boxscore/security
Saturday, June 13, 2026 · all times UTC← 2026-06-12 · archive · 2026-06-14 →

22 CVEs published June 13, 2026: 2 critical, 7 high, 9 medium, 4 low; 0 in KEV; 0 with a public exploit reference; 0 awaiting enrichment.

Standings

League
MTDYTD2025 same span2025 full
CVEs published3358773010612563
KEV catalog size1670

346 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9610628466331212730.37.8.0013-117
google59176567402272217460.88.1.0023+591
microsoft207697524661584378273.97.8.0043+70
red hat44108848466400.07.0.0030+40
apple146101636293711.55.7.0023+1
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
debian220020000.06.5.0023+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161800.04.3.0024+17
cisco316324096956.37.2.0971+3
palo alto networks911017114218.24.8.0022+8
ivanti49230033555.68.8.5187+3
checkpoint3915303111.17.5.0410+3
ubiquiti584400400.08.9.0052+5
fortinet28132028337.57.3.0066+1
broadcom2400204250.05.3.0887+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache679915404124011.07.3.0052+63
gitlab1120041224210.04.8.0024+11
mozilla51134401300.07.5.0032+1
docker250500100.08.8.0021+2
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
adobe1241284477227532.35.5.0021+124
ibm11601329180700.07.5.0028+11
oracle330916404026.78.1.0027+3
progress591710900.07.5.0036+5
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+9
siemens780440100.07.5.0020+6
abb550410000.07.2.0018+5
dahua330111200.06.9.0036+3
hitachi energy020020000.05.7.00140
moxa110100000.07.0.0007+1
schneider electric110100100.07.1.0023+1
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring6869227391000.06.5.0023+68
sourcecodester3658002434000.02.1.0026+36
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
openclaw3440024124000.07.4.0022+34

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2008-4250.987599.9
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2010-0249.918899.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-2022310.0.0083
CVE-2026-4714010.0.0082
CVE-2026-4720810.0.0076
Most disclosures (vendor)
VendorCVEs
google759
linux523
microsoft239
adobe125
apache84
red hat81
spring69
ibm60
sourcecodester58
edimax51
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco9
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven35
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171669
CVE-2021-27102Accellion2021-11-171669
CVE-2021-27101Accellion2021-11-171669
CVE-2021-27103Accellion2021-11-171669
CVE-2021-21017Adobe2021-11-171669
CVE-2021-28550Adobe2021-11-171669
CVE-2021-42013Apache2021-11-171669
CVE-2021-41773Apache2021-11-171669
CVE-2021-30858Apple2021-11-171669
CVE-2021-30860Apple2021-11-171669

Transactions

EXPLOIT PUBLISHEDCVE-2026-12183 (Nefteprodukttekhnika LLC BUK TS-G Gas Station Automation System). Public exploit reference added.

Yesterday's Results

22 CVEs published. 22 box scores, 0 table rows — nothing truncated.

D-Link DCS-935L HTTP rhea snprintf format string
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0058   45.1     —
AFFECTED
  Product   Versions   Fixed
  DCS-935L  1.10.01 –  —
TIMELINE
  Jun 13  Reserved by CNA
  Jun 13  Published (CNA: VulDB)
CWE-119, CWE-134 · CNA: VulDB · 6 references · NVD status: Analyzed
emarket-design Customer Support Ticket System & Helpdesk — WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0051   41.2     —
AFFECTED
  Product                                    Versions     Fixed
  Customer Support Ticket System & Helpdesk  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jun 13  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 7 references · NVD status: Deferred
Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0044   36.7     —
AFFECTED
  Product                                 Versions  Fixed
  BUK TS-G Gas Station Automation System  2.9.1 –   —
TIMELINE
  Jun 13  Public exploit reference published
  Jun 13  Reserved by CNA
  Jun 13  Published (CNA: TuranSec)
CWE-287, CWE-306 · CNA: TuranSec · 4 references · NVD status: Deferred
ladela Online Scheduling and Appointment Booking System – Bookly — Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0044   36.4     —
AFFECTED
  Product                                                    Versions     Fixed
  Online Scheduling and Appointment Booking System – Bookly  unspecified  —
TIMELINE
  Apr 3   Reserved by CNA
  Jun 13  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 2 references · NVD status: Deferred
Grafana Grafana Operator — Operator - Namespaced User Path Traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   N    6.4   .0036   29.2     —
AFFECTED
  Product           Versions     Fixed
  Grafana Operator  unspecified  —
TIMELINE
  Jun 9   Reserved by CNA
  Jun 13  Published (CNA: GRAFANA)
CWE-22 · CNA: GRAFANA · 1 reference · NVD status: Modified
aurelienlws LWS Optimize – All-in-One Speed Booster & Cache Tools — WS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0034   26.6     —
AFFECTED
  Product                                                Versions     Fixed
  LWS Optimize – All-in-One Speed Booster & Cache Tools  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Jun 13  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 3 references · NVD status: Deferred
john-dagelmore GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites — GPTranslate <= 2.31 - Unauthenticated Stored Cross-Site Scripting via REST API Translation Storage
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0032   24.3     —
AFFECTED
  Product                                                                                    Versions     Fixed
  GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 13  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 12 references · NVD status: Deferred
fooplugins Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel — Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0030   22.7     —
AFFECTED
  Product                                                                             Versions     Fixed
  Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 13  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 5 references · NVD status: Deferred
softaculous Page Builder: Pagelayer – Drag and Drop website builder — Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0029   21.8     —
AFFECTED
  Product                                                  Versions     Fixed
  Page Builder: Pagelayer – Drag and Drop website builder  unspecified  —
TIMELINE
  Feb 13  Reserved by CNA
  Jun 13  Published (CNA: Wordfence)
CWE-863 · CNA: Wordfence · 2 references · NVD status: Deferred
SourceCodester CET Automated Grading System with AI Predictive Analytics index.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0027   18.5     —
AFFECTED
  Product                                                    Versions  Fixed
  CET Automated Grading System with AI Predictive Analytics  1.0 –     —
TIMELINE
  Jun 13  Reserved by CNA
  Jun 13  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · 5 references · NVD status: Deferred
Unknown Store Locator WordPress — Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   R  C  L  N  N    3.4   .0025   16.4     —
AFFECTED
  Product                  Versions     Fixed
  Store Locator WordPress  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 13  Published (CNA: WPScan)
CWE-22 · CNA: WPScan · 1 reference · NVD status: Deferred
Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   L   L    5.6   .0024   15.9     —
AFFECTED
  Product  Versions     Fixed
  Koha     unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  Jun 13  Published (CNA: TuranSec)
CWE-89 · CNA: TuranSec · 3 references · NVD status: Awaiting Analysis
softaculous Page Builder: Pagelayer – Drag and Drop website builder — Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0022   13.0     —
AFFECTED
  Product                                                  Versions     Fixed
  Page Builder: Pagelayer – Drag and Drop website builder  unspecified  —
TIMELINE
  Feb 26  Reserved by CNA
  Jun 13  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 2 references · NVD status: Deferred
tigroumeow Meow Gallery — Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0021   12.0     —
AFFECTED
  Product       Versions     Fixed
  Meow Gallery  unspecified  —
TIMELINE
  Jan 21  Reserved by CNA
  Jun 13  Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · 6 references · NVD status: Deferred
CodeAstro Student Attendance Management System createStudents.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0021   12.1     —
AFFECTED
  Product                               Versions  Fixed
  Student Attendance Management System  1.0 –     —
TIMELINE
  Jun 13  Reserved by CNA
  Jun 13  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
codesupplyco Canvas — Canvas <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Block Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0020   10.1     —
AFFECTED
  Product  Versions     Fixed
  Canvas   unspecified  —
TIMELINE
  May 26  Reserved by CNA
  Jun 13  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 6 references · NVD status: Deferred
Google MCP Toolbox for Databases — The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all i…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    9.4   .0015    5.0     —
AFFECTED
  Product                    Versions     Fixed
  MCP Toolbox for Databases  unspecified  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 13  Published (CNA: Google)
CWE-346 · CNA: Google · 2 references · NVD status: Awaiting Analysis
Unknown Store Locator WordPress — Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   R  U  L  L  N    3.5   .0014    4.3     —
AFFECTED
  Product                  Versions     Fixed
  Store Locator WordPress  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 13  Published (CNA: WPScan)
CWE-79 · CNA: WPScan · 1 reference · NVD status: Deferred
Red Hat Red Hat Enterprise Linux 8 — Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0014    4.0     —
AFFECTED
  Product                     Versions     Fixed
  Red Hat Enterprise Linux 8  unspecified  0:2.10.9-26.el8_10
  Red Hat Enterprise Linux 6  unspecified  —
  Red Hat Enterprise Linux 7  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Jun 13  Published (CNA: redhat)
CWE-59 · CNA: redhat · 4 references · NVD status: Modified
Red Hat Red Hat Enterprise Linux 8 — Abrt: unsanitized systemd journal content written to dump directory files enables content injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  N  H  N    5.5   .0013    3.1     —
AFFECTED
  Product                     Versions     Fixed
  Red Hat Enterprise Linux 8  unspecified  0:2.10.9-26.el8_10
  Red Hat Enterprise Linux 6  unspecified  —
  Red Hat Enterprise Linux 7  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Jun 13  Published (CNA: redhat)
CWE-74 · CNA: redhat · 3 references · NVD status: Modified
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support — Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump directories
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0010    1.1     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:2.1.11-61.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  0:2.10.9-26.el8_10
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:2.10.9-25.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:2.10.9-25.el8_4.1
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:2.10.9-25.el8_6.1
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:2.10.9-25.el8_6.1
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:2.10.9-25.el8_8.1
  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions         unspecified  0:2.10.9-25.el8_8.1
  Red Hat Enterprise Linux 6                                             unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Jun 13  Published (CNA: redhat)
CWE-367 · CNA: redhat · 8 references · NVD status: Awaiting Analysis
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support — Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   H   L   N  U  H  H  H    7.0   .0009    0.6     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:2.1.11-61.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  0:2.10.9-26.el8_10
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:2.10.9-25.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:2.10.9-25.el8_4.1
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:2.10.9-25.el8_6.1
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:2.10.9-25.el8_6.1
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:2.10.9-25.el8_8.1
  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions         unspecified  0:2.10.9-25.el8_8.1
  Red Hat Enterprise Linux 6                                             unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Jun 13  Published (CNA: redhat)
CWE-362 · CNA: redhat · 8 references · NVD status: Awaiting Analysis

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-13 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.