17 CVEs published June 14, 2026: 1 critical, 10 high, 4 medium, 2 low; 0 in KEV; 0 with a public exploit reference; 0 awaiting enrichment.
Yesterday's Results
17 CVEs published. 17 box scores, 0 table rows — nothing truncated.
Ruijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N H N H H H 7.3 .0238 82.5 —
AFFECTED
Product Versions Fixed
EG105G-P 2.340 – —
TIMELINE
Jun 14 Reserved by CNA
Jun 14 Published (CNA: VulDB)
GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0197 78.7 —
AFFECTED
Product Versions Fixed
GL-MT3000 4.4.0 – 4.7
TIMELINE
Jun 14 Reserved by CNA
Jun 14 Published (CNA: VulDB)
GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0194 78.4 —
AFFECTED
Product Versions Fixed
GL-MT3000 4.4.0 – 4.7
TIMELINE
Jun 14 Reserved by CNA
Jun 14 Published (CNA: VulDB)
RURBAN GD — GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0135 69.2 —
AFFECTED
Product Versions Fixed
GD unspecified —
TIMELINE
Jun 7 Reserved by CNA
Jun 14 Published (CNA: CPANSec)
SHLOMIF Config::IniFiles — Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L N R C H H H 8.6 .0107 62.0 —
AFFECTED
Product Versions Fixed
Config::IniFiles unspecified —
TIMELINE
Jun 7 Reserved by CNA
Jun 14 Published (CNA: CPANSec)
debevv nanoMODBUS — nanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length Field
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L H 7.8 .0054 42.9 —
AFFECTED
Product Versions Fixed
nanoMODBUS unspecified —
TIMELINE
Jun 13 Reserved by CNA
Jun 14 Published (CNA: TuranSec)
LiamBindle MQTT-C — MQTT-C Heap Out-of-Bounds Read and Integer Underflow in mqtt_unpack_publish_response()
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L N H 7.8 .0041 33.9 —
AFFECTED
Product Versions Fixed
MQTT-C unspecified —
TIMELINE
Jun 13 Reserved by CNA
Jun 14 Published (CNA: TuranSec)
driftregion iso14229 — iso14229 Integer Underflow and Out-of-Bounds Read in Handle_0x27_SecurityAccess()
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L N H 7.8 .0041 33.9 —
AFFECTED
Product Versions Fixed
iso14229 unspecified —
TIMELINE
Jun 13 Reserved by CNA
Jun 14 Published (CNA: TuranSec)
Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H P N N H N N 6.9 .0033 26.2 —
AFFECTED
Product Versions Fixed
Linux-PAM unspecified —
TIMELINE
Jun 13 Reserved by CNA
Jun 14 Published (CNA: TuranSec)
GALAYOU Y4 Web Server buffer overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
A L N N N H H H 7.4 .0032 24.4 —
AFFECTED
Product Versions Fixed
Y4 1.0.0 – —
TIMELINE
Jun 14 Reserved by CNA
Jun 14 Published (CNA: VulDB)
OpenStack Ironic — In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is …
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N C H N N 6.8 .0029 21.5 —
AFFECTED
Product Versions Fixed
Ironic 17.0.0 – —
TIMELINE
Jun 14 Reserved by CNA
Jun 14 Published (CNA: mitre)
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0020 9.7 —
AFFECTED
Product Versions Fixed
Grit 0.1 – —
TIMELINE
Jun 14 Public exploit reference published
Jun 14 Reserved by CNA
Jun 14 Published (CNA: VulDB)
Unknown Iptanus File Upload — Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H L R U N H L 5.4 .0016 5.5 —
AFFECTED
Product Versions Fixed
Iptanus File Upload unspecified —
TIMELINE
Jan 26 Reserved by CNA
Jun 14 Published (CNA: WPScan)
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
L L N L N H H H 7.1 .0014 4.0 —
AFFECTED
Product Versions Fixed
RevoUninstaller 2.5.* – 2.7.0
TIMELINE
Jun 14 Reserved by CNA
Jun 14 Published (CNA: VulDB)
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
L L N L N H H H 7.1 .0014 3.6 —
AFFECTED
Product Versions Fixed
Openpilot 0.11 – —
TIMELINE
Jun 14 Reserved by CNA
Jun 14 Published (CNA: VulDB)
Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
L L N L N L L L 4.8 .0010 1.2 —
AFFECTED
Product Versions Fixed
AI Workspace App 2.8.4 – —
TIMELINE
Jun 14 Reserved by CNA
Jun 14 Published (CNA: VulDB)
Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
L L N L N L L L 1.9 .0010 1.2 —
AFFECTED
Product Versions Fixed
Bus & Public Transit App 1.18 – —
TIMELINE
Jun 14 Reserved by CNA
Jun 14 Published (CNA: VulDB)
Methodology
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-14 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.