boxscore/security
Thursday, June 11, 2026 · all times UTC← 2026-06-10 · archive · 2026-06-12 →

194 CVEs published June 11, 2026: 20 critical, 96 high, 71 medium, 7 low; 1 in KEV; 14 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 169 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published3056742810612563
KEV catalog size1670

341 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9610628466331212730.37.8.0013-115
google59076466402272217460.88.1.0023+590
microsoft207697524661584378273.97.8.0043+195
red hat39103845446400.07.0.0031+35
apple146101636293711.55.7.0023+1
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
debian220020000.06.5.0023+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161800.04.3.0024+17
cisco316324096956.37.2.0971+3
palo alto networks911017114218.24.8.0022+8
ivanti49230033555.68.8.5187+3
checkpoint3915303111.17.5.0410+3
fortinet28132028337.57.3.0066+2
broadcom2400204250.05.3.0887+2
vmware3301202100.05.4.0031+3
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache568812363724011.17.3.0053+52
gitlab1120041224210.04.8.0024+11
mozilla51134401300.07.5.0032+1
docker250500100.08.8.0021+2
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
adobe1231274467227532.45.5.0021+123
ibm10591328180700.07.5.0028+10
oracle229816404013.48.0.0027+2
progress591710900.07.5.0036+5
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link81103252619.14.2.0059+8
siemens780440100.07.5.0020+7
abb550410000.07.2.0018+5
dahua330111200.06.9.0036+3
hitachi energy020020000.05.7.00140
schneider electric110100100.07.1.0023+1
hikvision01000021100.01.00000
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring6869227391000.06.5.0023+68
sourcecodester3557002433000.02.1.0026+35
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
totolink338026111000.08.9.0191+3

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4399710.0.0098
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
Most disclosures (vendor)
VendorCVEs
google758
linux525
microsoft240
adobe124
red hat76
apache73
spring69
ibm59
sourcecodester57
edimax51
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco9
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven24
Packagist22
PyPI11
npm3
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171667
CVE-2021-27102Accellion2021-11-171667
CVE-2021-27101Accellion2021-11-171667
CVE-2021-27103Accellion2021-11-171667
CVE-2021-21017Adobe2021-11-171667
CVE-2021-28550Adobe2021-11-171667
CVE-2021-42013Apache2021-11-171667
CVE-2021-41773Apache2021-11-171667
CVE-2021-30858Apple2021-11-171667
CVE-2021-30860Apple2021-11-171667

Transactions

EXPLOIT PUBLISHEDCVE-2026-11816 (keras-team/keras). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11945 (DALIBO PostgreSQL Anonymizer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44486 (axios). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44487 (axios). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44488 (axios). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44489 (axios). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44490 (axios). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44492 (axios). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44494 (axios). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44495 (axios). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44496 (axios). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44705 (raszi node-tmp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49982 (raszi node-tmp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5497 (vllm-project/vllm). Public exploit reference added.

DUE DATE PASSEDCVE-2026-45321 (@tanstack arktype-adapter). CISA remediation deadline was June 10, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-48027 (nrwl nx-console). CISA remediation deadline was June 10, 2026; still in catalog.

Yesterday's Results

194 CVEs published. 25 box scores, 169 table rows — nothing truncated.

Ivanti Sentry
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS    %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .9990   100.0   YES
AFFECTED
  Product  Versions     Fixed
  Sentry   unspecified  R10.5.2
TIMELINE
  Jun 1   Reserved by CNA
  Jun 9   Patch available
  Jun 9   Public exploit reference published
  Jun 11  Added to CISA KEV, due Jun 14
  Jun 11  Published (CNA: ivanti)
CWE-78 · CNA: ivanti · 3 references · NVD status: Analyzed · KEV due June 14, 2026
davidanderson UpdraftPlus: WP Backup & Migration Plugin — UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0358   88.4     —
AFFECTED
  Product                                    Versions     Fixed
  UpdraftPlus: WP Backup & Migration Plugin  unspecified  —
TIMELINE
  Jun 3   Reserved by CNA
  Jun 11  Published (CNA: Wordfence)
CWE-347 · CNA: Wordfence · 4 references · NVD status: Deferred
MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0158   73.5     —
AFFECTED
  Product  Versions                Fixed
  server   >= 10.6.1, < 10.6.27 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 11  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 15 references · NVD status: Modified
Beardev JoomSport — WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  L    9.3   .0132   68.5     —
AFFECTED
  Product    Versions  Fixed
  JoomSport  n/a –     5.7.8
TIMELINE
  Apr 29  Reserved by CNA
  Jun 11  Published (CNA: Patchstack)
CWE-89 · CNA: Patchstack · 1 reference · NVD status: Deferred
Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  N    8.7   .0104   61.2     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-441, CWE-1321, CWE-915 · CNA: GitHub_M · 49 references · NVD status: Modified
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0103   60.7     —
AFFECTED
  Product  Versions                          Fixed
  netty    >= 4.2.0.Final, < 4.2.15.Final –  —
TIMELINE
  May 5   Reserved by CNA
  Jun 11  Published (CNA: GitHub_M)
CWE-284, CWE-697, CWE-1287 · CNA: GitHub_M · 21 references · NVD status: Modified
lingdojo kana-dojo — KanaDojo < 0.1.18 Command Injection via patchNotesData.json in release.yml
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   H   H   N    8.5   .0091   57.0     —
AFFECTED
  Product    Versions     Fixed
  kana-dojo  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 11  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Deferred
Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0087   55.8     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-918, CWE-289 · CNA: GitHub_M · 43 references · NVD status: Modified
Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8 — 389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  L  H    7.6   .0080   53.4     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Directory Server 11.5 E4S for RHEL 8                           unspecified  8060020260702180044.0ca98e7e
  Red Hat Directory Server 11.7 E4S for RHEL 8                           unspecified  8080020260702180836.f969626e
  Red Hat Directory Server 11.9 for RHEL 8                               unspecified  8100020260702145313.37ed7c03
  Red Hat Directory Server 12.2 E4S for RHEL 9                           unspecified  9020020260703060155.1674d574
  Red Hat Directory Server 12.4 E4S for RHEL 9                           unspecified  9040020260703055735.1674d574
  Red Hat Enterprise Linux 10                                            unspecified  0:3.2.0-8.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.0.6-19.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.3.11.1-13.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  8100020260626120929.25e700aa
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  8040020260629123121.96015a92
  + 13 more
TIMELINE
  Jun 9   Reserved by CNA
  Jun 11  Published (CNA: redhat)
CWE-190 · CNA: redhat · 20 references · NVD status: Awaiting Analysis
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  L  H    7.7   .0078   52.8     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.15.2 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-94, CWE-1321, CWE-915 · CNA: GitHub_M · 47 references · NVD status: Analyzed
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   N   N    8.2   .0066   48.8     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-201 · CNA: GitHub_M · 48 references · NVD status: Modified
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0066   48.6     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-200, CWE-201 · CNA: GitHub_M · 42 references · NVD status: Modified
Axios: Allocation of Resources Without Limits or Throttling in axios
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0062   46.9     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.7.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · 48 references · NVD status: Modified
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0062   46.9     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-400, CWE-1333 · CNA: GitHub_M · 40 references · NVD status: Modified
MacWarrior clipbucket-v5 — ClipBucket: Remote Play URL Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0060   46.0     —
AFFECTED
  Product        Versions          Fixed
  clipbucket-v5  < 5.5.3 - #140 –  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 11  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 1 reference · NVD status: Deferred
keras-team keras-team/keras — Path Traversal in keras-team/keras
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  N    8.1   .0056   44.2     —
AFFECTED
  Product           Versions       Fixed
  keras-team/keras  unspecified –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: @huntr_ai)
CWE-22 · CNA: @huntr_ai · 6 references · NVD status: Modified
CyberArk Software, a Palo Alto Networks Company PAM Self-Hosted, Privilege Cloud — Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special Elements used in an OS Command
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   L    8.7   .0055   43.5     —
AFFECTED
  Product                           Versions  Fixed
  PAM Self-Hosted, Privilege Cloud  14.0 –    14.0.6
TIMELINE
  May 8   Reserved by CNA
  Jun 11  Published (CNA: palo_alto)
CWE-78 · CNA: palo_alto · 4 references · NVD status: Analyzed
CyberArk Software, a Palo Alto Networks Company Privileged Session Manager, Vault — Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input Validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0054   43.1     —
AFFECTED
  Product                            Versions  Fixed
  Privileged Session Manager, Vault  14.0 –    14.0.5
TIMELINE
  May 8   Reserved by CNA
  Jun 11  Published (CNA: palo_alto)
CWE-22 · CNA: palo_alto · 4 references · NVD status: Analyzed
nesquena hermes-webui — Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   L    9.2   .0054   43.1     —
AFFECTED
  Product       Versions     Fixed
  hermes-webui  unspecified  —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 11  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 5 references · NVD status: Deferred
vllm-project vllm-project/vllm — Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0054   43.1     —
AFFECTED
  Product            Versions       Fixed
  vllm-project/vllm  unspecified –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: @huntr_ai)
CWE-400, CWE-770 · CNA: @huntr_ai · 5 references · NVD status: Modified
Hippoo Hippoo Mobile App for WooCommerce — WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.4     —
AFFECTED
  Product                            Versions  Fixed
  Hippoo Mobile App for WooCommerce  n/a –     1.9.5
TIMELINE
  May 27  Reserved by CNA
  Jun 11  Published (CNA: Patchstack)
CWE-266 · CNA: Patchstack · 1 reference · NVD status: Deferred
CyberArk Software, a Palo Alto Networks Company Conjur Cloud (Edge Finding only) — Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   N    9.1   .0050   40.7     —
AFFECTED
  Product                           Versions  Fixed
  Conjur Cloud (Edge Finding only)  1.0 –     1.8
TIMELINE
  May 8   Reserved by CNA
  Jun 11  Published (CNA: palo_alto)
CWE-284 · CNA: palo_alto · 1 reference · NVD status: Analyzed
raszi node-tmp — tmp: Type-confusion bypass of _assertPath in tmp@0.2.6 allows path traversal via non-string prefix/postfix/template
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  L    8.2   .0050   40.3     —
AFFECTED
  Product   Versions  Fixed
  node-tmp  0.2.6 –   —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-20, CWE-22 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
lingdojo kana-dojo — KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   H   H   N    8.5   .0049   39.8     —
AFFECTED
  Product    Versions     Fixed
  kana-dojo  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 11  Published (CNA: VulnCheck)
CWE-693 · CNA: VulnCheck · 3 references · NVD status: Deferred
TP-Link Systems Inc. Tapo C110 v2 — Authenticated Format String Injection on TP-Link Tapo C110
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   L   N   N   H   H    7.0   .0046   38.3     —
AFFECTED
  Product       Versions     Fixed
  Tapo C110 v2  unspecified  —
TIMELINE
  Apr 13  Reserved by CNA
  Jun 11  Published (CNA: TPLink)
CWE-134 · CNA: TPLink · 4 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-442507.538.1nettynettyCWE-400Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
CVE-2026-448907.538.1nettynettyCWE-400Netty has Unbounded Direct Memory Consumption in its RedisDecoder
CVE-2026-115619.837.3Soagen Informatics Technologies Software and Consulting Inc.ApinizerCWE-917SSTI in Soagen Informatics' Apinizer
CVE-2026-33298.737.3SonatypeNexus Repository ManagerCWE-307Nexus Repository Manager - Improper Restriction of Excessive Authentication A…
CVE-2026-416999.835.8SpringSpring for GraphQLCWE-502Unsafe Deserialization in Spring GraphQL
CVE-2026-538067.734.9OpenClawOpenClawCWE-367OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation
CVE-2026-538107.735.0OpenClawOpenClawCWE-829OpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Run…
CVE-2026-394949.332.1WBW PluginsProduct Filter by WBWCWE-89WordPress Product Filter by WBW plugin <= 3.1.2 - SQL Injection vulnerability
CVE-2026-409998.631.4SpringSpring Web ServicesCWE-918Spring WS SSRF via unvalidated WS-Addressing reply destinations
CVE-2026-537778.631.0PerryTSperryCWE-22Perry < 0.5.1159 Path Traversal via ArtifactReady WebSocket
CVE-2026-465198.830.7Flux159mcp-server-kubernetesCWE-863mcp-server-kubernetes Affected By Tool Access Control Bypass: Presentation-La…
CVE-2026-72507.530.1GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-409975.329.6SpringSpring Web ServicesCWE-209SOAP security faults leak Spring Security account state
CVE-2026-450609.829.5MacWarriorclipbucket-v5CWE-89ClipBucket: Blind SQL Injection in progress_video.php
CVE-2026-451788.429.3CyberArk Software, a Palo Alto Networks CompanyConjur EnterpriseCWE-284Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluste…
CVE-2026-78529.828.9Limatek System Inc.LimRAD NACCWE-434Unrestricted File Upload in Limatek's LimRAD NAC
CVE-2026-447057.728.5raszinode-tmpCWE-22tmp: Path Traversal via unsanitized prefix/postfix enables directory escape
CVE-2026-409988.228.3SpringSpring Web ServicesCWE-611Jaxp13 XPath XXE via StreamSource and SAXSource
CVE-2026-418567.528.2SpringSpring for GraphQLCWE-284Spring GraphQL Annotation Detection Vulnerability
CVE-2026-78708.827.3IBMiCWE-427IBM i is Affected by Privilege Escalation []
CVE-2026-538168.627.3OpenClawOpenClawCWE-862OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node
CVE-2026-118399.926.4Başarsoft Information Technologies Inc.RotabanCWE-434Arbitrary File Upload in Basarsoft's Rotaban
CVE-2026-385819.825.8n/an/aCWE-89SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0…
CVE-2026-537815.325.7steipetesummarizeCWE-770Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download
CVE-2026-471729.525.2duck-organizationquest-botCWE-829Quest Bot: Untrusted pull request code can be built and deployed by privilege…
CVE-2026-471718.825.2duck-organizationquest-botCWE-116Quest Bot: Reminder messages allow stored mass mentions through `@everyone` a…
CVE-2026-15006.524.9GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-471749.523.9duck-organizationduck-siteCWE-829Duck Site: Untrusted pull request code can trigger privileged production depl…
CVE-2026-539018.723.8cerebratecerebrateCWE-20Cerebrate before v1.37 allows mass assignment of record identifiers during ob…
CVE-2026-538077.723.9OpenClawOpenClawCWE-863OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks …
CVE-2026-464898.123.7SolidInvoiceSolidInvoiceCWE-79SolidInvoice: Unrestricted file upload with no MIME validation allows stored …
CVE-2026-538178.723.6OpenClawOpenClawCWE-290OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing
CVE-2026-538117.723.6OpenClawOpenClawCWE-290OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matri…
CVE-2026-454188.823.3MacWarriorclipbucket-v5CWE-89ClipBucket: Blind SQL Injection in subtitle_edit.php
CVE-2026-471898.323.3duck-organizationquest-botCWE-639Quest Bot: AutoMod removal can delete rules from another guild by global rule ID
CVE-2026-528596.922.9vimvimCWE-125Vim: Out-of-bounds Read in Terminal Screen Snapshot
CVE-2026-119864.922.6Red HatRed Hat build of Keycloak 26.6CWE-425Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-u…
CVE-2026-538198.722.3OpenClawOpenClawCWE-426OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace …
CVE-2026-120078.821.2GoogleChromeCWE-416Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 al…
CVE-2026-444908.221.2axiosaxiosCWE-1321Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in ax…
CVE-2026-538148.720.6OpenClawOpenClawCWE-266OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool A…
CVE-2026-120108.319.5GoogleChromeCWE-122Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.1…
CVE-2023-339997.119.6WPVibesWP Mail LogCWE-79WordPress WP Mail Log plugin <= 1.0.2 - Reflected Cross Site Scripting (XSS) …
CVE-2025-463157.519.2ApplemacOSCWE-284A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-472506.118.9Flux159mcp-server-kubernetesCWE-88mcp-server-kubernetes: kubectl-generic flag injection enables Kubernetes bear…
CVE-2026-537826.318.4steipetesummarizeCWE-918Summarize < 0.17.0 SSRF via podcast:transcript URL fetch
CVE-2026-471736.318.2duck-organizationquest-botCWE-116Quest Bot: Ticket reason allows mass-mention injection
CVE-2026-118505.018.0Red HatRed Hat Hardened ImagesCWE-191Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds…
CVE-2026-536618.817.7malach-itboruta-serverCWE-614boruta-server sent sensitive session cookies without the Secure attribute
CVE-2026-458026.017.8SetasignFPDICWE-400FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
CVE-2026-85898.717.3GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-120198.317.0GoogleChromeCWE-787Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior t…
CVE-2026-499496.017.0steipeteCodexBarCWE-522CodexBar < 0.33.0 Credential Leakage via HTTP Redirect
CVE-2026-63384.916.9KongKong Enterprise GatewayCWE-444HTTP request smuggling in Kong Enteprise Gateway
CVE-2026-471818.716.7PenguinModPenguinMod-BackendApiCWE-20PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Acco…
CVE-2026-471765.716.8duck-organizationquest-botCWE-200Quest Bot: Logging module can disclose private-channel message contents to a …
CVE-2026-471775.716.8duck-organizationquest-botCWE-200Quest Bot: Ticket transcripts can disclose private ticket contents to a lower…
CVE-2026-471627.316.7vimvimCWE-74Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted direct…
CVE-2026-100878.716.5GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-77878.116.4IBMLangflow OSSCWE-639Unauthenticated Session History Access via Public Flow Execution
CVE-2026-119457.516.2DALIBOPostgreSQL AnonymizerCWE-89PostgreSQL Anonymizer: SQL injection in the rules import functions
CVE-2026-92046.516.2GitLabGitLabCWE-918Server-Side Request Forgery (SSRF) in GitLab
CVE-2026-538124.916.2OpenClawOpenClawCWE-918OpenClaw < 2026.5.18 - Private-Network Navigation Bypass via Browser Act Inte…
CVE-2026-120088.316.1GoogleChromeCWE-416Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115…
CVE-2026-120098.316.1GoogleChromeCWE-20Insufficient validation of untrusted input in Accessibility in Google Chrome …
CVE-2026-120118.316.1GoogleChromeCWE-416Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115…
CVE-2026-539125.115.6cerebratecerebrateCWE-200Cerebrate self-registration password hash exposure via inbox and audit log views
CVE-2026-471697.515.1duck-organizationquest-botCWE-266Quest Bot: Manage Server users can configure AutoRole to grant Administrator …
CVE-2026-84067.115.1OS4EDopenSIS-ClassicCWE-639openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail
CVE-2026-120266.514.9GoogleChromeCWE-125Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.…
CVE-2026-35533.114.8GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-471752.314.6duck-organizationquest-botCWE-116Quest Bot: Moderation reason fields allow bot-powered `@everyone` / `@here` p…
CVE-2026-471882.314.6duck-organizationquest-botCWE-116Quest Bot: Unban and unwarn reason fields still allow bot-powered mass mentions.
CVE-2026-466977.514.6stefanbohacekfediverse-embeds-wordpress-pluginCWE-918Fediverse Embeds: Unauthenticated SSRF / open proxy via REST media-proxy endp…
CVE-2022-458135.414.0BeRocketAdvanced AJAX Product FiltersCWE-862WordPress Advanced AJAX Product Filters plugin <= 1.6.3.3 - Broken Access Con…
CVE-2025-463085.314.1AppleiOS and iPadOSCWE-284An authorization issue was addressed with improved state management. This iss…
CVE-2026-120168.313.9GoogleChromeCWE-20Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827…
CVE-2026-120238.313.9GoogleChromeCWE-416Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed…
CVE-2026-120288.313.9GoogleChromeCWE-416Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 all…
CVE-2026-409948.214.0SpringSpring Web ServicesCWE-1188Wss4jSecurityInterceptor disables WS-I BSP validation by default
CVE-2026-466985.313.9stefanbohacekfediverse-embeds-wordpress-pluginCWE-918Fediverse Embeds: Public-nonce SSRF via ftf_get_site_info AJAX action
CVE-2026-537026.513.8Red HatRed Hat Enterprise Linux 10CWE-787Gstreamer1-plugins-bad-free: gstreamer: stack buffer overflow in h.265 buffer…
CVE-2026-444895.313.8axiosaxiosCWE-113Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incompl…
CVE-2026-120155.313.6GoogleChromeCWE-416Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a…
CVE-2026-120255.313.6GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-120128.113.4GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an…
CVE-2026-409856.413.4SpringSpring Web FlowCWE-917Data Binding Vulnerability in Spring Web Flow with Unified EL Parser
CVE-2026-120279.613.3GoogleChromeCWE-250Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827…
CVE-2026-120208.813.3GoogleChromeCWE-416Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 al…
CVE-2026-528607.513.2vimvimCWE-94Vim: Arbitrary Code Execution via Python Omni-Completion
CVE-2026-96489.113.1Haskell Programming Languagecrypton-certificateCVE-2026-9648
CVE-2026-410003.713.1SpringSpring Web ServicesCWE-294WSS4J validation does not use configured replay cache
CVE-2026-107334.312.8GitLabGitLabCWE-1021Improper Restriction of Rendered UI Layers or Frames in GitLab
CVE-2026-537235.812.7guzzleguzzle-servicesCWE-20guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injec…
CVE-2026-471637.212.2duck-organizationquest-botCWE-862Quest Bot: Unprivileged users can create and remove AutoMod rules.
CVE-2026-538157.112.1OpenClawOpenClawCWE-862OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions
CVE-2026-96944.311.6GitLabGitLabCWE-153Improper Neutralization of Substitution Characters in GitLab
CVE-2026-409877.111.5SpringSpring IntegrationCWE-22Remote-file synchronizer in Spring Integration writes server-supplied filenam…
CVE-2026-471707.711.3garlic-signagegarlic-hubCWE-918Garlic-Hub: SSRF vulnerability in uploadFromUrl endpoint
CVE-2026-120173.111.3GoogleChromeCWE-20Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78…
CVE-2026-47649.411.1Google CloudDialogflow CXCWE-862Privilege Escalation in Dialogflow CX via Playbook Import
CVE-2026-539116.311.1cerebratecerebrateCWE-639Cerebrate primary key mass assignment in CRUD edit operations allows authenti…
CVE-2026-537016.511.0Red HatRed Hat Enterprise Linux 10CWE-787Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps …
CVE-2026-84648.310.7Neuron SoftGolem OEE MESCWE-22Path traversal in Neuron Soft Golem OEE MES
CVE-2026-528587.310.3vimvimCWE-94Vim: Arbitrary Code Execution via Python Omni-Completion
CVE-2026-409864.810.4SpringSpring Web FlowCWE-79Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
CVE-2026-472386.510.2MacWarriorclipbucket-v5CWE-639ClipBucket: IDOR in videos subtitle editor
CVE-2026-489985.39.9guzzlepsr7CWE-918guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
CVE-2026-500058.39.8BrickcomCubeCWE-1392Brickcom Cameras Use of Default Credentials
CVE-2026-466228.19.7SolidInvoiceSolidInvoiceCWE-312SolidInvoice: API tokens stored as plaintext in the database allowing full cr…
CVE-2026-471576.59.5subzeroidaiograpiCWE-918aiograpi: Unsafe signup challenge path handling
CVE-2026-538086.09.5OpenClawOpenClawCWE-863OpenClaw < 2026.5.6 - Approval Policy Bypass in Skill Workshop Apply Flow
CVE-2026-120298.39.1GoogleChromeCWE-416Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 a…
CVE-2026-120308.39.1GoogleChromeCWE-122Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.11…
CVE-2026-120318.39.1GoogleChromeCWE-693Inappropriate implementation in Views in Google Chrome on Windows prior to 14…
CVE-2026-119566.39.1TwiNgatusCWE-614TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
CVE-2026-492145.38.9guzzlepsr7CWE-20guzzlehttp/psr7 has CRLF Injection via URI Host Component
CVE-2026-417008.18.8SpringSpring for GraphQLCWE-346Cross-Site WebSocket Hijacking in Spring for GraphQL
CVE-2026-120335.38.8GoogleChromeCWE-125Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 a…
CVE-2023-402005.38.8Essential PluginWP Logo Showcase Responsive Slider and CarouselCWE-639WordPress WP Logo Showcase Responsive Slider and Carousel plugin <= 3.6 - Bro…
CVE-2026-28274.78.8100pluginsOpen User Map PROCWE-79Open User Map PRO <= 1.4.31 - Unauthenticated Stored Cross-Site Scripting via…
CVE-2026-120358.88.6GoogleChromeCWE-416Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 a…
CVE-2026-62695.48.6GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2023-329594.38.3Sparkle WPMetroStoreCWE-862WordPress MetroStore theme <= 1.3.2 - Broken Access Control
CVE-2026-62774.38.0GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-120348.37.9GoogleChromeCWE-20Insufficient validation of untrusted input in Linux Toolkit Theming in Google…
CVE-2022-424795.47.5TemplateHouseSoledadCWE-862WordPress Soledad premium theme <= 8.2.5 - Broken Access Control vulnerability
CVE-2023-259695.47.4ThemeHunkContact Form & Lead Form Elementor BuilderCWE-862WordPress Contact Form & Lead Form Elementor Builder plugin <= 1.8.4 - Broken…
CVE-2026-120148.37.2GoogleChromeCWE-416Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an at…
CVE-2026-494824.36.7MacWarriorclipbucket-v5CWE-155ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subt…
CVE-2026-120228.36.3GoogleChromeCWE-362Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed…
CVE-2026-451738.45.8CyberArk Software, a Palo Alto Networks CompanyIdentity Browser ExtensionsCWE-346Idira Identity Browser Extension: Unauthorized Application Interaction via Or…
CVE-2026-120188.85.7GoogleChromeCWE-269Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149…
CVE-2026-120246.55.4GoogleChromeCWE-346Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7…
CVE-2026-69763.75.5GitLabGitLabCWE-639Authorization Bypass Through User-Controlled Key in GitLab
CVE-2026-502458.35.3BrickcomCubeCWE-306Brickcom Cameras Missing Authentication for Critical Function
CVE-2026-120323.15.2GoogleChromeCWE-346Inappropriate implementation in Passwords in Google Chrome on Android prior t…
CVE-2025-432785.54.8ApplemacOSCWE-61This issue was addressed with improved handling of symlinks. This issue is fi…
CVE-2026-40966.14.6IBMDevOps PlanCWE-644A vulnerability has been identified in IBM DevOps Plan that allows a Host Hea…
CVE-2026-409955.44.5SpringSpring Web ServicesCWE-287X.509 authentication bypasses Spring Security account checks
CVE-2022-446304.64.2YITHYITH WooCommerce Product Slider CarouselCWE-352WordPress YITH WooCommerce Product Slider Carousel plugin <= 1.16.0 - Cross-S…
CVE-2026-426537.14.0iova.mihaiSliceWPCWE-79WordPress SliceWP plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability
CVE-2025-242685.53.9ApplemacOSCWE-22A parsing issue in the handling of directory paths was addressed with improve…
CVE-2025-462935.53.9ApplemacOSCWE-59This issue was addressed with improved handling of symlinks. This issue is fi…
CVE-2026-33415.43.6IBMLangflow DesktopCWE-918IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection All…
CVE-2026-471675.13.4vimvimCWE-94Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-de…
CVE-2026-410059.03.1Cloud FoundryUAACWE-347UAA accepts SAML Encrypted Assertions authentication bypass
CVE-2025-463135.53.1ApplemacOSCWE-532A logging issue was addressed with improved data redaction. This issue is fix…
CVE-2026-409964.82.9SpringSpring Web ServicesCWE-327Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
CVE-2026-451758.52.9CyberArk Software, a Palo Alto Networks CompanyIdira Endpoint Privilege ManagerCWE-295Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Va…
CVE-2025-242848.82.8ApplemacOSCWE-693This issue was addressed with improved checks to prevent unauthorized actions…
CVE-2025-304315.52.7ApplemacOSCWE-693The issue was addressed with improved checks. This issue is fixed in macOS Se…
CVE-2026-451748.52.7CyberArk Software, a Palo Alto Networks CompanyIdira Endpoint Privilege ManagerCWE-404Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemo…
CVE-2026-534235.92.7membraneframeworkmembrane_mp4_pluginCWE-770Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_…
CVE-2026-451768.92.6CyberArk Software, a Palo Alto Networks CompanyIdira Endpoint Privilege ManagerCWE-269Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Intern…
CVE-2026-108477.82.5checkpointIdentity AgentCWE-427Local Privilege Escalation vulnerability in Check Point Identity Agent Full f…
CVE-2026-409925.02.5SpringSpring BootCWE-295Mail Auto-Configuration Does Not Enable SSL Hostname Verification
CVE-2025-304595.52.4ApplemacOSCWE-359A privacy issue was addressed by removing the vulnerable code. This issue is …
CVE-2025-241655.52.3ApplemacOSCWE-284A permissions issue was addressed with additional restrictions. This issue is…
CVE-2025-70645.61.9ABBFreelanceCWE-305Freelance Security Lock – Access to Windows OS
CVE-2025-312727.81.8ApplemacOSCWE-269The issue was addressed with improved checks. This issue is fixed in macOS Se…
CVE-2026-538137.31.8OpenClawOpenClawCWE-427OpenClaw < 2026.4.25 - Arbitrary Artifact Loading via Fake Package Root Resol…
CVE-2022-471504.31.7weDevsWooCommerce Conversion TrackingCWE-352WordPress WooCommerce Conversion Tracking plugin <= 2.0.10 - Cross-Site Reque…
CVE-2025-433395.51.6ApplemacOSCWE-284An access issue was addressed with additional sandbox restrictions. This issu…
CVE-2024-321104.31.0Magepeople inc.WpEventlyCWE-352WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= …
CVE-2026-538186.90.8OpenClawOpenClawCWE-862OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback
CVE-2026-410015.30.7SpringSpring BootCWE-377Predictable Temp Directory in Artemis Auto-configuration
CVE-2024-456364.40.7IBMSecurity QRadar EDRCWE-522IBM Security QRadar EDR Software has a vulnerability where user credentials m…
CVE-2026-538094.80.6OpenClawOpenClawCWE-863OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-11 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.