boxscore/security
Saturday, June 20, 2026 · all times UTC← 2026-06-19 · archive · 2026-06-21 →

42 CVEs published June 20, 2026: 7 critical, 9 high, 23 medium, 3 low; 0 in KEV; 4 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 17 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published5104947611672563
KEV catalog size1670

437 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux10010668466731212730.37.8.0013-116
google68485883450293297460.78.1.0023+668
microsoft220710554741604378273.87.8.0044+68
red hat75139863626400.07.0.0028+66
apple146101636293711.55.7.0023+1
canonical1150465000.05.5.0009+1
freebsd070520000.07.8.00200
suse461410000.08.6.0029+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco9224380961045.56.8.0257+4
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
f56943107111.18.9.0221+5
ivanti49230033555.68.8.5187+3
checkpoint3915303111.17.5.0410+3
ubiquiti584400400.08.9.0052+5
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache8611818425074010.87.0.0048+82
mozilla495511182601300.07.3.0026+44
gitlab1120041224210.04.8.0024+11
docker470520100.08.2.0016+4
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1291334497527532.35.5.0021+128
ibm11601329180700.07.5.0028+11
progress591710900.07.5.0036+1
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+9
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb550410000.07.2.0018+5
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
mitsubishi electric330300000.08.7.0064+3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+37
themerex585855300000.08.1.0043+58
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2
dell2745021230212.26.7.0015+25
open ises044221210000.07.1.00210

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2026-9082.883299.89.8
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4925710.0.0093
CVE-2026-4714010.0.0082
Most disclosures (vendor)
VendorCVEs
google836
linux516
oracle268
microsoft238
adobe129
red hat107
apache101
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco10
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven42
Packagist22
PyPI10
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171676
CVE-2021-27102Accellion2021-11-171676
CVE-2021-27101Accellion2021-11-171676
CVE-2021-27103Accellion2021-11-171676
CVE-2021-21017Adobe2021-11-171676
CVE-2021-28550Adobe2021-11-171676
CVE-2021-42013Apache2021-11-171676
CVE-2021-41773Apache2021-11-171676
CVE-2021-30858Apple2021-11-171676
CVE-2021-30860Apple2021-11-171676

Transactions

EXPLOIT PUBLISHEDCVE-2025-71331 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71379 (vllm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5366 (prefecthq/prefect). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56304 (picklescan). Public exploit reference added.

DUE DATE PASSEDCVE-2026-28318 (SolarWinds Serv-U). CISA remediation deadline was June 19, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-48907 (joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla). CISA remediation deadline was June 19, 2026; still in catalog.

Yesterday's Results

42 CVEs published. 25 box scores, 17 table rows — nothing truncated.

joomshaper.net SP LMS extension for Joomla — Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0764   94.1     —
AFFECTED
  Product                      Versions       Fixed
  SP LMS extension for Joomla  1.0.0-4.1.3 –  —
TIMELINE
  May 26  Reserved by CNA
  Jun 20  Published (CNA: Joomla)
CWE-502 · CNA: Joomla · 1 reference · NVD status: Deferred
eemitch Simple File List — Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0117   64.9     —
AFFECTED
  Product           Versions     Fixed
  Simple File List  unspecified  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 20  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 6 references · NVD status: Deferred
WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0114   63.9     —
AFFECTED
  Product      Versions  Fixed
  WooCommerce  7.1.0 –   —
TIMELINE
  Jan 11  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 3 references · NVD status: Deferred
crmperks Database for Contact Form 7, WPforms, Elementor forms — Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  N  H  H    8.1   .0094   58.0     —
AFFECTED
  Product                                                Versions     Fixed
  Database for Contact Form 7, WPforms, Elementor forms  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jun 20  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 7 references · NVD status: Deferred
Flowise - Remote Code Execution via overrideConfig Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0093   57.5     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  2.1.4
TIMELINE
  Jun 8   Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 2 references · NVD status: Deferred
prefecthq prefecthq/prefect — Git Argument Injection in prefecthq/prefect
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0087   56.0     —
AFFECTED
  Product            Versions       Fixed
  prefecthq/prefect  unspecified –  —
TIMELINE
  Apr 1   Reserved by CNA
  Jun 20  Public exploit reference published
  Jun 20  Published (CNA: @huntr_ai)
CWE-94 · CNA: @huntr_ai · 1 reference · NVD status: Analyzed
Ultimatebeaver Ultimate Addons for Beaver Builder — WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0080   53.6     —
AFFECTED
  Product                             Versions     Fixed
  Ultimate Addons for Beaver Builder  unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-288 · CNA: VulnCheck · 3 references · NVD status: Deferred
JONASBN Crypt::OpenSSL::PKCS12 — Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0063   47.4     —
AFFECTED
  Product                 Versions     Fixed
  Crypt::OpenSSL::PKCS12  unspecified  —
TIMELINE
  May 22  Reserved by CNA
  Jun 20  Published (CNA: CPANSec)
CWE-125 · CNA: CPANSec · 3 references · NVD status: Deferred
Wptimecapsule Time Capsule Plugin — WordPress Time Capsule Plugin 1.21.16 Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0063   47.2     —
AFFECTED
  Product              Versions     Fixed
  Time Capsule Plugin  unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-288 · CNA: VulnCheck · 3 references · NVD status: Deferred
AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   L    6.9   .0062   46.6     —
AFFECTED
  Product  Versions     Fixed
  AVideo   unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 2 references · NVD status: Deferred
eemitch Simple File List — Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0052   41.6     —
AFFECTED
  Product           Versions     Fixed
  Simple File List  unspecified  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 20  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 7 references · NVD status: Deferred
Capgo - Denial of Service via Improper Password Policy Length Validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   N   H    6.9   .0047   38.5     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 19  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-20 · CNA: VulnCheck · 2 references · NVD status: Deferred
eemitch Simple File List — Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .0047   38.5     —
AFFECTED
  Product           Versions     Fixed
  Simple File List  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Jun 20  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 6 references · NVD status: Deferred
Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   L   N   N    6.9   .0046   38.3     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.0.13
TIMELINE
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · 2 references · NVD status: Deferred
Capgo - Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0046   38.0     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 19  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · 2 references · NVD status: Deferred
AVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0046   38.0     —
AFFECTED
  Product  Versions     Fixed
  AVideo   unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-862 · CNA: VulnCheck · 2 references · NVD status: Deferred
AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0045   37.6     —
AFFECTED
  Product  Versions     Fixed
  AVideo   unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-287 · CNA: VulnCheck · 2 references · NVD status: Deferred
picklescan - Arbitrary File Creation via logging.FileHandler Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    6.9   .0044   36.8     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  1.0.1
TIMELINE
  Jun 20  Public exploit reference published
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 2 references · NVD status: Modified
Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0044   36.8     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 19  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-269 · CNA: VulnCheck · 2 references · NVD status: Deferred
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  L  N  N    3.7   .0040   33.6     —
AFFECTED
  Product  Versions  Fixed
  Savane   3.14 –    —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: mitre)
CWE-696 · CNA: mitre · 6 references · NVD status: Deferred
Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privi…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   H   N   L   N   H    5.9   .0040   33.6     —
AFFECTED
  Product      Versions     Fixed
  liquidfiles  unspecified  —
TIMELINE
  Jun 19  Reserved by CNA
  Jun 20  Published (CNA: PRJBLK)
CWE-285 · CNA: PRJBLK · 2 references · NVD status: Deferred
Capgo - Information Disclosure via Unauthenticated /replication Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0040   32.8     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · 2 references · NVD status: Deferred
AVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   N   N    6.1   .0039   32.3     —
AFFECTED
  Product  Versions     Fixed
  AVideo   unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-918 · CNA: VulnCheck · 2 references · NVD status: Deferred
Cap-go capgo — Capgo - Unauthenticated Cross-Tenant Metrics Disclosure via RPC Functions
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0039   32.0     —
AFFECTED
  Product  Versions     Fixed
  capgo    unspecified  12.128.2
TIMELINE
  Jun 19  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · 2 references · NVD status: Deferred
Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   L    8.7   .0039   32.0     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.12
TIMELINE
  Jun 19  Reserved by CNA
  Jun 20  Published (CNA: VulnCheck)
CWE-639 · CNA: VulnCheck · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-563075.330.5Cap-gocapgoCWE-670Cap-go - Broken Cursor Pagination in /private/devices Endpoint
CVE-2026-562766.029.7FlowiseFlowiseCWE-915Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override
CVE-2026-562136.928.3CapgoCapgoCWE-862Capgo - Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_met…
CVE-2026-563408.728.2vLLMvLLMCWE-20vLLM - Denial of Service via Unvalidated Multimodal Embeddings
CVE-2026-562186.927.3CapgoCapgoCWE-200Capgo - EXIF Metadata Exposure via Image Upload
CVE-2026-562125.127.2CapgoCapgoCWE-269Capgo - Improper 2FA Enforcement Logic via Team Security Settings
CVE-2026-563252.326.6CapgoCapgoCWE-20Capgo - App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup
CVE-2025-713795.324.9vllmvllmCWE-1333vllm - Regular Expression Denial of Service in Multiple Components
CVE-2026-562955.323.9CapgoCapgoCWE-285Capgo - Policy Enforcement Bypass in Webhook Management Endpoints via Non-Exp…
CVE-2026-563195.323.2CapgoCapgoCWE-203Capgo - App Existence Oracle via GET /statistics/app/:app_id
CVE-2026-563325.122.5CapgoCapgoCWE-601Capgo - Open Redirect via confirmation_url Parameter
CVE-2026-563475.318.2WWBNAVideoCWE-79AVideo TopMenu Plugin - Stored Cross-Site Scripting via Unescaped Menu Item F…
CVE-2026-562275.317.9CapgoCapgoCWE-918Capgo - Server-Side Request Forgery via Webhook URL Validation
CVE-2026-563304.816.9CapgoCapgoCWE-601Capgo - Open Redirect via Unvalidated Stripe Billing URLs
CVE-2025-713315.113.0FlowiseFlowiseCWE-80Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
CVE-2026-562944.312.4capacitor-native-biometriccapacitor-native-biometricCWE-287capacitor-native-biometric - Authentication Bypass via Unvalidated CryptoObje…
CVE-2026-563172.311.3NuxtNuxtCWE-79Nuxt - Cross-Site Scripting via NoScript Component Slot Content

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-20 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.