boxscore/security
Thursday, June 18, 2026 · all times UTC← 2026-06-17 · archive · 2026-06-19 →

151 CVEs published June 18, 2026: 27 critical, 58 high, 62 medium, 4 low; 1 in KEV; 5 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 126 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published4868924011652563
KEV catalog size1670

430 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9710638466431212730.37.8.0013-118
google68485883450293297460.78.1.0023+684
microsoft212702534701584378273.87.8.0044+69
red hat67131858596400.07.0.0027+62
apple146101636293711.55.7.0023+1
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse350410000.08.5.0022+3
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco9224380961045.56.8.0257+8
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
f56943107111.18.9.0221+5
ivanti49230033555.68.8.5187+3
checkpoint3915303111.17.5.0410+3
ubiquiti584400400.08.9.0052+5
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache7410618414424010.97.3.0050+70
mozilla495511182601300.07.3.0026+45
gitlab1120041224210.04.8.0024+11
docker470520100.08.2.0016+4
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1291334497527532.35.5.0021+129
ibm11601329180700.07.5.0028+11
progress591710900.07.5.0036+5
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+9
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb550410000.07.2.0018+5
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
hitachi energy020020000.05.7.00140
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+37
themerex585855300000.08.1.0043+58
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2
dell2644020230212.36.7.0016+26
open ises044221210000.07.1.00210

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2008-4250.987599.9
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2010-0249.918899.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4925710.0.0093
CVE-2026-2022310.0.0083
Most disclosures (vendor)
VendorCVEs
google852
linux521
oracle268
microsoft238
adobe130
red hat103
apache91
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco10
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven42
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171674
CVE-2021-27102Accellion2021-11-171674
CVE-2021-27101Accellion2021-11-171674
CVE-2021-27103Accellion2021-11-171674
CVE-2021-21017Adobe2021-11-171674
CVE-2021-28550Adobe2021-11-171674
CVE-2021-42013Apache2021-11-171674
CVE-2021-41773Apache2021-11-171674
CVE-2021-30858Apple2021-11-171674
CVE-2021-30860Apple2021-11-171674

Transactions

EXPLOIT PUBLISHEDCVE-2026-43994 (coturn). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44663 (AcademySoftwareFoundation openexr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45696 (AcademySoftwareFoundation openexr). Public exploit reference added.

Yesterday's Results

151 CVEs published. 25 box scores, 126 table rows — nothing truncated.

Splunk Splunk Enterprise — Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9694   99.9   YES
AFFECTED
  Product            Versions  Fixed
  Splunk Enterprise  10.2 –    —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 18  Added to CISA KEV, due Jun 21
  Jun 18  Published (CNA: cisco)
CWE-306 · CNA: cisco · 3 references · NVD status: Analyzed · KEV due June 21, 2026
n/a n/a — InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0231   81.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 18  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Analyzed
n/a n/a — InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0231   81.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 18  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Analyzed
n/a n/a — InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0231   81.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 18  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Analyzed
n/a n/a — InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0231   81.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 18  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Analyzed
FFmpeg FFmpeg — Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0157   73.3     —
AFFECTED
  Product  Versions     Fixed
  FFmpeg   unspecified  —
TIMELINE
  May 13  Reserved by CNA
  Jun 18  Published (CNA: JFROG)
CWE-787 · CNA: JFROG · 5 references · NVD status: Awaiting Analysis
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0107   62.1     —
AFFECTED
  Product                         Versions    Fixed
  org.geoserver.extension:gs-db2  < 2.27.0 –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jun 18  Published (CNA: GitHub_M)
CWE-74, CWE-502 · CNA: GitHub_M · 4 references · NVD status: Analyzed
libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   L   N   H    8.3   .0103   60.8     —
AFFECTED
  Product  Versions     Fixed
  libssh2  unspecified  2dae3024897e1898d389835151f4e9606227721d
TIMELINE
  Jun 18  Reserved by CNA
  Jun 18  Published (CNA: VulnCheck)
CWE-125 · CNA: VulnCheck · 4 references · NVD status: Analyzed
LMS LMS — OS Command Injection in LMS
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   L   N   H   H   H    8.6   .0095   58.2     —
AFFECTED
  Product  Versions     Fixed
  LMS      unspecified  —
TIMELINE
  Apr 13  Reserved by CNA
  Jun 18  Published (CNA: CERT-PL)
CWE-78 · CNA: CERT-PL · 3 references · NVD status: Deferred
startreedata mcp-pinot — mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0093   57.7     —
AFFECTED
  Product    Versions   Fixed
  mcp-pinot  < 3.1.0 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 18  Published (CNA: GitHub_M)
CWE-306 · CNA: GitHub_M · 4 references · NVD status: Deferred
pgadmin.org pgAdmin 4 — pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0092   57.3     —
AFFECTED
  Product    Versions  Fixed
  pgAdmin 4  6.9 –     —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: PostgreSQL)
CWE-306, CWE-502 · CNA: PostgreSQL · 2 references · NVD status: Analyzed
PraisonAI - Arbitrary File Read and Write via Path Traversal in MultiAgentMonitor
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0092   57.2     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  1.5.115
TIMELINE
  Jun 18  Reserved by CNA
  Jun 18  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 3 references · NVD status: Deferred
AVer PTC cameras Files or Directories Accessible to External Parties
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0083   54.7     —
AFFECTED
  Product  Versions     Fixed
  PTC500S  unspecified  —
  PTC115   unspecified  —
  PTC500+  unspecified  —
  PTC115+  unspecified  —
TIMELINE
  May 7   Reserved by CNA
  Jun 18  Published (CNA: icscert)
CWE-552 · CNA: icscert · 2 references · NVD status: Awaiting Analysis
Microsoft Microsoft Dynamics 365 — Dynamics 365 Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0078   52.9     —
AFFECTED
  Product                 Versions  Fixed
  Microsoft Dynamics 365  - –       —
TIMELINE
  May 19  Reserved by CNA
  Jun 18  Published (CNA: microsoft)
CWE-284 · CNA: microsoft · 1 reference · NVD status: Analyzed
Government Accountability Office Electronic Protest Docketing System (EPDS) — U.S. GAO EPDS and CBCA EDS unauthenticated password change
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0077   52.7     —
AFFECTED
  Product                                     Versions     Fixed
  Electronic Protest Docketing System (EPDS)  unspecified  2026-02-22
  Electronic Docketing System (EDS)           unspecified  2026-03-19
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: cisa-cg)
CWE-306 · CNA: cisa-cg · 4 references · NVD status: Awaiting Analysis
PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   N    8.6   .0074   51.7     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  1.5.128
TIMELINE
  Jun 18  Reserved by CNA
  Jun 18  Published (CNA: VulnCheck)
CWE-942 · CNA: VulnCheck · 2 references · NVD status: Deferred
Government Accountability Office Electronic Protest Docketing System (EPDS) — U.S. GAO EPDS and CBCA EDS client-based privilege escalation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0072   51.0     —
AFFECTED
  Product                                     Versions     Fixed
  Electronic Protest Docketing System (EPDS)  unspecified  2026-02-22
  Electronic Docketing System (EDS)           unspecified  2026-03-19
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: cisa-cg)
CWE-602 · CNA: cisa-cg · 4 references · NVD status: Awaiting Analysis
pgadmin.org pgAdmin 4 — pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0071   50.5     —
AFFECTED
  Product    Versions  Fixed
  pgAdmin 4  1.0 –     —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: PostgreSQL)
CWE-89, CWE-116 · CNA: PostgreSQL · 3 references · NVD status: Analyzed
PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0071   50.4     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  4.5.128
TIMELINE
  Jun 18  Reserved by CNA
  Jun 18  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · 2 references · NVD status: Deferred
CometD has acknowledgement extension out of memory
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0068   49.6     —
AFFECTED
  Product  Versions              Fixed
  cometd   >= 5.0.0, < 5.0.23 –  —
TIMELINE
  Jun 25  Reserved by CNA
  Jun 18  Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · 6 references · NVD status: Deferred
UBB Systems UBB.threads — Remote Code Execution via arbitrary file read and write in UBB.threads
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0063   47.2     —
AFFECTED
  Product      Versions     Fixed
  UBB.threads  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Jun 18  Published (CNA: CERT-PL)
CWE-22 · CNA: CERT-PL · 2 references · NVD status: Deferred
GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0062   46.7     —
AFFECTED
  Product                            Versions    Fixed
  org.geoserver.web:gs-web-app       < 2.26.4 –  —
  org.geoserver.web:gs-web-sec-core  < 2.26.4 –  —
TIMELINE
  Jun 17  Reserved by CNA
  Jun 18  Published (CNA: GitHub_M)
CWE-73 · CNA: GitHub_M · 4 references · NVD status: Analyzed
JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0060   46.1     —
AFFECTED
  Product   Versions  Fixed
  JTL Shop  5.2.0 –   5.0.0
TIMELINE
  Jun 12  Reserved by CNA
  Jun 18  Published (CNA: VulnCheck)
CWE-1336 · CNA: VulnCheck · 3 references · NVD status: Deferred
Microsoft Microsoft 365 Copilot — M365 Copilot Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0058   44.9     —
AFFECTED
  Product                Versions  Fixed
  Microsoft 365 Copilot  - –       —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: microsoft)
CWE-306 · CNA: microsoft · 1 reference · NVD status: Analyzed
theonedev onedev — OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   N    8.3   .0057   44.5     —
AFFECTED
  Product  Versions    Fixed
  onedev   < 15.0.7 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 18  Published (CNA: GitHub_M)
CWE-61 · CNA: GitHub_M · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-476337.544.5MicrosoftMicrosoft Cost ManagementCWE-200Microsoft Cost Management Information Disclosure Vulnerability
CVE-2026-98608.844.0vanyukovOffload, AI & Optimize with Cloudflare ImagesCWE-434Offload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Auth…
CVE-2026-560226.943.7WebminWebminCWE-308Webmin MFA bypass
CVE-2026-80249.343.6ibaibaPDACWE-502Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-81008.643.4Progress ChefChef360CWE-23Impact A security issue has been identified in Chef 360 that could allow unau…
CVE-2026-489377.542.6nodejsnodeCWE-400A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data …
CVE-2025-323928.742.4Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in LoopVideoBlock
CVE-2026-552056.942.0nesquenahermes-webuiCWE-770Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow …
CVE-2026-540177.741.9open-webuiopen-webuiCWE-22Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path t…
CVE-2026-446888.441.0Eclipse FoundationEclipse TheiaCWE-829In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed worksp…
CVE-2026-465808.441.0Eclipse FoundationEclipse TheiaCWE-829In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompt…
CVE-2026-541056.940.8Government Accountability OfficeElectronic Protest Docketing System (EPDS)CWE-639U.S. GAO EPDS and CBCA EDS user information disclosure
CVE-2026-560209.240.3WebminWebminCWE-290Webmin HTTP header authentication bypass
CVE-2026-541065.140.0Government Accountability OfficeElectronic Protest Docketing System (EPDS)CWE-940U.S. GAO EPDS and CBCA EDS network access control bypass
CVE-2026-107364.939.9themeumTutor LMS – eLearning and online course solutionCWE-89Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data'…
CVE-2026-552048.739.6haproxyhaproxyCWE-476HAProxy - NULL Pointer Dereference in hpack_dht_insert Function
CVE-2026-478469.839.5Bitnamibitnami/cassandraCWE-798Bitnami Cassandra container images are affected by a retained default superus…
CVE-2026-120459.439.5pgadmin.orgpgAdmin 4CWE-77pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writ…
CVE-2026-560216.939.1WebminWebminCWE-185Webmin information disclosure via regex pattern
CVE-2026-119825.139.0Gravgrav-plugin-apiCWE-79Stored XSS via missing XSS safety check in Admin2 Pages API partial validation
CVE-2026-113604.939.0algolplusAdvanced Order Export For WooCommerceCWE-89Advanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager…
CVE-2026-492529.938.7deepstreamIOdeepstream.ioCWE-1321deepstream is vulnerable to prototype pollution
CVE-2026-387187.537.9n/an/aCWE-120InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlie…
CVE-2026-439949.837.4coturncoturnCWE-120Coturn: Stack buffer overflow in decode_oauth_token_gcm()
CVE-2026-560777.137.0PraisonAIPraisonAICWE-668PraisonAI - Information Disclosure via Shared MultiAgentLedger State
CVE-2026-544199.336.8claudiopizzilloPIAF-HMSCWE-89PIAF-HMS multiple unauthenticated SQL injection vulnerabilities via mysql_query
CVE-2025-324228.735.7Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in FileStoreBlock with StepThroughItemsBlock
CVE-2025-324248.735.7Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in ScreenshotWebPageBlock
CVE-2025-324378.735.7Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in MediaDurationBlock
CVE-2026-501417.135.6woodpecker-ciwoodpeckerCWE-290Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent imperson…
CVE-2026-560996.935.3openbsdsrcCWE-125OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input
CVE-2026-487168.735.2HKUDSnanobotCWE-22nanobot: Path traversal via unsanitized WhatsApp document fileName enables ar…
CVE-2026-96925.335.0HAYAJOMojolicious::Sessions::StorableCWE-338Mojolicious::Sessions::Storable versions through 0.05 for Perl generate sessi…
CVE-2026-449426.534.8SUSElibzyppCWE-24libzypp .repo files can have an optional path which can lead to path traversa…
CVE-2026-321748.834.2MicrosoftAzure AI Bot ServiceCWE-287Azure Bot Service Elevation of Privilege Vulnerability
CVE-2026-446918.434.0Eclipse FoundationEclipse TheiaCWE-829In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspa…
CVE-2025-105609.332.0Silver Leaf Technologies, Inc.Worksnaps.net WorksnapsCWE-798Hardcoded cloud credentials in Worksnaps client application binaries expose p…
CVE-2026-492056.531.6thorstenphpMyFAQCWE-862phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-2442…
CVE-2025-324367.131.3Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in AddAudioToVideoBlock
CVE-2026-124078.830.7oleksandrzE2Pdf – Export Pdf Tool for WordPressCWE-862E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary…
CVE-2026-560128.528.8David LingrenMedia LIbrary AssistantCWE-89WordPress Media LIbrary Assistant plugin <= 3.35 - SQL Injection vulnerability
CVE-2026-424888.128.4XenXenCWE-119x86: mismatched mapcache metadata
CVE-2026-120935.328.2wpinsider-1Simple MembershipCWE-862Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitra…
CVE-2026-528667.127.8Apollo PharmacyBlood Glucose Monitoring System (Model No. APG-01 BT)CWE-862Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Missing Authorization
CVE-2026-552039.027.8haproxyhaproxyCWE-190HAProxy - Integer Overflow in FCGI Demux Record Length Field
CVE-2026-117764.927.510webForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-89Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection…
CVE-2026-117774.927.510webForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-89Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection…
CVE-2026-121205.326.0firepluginsFireBox Popups – Increase Sales and Grow Your Email ListCWE-200FireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in '…
CVE-2026-466997.625.9conda-forgeconda-smithyCWE-284conda-smithy vulnerable to misrouted repository invitation by conda-forge-web…
CVE-2026-120505.325.0pgadmin.orgpgAdmin 4CWE-89pgAdmin 4: SQL injection in named restore point endpoint
CVE-2026-113574.325.0stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-200Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information …
CVE-2026-552378.824.6Significant-GravitasAutoGPTCWE-87AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
CVE-2026-88117.124.6SEPPmail AGSecure Email GatewayCWE-22Path traversal in PDF generation module
CVE-2026-404572.124.6LMSLMSCWE-79Reflected XSS in LMS
CVE-2026-478475.324.0Bitnamibitnami/mariadb-galeraCWE-798Bitnami MariaDB Galera container images and Helm chart are affected by a hard…
CVE-2026-225516.723.9Eclipse FoundationEclipse TheiaCWE-201In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown imag…
CVE-2026-100295.323.7eventkoiEvent Koi Lite – Events Calendar, Event Management, RSVP, and TicketsCWE-862Event Koi Lite <= 1.3.13.1 - Missing Authorization to Unauthenticated Sensiti…
CVE-2026-226744.823.6hashgraphguardianCWE-79Hashgraph Guardian Stored XSS via branding companyName field
CVE-2026-542228.623.1UBB SystemsUBB.threadsCWE-89Blind SQL Injection in UBB.threads
CVE-2026-91585.223.0Eclipse FoundationEclipse 4diacCWE-416In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE co…
CVE-2026-542195.121.9UBB SystemsUBB.threadsCWE-79Stored XSS in UBB.threads
CVE-2026-542215.121.8UBB SystemsUBB.threadsCWE-79Reflected XSS in UBB.threads
CVE-2026-456968.321.8AcademySoftwareFoundationopenexrCWE-122OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)
CVE-2026-113957.221.4mariovalneyCF7 to WebhookCWE-918CF7 to Webhook <= 5.0.0 - Unauthenticated Server-Side Request Forgery via CF7…
CVE-2025-581758.221.2geoserverorg.geoserver.web:gs-web-appCWE-20GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML E…
CVE-2026-557409.320.6Nur-Alam39bus-ticketCWE-89SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter
CVE-2026-121114.320.1codepeopleAppointment Booking CalendarCWE-200Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensiti…
CVE-2026-542247.119.6UBB SystemsUBB.threadsCWE-405Denial of Service in UBB.threads
CVE-2026-121022.719.6stiofansislandUsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPCWE-639UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor…
CVE-2026-86682.319.3Progress ChefChef360CWE-523Hardcoded credentials in embedded content
CVE-2026-113584.418.4themeisleOrbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & MoreCWE-79Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fon…
CVE-2026-106234.316.9pressprimerPressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment PluginCWE-639PressPrimer Quiz <= 2.3.0 - Insecure Direct Object Reference to Authenticated…
CVE-2026-125276.015.7Shenzhen Liandian Communication Technology LTDV380 IP Camera / AppFHE1_V1.0.6.0CWE-306A broken authorization boundary in the RTSP media delivery pipeline of Shenzh…
CVE-2026-100234.315.7dokanincDokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, EtsyCWE-639Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Ins…
CVE-2026-439155.415.3coturncoturnCWE-79Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN use…
CVE-2026-486171.815.4nodejsnodeCWE-284A flaw in Node.js Permission Model enforcement allows Bypass via `process.rep…
CVE-2026-91994.315.1equalizedigitalEqualize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 complianceCWE-862Equalize Digital Accessibility Checker <= 1.42.1 - Missing Authorization to A…
CVE-2026-117844.313.8optimoleOptimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image OptimizationCWE-352Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Op…
CVE-2026-494549.113.5szTheoryrelyraCWE-287Relyra SAML SignatureValue not cryptographically verified -> authentication b…
CVE-2026-120495.312.5pgadmin.orgpgAdmin 4CWE-601pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated …
CVE-2026-404558.612.3LMSLMSCWE-89SQL Injection in LMS
CVE-2026-98156.512.2UnknownMagicFormMagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCE
CVE-2026-117915.011.8Red HatRed Hat Directory Server 11CWE-416389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swa…
CVE-2026-121376.111.6phppoetSysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu ManagerCWE-79SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Sit…
CVE-2026-120489.311.5pgadmin.orgpgAdmin 4CWE-79pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through…
CVE-2026-500347.111.3Apollo PharmacyBlood Glucose Monitoring System (Model No. APG-01 BT)CWE-319Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmiss…
CVE-2026-114026.410.9bpluginsServices Section Block – Showcase Service Details in Grid or ColumnsCWE-79Services Section Block <= 1.4.4 - Authenticated (Contributor+) Stored Cross-S…
CVE-2026-424906.510.2XenXenCWE-667domctl lock open to abuse
CVE-2026-446637.110.1AcademySoftwareFoundationopenexrCWE-190OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow
CVE-2026-20216.410.1contridSlideshow Gallery LITECWE-79Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-S…
CVE-2026-258658.59.9YandexPunto SwitcherCWE-428Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec
CVE-2026-120986.49.7blubrryPowerPress Podcasting plugin by BlubrryCWE-79PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) …
CVE-2026-121366.48.7phppoetSysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu ManagerCWE-79SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Cont…
CVE-2026-542208.68.6UBB SystemsUBB.threadsCWE-352Cross-Site Request Forgery in UBB.threads
CVE-2026-117189.38.3GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox)CWE-287An authentication bypass vulnerability exists in the generic opaque token val…
CVE-2026-80396.48.0dijitulFancy TestimonialsCWE-79Fancy Testimonials <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting
CVE-2026-117179.37.5GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox)CWE-287An authentication bypass vulnerability exists in the generic opaque token val…
CVE-2026-560246.57.4Saad IqbalWP EasyPayCWE-352WordPress WP EasyPay plugin <= 4.5.0 - Cross Site Request Forgery (CSRF) vuln…
CVE-2026-489806.37.3mcdopepam_usbCWE-454pam_usb: getenv() used in PAM context allows environment variable injection i…
CVE-2026-557467.06.9CotontiCotontiCWE-79Cotonti stored XSS via PFS folder title
CVE-2026-478336.96.4Cloud Foundry Foundationbpm-releaseCWE-59setupBpmLogs follows symlink for bpm.log open and chown — container-to-host p…
CVE-2026-560746.86.3PraisonAIPraisonAICWE-863PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching
CVE-2026-489855.56.0mcdopepam_usbCWE-476pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Retur…
CVE-2026-125057.85.3Red HatRed Hat Enterprise Linux 10CWE-250Cifs-utils: local privilege escalation via forged cifs.spnego key description…
CVE-2026-489816.75.1mcdopepam_usbCWE-611pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c
CVE-2026-557429.44.8CotontiCotontiCWE-352Cotonti CSRF in admin.rights.php allows privilege escalation
CVE-2026-553926.74.8nilfs-devnilfs-utilsCWE-1284NILFS utilities - Undefined Behavior and Out-of-Memory via Unvalidated s_log_…
CVE-2026-557418.74.5CotontiCotontiCWE-352Cotonti CSRF in admin.config.php allows unauthorized configuration changes
CVE-2026-557448.64.6CotontiCotontiCWE-352Cotonti CSRF in PFS allows forced arbitrary file upload
CVE-2026-120395.74.5DockerDocker SandboxesCWE-923Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution
CVE-2026-489844.74.4mcdopepam_usbCWE-14pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic mater…
CVE-2026-117198.64.3GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox)CWE-862An authenticated authorization bypass vulnerability exists in MCP Toolbox for…
CVE-2026-489864.73.9mcdopepam_usbCWE-835pam_usb: Infinite loop DoS in process-tree walk when parent process exits dur…
CVE-2026-125395.73.8DockerDocker SandboxesCWE-665Docker Sandboxes ICMP egress restriction bypass after daemon restart
CVE-2026-2857310.03.7GoogleAndroidCWE-862In AndroidManifest.xml, there is a possible persistent denial of service due …
CVE-2026-560075.93.7OceanWPOcean Product SharingCWE-79WordPress Ocean Product Sharing plugin <= 2.2.2 - Cross Site Scripting (XSS) …
CVE-2026-506435.13.7rui3148ccCWE-125Out‑of‑Bounds Read in 8cc
CVE-2026-120474.83.6pgadmin.orgpgAdmin 4CWE-79pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via …
CVE-2026-560095.93.5BricksableBricksable for Bricks BuilderCWE-79WordPress Bricksable for Bricks Builder plugin <= 1.6.83 - Cross Site Scripti…
CVE-2026-123908.43.5AzeoTechDAQFactoryCWE-843Access of resource using incompatible type ('type confusion') in AzeoTech DAQ…
CVE-2026-489825.82.0mcdopepam_usbCWE-362pam_usb: Missing O_EXCL on pad temp file creation allows concurrent update race
CVE-2026-489835.81.3mcdopepam_usbCWE-367pam_usb: TOCTOU race condition in pad directory creation allows symlink subst…
CVE-2026-119587.31.1ANSSIDFIR-ORCCWE-427Local privilege escalation in ANSSI’s DFIR-ORC
CVE-2026-557455.30.9CotontiCotontiCWE-352Cotonti CSRF in PFS folder edit allows unauthorized folder modification
CVE-2026-424877.90.8XenXenCWE-362x86 HVM I/O port list traversal
CVE-2026-424895.30.2XenXenCWE-667domctl lock open to abuse

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-18 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.