of-Bounds Read in Bluedroid AVRCP Target Parser
CVE-2026-489945.913.7ImageMagickImageMagickCWE-122ImageMagick: Heap Buffer Over-Write in MAT decoder on 32-bit systems
CVE-2026-534625.913.7ImageMagickImageMagickCWE-416ImageMagick: Use-After-Free when allocation in CheckPrimitiveExtent fails
CVE-2026-505694.313.7fissionfissionCWE-20Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl…
CVE-2026-466698.713.5openvm-orgopenvmCWE-20`openvm-pairing` pairing check missing proper subfield check on scaling factor
CVE-2026-02694.613.2Palo Alto NetworksCloud NGFWCWE-754PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
CVE-2026-480113.713.1shopwareshopwareCWE-208Shopware: Timing-attack on admin panel allowing enumeration of administrator …
CVE-2024-219445.313.1AMDAMD EPYC™ 7003 Series ProcessorsCWE-20Improper input validation for DIMM serial presence detect (SPD) metadata coul…
CVE-2026-466426.112.9jgraphdrawioCWE-79draw.io: XSS via crafted cell label when opening a .drawio file
CVE-2026-115964.712.9ConnectWiseScreenConnectCWE-1284In ScreenConnect™ versions prior to 26.2, input validation within the Host Pa…
CVE-2026-455616.512.5roxy-wiroxy-wiCWE-918Roxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metada…
CVE-2026-467055.312.5EugenyrusshCWE-287russh server userauth state is not reset when authentication principal changes
CVE-2026-527528.412.1nationalsecurityagencyghidraCWE-22Ghidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry Names
CVE-2026-527558.412.1nationalsecurityagencyghidraCWE-22Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Import
CVE-2026-534384.311.9Jenkins ProjectJenkinsCWE-862A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earl…
CVE-2026-536344.311.9code16sharpCWE-862Sharp: Missing Authorization Check in Quick Creation Command Endpoints
CVE-2026-536897.111.8sahlberglibnfsCWE-1284libnfs through 6.0.2 before 55c18ea does not validate a string size, leading …
CVE-2026-451064.611.2WeblateOrgweblateCWE-79Weblate: Stored HTML injection in editor search preview
CVE-2026-86136.410.1smubaThemes Addons for ElementorCWE-79aThemes Addons for Elementor <= 1.1.8 - Authenticated (Contributor+) Stored C…
CVE-2026-455498.510.1roxy-wiroxy-wiCWE-862Roxy-WI: Authorization bypass on POST /smon/agent/action/<action> — guest can…
CVE-2026-118526.510.1DebiandebusineCWE-862Debusine is an integrated solution to build, distribute and maintain a Debian…
CVE-2026-02704.810.1Palo Alto NetworksCortex XSOARCWE-22Cortex XSOAR: Path Traversal Vulnerability
CVE-2026-202604.310.0SplunkSplunk SOARCWE-117Log Injection through HTTP Request Paths in Splunk SOAR
CVE-2026-455509.19.7roxy-wiroxy-wiCWE-639Roxy-WI: IDOR on PUT /smon/check — any user can rewrite any tenant's monitori…
CVE-2026-83357.19.6Aix-DBAix-DBCWE-306Missing authentication in Aix-DB
CVE-2026-90196.49.6brechtvdsEasy Image CollageCWE-79Easy Image Collage <= 1.13.6 - Authenticated (Author+) Stored Cross-Site Scri…
CVE-2026-488607.59.5ErlangOTPCWE-863Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peernam…
CVE-2026-534425.38.9Jenkins ProjectJenkinsCWE-311Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets f…
CVE-2026-291142.38.9DahuaIPCCWE-538A vulnerability has been found in some Dahua products. An attacker may obtain…
CVE-2026-202595.58.9SplunkSplunk EnterpriseCWE-284Improper Access Control in Splunk Enterprise
CVE-2026-477345.78.7jelmerdulwichCWE-400Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
CVE-2026-534735.48.6migration-planner-ui-appCWE-79Migration-planner-ui-app: stored xss via javascript: url in agent credential …
CVE-2026-534634.38.6ImageMagickImageMagickCWE-476ImageMagick: Null Pointer Dereference in distort operation when passing incor…
CVE-2026-494974.68.4nationalsecurityagencyghidraCWE-22Ghidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug Fil…
CVE-2026-466166.17.8umbracoUmbraco-CMSCWE-601Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
CVE-2026-455634.37.4roxy-wiroxy-wiCWE-639Roxy-WI: IDOR — any authenticated user can read another user's full action hi…
CVE-2026-424627.06.8fedify-devfedifyCWE-180Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVE-2026-75165.16.8LenovoApplicationCWE-749A vulnerability was identified in the Lenovo Android Application, distributed…
CVE-2026-494966.96.7nationalsecurityagencyghidraCWE-416Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via …
CVE-2026-118377.35.8Red HatRed Hat Enterprise Linux 10CWE-59Ansible-collection-ansible-posix: ansible.posix authorized_key: local privile…
CVE-2026-537375.35.4saas.groupJuicerCWE-79Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response
CVE-2025-584685.15.2QNAP Systems Inc.Notification CenterCWE-352Notification Center
CVE-2025-84446.45.1wealcoderAnimation Addons for Elementor – GSAP Motion Elementor Addons & Website TemplatesCWE-79Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Temp…
CVE-2026-455666.15.0roxy-wiroxy-wiCWE-601Roxy-WI: Open redirect on /login?next= via basic-auth userinfo syntax bypass
CVE-2022-485753.55.0ApplemacOS MontereyCWE-287A person with access to a Mac may be able to bypass Login Window. A consisten…
CVE-2026-466437.54.9KnpLabssnappyCWE-78Snappy: Binary path is never shell-escaped due to an inverted is_executable c…
CVE-2026-494956.74.7nationalsecurityagencyghidraCWE-835Ghidra 10.2 < 12.1 - Denial of Service via Circular Reference in Mach-O Expor…
CVE-2026-527536.74.7nationalsecurityagencyghidraCWE-789Ghidra < 12.0.3 - Out-of-Memory in Rust Symbol Demangler via Malformed Symbol
CVE-2026-527596.74.7GhidraGhidraCWE-789Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mac…
CVE-2026-455606.14.6roxy-wiroxy-wiCWE-79Roxy-WI: Stored XSS in log viewer (wrap_line/highlight_word produce unescaped…
CVE-2026-108468.24.5NLnet LabsldnsCWE-346Insufficient verification that responses belong to a query
CVE-2026-527574.64.2nationalsecurityagencyghidraCWE-416Ghidra < 12.1 - Heap-use-after-free in HighVariable::merge() during decompila…
CVE-2026-537405.13.9YoastYoast Duplicate PostCWE-79Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Re…
CVE-2026-537415.13.9quantumcloudSimple Link DirectoryCWE-79Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option
CVE-2026-537425.13.9quantumcloudSimple Link DirectoryCWE-79Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes
CVE-2026-107218.43.8Concrete CMSConcrete CMSCWE-502Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserializ…
CVE-2026-477123.33.7jelmerdulwichCWE-22Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
CVE-2026-90603.53.7UnknownStore Locator WordPressCWE-79Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style
CVE-2026-497606.93.5ErlangOTPCWE-121Stack Buffer Overflow in ei_s_print_term at Very Large Integer
CVE-2026-466094.63.5umbracoUmbraco-CMSCWE-79Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
CVE-2026-536947.33.3NoMachineNoMachineCWE-88Potential local privileges escalation through argument injection in the nxchm…
CVE-2026-240678.43.2Slate Digital LLCSlate Digital ConnectCWE-367Slate Digital Connect macOS XPC PID validation privilege escalation
CVE-2026-86378.53.0LenovoLanSchool ClassicCWE-427A potential uncontrolled search path vulnerability was reported in the LanSch…
CVE-2026-02661.13.0Palo Alto NetworksCloud NGFWCWE-79PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
CVE-2026-492195.52.9ImageMagickImageMagickCWE-22ImageMagick: Policy Bypass can read disallowed files
CVE-2026-453288.82.7espressifesp-idfCWE-787ESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service Wrappers
CVE-2026-453846.12.6rikyozbit7zCWE-59bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File D…
CVE-2026-240668.42.4Slate Digital LLCSlate Digital ConnectCWE-296Slate Digital Connect macOS XPC certificate validation privilege escalation
CVE-2026-453595.72.4ImageMagickImageMagickCWE-125ImageMagick: Out-of-Bounds Read in connected components when the user supplie…
CVE-2025-102388.42.3LenovoX13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) BIOSCWE-787During an internal security assessment, a potential out-of-bounds write vulne…
CVE-2026-465576.22.2ImageMagickImageMagickCWE-674ImageMagick: Stack overflow in fx operation
CVE-2026-423265.12.2ImageMagickImageMagickCWE-125ImageMagick: Heap Buffer Over-Read in IPTC encoder
CVE-2026-456245.12.2ImageMagickImageMagickCWE-125ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
CVE-2026-97587.32.1SysterelS2OPCCWE-295Improper Certificate Validation in S2OPC
CVE-2026-453296.52.0espressifesp-idfCWE-20ESF-IDF: Out-of-Bounds Read in ESP-TEE Secure Service Wrappers
CVE-2026-465594.01.9ImageMagickImageMagickCWE-193ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder
CVE-2026-453803.61.9rikyozbit7zCWE-22bit7z: Path Traversal via Null Byte Injection from `gcount()` Off-by-One in `…
CVE-2026-505683.61.8fissionfissionCWE-41Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory …
CVE-2026-534656.21.6ImageMagickImageMagickCWE-122ImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame i…
CVE-2026-465215.51.5ImageMagickImageMagickCWE-131ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
CVE-2026-534644.01.5ImageMagickImageMagickCWE-401ImageMagick: Memory Leak in wand option parser when providing invalid arguments
CVE-2026-425587.61.5xibosignagexibo-cmsCWE-79Xibo Vulnerable to Stored XSS and Iframe Sandbox Escape via Data Connector Sc…
CVE-2024-583502.11.5nationalsecurityagencyghidraCWE-758Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Order
CVE-2026-02715.91.4Palo Alto NetworksPrisma Access AgentCWE-732Prisma Access Agent: Local Privilege Escalation by Authorized Users
CVE-2026-471654.11.4ImageMagickImageMagickCWE-200ImageMagick: Information Disclosure in distributed pixel cache server because…
CVE-2026-466548.91.4Plonky3Plonky3CWE-345Plonky3 MultiField32Challenger: transcript malleability and challenge entropy…
CVE-2026-60907.31.4LenovoSmart ConnectCWE-290A potential authentication bypass was reported in Lenovo Smart Connect for Wi…
CVE-2026-487345.51.3ImageMagickImageMagickCWE-674ImageMagick: Stack Overflow in MVG decoder
CVE-2026-116265.41.3BroadcomSymantec Endpoint Protection CleanWipe Removal ToolCWE-250Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Re…
CVE-2026-487245.51.2ImageMagickImageMagickCWE-787ImageMagick: Heap Buffer Underwrite in Floyd-Steinberg depth dithering
CVE-2026-537365.11.2bpluginsEasy Twitter FeedsCWE-352Easy Twitter Feeds before 1.2.13 Cross-Site Request Forgery via duplicate_pos…
CVE-2026-537395.11.2YoastYoast Duplicate PostCWE-352Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_pos…
CVE-2026-02674.41.2Palo Alto NetworksGlobalProtect AppCWE-532GlobalProtect App: Information Exposure Vulnerability on macOS
CVE-2026-90458.51.1LenovoAccessories and Display Manager for EnterpriseCWE-306During an internal security assessment, a potential vulnerability was discove…
CVE-2026-480965.31.0openfgaopenfgaCWE-345OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and…
CVE-2022-267587.10.9ApplemacOS MontereyCWE-362A malicious application may cause unexpected changes in memory shared between…
CVE-2026-02684.40.8Palo Alto NetworksPrisma Access AgentCWE-424Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux
CVE-2026-471665.70.6ImageMagickImageMagickCWE-125ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
CVE-2026-487334.70.6ImageMagickImageMagickCWE-835ImageMagick: Infinite Loop in subimage-search with crafted image
CVE-2026-466924.10.6ImageMagickImageMagickCWE-122ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
CVE-2025-102378.40.1LenovoX13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) BIOSCWE-327During an internal security assessment, a potential vulnerability was discove…
CVE-2026-466934.10.1ImageMagickImageMagickCWE-362ImageMagick: Race Condition in distributed pixel cache server can result in f…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-10 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.