AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9547 99.9 YES
AFFECTED Product Versions Fixed PeopleSoft Enterprise PeopleTools 8.61 – —
TIMELINE Apr 1 Reserved by CNA Jun 12 Added to CISA KEV, due Jun 15 Jun 12 Published (CNA: oracle)
280 CVEs published June 12, 2026: 34 critical, 111 high, 124 medium, 11 low; 1 in KEV; 20 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 255 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 3336 | 7708 | 1061 | 2563 |
| KEV catalog size | 1670 | |||
344 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 96 | 1062 | 84 | 663 | 312 | 1 | 27 | 3 | 0.3 | 7.8 | .0013 | -115 |
| 590 | 764 | 66 | 402 | 272 | 21 | 74 | 6 | 0.8 | 8.1 | .0023 | +590 | |
| microsoft | 207 | 697 | 52 | 466 | 158 | 4 | 378 | 27 | 3.9 | 7.8 | .0043 | +70 |
| red hat | 40 | 104 | 8 | 45 | 45 | 6 | 4 | 0 | 0.0 | 7.0 | .0031 | +36 |
| apple | 14 | 61 | 0 | 16 | 36 | 2 | 93 | 7 | 11.5 | 5.7 | .0023 | +1 |
| canonical | 0 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | 0 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| debian | 2 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 6.5 | .0023 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | +17 |
| cisco | 3 | 16 | 3 | 2 | 4 | 0 | 96 | 9 | 56.3 | 7.2 | .0971 | +3 |
| palo alto networks | 9 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | +8 |
| ivanti | 4 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | +3 |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 |
| ubiquiti | 5 | 8 | 4 | 4 | 0 | 0 | 4 | 0 | 0.0 | 8.9 | .0052 | +5 |
| fortinet | 2 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | +1 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.3 | .0887 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 67 | 99 | 15 | 40 | 41 | 2 | 40 | 1 | 1.0 | 7.3 | .0052 | +63 |
| gitlab | 11 | 20 | 0 | 4 | 12 | 2 | 4 | 2 | 10.0 | 4.8 | .0024 | +11 |
| mozilla | 5 | 11 | 3 | 4 | 4 | 0 | 13 | 0 | 0.0 | 7.5 | .0032 | +1 |
| docker | 2 | 5 | 0 | 5 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0021 | +2 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| adobe | 124 | 128 | 4 | 47 | 72 | 2 | 75 | 3 | 2.3 | 5.5 | .0021 | +124 |
| ibm | 11 | 60 | 13 | 29 | 18 | 0 | 7 | 0 | 0.0 | 7.5 | .0028 | +11 |
| oracle | 3 | 30 | 9 | 16 | 4 | 0 | 40 | 2 | 6.7 | 8.1 | .0027 | +3 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +5 |
| solarwinds | 3 | 6 | 1 | 2 | 1 | 0 | 11 | 4 | 66.7 | 7.5 | .3995 | +3 |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | +1 |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 8 | 11 | 0 | 3 | 2 | 5 | 26 | 1 | 9.1 | 4.2 | .0059 | +8 |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 1 | 0 | 0.0 | 7.5 | .0020 | +6 |
| abb | 5 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +5 |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | +3 |
| hitachi energy | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | 0 |
| moxa | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.0 | .0007 | +1 |
| schneider electric | 1 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 7.1 | .0023 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 68 | 69 | 2 | 27 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0023 | +68 |
| sourcecodester | 35 | 57 | 0 | 0 | 24 | 33 | 0 | 0 | 0.0 | 2.1 | .0026 | +35 |
| edimax | 0 | 51 | 0 | 32 | 0 | 19 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| concrete cms | 2 | 46 | 1 | 11 | 13 | 21 | 0 | 0 | 0.0 | 6.2 | .0015 | +2 |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | 0 |
| helmholz | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| mb connect line | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| openclaw | 34 | 40 | 0 | 24 | 12 | 4 | 0 | 0 | 0.0 | 7.4 | .0022 | +34 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2009-3459 | .8658 | 99.7 | — |
| CVE-2025-34291 | .8384 | 99.7 | — |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-47140 | 10.0 | .0082 | |
| CVE-2026-47208 | 10.0 | .0076 |
| Vendor | CVEs |
|---|---|
| 758 | |
| linux | 523 |
| microsoft | 240 |
| adobe | 125 |
| apache | 84 |
| red hat | 77 |
| spring | 69 |
| ibm | 60 |
| sourcecodester | 57 |
| edimax | 51 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 9 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 35 |
| Packagist | 22 |
| PyPI | 11 |
| npm | 4 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1668 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1668 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1668 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1668 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1668 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1668 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1668 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1668 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1668 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1668 |
EXPLOIT PUBLISHED — CVE-2026-3840 (kedro-org/kedro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42850 (kovidgoyal kitty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42851 (kovidgoyal kitty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45669 (nuxt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45670 (nuxt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46690 (spearman unbounded-spsc). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47200 (nuxt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48558 (SimpleHelp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49993 (nuxt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50082 (Aqara Cloud Developer Portal). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50083 (Aqara Aquara IAM/SSO Gateway). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50084 (Aqara Cloud Production API). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50085 (Aqara Board service). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50086 (Aqara IAM/SSO Gateway). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50087 (Aqara IAM/SSO Gateway). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50088 (Aqara Developer Portal). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50089 (Aqara IAM/SSO Gateway). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50090 (Aqara Cloud OAuth Authorization Endpoint). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50091 (Aqara com.lumiunited.aqarahome). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54056 (kovidgoyal kitty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54057 (kovidgoyal kitty). Public exploit reference added.
DUE DATE PASSED — CVE-2026-50751 (checkpoint Quantum Security Gateway). CISA remediation deadline was June 11, 2026; still in catalog.
280 CVEs published. 25 box scores, 255 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9547 99.9 YES
AFFECTED Product Versions Fixed PeopleSoft Enterprise PeopleTools 8.61 – —
TIMELINE Apr 1 Reserved by CNA Jun 12 Added to CISA KEV, due Jun 15 Jun 12 Published (CNA: oracle)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0522 91.8 —
AFFECTED Product Versions Fixed Order Attributes for Magento 2 unspecified —
TIMELINE Jun 10 Reserved by CNA Jun 12 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0386 89.3 —
AFFECTED Product Versions Fixed phpBB 3.3.0 – —
TIMELINE May 22 Reserved by CNA Jun 12 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0185 77.3 —
AFFECTED Product Versions Fixed nezha < 2.0.13 – —
TIMELINE Jun 9 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0180 76.6 —
AFFECTED Product Versions Fixed vm2 < 3.11.4 – —
TIMELINE May 18 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0151 72.2 —
AFFECTED Product Versions Fixed server >= 10.6.1, < 10.6.27 – —
TIMELINE May 20 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N L L L 6.3 .0133 68.8 —
AFFECTED Product Versions Fixed server >= 10.6.1, < 10.6.26 – —
TIMELINE May 5 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0126 67.1 —
AFFECTED Product Versions Fixed Allegra 8.1.10.5 – —
TIMELINE Jun 5 Reserved by CNA Jun 12 Published (CNA: zdi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0098 59.4 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.5.18
TIMELINE Jun 10 Reserved by CNA Jun 12 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0095 58.4 —
AFFECTED Product Versions Fixed iVEC TANK-XM811 unspecified —
TIMELINE Jun 10 Reserved by CNA Jun 12 Published (CNA: twcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0091 57.2 —
AFFECTED Product Versions Fixed server >= 10.6.1, < 10.6.27 – —
TIMELINE May 20 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0086 55.5 —
AFFECTED Product Versions Fixed Apache CXF 4.2.0 – —
TIMELINE Jun 5 Reserved by CNA Jun 12 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0086 55.4 —
AFFECTED Product Versions Fixed netty >= 4.2.0.Final, < 4.2.15.Final – —
TIMELINE May 12 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0083 54.7 —
AFFECTED Product Versions Fixed UniFi OS Server unspecified — Express unspecified — UDM unspecified — UDM-Pro unspecified — UDM-SE unspecified — UDM-Pro-Max unspecified — UDM-Beast unspecified — EFG unspecified — UDW unspecified — UDR unspecified — + 22 more
TIMELINE May 19 Reserved by CNA Jun 12 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0083 54.4 —
AFFECTED Product Versions Fixed UID Enterprise Agent unspecified —
TIMELINE May 19 Reserved by CNA Jun 12 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R U L L N 4.6 .0082 54.2 —
AFFECTED Product Versions Fixed Allegra 8.1.6.22 – —
TIMELINE Jun 5 Reserved by CNA Jun 12 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0082 54.1 —
AFFECTED Product Versions Fixed vm2 < 3.11.4 – —
TIMELINE May 18 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0076 52.3 —
AFFECTED Product Versions Fixed vm2 < 3.11.4 – —
TIMELINE May 18 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0074 51.6 —
AFFECTED Product Versions Fixed netty >= 4.2.0.Final, < 4.2.15.Final – —
TIMELINE May 20 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H R C L L L 5.9 .0071 50.4 —
AFFECTED Product Versions Fixed KeepInMind Dashboard Notes unspecified —
TIMELINE May 22 Reserved by CNA Jun 12 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 49.9 —
AFFECTED Product Versions Fixed Apache CXF 4.2.0 – —
TIMELINE Jun 5 Reserved by CNA Jun 12 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0065 48.0 —
AFFECTED Product Versions Fixed Apache CXF 4.2.0 – —
TIMELINE Jun 5 Reserved by CNA Jun 12 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0063 47.3 —
AFFECTED Product Versions Fixed netty >= 4.2.0.Final, < 4.2.15.Final – —
TIMELINE May 20 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0062 46.8 —
AFFECTED Product Versions Fixed server >= 10.6.1, < 10.6.26 – —
TIMELINE May 5 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0062 46.8 —
AFFECTED Product Versions Fixed vm2 < 3.11.4 – —
TIMELINE May 18 Reserved by CNA Jun 12 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-44893 | 7.5 | 46.7 | netty | netty | CWE-703 | Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length |
| CVE-2026-48043 | 7.5 | 46.7 | netty | netty | CWE-400 | netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFram… |
| CVE-2026-44172 | 6.9 | 45.5 | MariaDB | server | CWE-89 | MariaDB: mysql_real_escape_string() incorrectly handled big5 |
| CVE-2026-44168 | 8.0 | 45.3 | MariaDB | server | CWE-78 | MariaDB: wsrep SST unsafe parameter handling on the donor side |
| CVE-2026-47138 | 8.7 | 45.2 | parse-community | parse-server | CWE-1333 | Parse Server: Pre-authentication denial of service via client version header … |
| CVE-2026-12143 | 8.7 | 42.7 | form-data | form-data | CWE-93 | form-data does not escape CR/LF/quote in multipart field names and filenames … |
| CVE-2026-49875 | 9.8 | 42.2 | Apache Software Foundation | Apache CXF | CWE-611 | Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and … |
| CVE-2026-44990 | 9.3 | 41.4 | apostrophecms | sanitize-html | CWE-79 | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` |
| CVE-2026-50629 | 5.3 | 38.7 | Apache Software Foundation | Apache CXF | CWE-93 | Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier |
| CVE-2026-46340 | 7.5 | 38.1 | netty | netty | CWE-770 | Netty: SCTP reassembly nests buffers without bound |
| CVE-2026-50011 | 7.5 | 38.1 | netty | netty | CWE-400 | Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array le… |
| CVE-2026-50645 | 7.5 | 38.0 | Apache Software Foundation | Apache CXF | CWE-400 | Apache CXF: No restriction on attachment headers per message |
| CVE-2026-50010 | 7.5 | 37.8 | netty | netty | CWE-347 | Netty's wrapping plain trust manager silently disables hostname verification |
| CVE-2026-53836 | 8.7 | 37.4 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases |
| CVE-2026-12059 | 8.7 | 37.4 | Cellopoint | CelloOS | CWE-1284 | Cellopoint|CelloOS - Improper Access Control |
| CVE-2026-50627 | 9.1 | 37.0 | Apache Software Foundation | Apache CXF | CWE-289 | Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Toke… |
| CVE-2026-40677 | 7.7 | 36.2 | AMD | AMD Management Console (AMC) | CWE-1428 | The use of insecure HTTP transport within AMD optional tools could allow an a… |
| CVE-2026-46716 | 9.9 | 35.8 | nezhahq | nezha | CWE-78 | Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE)… |
| CVE-2026-42853 | 6.5 | 35.7 | apostrophecms | @apostrophecms/cli | CWE-78 | @apostrophecms/cli: Command Injection in apos create via Unsanitized Password… |
| CVE-2026-50085 | 9.8 | 34.4 | Aqara | Board service | CWE-306 | Aqara Board IoT insecure debug API |
| CVE-2026-47365 | 9.9 | 34.1 | WebPros | WordPress-Toolkit | CWE-88 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used i… |
| CVE-2026-11844 | 6.9 | 33.9 | IEI Integration Corp | iVEC TANK-XM811 | CWE-22 | IEI Integration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File Read |
| CVE-2026-50630 | 6.5 | 33.6 | Apache Software Foundation | Apache CXF | CWE-113 | Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection |
| CVE-2026-11846 | 7.2 | 33.3 | IEI Integration Corp | iVEC TANK-XM811 | CWE-22 | IEI Integration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File D… |
| CVE-2026-42604 | 6.9 | 33.2 | actualbudget | actual | CWE-863 | Actual has an OpenID `client_secret` Disclosure via Broken Authorization Guar… |
| CVE-2026-48748 | 7.5 | 32.4 | netty | netty | CWE-770 | Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion |
| CVE-2026-11933 | 8.7 | 31.5 | MongoDB | MongoDB | CWE-416 | Post-authentication use-after-free in server-side JavaScript BSON-to-array co… |
| CVE-2026-47137 | 10.0 | 31.3 | patriksimek | vm2 | CWE-913 | vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require … |
| CVE-2026-54393 | 5.1 | 30.8 | misp | misp | CWE-79 | MISP Overmind theme stored XSS via unvalidated homepage setting |
| CVE-2026-53825 | 7.1 | 30.6 | OpenClaw | OpenClaw | CWE-22 | OpenClaw < 2026.4.7 - Arbitrary Local File Read via memory-wiki Ingest with o… |
| CVE-2026-50623 | 4.8 | 30.2 | Apache Software Foundation | Apache CXF | CWE-287 | Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService |
| CVE-2026-50083 | 9.8 | 29.5 | Aqara | Aquara IAM/SSO Gateway | CWE-798 | Aqara hardcoded OAuth client credentials |
| CVE-2026-50287 | 8.7 | 28.9 | agenticmail | agenticmail | CWE-306 | Missing Authentication for Critical Function in @agenticmail/mcp |
| CVE-2026-41157 | 9.8 | 28.9 | Imagination Technologies | Graphics DDK | CWE-787 | GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D |
| CVE-2026-47368 | 8.6 | 28.6 | Ubiquiti Inc | UniFi OS Server | CWE-22 | A malicious actor with access to the network could exploit a Path Traversal v… |
| CVE-2026-9125 | 6.4 | 28.6 | 2winfactor | Presto Player | CWE-79 | The Ultimate Video Player For WordPress <= 4.2.0 - Authenticated (Contributor… |
| CVE-2026-10557 | 9.3 | 28.4 | Yarbo | Yarbo Android/IOS mobile application | CWE-798 | Yarbo Android/iOS Mobile Application and Cloud Infrastructure Use of Hard-cod… |
| CVE-2026-12043 | 8.7 | 28.2 | AWS | aws-c-http | CWE-415 | Heap double-free in AWS Common Runtime aws-c-http |
| CVE-2026-11849 | 9.3 | 28.1 | IEI Integration Corp | iRM-TSi410X | CWE-798 | IEI Integration Corp|iRM-IEI Remote Management - Hard-coded Credentials |
| CVE-2026-45169 | 8.7 | 28.1 | CyberArk Software, a Palo Alto Networks Company | PAM SH Vault | CWE-400 | Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service du… |
| CVE-2026-6853 | 9.8 | 27.6 | Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. | Pause+ Mobile App | CWE-307 | OTP Bypass in Başbelen Group's Pause+ Mobile App |
| CVE-2026-45830 | 8.8 | 27.5 | Chroma | ChromaDB | CWE-639 | A lack of authorization validation in version 0.4.17 or later of the ChromaDB… |
| CVE-2026-50008 | 6.9 | 27.3 | parse-community | parse-server | CWE-863 | Parse Server: Server option routeAllowList is bypassable through batch sub-re… |
| CVE-2026-45833 | 9.4 | 27.2 | Chroma | ChromaDB | CWE-94 | A code injection vulnerability in version 0.4.17 or later of the ChromaDB Pyt… |
| CVE-2026-47216 | 8.7 | 26.5 | typesense | typesense | CWE-754 | Typesense: Unauthenticated Denial of Service in the Typesense /multi_search E… |
| CVE-2026-47190 | 4.4 | 26.1 | metal3-io | ip-address-manager | CWE-250 | IPAM controller service account granted unnecessary full access to Secrets |
| CVE-2026-28742 | 9.2 | 25.9 | Naxclow | Smart Doorbell X3 | CWE-321 | Naxclow IoT Platform Use of hard-coded cryptographic key |
| CVE-2026-53982 | 7.1 | 25.8 | Cap-go | capgo | CWE-645 | Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association |
| CVE-2026-34195 | 8.8 | 25.7 | Imagination Technologies | Graphics DDK | CWE-787 | GPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect p… |
| CVE-2026-45775 | 6.8 | 25.1 | discourse | discourse | CWE-22 | Discourse: Cross-site backup access via path traversal in multisite local bac… |
| CVE-2026-47260 | 7.7 | 24.9 | koel | koel | CWE-918 | Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs |
| CVE-2026-44207 | 6.9 | 24.9 | frappe | frappe | CWE-639 | Frappe: Insecure Direct Object Reference for email accounts |
| CVE-2026-44208 | 6.9 | 24.9 | frappe | frappe | CWE-284 | Frappe: IDOR in `submit_discussion()` |
| CVE-2026-54133 | 9.8 | 24.8 | jmespath | jmespath.php | CWE-20 | jmespath.php has CompilerRuntime code injection via unescaped function names |
| CVE-2017-20240 | 5.9 | 24.7 | ARODLAND | Crypt::PBKDF2 | CWE-208 | Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks |
| CVE-2026-54394 | 5.3 | 24.7 | misp | misp | CWE-22 | MISP organisation logo path traversal allows retrieval of arbitrary PNG/SVG f… |
| CVE-2026-47691 | 10.0 | 24.5 | netty | netty | CWE-345 | Netty has Insufficient Bailiwick Validation for NS Records |
| CVE-2026-12060 | 6.9 | 24.1 | Hepta Platforms | Heptabase | CWE-749 | Hepta Platforms|Heptabase - Exposed Dangerous |
| CVE-2026-42947 | 8.7 | 23.9 | Naxclow | Smart Doorbell X3 | CWE-639 | Naxclow IoT Platform Authorization bypass through User-Controlled key |
| CVE-2026-44206 | 6.9 | 23.8 | frappe | frappe | CWE-200 | Frappe: DB Schema Enumeration via Frappe-Authorization-Source |
| CVE-2026-7387 | 8.8 | 23.6 | Mattermost | Mattermost | CWE-863 | Mattermost group syncable endpoints allow privilege escalation via scheme_admin |
| CVE-2026-47141 | 6.9 | 23.4 | patriksimek | vm2 | CWE-668 | vm2: NodeVM observability builtins leak host process and HTTP request data |
| CVE-2026-50108 | 8.7 | 23.2 | Naxclow | Smart Doorbell X3 | CWE-862 | Naxclow IoT Platform Missing Authorization |
| CVE-2026-6961 | 7.6 | 23.1 | Mattermost | Mattermost | CWE-22 | CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost fed… |
| CVE-2026-9638 | 7.5 | 23.1 | ARODLAND | Crypt::PBKDF2 | CWE-338 | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random valu… |
| CVE-2026-47369 | 9.9 | 22.9 | Ubiquiti Inc | UniFi OS Server | CWE-20 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-43872 | 5.3 | 22.9 | actualbudget | actual | CWE-22 | actual-server has a path traversal vulnerability |
| CVE-2026-50560 | 6.9 | 22.7 | netty | netty | CWE-770 | Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature |
| CVE-2026-47366 | 7.2 | 22.4 | phpBB | phpBB | CWE-284 | Improper verification of access permissions when modifying permissions throug… |
| CVE-2026-11848 | 7.9 | 22.2 | IEI Integration Corp | iRM-TSi410X | CWE-306 | IEI Integration Corp| iRM-IEI Remote Management - Missing Authentication |
| CVE-2026-53721 | 8.8 | 21.9 | nuxt | nuxt | CWE-178 | Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-… |
| CVE-2026-50631 | 7.4 | 21.9 | Apache Software Foundation | Apache CXF | CWE-367 | Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing |
| CVE-2026-47244 | 5.3 | 21.7 | netty | netty | CWE-400 | Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced |
| CVE-2026-47248 | 6.9 | 21.7 | parse-community | parse-server | CWE-209 | Parse Server: GraphQL "Did you mean" validation suggestions disclose schema t… |
| CVE-2026-50086 | 9.8 | 21.5 | Aqara | Aqara IAM/SSO Gateway | CWE-327 | Aqara unauthenticated AES oracle |
| CVE-2026-53522 | 6.5 | 21.5 | nezhahq | nezha | CWE-770 | Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS |
| CVE-2026-53821 | 8.7 | 21.4 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.5.18 - Scope Elevation in trusted-proxy Control UI WebSocket |
| CVE-2026-12066 | 5.5 | 21.3 | n/a | PbootCMS | CWE-640 | PbootCMS Password MemberController.php retrieve password recovery |
| CVE-2026-11847 | 5.3 | 21.3 | IEI Integration Corp | iVEC TANK-XM811 | CWE-22 | Integration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File Deletion |
| CVE-2026-47209 | 8.6 | 21.2 | patriksimek | vm2 | CWE-693 | vm2: Bridge Proxy set trap ignores receiver parameter, enabling host object p… |
| CVE-2026-42850 | 7.4 | 21.2 | kovidgoyal | kitty | CWE-77 | Kitty has a shell command injection |
| CVE-2026-50091 | 7.4 | 21.2 | Aqara | com.lumiunited.aqarahome | CWE-798 | Aqara Home Android SDK hardcoded keys |
| CVE-2026-45014 | 5.3 | 21.1 | apostrophecms | apostrophe | CWE-79 | Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Dis… |
| CVE-2026-45832 | 8.8 | 20.9 | Chroma | ChromaDB | CWE-639 | All V1 collection-level endpoints in ChromaDB's Python project pass None for … |
| CVE-2026-47139 | 8.6 | 20.7 | patriksimek | vm2 | CWE-693 | vm2: NodeVM network builtin exclusions bypass via internal _http_client and _… |
| CVE-2026-53520 | 6.5 | 20.7 | nezhahq | nezha | CWE-284 | Nezha Monitoring: Authenticated users can claim the dashboard Host through NA… |
| CVE-2026-50101 | 9.2 | 20.6 | Naxclow | Smart Doorbell X3 | CWE-262 | Naxclow IoT Platform Not using password aging |
| CVE-2026-53724 | 2.1 | 20.6 | parse-community | parse-server | CWE-79 | Parse Server: Stored XSS via trailing-dot filename bypassing file upload exte… |
| CVE-2026-49993 | 5.9 | 20.5 | nuxt | nuxt | CWE-749 | @nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check b… |
| CVE-2026-8828 | 8.8 | 20.4 | Chroma | ChromaDB | CWE-639 | A lack of authorization validation in version 1.0.0 or later of the ChromaDB … |
| CVE-2026-44892 | 7.5 | 20.4 | netty | netty | CWE-400 | Netty has a Vulnerable Default Configuration Which Leads to Denial of Service… |
| CVE-2026-50634 | 6.5 | 20.3 | Apache Software Foundation | Apache CXF | CWE-347 | Apache CXF: WS JSON request filter trusts metadata from an unvalidated first … |
| CVE-2026-20746 | 6.3 | 20.2 | Ping Identity | PingDirectory | CWE-401 | PingDirectory copying of virtual attributes leads to memory exhaustion |
| CVE-2026-44975 | 5.3 | 20.2 | frappe | frappe | CWE-862 | Frappe: Missing authorization on reset form tours |
| CVE-2026-44976 | 5.3 | 20.2 | frappe | frappe | CWE-284 | Frappe: IDOR in update_onboarding_step |
| CVE-2026-47182 | 5.3 | 20.2 | frappe | frappe | CWE-284 | Frappe: Broken Access Control on Private Files |
| CVE-2026-53726 | 6.9 | 20.1 | parse-community | parse-server | CWE-639 | Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owni… |
| CVE-2026-46717 | 7.7 | 19.2 | nezhahq | nezha | CWE-863 | Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflectio… |
| CVE-2026-47124 | 6.5 | 19.2 | nezhahq | nezha | CWE-200 | Nezha WebSocket server stream discloses cross-tenant server telemetry to auth… |
| CVE-2026-4870 | 7.5 | 19.0 | IBM | Qiskit SDK | CWE-674 | Qiskit SDK is vulnerable to specific functions may recurse too deeply and ove… |
| CVE-2026-54056 | 7.1 | 19.0 | kovidgoyal | kitty | CWE-59 | Kitty has an arbitrary file overwrite via symlink following in `kitten dnd` r… |
| CVE-2026-53828 | 7.7 | 18.9 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command E… |
| CVE-2026-53981 | 7.2 | 18.9 | Cap-go | Cap-go | CWE-306 | Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism |
| CVE-2026-47135 | 8.7 | 18.8 | patriksimek | vm2 | CWE-693 | vm2: Sandbox escape via unblocked cross-realm Symbol.for keys + missing bridg… |
| CVE-2026-48119 | 7.1 | 18.8 | nezhahq | nezha | CWE-862 | Nezha Monitoring: Authenticated agents can forge service-monitor results for … |
| CVE-2026-50082 | 5.3 | 18.5 | Aqara | Cloud Developer Portal | CWE-306 | Aqara Developer Portal insecure authentication token |
| CVE-2026-53839 | 6.0 | 18.5 | OpenClaw | OpenClaw | CWE-1023 | OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoi… |
| CVE-2026-48610 | 8.1 | 18.4 | Ubiquiti Inc | UDM | CWE-284 | Under certain network configurations, a malicious actor with access to networ… |
| CVE-2026-12068 | 7.4 | 18.2 | Gen Digital | Avira Password Manager | CWE-669 | Avira Password Manager credential disclosure via cross-origin autofill in Fir… |
| CVE-2026-54361 | 8.8 | 18.1 | misp | misp | CWE-639 | MISP mass assignment vulnerabilities allow unauthorized modification of owner… |
| CVE-2026-47120 | 7.1 | 18.0 | nezhahq | nezha | CWE-862 | Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.F… |
| CVE-2026-50026 | 6.9 | 17.9 | frappe | frappe | CWE-862 | Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpo… |
| CVE-2026-7368 | 8.6 | 17.7 | Yarbo | Yarbo Android/IOS mobile application | CWE-862 | Yarbo Android/iOS Mobile Application and Cloud Infrastructure Missing Authori… |
| CVE-2026-44786 | 7.5 | 17.7 | discourse | discourse | CWE-200 | Discourse: Public chat MessageBus broadcasts are not restricted to chat-eligi… |
| CVE-2026-53868 | 8.7 | 17.6 | Capgo | Capgo | CWE-306 | Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registratio… |
| CVE-2026-44205 | 6.9 | 17.6 | frappe | frappe | CWE-79 | Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload |
| CVE-2026-47739 | 6.9 | 17.6 | frappe | frappe | CWE-79 | Frappe: Stored XSS in Note |
| CVE-2026-53568 | 6.9 | 17.6 | frappe | frappe | CWE-79 | Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value' |
| CVE-2026-6739 | 7.2 | 17.5 | Mattermost | Mattermost | CWE-863 | Mattermost: Delegated admins could patch protected default system roles |
| CVE-2026-45673 | 6.8 | 17.3 | netty | netty | CWE-330 | Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source … |
| CVE-2026-54395 | 5.3 | 17.3 | misp | misp | CWE-79 | MISP UiBeta event index reflected XSS in advanced filter popup |
| CVE-2026-7184 | 6.5 | 17.3 | Mattermost | Mattermost | CWE-201 | Mattermost Remote Cluster PATCH API Leaks Authentication Tokens |
| CVE-2026-53827 | 6.0 | 17.1 | OpenClaw | OpenClaw | CWE-918 | OpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in… |
| CVE-2026-54357 | 5.1 | 17.2 | misp | misp | CWE-639 | MISP improper authorization allows organization administrators to modify site… |
| CVE-2026-49397 | 5.3 | 17.0 | nezhahq | nezha | CWE-200 | Nezha Monitoring: Private services (`EnableShowInService: false`) are enumera… |
| CVE-2026-53725 | 5.9 | 16.8 | parse-community | parse-server | CWE-200 | Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets a… |
| CVE-2026-48485 | 2.1 | 16.8 | duck-organization | questbot | CWE-116 | Quest Bot: Stored warn reasons can still trigger bot-powered mass mentions th… |
| CVE-2026-45013 | 8.1 | 16.6 | apostrophecms | apostrophe | CWE-20 | Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and … |
| CVE-2026-12131 | 2.1 | 16.6 | CodeAstro | Human Resource Management System | CWE-74 | CodeAstro Human Resource Management System Payroll Invoice Payroll.php sql in… |
| CVE-2026-45674 | 10.0 | 16.4 | netty | netty | CWE-345 | Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME… |
| CVE-2026-54396 | 5.3 | 16.2 | misp | misp | CWE-200 | MISP AuthKey edit endpoint allows authenticated user email enumeration |
| CVE-2026-50084 | 6.5 | 15.9 | Aqara | Cloud Production API | CWE-862 | Aqara API cross-account access |
| CVE-2026-53523 | 6.8 | 15.2 | nezhahq | nezha | CWE-601 | Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection |
| CVE-2026-10715 | 5.1 | 15.1 | Camaleon CMS | Camaleon CMS | CWE-862 | Camaleon CMS 2.9.2 - Improper authorization in draft autosave endpoint |
| CVE-2026-53609 | 9.1 | 14.9 | apostrophecms | apostrophe | CWE-1321 | Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch ope… |
| CVE-2026-45831 | 8.8 | 14.9 | Chroma | ChromaDB | CWE-863 | The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 … |
| CVE-2026-44169 | 4.3 | 15.0 | MariaDB | server | CWE-863 | MariaDB: Authorization bypass in role-based routine-level privilege check exp… |
| CVE-2026-47196 | 8.4 | 14.6 | duck-organization | questbot | CWE-20 | Quest Bot: Empty automod rule causes every guild message to be deleted |
| CVE-2026-49347 | 5.3 | 14.6 | duck-organization | questbot | CWE-770 | Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown |
| CVE-2026-44779 | 4.3 | 14.7 | discourse | discourse | CWE-200 | Discourse: Bot debug endpoints disclose whisper translation audit logs |
| CVE-2026-42932 | 6.9 | 14.5 | Naxclow | Smart Doorbell X3 | CWE-340 | Naxclow IoT Platform Generation of Predictable Numbers or Identifiers |
| CVE-2026-53829 | 8.5 | 14.2 | OpenClaw | OpenClaw | CWE-451 | OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display |
| CVE-2026-50020 | 5.3 | 14.3 | netty | netty | CWE-444 | Netty's HttpObjectDecoder skips arbitrary initial control characters when onl… |
| CVE-2026-53407 | 9.8 | 14.1 | Zoom Communications | Zoom Workplace | CWE-939 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace bef… |
| CVE-2026-44784 | 6.5 | 14.2 | discourse | discourse | CWE-200 | Discourse: Non-staff group owners can see email password in plaintext through… |
| CVE-2026-47200 | 6.3 | 14.0 | nuxt | nuxt | CWE-284 | Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/… |
| CVE-2026-53838 | 6.0 | 14.0 | OpenClaw | OpenClaw | CWE-367 | OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection |
| CVE-2026-54358 | 7.5 | 13.9 | misp | misp | CWE-863 | MISP organization administrators can target site administrator accounts for p… |
| CVE-2026-47197 | 7.2 | 13.8 | duck-organization | questbot | CWE-862 | Quest Bot: Discord moderation role hierarchy bypass in ban, kick, mute, unmut… |
| CVE-2026-41581 | 6.9 | 13.7 | frappe | frappe | CWE-89 | Frappe Vulnerable to Possible SQL Injection via get_blog_list |
| CVE-2026-53521 | 6.4 | 13.8 | nezhahq | nezha | CWE-863 | Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of an… |
| CVE-2026-50090 | 6.1 | 13.8 | Aqara | Cloud OAuth Authorization Endpoint | CWE-1289 | Aqara OAuth redirect_uri validation bypass |
| CVE-2026-54360 | 8.4 | 13.5 | misp | misp | CWE-639 | MISP sharing group creation mass assignment allows unauthorized takeover of e… |
| CVE-2026-54397 | 6.1 | 13.5 | misp | misp | CWE-863 | MISP event editing allows unauthorized assignment to undisclosed sharing groups |
| CVE-2026-47225 | 6.0 | 13.5 | typesense | typesense | CWE-524 | Improper Search Cache Isolation for Scoped Search API Keys in Typesense |
| CVE-2026-9641 | 5.3 | 13.5 | ARODLAND | Crypt::PBKDF2 | CWE-916 | Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm… |
| CVE-2026-53607 | 3.7 | 13.6 | apostrophecms | apostrophe | CWE-918 | @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host he… |
| CVE-2026-50244 | 6.9 | 12.9 | Naxclow | Smart Doorbell X3 | CWE-862 | Naxclow IoT Platform Missing Authorization |
| CVE-2026-8694 | 5.3 | 12.9 | Devolutions | PowerShell Universal | CWE-306 | Improper access control on the API documentation endpoint in PowerShell Unive… |
| CVE-2026-54398 | 5.3 | 12.7 | misp | misp | CWE-863 | MISP object edit authorization bypass allows unauthorized sharing group assig… |
| CVE-2026-47264 | 5.3 | 12.3 | discourse | discourse | CWE-200 | Discourse: Don't leak restricted tag group names via tag info |
| CVE-2026-47195 | 7.1 | 12.2 | duck-organization | questbot | CWE-863 | Quest Bot: Per-channel permission overwrite bypass in purge and slowmode comm… |
| CVE-2026-50088 | 4.7 | 12.2 | Aqara | Aqara Developer Portal | CWE-942 | Aqara Developer Portal cross-origin resource sharing |
| CVE-2026-45085 | 5.3 | 11.8 | discourse | discourse | CWE-200 | Discourse: Chat misauthorization and information disclosure |
| CVE-2026-53408 | 8.1 | 11.7 | Zoom Communications | Zoom Workplace | CWE-939 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace bef… |
| CVE-2026-45011 | 7.3 | 11.6 | apostrophecms | apostrophe | CWE-79 | Apostrophe has stored XSS via javascript: URL in Image Widget Link |
| CVE-2026-47263 | 4.3 | 11.6 | discourse | discourse | CWE-200 | Discourse: Prevent webhook payload disclosure on event redelivery |
| CVE-2026-6211 | 8.7 | 11.5 | Global IT Informatics Services Inc. | WEOLL | CWE-434 | Arbitrary File Upload in Global IT's WEOLL |
| CVE-2026-53608 | 8.7 | 11.5 | apostrophecms | @apostrophecms/seo | CWE-79 | @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics … |
| CVE-2026-5792 | 6.5 | 11.5 | Hedef Media Promotion Interactive Media Marketing Inc. | Related Marketing Cloud (RMC) | CWE-290 | Authentication Bypass in Hedef Media's Related Marketing Cloud (RMC) |
| CVE-2026-53823 | 8.6 | 11.3 | OpenClaw | OpenClaw | CWE-290 | OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in… |
| CVE-2026-53830 | 6.0 | 11.0 | OpenClaw | OpenClaw | CWE-613 | OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload |
| CVE-2026-54362 | 5.3 | 11.1 | misp | misp | CWE-863 | MISP template builder exposes non-visible custom galaxies across organisations |
| CVE-2026-44967 | 5.3 | 11.0 | open-telemetry | opentelemetry-cpp | CWE-789 | opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response |
| CVE-2026-45670 | 5.9 | 10.8 | nuxt | nuxt | CWE-749 | Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete… |
| CVE-2026-50087 | 6.1 | 10.6 | Aqara | Aqara IAM/SSO Gateway | CWE-942 | Aqara IAM/SSO Gateway cross-origin resource sharing |
| CVE-2026-50009 | 4.8 | 10.6 | netty | netty | CWE-200 | Netty QUIC stateless reset token material exposed through header-visible conn… |
| CVE-2026-12129 | 2.0 | 10.5 | CodeAstro | Human Resource Management System | CWE-79 | CodeAstro Human Resource Management System Dashboard add_tod cross site scrip… |
| CVE-2026-12130 | 2.0 | 10.5 | CodeAstro | Human Resource Management System | CWE-79 | CodeAstro Human Resource Management System Projects Management Add_Projects c… |
| CVE-2026-53834 | 8.2 | 10.1 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands |
| CVE-2026-53831 | 7.6 | 9.9 | OpenClaw | OpenClaw | CWE-367 | OpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run … |
| CVE-2026-53722 | 5.1 | 9.9 | nuxt | nuxt | CWE-79 | Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL |
| CVE-2026-45012 | 7.6 | 9.9 | apostrophecms | apostrophe | CWE-918 | Apostrophe has authenticated SSRF in rich-text widget import via @apostrophec… |
| CVE-2026-50089 | 6.1 | 9.6 | Aqara | Aqara IAM/SSO Gateway | CWE-601 | Aqara IAM/SSO Gateway open redirect |
| CVE-2026-6046 | 5.3 | 9.0 | Mattermost | Mattermost | CWE-200 | Plugin bot username conflict allows user account to be used as bot identity i… |
| CVE-2026-54359 | 7.1 | 8.9 | misp | misp | CWE-352 | MISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protecti… |
| CVE-2026-53837 | 6.3 | 8.8 | OpenClaw | OpenClaw | CWE-636 | OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Han… |
| CVE-2026-44780 | 4.3 | 8.8 | discourse | discourse | CWE-200 | Discourse: Category queue reviewers can read raw incoming emails from queued … |
| CVE-2026-44782 | 4.3 | 8.8 | discourse | discourse | CWE-200 | Discourse: GroupPostSerializer leaks hidden full names through reaction post … |
| CVE-2026-44785 | 4.3 | 8.8 | discourse | discourse | CWE-200 | Discourse: Hidden reply-to post raw can be disclosed through AI explain prompts |
| CVE-2026-47224 | 4.3 | 8.6 | M2Team | NanaZip | CWE-125 | NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check |
| CVE-2026-53826 | 2.3 | 8.6 | OpenClaw | OpenClaw | CWE-668 | OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn |
| CVE-2026-3840 | 7.1 | 8.4 | kedro-org | kedro-org/kedro | CWE-22 | Path Traversal in kedro-org/kedro |
| CVE-2026-53867 | 5.3 | 8.2 | Capgo | Capgo | CWE-459 | Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement |
| CVE-2026-47236 | 4.3 | 8.1 | solidtime-io | solidtime | CWE-863 | Solidtime team page exposes pending invitation and member emails to employees… |
| CVE-2026-47268 | 6.4 | 8.1 | nezhahq | nezha | CWE-918 | Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF … |
| CVE-2026-53824 | 6.0 | 8.0 | OpenClaw | OpenClaw | CWE-613 | Mattermost plugin for OpenClaw < 2026.4.24 - Slash Token Revocation Lag via M… |
| CVE-2026-47223 | 5.4 | 7.9 | M2Team | NanaZip | CWE-125 | NanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser vi… |
| CVE-2026-3433 | 4.3 | 7.9 | Mattermost | Mattermost | CWE-200 | Mattermost fails to scope role_updated websocket events to authorized team an… |
| CVE-2026-53833 | 7.4 | 7.7 | OpenClaw | OpenClaw | CWE-290 | QQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Com… |
| CVE-2026-45669 | 5.3 | 7.5 | nuxt | nuxt | CWE-83 | Nuxt: Reflected XSS in `navigateTo()` external redirect |
| CVE-2026-44171 | 7.8 | 7.2 | MariaDB | server | CWE-22 | MariaDB: path traversal in mbstream |
| CVE-2026-24618 | 4.3 | 7.2 | HashThemes | Hash Elements | CWE-497 | WordPress Hash Elements plugin <= 1.5.4 - Sensitive Data Exposure vulnerability |
| CVE-2026-50099 | 5.1 | 6.8 | Naxclow | Smart Doorbell X3 | CWE-538 | Naxclow IoT Platform Insertion of sensitive information into Externally-Acces… |
| CVE-2026-47222 | 5.4 | 6.7 | M2Team | NanaZip | CWE-125 | NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser vi… |
| CVE-2026-12058 | 5.3 | 6.7 | vivo | PcSuite | CWE-807 | The connection confirmation pop-up of a specific feature in the PcSuite can b… |
| CVE-2026-50552 | 6.3 | 6.6 | koel | koel | CWE-918 | Koel: Server-Side Request Forgery (SSRF) in radio station creation due to mis… |
| CVE-2026-54057 | 7.3 | 6.3 | kovidgoyal | kitty | CWE-94 | Kitty vulnerable to command injection via unsanitized OSC 21 query reply |
| CVE-2026-53835 | 2.3 | 6.3 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent… |
| CVE-2026-42851 | 7.8 | 6.1 | kovidgoyal | kitty | CWE-94 | @kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process… |
| CVE-2026-48914 | 6.7 | 5.5 | — | qemu | CWE-122 | Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling |
| CVE-2026-48613 | 5.9 | 5.2 | phpBB | phpBB | CWE-89 | SQL injection vulnerability in phpBB profile field migration due to improper … |
| CVE-2026-6689 | 4.3 | 4.9 | Mattermost | Mattermost | CWE-862 | *Missing* {{invite_user}} *permission check on team creation allows unprivile… |
| CVE-2026-11535 | 9.4 | 4.8 | vivo | PcSuite | CWE-306 | An unauthorized access vulnerability exists in the PcSuite APP. The vulnerabi… |
| CVE-2026-47965 | 7.8 | 4.5 | Adobe | Acrobat Reader | CWE-787 | Acrobat Reader | Out-of-bounds Write (CWE-787) |
| CVE-2026-44783 | 5.4 | 4.5 | discourse | discourse | CWE-284 | Discourse: Replying to a whisper lets non-whisperers create staff-only whispe… |
| CVE-2025-7004 | 7.8 | 4.4 | Gen Digital | Avast Antivirus | CWE-787 | Avast antivirus heap buffer OOB write when scanning a malformed PE file |
| CVE-2025-7008 | 7.8 | 4.4 | Gen Digital | Avast Antivirus | CWE-125 | Avast antivirus heap buffer OOB read when scanning a malformed PE file |
| CVE-2025-7009 | 7.8 | 4.4 | Gen Digital | Avast Antivirus | CWE-125 | Avast antivirus heap buffer OOB read when scanning a malformed PE file |
| CVE-2025-7011 | 7.8 | 4.4 | Gen Digital | Avast Antivirus | CWE-125 | Avast antivirus heap OOB when scanning a malformed zip file |
| CVE-2026-9269 | 3.5 | 4.3 | Unknown | Secure Copy Content Protection and Content Locking | — | Secure Copy Content Protection and Content Locking < 5.1.5 - Admin+ Stored XS… |
| CVE-2026-44894 | 7.5 | 4.1 | netty | netty | CWE-940 | Netty's Default QUIC token handler accepts any client-supplied token |
| CVE-2026-53606 | 5.4 | 3.5 | apostrophecms | sanitize-html | CWE-79 | sanitize-html has an incomplete URI scheme validation that allows javascript:… |
| CVE-2026-45536 | 4.0 | 3.5 | netty | netty | CWE-200 | Netty: Unix-socket fd receive leaks descriptors when peer sends two at once |
| CVE-2025-7002 | 7.8 | 3.2 | Gen Digital | Avira Antivirus | CWE-125 | Avira antivirus engine heap buffer OOB read when scanning a malformed PDF fil… |
| CVE-2025-7003 | 7.8 | 3.2 | Gen Digital | Avira Antivirus | CWE-125 | Avira antivirus engine heap buffer OOB read when scanning a malformed PDF fil… |
| CVE-2025-7017 | 7.8 | 3.2 | Gen Digital | Avira Antivirus | CWE-125 | Avira antivirus engine heap buffer OOB read when scanning a malformed Windows… |
| CVE-2026-46690 | 5.8 | 3.1 | spearman | unbounded-spsc | CWE-125 | unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and f… |
| CVE-2026-42890 | 4.8 | 2.7 | actualbudget | actual | CWE-94 | actual Allows Electron to Run As Node |
| CVE-2026-49396 | 7.1 | 2.5 | nezhahq | nezha | CWE-352 | Nezha Monitoring: Cross-site GET request can trigger stored cron commands on … |
| CVE-2025-9032 | 7.8 | 2.4 | Gen Digital | Avira Antivirus | CWE-125 | Avira antivirus engine heap buffer OOB read when scanning a malformed PE file |
| CVE-2025-9033 | 7.8 | 2.3 | Gen Digital | Avira Antivirus | CWE-125 | Avira antivirus engine heap buffer OOB read when scanning a malformed PDF fil… |
| CVE-2025-14098 | 7.8 | 2.3 | Gen Digital | Avira Antivirus | CWE-190 | Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS… |
| CVE-2026-6676 | 7.8 | 2.3 | Gen Digital | Avira Antivirus | CWE-787 | Avira antivirus engine heap buffer OOB write when scanning a malformed POSIX … |
| CVE-2026-48612 | 8.0 | 2.2 | phpBB | phpBB | CWE-352 | Improper state verification in the OAuth implementation could allow an attack… |
| CVE-2026-41158 | 7.8 | 2.0 | Imagination Technologies | Graphics DDK | CWE-416 | GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after… |
| CVE-2025-7010 | 5.5 | 1.6 | Gen Digital | Avast Antivirus | CWE-674 | Avast antivirus stack overflow when scanning a malformed PDF file |
| CVE-2025-7019 | 5.5 | 1.6 | Gen Digital | Avast Antivirus | CWE-121 | Avast antivirus stack overflow when scanning a malformed Office Open XML file |
| CVE-2025-7005 | 5.5 | 1.5 | Gen Digital | Avast Antivirus | CWE-674 | Avast antivirus infinite recursion when scanning a malformed PE file |
| CVE-2025-7006 | 5.5 | 1.5 | Gen Digital | Avast Antivirus | CWE-590 | Avast antivirus use of stack memory after free when scanning a malformed PE file |
| CVE-2025-7018 | 5.5 | 1.5 | Gen Digital | Avira Antivirus | CWE-476 | Avira antivirus engine null pointer dereference when scanning a malformed PE … |
| CVE-2026-11879 | 8.5 | 1.4 | Mobatek | MobaXterm Personal Edition (Portable) | CWE-427 | Arbitrary code execution in MobaXterm Personal Edition (Portable) |
| CVE-2026-11967 | 8.5 | 1.4 | Mobatek | MobaXterm Personal Edition (Portable) | CWE-427 | Arbitrary code execution in MobaXterm Personal Edition (Portable) |
| CVE-2026-41568 | 6.1 | 1.4 | moby | moby | CWE-81 | Moby: Race condition in docker cp allows creation of arbitrary empty files on… |
| CVE-2026-41155 | 5.5 | 1.2 | Imagination Technologies | Graphics DDK | CWE-653 | GPU DDK - SharedSecMem mapped into all GPU virtual address spaces |
| CVE-2026-12065 | 0.3 | 1.2 | Groww | Stock, Mutual Fund, Gold App | CWE-285 | Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in hand… |
| CVE-2026-45170 | 7.5 | 1.2 | CyberArk Software, a Palo Alto Networks Company | Vendor PAM | CWE-295 | Idira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to In… |
| CVE-2026-1836 | 5.3 | 1.2 | Redmine | Redmine | CWE-257 | Stored credentials in Redmine |
| CVE-2026-42306 | 7.2 | 1.2 | moby | moby | CWE-61 | Moby: Race condition in docker cp allows bind mount redirection to host path |
| CVE-2026-53832 | 7.4 | 1.1 | OpenClaw | OpenClaw | CWE-290 | OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration |
| CVE-2026-53820 | 6.9 | 0.7 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.5.12 - Exec Denylist Bypass in Bundle MCP Loopback Session Spawn |
| CVE-2026-46342 | 2.3 | 0.6 | nuxt | nuxt | CWE-79 | Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enab… |
| CVE-2026-53406 | 7.8 | 0.2 | Zoom Communications | Remote Control for Zoom Contact Center | CWE-345 | Insufficient Verification of Data Authenticity in Remote Control for Zoom Con… |
| CVE-2026-54055 | 5.0 | 0.1 | kovidgoyal | kitty | CWE-59 | Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmis… |
| CVE-2026-9266 | 7.0 | 0.0 | Moxa | UC-1200A Series | CWE-325 | A Missing Required Cryptographic Step vulnerability has been identified in Mo… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-12 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.