AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .1903 97.1 —
AFFECTED Product Versions Fixed Jenkins unspecified 2.568
TIMELINE Jun 9 Reserved by CNA Jun 10 Published (CNA: jenkins)
250 CVEs published June 10, 2026: 16 critical, 98 high, 116 medium, 20 low; 0 in KEV; 16 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 225 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 2862 | 7234 | 1058 | 2563 |
| KEV catalog size | 1670 | |||
340 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 96 | 1062 | 84 | 663 | 312 | 1 | 27 | 3 | 0.3 | 7.8 | .0013 | -114 |
| 563 | 737 | 65 | 383 | 267 | 19 | 74 | 6 | 0.8 | 8.1 | .0023 | +563 | |
| microsoft | 207 | 697 | 52 | 466 | 158 | 4 | 378 | 27 | 3.9 | 7.8 | .0043 | +195 |
| red hat | 34 | 98 | 8 | 44 | 40 | 6 | 4 | 0 | 0.0 | 7.1 | .0032 | +30 |
| apple | 2 | 49 | 0 | 13 | 27 | 2 | 93 | 7 | 14.3 | 6.2 | .0032 | +2 |
| canonical | 0 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | 0 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| debian | 2 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 6.5 | .0023 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | +17 |
| cisco | 3 | 16 | 3 | 2 | 4 | 0 | 96 | 9 | 56.3 | 7.2 | .0971 | +3 |
| palo alto networks | 9 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | +8 |
| ivanti | 3 | 8 | 1 | 3 | 0 | 0 | 33 | 4 | 50.0 | 8.8 | .4316 | +2 |
| checkpoint | 2 | 8 | 1 | 4 | 3 | 0 | 3 | 1 | 12.5 | 7.5 | .0423 | +2 |
| fortinet | 2 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | +2 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.3 | .0887 | +2 |
| vmware | 3 | 3 | 0 | 1 | 2 | 0 | 21 | 0 | 0.0 | 5.4 | .0031 | +3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 56 | 88 | 12 | 36 | 37 | 2 | 40 | 1 | 1.1 | 7.3 | .0053 | +52 |
| mozilla | 5 | 11 | 3 | 4 | 4 | 0 | 13 | 0 | 0.0 | 7.5 | .0032 | +1 |
| gitlab | 0 | 9 | 0 | 1 | 6 | 0 | 4 | 2 | 22.2 | 4.3 | .0032 | 0 |
| docker | 2 | 5 | 0 | 5 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0021 | +2 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| adobe | 123 | 127 | 4 | 46 | 72 | 2 | 75 | 3 | 2.4 | 5.5 | .0021 | +123 |
| ibm | 5 | 54 | 13 | 26 | 15 | 0 | 7 | 0 | 0.0 | 7.5 | .0031 | +5 |
| oracle | 2 | 29 | 8 | 16 | 4 | 0 | 40 | 1 | 3.4 | 8.0 | .0027 | +2 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +5 |
| solarwinds | 3 | 6 | 1 | 2 | 1 | 0 | 11 | 4 | 66.7 | 7.5 | .3995 | +3 |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | +1 |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 8 | 11 | 0 | 3 | 2 | 5 | 26 | 1 | 9.1 | 4.2 | .0059 | +8 |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 1 | 0 | 0.0 | 7.5 | .0020 | +7 |
| abb | 4 | 4 | 0 | 4 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0024 | +4 |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | +3 |
| hitachi energy | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | 0 |
| schneider electric | 1 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 7.1 | .0023 | +1 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 35 | 57 | 0 | 0 | 24 | 33 | 0 | 0 | 0.0 | 2.1 | .0026 | +35 |
| spring | 53 | 54 | 1 | 21 | 32 | 0 | 0 | 0 | 0.0 | 6.5 | .0025 | +53 |
| edimax | 0 | 51 | 0 | 32 | 0 | 19 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| concrete cms | 2 | 46 | 1 | 11 | 13 | 21 | 0 | 0 | 0.0 | 6.2 | .0015 | +2 |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | 0 |
| helmholz | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| mb connect line | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| totolink | 3 | 38 | 0 | 26 | 1 | 11 | 0 | 0 | 0.0 | 8.9 | .0191 | +3 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2009-3459 | .8658 | 99.7 | — |
| CVE-2025-34291 | .8384 | 99.7 | — |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE-2010-0806 | .8217 | 99.6 | — |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-43997 | 10.0 | .0098 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-44005 | 10.0 | .0083 | |
| CVE-2026-44006 | 10.0 | .0081 |
| Vendor | CVEs |
|---|---|
| 731 | |
| linux | 525 |
| microsoft | 365 |
| adobe | 124 |
| apache | 73 |
| red hat | 71 |
| sourcecodester | 57 |
| ibm | 54 |
| spring | 54 |
| edimax | 51 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 9 |
| apple | 7 |
| 6 | |
| ivanti | 4 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 24 |
| Packagist | 22 |
| PyPI | 11 |
| npm | 3 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1666 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1666 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1666 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1666 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1666 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1666 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1666 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1666 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1666 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1666 |
EXPLOIT PUBLISHED — CVE-2026-1220 (Google Chrome). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42542 (taosdata TDengine). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46558 (makeplane plane). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46642 (jgraph drawio). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49495 (nationalsecurityagency ghidra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49496 (nationalsecurityagency ghidra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49497 (nationalsecurityagency ghidra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52751 (nationalsecurityagency ghidra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52752 (nationalsecurityagency ghidra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52753 (nationalsecurityagency ghidra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52755 (nationalsecurityagency ghidra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52756 (nationalsecurityagency ghidra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52757 (nationalsecurityagency ghidra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52759 (Ghidra). Public exploit reference added.
250 CVEs published. 25 box scores, 225 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .1903 97.1 —
AFFECTED Product Versions Fixed Jenkins unspecified 2.568
TIMELINE Jun 9 Reserved by CNA Jun 10 Published (CNA: jenkins)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .1899 97.1 —
AFFECTED Product Versions Fixed Splunk Enterprise 10.2 – — Splunk Cloud Platform 10.3.2512 – — Splunk Secure Gateway 3.10 – —
TIMELINE Oct 8 Reserved by CNA Jun 10 Published (CNA: cisco)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N N 8.6 .0187 77.5 —
AFFECTED Product Versions Fixed Xstore unspecified —
TIMELINE Feb 27 Reserved by CNA Jun 10 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0185 77.3 —
AFFECTED Product Versions Fixed ImageMagick < 7.1.2-23 – —
TIMELINE May 14 Reserved by CNA Jun 10 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0138 69.8 —
AFFECTED Product Versions Fixed Newsletters unspecified —
TIMELINE Feb 23 Reserved by CNA Jun 10 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 6.1 .0134 68.9 —
AFFECTED Product Versions Fixed Cloud NGFW unspecified All PAN-OS 12.1.0 – 12.1.4-h7 Prisma Access unspecified All
TIMELINE Nov 3 Reserved by CNA Jun 10 Published (CNA: palo_alto)
AV AC PR UI S C I A CVSS EPSS %ile KEV A H N N U H H H 7.5 .0109 62.6 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 10 unspecified 0:107-7.el10_2 Red Hat Enterprise Linux 8 unspecified 0:049-244.git20260529.el8_10 Red Hat Enterprise Linux 9 unspecified 0:057-115.git20260527.el9_8 Red Hat Enterprise Linux 9 unspecified 0:057-115.git20260527.el9_8 Red Hat Hardened Images unspecified 109-6.hum1 Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified — Red Hat OpenShift Container Platform 4 unspecified —
TIMELINE Apr 23 Reserved by CNA Jun 10 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0109 62.5 —
AFFECTED Product Versions Fixed QTS 5.2.0 – — QuTS hero h5.2.0 – —
TIMELINE Jan 13 Reserved by CNA Jun 10 Published (CNA: qnap)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N H N H H H 8.5 .0107 62.0 —
AFFECTED Product Versions Fixed Archer AX12 V1 unspecified — Archer AX18 v1 unspecified — Archer AX17 v1 unspecified — Archer AX1300 v1.6 unspecified —
TIMELINE May 20 Reserved by CNA Jun 10 Published (CNA: TPLink)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0105 61.4 —
AFFECTED Product Versions Fixed QTS 5.2.0 – — QuTS hero h5.2.0 – —
TIMELINE Nov 26 Reserved by CNA Jun 10 Published (CNA: qnap)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0105 61.4 —
AFFECTED Product Versions Fixed QTS 5.2.0 – — QuTS hero h5.2.0 – —
TIMELINE Nov 26 Reserved by CNA Jun 10 Published (CNA: qnap)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L N N 4.3 .0103 60.7 —
AFFECTED Product Versions Fixed yamcs < 5.12.7 – —
TIMELINE Apr 28 Reserved by CNA Jun 10 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 6.1 .0098 59.2 —
AFFECTED Product Versions Fixed QTS 5.2.0 – — QuTS hero h5.2.0 – —
TIMELINE Jan 26 Reserved by CNA Jun 10 Published (CNA: qnap)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L A H H H 7.0 .0094 57.9 —
AFFECTED Product Versions Fixed AWS Cloud Development Kit library unspecified —
TIMELINE Jun 5 Reserved by CNA Jun 10 Published (CNA: AMZN)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A H H H 8.6 .0071 50.5 —
AFFECTED Product Versions Fixed ghidra unspecified 12.1
TIMELINE Jun 8 Reserved by CNA Jun 10 Public exploit reference published Jun 10 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0066 48.5 —
AFFECTED Product Versions Fixed Apache OFBiz unspecified —
TIMELINE Jun 4 Reserved by CNA Jun 10 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0063 47.5 —
AFFECTED Product Versions Fixed dulwich >= 0.10.0, < 1.2.5 – —
TIMELINE Apr 26 Reserved by CNA Jun 10 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L N R U H H H 7.8 .0062 46.6 —
AFFECTED Product Versions Fixed GIMP 3.2.0-RC1 – —
TIMELINE Feb 6 Reserved by CNA Jun 10 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0057 44.6 —
AFFECTED Product Versions Fixed Schema & Structured Data for WP & AMP unspecified —
TIMELINE May 20 Reserved by CNA Jun 10 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0057 44.4 —
AFFECTED Product Versions Fixed frankenphp >= 1.11.2, < 1.12.3 – —
TIMELINE May 8 Reserved by CNA Jun 10 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H H 7.7 .0056 43.7 —
AFFECTED Product Versions Fixed dulwich >= 0.24.0, < 1.2.5 – —
TIMELINE Apr 28 Reserved by CNA Jun 10 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0054 42.9 —
AFFECTED Product Versions Fixed TDengine >= 3.4.0.0, < 3.4.1.6 – —
TIMELINE Apr 28 Reserved by CNA Jun 10 Public exploit reference published Jun 10 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N A H H H 8.4 .0053 42.3 —
AFFECTED Product Versions Fixed atril < 1.26.3 – —
TIMELINE May 14 Reserved by CNA Jun 10 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0052 41.6 —
AFFECTED Product Versions Fixed kafka-python unspecified —
TIMELINE May 29 Reserved by CNA Jun 10 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0051 41.3 —
AFFECTED Product Versions Fixed js-cookie < 3.0.7 – —
TIMELINE May 15 Reserved by CNA Jun 10 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-52750 | 8.4 | 40.8 | nationalsecurityagency | ghidra | CWE-88 | Ghidra < 12.1- Command Injection via URL Annotation Click |
| CVE-2026-49759 | 8.8 | 40.4 | Erlang | OTP | CWE-121 | Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote V… |
| CVE-2026-45031 | 5.3 | 40.3 | ImageMagick | ImageMagick | CWE-400 | ImageMagick: Policy Bypass in PSD decoder |
| CVE-2025-6254 | 9.8 | 40.2 | AmentoTech | Doctreat Core | CWE-269 | Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation |
| CVE-2026-46703 | 9.6 | 39.5 | boxlite-ai | boxlite | CWE-22 | BoxLite: Path Traversal Vulnerability in boxlite Leads to Arbitrary File Writ… |
| CVE-2026-49069 | 7.1 | 39.1 | WPZOOM | WPZOOM Portfolio | CWE-79 | WordPress WPZOOM Portfolio plugin <= 1.4.21 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-26241 | 1.3 | 38.0 | QNAP Systems Inc. | File Station 5 | CWE-121 | File Station 5 |
| CVE-2026-52756 | 6.3 | 37.8 | nationalsecurityagency | ghidra | CWE-22 | Ghidra < 12.2 - Unauthenticated Path Traversal in Debugger ISF Server |
| CVE-2025-66281 | 6.9 | 37.8 | QNAP Systems Inc. | QTS | CWE-476 | QTS, QuTS hero |
| CVE-2026-52726 | 7.5 | 37.3 | jelmer | dulwich | CWE-22 | Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.… |
| CVE-2026-25700 | 7.2 | 37.2 | Apache Software Foundation | Apache Answer | CWE-1259 | Apache Answer: AdminToken not invalidated after admin deactivation |
| CVE-2026-26240 | 1.3 | 36.8 | QNAP Systems Inc. | File Station 5 | CWE-121 | File Station 5 |
| CVE-2026-46520 | 7.5 | 36.7 | ImageMagick | ImageMagick | CWE-122 | ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple imag… |
| CVE-2026-45664 | 5.3 | 36.7 | ImageMagick | ImageMagick | CWE-400 | ImageMagick: Policy Bypass in MNG coder could |
| CVE-2026-45558 | 9.9 | 36.5 | roxy-wi | roxy-wi | CWE-20 | Roxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option… |
| CVE-2026-45541 | 7.5 | 36.5 | espressif | esp-idf | CWE-476 | ESF-IDF: Remote Null Pointer Dereference in WebSocket Server |
| CVE-2025-66280 | 5.1 | 36.3 | QNAP Systems Inc. | QTS | CWE-121 | QTS, QuTS hero |
| CVE-2025-71329 | 8.7 | 35.9 | image-size | image-size | CWE-835 | image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser |
| CVE-2025-71330 | 8.7 | 35.9 | image-size | image-size | CWE-835 | image-size 2.0.2 Denial of Service via Malformed ICNS Image Parsing |
| CVE-2026-26239 | 6.3 | 35.1 | QNAP Systems Inc. | File Station 5 | CWE-121 | File Station 5 |
| CVE-2026-8071 | 8.8 | 34.5 | Unknown | Anti-Spam by CleanTalk. Spam protection | CWE-79 | Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated St… |
| CVE-2026-20254 | 5.7 | 34.0 | Splunk | Splunk Enterprise | CWE-20 | Information Disclosure through External Content Restriction Bypass in Splunk … |
| CVE-2026-47342 | 8.8 | 33.9 | Apache Software Foundation | Apache OFBiz | CWE-285 | Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass |
| CVE-2026-29116 | 8.7 | 32.7 | Dahua | IPC/SD/NVR/XVR/EVS/VTO/VTH/ASI/TPC | CWE-617 | A vulnerability has been found in some Dahua products could allow an unauthen… |
| CVE-2026-24717 | 1.2 | 32.4 | QNAP Systems Inc. | QTS | CWE-22 | QTS, QuTS hero |
| CVE-2026-22899 | 1.3 | 31.3 | QNAP Systems Inc. | File Station 5 | CWE-476 | File Station 5 |
| CVE-2026-24720 | 1.3 | 31.3 | QNAP Systems Inc. | File Station 5 | CWE-770 | File Station 5 |
| CVE-2026-45556 | 9.9 | 30.4 | roxy-wi | roxy-wi | CWE-20 | Roxy-WI: Authenticated arbitrary file write on every managed load balancer (a… |
| CVE-2025-59382 | 1.2 | 30.0 | QNAP Systems Inc. | QTS | CWE-472 | QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) |
| CVE-2026-46618 | 6.9 | 29.5 | fission | fission | CWE-78 | Fission builder accepts arbitrary buildcmd strings from Environment.spec.buil… |
| CVE-2026-53437 | 4.3 | 29.4 | Jenkins Project | Jenkins | CWE-601 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that… |
| CVE-2026-29115 | 6.9 | 29.3 | Dahua | IPC/SD | CWE-617 | A vulnerability has been found in some Dahua products could allow an authenti… |
| CVE-2026-20256 | 5.7 | 29.2 | Splunk | Splunk Enterprise | CWE-20 | Improper Input Validation through Protocol-Relative URL in Classic Dashboards… |
| CVE-2026-45783 | 7.5 | 28.5 | libp2p | js-libp2p | CWE-20 | libp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT … |
| CVE-2026-48859 | 6.3 | 28.5 | Erlang | OTP | CWE-208 | SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenti… |
| CVE-2026-46614 | 9.8 | 28.4 | fission | fission | CWE-284 | Fission router exposes /fission-function/<ns>/<name> on its public listener, … |
| CVE-2026-53461 | 7.5 | 28.4 | ImageMagick | ImageMagick | CWE-787 | ImageMagick: Out-of-bounds write in ICON decoder due to incorrect loop |
| CVE-2026-50131 | 8.6 | 28.1 | fedify-dev | fedify | CWE-918 | Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validateP… |
| CVE-2026-20255 | 5.7 | 28.1 | Splunk | Splunk Enterprise | CWE-20 | Improper Input Validation through Classic Dashboards in Splunk Enterprise |
| CVE-2026-11884 | 6.5 | 28.0 | Red Hat | Red Hat Directory Server 11 | CWE-122 | 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serializ… |
| CVE-2026-10142 | 8.7 | 27.8 | Dana Powers | kafka-python | CWE-789 | kafka-python prior to 2.3.2 Denial of Service via Protocol Parser Frame Length |
| CVE-2026-20252 | 7.6 | 27.7 | Splunk | Splunk Enterprise | CWE-918 | Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Spl… |
| CVE-2026-46617 | 8.7 | 27.6 | fission | fission | CWE-250 | Fission runtime pods automount the fission-fetcher service-account token into… |
| CVE-2026-49218 | 7.5 | 27.6 | ImageMagick | ImageMagick | CWE-20 | ImageMagick: Policy Bypass in DCM decoder could result in image with invalid … |
| CVE-2026-53460 | 7.5 | 27.6 | ImageMagick | ImageMagick | CWE-770 | ImageMagick: Policy Bypass can trigger out-of-Memory condition |
| CVE-2026-46612 | 8.8 | 27.4 | fission | fission | CWE-306 | Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all… |
| CVE-2026-50638 | 9.1 | 27.3 | PEVANS | Metrics::Any::Adapter::DogStatsd | CWE-93 | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not prote… |
| CVE-2026-11604 | 5.6 | 26.7 | OpenVPN | ovpn-dco-win | CWE-122 | An incorrect buffer size calculation in the epoch key generator in OpenVPN ov… |
| CVE-2026-24724 | 6.2 | 26.7 | QNAP Systems Inc. | File Station 5 | CWE-863 | File Station 5 |
| CVE-2026-48856 | 7.1 | 26.5 | Erlang | OTP | CWE-601 | httpc leaks Authorization header to cross-origin redirect targets |
| CVE-2025-62850 | 5.1 | 26.0 | QNAP Systems Inc. | QuTS hero | CWE-476 | QuTS hero |
| CVE-2026-24716 | 1.2 | 26.0 | QNAP Systems Inc. | QTS | CWE-476 | QTS, QuTS hero |
| CVE-2026-53698 | 6.5 | 25.6 | Silverpeas | Silverpeas | CWE-36 | Silverpeas through 6.4.6 mishandles the "Personal space" feature that is sele… |
| CVE-2026-45542 | 7.1 | 25.3 | espressif | esp-idf | CWE-122 | ESF-IDF: Heap buffer overflow in protocomm Security2 over Bluetooth |
| CVE-2026-50637 | 8.2 | 25.1 | PEVANS | Metrics::Any::Adapter::Statsd | CWE-93 | Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect … |
| CVE-2026-26237 | 6.6 | 25.0 | QNAP Systems Inc. | QuMagie | CWE-862 | QuMagie |
| CVE-2026-46689 | 8.7 | 24.4 | kanidm | kanidm | CWE-248 | Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion |
| CVE-2026-11815 | 5.3 | 24.5 | Broadcom | Layer 7 API Gateway | CWE-502 | Insecure Deserialization via MITM in Layer 7 Policy Manager |
| CVE-2026-45569 | 8.1 | 24.3 | roxy-wi | roxy-wi | CWE-22 | Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership… |
| CVE-2026-52758 | 8.7 | 23.5 | nationalsecurityagency | ghidra | CWE-89 | Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search |
| CVE-2026-50127 | 5.9 | 23.4 | WeblateOrg | weblate | CWE-918 | Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b:… |
| CVE-2026-45564 | 8.8 | 23.0 | roxy-wi | roxy-wi | CWE-78 | Roxy-WI: Authenticated RCE via 'configver' URL parameter (os.system sink in /… |
| CVE-2026-45565 | 8.1 | 23.0 | roxy-wi | roxy-wi | CWE-20 | Roxy-WI: EscapedString validator skips its '..' block when stripping (root ca… |
| CVE-2026-50567 | 7.7 | 22.6 | fission | fission | CWE-22 | Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outsi… |
| CVE-2026-46523 | 6.2 | 22.7 | ImageMagick | ImageMagick | CWE-416 | ImageMagick: Use-After-Free in MSL decoder. |
| CVE-2026-50545 | 9.9 | 22.5 | fission | fission | CWE-269 | Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster … |
| CVE-2026-53474 | 6.5 | 22.3 | — | migration-planner | CWE-89 | Migration-planner: second-order sql injection via rvtools upload |
| CVE-2026-1220 | 7.5 | 22.2 | Chrome | CWE-362 | Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker … | |
| CVE-2026-53469 | 8.1 | 21.9 | — | migration-planner | CWE-306 | Migration-planner: unprotected delete endpoint wipes all tenant data |
| CVE-2026-8853 | 4.4 | 21.9 | websoudan | MW WP Form | CWE-79 | MW WP Form <= 5.1.3 - Authenticated (Editor+) Stored Cross-Site Scripting via… |
| CVE-2026-44693 | 8.8 | 21.9 | pi-hole | FTL | CWE-362 | Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global S… |
| CVE-2026-20257 | 5.7 | 21.8 | Splunk | Splunk Enterprise | CWE-20 | Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise |
| CVE-2026-53476 | 9.6 | 21.7 | — | assisted-migration-agent | CWE-22 | Assisted-migration-agent: vddk tarball chained-symlink arbitrary file write |
| CVE-2026-10740 | 6.9 | 21.6 | AWS | s2n-quic | CWE-770 | Excessive memory allocation in s2n-quic |
| CVE-2026-50566 | 9.9 | 21.5 | fission | fission | CWE-250 | Fission: Environment Runtime.Container and Builder.Container SecurityContext … |
| CVE-2025-66276 | 9.2 | 21.5 | QNAP Systems Inc. | QTS | — | QTS |
| CVE-2026-46695 | 10.0 | 21.4 | boxlite-ai | boxlite | CWE-284 | BoxLite: Permission Bypass in boxlite Allows Modification of Read-Only Files |
| CVE-2026-53471 | 7.7 | 21.1 | — | migration-planner | CWE-639 | Migration-planner: agent api ignores jwt source_id claim |
| CVE-2026-46497 | 2.3 | 21.1 | apify | crawlee-python | CWE-918 | SSRF via sitemap-derived URLs in Crawlee for Python |
| CVE-2026-0274 | 8.1 | 21.0 | Palo Alto Networks | Cortex XSIAM CommvaultSecurityIQ Marketplace | CWE-1390 | Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integ… |
| CVE-2026-53436 | 4.3 | 20.6 | Jenkins Project | Jenkins | CWE-601 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that… |
| CVE-2026-46558 | 8.3 | 20.5 | makeplane | plane | CWE-639 | Plane: Cross-workspace asset authorization bypass lets any authenticated user… |
| CVE-2026-53470 | 8.1 | 20.5 | — | migration-planner | CWE-639 | Migration-planner: getsourcedownloadurl missing organization check |
| CVE-2026-46645 | 4.3 | 20.4 | smithyhq | sqladmin | CWE-862 | SQLAdmin: Authorization Bypass on `ajax_lookup` |
| CVE-2026-46679 | 7.5 | 20.2 | libp2p | js-libp2p | CWE-20 | libp2p: Memory DoS via subscription flood of unique topics |
| CVE-2026-53693 | 6.9 | 20.1 | misp | bsimvis | CWE-79 | MISP BSimVis stored cross-site scripting in tag and cluster rendering paths v… |
| CVE-2026-48108 | 5.3 | 20.1 | Eugeny | russh | CWE-20 | Russh: SSH identification parsing accepted non-canonical client banners and d… |
| CVE-2026-48855 | 2.3 | 20.1 | Erlang | OTP | CWE-200 | SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured |
| CVE-2026-46668 | 2.3 | 20.1 | authzed | spicedb | CWE-285 | SpiceDB: Caveat structures with nested lists can result in improper cache reuse |
| CVE-2026-50563 | 9.9 | 19.8 | fission | fission | CWE-269 | Fission Container Executor Function PodSpec Injection Leading to Node Escape |
| CVE-2026-50564 | 9.9 | 19.8 | fission | fission | CWE-269 | Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privi… |
| CVE-2026-50570 | 8.5 | 19.8 | fission | fission | CWE-269 | Fission: Incomplete capability denylist in Environment/Function PodSpec valid… |
| CVE-2026-11853 | 6.5 | 19.1 | Debian | debusine | CWE-59 | Debusine is an integrated solution to build, distribute and maintain a Debian… |
| CVE-2026-46702 | 7.5 | 19.0 | Eugeny | russh | CWE-770 | Russh: Post-decompression SSH packet size was not bounded, allowing remote ov… |
| CVE-2026-48110 | 7.5 | 19.0 | Eugeny | russh | CWE-20 | Russh: SSH message fields were decoded through allocation-first parsers befor… |
| CVE-2026-47213 | 6.5 | 19.0 | boxlite-ai | boxlite | CWE-404 | BoxLite: Timeout Bypass Vulnerability |
| CVE-2026-45552 | 9.9 | 18.9 | roxy-wi | roxy-wi | CWE-639 | Roxy-WI: Cross-tenant authorization bypass on /install/* — guest can run Ansi… |
| CVE-2026-49823 | 7.7 | 18.5 | fission | fission | CWE-284 | Fission: Cross-namespace Package read via unvalidated PackageRef in Function … |
| CVE-2026-50639 | 6.5 | 18.4 | PEVANS | Metrics::Any::Adapter::SignalFx | CWE-93 | Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protec… |
| CVE-2026-46673 | 7.5 | 18.2 | Eugeny | russh | CWE-770 | Russh: Unchecked CryptoVec allocation and growth handling is reachable from l… |
| CVE-2026-44692 | 7.7 | 18.1 | code16 | sharp | CWE-639 | Authenticated Sharp users can download unrelated Laravel Storage objects thro… |
| CVE-2026-0272 | 6.0 | 18.0 | Palo Alto Networks | Cloud NGFW | CWE-863 | PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface… |
| CVE-2026-53441 | 5.4 | 18.0 | Jenkins Project | Jenkins | CWE-79 | Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (bo… |
| CVE-2026-49498 | 8.7 | 17.7 | nationalsecurityagency | ghidra | CWE-89 | Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescape… |
| CVE-2025-62851 | 4.6 | 17.7 | QNAP Systems Inc. | License Center | CWE-22 | License Center |
| CVE-2026-11859 | 2.0 | 17.6 | Thinkst Applied Research | Canarytokens | CWE-74 | HTML injection in the Canarytoken links email |
| CVE-2026-50565 | 4.9 | 17.3 | fission | fission | CWE-250 | Fission builder pods auto-mount the fission-builder ServiceAccount token in t… |
| CVE-2026-53475 | 7.4 | 16.9 | — | assisted-migration-agent | CWE-295 | Assisted-migration-agent: tls verification disabled on all vcenter connections |
| CVE-2026-52754 | 8.7 | 16.8 | nationalsecurityagency | ghidra | CWE-347 | Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthentication… |
| CVE-2026-46683 | 6.9 | 16.5 | KnpLabs | snappy | CWE-918 | Snappy: SSRF and local file read via the xsl-style-sheet option |
| CVE-2026-53738 | 7.2 | 16.4 | Inisev | Copy & Delete Posts | CWE-863 | Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handlin… |
| CVE-2026-45160 | 6.5 | 16.1 | espressif | esp-idf | CWE-125 | ESF-IDF: Out-of-bounds Read in lwIP DHCP Server Option Parser |
| CVE-2026-45567 | 8.3 | 15.8 | roxy-wi | roxy-wi | CWE-287 | Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /… |
| CVE-2026-45358 | 5.3 | 15.4 | ImageMagick | ImageMagick | CWE-125 | ImageMagick: Out-of-Bounds Read of a single byte in meta encoder |
| CVE-2026-53440 | 4.3 | 15.2 | Jenkins Project | Jenkins | CWE-601 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "… |
| CVE-2026-49824 | 8.5 | 14.8 | fission | fission | CWE-284 | Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef… |
| CVE-2026-20258 | 5.4 | 14.8 | Splunk | Splunk Enterprise | CWE-79 | Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise |
| CVE-2026-48858 | 6.3 | 14.6 | Erlang | OTP | CWE-918 | ftp client PASV response IP not validated against control peer, enabling SSRF… |
| CVE-2026-45559 | 4.9 | 14.6 | roxy-wi | roxy-wi | CWE-90 | Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only) |
| CVE-2026-53439 | 4.3 | 14.6 | Jenkins Project | Jenkins | CWE-862 | Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earli… |
| CVE-2026-48107 | 6.5 | 14.3 | Eugeny | russh | CWE-20 | Russh: Unchecked keyboard-interactive prompt count in client auth path |
| CVE-2026-49821 | 7.7 | 14.2 | fission | fission | CWE-441 | Fission: Cross-namespace Environment reference in Package allows build-time c… |
| CVE-2026-49822 | 7.7 | 14.2 | fission | fission | CWE-284 | Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows pers… |
| CVE-2026-46532 | 4.6 | 13.8 | espressif | esp-idf | CWE-125 | ESF-IDF: Heap Out-of-Bounds Read in Bluedroid AVRCP Target Parser |
| CVE-2026-48994 | 5.9 | 13.7 | ImageMagick | ImageMagick | CWE-122 | ImageMagick: Heap Buffer Over-Write in MAT decoder on 32-bit systems |
| CVE-2026-53462 | 5.9 | 13.7 | ImageMagick | ImageMagick | CWE-416 | ImageMagick: Use-After-Free when allocation in CheckPrimitiveExtent fails |
| CVE-2026-50569 | 4.3 | 13.7 | fission | fission | CWE-20 | Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl… |
| CVE-2026-46669 | 8.7 | 13.5 | openvm-org | openvm | CWE-20 | `openvm-pairing` pairing check missing proper subfield check on scaling factor |
| CVE-2026-0269 | 4.6 | 13.2 | Palo Alto Networks | Cloud NGFW | CWE-754 | PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing |
| CVE-2026-48011 | 3.7 | 13.1 | shopware | shopware | CWE-208 | Shopware: Timing-attack on admin panel allowing enumeration of administrator … |
| CVE-2024-21944 | 5.3 | 13.1 | AMD | AMD EPYC™ 7003 Series Processors | CWE-20 | Improper input validation for DIMM serial presence detect (SPD) metadata coul… |
| CVE-2026-46642 | 6.1 | 12.9 | jgraph | drawio | CWE-79 | draw.io: XSS via crafted cell label when opening a .drawio file |
| CVE-2026-11596 | 4.7 | 12.9 | ConnectWise | ScreenConnect | CWE-1284 | In ScreenConnect™ versions prior to 26.2, input validation within the Host Pa… |
| CVE-2026-45561 | 6.5 | 12.5 | roxy-wi | roxy-wi | CWE-918 | Roxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metada… |
| CVE-2026-46705 | 5.3 | 12.5 | Eugeny | russh | CWE-287 | russh server userauth state is not reset when authentication principal changes |
| CVE-2026-52752 | 8.4 | 12.1 | nationalsecurityagency | ghidra | CWE-22 | Ghidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry Names |
| CVE-2026-52755 | 8.4 | 12.1 | nationalsecurityagency | ghidra | CWE-22 | Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Import |
| CVE-2026-53438 | 4.3 | 11.9 | Jenkins Project | Jenkins | CWE-862 | A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earl… |
| CVE-2026-53634 | 4.3 | 11.9 | code16 | sharp | CWE-862 | Sharp: Missing Authorization Check in Quick Creation Command Endpoints |
| CVE-2026-53689 | 7.1 | 11.8 | sahlberg | libnfs | CWE-1284 | libnfs through 6.0.2 before 55c18ea does not validate a string size, leading … |
| CVE-2026-45106 | 4.6 | 11.2 | WeblateOrg | weblate | CWE-79 | Weblate: Stored HTML injection in editor search preview |
| CVE-2026-8613 | 6.4 | 10.1 | smub | aThemes Addons for Elementor | CWE-79 | aThemes Addons for Elementor <= 1.1.8 - Authenticated (Contributor+) Stored C… |
| CVE-2026-45549 | 8.5 | 10.1 | roxy-wi | roxy-wi | CWE-862 | Roxy-WI: Authorization bypass on POST /smon/agent/action/<action> — guest can… |
| CVE-2026-11852 | 6.5 | 10.1 | Debian | debusine | CWE-862 | Debusine is an integrated solution to build, distribute and maintain a Debian… |
| CVE-2026-0270 | 4.8 | 10.1 | Palo Alto Networks | Cortex XSOAR | CWE-22 | Cortex XSOAR: Path Traversal Vulnerability |
| CVE-2026-20260 | 4.3 | 10.0 | Splunk | Splunk SOAR | CWE-117 | Log Injection through HTTP Request Paths in Splunk SOAR |
| CVE-2026-45550 | 9.1 | 9.7 | roxy-wi | roxy-wi | CWE-639 | Roxy-WI: IDOR on PUT /smon/check — any user can rewrite any tenant's monitori… |
| CVE-2026-8335 | 7.1 | 9.6 | Aix-DB | Aix-DB | CWE-306 | Missing authentication in Aix-DB |
| CVE-2026-9019 | 6.4 | 9.6 | brechtvds | Easy Image Collage | CWE-79 | Easy Image Collage <= 1.13.6 - Authenticated (Author+) Stored Cross-Site Scri… |
| CVE-2026-48860 | 7.5 | 9.5 | Erlang | OTP | CWE-863 | Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peernam… |
| CVE-2026-53442 | 5.3 | 8.9 | Jenkins Project | Jenkins | CWE-311 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets f… |
| CVE-2026-29114 | 2.3 | 8.9 | Dahua | IPC | CWE-538 | A vulnerability has been found in some Dahua products. An attacker may obtain… |
| CVE-2026-20259 | 5.5 | 8.9 | Splunk | Splunk Enterprise | CWE-284 | Improper Access Control in Splunk Enterprise |
| CVE-2026-47734 | 5.7 | 8.7 | jelmer | dulwich | CWE-400 | Dulwich has unbounded memory allocation in receive-pack from crafted thin packs |
| CVE-2026-53473 | 5.4 | 8.6 | — | migration-planner-ui-app | CWE-79 | Migration-planner-ui-app: stored xss via javascript: url in agent credential … |
| CVE-2026-53463 | 4.3 | 8.6 | ImageMagick | ImageMagick | CWE-476 | ImageMagick: Null Pointer Dereference in distort operation when passing incor… |
| CVE-2026-49497 | 4.6 | 8.4 | nationalsecurityagency | ghidra | CWE-22 | Ghidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug Fil… |
| CVE-2026-46616 | 6.1 | 7.8 | umbraco | Umbraco-CMS | CWE-601 | Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers |
| CVE-2026-45563 | 4.3 | 7.4 | roxy-wi | roxy-wi | CWE-639 | Roxy-WI: IDOR — any authenticated user can read another user's full action hi… |
| CVE-2026-42462 | 7.0 | 6.8 | fedify-dev | fedify | CWE-180 | Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring |
| CVE-2026-7516 | 5.1 | 6.8 | Lenovo | Application | CWE-749 | A vulnerability was identified in the Lenovo Android Application, distributed… |
| CVE-2026-49496 | 6.9 | 6.7 | nationalsecurityagency | ghidra | CWE-416 | Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via … |
| CVE-2026-11837 | 7.3 | 5.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-59 | Ansible-collection-ansible-posix: ansible.posix authorized_key: local privile… |
| CVE-2026-53737 | 5.3 | 5.4 | saas.group | Juicer | CWE-79 | Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response |
| CVE-2025-58468 | 5.1 | 5.2 | QNAP Systems Inc. | Notification Center | CWE-352 | Notification Center |
| CVE-2025-8444 | 6.4 | 5.1 | wealcoder | Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates | CWE-79 | Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Temp… |
| CVE-2026-45566 | 6.1 | 5.0 | roxy-wi | roxy-wi | CWE-601 | Roxy-WI: Open redirect on /login?next= via basic-auth userinfo syntax bypass |
| CVE-2022-48575 | 3.5 | 5.0 | Apple | macOS Monterey | CWE-287 | A person with access to a Mac may be able to bypass Login Window. A consisten… |
| CVE-2026-46643 | 7.5 | 4.9 | KnpLabs | snappy | CWE-78 | Snappy: Binary path is never shell-escaped due to an inverted is_executable c… |
| CVE-2026-49495 | 6.7 | 4.7 | nationalsecurityagency | ghidra | CWE-835 | Ghidra 10.2 < 12.1 - Denial of Service via Circular Reference in Mach-O Expor… |
| CVE-2026-52753 | 6.7 | 4.7 | nationalsecurityagency | ghidra | CWE-789 | Ghidra < 12.0.3 - Out-of-Memory in Rust Symbol Demangler via Malformed Symbol |
| CVE-2026-52759 | 6.7 | 4.7 | Ghidra | Ghidra | CWE-789 | Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mac… |
| CVE-2026-45560 | 6.1 | 4.6 | roxy-wi | roxy-wi | CWE-79 | Roxy-WI: Stored XSS in log viewer (wrap_line/highlight_word produce unescaped… |
| CVE-2026-10846 | 8.2 | 4.5 | NLnet Labs | ldns | CWE-346 | Insufficient verification that responses belong to a query |
| CVE-2026-52757 | 4.6 | 4.2 | nationalsecurityagency | ghidra | CWE-416 | Ghidra < 12.1 - Heap-use-after-free in HighVariable::merge() during decompila… |
| CVE-2026-53740 | 5.1 | 3.9 | Yoast | Yoast Duplicate Post | CWE-79 | Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Re… |
| CVE-2026-53741 | 5.1 | 3.9 | quantumcloud | Simple Link Directory | CWE-79 | Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option |
| CVE-2026-53742 | 5.1 | 3.9 | quantumcloud | Simple Link Directory | CWE-79 | Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes |
| CVE-2026-10721 | 8.4 | 3.8 | Concrete CMS | Concrete CMS | CWE-502 | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserializ… |
| CVE-2026-47712 | 3.3 | 3.7 | jelmer | dulwich | CWE-22 | Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` |
| CVE-2026-9060 | 3.5 | 3.7 | Unknown | Store Locator WordPress | CWE-79 | Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style |
| CVE-2026-49760 | 6.9 | 3.5 | Erlang | OTP | CWE-121 | Stack Buffer Overflow in ei_s_print_term at Very Large Integer |
| CVE-2026-46609 | 4.6 | 3.5 | umbraco | Umbraco-CMS | CWE-79 | Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog |
| CVE-2026-53694 | 7.3 | 3.3 | NoMachine | NoMachine | CWE-88 | Potential local privileges escalation through argument injection in the nxchm… |
| CVE-2026-24067 | 8.4 | 3.2 | Slate Digital LLC | Slate Digital Connect | CWE-367 | Slate Digital Connect macOS XPC PID validation privilege escalation |
| CVE-2026-8637 | 8.5 | 3.0 | Lenovo | LanSchool Classic | CWE-427 | A potential uncontrolled search path vulnerability was reported in the LanSch… |
| CVE-2026-0266 | 1.1 | 3.0 | Palo Alto Networks | Cloud NGFW | CWE-79 | PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface |
| CVE-2026-49219 | 5.5 | 2.9 | ImageMagick | ImageMagick | CWE-22 | ImageMagick: Policy Bypass can read disallowed files |
| CVE-2026-45328 | 8.8 | 2.7 | espressif | esp-idf | CWE-787 | ESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service Wrappers |
| CVE-2026-45384 | 6.1 | 2.6 | rikyoz | bit7z | CWE-59 | bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File D… |
| CVE-2026-24066 | 8.4 | 2.4 | Slate Digital LLC | Slate Digital Connect | CWE-296 | Slate Digital Connect macOS XPC certificate validation privilege escalation |
| CVE-2026-45359 | 5.7 | 2.4 | ImageMagick | ImageMagick | CWE-125 | ImageMagick: Out-of-Bounds Read in connected components when the user supplie… |
| CVE-2025-10238 | 8.4 | 2.3 | Lenovo | X13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) BIOS | CWE-787 | During an internal security assessment, a potential out-of-bounds write vulne… |
| CVE-2026-46557 | 6.2 | 2.2 | ImageMagick | ImageMagick | CWE-674 | ImageMagick: Stack overflow in fx operation |
| CVE-2026-42326 | 5.1 | 2.2 | ImageMagick | ImageMagick | CWE-125 | ImageMagick: Heap Buffer Over-Read in IPTC encoder |
| CVE-2026-45624 | 5.1 | 2.2 | ImageMagick | ImageMagick | CWE-125 | ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation. |
| CVE-2026-9758 | 7.3 | 2.1 | Systerel | S2OPC | CWE-295 | Improper Certificate Validation in S2OPC |
| CVE-2026-45329 | 6.5 | 2.0 | espressif | esp-idf | CWE-20 | ESF-IDF: Out-of-Bounds Read in ESP-TEE Secure Service Wrappers |
| CVE-2026-46559 | 4.0 | 1.9 | ImageMagick | ImageMagick | CWE-193 | ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder |
| CVE-2026-45380 | 3.6 | 1.9 | rikyoz | bit7z | CWE-22 | bit7z: Path Traversal via Null Byte Injection from `gcount()` Off-by-One in `… |
| CVE-2026-50568 | 3.6 | 1.8 | fission | fission | CWE-41 | Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory … |
| CVE-2026-53465 | 6.2 | 1.6 | ImageMagick | ImageMagick | CWE-122 | ImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame i… |
| CVE-2026-46521 | 5.5 | 1.5 | ImageMagick | ImageMagick | CWE-131 | ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression |
| CVE-2026-53464 | 4.0 | 1.5 | ImageMagick | ImageMagick | CWE-401 | ImageMagick: Memory Leak in wand option parser when providing invalid arguments |
| CVE-2026-42558 | 7.6 | 1.5 | xibosignage | xibo-cms | CWE-79 | Xibo Vulnerable to Stored XSS and Iframe Sandbox Escape via Data Connector Sc… |
| CVE-2024-58350 | 2.1 | 1.5 | nationalsecurityagency | ghidra | CWE-758 | Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Order |
| CVE-2026-0271 | 5.9 | 1.4 | Palo Alto Networks | Prisma Access Agent | CWE-732 | Prisma Access Agent: Local Privilege Escalation by Authorized Users |
| CVE-2026-47165 | 4.1 | 1.4 | ImageMagick | ImageMagick | CWE-200 | ImageMagick: Information Disclosure in distributed pixel cache server because… |
| CVE-2026-46654 | 8.9 | 1.4 | Plonky3 | Plonky3 | CWE-345 | Plonky3 MultiField32Challenger: transcript malleability and challenge entropy… |
| CVE-2026-6090 | 7.3 | 1.4 | Lenovo | Smart Connect | CWE-290 | A potential authentication bypass was reported in Lenovo Smart Connect for Wi… |
| CVE-2026-48734 | 5.5 | 1.3 | ImageMagick | ImageMagick | CWE-674 | ImageMagick: Stack Overflow in MVG decoder |
| CVE-2026-11626 | 5.4 | 1.3 | Broadcom | Symantec Endpoint Protection CleanWipe Removal Tool | CWE-250 | Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Re… |
| CVE-2026-48724 | 5.5 | 1.2 | ImageMagick | ImageMagick | CWE-787 | ImageMagick: Heap Buffer Underwrite in Floyd-Steinberg depth dithering |
| CVE-2026-53736 | 5.1 | 1.2 | bplugins | Easy Twitter Feeds | CWE-352 | Easy Twitter Feeds before 1.2.13 Cross-Site Request Forgery via duplicate_pos… |
| CVE-2026-53739 | 5.1 | 1.2 | Yoast | Yoast Duplicate Post | CWE-352 | Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_pos… |
| CVE-2026-0267 | 4.4 | 1.2 | Palo Alto Networks | GlobalProtect App | CWE-532 | GlobalProtect App: Information Exposure Vulnerability on macOS |
| CVE-2026-9045 | 8.5 | 1.1 | Lenovo | Accessories and Display Manager for Enterprise | CWE-306 | During an internal security assessment, a potential vulnerability was discove… |
| CVE-2026-48096 | 5.3 | 1.0 | openfga | openfga | CWE-345 | OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and… |
| CVE-2022-26758 | 7.1 | 0.9 | Apple | macOS Monterey | CWE-362 | A malicious application may cause unexpected changes in memory shared between… |
| CVE-2026-0268 | 4.4 | 0.8 | Palo Alto Networks | Prisma Access Agent | CWE-424 | Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux |
| CVE-2026-47166 | 5.7 | 0.6 | ImageMagick | ImageMagick | CWE-125 | ImageMagick: Heap Buffer Over-Read in distributed pixel cache server |
| CVE-2026-48733 | 4.7 | 0.6 | ImageMagick | ImageMagick | CWE-835 | ImageMagick: Infinite Loop in subimage-search with crafted image |
| CVE-2026-46692 | 4.1 | 0.6 | ImageMagick | ImageMagick | CWE-122 | ImageMagick: Heap Buffer Over-Write in distributed pixel cache server |
| CVE-2025-10237 | 8.4 | 0.1 | Lenovo | X13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) BIOS | CWE-327 | During an internal security assessment, a potential vulnerability was discove… |
| CVE-2026-46693 | 4.1 | 0.1 | ImageMagick | ImageMagick | CWE-362 | ImageMagick: Race Condition in distributed pixel cache server can result in f… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-10 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.