AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0115 64.3 —
AFFECTED Product Versions Fixed vllm >= 0.3.0, < 0.22.0 – —
TIMELINE May 22 Reserved by CNA Jun 22 Published (CNA: GitHub_M)
220 CVEs published June 22, 2026: 21 critical, 80 high, 105 medium, 14 low; 0 in KEV; 22 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 195 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 5397 | 9769 | 1167 | 2563 |
| KEV catalog size | 1670 | |||
446 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 101 | 1067 | 84 | 668 | 312 | 1 | 27 | 3 | 0.3 | 7.8 | .0013 | -123 |
| 684 | 858 | 83 | 450 | 293 | 29 | 74 | 6 | 0.7 | 8.1 | .0023 | +668 | |
| microsoft | 220 | 710 | 55 | 474 | 160 | 4 | 378 | 27 | 3.8 | 7.8 | .0044 | +56 |
| red hat | 79 | 143 | 8 | 65 | 64 | 6 | 4 | 0 | 0.0 | 7.0 | .0028 | +70 |
| apple | 14 | 61 | 0 | 16 | 36 | 2 | 93 | 7 | 11.5 | 5.7 | .0023 | +1 |
| canonical | 2 | 16 | 1 | 4 | 6 | 5 | 0 | 0 | 0.0 | 5.5 | .0010 | +2 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | -7 |
| suse | 4 | 6 | 1 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 9 | 22 | 4 | 3 | 8 | 0 | 96 | 10 | 45.5 | 6.8 | .0257 | +4 |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | +17 |
| palo alto networks | 9 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | +8 |
| f5 | 6 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | +4 |
| ivanti | 4 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | +2 |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 |
| ubiquiti | 5 | 8 | 4 | 4 | 0 | 0 | 4 | 0 | 0.0 | 8.9 | .0052 | +3 |
| fortinet | 2 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 92 | 124 | 18 | 44 | 53 | 8 | 40 | 1 | 0.8 | 6.8 | .0048 | +83 |
| mozilla | 49 | 55 | 11 | 18 | 26 | 0 | 13 | 0 | 0.0 | 7.3 | .0026 | +44 |
| gitlab | 11 | 20 | 0 | 4 | 12 | 2 | 4 | 2 | 10.0 | 4.8 | .0024 | +11 |
| docker | 4 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | +1 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | -3 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 243 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | +243 |
| adobe | 129 | 133 | 4 | 49 | 75 | 2 | 75 | 3 | 2.3 | 5.5 | .0021 | +128 |
| ibm | 32 | 81 | 19 | 35 | 27 | 0 | 7 | 0 | 0.0 | 7.5 | .0028 | +32 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +1 |
| solarwinds | 3 | 6 | 1 | 2 | 1 | 0 | 11 | 4 | 66.7 | 7.5 | .3995 | +3 |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | +1 |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | -1 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 9 | 12 | 0 | 4 | 2 | 5 | 26 | 1 | 8.3 | 5.5 | .0058 | +9 |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 1 | 0 | 0.0 | 7.5 | .0020 | +6 |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 |
| abb | 5 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +5 |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | +3 |
| mitsubishi electric | 3 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.7 | .0064 | +3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 71 | 72 | 2 | 30 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0023 | +71 |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +61 |
| sourcecodester | 37 | 59 | 0 | 0 | 25 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +37 |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 |
| edimax | 5 | 56 | 0 | 33 | 0 | 23 | 1 | 0 | 0.0 | 7.4 | .0070 | +5 |
| dell | 31 | 49 | 0 | 24 | 24 | 0 | 2 | 1 | 2.0 | 6.8 | .0015 | +19 |
| concrete cms | 2 | 46 | 1 | 11 | 13 | 21 | 0 | 0 | 0.0 | 6.2 | .0015 | -42 |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | -37 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE-2026-48907 | .6883 | 99.3 | 10.0 |
| CVE-2026-49160 | .5383 | 98.9 | 7.5 |
| CVE-2026-10523 | .5187 | 98.9 | 9.8 |
| CVE-2024-21182 | .4997 | 98.8 | — |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-49257 | 10.0 | .0093 | |
| CVE-2026-10561 | 10.0 | .0091 |
| Vendor | CVEs |
|---|---|
| 836 | |
| linux | 515 |
| oracle | 268 |
| microsoft | 226 |
| adobe | 129 |
| red hat | 111 |
| apache | 104 |
| ibm | 81 |
| spring | 72 |
| openclaw | 67 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 10 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 43 |
| Packagist | 22 |
| PyPI | 10 |
| npm | 3 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-28318 | SolarWinds | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1678 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1678 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1678 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1678 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1678 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1678 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1678 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1678 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1678 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1678 |
EXPLOIT PUBLISHED — CVE-2025-66389. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10645 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10651 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-12549 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41479 (authlib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44311 (fabricjs fabric.js). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48931 (nodejs node). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50146 (withastro astro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53550 (nodeca js-yaml). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53571 (vitejs vite). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53655 (isaacs node-tar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54232 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54235 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54236 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54298 (withastro astro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55599 (phpseclib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55602 (chimurai http-proxy-middleware). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55603 (chimurai http-proxy-middleware). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56268 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-6653 (GNOME libxml2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-6858 (Unknown Transbank Webpay). Public exploit reference added.
DUE DATE PASSED — CVE-2026-20253 (Splunk Enterprise). CISA remediation deadline was June 21, 2026; still in catalog.
220 CVEs published. 25 box scores, 195 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0115 64.3 —
AFFECTED Product Versions Fixed vllm >= 0.3.0, < 0.22.0 – —
TIMELINE May 22 Reserved by CNA Jun 22 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N N N H H H 8.7 .0102 60.6 —
AFFECTED Product Versions Fixed Archer MR200 v07 unspecified — Archer MR200 v8 unspecified — Archer MR402 v1 unspecified — Archer VR2100 v1 unspecified — Archer C20 v5 unspecified — Archer C20 v6 unspecified — TL-MR6400 v7 unspecified —
TIMELINE Jun 9 Reserved by CNA Jun 22 Published (CNA: TPLink)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0094 58.0 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Nov 28 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0091 57.2 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Jun 1 Reserved by CNA Jun 22 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0082 54.3 —
AFFECTED Product Versions Fixed vllm < 0.23.1rc0 – —
TIMELINE Jun 12 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N R U H H H 7.5 .0075 51.8 —
AFFECTED Product Versions Fixed vllm < 0.22.0 – —
TIMELINE Apr 20 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H H 9.6 .0070 50.2 —
AFFECTED Product Versions Fixed Fusion 2703.1.11 – —
TIMELINE Jun 3 Reserved by CNA Jun 22 Published (CNA: autodesk)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0064 47.6 —
AFFECTED Product Versions Fixed Capgo unspecified 12.128.2
TIMELINE Jun 20 Reserved by CNA Jun 22 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H N 7.6 .0064 47.6 —
AFFECTED Product Versions Fixed picklescan unspecified 0.0.30
TIMELINE Jun 20 Reserved by CNA Jun 22 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H H 8.1 .0063 47.2 —
AFFECTED Product Versions Fixed PMI v8xx 0.0.0 – — PASvisu 0.0.0 – —
TIMELINE Oct 13 Reserved by CNA Jun 22 Published (CNA: CERTVDE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L N 6.9 .0062 46.7 —
AFFECTED Product Versions Fixed Central Dogma unspecified 0.84.0
TIMELINE Jun 9 Reserved by CNA Jun 22 Published (CNA: LY-Corporation)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0060 46.0 —
AFFECTED Product Versions Fixed misp unspecified —
TIMELINE Jun 22 Reserved by CNA Jun 22 Published (CNA: CIRCL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 .0059 45.5 —
AFFECTED Product Versions Fixed litellm < 1.84.0 – —
TIMELINE May 30 Reserved by CNA Jun 22 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0059 45.3 —
AFFECTED Product Versions Fixed webp_server_go unspecified —
TIMELINE Jun 10 Reserved by CNA Jun 22 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H N N 8.2 .0059 45.3 —
AFFECTED Product Versions Fixed vite >= 8.0.0, < 8.0.16 – —
TIMELINE Jun 9 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A L N N 5.1 .0058 44.8 —
AFFECTED Product Versions Fixed ail framework unspecified —
TIMELINE Jun 22 Reserved by CNA Jun 22 Published (CNA: CIRCL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L L 6.9 .0057 44.5 —
AFFECTED Product Versions Fixed Assassin game last version – —
TIMELINE Apr 27 Reserved by CNA Jun 22 Published (CNA: INCIBE)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0057 44.4 —
AFFECTED Product Versions Fixed Net::Statsite::Client unspecified —
TIMELINE Jun 5 Reserved by CNA Jun 22 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0056 44.1 —
AFFECTED Product Versions Fixed vllm < 0.22.1 – —
TIMELINE Jun 12 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0056 44.0 —
AFFECTED Product Versions Fixed Apache Doris MCP Server 0.1.0 – —
TIMELINE Nov 27 Reserved by CNA Jun 22 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0056 43.7 —
AFFECTED Product Versions Fixed nltk < 3.10.0-rc1 – —
TIMELINE Jun 12 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0055 43.4 —
AFFECTED Product Versions Fixed WebSphere Application Server 9.0.0 – — WebSphere Application Server - Liberty 17.0.0.3 – —
TIMELINE May 20 Reserved by CNA Jun 22 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 9.2 .0054 43.1 —
AFFECTED Product Versions Fixed Assassin game last version – —
TIMELINE Apr 27 Reserved by CNA Jun 22 Published (CNA: INCIBE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H N 7.6 .0052 42.0 —
AFFECTED Product Versions Fixed Picklescan unspecified 0.0.33
TIMELINE Jun 20 Reserved by CNA Jun 22 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 6.9 .0051 41.2 —
AFFECTED Product Versions Fixed Cloud Console UIs unspecified —
TIMELINE May 19 Reserved by CNA Jun 22 Published (CNA: GoogleCloud)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-48109 | 8.2 | 41.1 | MessagePack-CSharp | MessagePack-CSharp | CWE-20 | MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException … |
| CVE-2025-62198 | 5.4 | 40.9 | Apache Software Foundation | Apache Atlas | CWE-80 | Apache Atlas: Stored XSS in Create Entity page |
| CVE-2026-7664 | 9.8 | 40.5 | IBM | Langflow OSS | CWE-287 | Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS |
| CVE-2026-54281 | 8.7 | 40.5 | nestjs | nest | CWE-863 | Nest: Middleware Bypass on Fastify via Trailing Slash |
| CVE-2026-47240 | 5.8 | 40.0 | ruby | net-imap | CWE-77 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument |
| CVE-2026-7165 | 9.4 | 39.4 | Gaudire | Assassin game | CWE-20 | Multiple vulnerabilities in the Assassin game by Gaudire |
| CVE-2026-56266 | 9.2 | 39.1 | Crawl4AI | Crawl4AI | CWE-918 | Crawl4AI - Server-Side Request Forgery via Direct Crawl Endpoints |
| CVE-2026-48506 | 7.5 | 38.8 | MessagePack-CSharp | MessagePack-CSharp | CWE-674 | MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maxi… |
| CVE-2026-10845 | 7.3 | 38.4 | IBM | WebSphere Application Server | CWE-287 | IBM WebSphere Application Server is affected by an authentication bypass vuln… |
| CVE-2026-56324 | 8.8 | 38.3 | Capgo | Capgo | CWE-770 | Capgo - Rate Limit Bypass via User-Controlled device_id Parameter |
| CVE-2026-48712 | 7.5 | 38.0 | protobufjs | protobuf.js | CWE-674 | protobufjs: Denial of service through unbounded Any expansion during JSON con… |
| CVE-2026-56321 | 6.9 | 37.7 | Capgo | Capgo | CWE-306 | Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint |
| CVE-2026-55388 | 8.1 | 37.7 | piscinajs | piscina | CWE-94 | piscina: Prototype Pollution Gadget → RCE via inherited options.filename |
| CVE-2026-12581 | 7.7 | 37.6 | Digiwin | EasyFlow .NET | CWE-384 | Digiwin|EasyFlow .NET - Session Fixation |
| CVE-2026-12888 | 2.0 | 36.9 | Thinkst Applied Research | Canarytokens | CWE-74 | HTML injection in the Canarytoken Google Chat notification |
| CVE-2026-42129 | 7.7 | 36.8 | Grafana | Grafana OSS | CWE-22 | Path traversal in the Loki data source plugin |
| CVE-2026-11942 | 4.8 | 36.7 | Akaunting | Akaunting | CWE-79 | Akaunting 3.1.21 - Stored XSS in delete confirmation modal |
| CVE-2026-11943 | 4.8 | 36.7 | Akaunting | Akaunting | CWE-79 | Akaunting 3.1.21 - Authenticated stored XSS in document timeline |
| CVE-2026-11994 | 4.8 | 36.7 | Akaunting | Akaunting | CWE-79 | Akaunting 3.1.21 - Authenticated stored XSS in report description rendering |
| CVE-2026-56448 | 8.3 | 36.4 | ail project | ail framework | CWE-22 | Authenticated Path Traversal in AIL Framework Investigation Downloads Allows … |
| CVE-2026-39904 | 7.1 | 36.3 | gophish | gophish | CWE-770 | Gophish 0.12.1 Denial of Service via Office Document Upload |
| CVE-2026-54286 | 5.9 | 36.1 | honojs | hono | CWE-22 | Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) |
| CVE-2026-42127 | 7.5 | 36.0 | Grafana | Grafana Enterprise | CWE-400 | Pre-authentication denial of service in the public dashboard query endpoint |
| CVE-2025-71358 | 7.6 | 35.9 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via idlelib.autocomplete.AutoComplete.get_… |
| CVE-2026-56314 | 7.1 | 35.5 | Capgo | Capgo | CWE-672 | Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endp… |
| CVE-2026-54233 | 6.5 | 35.2 | vllm-project | vllm | CWE-409 | vLLM: OOM Denial of Service via Audio Decompression Bomb |
| CVE-2024-54178 | 6.5 | 35.0 | IBM | Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | CWE-770 | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Wareh… |
| CVE-2026-8157 | 8.8 | 34.8 | Unknown | Vitepos | CWE-269 | Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation |
| CVE-2026-56698 | 5.3 | 34.4 | Nuxt | Nuxt | CWE-79 | Nuxt - Cross-Site Scripting via navigateTo open Option |
| CVE-2026-12549 | 4.8 | 34.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-805 | Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup s… |
| CVE-2026-9072 | 9.8 | 34.1 | IBM | WebSphere Application Server | CWE-94 | WebSphere Application Server Remote Code Execution |
| CVE-2026-12725 | 5.9 | 33.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupporte… |
| CVE-2026-54269 | 5.3 | 33.4 | protobufjs | protobuf.js | CWE-674 | protobufjs: Schema-derived names can shadow runtime-significant properties |
| CVE-2026-54270 | 5.3 | 33.4 | protobufjs | protobuf.js | CWE-770 | protobufjs: Memory amplification from preserved unknown fields in binary decode |
| CVE-2026-54283 | 7.5 | 32.9 | Kludex | starlette | CWE-770 | Starlette: request.form() limits silently ignored for application/x-www-form-… |
| CVE-2026-54278 | 6.6 | 32.9 | aio-libs | aiohttp | CWE-409 | AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup |
| CVE-2026-44914 | 7.5 | 32.5 | Apache Software Foundation | Apache NiFi | CWE-862 | Apache NiFi: Missing Authorization of Restricted Permissions when Replacing F… |
| CVE-2026-56446 | 8.7 | 32.2 | misp | misp | CWE-94 | Authenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISP |
| CVE-2026-44913 | 5.2 | 31.7 | Apache Software Foundation | Apache NiFi | CWE-116 | Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL |
| CVE-2026-12479 | 6.1 | 31.5 | keras-team | keras-team/keras | CWE-22 | Path Traversal in keras-team/keras |
| CVE-2026-12862 | 5.1 | 31.3 | pretix | Venueless | CWE-148 | XLSX formula injection in exports |
| CVE-2026-53539 | 7.5 | 31.2 | Kludex | python-multipart | CWE-400 | Python-Multipart: Quadratic-time querystring parsing with semicolon separator… |
| CVE-2026-56221 | 7.1 | 31.1 | Cap-go | capgo | CWE-89 | Cap-go - SQL Injection in Cloudflare Analytics Engine Queries via cloudflare.ts |
| CVE-2026-53550 | 5.3 | 30.9 | nodeca | js-yaml | CWE-407 | js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases |
| CVE-2026-56255 | 5.3 | 30.5 | Capgo | Capgo | CWE-770 | Capgo - Denial of Service via Unlimited Demo App Creation |
| CVE-2026-56280 | 7.1 | 30.3 | Cap-go | capgo | CWE-862 | Cap-go - Privilege Inversion in Build Log Stream via SSE Disconnect |
| CVE-2026-55602 | 6.9 | 30.1 | chimurai | http-proxy-middleware | CWE-20 | http-proxy-middleware `router` host+path substring matching allows Host-heade… |
| CVE-2026-8646 | 9.1 | 29.6 | IBM | WebSphere Application Server | CWE-444 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-56311 | 6.9 | 29.5 | Capgo | Capgo | CWE-285 | Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC |
| CVE-2026-56326 | 5.3 | 29.3 | Nuxt | Nuxt | CWE-601 | Nuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateTo |
| CVE-2026-56424 | 7.1 | 29.2 | misp | misp | CWE-639 | Broken access control in MISP core allows cross-organization unauthorized mod… |
| CVE-2026-12628 | 9.1 | 28.8 | IBM | Storage Protect Client | CWE-798 | Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to… |
| CVE-2026-6653 | 7.0 | 28.6 | GNOME | libxml2 | CWE-416 | libxml2: Use after free in xmlParseInternalSubset via improper entity resolut… |
| CVE-2026-45034 | 9.2 | 28.2 | PHPOffice | PhpSpreadsheet | CWE-502 | PhpSpreadsheet: File::prohibitWrappers bypass |
| CVE-2026-12863 | 5.1 | 28.1 | pretix | Venueless | CWE-601 | Open redirect |
| CVE-2026-9320 | 7.5 | 28.0 | IBM | WebSphere Application Server | CWE-400 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-53632 | 5.5 | 28.0 | vitejs | launch-editor | CWE-73 | NTLMv2 hash disclosure via UNC path handling on Windows |
| CVE-2026-48166 | 5.3 | 27.5 | filamentphp | filament | CWE-208 | Filament: Timing-based user enumeration on login page |
| CVE-2026-56306 | 5.3 | 27.5 | Capgo | Capgo | CWE-20 | Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing |
| CVE-2026-48931 | 3.7 | 27.5 | nodejs | node | CWE-367 | A flaw in Node.js HTTP Agent can cause a client to accept as valid a response… |
| CVE-2026-54285 | 5.3 | 27.4 | open-telemetry | opentelemetry-js | CWE-770 | opentelemetry-js: Unbounded memory allocation in W3C Baggage propagation |
| CVE-2026-48500 | 6.5 | 27.3 | filamentphp | filament | CWE-862 | Filament: Unauthenticated temporary file upload on auth pages |
| CVE-2026-56447 | 9.3 | 27.2 | misp | misp | CWE-829 | MISP remote code execution via arbitrary rdkafka configuration path |
| CVE-2026-56268 | 5.3 | 26.6 | Flowise | Flowise | CWE-863 | Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint |
| CVE-2026-56697 | 5.3 | 26.6 | Nuxt | Nuxt | CWE-601 | Nuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtApp |
| CVE-2026-9162 | 4.3 | 26.4 | Mattermost | Mattermost | CWE-613 | Global session revocation does not invalidate active WebSocket connections |
| CVE-2026-54299 | 7.5 | 26.1 | withastro | astro | CWE-20 | Astro: Host-header full-read SSRF in core prerendered error-page fetch (prere… |
| CVE-2025-4994 | 8.7 | 26.0 | SafeLine | SafeLine SL6/SL6+ | CWE-305 | Authentication Bypass for SafeLine SL6 and SL6+ |
| CVE-2026-54290 | 7.1 | 25.7 | honojs | hono | CWE-942 | Hono: CORS Middleware reflects any Origin with credentials when `origin` defa… |
| CVE-2026-56423 | 9.4 | 25.5 | misp | misp | CWE-862 | MISP Core: Broken access control allows instance-wide unauthorized deletion o… |
| CVE-2026-54268 | 8.2 | 25.5 | angular | angular | CWE-400 | Angular: Denial of Service (DoS) via OOM in Date Formatting (formatDate) |
| CVE-2026-44911 | 2.3 | 25.5 | Apache Software Foundation | Apache NiFi | CWE-863 | Apache NiFi: Incorrect Authorization for Configuration Verification Requests |
| CVE-2026-54277 | 6.6 | 25.0 | aio-libs | aiohttp | CWE-770 | AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines |
| CVE-2026-8074 | 3.8 | 24.5 | Mattermost | Mattermost | CWE-863 | Improper Permission Check Allows User Manager to Deactivate Bot Accounts |
| CVE-2026-8823 | 3.8 | 24.5 | Mattermost | Mattermost | CWE-863 | User Manager can demote bot accounts to guest without bot-management permission |
| CVE-2026-54300 | 5.3 | 24.0 | withastro | astro | CWE-918 | @astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config |
| CVE-2026-54287 | 5.3 | 23.7 | honojs | hono | CWE-116 | Hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value,… |
| CVE-2026-44727 | 9.3 | 23.1 | jupyter-server | jupyter_server | CWE-79 | Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler`… |
| CVE-2026-54274 | 6.6 | 23.1 | aio-libs | aiohttp | CWE-770 | AIOHTTP: Incomplete websocket frame payloads bypass memory limits |
| CVE-2026-54271 | 8.2 | 22.9 | protobufjs | protobufjs-cli | CWE-94 | protobufjs-cli: Code injection in pbjs static output from crafted JSON descri… |
| CVE-2026-50269 | 2.7 | 22.7 | aio-libs | aiohttp | CWE-93 | AIOHTTP: CRLF injection in multipart headers |
| CVE-2026-48067 | 6.5 | 22.5 | filamentphp | filament | CWE-639 | Filament: Inconsistent scope enforcement for AttachAction and AssociateAction… |
| CVE-2026-6673 | 6.4 | 22.5 | Mattermost | Mattermost | CWE-306 | Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callba… |
| CVE-2026-48505 | 7.4 | 22.2 | filamentphp | filament | CWE-362 | Filament: Multi-factor authentication (app) recovery codes can still be used … |
| CVE-2026-10852 | 7.5 | 21.8 | IBM | WebSphere Application Server | CWE-476 | Websphere Application Server is Affected By a Denial of Service |
| CVE-2026-6858 | 7.1 | 21.8 | Unknown | Transbank Webpay | CWE-79 | Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS |
| CVE-2026-5139 | 5.4 | 21.2 | Mattermost | Mattermost | CWE-862 | GitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration |
| CVE-2026-54100 | 8.3 | 21.0 | Red Hat | Red Hat OpenShift for Windows Containers 10.22 | CWE-295 | Windows-machine-config-operator: windows-machine-config-operator: ssh host ke… |
| CVE-2026-55409 | 7.6 | 20.9 | filamentphp | filament | CWE-79 | Filament: Disabled RichEditor field state can be used for XSS |
| CVE-2026-53923 | 5.3 | 20.6 | vllm-project | vllm | CWE-200 | vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU … |
| CVE-2026-54280 | 1.7 | 20.6 | aio-libs | aiohttp | CWE-404 | AIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnect |
| CVE-2026-10651 | 6.5 | 20.5 | zephyrproject | zephyr | CWE-20 | Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_… |
| CVE-2026-12580 | 5.1 | 20.5 | Digiwin | EasyFlow .NET | CWE-79 | Digiwin|EasyFlow .NET - Stored Cross-Site Scripting |
| CVE-2026-8918 | 7.1 | 20.4 | ASUS | Armoury Crate | CWE-183 | A permissive list of allowed inputs in ASUS Armoury Crate allows a local admi… |
| CVE-2026-54273 | 6.6 | 20.4 | aio-libs | aiohttp | CWE-770 | AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit |
| CVE-2026-54279 | 1.3 | 20.4 | aio-libs | aiohttp | CWE-665 | AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence |
| CVE-2026-50178 | 8.7 | 19.9 | angular | angular | CWE-79 | Angular: Remote Code Execution via JSDoc Hover Command Injection in VS Code A… |
| CVE-2026-54911 | 6.5 | 19.6 | ultrajson | ultrajson | CWE-20 | UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson… |
| CVE-2026-54235 | 6.9 | 19.3 | vllm-project | vllm | CWE-1287 | vLLM: temperature=NaN and temperature=Infinity bypass validation and propagat… |
| CVE-2026-50170 | 8.2 | 19.0 | angular | angular | CWE-524 | Angular: Information Leak via Default Caching of Credentialed Requests in Htt… |
| CVE-2026-54665 | 6.3 | 18.9 | Apache Software Foundation | Apache NiFi | CWE-346 | Apache NiFi: Missing Validation for Proxy Host Headers |
| CVE-2026-50146 | 6.1 | 19.0 | withastro | astro | CWE-80 | Astro: Reflected XSS via unescaped slot name |
| CVE-2026-54275 | 2.7 | 18.6 | aio-libs | aiohttp | CWE-297 | AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections |
| CVE-2026-55603 | 7.5 | 18.5 | chimurai | http-proxy-middleware | CWE-93 | http-proxy-middleware: multipart/form-data field injection via unescaped CRLF… |
| CVE-2026-56348 | 5.3 | 18.1 | n8n | n8n | CWE-918 | n8n - Credential Exfiltration via Allowed HTTP Request Domains Bypass in Dyna… |
| CVE-2026-8858 | 8.8 | 17.9 | IBM | WebSphere Application Server | CWE-94 | WebSphere Application Server Remote Code Execution |
| CVE-2026-56425 | 9.3 | 17.7 | misp | misp | CWE-384 | MISP AAD authentication plugin - Improper OAuth State Handling, Missing Sessi… |
| CVE-2026-10601 | 4.3 | 17.7 | Grafana | Grafana OSS | CWE-22 | Path traversal in the Tempo and Loki data source plugins |
| CVE-2026-56104 | 8.8 | 17.4 | Chainlit | chainlit | CWE-862 | Chainlit < 2.10.1 Session Hijacking via WebSocket Session Restoration |
| CVE-2026-48502 | 8.2 | 17.3 | MessagePack-CSharp | MessagePack-CSharp | CWE-125 | MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or cr… |
| CVE-2026-4110 | 6.1 | 17.0 | Unknown | ultimate-woocommerce-auction-pro | — | Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bi… |
| CVE-2026-4259 | 7.1 | 16.8 | Unknown | ultimate-woocommerce-auction-pro | CWE-79 | Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auct… |
| CVE-2026-9029 | 5.4 | 16.7 | Grafana | Grafana OSS | CWE-79 | Stored XSS in the Geomap panel tile-layer attribution |
| CVE-2023-33854 | 5.3 | 16.7 | IBM | Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | CWE-294 | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Wareh… |
| CVE-2026-44271 | 8.8 | 16.6 | Dell | Wyse Management Suite (WMS) | CWE-89 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Impr… |
| CVE-2026-44272 | 8.8 | 16.6 | Dell | Wyse Management Suite (WMS) | CWE-89 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Impr… |
| CVE-2026-48509 | 6.3 | 16.6 | MessagePack-CSharp | MessagePack-CSharp | CWE-1188 | MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to Truste… |
| CVE-2026-47155 | 6.5 | 16.5 | vllm-project | vllm | CWE-345 | vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned c… |
| CVE-2026-48167 | 6.4 | 16.2 | filamentphp | filament | CWE-79 | Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS |
| CVE-2026-48517 | 6.3 | 16.2 | MessagePack-CSharp | MessagePack-CSharp | CWE-470 | MessagePack-CSharp: Typeless deserialization type restrictions do not recurse… |
| CVE-2026-6062 | 6.4 | 15.3 | Mattermost | Mattermost | CWE-639 | IDOR in Jira plugin subscription edit endpoint |
| CVE-2026-9006 | 9.1 | 15.3 | IBM | WebSphere Application Server | CWE-918 | IBM WebSphere Application Server is affected by server-side request forgery |
| CVE-2026-47241 | 2.1 | 15.2 | ruby | net-imap | CWE-162 | Net::IMAP: Denial of Service via incomplete raw argument validation |
| CVE-2026-50556 | 8.6 | 14.8 | angular | angular | CWE-79 | Angular: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-… |
| CVE-2026-48510 | 6.3 | 14.9 | MessagePack-CSharp | MessagePack-CSharp | CWE-409 | MessagePack-CSharp: LZ4 decompression allocates from unbounded declared outpu… |
| CVE-2026-8059 | 6.1 | 14.8 | IBM | Datacap | CWE-79 | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-54264 | 8.3 | 14.7 | angular | angular | CWE-200 | Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Servic… |
| CVE-2026-52725 | 5.3 | 14.6 | angular | angular | CWE-79 | Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site… |
| CVE-2026-48511 | 6.3 | 14.2 | MessagePack-CSharp | MessagePack-CSharp | CWE-407 | MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion w… |
| CVE-2026-48512 | 6.3 | 14.2 | MessagePack-CSharp | MessagePack-CSharp | CWE-674 | MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth… |
| CVE-2026-48513 | 6.3 | 14.2 | MessagePack-CSharp | MessagePack-CSharp | CWE-674 | MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth e… |
| CVE-2026-48515 | 6.3 | 14.2 | MessagePack-CSharp | MessagePack-CSharp | CWE-770 | MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecke… |
| CVE-2026-48514 | 6.3 | 14.2 | MessagePack-CSharp | MessagePack-CSharp | CWE-770 | MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte… |
| CVE-2026-48516 | 6.3 | 14.2 | MessagePack-CSharp | MessagePack-CSharp | CWE-407 | MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant com… |
| CVE-2025-33128 | 5.4 | 14.2 | IBM | Engineering Workflow Management | CWE-79 | IBM Engineering Lifecycle Management - Engineering Workflow Management is imp… |
| CVE-2026-11372 | 5.4 | 14.2 | IBM | TRIRIGA Application Platform | CWE-79 | IBM TRIRIGA Cross-Site Scripting Vulnerability |
| CVE-2026-44311 | 6.1 | 13.8 | fabricjs | fabric.js | CWE-79 | Fabric.js: Improper escaping in fabric.Gradient colorStops leads to XSS in SV… |
| CVE-2026-54298 | 6.1 | 13.8 | withastro | astro | CWE-79 | Astro: XSS via Unescaped Attribute Names in Spread Props |
| CVE-2026-46417 | 8.8 | 12.9 | angular | angular | CWE-918 | Angular: SSRF via Hostname Hijacking in @angular/platform-server |
| CVE-2026-11745 | 8.8 | 12.6 | LY Corporation | Central Dogma | CWE-322 | A vulnerability has been identified in centraldogma-server-mirror-git version… |
| CVE-2026-53540 | 3.7 | 12.4 | Kludex | python-multipart | CWE-1284 | Python-Multipart: Negative Content-Length in parse_form buffers the entire bo… |
| CVE-2023-45795 | 7.8 | 11.4 | Pilz | PMI v8xx | CWE-79 | Pilz: XSS vulnerability in Pilz PASvisu and PMI v8xx |
| CVE-2026-7253 | 6.0 | 11.0 | IBM | Sterling B2B Integrator | CWE-89 | IBM Sterling File Gateway SQL Injection |
| CVE-2026-28381 | 8.1 | 10.8 | Grafana | Snowflake Datasource | CWE-284 | Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT |
| CVE-2026-10530 | 5.3 | 10.7 | Unknown | Pie Register | — | Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predi… |
| CVE-2026-50557 | 5.3 | 10.6 | angular | angular | CWE-79 | Angular: Template and Attribute Namespace Sanitization Bypass (XSS) |
| CVE-2026-54265 | 5.3 | 10.6 | angular | angular | CWE-79 | Angular: Two-Way Property Binding Sanitization Bypass (XSS) |
| CVE-2025-2669 | 6.5 | 9.8 | IBM | Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | CWE-295 | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Wareh… |
| CVE-2026-50168 | 8.8 | 9.4 | angular | angular | CWE-346 | Angular: URL Parser Differential in @angular/platform-server leading to SSRF … |
| CVE-2026-9610 | 5.3 | 8.8 | IBM | Datacap | CWE-425 | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-54282 | 5.3 | 8.6 | Kludex | starlette | CWE-706 | Starlette: Unvalidated request path concatenated into authority poisons reque… |
| CVE-2026-56357 | 6.3 | 8.5 | n8n | n8n | CWE-290 | n8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHu… |
| CVE-2026-41046 | 7.3 | 8.4 | presire | qSnapper | CWE-23 | path traversal via `config` parameter in qSnapper |
| CVE-2026-41479 | 5.4 | 8.1 | authlib | authlib | CWE-601 | Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlle… |
| CVE-2026-54267 | 8.6 | 7.9 | angular | angular | CWE-79 | Angular Client Hydration DOM Clobbering & Response-Cache Poisoning |
| CVE-2024-51454 | 6.1 | 8.0 | IBM | Engineering Workflow Management | CWE-644 | IBM Engineering Lifecycle Management - Engineering Workflow Management is imp… |
| CVE-2026-6645 | 7.3 | 7.7 | PaperCut | Print Deploy | CWE-427 | Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows |
| CVE-2026-54276 | 6.3 | 7.6 | aio-libs | aiohttp | CWE-601 | AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Ch… |
| CVE-2026-54289 | 4.8 | 7.7 | honojs | hono | CWE-348 | Hono: Lambda@Edge adapter keeps only the last value of a repeated request hea… |
| CVE-2026-53537 | 5.3 | 7.5 | Kludex | python-multipart | CWE-20 | Python-Multipart: Content-Disposition parameter smuggling via RFC 2231/5987 e… |
| CVE-2026-53538 | 3.7 | 7.4 | Kludex | python-multipart | CWE-436 | Python-Multipart: Semicolon treated as querystring field separator enables pa… |
| CVE-2026-12602 | 8.8 | 7.2 | Aruba | ArubaSign | CWE-276 | Incorrect permissions in ArubaSign by Aruba |
| CVE-2026-10658 | 7.1 | 7.0 | zephyrproject | zephyr | CWE-787 | Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing … |
| CVE-2026-50555 | 8.6 | 6.5 | angular | angular | CWE-79 | Angular: Improper Neutralization of Input During Web Page Generation ('Cross-… |
| CVE-2026-50169 | 5.7 | 6.2 | angular | angular | CWE-200 | Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities |
| CVE-2026-7859 | 5.3 | 5.9 | Unknown | Motors | CWE-862 | Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-… |
| CVE-2026-44889 | 6.1 | 5.8 | Pylons | webob | CWE-601 | WebOb: Location header normalization during redirect leads to open redirect |
| CVE-2026-50171 | 8.2 | 5.8 | angular | angular | CWE-400 | Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo) |
| CVE-2026-55443 | 5.5 | 5.4 | langchain-ai | langchain | CWE-22 | LangChain: Path traversal and sandbox escape in LangChain file-search middlew… |
| CVE-2026-55599 | 5.8 | 5.2 | phpseclib | phpseclib | CWE-918 | phpseclib: X.509 certificate validation sends attacker-controlled outbound re… |
| CVE-2026-49241 | 8.7 | 5.1 | angular | angular | CWE-79 | Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language S… |
| CVE-2026-50184 | 5.7 | 4.8 | angular | angular | CWE-200 | Angular: Request Credential & Cache Policy Stripping in Angular Service Worker |
| CVE-2026-10645 | 5.5 | 4.8 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted fi… |
| CVE-2026-41047 | 6.9 | 4.7 | presire | qSnapper | CWE-306 | Information leak via “diff” methods in qSnapper |
| CVE-2026-53663 | 3.1 | 4.5 | remix-run | react-router | CWE-352 | React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATC… |
| CVE-2026-54288 | 6.5 | 4.5 | honojs | hono | CWE-345 | Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Co… |
| CVE-2026-8636 | 7.5 | 4.4 | IBM | Datacap | CWE-316 | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-11746 | 9.4 | 4.3 | LY Corporation | Central Dogma | CWE-798 | A vulnerability has been identified in centraldogma-server versions prior to … |
| CVE-2026-12249 | 9.0 | 4.1 | — | adsys | CWE-348 | Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enr… |
| CVE-2026-53655 | 6.9 | 4.0 | isaacs | node-tar | CWE-436 | node-tar applies PAX size override to intermediary GNU long-name/long-link he… |
| CVE-2026-56109 | 7.0 | 3.7 | alsa-project | alsa-lib | CWE-415 | ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c |
| CVE-2026-41049 | 8.4 | 3.6 | presire | qSnapper | CWE-863 | Caching of Authentication allows Authentication Bypass between users in qSnapper |
| CVE-2026-41045 | 7.0 | 3.5 | presire | qSnapper | CWE-367 | Weak polkit authentication check in qSnapper |
| CVE-2026-41048 | 8.4 | 3.3 | presire | qSnapper | CWE-863 | Caching of Authentication allows Authentication Bypass in qSnapper |
| CVE-2026-47242 | 5.8 | 3.2 | ruby | net-imap | CWE-77 | Net::IMAP: Command Injection via ID command argument |
| CVE-2026-44274 | 7.8 | 2.8 | Dell | Wyse Management Suite (WMS) | CWE-59 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Impr… |
| CVE-2026-49356 | 3.6 | 2.7 | babel | babel | CWE-22 | Babel: Arbitrary File Read via sourceMappingURL Comment in @babel/core |
| CVE-2026-49461 | 6.9 | 2.3 | py-pdf | pypdf | CWE-400 | pypdf: Possible large memory usage for form XObjects during text extraction |
| CVE-2026-54530 | 6.9 | 2.3 | py-pdf | pypdf | CWE-835 | pypdf: Possible infinite loop when retrieving fonts for layout-mode text extr… |
| CVE-2026-54531 | 6.9 | 2.3 | py-pdf | pypdf | CWE-835 | pypdf: Possible infinite loop when processing outlines/bookmarks in writer |
| CVE-2026-49460 | 5.1 | 1.9 | py-pdf | pypdf | CWE-407 | pypdf: Inefficient decoding of FlateDecode PNG predictor streams |
| CVE-2026-54099 | 8.8 | 1.5 | Red Hat | Red Hat OpenShift for Windows Containers 10.22 | CWE-269 | Windows-machine-config-operator: windows-machine-config-operator: wicd csr ex… |
| CVE-2026-54651 | 6.9 | 1.5 | py-pdf | pypdf | CWE-835 | pypdf: Possible infinite loop when processing threads/articles in writer |
| CVE-2026-44273 | 4.4 | 1.2 | Dell | Wyse Management Suite (WMS) | CWE-1392 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use o… |
| CVE-2026-54266 | 8.8 | 0.5 | angular | angular | CWE-328 | Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cros… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-22 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.