boxscore/security
Tuesday, June 16, 2026 · all times UTC← 2026-06-15 · archive · 2026-06-17 →

Edition of June 16, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–546 of 546
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-223128.614.2RadiflowiSAP Smart CollectorCWE-798Use of Hard-coded Credentials Vulnerability in Radiflow iSAP Smart Collector
CVE-2026-487756.814.3langchain-ailanggraphCWE-502LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
CVE-2026-106394.814.3zephyrprojectzephyrCWE-416Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet i…
CVE-2026-01518.814.1GoogleAndroidCWE-190In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write du…
CVE-2026-01548.814.1GoogleAndroidCWE-120In Modem, there is a possible way to trigger a modem crash during a SIP REFER…
CVE-2026-01608.814.1GoogleAndroidCWE-120In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, th…
CVE-2026-01618.814.1GoogleAndroidCWE-190In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds …
CVE-2026-01628.814.1GoogleAndroidCWE-843In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption…
CVE-2026-01648.814.1GoogleAndroidCWE-120In Modem, there is a possible out of bounds write due to a missing bounds che…
CVE-2026-467706.114.1Oracle CorporationOracle Application Development Framework (ADF)CWE-284Vulnerability in the Oracle Application Development Framework (ADF) product o…
CVE-2026-527127.613.8tnomiAttendance ManagerCWE-89WordPress Attendance Manager plugin <= 0.6.2 - SQL Injection vulnerability
CVE-2026-100936.413.8deepakkiteSecure Client Portal and Private File Sharing Plugin – User Private FilesCWE-79File Sharing & Download Manager <= 2.1.6 - Authenticated (Subscriber+) Stored…
CVE-2026-91875.313.8zealopensourceAbandoned Contact Form 7CWE-862Abandoned Contact Form 7 <= 2.2 - Missing Authorization to Unauthenticated Ar…
CVE-2026-123256.513.6MozillaFirefoxCWE-400Denial-of-service in the Graphics: ImageLib component
CVE-2026-538578.613.4OpenClawOpenClawCWE-290OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy
CVE-2025-680457.513.5ArrayticsWP Event SOlutionCWE-862WordPress WP Event SOlution plugin <= 4.1.12 - Broken Access Control vulnerab…
CVE-2026-527117.513.5kilbotWooCommerce POSCWE-862WordPress WooCommerce POS plugin <= 1.8.14 - Broken Access Control vulnerability
CVE-2026-445876.113.2carrierwaveuploadercarrierwaveCWE-79CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metachar…
CVE-2026-538406.013.2OpenClawOpenClawCWE-522OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Or…
CVE-2026-476847.713.0Sync-inserverCWE-918Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regE…
CVE-2026-123034.313.0MozillaFirefoxCWE-125Information disclosure due to incorrect boundary conditions in the Graphics: …
CVE-2026-395988.012.9Kodezen LLCAcademy LMS ProCWE-434WordPress Academy LMS Pro plugin < 3.5.2 - Arbitrary File Upload vulnerability
CVE-2026-487808.212.5foremforemCWE-287Forem vulnerable to bypass of email address domain restrictions
CVE-2026-487769.112.3langchain-ailangchain-aiCWE-22LangGraph SDK has unsafe URL path construction
CVE-2026-467869.611.7Oracle CorporationOracle WebCenter ContentCWE-352Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-01567.511.7GoogleAndroidCWE-476In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safe…
CVE-2026-123196.511.5MozillaFirefoxCWE-400Denial-of-service in the Audio/Video: Playback component
CVE-2026-538446.011.5OpenClawOpenClawCWE-862OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search
CVE-2026-538596.011.5OpenClawOpenClawCWE-918OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency
CVE-2026-487819.911.4gitroomhqpostiz-appCWE-302Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
CVE-2026-123247.311.3MozillaFirefoxCWE-703Incorrect boundary conditions in the Graphics: CanvasWebGL component
CVE-2026-17645.611.3Red HatRed Hat Enterprise Linux 10CWE-125Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer ove…
CVE-2025-712618.611.2SUSEHarvesterCWE-295Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
CVE-2026-123225.411.1MozillaFirefoxCWE-1021Clickjacking issue in the Widget: Gtk component
CVE-2026-479647.811.0AdobeDNG SDKCWE-122DNG SDK | Heap-based Buffer Overflow (CWE-122)
CVE-2026-538522.311.0OpenClawOpenClawCWE-636OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing
CVE-2026-490738.510.8wpWaxDirectorist BookingCWE-89WordPress Directorist Booking plugin <= 3.0.3 - SQL Injection vulnerability
CVE-2026-395775.510.9Elated-ThemesPlayroomCWE-502WordPress Playroom theme <= 1.4.1 - PHP Object Injection vulnerability
CVE-2026-107804.310.8mohammadtanzilurrahmanStatic BlockCWE-639Static Block <= 2.2 - Insecure Direct Object Reference to Authenticated (Cont…
CVE-2026-477497.810.6leejetstable-diffusion.cppCWE-122stable-diffusion.cpp: Heap buffer overflow in SHORT_BINUNICODE parsing for Py…
CVE-2026-352728.410.2Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-269Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-01414.310.2GoogleAndroidCWE-120In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to …
CVE-2024-304765.410.0DellPowerStoreCWE-79PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerS…
CVE-2026-541917.19.9Pods FrameworkPodsCWE-79WordPress Pods plugin <= 3.3.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-541987.19.9David LingrenMedia LIbrary AssistantCWE-79WordPress Media LIbrary Assistant plugin <= 3.35 - Reflected Cross Site Scrip…
CVE-2026-467859.39.7Oracle CorporationOracle WebCenter ContentCWE-352Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-408096.59.7Rara ThemesMetro MagazineCWE-862WordPress Metro Magazine theme <= 1.4.1 - Broken Access Control vulnerability
CVE-2026-241557.89.4NVIDIANeMo FrameworkCWE-94NVIDIA NeMo Framework for all platforms contains a code injection vulnerabili…
CVE-2026-538516.39.1OpenClawOpenClawCWE-862OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass
CVE-2026-123049.18.9MozillaFirefoxCWE-346Same-origin policy bypass in the Networking: Cookies component
CVE-2026-26045.68.9GNOMEEvolution Data ServerCWE-73Evolution-data-server: evolution data server: arbitrary file deletion via inc…
CVE-2026-352888.28.7Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-269Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-538412.18.7OpenClawOpenClawCWE-83OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Expo…
CVE-2026-488697.18.5KriesiEnfoldCWE-79WordPress Enfold theme <= 7.1.4 - Reflected Cross Site Scripting (XSS) vulner…
CVE-2026-123114.78.4MozillaFirefoxCWE-200Information disclosure, sandbox escape in the Security: Process Sandboxing co…
CVE-2026-538452.38.3OpenClawOpenClawCWE-693OpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call…
CVE-2026-538482.38.4OpenClawOpenClawCWE-184OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers
CVE-2026-01286.58.1GoogleAndroidCWE-190In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read d…
CVE-2026-477477.87.9leejetstable-diffusion.cppCWE-122stable-diffusion.cpp has a Heap-based Buffer Overflow
CVE-2026-477507.87.9leejetstable-diffusion.cppCWE-787stable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTor…
CVE-2025-691517.17.8ThemeGoodsGrand Car RentalCWE-79WordPress Grand Car Rental theme <= 3.7 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-468696.57.9Oracle CorporationMySQL ShellCWE-352Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: D…
CVE-2026-123204.37.7MozillaFirefoxCWE-200Information disclosure in the Password Manager component
CVE-2026-01404.37.6GoogleAndroidCWE-125In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an …
CVE-2026-538475.37.5OpenClawOpenClawCWE-266OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope
CVE-2026-395487.17.3SneeitMagOneCWE-79WordPress MagOne theme <= 9.0 - Reflected Cross Site Scripting (XSS) vulnerab…
CVE-2026-123134.77.3MozillaFirefoxCWE-269Information disclosure, sandbox escape in the Security: Process Sandboxing co…
CVE-2026-01303.57.1GoogleAndroidCWE-122In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to …
CVE-2026-420898.67.0yeomanenvironmentCWE-829yeoman-environment Vulnerable to Arbitrary Package Installation without User …
CVE-2026-527145.96.9SEO SquirrlySEO Plugin by Squirrly SEOCWE-862WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.16 - Broken Access Contro…
CVE-2026-01655.76.8GoogleAndroidCWE-120In several functions of the RTCP packet decoder, there is a possible out-of-b…
CVE-2026-538602.36.8OpenClawOpenClawCWE-807OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifie…
CVE-2025-116948.76.7Rockwell AutomationCompactLogix 5370CWE-354Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities
CVE-2026-487834.86.8gitroomhqpostiz-appCWE-345Postiz has an unauthenticated billing-enforcement bypass via /public/modify-s…
CVE-2026-538636.06.7OpenClawOpenClawCWE-639OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy
CVE-2026-01554.36.6GoogleAndroidCWE-120In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a m…
CVE-2026-01574.36.6GoogleAndroidCWE-120In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missin…
CVE-2026-468658.26.6Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-468948.06.5Oracle CorporationOracle iSupplier PortalCWE-352Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui…
CVE-2026-123235.46.5MozillaFirefoxCWE-1021Spoofing issue in the DOM: Core & HTML component
CVE-2026-01293.56.6GoogleAndroidCWE-120In RtcpByePacket::decodeByePacket, there is a possible due to a missing bound…
CVE-2026-468776.06.4Oracle CorporationOracle VM VirtualBoxCWE-269Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-479275.56.2AdobeDNG SDKCWE-125DNG SDK | Out-of-bounds Read (CWE-125)
CVE-2026-479345.56.2AdobeDNG SDKCWE-125DNG SDK | Out-of-bounds Read (CWE-125)
CVE-2026-479635.56.2AdobeDNG SDKCWE-125DNG SDK | Out-of-bounds Read (CWE-125)
CVE-2026-106356.36.0zephyrprojectzephyrCWE-416Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code…
CVE-2026-123305.46.1MozillaFirefoxCWE-119Incorrect boundary conditions in the Internationalization component
CVE-2026-477485.56.0leejetstable-diffusion.cppCWE-125stable-diffusion.cpp: Out-of-bounds reads in PyTorch checkpoint pickle opcode…
CVE-2026-468153.25.9Oracle CorporationOracle VM VirtualBoxCWE-200Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-468163.25.9Oracle CorporationOracle VM VirtualBoxCWE-200Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-469773.25.9Oracle CorporationOracle VM VirtualBoxCWE-200Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-242287.85.8NVIDIANeMo FrameworkCWE-502NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker ma…
CVE-2026-467878.05.7Oracle CorporationOracle WebCenter ContentCWE-352Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468256.05.6Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-123215.45.6MozillaFirefoxCWE-670JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-17666.15.5Red HatRed Hat Enterprise Linux 10CWE-805Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of servi…
CVE-2026-469557.55.3Oracle CorporationOracle Human ResourcesCWE-79Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit…
CVE-2026-469147.15.1Oracle CorporationOracle SolarisCWE-269Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fil…
CVE-2026-420146.64.7Red HatRed Hat Enterprise Linux 10CWE-825Gnutls: gnutls: use-after-free in gnutls_pkcs11_token_set_pin
CVE-2026-467686.04.7Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-124255.74.6PowerSchoolEmployee Access CenterCWE-79Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Acce…
CVE-2026-352757.54.5Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-120035.34.4Python Software FoundationCPythonCWE-427CPython >3.11 Insecure Input Validation resulting in privilege escalation
CVE-2026-394377.14.0WPFactoryMin Max Step Quantity Limits Manager for WooCommerceCWE-79WordPress Min Max Step Quantity Limits Manager for WooCommerce plugin <= 5.2.…
CVE-2026-468487.94.0Oracle CorporationWebLogic ServerCWE-284Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-469139.33.9Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-469747.53.9Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-84844.83.9FuseSourcejansiCWE-122Heap buffer overflow in Jansi
CVE-2026-17655.63.7Red HatRed Hat Enterprise Linux 10CWE-125Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of servi…
CVE-2026-467714.13.4Oracle CorporationOracle Application Development Framework (ADF)CWE-284Vulnerability in the Oracle Application Development Framework (ADF) product o…
CVE-2026-538427.03.3OpenClawOpenClawCWE-426OpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON …
CVE-2026-467724.73.2Oracle CorporationOracle Application Development Framework (ADF)CWE-284Vulnerability in the Oracle Application Development Framework (ADF) product o…
CVE-2026-43675.52.9Red HatRed Hat Hardened ImagesCWE-125Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing
CVE-2026-468743.23.0Oracle CorporationOracle VM VirtualBoxCWE-200Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-538587.02.6OpenClawOpenClawCWE-426OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTOR…
CVE-2026-538657.22.5OpenClawOpenClawCWE-426OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Servi…
CVE-2026-469268.82.1Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-468887.82.1Oracle CorporationSiebel CRM DeploymentCWE-284Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-538467.02.0OpenClawOpenClawCWE-426OpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env…
CVE-2025-102626.31.9NokiaSR LinuxCWE-134An unsanitized format validation vulnerability in Nokia SR Linux
CVE-2026-468737.51.7Oracle CorporationOracle VM VirtualBoxCWE-269Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2025-99126.31.5NokiaNokia SR LinuxCWE-269A local privilege escalation vulnerability in Nokia SR Linux
CVE-2026-01357.81.1GoogleAndroidCWE-125In Modem, there is a possible out of bounds read due to a missing bounds chec…
CVE-2026-539004.31.0MozillaFirefox for iOSCWE-345Cookie injection was possible when opening a PDF link
CVE-2024-224516.70.9DellPeripheral ManagerCWE-427Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolle…
CVE-2024-224477.80.9DellPeripheral ManagerCWE-427Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled sea…
CVE-2024-395757.40.8DellDell EMC VxRail ApplianceCWE-256update_disk_psu_baseline.sh requires password in plain text
CVE-2026-538996.50.8MozillaFirefox for iOSCWE-345Cross-origin cookies could be leaked when opening a PDF link
CVE-2026-538565.70.7OpenClawOpenClawCWE-732OpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery…
CVE-2026-538506.80.7OpenClawOpenClawCWE-862OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command
CVE-2026-502555.40.5Sony CorporationOptical Disc Archive Software for WindowsCWE-276Incorrect default permissions issue exists in Optical Disc Archive Software f…
CVE-2026-538622.30.5OpenClawOpenClawCWE-266OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening
CVE-2024-384877.00.2DellEMC VxRail ApplianceCWE-269api-gateway container running with root privilege would allow an attacker to …
CVE-2026-01377.80.1GoogleAndroidCWE-416In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possib…
CVE-2026-01387.80.1GoogleAndroidCWE-120In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bound…
CVE-2026-01437.80.1GoogleAndroidCWE-416In lwis_device_external_event_emit of lwis_event.c, there is a possible memor…
CVE-2026-01317.30.1GoogleAndroidCWE-125In RtpPacket::decodePacket, there is a possible out of bounds access due to a…
CVE-2026-01343.30.1GoogleAndroidCWE-1188In PostWipeData of recovery_ui.cpp, there is a possible data persistence issu…
CVE-2026-01527.80.1GoogleAndroidCWE-119In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system…
CVE-2026-01423.30.0GoogleAndroidCWE-20In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read d…
CVE-2026-01537.80.0GoogleAndroidCWE-787In Write of msg_to_host_buffer.cc, there is a possible out of bounds write du…
CVE-2026-01453.30.0GoogleAndroidCWE-862In keymint, there is a possible Permission Bypass due to a logic error in the…
CVE-2026-01337.80.0GoogleAndroidCWE-862In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign maliciou…
CVE-2026-01507.80.0GoogleAndroidCWE-190In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out …
CVE-2026-01257.00.0GoogleAndroidCWE-416In multiple functions of vpu_ioctl.c, there is a possible use after free due …
CVE-2026-01583.30.0GoogleAndroidCWE-862In Camera, there is a possible unauthorized way to access photos due to a mis…