boxscore/security
Wednesday, June 24, 2026 · all times UTC← 2026-06-23 · archive · 2026-06-25 →

520 CVEs published June 24, 2026: 56 critical, 226 high, 227 medium, 10 low; 0 in KEV; 16 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 495 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published61751054711702563
KEV catalog size1670

479 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux320128610476741212730.27.8.0013+94
google70487885462299297460.78.1.0023+688
microsoft220710554741604378273.87.8.0044+56
red hat93157967747400.06.8.0027+84
apple146101636293711.55.7.0023+1
canonical2161465000.05.5.0010+2
freebsd070520000.07.8.0020-7
suse461410000.08.6.0029+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco9224380961045.56.8.0257+4
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
ubiquiti81174004327.39.9.0083+6
f56943107111.18.9.0221+4
ivanti49230033555.68.8.5187+2
checkpoint3915303111.17.5.0410+3
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache9212418445384010.86.8.0048+83
mozilla495511182601300.07.3.0026+44
gitlab1120041224210.04.8.0024+11
docker470520100.08.2.0016+1
drupal0511305120.05.1.0026-3
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1321364507727532.25.5.0021+131
ibm32811935270700.07.5.0028+32
progress591710900.07.5.0036+1
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp131110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+8
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb660420000.07.2.0018+6
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
mitsubishi electric330300000.08.7.0064+3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+72
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+33
themerex585855300000.08.1.0043+58
edimax556033023100.07.4.0070-20
jenkins project364909391000.04.8.0021+36
dell3149024240212.06.8.0015+19
capgo4646222211000.07.0.0034+46

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
Most disclosures (vendor)
VendorCVEs
google856
linux734
oracle268
microsoft226
adobe132
red hat125
apache95
ibm81
spring72
openclaw67
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco10
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven37
Packagist22
PyPI10
npm3
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-48595Google0
CVE-2025-67038Lantronix0
CVE-2026-0257Palo Alto Networks0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171680
CVE-2021-27102Accellion2021-11-171680
CVE-2021-27101Accellion2021-11-171680
CVE-2021-27103Accellion2021-11-171680
CVE-2021-21017Adobe2021-11-171680
CVE-2021-28550Adobe2021-11-171680
CVE-2021-42013Apache2021-11-171680
CVE-2021-41773Apache2021-11-171680
CVE-2021-30858Apple2021-11-171680
CVE-2021-30860Apple2021-11-171680

Transactions

EXPLOIT PUBLISHEDCVE-2025-60466. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-60467. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-60468. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-60471. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-60473. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-60474. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71332 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10642 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11998 (Google AngularJS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49979 (appsmithorg appsmith). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50189 (appsmithorg appsmith). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53765 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53766 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54297 (lostisland faraday). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54904 (ruby-concurrency concurrent-ruby). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55454 (appsmithorg appsmith). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56270 (Flowise). Public exploit reference added.

DUE DATE PASSEDCVE-2026-11645 (Google Chrome). CISA remediation deadline was June 23, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-20245 (Cisco Catalyst SD-WAN Controller). CISA remediation deadline was June 23, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-7473 (Arista Networks EOS). CISA remediation deadline was June 23, 2026; still in catalog.

Yesterday's Results

520 CVEs published. 25 box scores and 375 table rows below; the remaining 120 continue on page 2 — every CVE is listed, nothing truncated.

ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  H  H    6.5   .0325   87.3     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Analyzed
siyuan-note siyuan — SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0189   77.8     —
AFFECTED
  Product  Versions   Fixed
  siyuan   < 3.7.0 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-22, CWE-23, CWE-1188 · CNA: GitHub_M · 1 reference · NVD status: Deferred
GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0180   76.6     —
AFFECTED
  Product        Versions  Fixed
  GV-I/O Box 4E  V2.09 –   V2.12
TIMELINE
  Jun 17  Reserved by CNA
  Jun 24  Published (CNA: GV)
CWE-78 · CNA: GV · 2 references · NVD status: Deferred
GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0180   76.6     —
AFFECTED
  Product        Versions  Fixed
  GV-I/O Box 4E  V2.09 –   V2.12
TIMELINE
  Jun 22  Reserved by CNA
  Jun 24  Published (CNA: GV)
CWE-78 · CNA: GV · 2 references · NVD status: Deferred
GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0176   76.1     —
AFFECTED
  Product        Versions  Fixed
  GV-I/O Box 4E  V2.09 –   V2.12
TIMELINE
  Jun 22  Reserved by CNA
  Jun 24  Published (CNA: GV)
CWE-78 · CNA: GV · 2 references · NVD status: Deferred
GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0176   76.1     —
AFFECTED
  Product        Versions  Fixed
  GV-I/O Box 4E  V2.09 –   V2.12
TIMELINE
  Jun 22  Reserved by CNA
  Jun 24  Published (CNA: GV)
CWE-78 · CNA: GV · 2 references · NVD status: Deferred
ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0158   73.4     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Analyzed
ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0148   71.7     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Analyzed
ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0148   71.7     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Analyzed
Gogs: RCE via git rebase --exec argument injection in pull request merge
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0146   71.4     —
AFFECTED
  Product  Versions    Fixed
  gogs     < 0.14.3 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-77 · CNA: GitHub_M · 4 references · NVD status: Deferred
Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0140   70.3     —
AFFECTED
  Product          Versions     Fixed
  NetVault Backup  14.0.0.19 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-78 · CNA: zdi · 2 references · NVD status: Analyzed
Cacti: Unauthenticated RCE on Graph Image
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0131   68.1     —
AFFECTED
  Product  Versions    Fixed
  cacti    < 1.2.31 –  —
TIMELINE
  Apr 7   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-22, CWE-78 · CNA: GitHub_M · 2 references · NVD status: Analyzed
motioneye-project motioneye — motionEye: World-Readable Configuration File Exposes Admin Password Hash
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  N  N    5.5   .0120   65.5     —
AFFECTED
  Product    Versions    Fixed
  motioneye  < 0.44.0 –  —
TIMELINE
  Mar 11  Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-200, CWE-522, CWE-732 · CNA: GitHub_M · 2 references · NVD status: Deferred
ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  H  H    6.5   .0120   65.4     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Analyzed
feast-dev feast — Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0114   64.0     —
AFFECTED
  Product  Versions     Fixed
  feast    unspecified  —
TIMELINE
  Jun 18  Reserved by CNA
  Jun 24  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 7 references · NVD status: Deferred
Cacti: Command Injection via escape_command() no-op in RRDtool execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0114   63.9     —
AFFECTED
  Product  Versions    Fixed
  cacti    < 1.2.31 –  —
TIMELINE
  Apr 9   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-78, CWE-88 · CNA: GitHub_M · 2 references · NVD status: Analyzed
Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0113   63.6     —
AFFECTED
  Product  Versions     Fixed
  Unraid   1161ec120 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-78 · CNA: zdi · 1 reference · NVD status: Analyzed
Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0112   63.3     —
AFFECTED
  Product  Versions     Fixed
  Unraid   1161ec120 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-78 · CNA: zdi · 1 reference · NVD status: Analyzed
Gogs: Unauthenticated Organization Teams Information Disclosure via API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0110   63.0     —
AFFECTED
  Product  Versions    Fixed
  gogs     < 0.14.3 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-200 · CNA: GitHub_M · 1 reference · NVD status: Deferred
warpdotdev warp — Warp: Remote SSH cwd can lead to unauthorized remote command execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0101   60.1     —
AFFECTED
  Product  Versions                                                           Fixed
  warp     >= 0.2023.03.21.08.02.stable_00, < 0.2026.05.13.09.15.stable_01 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 2 references · NVD status: Deferred
warpdotdev warp — Warp branch selector command injection via Git branch names
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  U  H  H  H    8.0   .0095   58.3     —
AFFECTED
  Product  Versions                                                           Fixed
  warp     >= 0.2025.08.06.08.12.stable_00, < 0.2026.05.13.09.15.stable_01 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 2 references · NVD status: Deferred
Gogs: Path Traversal in organization name results in RCE through Git hooks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0092   57.4     —
AFFECTED
  Product  Versions    Fixed
  gogs     < 0.14.3 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-23 · CNA: GitHub_M · 4 references · NVD status: Deferred
Rapid7 InsightConnect RPM Plugin — OS Command Injection in Rapid7 InsightConnect RPM Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0083   54.6     —
AFFECTED
  Product                    Versions     Fixed
  InsightConnect RPM Plugin  unspecified  1.0.2
TIMELINE
  May 15  Reserved by CNA
  Jun 24  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · 1 reference · NVD status: Analyzed
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0074   51.7     —
AFFECTED
  Product  Versions               Fixed
  rclone   >= 1.46.0, < 1.74.3 –  —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-306, CWE-78 · CNA: GitHub_M · 4 references · NVD status: Modified
Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0069   49.8     —
AFFECTED
  Product          Versions     Fixed
  NetVault Backup  14.0.0.19 –  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-89 · CNA: zdi · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-97818.849.8QuestNetVault BackupCWE-89Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulne…
CVE-2026-97828.849.8QuestNetVault BackupCWE-89Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vul…
CVE-2026-97838.849.8QuestNetVault BackupCWE-89Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution …
CVE-2026-97848.849.8QuestNetVault BackupCWE-89Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vul…
CVE-2026-97858.849.8QuestNetVault BackupCWE-89Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vul…
CVE-2026-97868.849.8QuestNetVault BackupCWE-89Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulne…
CVE-2026-75698.849.0QuestNetVault BackupCWE-79Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass V…
CVE-2026-97808.849.0QuestNetVault BackupCWE-79Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass V…
CVE-2025-604747.547.4n/an/aCWE-121A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c)…
CVE-2026-1248510.047.2GeoVision Inc.GV-I/O Box 4ECWE-121GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET …
CVE-2026-540699.247.0siyuan-notesiyuanCWE-346SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Orig…
CVE-2026-572968.845.6Jenkins ProjectJenkins External Workspace Manager PluginCWE-22Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject p…
CVE-2026-572817.545.6Jenkins ProjectJenkins Script Security PluginCWE-93Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject…
CVE-2026-251197.745.0gogsgogsCWE-290Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers
CVE-2026-124169.844.2pravelInvoice GeneratorCWE-640Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Passwo…
CVE-2025-604677.543.7n/an/aCWE-416A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter…
CVE-2026-529869.843.5LinuxLinuxCWE-476netfilter: nf_conntrack_sip: don't use simple_strtoul
CVE-2026-20507.843.5GIMPGIMPCWE-122GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulner…
CVE-2026-561118.343.0MarlinFirmwareMarlinCWE-129Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler
CVE-2026-529589.142.8LinuxLinuxCWE-125libceph: Fix potential out-of-bounds access in osdmap_decode()
CVE-2026-529829.842.7LinuxLinuxCWE-416net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
CVE-2026-529817.542.5LinuxLinuxCWE-401neigh: let neigh_xmit take skb ownership
CVE-2026-554887.742.3motioneye-projectmotioneyeCWE-22motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary F…
CVE-2026-530469.842.0LinuxLinuxCWE-416ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine
CVE-2026-529547.542.0LinuxLinuxCWE-617libceph: handle rbtree insertion error in decode_choose_args()
CVE-2026-529577.542.0LinuxLinuxCWE-476libceph: Fix potential null-ptr-deref in decode_choose_args()
CVE-2026-530459.841.4LinuxLinuxmemory: tegra124-emc: Fix dll_change check
CVE-2026-529999.141.4LinuxLinuxCWE-125netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
CVE-2026-530439.141.4LinuxLinuxCWE-787ocfs2/dlm: validate qr_numregions in dlm_match_regions()
CVE-2026-529149.841.3LinuxLinuxCWE-787batman-adv: fix fragment reassembly length accounting
CVE-2026-18408.741.2HubbellAclara Metrum Cellular Web InterfaceCWE-306Missing authentication for critical function in Hubbell Aclara Metrum Cellula…
CVE-2026-77618.841.0ultimatememberUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-862Ultimate Member <= 2.11.4 - Authenticated (Contributor+) Account Takeover via…
CVE-2026-87057.540.8clearsaleClearSale TotalCWE-89ClearSale Total <= 3.4.2 - Unauthenticated SQL Injection
CVE-2026-399489.340.6CacticactiCWE-89Cacti has SQL Injection via rfilter parameter in RLIKE clauses
CVE-2026-529987.540.6LinuxLinuxCWE-476netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check
CVE-2026-530037.540.6LinuxLinuxpppoe: drop PFC frames
CVE-2026-529747.540.6LinuxLinuxCWE-401net: tls: fix strparser anchor skb leak on offload RX setup failure
CVE-2026-487317.840.3warpdotdevwarpCWE-78Warp: Linux external editor command injection
CVE-2026-542977.539.8lostislandfaradayCWE-674Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustio…
CVE-2026-562708.739.0FlowiseFlowiseCWE-306Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod En…
CVE-2026-528165.439.0gogsgogsCWE-80Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary dat…
CVE-2026-440177.538.8docling-projectdoclingCWE-22Docling: Unsafe Zip Extraction in EasyOCR Model Download
CVE-2026-122428.838.6adegansAdRotate Banner ManagerCWE-94AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Inj…
CVE-2026-528025.437.8gogsgogsCWE-601Gogs: Open Redirect via redirect_to in Gogs
CVE-2026-528119.037.7gogsgogsCWE-22Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-529467.537.7LinuxLinuxCWE-667fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2026-124179.837.7pravelSignUp & SignInCWE-640SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Pass…
CVE-2026-456778.737.4RocketChatRocket.ChatCWE-862Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS
CVE-2026-42978.837.3newscredWelcome Software PublishingCWE-862Welcome Software Publishing <= 0.0.31 - Authenticated (Subscriber+) Arbitrary…
CVE-2026-1284610.037.1GeoVision Inc.GV-I/O Box 4ECWE-121GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET …
CVE-2026-1284710.037.1GeoVision Inc.GV-I/O Box 4ECWE-121GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET …
CVE-2026-1284810.037.1GeoVision Inc.GV-I/O Box 4ECWE-121GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET …
CVE-2026-529837.537.0LinuxLinuxnet: airoha: fix BQL imbalance in TX path
CVE-2026-527978.536.8gogsgogsCWE-22Gogs: Overwriting critical files results in a denial of service
CVE-2026-505519.936.7siyuan-notesiyuanCWE-79SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
CVE-2026-546997.736.3warpdotdevwarpCWE-78Warp: OS command injection when opening terminal links from WSL
CVE-2026-528145.535.9gogsgogsCWE-400Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake St…
CVE-2026-530109.835.8LinuxLinuxCWE-416ksmbd: fix use-after-free in smb2_open during durable reconnect
CVE-2026-530559.835.8LinuxLinuxCWE-416crypto: hisilicon/sec2 - prevent req used-after-free for sec
CVE-2026-573018.835.7Jenkins ProjectJenkins OWASP ZAP PluginCWE-610Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the J…
CVE-2026-530267.535.5LinuxLinuxNFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg
CVE-2026-562626.934.7Crawl4AICrawl4AICWE-306Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server
CVE-2026-528018.134.7gogsgogsCWE-20Gogs: Ability to import local repositories via Mirror Settings
CVE-2026-549048.234.4ruby-concurrencyconcurrent-rubyCWE-835concurrent-ruby: `AtomicReference#update` livelocks when the stored value is …
CVE-2026-131648.833.8MailerupMailerupCWE-306Unauthenticated self-registration in MailerUp allows access to stored email data
CVE-2026-238798.033.6miurahrpy7zrCWE-59py7zr: Arbitrary File Write Vulnerability
CVE-2026-398939.833.1CacticactiCWE-89Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_vie…
CVE-2026-529319.833.1LinuxLinuxbatman-adv: tp_meter: avoid use of uninit sender vars
CVE-2026-530889.833.1LinuxLinuxCWE-193net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
CVE-2026-97797.232.9ATENUnizonCWE-347ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Sig…
CVE-2026-530069.832.7LinuxLinuxCWE-416ipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-529678.132.4LinuxLinuxCWE-125smb/client: fix possible infinite loop and oob read in symlink_data()
CVE-2026-554549.932.3appsmithorgappsmithCWE-749Appsmith: Caddy admin API exposed without authentication
CVE-2026-529227.532.0LinuxLinuxCWE-476batman-adv: dat: handle forward allocation error
CVE-2026-529297.532.0LinuxLinuxCWE-476sctp: stream: fully roll back denied add-stream state
CVE-2026-530499.832.0LinuxLinuxCWE-667gfs2: add some missing log locking
CVE-2026-107357.531.9Unknownsmart-post-show-proShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Se…
CVE-2026-440168.231.6docling-projectdoclingCWE-94Docling: Unsafe Playwright-based HTML Rendering
CVE-2026-107497.231.4UnknownPost DuplicatorPost Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData
CVE-2026-529559.831.2LinuxLinuxCWE-125libceph: Fix potential out-of-bounds access in crush_decode()
CVE-2026-572808.831.1Jenkins ProjectJenkins Script Security PluginCWE-693Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not interc…
CVE-2026-530697.531.1LinuxLinuxCWE-476net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master
CVE-2026-527997.531.1gogsgogsCWE-639Gogs: Missing Authorization in Attachment Download
CVE-2026-91797.530.7hancock11WP Forms ConnectorCWE-89WP Forms Connector <= 1.8 - Unauthenticated SQL Injection via 'order' Parameter
CVE-2026-530877.530.2LinuxLinuxCWE-401net: bcmgenet: fix leaking free_bds
CVE-2026-529939.829.9LinuxLinuxCWE-415tipc: fix double-free in tipc_buf_append()
CVE-2026-528074.829.9gogsgogsCWE-79Gogs: DOM-based XSS via Milestone Name on New Issue Page
CVE-2026-528045.529.1gogsgogsCWE-193Gogs: Privilege Escalation via Collaboration Access Mode Validation
CVE-2026-529567.529.0LinuxLinuxCWE-125libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()
CVE-2026-529607.529.0LinuxLinuxceph: put folios not suitable for writeback
CVE-2026-487938.828.8jellyfinjellyfinCWE-88Jellyfin: Potential FFmpeg argument injection via unescaped subtitle file path
CVE-2026-530029.828.5LinuxLinuxCWE-787netfilter: conntrack: remove sprintf usage
CVE-2026-350258.627.9ProFTPD ProjectProFTPDCWE-59ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR
CVE-2026-91755.327.8ajitdasDevs Accounting – Simple Accounting and Invoicing SolutionCWE-862Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Sensitive…
CVE-2026-91787.527.7hancock11WP Forms ConnectorCWE-862WP Forms Connector <= 1.8 - Missing Authorization to Unauthenticated Informat…
CVE-2026-399559.827.6CacticactiCWE-89Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REG…
CVE-2026-498518.727.6lepturemistuneCWE-400Mistune: Potential DoS via quadratic-time parsing in parse_link_text
CVE-2026-530707.527.6LinuxLinuxsctp: disable BH before calling udp_tunnel_xmit_skb()
CVE-2025-713328.527.5FlowiseFlowiseCWE-89Flowise - SQL Injection in importChatflows API via chatflow.id Parameter
CVE-2026-130338.827.4GoogleChromeCWE-125Out of bounds read and write in Blink>InterestGroups in Google Chrome prior t…
CVE-2026-130388.827.4GoogleChromeCWE-416Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.19…
CVE-2026-492478.827.5jellyfinjellyfinCWE-22Jellyfin: Potential Authenticated path traversal in /ClientLog/Document
CVE-2025-647194.927.4gogsgogsCWE-20Gogs: Denial of Service in repository/wiki file listing web pages
CVE-2026-529899.827.3LinuxLinuxCWE-908nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
CVE-2025-713617.626.8picklescanpicklescanCWE-95picklescan - Remote Code Execution via Undetected idlelib.calltip.Calltip.fet…
CVE-2026-463488.726.7mastodonmastodonCWE-918Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)
CVE-2026-528107.126.6gogsgogsCWE-284Gogs: Write to readonly repositories using receive-pack + service=git-upload-…
CVE-2026-529327.526.4LinuxLinuxxfrm: ipcomp: Free destination pages on acomp errors
CVE-2026-528087.126.4gogsgogsCWE-269Gogs: Write-level collaborators can mutate admin-only repository settings via…
CVE-2026-119987.626.2GoogleAngularJSCWE-791AngularJS XSS via SCE resource URL sanitization bypass
CVE-2026-529249.826.0LinuxLinuxCWE-416sctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-440207.525.9docling-projectdoclingCWE-776Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVE-2026-131635.325.8MailerupMailerupCWE-601Lack of input validation in Mailerup input parameter leads to Open Redirect
CVE-2026-555709.025.5siyuan-notesiyuanCWE-79SiYuan: Stored XSS results to Electron RCE in SiYuan marketplace via unescape…
CVE-2026-501898.925.4appsmithorgappsmithCWE-183Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor…
CVE-2026-557628.125.1RocketChatRocket.ChatCWE-862Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from…
CVE-2026-472678.324.7gogsgogsCWE-918Gogs: SSRF in webhook deliveries
CVE-2026-506994.624.0FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule re…
CVE-2026-332357.723.7Significant-GravitasAutoGPTCWE-400AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating f…
CVE-2026-529457.523.6LinuxLinuxRevert "wireguard: device: enable threaded NAPI"
CVE-2026-456899.123.4RocketChatRocket.ChatCWE-943Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arb…
CVE-2026-96125.323.4yapacdevWhatsOrder – Instant Checkout for WooCommerceCWE-200WhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Pred…
CVE-2026-540679.923.3siyuan-notesiyuanCWE-79SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVE-2026-471107.123.1ueberdosistiptap-phpCWE-241Tiptap for PHP < 2.1.1 DoS via Malformed href Attribute
CVE-2026-530869.823.0LinuxLinuxCWE-362net: bcmgenet: fix racing timeout handler
CVE-2026-529208.322.5LinuxLinuxnetfilter: xt_policy: fix strict mode inbound policy matching
CVE-2026-96194.322.4berfectReviews and Rating – DocplannerCWE-862Reviews and Rating <= 1.1.4 - Missing Authorization to Authenticated (Subscri…
CVE-2026-100927.222.3nicashmuCincopa video and media plug-inCWE-79Cincopa video and media plug-in <= 1.163 - Unauthenticated Stored Cross-Site …
CVE-2026-527988.922.2gogsgogsCWE-79Gogs: Stored XSS in `.ipynb` Preview
CVE-2026-556669.322.1RocketChatRocket.ChatCWE-287Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple …
CVE-2026-76175.322.1secuforSecufor_OAuthCWE-862Secufor_OAuth <= 1.0.7 - Missing Authorization to Unauthenticated Account Log…
CVE-2026-120945.322.1iamranitAdvanced Contact Form 7 – Compact DBCWE-862Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated A…
CVE-2026-100437.821.9MosaicMLComposerCWE-502MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vul…
CVE-2026-562379.321.8CapgoCapgoCWE-287Capgo - Unauthenticated API Key Generation via Client-Side Parameter Manipula…
CVE-2026-130368.821.9GoogleChromeCWE-416Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a re…
CVE-2026-131506.921.7PentestifyPentestifyCWE-918SSRF in Pentestify PDF generation endpoint via Host header
CVE-2026-120957.221.5bytuncayKargo TakipCWE-918Kargo Takip <= 1.2 - Unauthenticated Server-Side Request Forgery via 'api_url…
CVE-2026-121007.221.5abhisheksaha11URL PreviewCWE-918URL Preview <= 1.0 - Unauthenticated Server-Side Request Forgery via 'url' Pa…
CVE-2026-541589.921.4siyuan-notesiyuanCWE-79SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
CVE-2026-335439.321.4FOSSBillingFOSSBillingCWE-288FOSSBilling: Authentication bypass allows unauthenticated administrator creation
CVE-2026-456889.121.4RocketChatRocket.ChatCWE-943Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitra…
CVE-2026-130289.621.2GoogleChromeCWE-416Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 a…
CVE-2026-130329.621.2GoogleChromeCWE-416Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 a…
CVE-2026-398996.920.8CacticactiCWE-22Cacti: Path Traversal via filename parameter in package_import.php
CVE-2026-563386.920.6CapgoCapgoCWE-703Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint
CVE-2026-319786.520.4motioneye-projectmotioneyeCWE-22motionEye: Arbitrary File Read via Path Traversal in Picture/Movie Preview En…
CVE-2026-528058.720.4gogsgogsCWE-918Gogs: Migration Redirect Bypass Leads to Internal Repository Theft
CVE-2026-539439.620.2TryGhostGhostCWE-524Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
CVE-2026-546864.320.2warpdotdevwarpCWE-78Warp: DCS lifecycle hook spoofing can alter terminal session metadata
CVE-2026-107457.920.1upKeeper SolutionsupKeeper Instant Privilege AccessCWE-117Improper output neutralization for logs vulnerability in upKeeper Solutions u…
CVE-2026-572844.319.9Jenkins ProjectJenkins Pipeline: Groovy PluginCWE-470Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restr…
CVE-2026-562458.819.2Cap-gocapgoCWE-269Supabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning…
CVE-2026-507015.119.0FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb …
CVE-2026-527947.518.9getsentrysentryCWE-1333Sentry: Inefficient Regular Expression Complexity in sentry
CVE-2026-562328.718.8CapgoCapgoCWE-863Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header
CVE-2026-277087.118.5FOSSBillingFOSSBillingCWE-284FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access
CVE-2026-501297.518.2mastodonmastodonCWE-248Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSF…
CVE-2026-529188.818.1LinuxLinuxBluetooth: serialize accept_q access
CVE-2026-547598.718.1siyuan-notesiyuanCWE-79SiYuan: Lute HTML sanitizer allows `<iframe>` tags in Bazaar package README, …
CVE-2026-563376.918.0CapgoCapgoCWE-200Capgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2
CVE-2026-530718.817.9LinuxLinuxCWE-667Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
CVE-2026-563686.317.9ImageMagickImageMagickCWE-401ImageMagick - Memory Leak in Raw Pixel Data Coders
CVE-2026-492461.717.6jellyfinjellyfinCWE-22Jellyfin: Potential MKV attachment filename path traversal to RCE
CVE-2026-100917.217.4cgarveyEmail JavaScript CloakCWE-79Email JavaScript Cloak <= 1.03 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-506984.617.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering
CVE-2026-507004.617.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image rendering
CVE-2026-507044.617.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs r…
CVE-2026-507054.617.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering
CVE-2026-507104.617.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config
CVE-2026-507114.617.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering
CVE-2026-487048.817.3warpdotdevwarpCWE-20Warp Markdown notebook links may open executable local files
CVE-2026-86905.317.3rentmyRentMy Real-Time Rental Management PluginCWE-862RentMy Real-Time Rental Management Plugin <= 4.0.4.1 - Missing Authorization …
CVE-2026-499795.117.1appsmithorgappsmithCWE-918Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses W…
CVE-2025-713547.617.0picklescanpicklescanCWE-502picklescan - Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText
CVE-2026-530758.816.7LinuxLinuxppp: require CAP_NET_ADMIN in target netns for unattached ioctls
CVE-2026-116146.416.4xproXpro Addons — 140+ Widgets for ElementorCWE-79Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting vi…
CVE-2026-487208.816.2warpdotdevwarpCWE-20Warp: SSH remote output can lead to local file overwrite and persistence
CVE-2026-562239.315.8CapgoCapgoCWE-287Capgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-user
CVE-2026-529348.815.9LinuxLinuxbatman-adv: tvlv: reject oversized TVLV packets
CVE-2026-557597.415.7RocketChatRocket.ChatCWE-287Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and …
CVE-2026-492786.715.7RocketChatRocket.ChatCWE-285Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enabl…
CVE-2026-96437.215.5joomunitedWP Meta SEOCWE-79WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUE…
CVE-2026-540685.915.2siyuan-notesiyuanCWE-306SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /a…
CVE-2026-507034.815.2FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label rendering
CVE-2026-507084.815.2FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering
CVE-2026-507094.815.2FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering
CVE-2026-507124.815.2FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering
CVE-2026-529437.815.1LinuxLinuxCWE-416net: skbuff: fix missing zerocopy reference in pskb_carve helpers
CVE-2026-562567.115.0CapgoCapgoCWE-602Capgo - Two-Factor Authentication Bypass via Organization Management API
CVE-2026-556110.014.8Mintplex-Labsanything-llmCWE-639AnythingLLM: embed-parsed-file cleanup deletes any parsed file by ID without …
CVE-2026-113706.414.7joomunitedWP Meta SEOCWE-918WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forg…
CVE-2026-130318.814.5GoogleChromeCWE-416Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a re…
CVE-2026-96164.314.4verenigingvanregistrarsGenerate Security.txtCWE-862Generate Security.txt <= 1.0.12 - Missing Authorization to Authenticated (Sub…
CVE-2026-473898.614.3mastodonmastodonCWE-184Mastodon: SSRF protection bypass on older Ruby versions
CVE-2026-86144.314.2assistioaiAssistioCWE-862Assistio <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Plug…
CVE-2026-487894.314.2Mintplex-Labsanything-llmCWE-22AnythingLLM: Windows path containment bypass in document folder route
CVE-2026-86175.313.8ailchevSearchPlusCWE-862SearchPlus <= 1.7.1 - Missing Authorization to Unauthenticated Settings Modif…
CVE-2026-91725.313.7ajitdasDevs Accounting – Simple Accounting and Invoicing SolutionCWE-862Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Account D…
CVE-2026-527963.513.5gogsgogsCWE-1336Gogs: DoS in rendering issue index pattern
CVE-2026-560527.613.3FunnelKitFunnel Builder by FunnelKitCWE-89WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.5 - SQL Injection vuln…
CVE-2026-573037.113.2Jenkins ProjectJenkins Assembla PluginCWE-918Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to …
CVE-2026-572883.713.3Jenkins ProjectJenkins Active Directory PluginCWE-90Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user n…
CVE-2026-127607.113.1TP-Link Systems Inc.Tapo C200 v3CWE-770Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in …
CVE-2026-399518.812.9CacticactiCWE-89Cacti: Stored SQL Injection via graph_name_regexp in Reports feature
CVE-2026-554555.312.8appsmithorgappsmithCWE-918Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host…
CVE-2026-106424.612.7zephyrprojectzephyrCWE-835Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flo…
CVE-2026-86884.312.8krishawebAdvance Nav Menu ManagerCWE-862Advance Nav Menu Manager <= 1.3 - Missing Authorization to Authenticated (Sub…
CVE-2026-563515.312.4n8nn8nCWE-89n8n - SQL Injection in MySQL, PostgreSQL, and Microsoft SQL Nodes
CVE-2026-130358.812.3GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 a…
CVE-2026-528127.112.3gogsgogsCWE-345Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-572854.312.3Jenkins ProjectJenkins GitHub Branch Source PluginCWE-862A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v…
CVE-2026-572864.312.3Jenkins ProjectJenkins Git Parameter PluginCWE-862A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_…
CVE-2026-457572.312.1RocketChatRocket.ChatCWE-613Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking exis…
CVE-2026-492772.312.1RocketChatRocket.ChatCWE-613Rocket.Chat: OAuth access and refresh tokens remain valid after account deact…
CVE-2026-539495.312.0TryGhostGhostCWE-200Ghost Content API filter bypass reveals private fields
CVE-2026-487258.111.9warpdotdevwarpCWE-276Warp may allow terminal output to access the local clipboard through OSC 52
CVE-2026-97097.711.8UnknownCornerstoneThemeco Cornerstone < 7.8.9 (Premium, bundled with X Theme) - Subscriber+ Arb…
CVE-2026-97107.711.8UnknownCornerstoneThemeco Cornerstone < 7.8.8 (Premium, bundled with X Theme) - Subscriber+ Arb…
CVE-2026-91844.311.424liveblog24liveblog – live blog toolCWE-86224liveblog <= 2.2 - Missing Authorization to Authenticated (Author+) Settings…
CVE-2026-563026.911.2CapgoCapgoCWE-284Capgo - Unsecured Supabase Images Bucket via Missing Row Level Security
CVE-2026-572825.011.1Jenkins ProjectJenkins Git client PluginCWE-78Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the wor…
CVE-2026-539475.311.0TryGhostGhostCWE-204Ghost: Member existence leak via magic link sign-in response
CVE-2026-456878.510.9RocketChatRocket.ChatCWE-915Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in…
CVE-2026-86286.110.8owencutajarEntreDroppersCWE-79EntreDroppers <= 1.1.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter
CVE-2026-539507.510.7TryGhostGhostCWE-79@tryghost/activitypub: XSS in Ghost's ActivityPub client
CVE-2026-91834.310.724liveblog24liveblog – live blog toolCWE-20024liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Inform…
CVE-2025-604685.510.6n/an/aCWE-122GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88…
CVE-2026-124886.210.5GeoVision Inc.GeoVisionCWE-121GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability
CVE-2026-96206.410.4joomunitedWP Latest PostsCWE-79WP Latest Posts <= 5.0.11 - Authenticated (Author+) Stored Cross-Site Scripti…
CVE-2026-130268.810.1GoogleChromeCWE-416Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.…
CVE-2026-130278.810.1GoogleChromeCWE-416Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed…
CVE-2026-539445.89.7TryGhostGhostCWE-184Ghost: Private IP filtering bypass to make server-side requests to internal s…
CVE-2026-530728.89.5LinuxLinuxCWE-667Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
CVE-2026-528008.89.4gogsgogsCWE-352Gogs: CSRF Leading to Organization Owner Takeover
CVE-2026-562447.19.4CapgoCapgoCWE-200Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key
CVE-2026-492205.79.4jellyfinjellyfinCWE-79Jellyfin: Potential XSS in user management
CVE-2026-126818.99.1Googlego-attestationCWE-1285Improper Validation of Specified Index, Position, or Offset in Input vulnerab…
CVE-2026-555837.69.1twentyhqtwentyCWE-639Twenty: Cross-workspace IDOR in AgentTurnResolver
CVE-2026-36527.29.0n/aARformsCWE-79ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Pa…
CVE-2026-540707.19.0siyuan-notesiyuanCWE-79SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
CVE-2026-88656.48.7paradigmatoolsAvalon23 Products Filter for WooCommerceCWE-79Avalon23 Products Filter for WooCommerce <= 1.1.6 - Authenticated (Contributo…
CVE-2026-130235.38.5GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a r…
CVE-2026-130305.38.5GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 …
CVE-2026-131401.18.4Thinkst Applied ResearchCanarytokensCWE-79Stored Cross-Site Scripting in Canarytokens.org
CVE-2026-130258.38.3GoogleChromeCWE-20Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote at…
CVE-2026-562577.18.1CapgoCapgoCWE-284Capgo - Authorization Bypass in App Ownership Transfer via Direct PostgREST U…
CVE-2025-604735.58.1n/an/aCWE-476A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter…
CVE-2026-563105.38.1Cap-gocapgoCWE-285Cap-go - Authorization Bypass in Organization Members Endpoint via API Key Sc…
CVE-2026-129867.38.0PayaraPayara ServerCWE-352A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.…
CVE-2026-88966.48.0mirsoftwareMIR blocks and shortcodesCWE-79MIR blocks and shortcodes <= 1.0.0 - Authenticated (Contributor+) Stored Cros…
CVE-2026-118776.37.6OpenTextAccess ManagerCWE-648Missing Authorization Vulnerability in OpenText Access Manager
CVE-2026-573004.37.6Jenkins ProjectJenkins MCP Server PluginCWE-862A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe …
CVE-2026-573024.37.6Jenkins ProjectJenkins FitNesse PluginCWE-256Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job …
CVE-2026-487037.87.5warpdotdevwarpCWE-78Warp: Command Injection via Warp code search tool arguments
CVE-2025-604715.57.5n/an/aCWE-416A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/fil…
CVE-2026-562317.27.4CapgoCapgoCWE-285Capgo - Broken Object Level Authorization in Build Job Control via jobId Para…
CVE-2026-62924.37.4manuelpadillacMP Customize Login PageCWE-352MP Customize Login Page <= 1.0 - Cross-Site Request Forgery to Settings Update
CVE-2026-567615.37.2honohonoCWE-79hono - HTML Injection via Improper JSX Attribute Name Handling in SSR
CVE-2026-572934.36.8Jenkins ProjectJenkins Gitee PluginCWE-862An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ a…
CVE-2026-86226.16.6pixelweltImage Sizes on DemandCWE-79Image Sizes on Demand <= 1.3 - Reflected Cross-Site Scripting via PHP_SELF Se…
CVE-2026-527954.36.5gogsgogsCWE-863Gogs: Authorization Bypass in Watch API allows any user to monitor private re…
CVE-2026-398975.36.4CacticactiCWE-79Cacti has a Reflected XSS Vulnerability via html_auth_footer
CVE-2026-399005.36.4CacticactiCWE-79Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context
CVE-2026-572974.36.4Jenkins ProjectJenkins Contrast Continuous Application Security PluginCWE-862A missing permission check in Jenkins Contrast Continuous Application Securit…
CVE-2026-572994.36.4Jenkins ProjectJenkins Contrast Continuous Application Security PluginCWE-862Missing permission checks in Jenkins Contrast Continuous Application Security…
CVE-2026-440225.55.9docling-projectdoclingCWE-22Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
CVE-2026-107532.76.0UnknownSite Kit by GoogleSite Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update
CVE-2026-130297.55.8GoogleChromeCWE-416Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197…
CVE-2026-463495.35.9mastodonmastodonCWE-347Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVE-2026-572945.45.8Jenkins ProjectJenkins EC2 Fleet PluginCWE-862A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81…
CVE-2026-573045.45.8Jenkins ProjectJenkins Assembla PluginCWE-862A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows …
CVE-2026-549062.15.7ruby-concurrencyconcurrent-rubyCWE-414concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray re…
CVE-2025-604665.05.6n/an/aCWE-416A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filte…
CVE-2026-572834.35.4Jenkins ProjectJenkins Pipeline: Groovy PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy…
CVE-2026-1253710.05.0Google CloudGemini CLICWE-78Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows
CVE-2026-529697.84.9LinuxLinuxCWE-129KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
CVE-2026-572904.34.9Jenkins ProjectJenkins Priority Sorter PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter …
CVE-2026-528096.84.8gogsgogsCWE-324Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_P…
CVE-2026-464239.34.7RocketChatRocket.ChatCWE-347Rocket.Chat: SAML signature validation skipped when IdP certificate field is …
CVE-2026-132017.34.5Red HatRed Hat Container Native Virtualization 4.13CWE-61Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-ha…
CVE-2026-398942.54.4CacticactiCWE-474Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting
CVE-2026-105524.34.4jotisBlue CaptchaCWE-352Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter
CVE-2026-130244.24.4GoogleChromeCWE-20Insufficient validation of untrusted input in Navigation in Google Chrome pri…
CVE-2026-487218.64.2warpdotdevwarpCWE-180Warp: Env-var prefixes can lead to denylisted command autoexecution
CVE-2026-572915.44.3Jenkins ProjectJenkins Gitee PluginCWE-862Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and e…
CVE-2026-97244.34.3motordeskMotorDeskCWE-352MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update
CVE-2026-529615.54.2LinuxLinuxCWE-617ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
CVE-2026-529725.54.2LinuxLinuxCWE-190crypto: af_alg - Cap AEAD AD length to 0x80000000
CVE-2026-563585.14.2n8nn8nCWE-79n8n - Stored Cross-Site Scripting in Form Trigger Node
CVE-2026-529767.84.1LinuxLinuxCWE-416drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl()
CVE-2026-130344.74.1GoogleChromeCWE-346Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782…
CVE-2026-130214.34.1GoogleChromeCWE-346Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrom…
CVE-2026-529127.84.0LinuxLinuxCWE-416netfilter: nf_queue: hold bridge skb->dev while queued
CVE-2026-529737.84.0LinuxLinuxCWE-416futex: Drop CLONE_THREAD requirement for private default hash alloc
CVE-2026-530167.83.9LinuxLinuxCWE-787crypto: ccp - copy IV using skcipher ivsize
CVE-2026-530597.83.9LinuxLinuxCWE-787dm log: fix out-of-bounds write due to region_count overflow
CVE-2026-573074.23.8Jenkins ProjectJenkins Zowe zDevOps PluginCWE-862A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_4…
CVE-2026-539454.03.9TryGhostGhostCWE-367Ghost: Server-side request forgery via DNS rebinding in external request hand…
CVE-2026-529507.83.7LinuxLinuxCWE-416drm/xe/dma-buf: fix UAF with retry loop
CVE-2026-529517.83.7LinuxLinuxCWE-416drm/xe/dma-buf: handle empty bo and UAF races
CVE-2026-529627.83.7LinuxLinuxCWE-787ceph: fix a buffer leak in __ceph_setxattr()
CVE-2026-529757.83.7LinuxLinuxbonding: 3ad: implement proper RCU rules for port->aggregator
CVE-2026-529927.83.7LinuxLinuxCWE-787fs/adfs: validate nzones in adfs_validate_bblk()
CVE-2026-530367.83.7LinuxLinuxCWE-193bpf, arm64: Fix off-by-one in check_imm signed range check
CVE-2026-529687.13.7LinuxLinuxCWE-125KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
CVE-2026-529528.83.7LinuxLinuxCWE-617iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset
CVE-2026-130226.53.7GoogleChromeCWE-346Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827…
CVE-2026-529877.83.6LinuxLinuxCWE-1341drm/amdgpu: avoid double drm_exec_fini() in userq validate
CVE-2026-529477.83.4LinuxLinuxCWE-416net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
CVE-2026-530337.83.4LinuxLinuxCWE-416bpf, sockmap: Take state lock for af_unix iter
CVE-2026-89056.13.4osiris8Osiris Signature BannerCWE-352Osiris Signature Banner <= 0.5 - Cross-Site Request Forgery to Stored Cross-S…
CVE-2026-529965.53.5LinuxLinuxCWE-401ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open
CVE-2026-530475.53.5LinuxLinuxefi/capsule-loader: fix incorrect sizeof in phys array reallocation
CVE-2026-529237.83.4LinuxLinuxCWE-401ipc: limit next_id allocation to the valid ID range
CVE-2026-530057.83.4LinuxLinuxCWE-416af_unix: Drop all SCM attributes for SOCKMAP.
CVE-2026-529665.53.3LinuxLinuxdrm: Replace old pointer to new idr
CVE-2026-529717.83.3LinuxLinuxCWE-416net: ena: PHC: Fix potential use-after-free in get_timestamp
CVE-2026-529537.13.3LinuxLinuxCWE-125iommu/vt-d: Fix oops due to out of scope access
CVE-2026-539485.43.3TryGhostGhostCWE-434Ghost: File Upload Content-Type Spoofing
CVE-2026-546398.83.2style-dictionarystyle-dictionaryCWE-1321Style Dictionary - Prototype Pollution in convertTokenData utility function
CVE-2026-118788.23.2OpenTextAccess ManagerCWE-79Reflected Cross-Site Scripting vulnerability in OpenText Access Manager
CVE-2026-530967.83.2LinuxLinuxCWE-476bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
CVE-2026-530907.83.1LinuxLinuxCWE-253bpf: Fix ld_{abs,ind} failure path analysis in subprogs
CVE-2026-530927.83.1LinuxLinuxCWE-393bpf: Fix linked reg delta tracking when src_reg == dst_reg
CVE-2026-530125.53.1LinuxLinuxCWE-476nexthop: fix IPv6 route referencing IPv4 nexthop
CVE-2026-572874.33.1Jenkins ProjectJenkins Job Configuration History PluginCWE-312Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier doe…
CVE-2026-530538.82.9LinuxLinuxiommu/amd: Fix clone_alias() to use the original device's devid
CVE-2026-530918.42.9LinuxLinuxCWE-131net: pull headers in qdisc_pkt_len_segs_init()
CVE-2026-530007.83.0LinuxLinuxCWE-763netfilter: nat: use kfree_rcu to release ops
CVE-2026-530047.83.0LinuxLinuxCWE-787sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks
CVE-2026-530097.83.0LinuxLinuxCWE-415ice: fix double-free of tx_buf skb
CVE-2026-530247.83.0LinuxLinuxCWE-416greybus: raw: fix use-after-free if write is called after disconnect
CVE-2026-530257.83.0LinuxLinuxCWE-416greybus: raw: fix use-after-free on cdev close
CVE-2026-530317.82.9LinuxLinuxbpf: Validate node_id in arena_alloc_pages()
CVE-2026-530947.82.9LinuxLinuxbpf: Fix stale offload->prog pointer after constant blinding
CVE-2026-531307.83.0LinuxLinuxCWE-191fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
CVE-2026-529485.53.0LinuxLinuxCWE-190i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
CVE-2026-105315.43.0UnknownAI Share & SummarizeAI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortc…
CVE-2026-501285.32.9mastodonmastodonCWE-354Mastodon: Spoofing of attribution domains
CVE-2026-529635.52.9LinuxLinuxALSA: usb-audio: Bound MIDI endpoint descriptor scans
CVE-2026-529705.52.9LinuxLinuxnetfilter: nft_ct: fix missing expect put in obj eval
CVE-2026-529845.52.9LinuxLinuxnet/sched: netem: fix queue limit check to include reordered packets
CVE-2026-530345.52.9LinuxLinuxCWE-476bpf, sockmap: Fix af_unix null-ptr-deref in proto update
CVE-2026-530565.52.9LinuxLinuxdrm/msm/dpu: fix mismatch between power and frequency
CVE-2026-530605.52.9LinuxLinuxCWE-401dm cache metadata: fix memory leak on metadata abort retry
CVE-2026-530635.52.9LinuxLinuxdm cache: fix write hang in passthrough mode
CVE-2026-572955.42.8Jenkins ProjectJenkins EC2 Fleet PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin…
CVE-2026-573055.42.8Jenkins ProjectJenkins Assembla PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin …
CVE-2026-119974.32.9seo_toolsBulk SEO ImageCWE-352Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update
CVE-2026-530578.82.8LinuxLinuxiommu/riscv: Add IOTINVAL after updating DDT/PDT entries
CVE-2026-531097.82.8LinuxLinuxCWE-416powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy
CVE-2026-529645.52.8LinuxLinuxALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
CVE-2026-529905.52.8LinuxLinuxfsnotify: fix inode reference leak in fsnotify_recalc_mask()
CVE-2026-530515.52.8LinuxLinuxPCI: tegra194: Fix CBB timeout caused by DBI access before core power-on
CVE-2026-530117.82.7LinuxLinuxCWE-416net/sched: taprio: fix use-after-free in advance_sched() on schedule switch
CVE-2026-529157.12.7LinuxLinuxCWE-129netfilter: ip6t_hbh: reject oversized option lists
CVE-2026-529177.12.7LinuxLinuxCWE-125sctp: diag: reject stale associations in dump_one path
CVE-2026-530417.12.7LinuxLinuxCWE-787ocfs2: fix listxattr handling when the buffer is full
CVE-2026-529785.52.7LinuxLinuxnet: psp: require admin permission for dev-set and key-rotate
CVE-2026-529945.52.7LinuxLinuxvsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting
CVE-2026-529975.52.7LinuxLinuxCWE-476net/sched: sch_dualpi2: drain both C-queue and L-queue in dualpi2_change()
CVE-2026-530977.82.6LinuxLinuxCWE-416wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()
CVE-2026-530987.82.6LinuxLinuxCWE-416wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()
CVE-2026-529427.12.7LinuxLinuxCWE-125netfilter: nf_log: validate MAC header was set before dumping it
CVE-2026-530447.12.5LinuxLinuxCWE-125soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric lookup tables
CVE-2026-480286.52.5mastodonmastodonCWE-354Mastodon: Removal of integrity-protected JSON entries from signed activities
CVE-2026-119685.52.6TortoiseGit teamTortoiseGitCWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Inject…
CVE-2026-529135.52.4LinuxLinuxCWE-476batman-adv: v: stop OGMv2 on disabled interface
CVE-2026-529165.52.5LinuxLinuxbatman-adv: frag: disallow unicast fragment in fragment
CVE-2026-529655.52.5LinuxLinuxCWE-835drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure
CVE-2026-529775.52.4LinuxLinuxfutex: Prevent lockup in requeue-PI during signal/ timeout wakeup
CVE-2026-529855.52.4LinuxLinuxCWE-908netdevsim: zero initialize struct iphdr in dummy sk_buff
CVE-2026-529955.52.4LinuxLinuxnet/rds: zero per-item info buffer before handing it to visitors
CVE-2026-530015.52.4LinuxLinuxnetfilter: xtables: restrict several matches to inet family
CVE-2026-530215.52.5LinuxLinuxCWE-190scsi: target: core: Fix integer overflow in UNMAP bounds check

Results continue: ranks 401–520.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-24 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.