boxscore/security
Wednesday, June 17, 2026 · all times UTC← 2026-06-16 · archive · 2026-06-18 →

396 CVEs published June 17, 2026: 90 critical, 196 high, 101 medium, 9 low; 0 in KEV; 7 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 371 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published4717908910712563
KEV catalog size1670

424 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9710638466431212730.37.8.0013-118
google68085480449293297460.78.1.0023+680
microsoft208698524671584378273.97.8.0043+69
red hat65129857586400.07.0.0028+61
apple146101636293711.55.7.0023+1
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse240400000.08.6.0021+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco9224380961045.56.8.0257+8
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
f56943107111.18.9.0221+5
ivanti49230033555.68.8.5187+3
checkpoint3915303111.17.5.0410+3
ubiquiti584400400.08.9.0052+5
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache7410618414424010.97.3.0050+70
mozilla495511182601300.07.3.0026+45
gitlab1120041224210.04.8.0024+11
docker250500100.08.8.0021+2
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1291334497527532.35.5.0021+129
ibm11601329180700.07.5.0028+11
progress591710900.07.5.0036+5
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+9
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb550410000.07.2.0018+5
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
hitachi energy020020000.05.7.00140
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+37
themerex585855300000.08.1.0043+58
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2
dell2644020230212.36.7.0016+26
open ises044221210000.07.1.00210

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2008-4250.987599.9
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2010-0249.918899.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-2022310.0.0083
CVE-2026-4714010.0.0082
Most disclosures (vendor)
VendorCVEs
google848
linux522
oracle268
microsoft235
adobe130
red hat101
apache91
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco10
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven42
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171673
CVE-2021-27102Accellion2021-11-171673
CVE-2021-27101Accellion2021-11-171673
CVE-2021-27103Accellion2021-11-171673
CVE-2021-21017Adobe2021-11-171673
CVE-2021-28550Adobe2021-11-171673
CVE-2021-42013Apache2021-11-171673
CVE-2021-41773Apache2021-11-171673
CVE-2021-30858Apple2021-11-171673
CVE-2021-30860Apple2021-11-171673

Transactions

EXPLOIT PUBLISHEDCVE-2026-10641 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10850 (Plane). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47103 (fgmacedo python-statemachine). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47774 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48988 (markdown-it). Public exploit reference added.

Yesterday's Results

396 CVEs published. 25 box scores, 371 table rows — nothing truncated.

F5 NGINX Open Source — NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0402   89.7     —
AFFECTED
  Product            Versions   Fixed
  NGINX Open Source  1.13.10 –  —
  NGINX Plus         37.0 –     —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 17  Published (CNA: f5)
CWE-787, CWE-122, CWE-131 · CNA: f5 · 12 references · NVD status: Analyzed
F5 NGINX Open Source — NGINX Open-Source ngx_http_v3_module vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.2   .0368   88.7     —
AFFECTED
  Product            Versions  Fixed
  NGINX Open Source  1.31.0 –  —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 17  Published (CNA: f5)
CWE-416 · CNA: f5 · 5 references · NVD status: Modified
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0203   79.4     —
AFFECTED
  Product  Versions     Fixed
  libssh2  unspecified  7acf3dfda80c91c3a8c9f2372546301d4a1a7a8
TIMELINE
  Jun 16  Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-680 · CNA: VulnCheck · 4 references · NVD status: Analyzed
Micro-Star International Co., Ltd. RadiX AX6600 WiFi 6 Tri-Band Gaming Router — RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead t…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0179   76.4     —
AFFECTED
  Product                                     Versions                              Fixed
  RadiX AX6600 WiFi 6 Tri-Band Gaming Router  firmware versions prior to v781521 –  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 17  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · 2 references · NVD status: Deferred
fgmacedo python-statemachine — Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0117   64.8     —
AFFECTED
  Product              Versions  Fixed
  python-statemachine  3.0.0 –   —
TIMELINE
  May 18  Reserved by CNA
  Jun 17  Public exploit reference published
  Jun 17  Published (CNA: VulnCheck)
CWE-94, CWE-95 · CNA: VulnCheck · 3 references · NVD status: Analyzed
envoyproxy envoy — Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0097   58.8     —
AFFECTED
  Product  Versions     Fixed
  envoy    < 1.35.11 –  —
TIMELINE
  May 19  Reserved by CNA
  Jun 17  Public exploit reference published
  Jun 17  Published (CNA: GitHub_M)
CWE-405, CWE-770, CWE-409 · CNA: GitHub_M · 10 references · NVD status: Analyzed
libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0092   57.3     —
AFFECTED
  Product  Versions     Fixed
  libssh2  unspecified  17626857d20b3c9a1addfa45979dadcee1cd84a4
TIMELINE
  Jun 16  Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-835 · CNA: VulnCheck · 3 references · NVD status: Analyzed
nv-tlabs GEN3C — NVIDIA SIL GEN3C Unauthenticated RCE via Pickle Deserialization in Inference API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0087   55.9     —
AFFECTED
  Product  Versions     Fixed
  GEN3C    unspecified  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 4 references · NVD status: Awaiting Analysis
undici WebSocket client vulnerable to denial of service via fragment count bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0079   53.2     —
AFFECTED
  Product  Versions     Fixed
  undici   unspecified  6.26.0
TIMELINE
  Jun 12  Reserved by CNA
  Jun 17  Published (CNA: openjs)
CWE-400, CWE-770 · CNA: openjs · 23 references · NVD status: Modified
picklescan - Remote Code Execution via Unblocked ctypes Module
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0076   52.2     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  0.0.33
TIMELINE
  Jun 8   Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-184 · CNA: VulnCheck · 2 references · NVD status: Deferred
Cisco Identity Services Engine Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0075   51.9     —
AFFECTED
  Product                                  Versions  Fixed
  Cisco Identity Services Engine Software  3.1.0 –   —
  Cisco ISE Passive Identity Connector     3.2.0 –   —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 17  Published (CNA: cisco)
CWE-22 · CNA: cisco · 1 reference · NVD status: Analyzed
e107inc e107 — e107: Command Injection via shell expansion in ImageMagick resize destination path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  L  H  H    7.1   .0075   51.9     —
AFFECTED
  Product  Versions   Fixed
  e107     < 2.3.6 –  —
TIMELINE
  May 26  Reserved by CNA
  Jun 17  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 2 references · NVD status: Deferred
Melapress WP Activity Log — WordPress WP Activity Log plugin <= 5.6.3.1 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.1     —
AFFECTED
  Product          Versions  Fixed
  WP Activity Log  n/a –     5.6.4
TIMELINE
  Jun 16  Reserved by CNA
  Jun 17  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · 1 reference · NVD status: Deferred
F5 NGINX Open Source — NGINX ngx_http_charset_module vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   L   N   L    6.3   .0068   49.6     —
AFFECTED
  Product            Versions   Fixed
  NGINX Open Source  1.13.10 –  —
  NGINX Plus         37.0 –     —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 17  Published (CNA: f5)
CWE-125 · CNA: f5 · 1 reference · NVD status: Analyzed
Splunk Splunk AI Toolkit — OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0063   47.4     —
AFFECTED
  Product            Versions  Fixed
  Splunk AI Toolkit  5.7 –     —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 17  Published (CNA: cisco)
CWE-78 · CNA: cisco · 1 reference · NVD status: Analyzed
Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory allows local file write outside the destination directory via malicious server-supplied directory-entry names
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0063   47.1     —
AFFECTED
  Product                       Versions     Fixed
  Apache Airflow SFTP provider  unspecified  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 17  Published (CNA: apache)
CWE-22 · CNA: apache · 3 references · NVD status: Analyzed
picklescan - Arbitrary File Writing via distutils Module Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0062   47.0     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  0.0.33
TIMELINE
  Jun 8   Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 2 references · NVD status: Deferred
picklescan - Universal Blocklist Bypass via pkgutil.resolve_name
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0062   47.0     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  1.0.4
TIMELINE
  Mar 3   Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-183 · CNA: VulnCheck · 2 references · NVD status: Deferred
picklescan - Remote Code Execution via Incomplete Disallowed Inputs
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0062   47.0     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  0.0.33
TIMELINE
  Jun 8   Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-184 · CNA: VulnCheck · 2 references · NVD status: Deferred
Pimcore CMS 12.3.8 Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0062   47.0     —
AFFECTED
  Product          Versions     Fixed
  Pimcore CMS/DXP  unspecified  fffa7f6396329e88610db70a8652529bbc734892
TIMELINE
  Jun 5   Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-1336 · CNA: VulnCheck · 3 references · NVD status: Deferred
Google Chrome — Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0061   46.5     —
AFFECTED
  Product  Versions          Fixed
  Chrome   149.0.7827.155 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 17  Published (CNA: Chrome)
CWE-416 · CNA: Chrome · 2 references · NVD status: Analyzed
ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0060   46.0     —
AFFECTED
  Product      Versions             Fixed
  ThingsBoard  prior to v4.3.1.2 –  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 17  Published (CNA: jpcert)
CWE-1321 · CNA: jpcert · 3 references · NVD status: Deferred
NousResearch hermes-agent — Hermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket Endpoints
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0059   45.5     —
AFFECTED
  Product       Versions     Fixed
  hermes-agent  unspecified  0.16.0
TIMELINE
  Jun 10  Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 5 references · NVD status: Deferred
hermes-webui hermes-webui — Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   N    9.1   .0058   44.9     —
AFFECTED
  Product       Versions     Fixed
  hermes-webui  unspecified  0.51.409
TIMELINE
  Jun 16  Reserved by CNA
  Jun 17  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 5 references · NVD status: Deferred
F5 NGINX Gateway Fabric — NGINX Gateway Fabric vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   N    8.6   .0057   44.3     —
AFFECTED
  Product               Versions  Fixed
  NGINX Gateway Fabric  2.5.0 –   —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 17  Published (CNA: f5)
CWE-74, CWE-76 · CNA: f5 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-83835.344.1UnknownLearnPressCWE-862LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure vi…
CVE-2026-497679.843.3TomdeverwpForo ForumCWE-288WordPress wpForo Forum plugin <= 3.1.0 - Broken Authentication vulnerability
CVE-2026-407839.943.0Creative ThemesBlocksy Companion ProCWE-94WordPress Blocksy Companion Pro plugin <= 2.1.37 - Remote Code Execution (RCE…
CVE-2026-274008.642.9OvathemeBookProCWE-22WordPress BookPro plugin <= 1.1.0 - Arbitrary File Deletion vulnerability
CVE-2025-602059.842.1ThemeREXThemeREX AddonsCWE-502WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerabi…
CVE-2026-538749.341.7picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Obfuscated eval Call
CVE-2026-121156.641.8wpcalcCounter Box – Add Countdowns, Timers & Dynamic Counters to WordPressCWE-502Counter Box <= 2.0.13 - Authenticated (Administrator+) PHP Object Injection v…
CVE-2026-423809.841.2jwsthemesAI LabCWE-502WordPress AI Lab theme < 5.4.2 - PHP Object Injection vulnerability
CVE-2026-538728.741.1picklescanpicklescanCWE-22picklescan - Arbitrary File Read via Unsafe Pickle Deserialization
CVE-2026-201907.540.8CiscoCisco Identity Services Engine SoftwareCWE-285Cisco Identity Services Engine Information Disclosure Vulnerability
CVE-2026-492688.840.2Apache Software FoundationApache ShiroCWE-90Apache Shiro: LDAP DN Injection in DefaultLdapRealm
CVE-2026-527078.140.2Mikado-ThemesKastellCWE-35WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability
CVE-2026-501078.640.1F5NGINX Gateway FabricCWE-74NGINX Gateway Fabric vulnerability
CVE-2025-691308.839.5ThemovationEntrepreneur - Booking for Small Businesses WordPress ThemeCWE-502WordPress Entrepreneur - Booking for Small Businesses WordPress Theme theme <…
CVE-2025-713259.339.1picklescanpicklescanCWE-391picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw
CVE-2024-524889.938.7ZidithemesGripCWE-434WordPress Grip theme <= 1.0.9 - Arbitrary Plugin Activation/Deactivation to R…
CVE-2026-364189.138.7n/an/aCWE-94JimuReport versions 2.3.4 and below are vulnerable to remote code execution d…
CVE-2026-96907.538.5JoomunitedWP Media folder AddonCWE-22WordPress WP Media folder Addon plugin <= 4.0.1 - Arbitrary File Download vul…
CVE-2026-223347.538.5WPosWoocommerce Book PriceCWE-22WordPress Woocommerce Book Price plugin <= 1.3 - Arbitrary File Download vuln…
CVE-2026-527069.838.4Jetimpex Inc.JetEngineCWE-502WordPress JetEngine plugin <= 3.8.10 - PHP Object Injection vulnerability
CVE-2026-223279.938.4ZozothemesRestaurtCWE-434WordPress Restaurt theme <= 1.0.4 - Arbitrary File Upload vulnerability
CVE-2026-538739.338.0picklescanpicklescanCWE-184picklescan - Arbitrary Code Execution via profile.run() Blocklist Bypass
CVE-2025-691288.638.0EMVJobCareerCWE-22WordPress JobCareer theme <= 7.3 - Arbitrary File Deletion vulnerability
CVE-2026-96977.438.0undiciundiciCWE-295undici vulnerable to TLS certificate validation bypass via dropped requestTls…
CVE-2025-598729.837.6HCL SoftwareZIECWE-434HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,
CVE-2025-691799.837.4Theme passionSupport Ticket Management SystemCWE-266WordPress Support Ticket Management System plugin <= 1.9 - Privilege Escalati…
CVE-2026-548039.837.4Cozy Vision Technologies Pvt. Ltd.SMS Alert Order NotificationsCWE-863WordPress SMS Alert Order Notifications plugin <= 3.9.4 - Privilege Escalatio…
CVE-2025-602237.737.4QuantumCloudWPBot Pro Wordpress ChatbotCWE-22WordPress WPBot Pro Wordpress Chatbot plugin <= 13.6.5 - Arbitrary File Delet…
CVE-2026-395899.937.3A WP LifeWebenvoCWE-434WordPress Webenvo theme <= 0.0.6 - Arbitrary File Upload vulnerability
CVE-2025-602189.937.1WPLockerPT Luxa AddonsCWE-434WordPress PT Luxa Addons Plugin <= 1.2.2 - Arbitrary File Upload Vulnerability
CVE-2026-543879.336.5tinyproxytinyproxyCWE-444Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization
CVE-2026-543889.336.5tinyproxytinyproxyCWE-444Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers
CVE-2026-548079.836.4ThemeGrillRegistration Form for WooCommerceCWE-266WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escal…
CVE-2026-246119.136.4WPMetMetForm ProCWE-862WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability
CVE-2026-412804.936.4Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: Incorrect Authorization vulnerability allows users w…
CVE-2025-691068.136.3ThemeREXImbaCWE-98WordPress Imba theme <= 1.5.0 - Local File Inclusion vulnerability
CVE-2025-691108.136.3ThemeREXAirSupplyCWE-98WordPress AirSupply theme <= 2.0.0 - Local File Inclusion vulnerability
CVE-2025-691178.136.3ThemeREXIngeniosoCWE-98WordPress Ingenioso theme <= 1.14.0 - Local File Inclusion vulnerability
CVE-2025-691208.136.3ThemeREXDazzleCWE-98WordPress Dazzle theme <= 1.0.0 - Local File Inclusion vulnerability
CVE-2025-691488.136.3ThemeREXQuirkyCWE-98WordPress Quirky theme <= 1.23 - Local File Inclusion vulnerability
CVE-2025-691578.136.3ThemeREXGamicCWE-98WordPress Gamic theme <= 1.15 - Local File Inclusion vulnerability
CVE-2025-691668.136.3ThemeREXGunslingerCWE-98WordPress Gunslinger theme <= 1.7 - Local File Inclusion vulnerability
CVE-2025-691728.136.2ThemeREXResursCWE-98WordPress Resurs theme <= 1.3 - Local File Inclusion vulnerability
CVE-2025-691738.136.3ThemeREXTipsyCWE-98WordPress Tipsy theme <= 1.1 - Local File Inclusion vulnerability
CVE-2026-254469.936.1WishList Products, LLC.WishList Member XCWE-434WordPress WishList Member X plugin <= 3.29.0 - Arbitrary File Upload vulnerab…
CVE-2026-407469.936.1themagnifico52Restaurant ZoneCWE-434WordPress Restaurant Zone theme <= 0.7.8 - Arbitrary File Upload vulnerability
CVE-2026-407479.936.1themagnifico52Ecommerce ZoneCWE-434WordPress Ecommerce Zone theme <= 0.9.7 - Arbitrary File Upload vulnerability
CVE-2026-407489.936.1themagnifico52Kids Gift ShopCWE-434WordPress Kids Gift Shop theme <= 0.5.4 - Arbitrary File Upload vulnerability
CVE-2026-407499.936.1themagnifico52Charity ZoneCWE-434WordPress Charity Zone theme <= 1.1.1 - Arbitrary File Upload vulnerability
CVE-2026-538757.136.2picklescanpicklescanCWE-95picklescan - Scanning Bypass via Dynamic Eval in scan_pytorch
CVE-2026-473406.536.1Apache Software FoundationApache DolphinSchedulerCWE-200Apache DolphinScheduler: An incorrect authorization vulnerability allows auth…
CVE-2025-6912910.036.0ExtendonsWordPress & WooCommerce Scraper Plugin, Import Data from Any SiteCWE-434WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site p…
CVE-2024-327297.535.8QuantumCloudConversational Forms for ChatBotCWE-22WordPress ChatBot Conversational Forms plugin <= 1.1.8 - Arbitrary File Downl…
CVE-2025-602299.835.5ThemetonLagomCWE-502WordPress Lagom theme <= 2.0 - PHP Object Injection vulnerability
CVE-2025-602309.835.5ThemetonThe Barber ShopCWE-502WordPress The Barber Shop theme <= 1.9 - PHP Object Injection vulnerability
CVE-2026-124478.835.5GoogleChromeCWE-122Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allow…
CVE-2026-124668.835.5GoogleChromeCWE-122Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.782…
CVE-2026-96757.535.5undiciundiciCWE-400undici WebSocket client vulnerable to denial of service via cumulative fragme…
CVE-2025-589538.135.3ThemeREXJolyCWE-98WordPress Joly theme <= 1.22.0 - Local File Inclusion vulnerability
CVE-2025-589548.135.3ThemeREXHomeRooferCWE-98WordPress HomeRoofer theme <= 2.11.0 - Local File Inclusion vulnerability
CVE-2026-395378.135.3Mikado-ThemesMikado CoreCWE-98WordPress Mikado Core plugin <= 1.6 - Local File Inclusion vulnerability
CVE-2026-407318.135.3Mikado-ThemesChapterOneCWE-98WordPress ChapterOne theme <= 1.7 - Local File Inclusion vulnerability
CVE-2026-108395.135.0Password ManagerPassword ManagerCWE-601Open redirection vulnerability in Password Manager
CVE-2026-544178.734.8rximicrotarCWE-190Integer Overflow in rxi/microtar mtar_next() Causes Infinite Loop DoS
CVE-2026-407246.534.3Client Portal Ltd.Client Portal (Pro)CWE-22WordPress Client Portal (Pro) plugin <= 5.6.2 - Arbitrary File Download vulne…
CVE-2026-407217.533.2BdThemesElement Pack ProCWE-98WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability
CVE-2026-557388.733.0rximicrotarCWE-121Stack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated…
CVE-2026-489898.932.8CursorTouchWindows-MCPCWE-306Windows-MCP: HTTP transports expose unauthenticated PowerShell control with w…
CVE-2025-595549.332.8Advanced Ads GmbHAdvanced Ads – TrackingCWE-89WordPress Advanced Ads – Tracking plugin < 3.0.7 - SQL Injection vulnerability
CVE-2026-121658.832.8contest-galleryContest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-269Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via …
CVE-2026-124428.832.7GoogleChromeCWE-416Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.1…
CVE-2026-394458.132.6PressLayoutsAlukasCWE-502WordPress Alukas theme < 3.0.0 - PHP Object Injection vulnerability
CVE-2026-395458.132.6Select-ThemesZermattCWE-502WordPress Zermatt theme <= 1.6.1 - PHP Object Injection vulnerability
CVE-2026-395738.132.6Select-ThemesMildhillCWE-502WordPress Mildhill theme <= 1.5 - PHP Object Injection vulnerability
CVE-2026-395768.132.6Elated-ThemesSingleMaltCWE-502WordPress SingleMalt theme <= 1.5 - PHP Object Injection vulnerability
CVE-2026-407358.132.6Edge-ThemesReinaCWE-502WordPress Reina theme <= 2.1 - PHP Object Injection vulnerability
CVE-2026-278686.932.5TeldatRegesta Smart HD-PLC - TLDPH16D2CWE-201PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT
CVE-2026-278696.932.5TeldatRegesta Smart HD-PLC - TLDPH16D2CWE-770WEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC…
CVE-2025-262408.432.4n/an/aCWE-120In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution…
CVE-2026-329669.832.2Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to …
CVE-2025-691388.832.1JthemesGenemyCWE-266WordPress Genemy theme <= 1.6.6 - Privilege Escalation vulnerability
CVE-2026-557439.432.0tinyhumansaiOpenHumanCWE-78OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command …
CVE-2025-691119.831.8ThemeREXReisenCWE-502WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability
CVE-2025-691279.831.8ThemeREXPlumbingCWE-502WordPress Plumbing theme <= 1.6 - PHP Object Injection vulnerability
CVE-2026-453577.531.7harttleliquidjsCWE-400LiquidJS: Memory and render limit bypass via unbounded width padding in `date…
CVE-2026-456177.531.7harttleliquidjsCWE-1333LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
CVE-2025-713228.731.5PickleScanPickleScanCWE-693PickleScan - Unsafe Globals Check Bypass via pty.spawn Function
CVE-2025-663918.831.5n/an/aCWE-284In Citrix Cloud through 2025-11-10, an account with read-only access can trig…
CVE-2026-552028.831.3tinyproxytinyproxyCWE-290Tinyproxy - Stathost Detection Bypass via Host Header Manipulation
CVE-2026-100949.831.2Dassault SystèmesSOLIDWORKS VisualizeCWE-22Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS D…
CVE-2026-489885.331.0markdown-itmarkdown-itCWE-400markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt strin…
CVE-2025-595638.830.9SONAAR MUSICSonaarCWE-266WordPress Sonaar theme <= 4.27.4 - Privilege Escalation vulnerability
CVE-2026-548058.830.9sboueyFalang multilanguageCWE-266WordPress Falang multilanguage plugin <= 1.4.2 - Privilege Escalation vulnera…
CVE-2026-407259.830.6Barn2 Media LtdWooCommerce Product FiltersCWE-502WordPress WooCommerce Product Filters plugin < 2.0.6 - PHP Object Injection v…
CVE-2026-490759.830.6Jetimpex Inc.JetEngineCWE-502WordPress JetEngine plugin <= 3.8.9.1 - PHP Object Injection vulnerability
CVE-2026-491079.830.6Thrive ThemesThrive ApprenticeCWE-502WordPress Thrive Apprentice plugin < 10.8.10.2 - PHP Object Injection vulnera…
CVE-2026-223409.330.3Jobster MarketplaceWPJobsterCWE-89WordPress WPJobster theme <= 6.3.5 - SQL Injection vulnerability
CVE-2026-395969.330.3Creative ThemesBlocksy Companion ProCWE-89WordPress Blocksy Companion Pro plugin < 2.1.29 - SQL Injection vulnerability
CVE-2026-488759.330.3Jetimpex Inc.JetSmartFiltersCWE-89WordPress JetSmartFilters plugin <= 3.8.1 - SQL Injection vulnerability
CVE-2026-490769.330.3Jetimpex Inc.JetEngineCWE-89WordPress JetEngine plugin <= 3.8.9.1 - SQL Injection vulnerability
CVE-2026-548027.530.1Cozy Vision Technologies Pvt. Ltd.SMS Alert Order NotificationsCWE-862WordPress SMS Alert Order Notifications plugin <= 3.9.3 - Broken Authenticati…
CVE-2026-488187.529.9KludexstarletteCWE-918Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Win…
CVE-2026-538718.629.6nesquenahermes-webuiCWE-565Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged herm…
CVE-2026-80507.529.6SignalRGBSignalRGB kernel driverCVE-2026-8050
CVE-2026-223258.129.4AxiomThemesPromoCWE-98WordPress Promo theme <= 1.3.0 - Local File Inclusion vulnerability
CVE-2026-223308.129.4ThemeumRight WayCWE-98WordPress Right Way theme <= 4.0 - Local File Inclusion vulnerability
CVE-2026-223318.129.4ThemeREXAutoPartsCWE-98WordPress AutoParts theme <= 1.5.8 - Local File Inclusion vulnerability
CVE-2026-96785.929.1undiciundiciCWE-524undici vulnerable to cross-user information disclosure via shared cache white…
CVE-2026-557068.328.5OpenBSDOpenBSDCWE-1284sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows auth…
CVE-2026-350658.828.4DellPowerFlexCWE-306Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Aut…
CVE-2026-544158.627.8AzuriomAzuriom CMSCWE-269Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
CVE-2025-691158.127.9ThemeREXLuxMed | Medicine & Healthcare Doctor WordPress ThemeCWE-98WordPress LuxMed | Medicine & Healthcare Doctor WordPress Theme theme <= 1.2.…
CVE-2025-691238.127.9ThemeREXSnow ClubCWE-98WordPress Snow Club theme <= 1.1 - Local File Inclusion vulnerability
CVE-2025-691268.127.9ThemeREXFortiusCWE-98WordPress Fortius theme <= 2.3.0 - Local File Inclusion vulnerability
CVE-2025-691448.127.9ThemeREXPreservationCWE-98WordPress Preservation theme <= 1.10 - Local File Inclusion vulnerability
CVE-2025-691458.127.9ThemeREXGatCWE-98WordPress Gat theme <= 1.16 - Local File Inclusion vulnerability
CVE-2025-691588.127.9ThemeREXGranolaCWE-98WordPress Granola theme <= 1.13 - Local File Inclusion vulnerability
CVE-2025-691618.127.9ThemeREXSnowyCWE-98WordPress Snowy theme <= 1.13 - Local File Inclusion vulnerability
CVE-2025-691648.127.9ThemeREXSkywardCWE-98WordPress Skyward theme <= 1.10 - Local File Inclusion vulnerability
CVE-2025-691708.127.9ThemeREXEventicityCWE-98WordPress Eventicity theme <= 1.5 - Local File Inclusion vulnerability
CVE-2025-691718.127.9ThemeREXOrpheusCWE-98WordPress Orpheus theme <= 1.3 - Local File Inclusion vulnerability
CVE-2025-691748.127.9ThemeREXEtudeCWE-98WordPress Etude theme <= 1.6 - Local File Inclusion vulnerability
CVE-2025-691758.127.9ThemeREXLine AgencyCWE-98WordPress Line Agency theme <= 1.3.1 - Local File Inclusion vulnerability
CVE-2026-223358.527.7WC Lovers.WooCommerce Frontend Manager – UltimateCWE-89WordPress WooCommerce Frontend Manager – Ultimate plugin < 6.7.7 - SQL Inject…
CVE-2026-490799.327.7Jetimpex Inc.JetSearchCWE-89WordPress JetSearch plugin <= 3.5.17 - SQL Injection vulnerability
CVE-2026-67348.827.5undiciundiciCWE-346undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
CVE-2026-491337.127.3typemilltypemillCWE-22Typemill < 2.24.0 Path Traversal via ControllerApiImage::getPagemedia()
CVE-2025-691358.527.2CurlyThemesEvents Schedule - WordPress Events Calendar PluginCWE-89WordPress Events Schedule - WordPress Events Calendar Plugin plugin <= 2.7.2 …
CVE-2026-527166.527.0purethemesWorkScout-CoreCWE-22WordPress WorkScout-Core plugin <= 1.7.11 - Arbitrary File Deletion vulnerabi…
CVE-2026-501967.526.8SteeltoeOSSSteeltoe.Discovery.EurekaCWE-20Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire re…
CVE-2025-589528.126.7ThemeREXNeuronetCWE-98WordPress Neuronet theme < 1.14.0 - Local File Inclusion vulnerability
CVE-2026-223268.126.7AxiomThemesReprizoCWE-98WordPress Reprizo theme <= 1.0.8 - Local File Inclusion vulnerability
CVE-2026-223388.126.7ThemeREXEcoBlueCWE-98WordPress EcoBlue theme <= 1.15 - Local File Inclusion vulnerability
CVE-2026-395238.126.7Elated-ThemesSolene CoreCWE-98WordPress Solene Core plugin <= 2.3.2 - Local File Inclusion vulnerability
CVE-2026-395588.126.7Elated-ThemesMalmöCWE-98WordPress Malmö theme <= 2.2 - Local File Inclusion vulnerability
CVE-2026-395598.126.7codesupplycoUppercaseCWE-98WordPress Uppercase theme < 1.2.2 - Local File Inclusion vulnerability
CVE-2026-395828.126.7xtemosHitekCWE-98WordPress Hitek theme < 1.8.3 - Local File Inclusion vulnerability
CVE-2026-395908.126.7ThemeMoveAtomlabCWE-98WordPress Atomlab theme <= 2.4.5 - Local File Inclusion vulnerability
CVE-2026-329679.126.7Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: The `/v2` experimental interface lacks permission ch…
CVE-2026-489678.526.1Dylan KuhnGeo MashupCWE-89WordPress Geo Mashup plugin <= 1.13.19 - SQL Injection vulnerability
CVE-2026-541858.526.1THEMECOCornerstoneCWE-89WordPress Cornerstone plugin < 7.8.8 - SQL Injection vulnerability
CVE-2026-124398.825.9GoogleChromeCWE-416Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.15…
CVE-2026-548148.125.5StylemixThemesMotorsCWE-98WordPress Motors plugin <= 1.4.109 - Local File Inclusion vulnerability
CVE-2026-541937.725.6ThemeFusionFusion BuilderCWE-22WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerabi…
CVE-2026-548167.525.5MonetizemoreAdvanced AdsCWE-94WordPress Advanced Ads plugin <= 2.0.21 - Remote Code Execution (RCE) vulnera…
CVE-2026-121997.525.3nltknltk/nltkCWE-306Unauthenticated Denial of Service in nltk.app.wordnet_app
CVE-2026-254398.125.0fs-codeBookneticCWE-288WordPress Booknetic plugin <= 4.8.5 - Account Takeover vulnerability
CVE-2026-123607.525.0CrocoblockJetEngineCWE-89JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection via Listing Grid Load M…
CVE-2026-490589.824.9LoginPressLoginPress ProCWE-266WordPress LoginPress Pro plugin <= 6.2.2 - Privilege Escalation vulnerability
CVE-2026-270419.924.7Studio Keren Aga LTD.Unlimited Elements for Elementor (Premium)CWE-434WordPress Unlimited Elements for Elementor (Premium) plugin <= 2.0.6 - Arbitr…
CVE-2026-446456.524.5harttleliquidjsCWE-400LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
CVE-2026-426298.824.3PowerpackelementsPowerPack Pro for ElementorCWE-288WordPress PowerPack Pro for Elementor plugin < v2.13.0 - Broken Authenticatio…
CVE-2026-108375.124.2Password ManagerPassword ManagerCWE-601Open redirection vulnerability in Password Manager
CVE-2025-602319.824.1EMVThe HospitalCWE-502WordPress The Hospital theme <= 1.8.1 - PHP Object Injection vulnerability
CVE-2025-602369.824.1EMVCreatifyCWE-502WordPress Creatify theme <= 1.5 - PHP Object Injection vulnerability
CVE-2026-423576.523.9Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: Incorrect Authorization vulnerability allows users t…
CVE-2026-490726.523.5OPMCWooCommerce Anti-FraudCWE-862WordPress WooCommerce Anti-Fraud plugin <= 7.2.6 - Broken Access Control vuln…
CVE-2026-548089.323.4WP TravelWP Travel Gutenberg BlocksCWE-89WordPress WP Travel Gutenberg Blocks plugin <= 3.9.4 - SQL Injection vulnerab…
CVE-2026-394428.123.4PressLayoutsPressMartCWE-502WordPress PressMart theme <= 1.2.26 - PHP Object Injection vulnerability
CVE-2026-395568.123.4Elated-ThemesKonseptCWE-502WordPress Konsept theme <= 1.9 - PHP Object Injection vulnerability
CVE-2026-395608.123.4Select-ThemesHiroshiCWE-502WordPress Hiroshi theme <= 1.5.1 - PHP Object Injection vulnerability
CVE-2026-407338.123.4Mikado-ThemesShiftUpCWE-502WordPress ShiftUp theme <= 1.3 - PHP Object Injection vulnerability
CVE-2026-407388.123.4Edge-ThemesEldonCWE-502WordPress Eldon theme <= 1.4.1 - PHP Object Injection vulnerability
CVE-2026-407528.123.4Select-ThemesManufaktur SolutionsCWE-502WordPress Manufaktur Solutions theme <= 1.1.1 - PHP Object Injection vulnerab…
CVE-2026-407538.123.4Mikado-ThemesEasyMealsCWE-502WordPress EasyMeals theme <= 1.5.1 - PHP Object Injection vulnerability
CVE-2026-108365.123.4Password ManagerPassword ManagerCWE-644Improper neutralization of HTTP headers in Password Manager
CVE-2026-490716.523.1OPMCWooCommerce DropshippingCWE-288WordPress WooCommerce Dropshipping plugin <= 5.2.4 - Broken Authentication vu…
CVE-2026-491089.823.0park_of_ideasModernoCWE-502WordPress Moderno theme < 1.43 - PHP Object Injection vulnerability
CVE-2025-494037.523.0AA-TeamPremium Age Verification / Restriction for WordPressCWE-98WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.…
CVE-2026-552017.423.0Hackplayersevil-winrmCWE-22Evil-WinRM - Path Traversal in download_dir() Function
CVE-2026-454366.523.0Rain-Task Ltd.WPBakery Page BuilderCWE-862WordPress WPBakery Page Builder plugin <= 8.7.2 - Broken Access Control vulne…
CVE-2026-348887.522.8BricksforgeBricksforgeCWE-201WordPress Bricksforge plugin <= 3.1.8.4 - Sensitive Data Exposure vulnerability
CVE-2026-125308.422.7AWSbedrock-agentcoreCWE-88Improper neutralization of argument delimiters in AWS Bedrock AgentCore Pytho…
CVE-2026-124418.822.7GoogleChromeCWE-416Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.15…
CVE-2026-124378.322.4GoogleChromeCWE-416Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.15…
CVE-2026-488149.122.3JovancodingNetwork-AICWE-306Network-AI: Empty default secret still authorizes all requests (Incomplete fi…
CVE-2026-308038.822.2RTIConnext MicroCWE-191Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Co…
CVE-2024-356906.521.9MarketingFireWidget OptionsCWE-201WordPress Widget Options plugin <= 4.0.1 - Subscriber+ User Meta Data Exposur…
CVE-2024-329498.321.8PrinceIntegrate Google DriveCWE-862WordPress Integrate Google Drive plugin <= 1.3.8 - Broken Access Control vuln…
CVE-2026-278704.821.8TeldatRegesta Smart HD-PLC - TLDPH16D2CWE-79CROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC …
CVE-2026-326827.121.7F5NGINX Gateway FabricCWE-129NGINX Gateway Fabric vulnerability
CVE-2026-544456.921.7vantage6vantage6CWE-204Vantage6: Set admin user and password from environment or configuration
CVE-2026-490818.221.6ThemeGrillUser Registration StripeCWE-862WordPress User Registration Stripe plugin <= 1.3.12 - Broken Access Control v…
CVE-2026-502025.921.5SteeltoeOSSSteeltoe.Security.Authentication.CloudFoundryBaseCWE-668Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2026-541869.321.4eyecixJobSearchCWE-89WordPress JobSearch plugin <= 3.2.9 - SQL Injection vulnerability
CVE-2026-395467.621.3TechspawnMultiLocaCWE-266WordPress MultiLoca plugin <= 4.2.15 - Privilege Escalation vulnerability
CVE-2026-407687.321.3Dimitri GrassiSalon booking systemCWE-639WordPress Salon booking system plugin <= 10.30.24 - Insecure Direct Object Re…
CVE-2026-527059.021.0BDthemesSigmaForms Pro – AI Generated FormsCWE-434WordPress SigmaForms Pro – AI Generated Forms plugin <= 1.4.5 - Arbitrary Fil…
CVE-2026-545336.921.0vantage6vantage6CWE-284vantage6 node has an Improper Access Control issue
CVE-2026-125296.920.9SourceCodesterCET Automated Grading System with AI Predictive AnalyticsCWE-266SourceCodester CET Automated Grading System with AI Predictive Analytics Stud…
CVE-2026-223329.320.8ThemeumTutor LMS ProCWE-89WordPress Tutor LMS Pro plugin <= 3.9.6 - SQL Injection vulnerability
CVE-2026-490849.320.8Jetimpex Inc.JetEngineCWE-89WordPress JetEngine plugin < 3.8.9.1 - SQL Injection vulnerability
CVE-2026-541879.320.8Jetimpex Inc.JetEngineCWE-89WordPress JetEngine plugin <= 3.8.10.1 - SQL Injection vulnerability
CVE-2026-548119.320.8Tips and Tricks HQWP eMemberCWE-89WordPress WP eMember plugin < v10.9.4 - SQL Injection vulnerability
CVE-2026-548129.320.8StylemixThemesMotorsCWE-89WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerability
CVE-2026-106417.120.7zephyrprojectzephyrCWE-787Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_…
CVE-2026-548188.520.3VeronaLabsSlimstat AnalyticsCWE-89WordPress Slimstat Analytics plugin <= 5.4.11 - SQL Injection vulnerability
CVE-2024-279285.920.3vantage6vantage6CWE-308Vantage6: 2FA can be circumvented with hacked email access
CVE-2024-247692.120.2vantage6vantage6CWE-400Vantage6: No limit on emails sent for password/MFA reset
CVE-2026-548047.619.8melhorenvioMelhor EnvioCWE-288WordPress Melhor Envio plugin <= 2.16.3 - Broken Authentication vulnerability
CVE-2026-274106.519.8VeronaLabsSlimstat AnalyticsCWE-502WordPress Slimstat Analytics plugin < 5.4.0 - Deserialization of untrusted da…
CVE-2026-118578.419.7Quanos Solutions GmbHSCHEMA ST4CWE-502Insecure .NET Remoting deserialization in Quanos SCHEMA ST4 Client Update Ser…
CVE-2026-551977.119.6nesquenahermes-webuiCWE-639Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint
CVE-2026-551987.119.6nesquenahermes-webuiCWE-639Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session…
CVE-2026-487648.219.5baptisteArnotypebot.ioCWE-918TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass
CVE-2026-124627.519.3GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a re…
CVE-2026-446465.319.3harttleliquidjsCWE-693LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:tr…
CVE-2026-107415.919.2SonatypeNexus Repository ManagerCWE-863Nexus Repository Manager - Incorrect Authorization allows credential disclosu…
CVE-2026-106967.519.1DevolutionsUniGetUICWE-706Use of an incorrectly resolved name or reference in the pinget backend in Dev…
CVE-2024-372106.519.1ali2wooAliNextCWE-862WordPress AliExpress Dropshipping with AliNext Lite plugin <= 3.3.5 - Broken …
CVE-2026-487689.319.0baptisteArnotypebot.ioCWE-22TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via…
CVE-2026-489797.518.9php-standard-libraryphp-standard-libraryCWE-444PHP Standard Library: HTTP/2 server-side missing content-length validation en…
CVE-2026-223438.618.0PremiumPress Limited.WordPress Dating ThemeCWE-862WordPress WordPress Dating Theme theme <= 11.2.0 - Broken Access Control vuln…
CVE-2026-86076.418.0saadiqbalPoints Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCredCWE-79myCred – Points Management System For Gamification, Ranks, Badges, and Loyalt…
CVE-2026-245754.317.7WishList MemberWishList Member XCWE-862WordPress WishList Member X plugin <= 3.29.0 - Broken Access Control vulnerab…
CVE-2026-488206.317.6cakephpcakephpCWE-22CakePHP: View::element() is missing a path containment check
CVE-2026-96795.917.5undiciundiciCWE-93undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
CVE-2026-124528.817.4GoogleChromeCWE-416Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.1…
CVE-2026-84946.417.4mbisPermalink Manager LiteCWE-79Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross…
CVE-2026-119756.217.4simplcommerceSimplCommerceCWE-79Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface
CVE-2026-124488.817.3GoogleChromeCWE-269Inappropriate implementation in WebView in Google Chrome on Android prior to …
CVE-2026-307996.117.3RTIConnext ProfessionalCWE-306Missing Authentication for Critical Function vulnerability in RTI Connext Pro…
CVE-2026-541848.217.1Alberto HorneroClean LoginCWE-639WordPress Clean Login plugin <= 1.15 - Insecure Direct Object References (IDO…
CVE-2026-548176.517.0FluxBuilderMStore APICWE-288WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability
CVE-2026-202206.317.0CiscoCisco Crosswork Network Change AutomationCWE-74Cisco Crosswork Network Controller Remote Code Execution Vulnerability
CVE-2026-124409.616.8GoogleChromeCWE-416Use after free in DigitalCredentials in Google Chrome on Windows prior to 149…
CVE-2026-73008.816.8RTIConnext ProfessionalCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulner…
CVE-2026-125686.516.7Black Lantern SecurityBBOTCWE-22Arbitrary File Write in postman_download module
CVE-2026-407568.116.6Mikado-ThemesZoyaCWE-502WordPress Zoya theme <= 1.4 - PHP Object Injection vulnerability
CVE-2026-407578.116.6Mikado-ThemesChâteauCWE-502WordPress Château theme <= 1.2.1 - PHP Object Injection vulnerability
CVE-2026-308028.816.4RTIConnext MicroCWE-125Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows…
CVE-2024-339095.316.5AvirtumiPages FlipbookCWE-862WordPress iPages Flipbook plugin <= 1.5.1 - Broken Access Control vulnerability
CVE-2026-407268.215.9ThemeGrillUser Registration StripeCWE-862WordPress User Registration Stripe plugin <= 1.3.14 - Broken Access Control v…
CVE-2026-223287.115.8VamTamAuto RepairCWE-79WordPress Auto Repair theme <= 22.6 - Reflected Cross Site Scripting (XSS) vu…
CVE-2026-246104.315.8WPMetMetForm ProCWE-862WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability
CVE-2026-407234.315.8BricksBricks BuilderCWE-862WordPress Bricks Builder theme <= 2.1.4 - Broken Access Control vulnerability
CVE-2026-124658.315.6GoogleChromeCWE-20Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 al…
CVE-2026-124616.515.6GoogleChromeCWE-125Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.…
CVE-2024-492697.115.4Mythemesmy flatonicaCWE-79WordPress my flatonica theme <= 0.0.8 - Reflected Cross Site Scripting (XSS) …
CVE-2026-543865.115.2marimo-teammarimoCWE-79marimo < 0.23.9 XSS via file Query Parameter in assets.py
CVE-2026-124914.815.2vllm-projectvLLMCWE-115Vllm: vllm: image exif rotation & png trns transparency not normalized, causi…
CVE-2026-501948.215.0SteeltoeOSSSteeltoe.Management.EndpointCWE-288Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVE-2026-526967.515.0Jetimpex Inc.JetBlogCWE-1258WordPress JetBlog plugin <= 2.4.8 - Sensitive Data Exposure vulnerability
CVE-2026-115253.715.1undiciundiciCWE-183undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive s…
CVE-2026-548107.514.8Nexi PaymentsNexi XPayCWE-862WordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerability
CVE-2026-541966.814.8JetmonstersJetFormBuilderCWE-266WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability
CVE-2026-548099.314.6VillaThemeGIFT4UCWE-89WordPress GIFT4U plugin <= 1.0.10 - SQL Injection vulnerability
CVE-2026-502016.514.1SteeltoeOSSSteeltoe.Management.EndpointCWE-269Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2025-595607.114.0SONAAR MUSICSonaarCWE-79WordPress Sonaar theme <= 4.27.4 - Cross Site Scripting (XSS) vulnerability
CVE-2025-685247.114.1ThemeGoodsAvanteCWE-79WordPress Avante theme < 3.0.5 - Reflected Cross Site Scripting (XSS) vulnera…
CVE-2026-223397.114.0Jobster MarketplaceWPJobsterCWE-79WordPress WPJobster theme <= 6.3.5 - Reflected Cross Site Scripting (XSS) vul…
CVE-2026-407657.114.0collectchatcollectchatCWE-79WordPress collectchat plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability
CVE-2026-415577.114.0PressLayoutsKapeeCWE-79WordPress Kapee theme < 1.7.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-423857.114.0CozmoslabsProfile Builder ProCWE-79WordPress Profile Builder Pro plugin <= 3.15.0 - Cross Site Scripting (XSS) v…
CVE-2026-548159.314.0Cargo RDCargo Shipping Location for WooCommerceCWE-89WordPress Cargo Shipping Location for WooCommerce plugin <= 5.6 - SQL Injecti…
CVE-2026-548199.314.0Webilia Inc.ListdomCWE-89WordPress Listdom plugin <= 5.4.0 - SQL Injection vulnerability
CVE-2026-350698.013.9DellPowerFlexCWE-89Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper N…
CVE-2026-328048.113.9DellPowerFlexCWE-287Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A…
CVE-2025-156575.313.7MojoomlaSchool ManagementCWE-639WordPress School Management plugin <= 93.1.0 - Insecure Direct Object Referen…
CVE-2026-124557.513.7GoogleChromeCWE-416Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed …
CVE-2026-125285.413.5Red HatRed Hat Directory Server 11CWE-787389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
CVE-2026-125154.313.1Red HatRed Hat Satellite 6.16 for RHEL 8CWE-862Katello: missing repository authorization in content_uploads exposes cross-pr…
CVE-2026-124648.313.1GoogleChromeCWE-416Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a …
CVE-2026-124678.313.1GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed…
CVE-2026-541927.112.8Ays ProPopup boxCWE-79WordPress Popup box plugin <= 6.2.9 - Reflected Cross Site Scripting (XSS) vu…
CVE-2026-67333.712.7undiciundiciCWE-367undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVE-2026-009210.012.5GoogleAndroidCWE-862In Package Manager, there is a possible device lock controller bypass due to …
CVE-2026-557486.012.5OpenStackHorizonCWE-78OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downlo…
CVE-2026-202654.312.4SplunkSplunk AI ToolkitCWE-1188Insecure Default Domain Allowlist in Splunk AI Toolkit
CVE-2026-80897.112.2UnknownweMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerceCWE-79weMail < 2.1.3 - Reflected Cross-Site Scripting
CVE-2026-526987.412.0Syed BalkhiPushEngage – Web Push Notifications, eCommerce Automation &amp; Chat WidgetCWE-201WordPress PushEngage – Web Push Notifications, eCommerce Automation & Chat Wi…
CVE-2026-222837.511.9DellPowerFlexCWE-829Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion …
CVE-2026-488175.311.9KludexstarletteCWE-470Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via …
CVE-2026-26756.011.7RTIConnext ProfessionalCWE-306Missing Authentication for Critical Function vulnerability in RTI Connext Pro…
CVE-2026-495028.111.4DellPowerFlexCWE-287Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A…
CVE-2026-351626.511.5DellPowerFlexCWE-284Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A…
CVE-2026-395954.711.4BoldGridW3 Total CacheCWE-862WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability
CVE-2026-125655.311.3Black Lantern SecurityBBOTCWE-22Path Traversal (Zip-Slip) in unarchive module
CVE-2024-314354.311.2InisevSocial Media & Share IconsCWE-862WordPress Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.6 -…
CVE-2024-374964.311.2Rara ThemesMetro MagazineCWE-862WordPress Metro Magazine theme <= 1.3.7 - Broken Access Control on Notice Dis…
CVE-2026-124388.311.1GoogleChromeCWE-693Inappropriate implementation in WebView in Google Chrome on Android prior to …
CVE-2026-548138.510.8Brainstorm ForceSureDashCWE-89WordPress SureDash plugin <= 1.8.0 - SQL Injection vulnerability
CVE-2025-623405.310.6HCL SoftwareiControlCWE-613HCL iControl was affected by Inadequate Session Timeout vulnerability
CVE-2026-446446.110.6harttleliquidjsCWE-79LiquidJS's strip_html filter bypass via newline characters in HTML tags enabl…
CVE-2026-487597.110.5baptisteArnotypebot.ioCWE-639TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)
CVE-2026-201784.310.5CiscoCisco Webex AppCWE-601A vulnerability in the browser-based version of Cisco Webex App could have al…
CVE-2026-38949.210.1RTIConnext ProfessionalCWE-125Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries)…
CVE-2026-541957.19.9JetmonstersJetFormBuilderCWE-79WordPress JetFormBuilder plugin <= 3.6.0.1 - Cross Site Scripting (XSS) vulne…
CVE-2026-95916.99.8simplcommerceSimplCommerceCWE-352Cross-Site Request Forgery (CSRF) in SimplCommerce News Module
CVE-2026-124464.39.5GoogleChromeCWE-863Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782…
CVE-2026-350685.79.2DellPowerFlexCWE-89Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper N…
CVE-2024-247094.39.2ShareaholicShareaholicCWE-862WordPress Shareaholic plugin <= 9.7.11 - Broken Access Control vulnerability
CVE-2025-485714.39.0GoogleAndroidCWE-693In multiple functions of btm_sec.cc, there is a possible way for an attacker …
CVE-2026-124583.19.0GoogleChromeCWE-451Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782…
CVE-2026-24679.28.8RTIConnext ProfessionalCWE-122Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Li…
CVE-2026-407225.58.7Yoast BVYoast SEO PremiumCWE-862WordPress Yoast SEO Premium plugin <= 26.6 - Broken Access Control vulnerability
CVE-2026-223297.18.5ThemeumSkillateCWE-79WordPress Skillate theme <= 1.2.10 - Reflected Cross Site Scripting (XSS) vul…
CVE-2026-497787.18.5WPFunnelsWPFunnels ProCWE-79WordPress WPFunnels Pro plugin <= 2.9.4 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-124694.38.5GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 …
CVE-2026-502007.58.4SteeltoeOSSSteeltoe.Management.EndpointCWE-200Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVE-2026-223428.88.3PremiumPress Limited.WordPress Dating ThemeCWE-352WordPress WordPress Dating Theme theme <= 11.2.0 - Cross Site Request Forgery…
CVE-2026-481176.88.3fduflyerDroneAware-Node-ReleasesCWE-287DroneAware's Improper Account Activation in Registration and SSO Flows Leads …
CVE-2026-124506.58.2GoogleChromeCWE-269Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.15…
CVE-2026-350667.18.2DellPowerFlexCWE-284Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A…
CVE-2026-124596.17.9GoogleChromeCWE-79Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.1…
CVE-2025-691407.17.8SeventhQueenSweetDate CoreCWE-79WordPress SweetDate Core plugin < 1.1.5 - Reflected Cross Site Scripting (XSS…
CVE-2026-26744.87.9RTIConnext ProfessionalCWE-787Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Servi…
CVE-2026-124534.27.9GoogleChromeCWE-20Insufficient validation of untrusted input in Input in Google Chrome prior to…
CVE-2025-691897.37.6EMVJobBankCWE-862WordPress JobBank plugin <= 1.2.3 - Broken Access Control vulnerability
CVE-2026-124518.37.5GoogleChromeCWE-416Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155…
CVE-2026-395977.17.3WPZOOMWPZOOM Addons for ElementorCWE-79WordPress WPZOOM Addons for Elementor plugin <= 1.3.4 - Reflected Cross Site …
CVE-2026-407207.17.2Royal Elementor AddonsRoyal Elementor Addons ProCWE-79WordPress Royal Elementor Addons Pro plugin < 1.7.1041 - Cross Site Scripting…
CVE-2026-490747.17.2Jetimpex Inc.JetEngineCWE-79WordPress JetEngine plugin <= 3.8.9.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-125663.16.4Black Lantern SecurityBBOTCWE-918SSRF via unvalidated WWW-Authenticate realm in docker_pull module
CVE-2026-008210.06.2GoogleAndroidCWE-453In tryStartActivity of NfcDispatcher.java, there is a possible automatic spec…
CVE-2026-108506.96.2PlanePlaneCWE-79Plane 1.3.1 - Stored XSS in intake issue description_html
CVE-2025-156416.85.9NetskopeNetskope ClientCWE-782Netskope Client Exposed IOCTL with Insufficient Access Controls
CVE-2026-489905.35.9authlibjoserfcCWE-400joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limit…
CVE-2026-124457.55.5GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed…
CVE-2026-006310.05.2GoogleAndroidCWE-269In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way …
CVE-2026-007110.05.2GoogleAndroidCWE-862In SettingsLib, there is a possible missing permission check due to a logic e…
CVE-2024-336854.35.1JegstudioStartupzyCWE-862WordPress Startupzy theme <= 1.1.1 - Broken Access Control vulnerability
CVE-2026-124604.25.0GoogleChromeCWE-284Insufficient policy enforcement in File System Access in Google Chrome prior …
CVE-2026-56677.24.8Mitsubishi Electric CorporationRoom Air Conditioners (for Japan) MSZ-BKR2223-WCWE-798Information Disclosure, Information Tampering, or Denial-of-Service (DoS) Vul…
CVE-2026-350678.04.7DellPowerFlexCWE-284Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A…
CVE-2026-008110.04.5GoogleAndroidCWE-862In NFC, there is a possible way to spoof an NFC event due to a missing permis…
CVE-2026-2857610.04.5AndroidAndroidCWE-89In Contacts Provider, there is a possible way to access the contacts database…
CVE-2026-124548.34.3GoogleChromeCWE-362Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed…
CVE-2025-310137.14.4ThemifyThemify FoloCWE-79WordPress Themify Folo theme <= 1.9.6 - Reflected Cross Site Scripting (XSS) …
CVE-2026-95707.14.4UnknownTaskbuilderCWE-79Taskbuilder < 5.0.8 - Reflected XSS via Shortcode
CVE-2025-327486.14.3DellPowerFlex rackCWE-601Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header…
CVE-2026-124688.34.1GoogleChromeCWE-362Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a rem…
CVE-2025-156426.84.2NetskopeNetskope ClientCWE-276Netskope Client Service Insufficient Access Controls
CVE-2026-124445.54.1GoogleChromeCWE-125Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7…
CVE-2026-541887.14.0Jetimpex Inc.JetEngineCWE-79WordPress JetEngine plugin <= 3.8.10 - Cross Site Scripting (XSS) vulnerability
CVE-2026-541897.14.0Jetimpex Inc.JetEngineCWE-79WordPress JetEngine plugin <= 3.8.10 - Cross Site Scripting (XSS) vulnerability
CVE-2026-78505.93.8UnknownWP Magnific PopupWP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute
CVE-2026-124564.23.6GoogleChromeCWE-20Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78…
CVE-2026-124574.23.5GoogleChromeCWE-693Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78…
CVE-2026-485914.83.3pragdaveearmarkCWE-83Stored XSS via unescaped HTML attribute values in earmark
CVE-2026-124634.73.3GoogleChromeCWE-79Inappropriate implementation in Views in Google Chrome on Linux prior to 149.…
CVE-2026-488215.83.0shaarliShaarliCWE-79Shaarli: DOM-based Cross-Site Scripting (XSS) in Thumbnail Synchronizer
CVE-2026-489915.52.8XianYuLauncherXianYuLauncherCWE-287XianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and st…
CVE-2024-356484.32.8Andy MoyleEmergency Password ResetCWE-352WordPress Emergency Password Reset plugin <= 8.0 - Cross Site Request Forgery…
CVE-2026-118588.42.7Quanos Solutions GmbHSCHEMA ST4CWE-862Missing authorization in Quanos SCHEMA ST4 Client Update Service allows arbit…
CVE-2026-2857510.02.6GoogleAndroidCWE-400In PackageInstaller.Session#transfer of frameworks/base/services/core/java/co…
CVE-2026-391992.92.6Snes9X teamSnes9XCWE-787snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted…
CVE-2024-474776.52.5DellPowerFlex ManagerCWE-295Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certif…
CVE-2026-006810.02.5GoogleAndroidCWE-362In createSessionInternal of PackageInstallerService.java, there is a possible…
CVE-2026-2861510.02.5GoogleAndroidCWE-862In Telecomm, there is a possible way to initiate an unauthorized phone call d…
CVE-2026-006410.02.4GoogleAndroidCWE-400In multiple places, there is a possible persistent denial of service due to r…
CVE-2026-008310.02.2GoogleAndroidCWE-362In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a…
CVE-2026-488225.82.2shaarliShaarliCWE-79Shaarli has Stored Cross-Site Scripting (XSS) via Markdown Reference Links
CVE-2024-348104.31.9Extend ThemesSkyline WPCWE-352WordPress Skyline WP theme <= 1.0.10 - Cross Site Request Forgery (CSRF) vuln…
CVE-2026-12885.51.8AutodeskRevitCWE-476RFA File Parsing Vulnerability in Autodesk Revit
CVE-2026-2858710.01.8GoogleAndroidCWE-862In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve…
CVE-2026-488234.81.8shaarliShaarliCWE-79Shaarli has Stored Cross-Site Scripting (XSS) via Tags Search
CVE-2026-80495.31.6SignalRGBSignalRGB kernel driverCVE-2026-8049
CVE-2026-124497.81.4GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.…
CVE-2026-538706.81.4NousResearchhermes-agentCWE-276Hermes Agent < 0.16.0 - Sensitive File Permission Vulnerability in Store Files
CVE-2026-202466.01.2CiscoCisco Umbrella Insights Virtual ApplianceCWE-269Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
CVE-2026-406414.81.0DellPowerFlexCWE-327Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a B…
CVE-2026-326527.80.9DellAIOpsCWE-1392Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Crede…
CVE-2025-486408.00.7GoogleAndroidCWE-862In multiple locations, there is a possible 3rd party passkey entry pairing ap…
CVE-2026-125672.20.6Black Lantern SecurityBBOTCWE-59Symlink-following arbitrary write via github_workflows module
CVE-2025-486437.80.3GoogleAndroidCWE-20In multiple locations there is a possible provisioning bypass due to improper…
CVE-2026-00197.80.2GoogleAndroidCWE-269In SettingsLib, there is a possible way to disable system components due to a…
CVE-2025-486177.80.1GoogleAndroidCWE-862In overrideConfig of CarrierConfigLoader.java, there is a possible way to byp…
CVE-2026-502674.70.0SteeltoeOSSSteeltoe.Configuration.AbstractionsCWE-312Steeltoe: TLS private keys written to /tmp with default permissions, never de…
CVE-2026-00573.30.0GoogleAndroidCWE-862In Contacts Provider, there is a possible way to access an incoming call's ph…
CVE-2026-502681.90.0SteeltoeOSSSteeltoe.Configuration.EncryptionCWE-256Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-17 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.