boxscore/security
Sunday, June 21, 2026 · all times UTC← 2026-06-20 · archive · 2026-06-22 →

73 CVEs published June 21, 2026: 3 critical, 21 high, 23 medium, 26 low; 0 in KEV; 14 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 48 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published5177954911672563
KEV catalog size1670

439 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux10110678466831212730.37.8.0013-123
google68485883450293297460.78.1.0023+668
microsoft220710554741604378273.87.8.0044+68
red hat75139863626400.07.0.0028+66
apple146101636293711.55.7.0023+1
canonical1150465000.05.5.0009+1
freebsd070520000.07.8.0020-7
suse461410000.08.6.0029+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco9224380961045.56.8.0257+4
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
f56943107111.18.9.0221+5
ivanti49230033555.68.8.5187+3
checkpoint3915303111.17.5.0410+3
ubiquiti584400400.08.9.0052+5
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache8611818425074010.87.0.0048+80
mozilla495511182601300.07.3.0026+44
gitlab1120041224210.04.8.0024+11
docker470520100.08.2.0016+4
drupal0511305120.05.1.0026-2
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1291334497527532.35.5.0021+128
ibm11601329180700.07.5.0028+11
progress591710900.07.5.0036+1
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.0104-1
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+9
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb550410000.07.2.0018+5
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
mitsubishi electric330300000.08.7.0064+3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+37
themerex585855300000.08.1.0043+58
edimax556033023100.07.4.0070+5
concrete cms2461111321000.06.2.0015-39
dell2745021230212.26.7.0015+25
open ises044221210000.07.1.0021-37

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
CVE-2024-21182.499798.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4925710.0.0093
CVE-2026-4714010.0.0082
Most disclosures (vendor)
VendorCVEs
google836
linux517
oracle268
microsoft226
adobe129
red hat107
apache98
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco10
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven39
Packagist22
PyPI10
npm3
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171677
CVE-2021-27102Accellion2021-11-171677
CVE-2021-27101Accellion2021-11-171677
CVE-2021-27103Accellion2021-11-171677
CVE-2021-21017Adobe2021-11-171677
CVE-2021-28550Adobe2021-11-171677
CVE-2021-42013Apache2021-11-171677
CVE-2021-41773Apache2021-11-171677
CVE-2021-30858Apple2021-11-171677
CVE-2021-30860Apple2021-11-171677

Transactions

EXPLOIT PUBLISHEDCVE-2025-71348 (picklescan). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71357 (picklescan). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71378 (picklescan). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-12822 (langflow-ai langflow). Public exploit reference added.

Yesterday's Results

73 CVEs published. 25 box scores, 48 table rows — nothing truncated.

Edimax BR-6478AC V2 POST Request setWAN command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   78.9     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
Edimax BR-6478AC V2 POST Request stainfo command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   78.9     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
Edimax BR-6478AC V2 POST Request wiz_5in1_redirect command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   78.9     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
Edimax BR-6478AC V2 POST Request mp command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   78.9     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   78.9     —
AFFECTED
  Product        Versions   Fixed
  CF-WR631AX V3  2.7.0.0 –  —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
coollabsio coolify Image Name os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   78.9     —
AFFECTED
  Product  Versions  Fixed
  coolify  4.0.0 –   —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0080   53.8     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · 5 references · NVD status: Deferred
Crawl4AI - Authentication Bypass via Hardcoded JWT Signing Key
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0077   52.6     —
AFFECTED
  Product   Versions     Fixed
  Crawl4AI  unspecified  0.8.7
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-798 · CNA: VulnCheck · 3 references · NVD status: Analyzed
picklescan - Remote Code Execution via timeit.timeit() Detection Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   N    7.6   .0071   50.5     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  0.0.25
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-184 · CNA: VulnCheck · 2 references · NVD status: Deferred
SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    9.4   .0070   50.2     —
AFFECTED
  Product  Versions     Fixed
  SiYuan   unspecified  3.6.1
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · 2 references · NVD status: Deferred
SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    9.4   .0070   50.2     —
AFFECTED
  Product  Versions     Fixed
  SiYuan   unspecified  3.6.1
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · 2 references · NVD status: Deferred
Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0068   49.5     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 2 references · NVD status: Deferred
BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0061   46.4     —
AFFECTED
  Product  Versions  Fixed
  litellm  1.59.0 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-287, CWE-303 · CNA: VulDB · 8 references · NVD status: Modified
BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0051   41.1     —
AFFECTED
  Product  Versions  Fixed
  litellm  1.82.0 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · 5 references · NVD status: Analyzed
kortix-ai suna Auth Endpoint page.tsx router.push cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0050   40.4     —
AFFECTED
  Product  Versions  Fixed
  suna     0.8.0 –   0.8.39
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · 8 references · NVD status: Deferred
FlowiseAI Flowise S3 Document Loader S3.ts path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0049   40.2     —
AFFECTED
  Product  Versions  Fixed
  Flowise  3.1.0 –   —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-22 · CNA: VulDB · 5 references · NVD status: Deferred
craftcms cms — Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0049   40.1     —
AFFECTED
  Product  Versions  Fixed
  cms      5.5.0 –   5.9.14
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 2 references · NVD status: Deferred
OFFIS DCMTK ofxml.cc parseFile heap-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   L   L    2.1   .0047   38.5     —
AFFECTED
  Product  Versions  Fixed
  DCMTK    3.0 –     —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-119, CWE-122 · CNA: VulDB · 8 references · NVD status: Deferred
Capgo - Privilege Escalation via Broken Row Level Security in org_users
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   H   H    7.0   .0044   36.9     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 19  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-266 · CNA: VulnCheck · 2 references · NVD status: Deferred
phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0044   36.8     —
AFFECTED
  Product   Versions     Fixed
  phpMyFAQ  unspecified  4.1.4
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-862 · CNA: VulnCheck · 2 references · NVD status: Deferred
Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPC
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0044   36.6     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 19  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · 2 references · NVD status: Deferred
Capgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPC
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0042   35.3     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 19  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-284 · CNA: VulnCheck · 2 references · NVD status: Deferred
Montodel House-Rental-Management login.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0041   34.2     —
AFFECTED
  Product                  Versions                                    Fixed
  House-Rental-Management  90010017b81265eb1ef3810268909f7719a33863 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 5 references · NVD status: Deferred
Cap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/*
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0041   34.1     —
AFFECTED
  Product  Versions     Fixed
  capgo    unspecified  12.128.2
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-203 · CNA: VulnCheck · 2 references · NVD status: Deferred
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testConnection Endpoint deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0041   34.1     —
AFFECTED
  Product                                     Versions  Fixed
  ADP Application Developer Platform 应用开发者平台  1.0.0 –   —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-20, CWE-502 · CNA: VulDB · 5 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-127882.133.2zhilink 智互联(深圳)科技有限公司ADP Application Developer Platform 应用开发者平台CWE-610zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser i…
CVE-2026-127972.133.2BerriAIlitellmCWE-285BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
CVE-2025-713487.632.9picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via torch.utils._config_module.load_con…
CVE-2026-562297.130.7CapgoCapgoCWE-639Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/statu…
CVE-2026-529118.829.3LinuxLinuxksmbd: scope conn->binding slowpath to bound sessions only
CVE-2026-563855.329.0craftcmscmsCWE-639Craft CMS - Authorization Bypass in assets/preview-file Endpoint
CVE-2026-127962.128.9BerriAIlitellmCWE-613BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_…
CVE-2026-128132.127.8n/aactivepiecesCWE-918activepieces File URL file.ts handleUrlFile server-side request forgery
CVE-2026-562397.227.6CapgoCapgoCWE-269Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage
CVE-2025-713787.626.7picklescanpicklescanCWE-502picklescan - Remote Code Execution via Undetected cProfile.runctx in Pickle F…
CVE-2026-127702.126.6BerriAIlitellmCWE-266BerriAI litellm Admin Key key_management_endpoints.py improper authorization
CVE-2026-563947.126.5craftcmscmsCWE-22Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter
CVE-2026-127892.026.1ILIASLearning Management SystemCWE-74ILIAS Learning Management System Learning Progress Tracking class.ilTrQuery.p…
CVE-2026-563845.326.0craftcmscmsCWE-862Craft CMS - Missing Authorization in assets/preview-thumb Endpoint
CVE-2026-128122.025.9RadwareCyber ControllerCWE-74Radware Cyber Controller HTML Report Generation HTML injection
CVE-2026-563934.624.7craftcmscmsCWE-79Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field …
CVE-2026-127762.124.4MontodelHouse-Rental-ManagementCWE-74Montodel House-Rental-Management index.php houses sql injection
CVE-2026-563834.623.6craftcmscmsCWE-79Craft CMS - Stored XSS in Table Field via Row Heading Column Type
CVE-2026-127992.121.3BerriAIlitellmCWE-266BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_vi…
CVE-2026-127711.321.3BerriAIlitellmCWE-266BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
CVE-2025-713577.620.0picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected idlelib.pyshell.Modified…
CVE-2026-127722.118.1BerriAIlitellmCWE-613BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authent…
CVE-2026-127742.118.1BerriAIlitellmCWE-918BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with…
CVE-2026-127982.118.1BerriAIlitellmCWE-918BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_open…
CVE-2026-128042.117.9n/alemonldap-ngCWE-601lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect
CVE-2026-563814.616.8craftcmscmsCWE-79Craft CMS - Stored XSS via User Group Name in User Permissions Page
CVE-2026-563676.314.8ImageMagickImageMagickCWE-125ImageMagick - Heap Out-of-Bounds Read in PSB RLE Decoding
CVE-2026-128221.914.6langflow-ailangflowCWE-74langflow-ai langflow Bundle URL Loader code injection
CVE-2026-563786.313.1ImageMagickImageMagickCWE-125ImageMagick - Heap Out-of-Bounds Read in PCD Decoder
CVE-2026-562366.88.2capgocliCWE-59Capgo CLI - Arbitrary File Overwrite via Symlink-Following in Local Credentia…
CVE-2026-127787.15.9AOMEIPartition AssistantCWE-266AOMEI Partition Assistant Kernel Driver ampa10.sys access control
CVE-2026-127797.15.9AOMEIDynamic Disk ManagerCWE-266AOMEI Dynamic Disk Manager Kernel Driver ddmdrv.sys access control
CVE-2026-127807.15.9AOMEIBackupperCWE-266AOMEI Backupper Kernel Driver amwrtdrv.sys access control
CVE-2026-127847.15.9IM-MagicPartition ResizerCWE-266IM-Magic Partition Resizer Kernel Driver MDA_NTDRV.sys access control
CVE-2026-127867.15.9EzbsystemsUltraISO Premium EditionCWE-266Ezbsystems UltraISO Premium Edition Kernel Driver bootpt64.sys access control
CVE-2026-127817.15.7EaseUSPartition MasterCWE-266EaseUS Partition Master Kernel Driver epmntdrv.sys access control
CVE-2026-127827.15.7EaseUSPartition MasterCWE-266EaseUS Partition Master Kernel Driver EUEDKEPM.sys access control
CVE-2026-128231.95.7BrowserbaseSkillsCWE-266Browserbase Skills Autobrowse Trace Artifact default permission
CVE-2026-564106.93.8libexpat projectlibexpatCWE-190xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-564116.93.8libexpat projectlibexpatCWE-190xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via …
CVE-2026-564125.93.6libexpat projectlibexpatCWE-416libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection …
CVE-2026-564066.93.3libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it l…
CVE-2026-564096.53.4libexpat projectlibexpatCWE-190xmlwf in libexpat before 2.8.2 has an integer overflow for the output filenam…
CVE-2026-564036.92.6libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-564046.92.6libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-564056.92.6libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-564086.92.6libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-564076.92.5libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in doProlog that is related to …

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-21 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.