boxscore/security
Friday, June 19, 2026 · all times UTC← 2026-06-18 · archive · 2026-06-20 →

194 CVEs published June 19, 2026: 20 critical, 115 high, 51 medium, 8 low; 0 in KEV; 16 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 169 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published5062943411652563
KEV catalog size1670

437 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux10010668466731212730.37.8.0013-116
google68485883450293297460.78.1.0023+684
microsoft220710554741604378273.87.8.0044+76
red hat75139863626400.07.0.0028+70
apple146101636293711.55.7.0023+1
canonical1150465000.05.5.0009+1
freebsd070520000.07.8.00200
suse461410000.08.6.0029+4
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco9224380961045.56.8.0257+8
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
f56943107111.18.9.0221+5
ivanti49230033555.68.8.5187+3
checkpoint3915303111.17.5.0410+3
ubiquiti584400400.08.9.0052+5
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache8611818425074010.87.0.0048+82
mozilla495511182601300.07.3.0026+44
gitlab1120041224210.04.8.0024+11
docker470520100.08.2.0016+4
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1291334497527532.35.5.0021+129
ibm11601329180700.07.5.0028+11
progress591710900.07.5.0036+5
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+9
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb550410000.07.2.0018+5
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
mitsubishi electric330300000.08.7.0064+3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+37
themerex585855300000.08.1.0043+58
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2
dell2745021230212.26.7.0015+27
open ises044221210000.07.1.00210

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2026-9082.883299.89.8
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-49160.538398.97.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4925710.0.0093
CVE-2026-4714010.0.0082
Most disclosures (vendor)
VendorCVEs
google836
linux524
oracle268
microsoft238
adobe129
red hat107
apache103
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco10
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven42
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171675
CVE-2021-27102Accellion2021-11-171675
CVE-2021-27101Accellion2021-11-171675
CVE-2021-27103Accellion2021-11-171675
CVE-2021-21017Adobe2021-11-171675
CVE-2021-28550Adobe2021-11-171675
CVE-2021-42013Apache2021-11-171675
CVE-2021-41773Apache2021-11-171675
CVE-2021-30858Apple2021-11-171675
CVE-2021-30860Apple2021-11-171675

Transactions

EXPLOIT PUBLISHEDCVE-2025-62821. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48772 (sysown proxysql). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48773 (sysown proxysql). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48774 (sysown proxysql). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49293 (sunnyadn js-toml). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49295 (strukturag libde265). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49346 (strukturag libde265). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50559 (quarkusio quarkus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-51843. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-51844. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-51845. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-51846. Public exploit reference added.

DUE DATE PASSEDCVE-2026-54420 (LiteSpeed Technologies cPanel Plugin). CISA remediation deadline was June 18, 2026; still in catalog.

Yesterday's Results

194 CVEs published. 25 box scores, 169 table rows — nothing truncated.

themefusion Avada (Fusion) Builder — Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0267   84.5     —
AFFECTED
  Product                 Versions     Fixed
  Avada (Fusion) Builder  unspecified  —
TIMELINE
  May 15  Reserved by CNA
  Jun 19  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 2 references · NVD status: Deferred
SIMA GmbH Bondix Server — Authenticated OS Command Injection in Bondix
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0132   68.4     —
AFFECTED
  Product        Versions     Fixed
  Bondix Server  unspecified  1.25.7.6
TIMELINE
  Jun 12  Reserved by CNA
  Jun 19  Published (CNA: NCSC.ch)
CWE-78 · CNA: NCSC.ch · 2 references · NVD status: Deferred
SUSE Rancher — Command injection through unsanitized YAML parameter in Rancher
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4   .0128   67.6     —
AFFECTED
  Product  Versions  Fixed
  Rancher  2.14.0 –  —
TIMELINE
  May 8   Reserved by CNA
  Jun 19  Published (CNA: suse)
CWE-95 · CNA: suse · 1 reference · NVD status: Awaiting Analysis
microsoft kiota-typescript — @microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0118   65.0     —
AFFECTED
  Product           Versions                                    Fixed
  kiota-typescript  >= 1.0.0-preview.97, < 1.0.0-preview.102 –  —
TIMELINE
  May 29  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-178, CWE-200 · CNA: GitHub_M · 2 references · NVD status: Deferred
n/a n/a — Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize c…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0105   61.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Oct 23  Reserved by CNA
  Jun 19  Public exploit reference published
  Jun 19  Published (CNA: mitre)
CWE-125 · CNA: mitre · 1 reference · NVD status: Analyzed
pontedilana php-weasyprint — PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0095   58.3     —
AFFECTED
  Product         Versions   Fixed
  php-weasyprint  < 2.6.0 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · 4 references · NVD status: Deferred
BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0094   58.1     —
AFFECTED
  Product         Versions     Fixed
  BetterDocs Pro  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 19  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · 3 references · NVD status: Deferred
Wdmtech vBizz — Joomla! Component vBizz 1.0.7 Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0089   56.5     —
AFFECTED
  Product  Versions  Fixed
  vBizz    1.0.7 –   —
TIMELINE
  Jun 19  Reserved by CNA
  Jun 19  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 4 references · NVD status: Analyzed
byrongamatos slopsmith — Slopsmith has path traversal in archive extractors that allows arbitrary file write → potential RCE
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.6   .0083   54.6     —
AFFECTED
  Product    Versions           Fixed
  slopsmith  < 0.2.9-alpha.5 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-22, CWE-23, CWE-36 · CNA: GitHub_M · 3 references · NVD status: Deferred
Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0076   52.2     —
AFFECTED
  Product                Versions  Fixed
  Microsoft 365 Copilot  - –       —
TIMELINE
  May 19  Reserved by CNA
  Jun 19  Published (CNA: microsoft)
CWE-601 · CNA: microsoft · 1 reference · NVD status: Analyzed
n/a n/a — In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer o…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   49.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 19  Public exploit reference published
  Jun 19  Published (CNA: mitre)
CWE-121 · CNA: mitre · 1 reference · NVD status: Analyzed
flipped-aurora gin-vue-admin — gin-vue-admin vulnerable to RCE
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0069   49.8     —
AFFECTED
  Product        Versions   Fixed
  gin-vue-admin  = 2.9.1 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Microsoft Exchange Online Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  N    9.6   .0069   49.8     —
AFFECTED
  Product                    Versions  Fixed
  Microsoft Exchange Online  - –       —
TIMELINE
  May 21  Reserved by CNA
  Jun 19  Published (CNA: microsoft)
CWE-862 · CNA: microsoft · 1 reference · NVD status: Analyzed
error311 FileRise — FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0066   48.8     —
AFFECTED
  Product   Versions     Fixed
  FileRise  unspecified  —
TIMELINE
  Jun 13  Reserved by CNA
  Jun 19  Published (CNA: TuranSec)
CWE-22, CWE-434 · CNA: TuranSec · 3 references · NVD status: Deferred
strablengineering STRABL – A checkout solution — STRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0064   47.9     —
AFFECTED
  Product                       Versions     Fixed
  STRABL – A checkout solution  unspecified  —
TIMELINE
  Mar 6   Reserved by CNA
  Jun 19  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 14 references · NVD status: Deferred
Mitsubishi Electric Corporation Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series EtherNet/IP module
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0064   47.6     —
AFFECTED
  Product                                                                    Versions                    Fixed
  Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP  versions 1.000 and prior –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 19  Published (CNA: Mitsubishi)
CWE-190 · CNA: Mitsubishi · 3 references · NVD status: Deferred
Mitsubishi Electric Corporation Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0064   47.6     —
AFFECTED
  Product                                                                         Versions        Fixed
  Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP  All versions –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 19  Published (CNA: Mitsubishi)
CWE-440 · CNA: Mitsubishi · 3 references · NVD status: Deferred
sourcentis mercator — Mercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    5.3   .0063   47.5     —
AFFECTED
  Product   Versions        Fixed
  mercator  < 2025.05.19 –  —
TIMELINE
  May 29  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · 1 reference · NVD status: Deferred
wpmudev Branda – White Label & Branding, Free Login Page Customizer — Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0063   47.1     —
AFFECTED
  Product                                                      Versions     Fixed
  Branda – White Label & Branding, Free Login Page Customizer  unspecified  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 19  Published (CNA: Wordfence)
CWE-640 · CNA: Wordfence · 3 references · NVD status: Deferred
JetBrains Hub — In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.14…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0060   45.9     —
AFFECTED
  Product  Versions     Fixed
  Hub      unspecified  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 19  Published (CNA: JetBrains)
CWE-306 · CNA: JetBrains · 1 reference · NVD status: Analyzed
teamwsa Woosa – Marktplaats for WooCommerce — Woosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0059   45.4     —
AFFECTED
  Product                              Versions     Fixed
  Woosa – Marktplaats for WooCommerce  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 19  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 8 references · NVD status: Deferred
legalweb WP DSGVO Tools (GDPR) — WP DSGVO Tools (GDPR) <= 3.1.39 - Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0058   44.9     —
AFFECTED
  Product                Versions     Fixed
  WP DSGVO Tools (GDPR)  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jun 19  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 12 references · NVD status: Deferred
Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0057   44.7     —
AFFECTED
  Product  Versions     Fixed
  capgo    unspecified  12.128.2
TIMELINE
  Jun 18  Reserved by CNA
  Jun 19  Published (CNA: VulnCheck)
CWE-640 · CNA: VulnCheck · 2 references · NVD status: Deferred
JetBrains Hub — In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.14…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0057   44.6     —
AFFECTED
  Product  Versions     Fixed
  Hub      unspecified  —
TIMELINE
  Jun 19  Reserved by CNA
  Jun 19  Published (CNA: JetBrains)
CWE-915 · CNA: JetBrains · 1 reference · NVD status: Analyzed
dtwang line-desktop-mcp — Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   N    8.8   .0056   44.2     —
AFFECTED
  Product           Versions   Fixed
  line-desktop-mcp  < 1.1.2 –  —
TIMELINE
  May 29  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-306, CWE-862 · CNA: GitHub_M · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-4548010.044.1MicrosoftAzure Active DirectoryCWE-287Azure Active Directory Elevation of Privilege Vulnerability
CVE-2026-481379.344.0NIgrpc-deviceCWE-822Untrusted pointer dereference in NI grpc-device sideband streaming API
CVE-2019-257606.943.0JoomtechEasy ShopCWE-98Joomla! Component Easy Shop 1.2.3 Local File Inclusion
CVE-2026-560806.943.0Cap-gocapgoCWE-287Cap-go - Authentication Logic Flaw in Enforce Password Policy
CVE-2019-257628.742.9JoomboostJoomProjectCWE-359Joomla! Component JoomProject 1.1.3.2 Information Disclosure
CVE-2023-543578.742.9ArtioJoomla! com_booking componentCWE-203Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration
CVE-2026-322085.442.0MicrosoftMicrosoft Edge (Chromium-based)CWE-79Microsoft Entra ID Spoofing Vulnerability
CVE-2026-561419.841.9JetBrainsHubCWE-338In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.14…
CVE-2026-505197.541.4MicrosoftGitHub Copilot ChatCWE-1188Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
CVE-2026-561385.341.2ail-projectail-frameworkCWE-22Authenticated Path Traversal in AIL framework /objects/item/diff Allows Readi…
CVE-2026-126445.541.0n/ats-deepmergeCWE-248Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught …
CVE-2026-485848.840.6MicrosoftAzure SynapseCWE-250Microsoft Azure Synapse Elevation of Privilege Vulnerability
CVE-2026-119896.540.3bitpressadminBit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email AutomationCWE-918Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via F…
CVE-2026-481388.739.8NIgrpc-deviceCWE-125Out-of-bounds read vulnerability in the NI grpc-device streaming API
CVE-2026-481398.739.8NIgrpc-deviceCWE-476NULL pointer dereference vulnerability in NI grpc-device data moniker service
CVE-2026-492918.139.8doobidoomcp-memory-serviceCWE-862mcp-memory-service: OAuth read-only clients can write and delete memories thr…
CVE-2026-487739.838.4sysownproxysqlCWE-787ProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handling
CVE-2026-505597.538.2quarkusioquarkusCWE-287Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabi…
CVE-2025-77378.638.0HitachiHitachi Virtual Storage Platform E990, E1090, E1090HCWE-770DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform
CVE-2026-115767.538.0Eclipse FoundationEclipse ThreadX - NetX DuoCWE-459The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors erro…
CVE-2026-492877.437.9statamiccmsCWE-470Statamic CMS vulnerable to unsafe method invocation via collection sorting al…
CVE-2026-67985.337.72download2Download Connector for 2DL Hosted CheckoutCWE-8622Download Connector for 2DL Hosted Checkout <= 0.1.5 - Missing Authorization …
CVE-2026-472032.937.5autheliaautheliaCWE-178Authelia Missing Username Canonicalization in Basic Auth (LDAP)
CVE-2026-562117.137.5Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9CWE-787Libaom: libaom: remote code execution via svc layer context handling with att…
CVE-2017-202538.837.3GegabyteMy ProjectsCWE-89Joomla! Component My Projects 2.0 SQL Injection
CVE-2017-202548.837.3GegabyteUser BenchCWE-89Joomla! Component User Bench 1.0 SQL Injection via userid
CVE-2017-202558.837.3JoombookingJB VisaCWE-89Joomla! Component JB Visa 1.0 SQL Injection via visatype
CVE-2017-202568.837.3JoomplaceSurvey Force DeluxeCWE-89Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
CVE-2017-202578.837.3JoomplaceQuiz DeluxeCWE-89Joomla! Component Quiz Deluxe 3.7.4 SQL Injection
CVE-2017-202588.837.3ExtroRPCCWE-89Joomla! Component RPC Responsive Portfolio 1.6.1 SQL Injection
CVE-2017-202598.837.3JoomlashackOSDownloadsCWE-89Joomla OSDownloads 1.7.4 SQL Injection via item view
CVE-2017-202608.837.3WeborangePrice AlertCWE-89Joomla! Component Price Alert 3.0.2 SQL Injection
CVE-2017-202618.837.3WeborangeBargain Product VM3CWE-89Joomla! Component Bargain Product VM3 1.0 SQL Injection
CVE-2017-202628.837.3WebkulAjax QuizCWE-89Joomla! Component Ajax Quiz 1.8 SQL Injection
CVE-2017-202638.837.3FocalpointxFocalPoint Pro / FreeCWE-89Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via location
CVE-2017-202668.837.3JoomshaperSP Movie DatabaseCWE-89Joomla SP Movie Database 1.3 SQL Injection via searchword
CVE-2017-202678.837.3JoomlathatCalendar PlannerCWE-89Joomla! Component Calendar Planner 1.0.1 SQL Injection
CVE-2017-202688.837.3ZcontentZap Calendar LiteCWE-89Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection
CVE-2017-202698.837.3TerrywcarterKissGalleryCWE-89Joomla! Component KissGallery 1.0.0 SQL Injection
CVE-2017-202708.837.3RaindropsinfotechTwitch TvCWE-89Joomla! Component Twitch Tv 1.1 SQL Injection
CVE-2019-257488.837.3CmsjunkieJHotelReservationCWE-89Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels
CVE-2019-257508.837.3CmsjunkieMultipleHotelReservationCWE-89Joomla J-MultipleHotelReservation 6.0.7 SQL Injection
CVE-2019-257518.837.3CmsjunkieClassifiedsManagerCWE-89Joomla J-ClassifiedsManager 3.0.5 SQL Injection
CVE-2019-257528.837.3CmsjunkieJ-BusinessDirectoryCWE-89Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection
CVE-2019-257538.837.3WdmtechVMapCWE-89Joomla! Component VMap 1.9.6 SQL Injection via loadmarker
CVE-2019-257548.837.3WdmtechvRestaurantCWE-89Joomla vRestaurant 1.9.4 SQL Injection via menu-listing-layout
CVE-2019-257558.837.3WdmtechvReviewCWE-89Joomla vReview 1.9.11 SQL Injection via editReview
CVE-2019-257568.837.3WdmtechvAccountCWE-89Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard
CVE-2026-481407.137.0NIgrpc-deviceCWE-704Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream
CVE-2026-481296.537.0kestra-iokestraCWE-22Kestra task inputFiles accepts traversal filenames for worker file writes
CVE-2026-90134.336.8rocklobsterincBogoCWE-862Bogo <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitiv…
CVE-2026-518439.836.5n/an/aCWE-121Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the …
CVE-2026-518449.836.5n/an/aCWE-121Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the …
CVE-2026-518459.836.5n/an/aCWE-121Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the …
CVE-2026-91429.336.1NIgrpc-deviceCWE-306Insecure Default Credentials vulnerability in NI grpc-device when TLS configu…
CVE-2017-202528.836.2nextgeneditorNextGen EditorCWE-89Joomla NextGen Editor 2.1.0 SQL Injection via plname Parameter
CVE-2017-202818.836.2JoomlaboatExtra SearchCWE-89Joomla! Component Extra Search 2.2.8 SQL Injection
CVE-2017-202828.836.2Soft-PhpjCart for OpenCartCWE-89Joomla! Component jCart for OpenCart 2.0 SQL Injection
CVE-2026-473416.335.9Apache Software FoundationApache APISIXCWE-294Apache APISIX: Session replay issue in hmac-auth
CVE-2026-493408.135.7sentrizgonicCWE-22gonic has arbitrary file write in createPlaylist: any authenticated user can …
CVE-2026-399997.035.4Apache Software FoundationApache APISIXCWE-290Apache APISIX: JWT Algorithm Confusion allows authentication bypass
CVE-2026-493596.535.3pontedilanaphp-weasyprintCWE-918PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment…
CVE-2017-202778.834.4JoomboostJoomla JoomRecipeCWE-89Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author
CVE-2026-278786.534.2GrafanaEnterprise Traces (GET)CWE-400Tempo TraceQL query with exemplar hint could result in unbounded memory usage
CVE-2026-492937.534.1sunnyadnjs-tomlCWE-400CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
CVE-2026-560797.134.1CapgoCapgoCWE-200Capgo - Cross-Tenant Authorization Bypass via PostgREST Webhook Access
CVE-2026-488952.134.1Apache Software FoundationApache APISIXCWE-601Apache APISIX: Cas-auth Host header influence on CAS service URL
CVE-2017-202647.133.9PulseextensionsSponsor WallCWE-89Joomla! Component Sponsor Wall 8.0 SQL Injection
CVE-2017-202657.133.9PulseextensionsFlip WallCWE-89Joomla! Component Flip Wall 8.0 SQL Injection
CVE-2026-399985.833.5Apache Software FoundationApache APISIXCWE-20Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup
CVE-2026-493425.333.5lsegalyardCWE-22YARD static cache reads raw traversal paths before router sanitization
CVE-2026-449152.133.3Apache Software FoundationApache APISIXCWE-601Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value
CVE-2026-428957.533.1MicrosoftMicrosoft 365 CopilotCWE-77Microsoft Copilot Tampering Vulnerability
CVE-2017-202718.832.6NordmographStreetGuessr GameCWE-89Joomla StreetGuessr Game 1.1.8 SQL Injection via catid
CVE-2017-202728.832.6FabobaUltimate Property ListingCWE-89Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
CVE-2017-202738.832.6JoomlashowroomEvent Registration Pro CalendarCWE-89Joomla Event Registration Pro Calendar 4.1.3 SQL Injection
CVE-2017-202748.832.6King-productsLMS King ProfessionalCWE-89Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath
CVE-2017-202758.832.6HenryschorradtBridgeCWE-89Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter
CVE-2017-202768.832.6SimbunchSIMGenealogyCWE-89Joomla! Component SIMGenealogy 2.1.5 SQL Injection
CVE-2017-202788.832.6JoomboostJoomRecipeCWE-89Joomla JoomRecipe 1.0.3 SQL Injection via category parameter
CVE-2017-202798.832.6ExtensionsJoomla PayageCWE-89Joomla Payage 2.05 SQL Injection via aid Parameter
CVE-2017-202808.832.6MyportfolioMyportfolioCWE-89Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter
CVE-2026-493397.132.0sentrizgonicCWE-22Path traversal in getPlaylist/deletePlaylist bypasses ownership check: any au…
CVE-2026-81186.531.7wproyalRoyal Addons for Elementor – Addons and Templates Kit for ElementorCWE-73Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 …
CVE-2026-493447.131.3sourcentismercatorCWE-359Mercator has a Personal Identifiable Information Leak from Query Executor fea…
CVE-2026-560828.730.3Cap-gocapgoCWE-284Capgo - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_…
CVE-2026-107794.330.2techlabpro1Classified Listing – AI-Powered Classified ads & Business DirectoryCWE-862Classified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscri…
CVE-2019-257497.129.8CmsjunkieJ-CruisePortalCWE-89Joomla J-CruisePortal 6.0.4 SQL Injection via cruises
CVE-2019-257577.129.8WdmtechvWishlistCWE-89Joomla vWishlist 1.0.1 SQL Injection via vproductid Parameter
CVE-2019-257617.129.8JoomboostJoomCRMCWE-89Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id
CVE-2026-480897.129.5l3montree-devdevguardCWE-285DevGuard has improper authorization on public assets
CVE-2026-492312.329.0Apache Software FoundationApache APISIXCWE-290Apache APISIX: Identity spoofing issue in APISIX opa plugin
CVE-2026-40268.728.1FlexeraFlexNet Manager SuiteCWE-284FlexNet Manager Suite Privilege Escalation Vulnerability
CVE-2026-40277.128.1FlexeraFlexNet Manager SuiteCWE-284FlexNet Manager Suite Attachment File Disclosure
CVE-2026-121576.427.9wpdevteamBetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with ChatbotCWE-79BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-562087.627.6Red HatRed Hat Enterprise Linux 10.0 Extended Update SupportCWE-122Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer v…
CVE-2026-43286.427.2addonspressAdvanced ImportCWE-918Advanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated…
CVE-2026-122385.327.2wpgmapsWP Go Maps – Google Map, OpenStreetMap, Leaflet MapCWE-862WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation
CVE-2026-98226.527.0UnknownWP Hotel BookingWP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX…
CVE-2026-124304.426.4creativethemeshqBlocksy CompanionCWE-79Blocksy Companion <= 2.1.45 - Authenticated (Editor+) Stored Cross-Site Scrip…
CVE-2026-18566.426.0creaviCreavi Appointment Booking CalendarCWE-79Appointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-…
CVE-2026-562097.125.7Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9CWE-787Libaom: libaom: arbitrary address write via svc layer context oob and cyclic …
CVE-2026-127266.325.5Red HatRed Hat Ansible Automation Platform 2CWE-918Awx: automation-controller: awx: github webhook second-order ssrf via unvalid…
CVE-2026-498725.324.8Apache Software FoundationApache APISIXCWE-287Apache APISIX: Improper authentication in cas-auth plugin
CVE-2026-117525.924.4LY CorporationArmeriaA vulnerability has been identified in armeria-xds versions 1.38.0 through 1.…
CVE-2026-82965.624.4Octopus DeployOctopus ServerCWE-79In affected versions of Octopus Server with certain access levels it was poss…
CVE-2026-440462.324.1Apache Software FoundationApache APISIXCWE-348Apache APISIX: wolf-rbac plugin Identity Spoofing
CVE-2026-107205.122.5CanonicalMicrocephCWE-23MicroCeph path traversal issue in the remote-import API
CVE-2026-562107.121.4Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9CWE-125Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_se…
CVE-2026-539158.821.3JetBrainsGoLandCWE-73In JetBrains GoLand before 2026.1.3 remote code execution was possible via un…
CVE-2026-493387.121.4sentrizgonicCWE-285Subsonic API: any authenticated user can delete or read any other user's play…
CVE-2026-473395.321.0Apache Software FoundationApache APISIXCWE-863Apache APISIX: authz-casdoor incorrect session sharing
CVE-2026-487941.320.8autheliaautheliaCWE-178Authelia has an Edge Case Access Control Rule Mismatch
CVE-2026-487747.519.8sysownproxysqlCWE-20ProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements …
CVE-2026-560739.319.2Cap-gocapgoCWE-345Cap-go - OTP Bypass via Response Manipulation in Email Verification
CVE-2026-492884.319.2statamiccmsCWE-200Statamic CMS missing authorization on Control Panel fieldtype endpoints allow…
CVE-2019-257597.118.3WdmtechvBizzCWE-89Joomla! Component vBizz 1.0.7 SQL Injection
CVE-2026-498712.117.9Apache Software FoundationApache APISIXCWE-352Apache APISIX: cas-auth login CSRF / session injection issue
CVE-2026-119415.616.7CloudflareQuicheCWE-416Use-after-free in connection ID iterator and FFI functions
CVE-2026-127066.516.0Red HatRed Hat Enterprise Linux AI (RHEL AI) 3CWE-416Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()
CVE-2026-481416.015.3NIgrpc-deviceCWE-401Memory leak in NI grpc-device BeginSidebandStream
CVE-2026-492957.113.7strukturaglibde265CWE-787libde265 has an out-of-bounds write in process_reference_picture_set via pred…
CVE-2026-493467.113.7strukturaglibde265CWE-190libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimensi…
CVE-2026-126204.613.6MicrochipGridTime 3000CWE-200Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server
CVE-2026-492608.213.4pontedilanaphp-weasyprintCWE-78PhpWeasyPrint: shell command injection via configurable WeasyPrint binary pat…
CVE-2026-492306.313.3Apache Software FoundationApache APISIXCWE-354Apache APISIX: Authentication bypass in jwe-decrypt
CVE-2026-440875.311.8Apache Software FoundationApache APISIXCWE-345Apache APISIX: Openid-connect plugin Identity Header Spoofing
CVE-2026-4877210.011.7sysownproxysqlCWE-348ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql…
CVE-2022-509718.510.8MalwarebytesMalwarebytesCWE-428Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
CVE-2026-487157.710.6radvd-projectradvdumpCWE-121radvdump's Route Information Option Parser has a Stack Buffer Overflow
CVE-2026-492716.510.1strukturaglibheifCWE-125libheif: Wrapped icef compressed-unit range check causes out-of-bounds read i…
CVE-2026-493374.39.5strukturaglibde265CWE-770libde265 has an unbounded memory leak via orphaned slice headers in `read_sli…
CVE-2026-117754.39.0adamsilversteinUser Admin SimplifierCWE-352User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery
CVE-2025-713268.58.1AvastAVAST AntivirusCWE-428AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
CVE-2016-200948.58.0AnydeskAnyDeskCWE-428AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege
CVE-2026-91436.37.9NIgrpc-deviceCWE-681Incorrect Conversion between Numeric Types in NI grpc-device due to missing r…
CVE-2016-200878.57.3NetworkdlsFortitude HTTPCWE-428Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege
CVE-2016-200888.57.3ComodoChromodo BrowserCWE-428Comodo Chromodo Browser 52.15.25.664 Unquoted Service Path Privilege Escalation
CVE-2016-200898.57.3IperiusremoteIperius RemoteCWE-428Iperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege
CVE-2016-200908.57.3ComodoDragon BrowserCWE-428Comodo Dragon Browser 52.15.25.663 Privilege Escalation via Unquoted Service …
CVE-2016-200928.57.3NetdriveNetDriveCWE-428NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege
CVE-2016-200938.57.3WisecleanerWise Care 365CWE-428Wise Care 365 4.27 and Wise Disk Cleaner 9.29 Unquoted Service Path Privilege…
CVE-2019-257478.57.3Network-Inventory-AdvisorNetwork Inventory AdvisorCWE-428Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation
CVE-2020-372548.57.3WondersharePDFelementCWE-428Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
CVE-2023-543538.57.3PersonifyincChromacamCWE-428Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation
CVE-2016-200958.57.1Matrix42Matrix42 Remote Control HostCWE-428Matrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation
CVE-2020-372508.57.1Weird-SolutionsTFTP BroadbandCWE-428TFTP Broadband 4.3.0.1465 Unquoted Service Path Privilege Escalation
CVE-2020-372518.57.1RealRealTimes Desktop ServiceCWE-428RealTimes Desktop Service 18.1.4 Unquoted Service Path Privilege Escalation
CVE-2020-372528.57.1RealtekRealtek Audio ServiceCWE-428Realtek Audio Service 1.0.0.55 Unquoted Service Path Privilege Escalation
CVE-2026-31957.46.9qemuCWE-122Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplet…
CVE-2016-200858.56.5RealtekRealtek High Definition Audio DriverCWE-428Realtek High Definition Audio Driver 6.0.1.6730 Privilege Escalation
CVE-2016-200868.56.5VembuVembu StoreGridCWE-428Vembu StoreGrid 4.0 Unquoted Service Path Privilege Escalation
CVE-2016-200918.56.1BinisoftWindows Firewall ControlCWE-428Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation
CVE-2021-479858.56.1BrotherSAPSprintCWE-428Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
CVE-2026-341927.75.8Imagination TechnologiesGraphics DDKCWE-416GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries
CVE-2026-411567.75.8Imagination TechnologiesGraphics DDKCWE-416GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address with…
CVE-2020-372538.55.4WinstepWinstepCWE-428Winstep 18.06.0096 Unquoted Service Path Privilege Escalation
CVE-2026-217686.35.3HCLSoftwareVerse for AndroidCWE-20HCL Verse for Android is susceptible to an injection vulnerability
CVE-2026-493583.04.7pontedilanaphp-weasyprintCWE-73PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $t…
CVE-2026-31965.54.1qemuCWE-190Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
CVE-2026-464617.83.6DellServer Hardware ManagerCWE-284Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper A…
CVE-2026-126215.33.5MicrochipGridTime 3000CWE-79Cross-Site Scripting (XSS) Vulnerability in Password Reset Redirect in GridTi…
CVE-2026-126195.13.5MicrochipGridTime 3000CWE-79GridTime™ 3000 GNSS Time Server CSRF to XSS
CVE-2026-561314.93.4libexpat projectlibexpatCWE-416libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_Resu…
CVE-2026-529087.82.9LinuxLinuxRDMA: During rereg_mr ensure that REREG_ACCESS is compatible
CVE-2026-126225.32.3MicrochipGridTime 3000CWE-601Open Redirect Vulnerability in Password Reset Submission in GridTime™ 3000 GN…
CVE-2026-529097.82.2LinuxLinuxip6_vti: set netns_immutable on the fallback device.
CVE-2026-561326.91.3libexpat projectlibexpatCWE-821In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog i…
CVE-2026-529107.81.2LinuxLinuxCWE-125bpf: Free reuseport cBPF prog after RCU grace period.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-19 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.