boxscore/security
Friday, June 12, 2026 · all times UTC← 2026-06-11 · archive · 2026-06-13 →

280 CVEs published June 12, 2026: 34 critical, 111 high, 124 medium, 11 low; 1 in KEV; 20 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 255 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published3336770810612563
KEV catalog size1670

344 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9610628466331212730.37.8.0013-115
google59076466402272217460.88.1.0023+590
microsoft207697524661584378273.97.8.0043+70
red hat40104845456400.07.0.0031+36
apple146101636293711.55.7.0023+1
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
debian220020000.06.5.0023+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161800.04.3.0024+17
cisco316324096956.37.2.0971+3
palo alto networks911017114218.24.8.0022+8
ivanti49230033555.68.8.5187+3
checkpoint3915303111.17.5.0410+3
ubiquiti584400400.08.9.0052+5
fortinet28132028337.57.3.0066+1
broadcom2400204250.05.3.0887+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache679915404124011.07.3.0052+63
gitlab1120041224210.04.8.0024+11
mozilla51134401300.07.5.0032+1
docker250500100.08.8.0021+2
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
adobe1241284477227532.35.5.0021+124
ibm11601329180700.07.5.0028+11
oracle330916404026.78.1.0027+3
progress591710900.07.5.0036+5
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link81103252619.14.2.0059+8
siemens780440100.07.5.0020+6
abb550410000.07.2.0018+5
dahua330111200.06.9.0036+3
hitachi energy020020000.05.7.00140
moxa110100000.07.0.0007+1
schneider electric110100100.07.1.0023+1
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring6869227391000.06.5.0023+68
sourcecodester3557002433000.02.1.0026+35
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
openclaw3440024124000.07.4.0022+34

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2008-4250.987599.9
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-2022310.0.0083
CVE-2026-4714010.0.0082
CVE-2026-4720810.0.0076
Most disclosures (vendor)
VendorCVEs
google758
linux523
microsoft240
adobe125
apache84
red hat77
spring69
ibm60
sourcecodester57
edimax51
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco9
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven35
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171668
CVE-2021-27102Accellion2021-11-171668
CVE-2021-27101Accellion2021-11-171668
CVE-2021-27103Accellion2021-11-171668
CVE-2021-21017Adobe2021-11-171668
CVE-2021-28550Adobe2021-11-171668
CVE-2021-42013Apache2021-11-171668
CVE-2021-41773Apache2021-11-171668
CVE-2021-30858Apple2021-11-171668
CVE-2021-30860Apple2021-11-171668

Transactions

EXPLOIT PUBLISHEDCVE-2026-3840 (kedro-org/kedro). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42850 (kovidgoyal kitty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42851 (kovidgoyal kitty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45669 (nuxt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45670 (nuxt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46690 (spearman unbounded-spsc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47200 (nuxt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48558 (SimpleHelp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49993 (nuxt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50082 (Aqara Cloud Developer Portal). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50083 (Aqara Aquara IAM/SSO Gateway). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50084 (Aqara Cloud Production API). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50085 (Aqara Board service). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50086 (Aqara IAM/SSO Gateway). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50087 (Aqara IAM/SSO Gateway). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50088 (Aqara Developer Portal). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50089 (Aqara IAM/SSO Gateway). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50090 (Aqara Cloud OAuth Authorization Endpoint). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50091 (Aqara com.lumiunited.aqarahome). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54056 (kovidgoyal kitty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54057 (kovidgoyal kitty). Public exploit reference added.

DUE DATE PASSEDCVE-2026-50751 (checkpoint Quantum Security Gateway). CISA remediation deadline was June 11, 2026; still in catalog.

Yesterday's Results

280 CVEs published. 25 box scores, 255 table rows — nothing truncated.

Oracle PeopleSoft Enterprise PeopleTools
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9547   99.9   YES
AFFECTED
  Product                            Versions  Fixed
  PeopleSoft Enterprise PeopleTools  8.61 –    —
TIMELINE
  Apr 1   Reserved by CNA
  Jun 12  Added to CISA KEV, due Jun 15
  Jun 12  Published (CNA: oracle)
CWE-306 · CNA: oracle · 2 references · NVD status: Analyzed · KEV due June 15, 2026
Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0522   91.8     —
AFFECTED
  Product                         Versions     Fixed
  Order Attributes for Magento 2  unspecified  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 12  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 3 references · NVD status: Awaiting Analysis
phpBB phpBB — Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not c…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0386   89.3     —
AFFECTED
  Product  Versions  Fixed
  phpBB    3.3.0 –   —
TIMELINE
  May 22  Reserved by CNA
  Jun 12  Published (CNA: hackerone)
CWE-287 · CNA: hackerone · 1 reference · NVD status: Deferred
nezhahq nezha — Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0185   77.3     —
AFFECTED
  Product  Versions    Fixed
  nezha    < 2.0.13 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 1 reference · NVD status: Deferred
patriksimek vm2 — vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0180   76.6     —
AFFECTED
  Product  Versions    Fixed
  vm2      < 3.11.4 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-913 · CNA: GitHub_M · 3 references · NVD status: Deferred
MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0151   72.2     —
AFFECTED
  Product  Versions                Fixed
  server   >= 10.6.1, < 10.6.27 –  —
TIMELINE
  May 20  Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 13 references · NVD status: Modified
MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   L   L   L    6.3   .0133   68.8     —
AFFECTED
  Product  Versions                Fixed
  server   >= 10.6.1, < 10.6.26 –  —
TIMELINE
  May 5   Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 13 references · NVD status: Modified
Allegra exportReport Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0126   67.1     —
AFFECTED
  Product  Versions    Fixed
  Allegra  8.1.10.5 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 12  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Deferred
OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0098   59.4     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.5.18
TIMELINE
  Jun 10  Reserved by CNA
  Jun 12  Published (CNA: VulnCheck)
CWE-77, CWE-367 · CNA: VulnCheck · 2 references · NVD status: Analyzed
IEI Integration Corp|iVEC-IEI Virtualization Edge Computer - OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0095   58.4     —
AFFECTED
  Product          Versions     Fixed
  iVEC TANK-XM811  unspecified  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 12  Published (CNA: twcert)
CWE-78 · CNA: twcert · 2 references · NVD status: Deferred
MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0091   57.2     —
AFFECTED
  Product  Versions                Fixed
  server   >= 10.6.1, < 10.6.27 –  —
TIMELINE
  May 20  Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 13 references · NVD status: Modified
Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0086   55.5     —
AFFECTED
  Product     Versions  Fixed
  Apache CXF  4.2.0 –   —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 12  Published (CNA: apache)
CWE-20, CWE-502 · CNA: apache · 6 references · NVD status: Modified
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0086   55.4     —
AFFECTED
  Product  Versions                          Fixed
  netty    >= 4.2.0.Final, < 4.2.15.Final –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · 19 references · NVD status: Modified
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0083   54.7     —
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
  Express          unspecified  —
  UDM              unspecified  —
  UDM-Pro          unspecified  —
  UDM-SE           unspecified  —
  UDM-Pro-Max      unspecified  —
  UDM-Beast        unspecified  —
  EFG              unspecified  —
  UDW              unspecified  —
  UDR              unspecified  —
  + 22 more
TIMELINE
  May 19  Reserved by CNA
  Jun 12  Published (CNA: hackerone)
CWE-20 · CNA: hackerone · 1 reference · NVD status: Deferred
Ubiquiti Inc UID Enterprise Agent — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0083   54.4     —
AFFECTED
  Product               Versions     Fixed
  UID Enterprise Agent  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jun 12  Published (CNA: hackerone)
CWE-20 · CNA: hackerone · 1 reference · NVD status: Deferred
Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  U  L  L  N    4.6   .0082   54.2     —
AFFECTED
  Product  Versions    Fixed
  Allegra  8.1.6.22 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 12  Published (CNA: zdi)
CWE-79 · CNA: zdi · 2 references · NVD status: Deferred
patriksimek vm2 — vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0082   54.1     —
AFFECTED
  Product  Versions    Fixed
  vm2      < 3.11.4 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-693 · CNA: GitHub_M · 3 references · NVD status: Deferred
patriksimek vm2 — vm2: Sandbox Breakout Using Promise Species
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0076   52.3     —
AFFECTED
  Product  Versions    Fixed
  vm2      < 3.11.4 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-913 · CNA: GitHub_M · 3 references · NVD status: Deferred
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0074   51.6     —
AFFECTED
  Product  Versions                          Fixed
  netty    >= 4.2.0.Final, < 4.2.15.Final –  —
TIMELINE
  May 20  Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-401, CWE-772 · CNA: GitHub_M · 11 references · NVD status: Modified
Unknown KeepInMind Dashboard Notes — KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   R  C  L  L  L    5.9   .0071   50.4     —
AFFECTED
  Product                     Versions     Fixed
  KeepInMind Dashboard Notes  unspecified  —
TIMELINE
  May 22  Reserved by CNA
  Jun 12  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Deferred
Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   49.9     —
AFFECTED
  Product     Versions  Fixed
  Apache CXF  4.2.0 –   —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 12  Published (CNA: apache)
CWE-20, CWE-358 · CNA: apache · 6 references · NVD status: Modified
Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0065   48.0     —
AFFECTED
  Product     Versions  Fixed
  Apache CXF  4.2.0 –   —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 12  Published (CNA: apache)
CWE-20, CWE-502 · CNA: apache · 5 references · NVD status: Modified
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0063   47.3     —
AFFECTED
  Product  Versions                          Fixed
  netty    >= 4.2.0.Final, < 4.2.15.Final –  —
TIMELINE
  May 20  Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-401, CWE-1286 · CNA: GitHub_M · 18 references · NVD status: Modified
MariaDB: FILE privilege was not checked for subqueries in the FROM clause
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0062   46.8     —
AFFECTED
  Product  Versions                Fixed
  server   >= 10.6.1, < 10.6.26 –  —
TIMELINE
  May 5   Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-863, CWE-266 · CNA: GitHub_M · 13 references · NVD status: Modified
patriksimek vm2 — vm2: Sandbox Escape
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0062   46.8     —
AFFECTED
  Product  Versions    Fixed
  vm2      < 3.11.4 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 12  Published (CNA: GitHub_M)
CWE-913 · CNA: GitHub_M · 3 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-448937.546.7nettynettyCWE-703Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
CVE-2026-480437.546.7nettynettyCWE-400netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFram…
CVE-2026-441726.945.5MariaDBserverCWE-89MariaDB: mysql_real_escape_string() incorrectly handled big5
CVE-2026-441688.045.3MariaDBserverCWE-78MariaDB: wsrep SST unsafe parameter handling on the donor side
CVE-2026-471388.745.2parse-communityparse-serverCWE-1333Parse Server: Pre-authentication denial of service via client version header …
CVE-2026-121438.742.7form-dataform-dataCWE-93form-data does not escape CR/LF/quote in multipart field names and filenames …
CVE-2026-498759.842.2Apache Software FoundationApache CXFCWE-611Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and …
CVE-2026-449909.341.4apostrophecmssanitize-htmlCWE-79Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
CVE-2026-506295.338.7Apache Software FoundationApache CXFCWE-93Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier
CVE-2026-463407.538.1nettynettyCWE-770Netty: SCTP reassembly nests buffers without bound
CVE-2026-500117.538.1nettynettyCWE-400Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array le…
CVE-2026-506457.538.0Apache Software FoundationApache CXFCWE-400Apache CXF: No restriction on attachment headers per message
CVE-2026-500107.537.8nettynettyCWE-347Netty's wrapping plain trust manager silently disables hostname verification
CVE-2026-538368.737.4OpenClawOpenClawCWE-184OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases
CVE-2026-120598.737.4CellopointCelloOSCWE-1284Cellopoint|CelloOS - Improper Access Control
CVE-2026-506279.137.0Apache Software FoundationApache CXFCWE-289Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Toke…
CVE-2026-406777.736.2AMDAMD Management Console (AMC)CWE-1428The use of insecure HTTP transport within AMD optional tools could allow an a…
CVE-2026-467169.935.8nezhahqnezhaCWE-78Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE)…
CVE-2026-428536.535.7apostrophecms@apostrophecms/cliCWE-78@apostrophecms/cli: Command Injection in apos create via Unsanitized Password…
CVE-2026-500859.834.4AqaraBoard serviceCWE-306Aqara Board IoT insecure debug API
CVE-2026-473659.934.1WebProsWordPress-ToolkitCWE-88Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used i…
CVE-2026-118446.933.9IEI Integration CorpiVEC TANK-XM811CWE-22IEI Integration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File Read
CVE-2026-506306.533.6Apache Software FoundationApache CXFCWE-113Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection
CVE-2026-118467.233.3IEI Integration CorpiVEC TANK-XM811CWE-22IEI Integration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File D…
CVE-2026-426046.933.2actualbudgetactualCWE-863Actual has an OpenID `client_secret` Disclosure via Broken Authorization Guar…
CVE-2026-487487.532.4nettynettyCWE-770Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
CVE-2026-119338.731.5MongoDBMongoDBCWE-416Post-authentication use-after-free in server-side JavaScript BSON-to-array co…
CVE-2026-4713710.031.3patriksimekvm2CWE-913vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require …
CVE-2026-543935.130.8mispmispCWE-79MISP Overmind theme stored XSS via unvalidated homepage setting
CVE-2026-538257.130.6OpenClawOpenClawCWE-22OpenClaw < 2026.4.7 - Arbitrary Local File Read via memory-wiki Ingest with o…
CVE-2026-506234.830.2Apache Software FoundationApache CXFCWE-287Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService
CVE-2026-500839.829.5AqaraAquara IAM/SSO GatewayCWE-798Aqara hardcoded OAuth client credentials
CVE-2026-502878.728.9agenticmailagenticmailCWE-306Missing Authentication for Critical Function in @agenticmail/mcp
CVE-2026-411579.828.9Imagination TechnologiesGraphics DDKCWE-787GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D
CVE-2026-473688.628.6Ubiquiti IncUniFi OS ServerCWE-22A malicious actor with access to the network could exploit a Path Traversal v…
CVE-2026-91256.428.62winfactorPresto PlayerCWE-79The Ultimate Video Player For WordPress <= 4.2.0 - Authenticated (Contributor…
CVE-2026-105579.328.4YarboYarbo Android/IOS mobile applicationCWE-798Yarbo Android/iOS Mobile Application and Cloud Infrastructure Use of Hard-cod…
CVE-2026-120438.728.2AWSaws-c-httpCWE-415Heap double-free in AWS Common Runtime aws-c-http
CVE-2026-118499.328.1IEI Integration CorpiRM-TSi410XCWE-798IEI Integration Corp|iRM-IEI Remote Management - Hard-coded Credentials
CVE-2026-451698.728.1CyberArk Software, a Palo Alto Networks CompanyPAM SH VaultCWE-400Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service du…
CVE-2026-68539.827.6Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co.Pause+ Mobile AppCWE-307OTP Bypass in Başbelen Group's Pause+ Mobile App
CVE-2026-458308.827.5ChromaChromaDBCWE-639A lack of authorization validation in version 0.4.17 or later of the ChromaDB…
CVE-2026-500086.927.3parse-communityparse-serverCWE-863Parse Server: Server option routeAllowList is bypassable through batch sub-re…
CVE-2026-458339.427.2ChromaChromaDBCWE-94A code injection vulnerability in version 0.4.17 or later of the ChromaDB Pyt…
CVE-2026-472168.726.5typesensetypesenseCWE-754Typesense: Unauthenticated Denial of Service in the Typesense /multi_search E…
CVE-2026-471904.426.1metal3-ioip-address-managerCWE-250IPAM controller service account granted unnecessary full access to Secrets
CVE-2026-287429.225.9NaxclowSmart Doorbell X3CWE-321Naxclow IoT Platform Use of hard-coded cryptographic key
CVE-2026-539827.125.8Cap-gocapgoCWE-645Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association
CVE-2026-341958.825.7Imagination TechnologiesGraphics DDKCWE-787GPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect p…
CVE-2026-457756.825.1discoursediscourseCWE-22Discourse: Cross-site backup access via path traversal in multisite local bac…
CVE-2026-472607.724.9koelkoelCWE-918Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs
CVE-2026-442076.924.9frappefrappeCWE-639Frappe: Insecure Direct Object Reference for email accounts
CVE-2026-442086.924.9frappefrappeCWE-284Frappe: IDOR in `submit_discussion()`
CVE-2026-541339.824.8jmespathjmespath.phpCWE-20jmespath.php has CompilerRuntime code injection via unescaped function names
CVE-2017-202405.924.7ARODLANDCrypt::PBKDF2CWE-208Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks
CVE-2026-543945.324.7mispmispCWE-22MISP organisation logo path traversal allows retrieval of arbitrary PNG/SVG f…
CVE-2026-4769110.024.5nettynettyCWE-345Netty has Insufficient Bailiwick Validation for NS Records
CVE-2026-120606.924.1Hepta PlatformsHeptabaseCWE-749Hepta Platforms|Heptabase - Exposed Dangerous
CVE-2026-429478.723.9NaxclowSmart Doorbell X3CWE-639Naxclow IoT Platform Authorization bypass through User-Controlled key
CVE-2026-442066.923.8frappefrappeCWE-200Frappe: DB Schema Enumeration via Frappe-Authorization-Source
CVE-2026-73878.823.6MattermostMattermostCWE-863Mattermost group syncable endpoints allow privilege escalation via scheme_admin
CVE-2026-471416.923.4patriksimekvm2CWE-668vm2: NodeVM observability builtins leak host process and HTTP request data
CVE-2026-501088.723.2NaxclowSmart Doorbell X3CWE-862Naxclow IoT Platform Missing Authorization
CVE-2026-69617.623.1MattermostMattermostCWE-22CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost fed…
CVE-2026-96387.523.1ARODLANDCrypt::PBKDF2CWE-338Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random valu…
CVE-2026-473699.922.9Ubiquiti IncUniFi OS ServerCWE-20A malicious actor with access to the network and low privileges could exploit…
CVE-2026-438725.322.9actualbudgetactualCWE-22actual-server has a path traversal vulnerability
CVE-2026-505606.922.7nettynettyCWE-770Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
CVE-2026-473667.222.4phpBBphpBBCWE-284Improper verification of access permissions when modifying permissions throug…
CVE-2026-118487.922.2IEI Integration CorpiRM-TSi410XCWE-306IEI Integration Corp| iRM-IEI Remote Management - Missing Authentication
CVE-2026-537218.821.9nuxtnuxtCWE-178Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-…
CVE-2026-506317.421.9Apache Software FoundationApache CXFCWE-367Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing
CVE-2026-472445.321.7nettynettyCWE-400Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
CVE-2026-472486.921.7parse-communityparse-serverCWE-209Parse Server: GraphQL "Did you mean" validation suggestions disclose schema t…
CVE-2026-500869.821.5AqaraAqara IAM/SSO GatewayCWE-327Aqara unauthenticated AES oracle
CVE-2026-535226.521.5nezhahqnezhaCWE-770Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
CVE-2026-538218.721.4OpenClawOpenClawCWE-862OpenClaw < 2026.5.18 - Scope Elevation in trusted-proxy Control UI WebSocket
CVE-2026-120665.521.3n/aPbootCMSCWE-640PbootCMS Password MemberController.php retrieve password recovery
CVE-2026-118475.321.3IEI Integration CorpiVEC TANK-XM811CWE-22Integration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File Deletion
CVE-2026-472098.621.2patriksimekvm2CWE-693vm2: Bridge Proxy set trap ignores receiver parameter, enabling host object p…
CVE-2026-428507.421.2kovidgoyalkittyCWE-77Kitty has a shell command injection
CVE-2026-500917.421.2Aqaracom.lumiunited.aqarahomeCWE-798Aqara Home Android SDK hardcoded keys
CVE-2026-450145.321.1apostrophecmsapostropheCWE-79Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Dis…
CVE-2026-458328.820.9ChromaChromaDBCWE-639All V1 collection-level endpoints in ChromaDB's Python project pass None for …
CVE-2026-471398.620.7patriksimekvm2CWE-693vm2: NodeVM network builtin exclusions bypass via internal _http_client and _…
CVE-2026-535206.520.7nezhahqnezhaCWE-284Nezha Monitoring: Authenticated users can claim the dashboard Host through NA…
CVE-2026-501019.220.6NaxclowSmart Doorbell X3CWE-262Naxclow IoT Platform Not using password aging
CVE-2026-537242.120.6parse-communityparse-serverCWE-79Parse Server: Stored XSS via trailing-dot filename bypassing file upload exte…
CVE-2026-499935.920.5nuxtnuxtCWE-749@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check b…
CVE-2026-88288.820.4ChromaChromaDBCWE-639A lack of authorization validation in version 1.0.0 or later of the ChromaDB …
CVE-2026-448927.520.4nettynettyCWE-400Netty has a Vulnerable Default Configuration Which Leads to Denial of Service…
CVE-2026-506346.520.3Apache Software FoundationApache CXFCWE-347Apache CXF: WS JSON request filter trusts metadata from an unvalidated first …
CVE-2026-207466.320.2Ping IdentityPingDirectoryCWE-401PingDirectory copying of virtual attributes leads to memory exhaustion
CVE-2026-449755.320.2frappefrappeCWE-862Frappe: Missing authorization on reset form tours
CVE-2026-449765.320.2frappefrappeCWE-284Frappe: IDOR in update_onboarding_step
CVE-2026-471825.320.2frappefrappeCWE-284Frappe: Broken Access Control on Private Files
CVE-2026-537266.920.1parse-communityparse-serverCWE-639Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owni…
CVE-2026-467177.719.2nezhahqnezhaCWE-863Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflectio…
CVE-2026-471246.519.2nezhahqnezhaCWE-200Nezha WebSocket server stream discloses cross-tenant server telemetry to auth…
CVE-2026-48707.519.0IBMQiskit SDKCWE-674Qiskit SDK is vulnerable to specific functions may recurse too deeply and ove…
CVE-2026-540567.119.0kovidgoyalkittyCWE-59Kitty has an arbitrary file overwrite via symlink following in `kitten dnd` r…
CVE-2026-538287.718.9OpenClawOpenClawCWE-863OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command E…
CVE-2026-539817.218.9Cap-goCap-goCWE-306Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism
CVE-2026-471358.718.8patriksimekvm2CWE-693vm2: Sandbox escape via unblocked cross-realm Symbol.for keys + missing bridg…
CVE-2026-481197.118.8nezhahqnezhaCWE-862Nezha Monitoring: Authenticated agents can forge service-monitor results for …
CVE-2026-500825.318.5AqaraCloud Developer PortalCWE-306Aqara Developer Portal insecure authentication token
CVE-2026-538396.018.5OpenClawOpenClawCWE-1023OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoi…
CVE-2026-486108.118.4Ubiquiti IncUDMCWE-284Under certain network configurations, a malicious actor with access to networ…
CVE-2026-120687.418.2Gen DigitalAvira Password ManagerCWE-669Avira Password Manager credential disclosure via cross-origin autofill in Fir…
CVE-2026-543618.818.1mispmispCWE-639MISP mass assignment vulnerabilities allow unauthorized modification of owner…
CVE-2026-471207.118.0nezhahqnezhaCWE-862Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.F…
CVE-2026-500266.917.9frappefrappeCWE-862Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpo…
CVE-2026-73688.617.7YarboYarbo Android/IOS mobile applicationCWE-862Yarbo Android/iOS Mobile Application and Cloud Infrastructure Missing Authori…
CVE-2026-447867.517.7discoursediscourseCWE-200Discourse: Public chat MessageBus broadcasts are not restricted to chat-eligi…
CVE-2026-538688.717.6CapgoCapgoCWE-306Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registratio…
CVE-2026-442056.917.6frappefrappeCWE-79Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload
CVE-2026-477396.917.6frappefrappeCWE-79Frappe: Stored XSS in Note
CVE-2026-535686.917.6frappefrappeCWE-79Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value'
CVE-2026-67397.217.5MattermostMattermostCWE-863Mattermost: Delegated admins could patch protected default system roles
CVE-2026-456736.817.3nettynettyCWE-330Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source …
CVE-2026-543955.317.3mispmispCWE-79MISP UiBeta event index reflected XSS in advanced filter popup
CVE-2026-71846.517.3MattermostMattermostCWE-201Mattermost Remote Cluster PATCH API Leaks Authentication Tokens
CVE-2026-538276.017.1OpenClawOpenClawCWE-918OpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in…
CVE-2026-543575.117.2mispmispCWE-639MISP improper authorization allows organization administrators to modify site…
CVE-2026-493975.317.0nezhahqnezhaCWE-200Nezha Monitoring: Private services (`EnableShowInService: false`) are enumera…
CVE-2026-537255.916.8parse-communityparse-serverCWE-200Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets a…
CVE-2026-484852.116.8duck-organizationquestbotCWE-116Quest Bot: Stored warn reasons can still trigger bot-powered mass mentions th…
CVE-2026-450138.116.6apostrophecmsapostropheCWE-20Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and …
CVE-2026-121312.116.6CodeAstroHuman Resource Management SystemCWE-74CodeAstro Human Resource Management System Payroll Invoice Payroll.php sql in…
CVE-2026-4567410.016.4nettynettyCWE-345Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME…
CVE-2026-543965.316.2mispmispCWE-200MISP AuthKey edit endpoint allows authenticated user email enumeration
CVE-2026-500846.515.9AqaraCloud Production APICWE-862Aqara API cross-account access
CVE-2026-535236.815.2nezhahqnezhaCWE-601Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
CVE-2026-107155.115.1Camaleon CMSCamaleon CMSCWE-862Camaleon CMS 2.9.2 - Improper authorization in draft autosave endpoint
CVE-2026-536099.114.9apostrophecmsapostropheCWE-1321Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch ope…
CVE-2026-458318.814.9ChromaChromaDBCWE-863The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 …
CVE-2026-441694.315.0MariaDBserverCWE-863MariaDB: Authorization bypass in role-based routine-level privilege check exp…
CVE-2026-471968.414.6duck-organizationquestbotCWE-20Quest Bot: Empty automod rule causes every guild message to be deleted
CVE-2026-493475.314.6duck-organizationquestbotCWE-770Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown
CVE-2026-447794.314.7discoursediscourseCWE-200Discourse: Bot debug endpoints disclose whisper translation audit logs
CVE-2026-429326.914.5NaxclowSmart Doorbell X3CWE-340Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
CVE-2026-538298.514.2OpenClawOpenClawCWE-451OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display
CVE-2026-500205.314.3nettynettyCWE-444Netty's HttpObjectDecoder skips arbitrary initial control characters when onl…
CVE-2026-534079.814.1Zoom CommunicationsZoom WorkplaceCWE-939Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace bef…
CVE-2026-447846.514.2discoursediscourseCWE-200Discourse: Non-staff group owners can see email password in plaintext through…
CVE-2026-472006.314.0nuxtnuxtCWE-284Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/…
CVE-2026-538386.014.0OpenClawOpenClawCWE-367OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection
CVE-2026-543587.513.9mispmispCWE-863MISP organization administrators can target site administrator accounts for p…
CVE-2026-471977.213.8duck-organizationquestbotCWE-862Quest Bot: Discord moderation role hierarchy bypass in ban, kick, mute, unmut…
CVE-2026-415816.913.7frappefrappeCWE-89Frappe Vulnerable to Possible SQL Injection via get_blog_list
CVE-2026-535216.413.8nezhahqnezhaCWE-863Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of an…
CVE-2026-500906.113.8AqaraCloud OAuth Authorization EndpointCWE-1289Aqara OAuth redirect_uri validation bypass
CVE-2026-543608.413.5mispmispCWE-639MISP sharing group creation mass assignment allows unauthorized takeover of e…
CVE-2026-543976.113.5mispmispCWE-863MISP event editing allows unauthorized assignment to undisclosed sharing groups
CVE-2026-472256.013.5typesensetypesenseCWE-524Improper Search Cache Isolation for Scoped Search API Keys in Typesense
CVE-2026-96415.313.5ARODLANDCrypt::PBKDF2CWE-916Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm…
CVE-2026-536073.713.6apostrophecmsapostropheCWE-918@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host he…
CVE-2026-502446.912.9NaxclowSmart Doorbell X3CWE-862Naxclow IoT Platform Missing Authorization
CVE-2026-86945.312.9DevolutionsPowerShell UniversalCWE-306Improper access control on the API documentation endpoint in PowerShell Unive…
CVE-2026-543985.312.7mispmispCWE-863MISP object edit authorization bypass allows unauthorized sharing group assig…
CVE-2026-472645.312.3discoursediscourseCWE-200Discourse: Don't leak restricted tag group names via tag info
CVE-2026-471957.112.2duck-organizationquestbotCWE-863Quest Bot: Per-channel permission overwrite bypass in purge and slowmode comm…
CVE-2026-500884.712.2AqaraAqara Developer PortalCWE-942Aqara Developer Portal cross-origin resource sharing
CVE-2026-450855.311.8discoursediscourseCWE-200Discourse: Chat misauthorization and information disclosure
CVE-2026-534088.111.7Zoom CommunicationsZoom WorkplaceCWE-939Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace bef…
CVE-2026-450117.311.6apostrophecmsapostropheCWE-79Apostrophe has stored XSS via javascript: URL in Image Widget Link
CVE-2026-472634.311.6discoursediscourseCWE-200Discourse: Prevent webhook payload disclosure on event redelivery
CVE-2026-62118.711.5Global IT Informatics Services Inc.WEOLLCWE-434Arbitrary File Upload in Global IT's WEOLL
CVE-2026-536088.711.5apostrophecms@apostrophecms/seoCWE-79@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics …
CVE-2026-57926.511.5Hedef Media Promotion Interactive Media Marketing Inc.Related Marketing Cloud (RMC)CWE-290Authentication Bypass in Hedef Media's Related Marketing Cloud (RMC)
CVE-2026-538238.611.3OpenClawOpenClawCWE-290OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in…
CVE-2026-538306.011.0OpenClawOpenClawCWE-613OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload
CVE-2026-543625.311.1mispmispCWE-863MISP template builder exposes non-visible custom galaxies across organisations
CVE-2026-449675.311.0open-telemetryopentelemetry-cppCWE-789opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response
CVE-2026-456705.910.8nuxtnuxtCWE-749Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete…
CVE-2026-500876.110.6AqaraAqara IAM/SSO GatewayCWE-942Aqara IAM/SSO Gateway cross-origin resource sharing
CVE-2026-500094.810.6nettynettyCWE-200Netty QUIC stateless reset token material exposed through header-visible conn…
CVE-2026-121292.010.5CodeAstroHuman Resource Management SystemCWE-79CodeAstro Human Resource Management System Dashboard add_tod cross site scrip…
CVE-2026-121302.010.5CodeAstroHuman Resource Management SystemCWE-79CodeAstro Human Resource Management System Projects Management Add_Projects c…
CVE-2026-538348.210.1OpenClawOpenClawCWE-863OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands
CVE-2026-538317.69.9OpenClawOpenClawCWE-367OpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run …
CVE-2026-537225.19.9nuxtnuxtCWE-79Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
CVE-2026-450127.69.9apostrophecmsapostropheCWE-918Apostrophe has authenticated SSRF in rich-text widget import via @apostrophec…
CVE-2026-500896.19.6AqaraAqara IAM/SSO GatewayCWE-601Aqara IAM/SSO Gateway open redirect
CVE-2026-60465.39.0MattermostMattermostCWE-200Plugin bot username conflict allows user account to be used as bot identity i…
CVE-2026-543597.18.9mispmispCWE-352MISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protecti…
CVE-2026-538376.38.8OpenClawOpenClawCWE-636OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Han…
CVE-2026-447804.38.8discoursediscourseCWE-200Discourse: Category queue reviewers can read raw incoming emails from queued …
CVE-2026-447824.38.8discoursediscourseCWE-200Discourse: GroupPostSerializer leaks hidden full names through reaction post …
CVE-2026-447854.38.8discoursediscourseCWE-200Discourse: Hidden reply-to post raw can be disclosed through AI explain prompts
CVE-2026-472244.38.6M2TeamNanaZipCWE-125NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check
CVE-2026-538262.38.6OpenClawOpenClawCWE-668OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn
CVE-2026-38407.18.4kedro-orgkedro-org/kedroCWE-22Path Traversal in kedro-org/kedro
CVE-2026-538675.38.2CapgoCapgoCWE-459Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement
CVE-2026-472364.38.1solidtime-iosolidtimeCWE-863Solidtime team page exposes pending invitation and member emails to employees…
CVE-2026-472686.48.1nezhahqnezhaCWE-918Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF …
CVE-2026-538246.08.0OpenClawOpenClawCWE-613Mattermost plugin for OpenClaw < 2026.4.24 - Slash Token Revocation Lag via M…
CVE-2026-472235.47.9M2TeamNanaZipCWE-125NanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser vi…
CVE-2026-34334.37.9MattermostMattermostCWE-200Mattermost fails to scope role_updated websocket events to authorized team an…
CVE-2026-538337.47.7OpenClawOpenClawCWE-290QQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Com…
CVE-2026-456695.37.5nuxtnuxtCWE-83Nuxt: Reflected XSS in `navigateTo()` external redirect
CVE-2026-441717.87.2MariaDBserverCWE-22MariaDB: path traversal in mbstream
CVE-2026-246184.37.2HashThemesHash ElementsCWE-497WordPress Hash Elements plugin <= 1.5.4 - Sensitive Data Exposure vulnerability
CVE-2026-500995.16.8NaxclowSmart Doorbell X3CWE-538Naxclow IoT Platform Insertion of sensitive information into Externally-Acces…
CVE-2026-472225.46.7M2TeamNanaZipCWE-125NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser vi…
CVE-2026-120585.36.7vivoPcSuiteCWE-807The connection confirmation pop-up of a specific feature in the PcSuite can b…
CVE-2026-505526.36.6koelkoelCWE-918Koel: Server-Side Request Forgery (SSRF) in radio station creation due to mis…
CVE-2026-540577.36.3kovidgoyalkittyCWE-94Kitty vulnerable to command injection via unsanitized OSC 21 query reply
CVE-2026-538352.36.3OpenClawOpenClawCWE-863OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent…
CVE-2026-428517.86.1kovidgoyalkittyCWE-94@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process…
CVE-2026-489146.75.5qemuCWE-122Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling
CVE-2026-486135.95.2phpBBphpBBCWE-89SQL injection vulnerability in phpBB profile field migration due to improper …
CVE-2026-66894.34.9MattermostMattermostCWE-862*Missing* {{invite_user}} *permission check on team creation allows unprivile…
CVE-2026-115359.44.8vivoPcSuiteCWE-306An unauthorized access vulnerability exists in the PcSuite APP. The vulnerabi…
CVE-2026-479657.84.5AdobeAcrobat ReaderCWE-787Acrobat Reader | Out-of-bounds Write (CWE-787)
CVE-2026-447835.44.5discoursediscourseCWE-284Discourse: Replying to a whisper lets non-whisperers create staff-only whispe…
CVE-2025-70047.84.4Gen DigitalAvast AntivirusCWE-787Avast antivirus heap buffer OOB write when scanning a malformed PE file
CVE-2025-70087.84.4Gen DigitalAvast AntivirusCWE-125Avast antivirus heap buffer OOB read when scanning a malformed PE file
CVE-2025-70097.84.4Gen DigitalAvast AntivirusCWE-125Avast antivirus heap buffer OOB read when scanning a malformed PE file
CVE-2025-70117.84.4Gen DigitalAvast AntivirusCWE-125Avast antivirus heap OOB when scanning a malformed zip file
CVE-2026-92693.54.3UnknownSecure Copy Content Protection and Content LockingSecure Copy Content Protection and Content Locking < 5.1.5 - Admin+ Stored XS…
CVE-2026-448947.54.1nettynettyCWE-940Netty's Default QUIC token handler accepts any client-supplied token
CVE-2026-536065.43.5apostrophecmssanitize-htmlCWE-79sanitize-html has an incomplete URI scheme validation that allows javascript:…
CVE-2026-455364.03.5nettynettyCWE-200Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
CVE-2025-70027.83.2Gen DigitalAvira AntivirusCWE-125Avira antivirus engine heap buffer OOB read when scanning a malformed PDF fil…
CVE-2025-70037.83.2Gen DigitalAvira AntivirusCWE-125Avira antivirus engine heap buffer OOB read when scanning a malformed PDF fil…
CVE-2025-70177.83.2Gen DigitalAvira AntivirusCWE-125Avira antivirus engine heap buffer OOB read when scanning a malformed Windows…
CVE-2026-466905.83.1spearmanunbounded-spscCWE-125unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and f…
CVE-2026-428904.82.7actualbudgetactualCWE-94actual Allows Electron to Run As Node
CVE-2026-493967.12.5nezhahqnezhaCWE-352Nezha Monitoring: Cross-site GET request can trigger stored cron commands on …
CVE-2025-90327.82.4Gen DigitalAvira AntivirusCWE-125Avira antivirus engine heap buffer OOB read when scanning a malformed PE file
CVE-2025-90337.82.3Gen DigitalAvira AntivirusCWE-125Avira antivirus engine heap buffer OOB read when scanning a malformed PDF fil…
CVE-2025-140987.82.3Gen DigitalAvira AntivirusCWE-190Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS…
CVE-2026-66767.82.3Gen DigitalAvira AntivirusCWE-787Avira antivirus engine heap buffer OOB write when scanning a malformed POSIX …
CVE-2026-486128.02.2phpBBphpBBCWE-352Improper state verification in the OAuth implementation could allow an attack…
CVE-2026-411587.82.0Imagination TechnologiesGraphics DDKCWE-416GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after…
CVE-2025-70105.51.6Gen DigitalAvast AntivirusCWE-674Avast antivirus stack overflow when scanning a malformed PDF file
CVE-2025-70195.51.6Gen DigitalAvast AntivirusCWE-121Avast antivirus stack overflow when scanning a malformed Office Open XML file
CVE-2025-70055.51.5Gen DigitalAvast AntivirusCWE-674Avast antivirus infinite recursion when scanning a malformed PE file
CVE-2025-70065.51.5Gen DigitalAvast AntivirusCWE-590Avast antivirus use of stack memory after free when scanning a malformed PE file
CVE-2025-70185.51.5Gen DigitalAvira AntivirusCWE-476Avira antivirus engine null pointer dereference when scanning a malformed PE …
CVE-2026-118798.51.4MobatekMobaXterm Personal Edition (Portable)CWE-427Arbitrary code execution in MobaXterm Personal Edition (Portable)
CVE-2026-119678.51.4MobatekMobaXterm Personal Edition (Portable)CWE-427Arbitrary code execution in MobaXterm Personal Edition (Portable)
CVE-2026-415686.11.4mobymobyCWE-81Moby: Race condition in docker cp allows creation of arbitrary empty files on…
CVE-2026-411555.51.2Imagination TechnologiesGraphics DDKCWE-653GPU DDK - SharedSecMem mapped into all GPU virtual address spaces
CVE-2026-120650.31.2GrowwStock, Mutual Fund, Gold AppCWE-285Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in hand…
CVE-2026-451707.51.2CyberArk Software, a Palo Alto Networks CompanyVendor PAMCWE-295Idira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to In…
CVE-2026-18365.31.2RedmineRedmineCWE-257Stored credentials in Redmine
CVE-2026-423067.21.2mobymobyCWE-61Moby: Race condition in docker cp allows bind mount redirection to host path
CVE-2026-538327.41.1OpenClawOpenClawCWE-290OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration
CVE-2026-538206.90.7OpenClawOpenClawCWE-862OpenClaw < 2026.5.12 - Exec Denylist Bypass in Bundle MCP Loopback Session Spawn
CVE-2026-463422.30.6nuxtnuxtCWE-79Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enab…
CVE-2026-534067.80.2Zoom CommunicationsRemote Control for Zoom Contact CenterCWE-345Insufficient Verification of Data Authenticity in Remote Control for Zoom Con…
CVE-2026-540555.00.1kovidgoyalkittyCWE-59Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmis…
CVE-2026-92667.00.0MoxaUC-1200A SeriesCWE-325A Missing Required Cryptographic Step vulnerability has been identified in Mo…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-12 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.