boxscore/security
Tuesday, June 23, 2026 · all times UTC← 2026-06-22 · archive · 2026-06-24 →

258 CVEs published June 23, 2026: 28 critical, 98 high, 117 medium, 11 low; 4 in KEV; 58 with a public exploit reference; 4 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 233 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published56551002711682563
KEV catalog size1670

466 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux10110678466831212730.37.8.0013-125
google68485883450293297460.78.1.0023+668
microsoft220710554741604378273.87.8.0044+56
red hat91155966737400.06.8.0027+82
apple146101636293711.55.7.0023+1
canonical2161465000.05.5.0010+2
freebsd070520000.07.8.0020-7
suse461410000.08.6.0029+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco9224380961045.56.8.0257+4
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
ubiquiti81174004327.39.9.0083+6
f56943107111.18.9.0221+4
ivanti49230033555.68.8.5187+2
checkpoint3915303111.17.5.0410+3
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache9212418445384010.86.8.0048+83
mozilla495511182601300.07.3.0026+44
gitlab1120041224210.04.8.0024+11
docker470520100.08.2.0016+1
drupal0511305120.05.1.0026-3
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1321364507727532.25.5.0021+131
ibm32811935270700.07.5.0028+32
progress591710900.07.5.0036+1
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp131110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+8
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb660420000.07.2.0018+6
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
mitsubishi electric330300000.08.7.0064+3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+72
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+36
themerex585855300000.08.1.0043+58
edimax556033023100.07.4.00700
dell3149024240212.06.8.0015+19
concrete cms2461111321000.06.2.0015-42
open ises044221210000.07.1.0021-37

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
Most disclosures (vendor)
VendorCVEs
google836
linux515
oracle268
microsoft226
adobe132
red hat123
apache104
ibm81
spring73
openclaw67
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco10
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven43
Packagist22
PyPI10
npm3
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-48595Google0
CVE-2025-67038Lantronix0
CVE-2026-0257Palo Alto Networks0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171679
CVE-2021-27102Accellion2021-11-171679
CVE-2021-27101Accellion2021-11-171679
CVE-2021-27103Accellion2021-11-171679
CVE-2021-21017Adobe2021-11-171679
CVE-2021-28550Adobe2021-11-171679
CVE-2021-42013Apache2021-11-171679
CVE-2021-41773Apache2021-11-171679
CVE-2021-30858Apple2021-11-171679
CVE-2021-30860Apple2021-11-171679

Transactions

EXPLOIT PUBLISHEDCVE-2025-55639. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71337 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-33760 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-34908 (Ubiquiti Inc UniFi OS Server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-34909 (Ubiquiti Inc UniFi OS Server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-34910 (Ubiquiti Inc UniFi OS Server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42867 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44726 (denoland deno). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45135 (caddyserver caddy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45692 (caddyserver caddy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48020 (traefik). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48491 (traefik). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48519 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48520 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49401 (denoland deno). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49402 (denoland deno). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49406 (denoland deno). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49411 (denoland deno). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-4983 (Eclipse Foundation Eclipse Open VSX). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50023 (yt-dlp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50193 (FasterXML jackson-databind). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50221 (OpenStack Swift). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52844 (caddyserver caddy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52845 (caddyserver caddy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52846 (caddyserver caddy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53622 (traefik). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54006 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54007 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54008 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54009 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54010 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54011 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54012 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54013 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54014 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54015 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54016 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54018 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54019 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54022 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54317 (home-assistant core). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54318 (home-assistant core). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54512 (FasterXML jackson-databind). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54761 (traefik). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54762 (traefik). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55249 (rtk-ai rtk). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55423 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55446 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55447 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55450 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55653 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56274 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56275 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56968 (GNU SASL). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57053 (GNU libidn). Public exploit reference added.

DUE DATE PASSEDCVE-2026-42271 (BerriAI LiteLLM). CISA remediation deadline was June 22, 2026; still in catalog.

Yesterday's Results

258 CVEs published. 25 box scores, 233 table rows — nothing truncated.

Ubiquiti UniFi OS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .8696   99.7   YES
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
  UDM              unspecified  —
  UDM-Pro          unspecified  —
  UDM-SE           unspecified  —
  UDM-Pro-Max      unspecified  —
  UDM-Beast        unspecified  —
  EFG              unspecified  —
  UDW              unspecified  —
  UDR              unspecified  —
  UDR7             unspecified  —
  + 21 more
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Added to CISA KEV, due Jun 26
  Jun 23  Published (CNA: hackerone)
CWE-20 · CNA: hackerone · 3 references · NVD status: Analyzed · KEV due June 26, 2026
Ubiquiti UniFi OS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .8519   99.7   YES
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
  UDM              unspecified  —
  UDM-Pro          unspecified  —
  UDM-SE           unspecified  —
  UDM-Pro-Max      unspecified  —
  UDM-Beast        unspecified  —
  EFG              unspecified  —
  UDW              unspecified  —
  UDR              unspecified  —
  UDR7             unspecified  —
  + 21 more
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Added to CISA KEV, due Jun 26
  Jun 23  Published (CNA: hackerone)
CWE-284 · CNA: hackerone · 3 references · NVD status: Analyzed · KEV due June 26, 2026
Ubiquiti UniFi OS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .6390   99.2   YES
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
  Express          unspecified  —
  UDM              unspecified  —
  UDM-Pro          unspecified  —
  UDM-SE           unspecified  —
  UDM-Pro-Max      unspecified  —
  UDM-Beast        unspecified  —
  EFG              unspecified  —
  UDW              unspecified  —
  UDR              unspecified  —
  + 22 more
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Added to CISA KEV, due Jun 26
  Jun 23  Published (CNA: hackerone)
CWE-22 · CNA: hackerone · 3 references · NVD status: Analyzed · KEV due June 26, 2026
CVE-2025-67038AWAITING ENRICHMENT
Lantronix EDS5000
  CVSS   EPSS    %ile   KEV
  —      .1355   96.1   YES
AFFECTED
  Product  Versions     Fixed
  EDS5000  unspecified  —
TIMELINE
  Jun 23  Added to CISA KEV, due Jun 26
  Jun 23  Published
0 references · KEV due June 26, 2026
FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    9.4   .1761   96.9     —
AFFECTED
  Product      Versions   Fixed
  FOSSBilling  < 0.8.0 –  —
TIMELINE
  Feb 27  Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-1336 · CNA: GitHub_M · 3 references · NVD status: Deferred
langflow-ai langflow — Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  N  H    9.3   .1182   95.7     —
AFFECTED
  Product   Versions   Fixed
  langflow  < 1.9.1 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: GitHub_M)
CWE-200, CWE-306, CWE-400 · CNA: GitHub_M · 2 references · NVD status: Analyzed
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0327   87.4     —
AFFECTED
  Product             Versions     Fixed
  Flowise             unspecified  3.1.2
  Flowise Components  unspecified  3.1.2
TIMELINE
  Jun 20  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Analyzed
zohocorp manageengine_adselfservice_plus — Account Takeover via Predictable SSO Ticket Generation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  H    9.0   .0196   78.6     —
AFFECTED
  Product                             Versions     Fixed
  manageengine_adselfservice_plus     unspecified  —
  manageengine_recovery_manager_plus  unspecified  —
  manageengine_m365_manager_plus      unspecified  —
  manageengine_adaudit_plus           unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 23  Published (CNA: Zohocorp)
CWE-287, CWE-330, CWE-340 · CNA: Zohocorp · 1 reference · NVD status: Awaiting Analysis
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  L  H    9.0   .0178   76.4     —
AFFECTED
  Product  Versions    Fixed
  lobehub  < 2.1.57 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · 1 reference · NVD status: Deferred
unclecode crawl4ai — Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0100   59.8     —
AFFECTED
  Product   Versions   Fixed
  crawl4ai  < 0.8.9 –  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
ImageMagick - Command Injection via SVG Decoder
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0088   56.2     —
AFFECTED
  Product      Versions     Fixed
  ImageMagick  unspecified  7.1.2-15
  ImageMagick  unspecified  6.9.13-40
TIMELINE
  Jun 21  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-116, CWE-78 · CNA: VulnCheck · 6 references · NVD status: Modified
n8n-io n8n — n8n: HTTP Request Node Pagination Prototype Pollution to RCE
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0088   56.0     —
AFFECTED
  Product  Versions      Fixed
  n8n      < 1.123.43 –  —
TIMELINE
  May 7   Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-1321 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
Traefik StripPrefix Route-Level Auth Bypass via Path Normalization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   N    7.8   .0087   55.7     —
AFFECTED
  Product  Versions                  Fixed
  traefik  >= 3.7.0-ea.1, < 3.7.3 –  —
TIMELINE
  May 20  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: GitHub_M)
CWE-288, CWE-22 · CNA: GitHub_M · 7 references · NVD status: Modified
langflow-ai langflow — Langflow: Unauthenticated RCE in Shareable Playgrounds
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0082   54.3     —
AFFECTED
  Product   Versions   Fixed
  langflow  < 1.9.2 –  —
TIMELINE
  May 21  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
n/a n/a — An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0080   53.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 23  Published (CNA: mitre)
CWE-502 · CNA: mitre · 2 references · NVD status: Deferred
FasterXML jackson-databind — jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0078   52.9     —
AFFECTED
  Product           Versions               Fixed
  jackson-databind  >= 2.10.0, < 2.18.8 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: GitHub_M)
CWE-184, CWE-502 · CNA: GitHub_M · 3 references · NVD status: Analyzed
picklescan - Remote Code Execution via Unblocked Standard Library Modules
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0076   52.2     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  1.0.4
TIMELINE
  Jun 20  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-184 · CNA: VulnCheck · 2 references · NVD status: Deferred
Revive Adserver Revive Adserver — A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier co…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0075   52.1     —
AFFECTED
  Product          Versions     Fixed
  Revive Adserver  unspecified  —
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Published (CNA: hackerone)
CWE-94 · CNA: hackerone · 1 reference · NVD status: Deferred
Python Software Foundation CPython — tarfile extraction filter bypass allows escaping the destination directory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   N    7.8   .0075   52.0     —
AFFECTED
  Product  Versions     Fixed
  CPython  unspecified  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 23  Published (CNA: PSF)
CWE-22, CWE-59 · CNA: PSF · 10 references · NVD status: Awaiting Analysis
FasterXML jackson-databind — jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0071   50.6     —
AFFECTED
  Product           Versions               Fixed
  jackson-databind  >= 2.10.0, < 2.18.8 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-184 · CNA: GitHub_M · 29 references · NVD status: Modified
elixir-plug plug — Plug: quadratic-time decoding of nested query/body parameters enables denial of service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0071   50.4     —
AFFECTED
  Product  Versions                                    Fixed
  plug     1.15.0 –                                    —
  plug     712b875d3442c765d8d37e546ffd5ad9f8afcc55 –  c317d08fdcf96e17931f7419275b2b8c4bf3e951
TIMELINE
  Jun 16  Reserved by CNA
  Jun 23  Published (CNA: EEF)
CWE-407 · CNA: EEF · 8 references · NVD status: Deferred
Crawl4AI - Arbitrary File Write via output_path Symlink and TOCTOU
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0067   49.0     —
AFFECTED
  Product   Versions     Fixed
  Crawl4AI  unspecified  0.8.8
TIMELINE
  Jun 19  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 2 references · NVD status: Analyzed
NetComm NF20MESH < R6B032 Authenticated RCE via OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0066   48.8     —
AFFECTED
  Product   Versions     Fixed
  NF20MESH  unspecified  —
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 4 references · NVD status: Deferred
n8n-io n8n — n8n: Arbitrary File Read via Git Node
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0065   48.0     —
AFFECTED
  Product  Versions      Fixed
  n8n      < 1.123.43 –  —
TIMELINE
  May 7   Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-88 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
n8n-io n8n — n8n: XML Node Prototype Pollution Patch Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0063   47.5     —
AFFECTED
  Product  Versions      Fixed
  n8n      < 1.123.43 –  —
TIMELINE
  May 7   Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-1321 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-500239.646.8yt-dlpyt-dlpCWE-641yt-dlp: Dangerous file type creation via insufficient filename sanitization (…
CVE-2026-5375310.046.3unclecodecrawl4aiCWE-94Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Dock…
CVE-2023-543658.744.3TraefikTraefikCWE-400Traefik - Denial of Service via HTTP/2 Request Handling
CVE-2026-451358.140.6caddyservercaddyCWE-20Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PH…
CVE-2026-128669.240.3n/aexpr-evalCWE-94All versions of the package expr-eval are vulnerable to Code Execution via th…
CVE-2026-494656.040.3n8n-ion8nCWE-22n8n: Git Node Clone and Push Operations Bypass File Sandbox
CVE-2026-528447.539.2caddyservercaddyCWE-22Caddy: Windows `file_server` path authorization bypass via encoded backslash
CVE-2025-610187.539.1n/an/aCWE-89An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v…
CVE-2025-610207.539.1n/an/aCWE-89An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource …
CVE-2025-610237.539.1n/an/aCWE-89An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 …
CVE-2025-610287.539.1n/an/aCWE-89An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.1…
CVE-2026-350199.238.9NetComm Wireless Pty LtdNF20MESHCWE-321NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass
CVE-2026-554479.638.6langflow-ailangflowCWE-61Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-449598.838.4ReviveAdserverCWE-94A missing validation of user input exists when saving delivery limitations in…
CVE-2025-713417.638.4picklescanpicklescanCWE-502picklescan - Remote Code Execution via Undetected profile.Profile.runctx
CVE-2026-501936.338.0FasterXMLjackson-databindCWE-400jackson-databind: Deeply nested JsonNode throws StackOverflowError for toStri…
CVE-2026-119728.237.0Python Software FoundationCPythonCWE-252tarfile opened in streaming mode mishandles EOF
CVE-2026-526736.536.4n/an/aCWE-89SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote atta…
CVE-2026-130078.736.0tenableTenable Identity ExposureCWE-306Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure
CVE-2026-543058.935.9n8n-ion8nCWE-200n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-556543.735.9Red HatRed Hat Enterprise Linux 10CWE-125Openssh: heap out-of-bounds read in red hat enterprise linux versions of open…
CVE-2026-543146.335.6n8n-ion8nCWE-409n8n: Denial of Service via ZIP decompression in webhook workflow
CVE-2026-418628.835.3SpringSpring StatemachineCWE-502Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis an…
CVE-2026-118079.634.7Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-862Eda-server: websocket missing authorization allows credential theft via activ…
CVE-2026-485206.134.1langflow-ailangflowCWE-73Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-2760410.034.0FOSSBillingFOSSBillingCWE-200FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Ac…
CVE-2026-547625.933.9traefiktraefikCWE-636Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolut…
CVE-2026-505749.633.8yt-dlpyt-dlpCWE-74yt-dlp: Arbitrary code execution via manifest downloads with aria2c
CVE-2026-543098.833.6n8n-ion8nCWE-306n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control S…
CVE-2026-543166.033.6anthropicsclaude-codeCWE-183Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domai…
CVE-2026-543106.532.6n8n-ion8nCWE-89n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
CVE-2025-556396.531.4n/an/aCWE-476GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the …
CVE-2025-713707.631.1picklescanpicklescanCWE-502picklescan - Remote Code Execution via torch.jit.unsupported_tensor_ops.execW…
CVE-2026-117725.130.9DRIMODRIMO CMSCWE-79Reflected XSS in DRIMO CMS
CVE-2026-562488.729.0Cap-gocapgoCWE-400Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy
CVE-2026-337608.828.8langflow-ailangflowCWE-639Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpo…
CVE-2026-562228.628.7CapgoCapgoCWE-639Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /…
CVE-2026-494447.128.7n8n-ion8nCWE-20n8n: Python sandbox escape
CVE-2026-543047.128.5n8n-ion8nCWE-200n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
CVE-2025-713378.728.2FlowiseFlowiseCWE-620Flowise - Unverified Email Change via Account Profile Endpoint
CVE-2025-610197.528.1n/an/aCWE-89An issue in the sqlo_key_part_best component of openlink virtuoso-opensource …
CVE-2025-610217.528.1n/an/aCWE-89An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensou…
CVE-2025-610227.528.1n/an/aCWE-89An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v…
CVE-2025-610247.528.1n/an/aCWE-89An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7…
CVE-2025-610257.528.1n/an/aCWE-89An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.1…
CVE-2025-610277.528.1n/an/aCWE-89An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 …
CVE-2025-610297.528.1n/an/aCWE-89An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 …
CVE-2026-428676.527.9langflow-ailangflowCWE-22Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2026-543078.527.8n8n-ion8nCWE-863n8n: Credential Exfiltration via Permission Bypass
CVE-2026-554467.527.8langflow-ailangflowCWE-400Langflow: Unauthenticated DoS through multipart form boundary file upload
CVE-2026-545155.327.6FasterXMLjackson-databindCWE-915jackson-databind: Case-insensitive deserialization bypasses per-property @Jso…
CVE-2026-561158.727.4garybowersbootimusCWE-862Bootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass
CVE-2026-97339.126.8HAYAJOMojolicious::Plugin::Web::Auth::OAuth2CWE-338Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an…
CVE-2026-449560.026.9ReviveAdserverCWE-79Low‑privileged users could use their Full Name as a vector for a stored XSS a…
CVE-2026-449600.026.9ReviveAdserverCWE-79A stored XSS can be exploited by leveraging the usernames as an attack vector…
CVE-2026-449610.026.7ReviveAdserverCWE-287The XML‑RPC API addUser method has a validation bypass introduced in the fix …
CVE-2026-494028.126.4denolanddenoCWE-78Deno: Command Injection via spawnSync & spawn on Windows
CVE-2026-540187.726.4open-webuiopen-webuiCWE-918Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
CVE-2026-540196.526.4open-webuiopen-webuiCWE-862Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
CVE-2026-563228.726.3CapgoCapgoCWE-200Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Pa…
CVE-2026-447928.926.0n8n-ion8nCWE-89n8n: Source Control Pull SQL Injection
CVE-2026-552498.826.0rtk-airtkCWE-78@rtk-ai/rtk-rewrite: OpenClaw Rewrite Plugin Command Injection via execSync T…
CVE-2026-473855.325.2nocodbnocodbCWE-22NocoDB: Path Traversal via SQLite Source Filename
CVE-2025-713827.125.0ArtifexSoftwaremupdfCWE-674MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering
CVE-2026-457328.324.9n8n-ion8nCWE-639n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
CVE-2026-349174.324.9ReviveAdserverCWE-287Low‑privileged session IDs generated for the web admin console could be reuse…
CVE-2026-540225.324.8open-webuiopen-webuiCWE-706Open WebUI: Any authenticated user can read other users' private notes via So…
CVE-2026-547616.024.6traefiktraefikCWE-284Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute o…
CVE-2026-543116.024.3n8n-ion8nCWE-488n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-105218.624.0MB connect linembCONNECT24CWE-425Authenticated unintended access to critical program parameters
CVE-2026-473816.924.1nocodbnocodbCWE-290NocoDB: Cross-Workspace Integration Use in Connection Test
CVE-2026-545889.624.0poweradminpoweradminCWE-20Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, …
CVE-2026-349148.323.5ReviveAdserverCWE-89A missing sanitisation of user input in the zone-include.php script of Revive…
CVE-2026-465525.823.3nocodbnocodbCWE-285NocoDB: Shared-base link access can invite arbitrary users as persistent base…
CVE-2026-473845.323.2nocodbnocodbCWE-89NocoDB: SQL Injection via Column Title in Bulk GroupBy
CVE-2025-713657.622.6picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.myeval Dete…
CVE-2025-713767.622.6picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected idlelib.autocomplete.Aut…
CVE-2026-545175.322.2FasterXMLjackson-databindCWE-863jackson-databind: @JsonView bypass for setterless creator properties
CVE-2026-539316.922.1nocodbnocodbCWE-441NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
CVE-2026-539266.322.1nocodbnocodbCWE-613NocoDB: OAuth Tokens Persist Through Security Events
CVE-2026-543127.221.9n8n-ion8nCWE-1321n8n: Microsoft SQL Node Prototype Pollution
CVE-2026-562258.721.7CapgoCapgoCWE-269Capgo - Authorization Bypass in API Key Management via App-Limited Keys
CVE-2026-540108.321.7open-webuiopen-webuiCWE-284Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVE-2026-543177.621.7home-assistantcoreCWE-200Home Assistant: Konnected alarm-panel switch state and zone topology disclose…
CVE-2026-528458.121.6caddyservercaddyCWE-287Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
CVE-2026-556536.521.5Red HatRed Hat Enterprise Linux 10CWE-415Openssh: double free in red hat enterprise linux versions of openssh dh-gex c…
CVE-2026-536227.821.4traefiktraefikCWE-288Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and …
CVE-2026-473837.421.4nocodbnocodbCWE-79NocoDB: Stored Cross-Site Scripting via Row Comments
CVE-2026-539295.121.4nocodbnocodbCWE-79NocoDB: Stored Cross-Site Scripting via Secure Attachment
CVE-2026-539305.121.3nocodbnocodbCWE-918NocoDB: Server-Side Request Forgery via Base Migration URL
CVE-2026-118206.521.2Red HatRed Hat Enterprise Linux 10CWE-532Community.general: community.general nexmo — api credentials exposed in get u…
CVE-2026-540144.321.1open-webuiopen-webuiCWE-22Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/ope…
CVE-2026-569685.321.1GNUGNU SASLCWE-908GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_…
CVE-2026-545165.320.8FasterXMLjackson-databindCWE-915jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private f…
CVE-2026-235137.120.6FOSSBillingFOSSBillingCWE-863FOSSBilling: Broken Authorization in Client Transaction and Order Listings
CVE-2026-539275.120.7nocodbnocodbCWE-918NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
CVE-2026-484917.820.4traefiktraefikCWE-288Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-front…
CVE-2026-543086.320.1n8n-ion8nCWE-290n8n: Missing Token Validation on Microsoft Agent 365 Trigger Node
CVE-2026-543246.519.8daytonaiodaytonaCWE-639Daytona: Cross-tenant data leak in notification WebSocket gateway via unverif…
CVE-2026-449585.419.8ReviveAdserverCWE-284An access control bypass allows an advertiser‑level user to activate or deact…
CVE-2026-562438.619.7CapgoCapgoCWE-288Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane
CVE-2026-128914.319.6Red HatRed Hat Enterprise Linux 10CWE-125Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob r…
CVE-2026-500197.419.0yt-dlpyt-dlpCWE-200yt-dlp: File Downloader cookie leak with curl
CVE-2026-537547.518.9unclecodecrawl4aiCWE-918Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT6…
CVE-2026-540096.518.9open-webuiopen-webuiCWE-639Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
CVE-2025-641055.118.5FOSSBillingFOSSBillingCWE-639FOSSBilling: IDOR Vulnerability in Support Ticket Creation
CVE-2026-545186.518.4FasterXMLjackson-databindCWE-863jackson-databind: @JsonView bypass for unwrapped creator parameters in jackso…
CVE-2026-473765.118.1nocodbnocodbCWE-79NocoDB: Reflected Cross-Site Scripting via Password Reset Token
CVE-2026-543136.517.9n8n-ion8nCWE-89n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
CVE-2026-543066.317.7n8n-ion8nCWE-1321n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-540164.317.8open-webuiopen-webuiCWE-639Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Kno…
CVE-2026-567848.617.6openremoteopenremoteCWE-639OpenRemote < 1.25.0 IDOR via Bulk Alarm Deletion Endpoint
CVE-2026-563716.917.5ImageMagickImageMagickCWE-401ImageMagick - Memory Leak in TXT File Processing via Texture Attribute
CVE-2026-129588.517.3Amazon Web ServicesLanguage Servers for AWSCWE-61Arbitrary file write in Language Servers for AWS
CVE-2026-542579.316.9electronelectronCWE-120Electron: Buffer performs incorrect byte length calculations resulting in hea…
CVE-2026-473796.916.9nocodbnocodbCWE-200NocoDB: Plaintext Password Comparison in Shared Views
CVE-2026-543217.016.4daytonaiodaytonaCWE-613Daytona: Public sandbox previews remain accessible for up to one hour after b…
CVE-2026-562346.916.2CapgoCapgoCWE-307Capgo - Password Spraying via Public-Key Accessible Credential Validation End…
CVE-2026-567626.916.2HonoHonoCWE-20Hono - Missing Cookie Name Validation in setCookie()
CVE-2026-83797.515.9UnknownFrontend File Manager PluginFrontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download
CVE-2026-349134.315.8ReviveAdserverCWE-284A missing access control check when linking trackers to campaigns through the…
CVE-2026-449574.315.8ReviveAdserverCWE-284A missing access control check when invoking various modify methods in the XM…
CVE-2026-567858.415.7FlatPressFlatPressCWE-79FlatPress - Stored Cross-Site Scripting via Unescaped Comment and Contact For…
CVE-2026-539286.315.6nocodbnocodbCWE-613NocoDB: Refresh Tokens Persist Through Password Recovery
CVE-2026-465532.115.3nocodbnocodbCWE-770NocoDB: Attachment Size Limit Bypass via Upload-by-URL
CVE-2026-540127.115.2open-webuiopen-webuiCWE-284Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVE-2026-472796.915.3nocodbnocodbCWE-284NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints
CVE-2026-473786.915.3nocodbnocodbCWE-639NocoDB: Hidden Column Exposure in Public Shared View Endpoints
CVE-2026-129695.315.2Red HatRed Hat Enterprise Linux 10CWE-125Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes …
CVE-2026-473775.115.3nocodbnocodbCWE-601NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin
CVE-2026-81638.814.9UnknownInfility GlobalInfility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter
CVE-2026-536629.614.7immich-appimmichCWE-79immich: One-click account takeover via XSS in login page continue redirect
CVE-2026-465516.514.6nocodbnocodbCWE-770NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Servi…
CVE-2026-349124.314.7ReviveAdserverCWE-284A missing access control check when linking banners or campaigns to a zone th…
CVE-2026-107118.814.5AKIN Software Computer Import Export Industry and Trade Ltd.CafePlusCWE-306RCE in Akınsoft's CafePlus
CVE-2026-473878.414.5nocodbnocodbCWE-79NocoDB: Stored Cross-Site Scripting via Form View Redirect URL
CVE-2026-567017.114.4GravGravCWE-611Grav - XML External Entity Injection via SVG Upload
CVE-2026-540088.514.2open-webuiopen-webuiCWE-918Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url`
CVE-2026-566957.114.1HKUDSOpenHarnessCWE-862OpenHarness - Cross-Session Disclosure via /resume and /summary Commands
CVE-2026-540115.414.2open-webuiopen-webuiCWE-79Open WebUI: Stored XSS in Mermaid Markdown Preview
CVE-2026-440899.414.0TotolinkEX1200LCWE-121Buffer Overflow in Totolink EX1200L router
CVE-2026-476936.913.9poweradminpoweradminCWE-1236Poweradmin: CSV Injection in log export endpoints allows formula execution in…
CVE-2026-106096.813.5Red HatLogging Subsystem for Red Hat OpenShiftCWE-862Openshift/cluster-logging-operator: cluster logging operator creates and forw…
CVE-2026-349156.113.3ReviveAdserverCWE-79A missing sanitisation of user input in the zone-include.php script of Revive…
CVE-2026-129578.513.2Amazon Web ServicesLanguage Servers for AWSCWE-732Arbitrary Code Execution in Language Servers for AWS
CVE-2026-78426.813.3UnknownInfility GlobalInfility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter
CVE-2026-49835.413.2Eclipse FoundationEclipse Open VSXCWE-79Open VSX Registry does not sanitize SVG files uploaded as extension icons pri…
CVE-2026-545145.312.6FasterXMLjackson-databindCWE-918jackson-databind: InetSocketAddress deserialization triggers eager DNS resolu…
CVE-2026-118338.212.4Yokogawa Electric CorporationFAST/TOOLSCWE-319Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web…
CVE-2026-543017.012.3n8n-ion8nCWE-79n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-566965.312.3HKUDSOpenHarnessCWE-862OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands
CVE-2026-543208.412.1daytonaiodaytonaCWE-287Daytona: Cross-tenant organization takeover via invitation acceptance with an…
CVE-2025-621807.112.2PegasystemsPega InfinityCWE-639Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an autho…
CVE-2026-473756.012.1nocodbnocodbCWE-89NocoDB: Postgres SQL Injection in Formula `ARRAYSORT`
CVE-2026-562756.012.1FlowiseFlowiseCWE-918Flowise - Server-Side Request Forgery via Execute Flow Base URL
CVE-2026-564027.111.9nanocoainanoclawCWE-862NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Han…
CVE-2026-543027.011.4n8n-ion8nCWE-79n8n: Stored XSS in Chat Trigger Node
CVE-2026-540216.311.5open-webuiopen-webuiCWE-863Open WebUI: Authenticated users can target arbitrary configured Ollama backen…
CVE-2026-473882.311.4nocodbnocodbCWE-639NocoDB: Missing Ownership Check in MCP Attachment Read
CVE-2026-473825.311.1nocodbnocodbCWE-918NocoDB: Server-Side Request Forgery via Database Connection Host
CVE-2026-540064.311.0open-webuiopen-webuiCWE-639Open WebUI: Calendar event re-parenting allows writing events into another us…
CVE-2026-540137.610.4open-webuiopen-webuiCWE-79Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open W…
CVE-2026-540156.49.9open-webuiopen-webuiCWE-284Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read …
CVE-2026-473806.39.7nocodbnocodbCWE-208NocoDB: User Enumeration via Sign-In Timing
CVE-2026-473866.39.9nocodbnocodbCWE-362NocoDB: OAuth Authorization Code Race Condition
CVE-2026-465542.39.7nocodbnocodbCWE-613NocoDB: Stale Auth Cache After API Token Deletion
CVE-2026-46106.49.6metagaussProfileGrid – User Profiles, Groups and CommunitiesCWE-79ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Script…
CVE-2026-562635.39.5Crawl4AICrawl4AICWE-79Crawl4AI - Stored Cross-Site Scripting in Monitor Dashboard
CVE-2026-554236.18.8langflow-ailangflowCWE-613Langflow: Logout button does not clear session
CVE-2026-528464.28.8caddyservercaddyCWE-116Caddy: stripHTML template function bypass
CVE-2026-561167.18.7NetworkConfigurationdhcpcdCWE-401dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling
CVE-2026-494018.48.6denolanddenoCWE-41Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
CVE-2026-543227.78.4daytonaiodaytonaCWE-639Daytona: Cross-org IDOR in organization role update/delete — any org owner ca…
CVE-2020-97115.58.4AdobeAcrobat ReaderCWE-125Acrobat Reader | Out-of-bounds Read (CWE-125)
CVE-2020-97135.58.4AdobeAcrobat ReaderCWE-125Acrobat Reader | Out-of-bounds Read (CWE-125)
CVE-2026-563766.38.3ImageMagickImageMagickCWE-416ImageMagick - Heap Use-After-Free in Meta Coder
CVE-2026-555174.38.2denolanddenoCWE-248Deno: Denial of service via non-ASCII bytes in WebSocket response headers
CVE-2026-484935.58.1grokabilitysnipe-itCWE-863Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assi…
CVE-2020-96957.88.0AdobeAcrobat ReaderCWE-787Acrobat Reader | Out-of-bounds Write (CWE-787)
CVE-2026-543036.87.5n8n-ion8nCWE-79n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhoo…
CVE-2026-465484.37.4nocodbnocodbCWE-918NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discor…
CVE-2026-540077.17.2open-webuiopen-webuiCWE-346Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
CVE-2026-561136.07.3NetworkConfigurationdhcpcdCWE-416dhcpcd Heap Use-After-Free in dhcp6_deprecateaddrs via DHCPv6 RENEW
CVE-2026-561146.07.3NetworkConfigurationdhcpcdCWE-787dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()
CVE-2026-543194.26.9daytonaiodaytonaCWE-22Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into…
CVE-2026-494065.56.8denolanddenoCWE-22Deno: BYONM module resolution allows `package.json` main path traversal to by…
CVE-2026-566945.36.9nanocoainanoclawCWE-863NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback
CVE-2026-447269.16.6denolanddenoCWE-319Deno: TLS retry copies stale upgrade hook, risking plaintext traffic
CVE-2026-456923.86.4caddyservercaddyCWE-187Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Nor…
CVE-2026-81727.15.6UnknownSimple Basic Contact FormSimple Basic Contact Form <= 20250114 - Reflected XSS
CVE-2026-557664.85.4guzzlepsr7CWE-93guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
CVE-2026-465476.15.2nocodbnocodbCWE-79NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
CVE-2026-568157.45.2rasta-mousepwnliftCWE-61pwnlift before d7a9544, in a privileged deployment, contains a symlink follow…
CVE-2026-58187.25.2CaliptraCore Runtime FirmwareCWE-253MCU Firmware Update Authentication Bypass on Caliptra Core
CVE-2026-121127.85.0Red HatRed Hat Satellite 6.18CWE-287Foreman-mcp-server: mcp server: active session hijacking via insecure session…
CVE-2026-90736.25.0Red HatRed Hat Satellite 6.18CWE-532Foreman-mcp-server: mcp server: insecure sensitive http header sanitization
CVE-2026-557365.94.9ash-projectashCWE-915Private action arguments can be set by user input in Ash
CVE-2026-465492.04.8nocodbnocodbCWE-863NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVE-2026-494407.44.6denolanddenoCWE-325Deno: Miller-Rabin Primality Test Allows Zero Rounds
CVE-2026-108576.14.6AKIN Software Computer Import Export Industry and Trade Ltd.e-CommerceCWE-79Reflected XSS in Akinsoft's e-Commerce
CVE-2026-570532.54.6GNUlibidnCWE-1284GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memor…
CVE-2026-121634.84.3FortraFile Integrity Monitoring (FIM)CWE-79Stored XSS in Fortra File Integrity Monitoring (FIM)
CVE-2026-494116.54.2denolanddenoCWE-284Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny…
CVE-2026-502215.34.2OpenStackSwiftCWE-918In OpenStack Swift before 2.37.2, proxy-server does not strip internal update…
CVE-2026-557675.84.1guzzleguzzleCWE-346Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
CVE-2026-570622.94.0GnuPGGnuPGCWE-1284CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 m…
CVE-2026-75748.73.7AnthropicClaude Desktop CoworkCWE-353Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use
CVE-2026-08644.13.8Python Software FoundationCPythonCWE-74Configuration Injection via Carriage Return (\r) in write() method
CVE-2026-543187.13.7home-assistantcoreCWE-926Home Assistant: Exported BroadcastReceiver allows local apps to spoof device …
CVE-2026-83785.43.2UnknownFrontend File Manager PluginFrontend File Manager Plugin <= 23.6 - Subscriber+ Stored Cross-Site Scriptin…
CVE-2026-543262.53.2earendil-workspiCWE-79Pi: Potential XSS in HTML session exports via Markdown URL sanitization bypass
CVE-2026-566926.83.1nanocoainanoclawCWE-59NanoClaw < 2.1.17 - Arbitrary File Read via Symlink Following in forwardAttac…
CVE-2026-545557.82.9rtk-airtkCWE-863rtk: Permission-gate bypass in rtk rewrite auto-allow via unsplit shell separ…
CVE-2026-64585.12.9CaliptraCore Runtime FirmwareCWE-325AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AA…
CVE-2026-118195.52.3Red HatRed Hat Enterprise Linux 10CWE-532Community.general: community.general keyring_info — os keyring passphrase ret…
CVE-2026-543254.42.0earendil-workspiCWE-829Pi loads project-local extensions without approval
CVE-2026-543235.92.0daytonaiodaytonaCWE-295Daytona: Git credential leak via git clone with TLS verification disabled
CVE-2026-128924.42.0Red HatRed Hat Enterprise Linux 10CWE-125Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds rea…
CVE-2026-543287.31.8earendil-workspiCWE-379Pi: Predictable temporary extension install paths allow local privilege escal…
CVE-2026-566936.81.7nanocoainanoclawCWE-602NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System…
CVE-2026-555685.91.3guzzleguzzleCWE-311Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVE-2026-563016.81.1NuxtNuxtCWE-276Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux
CVE-2026-498595.21.0denolanddenoCWE-693Deno: `fetch()` API sandbox bypass via missing DNS resolution check
CVE-2026-498605.21.0denolanddenoCWE-918Deno: WebSocket API sandbox bypass via missing post-DNS check
CVE-2026-121644.41.0FortraFile Integrity Monitoring (FIM)CWE-266Privilege Escalation in Fortra File Integrity Monitoring (FIM)
CVE-2026-465505.40.9nocodbnocodbCWE-614NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags
CVE-2026-499835.20.9denolanddenoCWE-863Deno: process.loadEnvFile() bypasses env permission checks and mutates proces…
CVE-2025-156193.50.9HCLSoftwareConnectionsCWE-284HCL Connections is vulnerable to broken access control
CVE-2026-561175.70.7NetworkConfigurationdhcpcdCWE-416dhcpcd Heap Use-After-Free via Control Socket Handling
CVE-2026-556556.10.5Red HatRed Hat Enterprise Linux 10CWE-923Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in…
CVE-2025-131624.10.3ABBControl Builder ACWE-427Advant Master Online Builder DLL vulnerability
CVE-2026-457926.90.2rtk-airtkCWE-345RTK improperly trusts project-local filter configuration, allowing silent tam…
CVE-2026-543272.20.1earendil-workspiCWE-367Pi: Race condition in auth.json writes could expose stored credentials

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-23 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.