AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U N H H 6.5 .0325 87.3 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
520 CVEs published June 24, 2026: 56 critical, 226 high, 227 medium, 10 low; 0 in KEV; 16 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 495 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 6175 | 10547 | 1170 | 2563 |
| KEV catalog size | 1670 | |||
479 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 320 | 1286 | 104 | 767 | 412 | 1 | 27 | 3 | 0.2 | 7.8 | .0013 | +94 |
| 704 | 878 | 85 | 462 | 299 | 29 | 74 | 6 | 0.7 | 8.1 | .0023 | +688 | |
| microsoft | 220 | 710 | 55 | 474 | 160 | 4 | 378 | 27 | 3.8 | 7.8 | .0044 | +56 |
| red hat | 93 | 157 | 9 | 67 | 74 | 7 | 4 | 0 | 0.0 | 6.8 | .0027 | +84 |
| apple | 14 | 61 | 0 | 16 | 36 | 2 | 93 | 7 | 11.5 | 5.7 | .0023 | +1 |
| canonical | 2 | 16 | 1 | 4 | 6 | 5 | 0 | 0 | 0.0 | 5.5 | .0010 | +2 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | -7 |
| suse | 4 | 6 | 1 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 9 | 22 | 4 | 3 | 8 | 0 | 96 | 10 | 45.5 | 6.8 | .0257 | +4 |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | +17 |
| palo alto networks | 9 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | +8 |
| ubiquiti | 8 | 11 | 7 | 4 | 0 | 0 | 4 | 3 | 27.3 | 9.9 | .0083 | +6 |
| f5 | 6 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | +4 |
| ivanti | 4 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | +2 |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 |
| fortinet | 2 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 92 | 124 | 18 | 44 | 53 | 8 | 40 | 1 | 0.8 | 6.8 | .0048 | +83 |
| mozilla | 49 | 55 | 11 | 18 | 26 | 0 | 13 | 0 | 0.0 | 7.3 | .0026 | +44 |
| gitlab | 11 | 20 | 0 | 4 | 12 | 2 | 4 | 2 | 10.0 | 4.8 | .0024 | +11 |
| docker | 4 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | +1 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | -3 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 243 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | +243 |
| adobe | 132 | 136 | 4 | 50 | 77 | 2 | 75 | 3 | 2.2 | 5.5 | .0021 | +131 |
| ibm | 32 | 81 | 19 | 35 | 27 | 0 | 7 | 0 | 0.0 | 7.5 | .0028 | +32 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +1 |
| solarwinds | 3 | 6 | 1 | 2 | 1 | 0 | 11 | 4 | 66.7 | 7.5 | .3995 | +3 |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | +1 |
| zohocorp | 1 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 9 | 12 | 0 | 4 | 2 | 5 | 26 | 1 | 8.3 | 5.5 | .0058 | +8 |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 1 | 0 | 0.0 | 7.5 | .0020 | +6 |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 |
| abb | 6 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +6 |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | +3 |
| mitsubishi electric | 3 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.7 | .0064 | +3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 72 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | +72 |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +61 |
| sourcecodester | 37 | 59 | 0 | 0 | 25 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +33 |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 |
| edimax | 5 | 56 | 0 | 33 | 0 | 23 | 1 | 0 | 0.0 | 7.4 | .0070 | -20 |
| jenkins project | 36 | 49 | 0 | 9 | 39 | 1 | 0 | 0 | 0.0 | 4.8 | .0021 | +36 |
| dell | 31 | 49 | 0 | 24 | 24 | 0 | 2 | 1 | 2.0 | 6.8 | .0015 | +19 |
| capgo | 46 | 46 | 2 | 22 | 21 | 1 | 0 | 0 | 0.0 | 7.0 | .0034 | +46 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE-2026-48907 | .6883 | 99.3 | 10.0 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 |
| Vendor | CVEs |
|---|---|
| 856 | |
| linux | 734 |
| oracle | 268 |
| microsoft | 226 |
| adobe | 132 |
| red hat | 125 |
| apache | 95 |
| ibm | 81 |
| spring | 72 |
| openclaw | 67 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 10 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 37 |
| Packagist | 22 |
| PyPI | 10 |
| npm | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1680 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1680 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1680 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1680 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1680 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1680 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1680 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1680 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1680 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1680 |
EXPLOIT PUBLISHED — CVE-2025-60466. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60467. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60468. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60471. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60473. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60474. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71332 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10642 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11998 (Google AngularJS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49979 (appsmithorg appsmith). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50189 (appsmithorg appsmith). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53765 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53766 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54297 (lostisland faraday). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54904 (ruby-concurrency concurrent-ruby). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55454 (appsmithorg appsmith). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56270 (Flowise). Public exploit reference added.
DUE DATE PASSED — CVE-2026-11645 (Google Chrome). CISA remediation deadline was June 23, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-20245 (Cisco Catalyst SD-WAN Controller). CISA remediation deadline was June 23, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-7473 (Arista Networks EOS). CISA remediation deadline was June 23, 2026; still in catalog.
520 CVEs published. 25 box scores and 375 table rows below; the remaining 120 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U N H H 6.5 .0325 87.3 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0189 77.8 —
AFFECTED Product Versions Fixed siyuan < 3.7.0 – —
TIMELINE Jun 11 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0180 76.6 —
AFFECTED Product Versions Fixed GV-I/O Box 4E V2.09 – V2.12
TIMELINE Jun 17 Reserved by CNA Jun 24 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0180 76.6 —
AFFECTED Product Versions Fixed GV-I/O Box 4E V2.09 – V2.12
TIMELINE Jun 22 Reserved by CNA Jun 24 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0176 76.1 —
AFFECTED Product Versions Fixed GV-I/O Box 4E V2.09 – V2.12
TIMELINE Jun 22 Reserved by CNA Jun 24 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0176 76.1 —
AFFECTED Product Versions Fixed GV-I/O Box 4E V2.09 – V2.12
TIMELINE Jun 22 Reserved by CNA Jun 24 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0158 73.4 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0148 71.7 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0148 71.7 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0146 71.4 —
AFFECTED Product Versions Fixed gogs < 0.14.3 – —
TIMELINE Jun 8 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0140 70.3 —
AFFECTED Product Versions Fixed NetVault Backup 14.0.0.19 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0131 68.1 —
AFFECTED Product Versions Fixed cacti < 1.2.31 – —
TIMELINE Apr 7 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U H N N 5.5 .0120 65.5 —
AFFECTED Product Versions Fixed motioneye < 0.44.0 – —
TIMELINE Mar 11 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U N H H 6.5 .0120 65.4 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0114 64.0 —
AFFECTED Product Versions Fixed feast unspecified —
TIMELINE Jun 18 Reserved by CNA Jun 24 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0114 63.9 —
AFFECTED Product Versions Fixed cacti < 1.2.31 – —
TIMELINE Apr 9 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0113 63.6 —
AFFECTED Product Versions Fixed Unraid 1161ec120 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0112 63.3 —
AFFECTED Product Versions Fixed Unraid 1161ec120 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0110 63.0 —
AFFECTED Product Versions Fixed gogs < 0.14.3 – —
TIMELINE Jun 8 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0101 60.1 —
AFFECTED Product Versions Fixed warp >= 0.2023.03.21.08.02.stable_00, < 0.2026.05.13.09.15.stable_01 – —
TIMELINE May 22 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R U H H H 8.0 .0095 58.3 —
AFFECTED Product Versions Fixed warp >= 0.2025.08.06.08.12.stable_00, < 0.2026.05.13.09.15.stable_01 – —
TIMELINE May 22 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0092 57.4 —
AFFECTED Product Versions Fixed gogs < 0.14.3 – —
TIMELINE Jun 8 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0083 54.6 —
AFFECTED Product Versions Fixed InsightConnect RPM Plugin unspecified 1.0.2
TIMELINE May 15 Reserved by CNA Jun 24 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0074 51.7 —
AFFECTED Product Versions Fixed rclone >= 1.46.0, < 1.74.3 – —
TIMELINE Jun 2 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0069 49.8 —
AFFECTED Product Versions Fixed NetVault Backup 14.0.0.19 – —
TIMELINE Apr 30 Reserved by CNA Jun 24 Published (CNA: zdi)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-9781 | 8.8 | 49.8 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulne… |
| CVE-2026-9782 | 8.8 | 49.8 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vul… |
| CVE-2026-9783 | 8.8 | 49.8 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution … |
| CVE-2026-9784 | 8.8 | 49.8 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vul… |
| CVE-2026-9785 | 8.8 | 49.8 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vul… |
| CVE-2026-9786 | 8.8 | 49.8 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulne… |
| CVE-2026-7569 | 8.8 | 49.0 | Quest | NetVault Backup | CWE-79 | Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass V… |
| CVE-2026-9780 | 8.8 | 49.0 | Quest | NetVault Backup | CWE-79 | Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass V… |
| CVE-2025-60474 | 7.5 | 47.4 | n/a | n/a | CWE-121 | A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c)… |
| CVE-2026-12485 | 10.0 | 47.2 | GeoVision Inc. | GV-I/O Box 4E | CWE-121 | GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET … |
| CVE-2026-54069 | 9.2 | 47.0 | siyuan-note | siyuan | CWE-346 | SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Orig… |
| CVE-2026-57296 | 8.8 | 45.6 | Jenkins Project | Jenkins External Workspace Manager Plugin | CWE-22 | Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject p… |
| CVE-2026-57281 | 7.5 | 45.6 | Jenkins Project | Jenkins Script Security Plugin | CWE-93 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject… |
| CVE-2026-25119 | 7.7 | 45.0 | gogs | gogs | CWE-290 | Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers |
| CVE-2026-12416 | 9.8 | 44.2 | pravel | Invoice Generator | CWE-640 | Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Passwo… |
| CVE-2025-60467 | 7.5 | 43.7 | n/a | n/a | CWE-416 | A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter… |
| CVE-2026-52986 | 9.8 | 43.5 | Linux | Linux | CWE-476 | netfilter: nf_conntrack_sip: don't use simple_strtoul |
| CVE-2026-2050 | 7.8 | 43.5 | GIMP | GIMP | CWE-122 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulner… |
| CVE-2026-56111 | 8.3 | 43.0 | MarlinFirmware | Marlin | CWE-129 | Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler |
| CVE-2026-52958 | 9.1 | 42.8 | Linux | Linux | CWE-125 | libceph: Fix potential out-of-bounds access in osdmap_decode() |
| CVE-2026-52982 | 9.8 | 42.7 | Linux | Linux | CWE-416 | net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() |
| CVE-2026-52981 | 7.5 | 42.5 | Linux | Linux | CWE-401 | neigh: let neigh_xmit take skb ownership |
| CVE-2026-55488 | 7.7 | 42.3 | motioneye-project | motioneye | CWE-22 | motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary F… |
| CVE-2026-53046 | 9.8 | 42.0 | Linux | Linux | CWE-416 | ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine |
| CVE-2026-52954 | 7.5 | 42.0 | Linux | Linux | CWE-617 | libceph: handle rbtree insertion error in decode_choose_args() |
| CVE-2026-52957 | 7.5 | 42.0 | Linux | Linux | CWE-476 | libceph: Fix potential null-ptr-deref in decode_choose_args() |
| CVE-2026-53045 | 9.8 | 41.4 | Linux | Linux | — | memory: tegra124-emc: Fix dll_change check |
| CVE-2026-52999 | 9.1 | 41.4 | Linux | Linux | CWE-125 | netfilter: nfnetlink_osf: fix out-of-bounds read on option matching |
| CVE-2026-53043 | 9.1 | 41.4 | Linux | Linux | CWE-787 | ocfs2/dlm: validate qr_numregions in dlm_match_regions() |
| CVE-2026-52914 | 9.8 | 41.3 | Linux | Linux | CWE-787 | batman-adv: fix fragment reassembly length accounting |
| CVE-2026-1840 | 8.7 | 41.2 | Hubbell | Aclara Metrum Cellular Web Interface | CWE-306 | Missing authentication for critical function in Hubbell Aclara Metrum Cellula… |
| CVE-2026-7761 | 8.8 | 41.0 | ultimatemember | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | CWE-862 | Ultimate Member <= 2.11.4 - Authenticated (Contributor+) Account Takeover via… |
| CVE-2026-8705 | 7.5 | 40.8 | clearsale | ClearSale Total | CWE-89 | ClearSale Total <= 3.4.2 - Unauthenticated SQL Injection |
| CVE-2026-39948 | 9.3 | 40.6 | Cacti | cacti | CWE-89 | Cacti has SQL Injection via rfilter parameter in RLIKE clauses |
| CVE-2026-52998 | 7.5 | 40.6 | Linux | Linux | CWE-476 | netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check |
| CVE-2026-53003 | 7.5 | 40.6 | Linux | Linux | — | pppoe: drop PFC frames |
| CVE-2026-52974 | 7.5 | 40.6 | Linux | Linux | CWE-401 | net: tls: fix strparser anchor skb leak on offload RX setup failure |
| CVE-2026-48731 | 7.8 | 40.3 | warpdotdev | warp | CWE-78 | Warp: Linux external editor command injection |
| CVE-2026-54297 | 7.5 | 39.8 | lostisland | faraday | CWE-674 | Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustio… |
| CVE-2026-56270 | 8.7 | 39.0 | Flowise | Flowise | CWE-306 | Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod En… |
| CVE-2026-52816 | 5.4 | 39.0 | gogs | gogs | CWE-80 | Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary dat… |
| CVE-2026-44017 | 7.5 | 38.8 | docling-project | docling | CWE-22 | Docling: Unsafe Zip Extraction in EasyOCR Model Download |
| CVE-2026-12242 | 8.8 | 38.6 | adegans | AdRotate Banner Manager | CWE-94 | AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Inj… |
| CVE-2026-52802 | 5.4 | 37.8 | gogs | gogs | CWE-601 | Gogs: Open Redirect via redirect_to in Gogs |
| CVE-2026-52811 | 9.0 | 37.7 | gogs | gogs | CWE-22 | Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym |
| CVE-2026-52946 | 7.5 | 37.7 | Linux | Linux | CWE-667 | fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling |
| CVE-2026-12417 | 9.8 | 37.7 | pravel | SignUp & SignIn | CWE-640 | SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Pass… |
| CVE-2026-45677 | 8.7 | 37.4 | RocketChat | Rocket.Chat | CWE-862 | Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS |
| CVE-2026-4297 | 8.8 | 37.3 | newscred | Welcome Software Publishing | CWE-862 | Welcome Software Publishing <= 0.0.31 - Authenticated (Subscriber+) Arbitrary… |
| CVE-2026-12846 | 10.0 | 37.1 | GeoVision Inc. | GV-I/O Box 4E | CWE-121 | GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET … |
| CVE-2026-12847 | 10.0 | 37.1 | GeoVision Inc. | GV-I/O Box 4E | CWE-121 | GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET … |
| CVE-2026-12848 | 10.0 | 37.1 | GeoVision Inc. | GV-I/O Box 4E | CWE-121 | GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET … |
| CVE-2026-52983 | 7.5 | 37.0 | Linux | Linux | — | net: airoha: fix BQL imbalance in TX path |
| CVE-2026-52797 | 8.5 | 36.8 | gogs | gogs | CWE-22 | Gogs: Overwriting critical files results in a denial of service |
| CVE-2026-50551 | 9.9 | 36.7 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content |
| CVE-2026-54699 | 7.7 | 36.3 | warpdotdev | warp | CWE-78 | Warp: OS command injection when opening terminal links from WSL |
| CVE-2026-52814 | 5.5 | 35.9 | gogs | gogs | CWE-400 | Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake St… |
| CVE-2026-53010 | 9.8 | 35.8 | Linux | Linux | CWE-416 | ksmbd: fix use-after-free in smb2_open during durable reconnect |
| CVE-2026-53055 | 9.8 | 35.8 | Linux | Linux | CWE-416 | crypto: hisilicon/sec2 - prevent req used-after-free for sec |
| CVE-2026-57301 | 8.8 | 35.7 | Jenkins Project | Jenkins OWASP ZAP Plugin | CWE-610 | Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the J… |
| CVE-2026-53026 | 7.5 | 35.5 | Linux | Linux | — | NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg |
| CVE-2026-56262 | 6.9 | 34.7 | Crawl4AI | Crawl4AI | CWE-306 | Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server |
| CVE-2026-52801 | 8.1 | 34.7 | gogs | gogs | CWE-20 | Gogs: Ability to import local repositories via Mirror Settings |
| CVE-2026-54904 | 8.2 | 34.4 | ruby-concurrency | concurrent-ruby | CWE-835 | concurrent-ruby: `AtomicReference#update` livelocks when the stored value is … |
| CVE-2026-13164 | 8.8 | 33.8 | Mailerup | Mailerup | CWE-306 | Unauthenticated self-registration in MailerUp allows access to stored email data |
| CVE-2026-23879 | 8.0 | 33.6 | miurahr | py7zr | CWE-59 | py7zr: Arbitrary File Write Vulnerability |
| CVE-2026-39893 | 9.8 | 33.1 | Cacti | cacti | CWE-89 | Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_vie… |
| CVE-2026-52931 | 9.8 | 33.1 | Linux | Linux | — | batman-adv: tp_meter: avoid use of uninit sender vars |
| CVE-2026-53088 | 9.8 | 33.1 | Linux | Linux | CWE-193 | net: bcmgenet: fix off-by-one in bcmgenet_put_txcb |
| CVE-2026-9779 | 7.2 | 32.9 | ATEN | Unizon | CWE-347 | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Sig… |
| CVE-2026-53006 | 9.8 | 32.7 | Linux | Linux | CWE-416 | ipv6: fix possible UAF in icmpv6_rcv() |
| CVE-2026-52967 | 8.1 | 32.4 | Linux | Linux | CWE-125 | smb/client: fix possible infinite loop and oob read in symlink_data() |
| CVE-2026-55454 | 9.9 | 32.3 | appsmithorg | appsmith | CWE-749 | Appsmith: Caddy admin API exposed without authentication |
| CVE-2026-52922 | 7.5 | 32.0 | Linux | Linux | CWE-476 | batman-adv: dat: handle forward allocation error |
| CVE-2026-52929 | 7.5 | 32.0 | Linux | Linux | CWE-476 | sctp: stream: fully roll back denied add-stream state |
| CVE-2026-53049 | 9.8 | 32.0 | Linux | Linux | CWE-667 | gfs2: add some missing log locking |
| CVE-2026-10735 | 7.5 | 31.9 | Unknown | smart-post-show-pro | — | ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Se… |
| CVE-2026-44016 | 8.2 | 31.6 | docling-project | docling | CWE-94 | Docling: Unsafe Playwright-based HTML Rendering |
| CVE-2026-10749 | 7.2 | 31.4 | Unknown | Post Duplicator | — | Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData |
| CVE-2026-52955 | 9.8 | 31.2 | Linux | Linux | CWE-125 | libceph: Fix potential out-of-bounds access in crush_decode() |
| CVE-2026-57280 | 8.8 | 31.1 | Jenkins Project | Jenkins Script Security Plugin | CWE-693 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not interc… |
| CVE-2026-53069 | 7.5 | 31.1 | Linux | Linux | CWE-476 | net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master |
| CVE-2026-52799 | 7.5 | 31.1 | gogs | gogs | CWE-639 | Gogs: Missing Authorization in Attachment Download |
| CVE-2026-9179 | 7.5 | 30.7 | hancock11 | WP Forms Connector | CWE-89 | WP Forms Connector <= 1.8 - Unauthenticated SQL Injection via 'order' Parameter |
| CVE-2026-53087 | 7.5 | 30.2 | Linux | Linux | CWE-401 | net: bcmgenet: fix leaking free_bds |
| CVE-2026-52993 | 9.8 | 29.9 | Linux | Linux | CWE-415 | tipc: fix double-free in tipc_buf_append() |
| CVE-2026-52807 | 4.8 | 29.9 | gogs | gogs | CWE-79 | Gogs: DOM-based XSS via Milestone Name on New Issue Page |
| CVE-2026-52804 | 5.5 | 29.1 | gogs | gogs | CWE-193 | Gogs: Privilege Escalation via Collaboration Access Mode Validation |
| CVE-2026-52956 | 7.5 | 29.0 | Linux | Linux | CWE-125 | libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() |
| CVE-2026-52960 | 7.5 | 29.0 | Linux | Linux | — | ceph: put folios not suitable for writeback |
| CVE-2026-48793 | 8.8 | 28.8 | jellyfin | jellyfin | CWE-88 | Jellyfin: Potential FFmpeg argument injection via unescaped subtitle file path |
| CVE-2026-53002 | 9.8 | 28.5 | Linux | Linux | CWE-787 | netfilter: conntrack: remove sprintf usage |
| CVE-2026-35025 | 8.6 | 27.9 | ProFTPD Project | ProFTPD | CWE-59 | ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR |
| CVE-2026-9175 | 5.3 | 27.8 | ajitdas | Devs Accounting – Simple Accounting and Invoicing Solution | CWE-862 | Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Sensitive… |
| CVE-2026-9178 | 7.5 | 27.7 | hancock11 | WP Forms Connector | CWE-862 | WP Forms Connector <= 1.8 - Missing Authorization to Unauthenticated Informat… |
| CVE-2026-39955 | 9.8 | 27.6 | Cacti | cacti | CWE-89 | Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REG… |
| CVE-2026-49851 | 8.7 | 27.6 | lepture | mistune | CWE-400 | Mistune: Potential DoS via quadratic-time parsing in parse_link_text |
| CVE-2026-53070 | 7.5 | 27.6 | Linux | Linux | — | sctp: disable BH before calling udp_tunnel_xmit_skb() |
| CVE-2025-71332 | 8.5 | 27.5 | Flowise | Flowise | CWE-89 | Flowise - SQL Injection in importChatflows API via chatflow.id Parameter |
| CVE-2026-13033 | 8.8 | 27.4 | Chrome | CWE-125 | Out of bounds read and write in Blink>InterestGroups in Google Chrome prior t… | |
| CVE-2026-13038 | 8.8 | 27.4 | Chrome | CWE-416 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.19… | |
| CVE-2026-49247 | 8.8 | 27.5 | jellyfin | jellyfin | CWE-22 | Jellyfin: Potential Authenticated path traversal in /ClientLog/Document |
| CVE-2025-64719 | 4.9 | 27.4 | gogs | gogs | CWE-20 | Gogs: Denial of Service in repository/wiki file listing web pages |
| CVE-2026-52989 | 9.8 | 27.3 | Linux | Linux | CWE-908 | nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers |
| CVE-2025-71361 | 7.6 | 26.8 | picklescan | picklescan | CWE-95 | picklescan - Remote Code Execution via Undetected idlelib.calltip.Calltip.fet… |
| CVE-2026-46348 | 8.7 | 26.7 | mastodon | mastodon | CWE-918 | Mastodon: SSRF Bypass via IPv6 Unspecified Address (::) |
| CVE-2026-52810 | 7.1 | 26.6 | gogs | gogs | CWE-284 | Gogs: Write to readonly repositories using receive-pack + service=git-upload-… |
| CVE-2026-52932 | 7.5 | 26.4 | Linux | Linux | — | xfrm: ipcomp: Free destination pages on acomp errors |
| CVE-2026-52808 | 7.1 | 26.4 | gogs | gogs | CWE-269 | Gogs: Write-level collaborators can mutate admin-only repository settings via… |
| CVE-2026-11998 | 7.6 | 26.2 | AngularJS | CWE-791 | AngularJS XSS via SCE resource URL sanitization bypass | |
| CVE-2026-52924 | 9.8 | 26.0 | Linux | Linux | CWE-416 | sctp: purge outqueue on stale COOKIE-ECHO handling |
| CVE-2026-44020 | 7.5 | 25.9 | docling-project | docling | CWE-776 | Docling: Unsafe XML Entity Expansion in USPTO Patent Backend |
| CVE-2026-13163 | 5.3 | 25.8 | Mailerup | Mailerup | CWE-601 | Lack of input validation in Mailerup input parameter leads to Open Redirect |
| CVE-2026-55570 | 9.0 | 25.5 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS results to Electron RCE in SiYuan marketplace via unescape… |
| CVE-2026-50189 | 8.9 | 25.4 | appsmithorg | appsmith | CWE-183 | Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor… |
| CVE-2026-55762 | 8.1 | 25.1 | RocketChat | Rocket.Chat | CWE-862 | Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from… |
| CVE-2026-47267 | 8.3 | 24.7 | gogs | gogs | CWE-918 | Gogs: SSRF in webhook deliveries |
| CVE-2026-50699 | 4.6 | 24.0 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule re… |
| CVE-2026-33235 | 7.7 | 23.7 | Significant-Gravitas | AutoGPT | CWE-400 | AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating f… |
| CVE-2026-52945 | 7.5 | 23.6 | Linux | Linux | — | Revert "wireguard: device: enable threaded NAPI" |
| CVE-2026-45689 | 9.1 | 23.4 | RocketChat | Rocket.Chat | CWE-943 | Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arb… |
| CVE-2026-9612 | 5.3 | 23.4 | yapacdev | WhatsOrder – Instant Checkout for WooCommerce | CWE-200 | WhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Pred… |
| CVE-2026-54067 | 9.9 | 23.3 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() |
| CVE-2026-47110 | 7.1 | 23.1 | ueberdosis | tiptap-php | CWE-241 | Tiptap for PHP < 2.1.1 DoS via Malformed href Attribute |
| CVE-2026-53086 | 9.8 | 23.0 | Linux | Linux | CWE-362 | net: bcmgenet: fix racing timeout handler |
| CVE-2026-52920 | 8.3 | 22.5 | Linux | Linux | — | netfilter: xt_policy: fix strict mode inbound policy matching |
| CVE-2026-9619 | 4.3 | 22.4 | berfect | Reviews and Rating – Docplanner | CWE-862 | Reviews and Rating <= 1.1.4 - Missing Authorization to Authenticated (Subscri… |
| CVE-2026-10092 | 7.2 | 22.3 | nicashmu | Cincopa video and media plug-in | CWE-79 | Cincopa video and media plug-in <= 1.163 - Unauthenticated Stored Cross-Site … |
| CVE-2026-52798 | 8.9 | 22.2 | gogs | gogs | CWE-79 | Gogs: Stored XSS in `.ipynb` Preview |
| CVE-2026-55666 | 9.3 | 22.1 | RocketChat | Rocket.Chat | CWE-287 | Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple … |
| CVE-2026-7617 | 5.3 | 22.1 | secufor | Secufor_OAuth | CWE-862 | Secufor_OAuth <= 1.0.7 - Missing Authorization to Unauthenticated Account Log… |
| CVE-2026-12094 | 5.3 | 22.1 | iamranit | Advanced Contact Form 7 – Compact DB | CWE-862 | Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated A… |
| CVE-2026-10043 | 7.8 | 21.9 | MosaicML | Composer | CWE-502 | MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vul… |
| CVE-2026-56237 | 9.3 | 21.8 | Capgo | Capgo | CWE-287 | Capgo - Unauthenticated API Key Generation via Client-Side Parameter Manipula… |
| CVE-2026-13036 | 8.8 | 21.9 | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a re… | |
| CVE-2026-13150 | 6.9 | 21.7 | Pentestify | Pentestify | CWE-918 | SSRF in Pentestify PDF generation endpoint via Host header |
| CVE-2026-12095 | 7.2 | 21.5 | bytuncay | Kargo Takip | CWE-918 | Kargo Takip <= 1.2 - Unauthenticated Server-Side Request Forgery via 'api_url… |
| CVE-2026-12100 | 7.2 | 21.5 | abhisheksaha11 | URL Preview | CWE-918 | URL Preview <= 1.0 - Unauthenticated Server-Side Request Forgery via 'url' Pa… |
| CVE-2026-54158 | 9.9 | 21.4 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() |
| CVE-2026-33543 | 9.3 | 21.4 | FOSSBilling | FOSSBilling | CWE-288 | FOSSBilling: Authentication bypass allows unauthenticated administrator creation |
| CVE-2026-45688 | 9.1 | 21.4 | RocketChat | Rocket.Chat | CWE-943 | Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitra… |
| CVE-2026-13028 | 9.6 | 21.2 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 a… | |
| CVE-2026-13032 | 9.6 | 21.2 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 a… | |
| CVE-2026-39899 | 6.9 | 20.8 | Cacti | cacti | CWE-22 | Cacti: Path Traversal via filename parameter in package_import.php |
| CVE-2026-56338 | 6.9 | 20.6 | Capgo | Capgo | CWE-703 | Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint |
| CVE-2026-31978 | 6.5 | 20.4 | motioneye-project | motioneye | CWE-22 | motionEye: Arbitrary File Read via Path Traversal in Picture/Movie Preview En… |
| CVE-2026-52805 | 8.7 | 20.4 | gogs | gogs | CWE-918 | Gogs: Migration Redirect Bypass Leads to Internal Repository Theft |
| CVE-2026-53943 | 9.6 | 20.2 | TryGhost | Ghost | CWE-524 | Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header |
| CVE-2026-54686 | 4.3 | 20.2 | warpdotdev | warp | CWE-78 | Warp: DCS lifecycle hook spoofing can alter terminal session metadata |
| CVE-2026-10745 | 7.9 | 20.1 | upKeeper Solutions | upKeeper Instant Privilege Access | CWE-117 | Improper output neutralization for logs vulnerability in upKeeper Solutions u… |
| CVE-2026-57284 | 4.3 | 19.9 | Jenkins Project | Jenkins Pipeline: Groovy Plugin | CWE-470 | Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restr… |
| CVE-2026-56245 | 8.8 | 19.2 | Cap-go | capgo | CWE-269 | Supabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning… |
| CVE-2026-50701 | 5.1 | 19.0 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb … |
| CVE-2026-52794 | 7.5 | 18.9 | getsentry | sentry | CWE-1333 | Sentry: Inefficient Regular Expression Complexity in sentry |
| CVE-2026-56232 | 8.7 | 18.8 | Capgo | Capgo | CWE-863 | Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header |
| CVE-2026-27708 | 7.1 | 18.5 | FOSSBilling | FOSSBilling | CWE-284 | FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access |
| CVE-2026-50129 | 7.5 | 18.2 | mastodon | mastodon | CWE-248 | Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSF… |
| CVE-2026-52918 | 8.8 | 18.1 | Linux | Linux | — | Bluetooth: serialize accept_q access |
| CVE-2026-54759 | 8.7 | 18.1 | siyuan-note | siyuan | CWE-79 | SiYuan: Lute HTML sanitizer allows `<iframe>` tags in Bazaar package README, … |
| CVE-2026-56337 | 6.9 | 18.0 | Capgo | Capgo | CWE-200 | Capgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2 |
| CVE-2026-53071 | 8.8 | 17.9 | Linux | Linux | CWE-667 | Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp |
| CVE-2026-56368 | 6.3 | 17.9 | ImageMagick | ImageMagick | CWE-401 | ImageMagick - Memory Leak in Raw Pixel Data Coders |
| CVE-2026-49246 | 1.7 | 17.6 | jellyfin | jellyfin | CWE-22 | Jellyfin: Potential MKV attachment filename path traversal to RCE |
| CVE-2026-10091 | 7.2 | 17.4 | cgarvey | Email JavaScript Cloak | CWE-79 | Email JavaScript Cloak <= 1.03 - Unauthenticated Stored Cross-Site Scripting |
| CVE-2026-50698 | 4.6 | 17.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering |
| CVE-2026-50700 | 4.6 | 17.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image rendering |
| CVE-2026-50704 | 4.6 | 17.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs r… |
| CVE-2026-50705 | 4.6 | 17.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering |
| CVE-2026-50710 | 4.6 | 17.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config |
| CVE-2026-50711 | 4.6 | 17.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering |
| CVE-2026-48704 | 8.8 | 17.3 | warpdotdev | warp | CWE-20 | Warp Markdown notebook links may open executable local files |
| CVE-2026-8690 | 5.3 | 17.3 | rentmy | RentMy Real-Time Rental Management Plugin | CWE-862 | RentMy Real-Time Rental Management Plugin <= 4.0.4.1 - Missing Authorization … |
| CVE-2026-49979 | 5.1 | 17.1 | appsmithorg | appsmith | CWE-918 | Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses W… |
| CVE-2025-71354 | 7.6 | 17.0 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText |
| CVE-2026-53075 | 8.8 | 16.7 | Linux | Linux | — | ppp: require CAP_NET_ADMIN in target netns for unattached ioctls |
| CVE-2026-11614 | 6.4 | 16.4 | xpro | Xpro Addons — 140+ Widgets for Elementor | CWE-79 | Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting vi… |
| CVE-2026-48720 | 8.8 | 16.2 | warpdotdev | warp | CWE-20 | Warp: SSH remote output can lead to local file overwrite and persistence |
| CVE-2026-56223 | 9.3 | 15.8 | Capgo | Capgo | CWE-287 | Capgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-user |
| CVE-2026-52934 | 8.8 | 15.9 | Linux | Linux | — | batman-adv: tvlv: reject oversized TVLV packets |
| CVE-2026-55759 | 7.4 | 15.7 | RocketChat | Rocket.Chat | CWE-287 | Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and … |
| CVE-2026-49278 | 6.7 | 15.7 | RocketChat | Rocket.Chat | CWE-285 | Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enabl… |
| CVE-2026-9643 | 7.2 | 15.5 | joomunited | WP Meta SEO | CWE-79 | WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUE… |
| CVE-2026-54068 | 5.9 | 15.2 | siyuan-note | siyuan | CWE-306 | SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /a… |
| CVE-2026-50703 | 4.8 | 15.2 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label rendering |
| CVE-2026-50708 | 4.8 | 15.2 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering |
| CVE-2026-50709 | 4.8 | 15.2 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering |
| CVE-2026-50712 | 4.8 | 15.2 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering |
| CVE-2026-52943 | 7.8 | 15.1 | Linux | Linux | CWE-416 | net: skbuff: fix missing zerocopy reference in pskb_carve helpers |
| CVE-2026-56256 | 7.1 | 15.0 | Capgo | Capgo | CWE-602 | Capgo - Two-Factor Authentication Bypass via Organization Management API |
| CVE-2026-55611 | 0.0 | 14.8 | Mintplex-Labs | anything-llm | CWE-639 | AnythingLLM: embed-parsed-file cleanup deletes any parsed file by ID without … |
| CVE-2026-11370 | 6.4 | 14.7 | joomunited | WP Meta SEO | CWE-918 | WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forg… |
| CVE-2026-13031 | 8.8 | 14.5 | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a re… | |
| CVE-2026-9616 | 4.3 | 14.4 | verenigingvanregistrars | Generate Security.txt | CWE-862 | Generate Security.txt <= 1.0.12 - Missing Authorization to Authenticated (Sub… |
| CVE-2026-47389 | 8.6 | 14.3 | mastodon | mastodon | CWE-184 | Mastodon: SSRF protection bypass on older Ruby versions |
| CVE-2026-8614 | 4.3 | 14.2 | assistioai | Assistio | CWE-862 | Assistio <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Plug… |
| CVE-2026-48789 | 4.3 | 14.2 | Mintplex-Labs | anything-llm | CWE-22 | AnythingLLM: Windows path containment bypass in document folder route |
| CVE-2026-8617 | 5.3 | 13.8 | ailchev | SearchPlus | CWE-862 | SearchPlus <= 1.7.1 - Missing Authorization to Unauthenticated Settings Modif… |
| CVE-2026-9172 | 5.3 | 13.7 | ajitdas | Devs Accounting – Simple Accounting and Invoicing Solution | CWE-862 | Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Account D… |
| CVE-2026-52796 | 3.5 | 13.5 | gogs | gogs | CWE-1336 | Gogs: DoS in rendering issue index pattern |
| CVE-2026-56052 | 7.6 | 13.3 | FunnelKit | Funnel Builder by FunnelKit | CWE-89 | WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.5 - SQL Injection vuln… |
| CVE-2026-57303 | 7.1 | 13.2 | Jenkins Project | Jenkins Assembla Plugin | CWE-918 | Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to … |
| CVE-2026-57288 | 3.7 | 13.3 | Jenkins Project | Jenkins Active Directory Plugin | CWE-90 | Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user n… |
| CVE-2026-12760 | 7.1 | 13.1 | TP-Link Systems Inc. | Tapo C200 v3 | CWE-770 | Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in … |
| CVE-2026-39951 | 8.8 | 12.9 | Cacti | cacti | CWE-89 | Cacti: Stored SQL Injection via graph_name_regexp in Reports feature |
| CVE-2026-55455 | 5.3 | 12.8 | appsmithorg | appsmith | CWE-918 | Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host… |
| CVE-2026-10642 | 4.6 | 12.7 | zephyrproject | zephyr | CWE-835 | Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flo… |
| CVE-2026-8688 | 4.3 | 12.8 | krishaweb | Advance Nav Menu Manager | CWE-862 | Advance Nav Menu Manager <= 1.3 - Missing Authorization to Authenticated (Sub… |
| CVE-2026-56351 | 5.3 | 12.4 | n8n | n8n | CWE-89 | n8n - SQL Injection in MySQL, PostgreSQL, and Microsoft SQL Nodes |
| CVE-2026-13035 | 8.8 | 12.3 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 a… | |
| CVE-2026-52812 | 7.1 | 12.3 | gogs | gogs | CWE-345 | Gogs: LFS dedupe path leaks private repo content across tenants |
| CVE-2026-57285 | 4.3 | 12.3 | Jenkins Project | Jenkins GitHub Branch Source Plugin | CWE-862 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v… |
| CVE-2026-57286 | 4.3 | 12.3 | Jenkins Project | Jenkins Git Parameter Plugin | CWE-862 | A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_… |
| CVE-2026-45757 | 2.3 | 12.1 | RocketChat | Rocket.Chat | CWE-613 | Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking exis… |
| CVE-2026-49277 | 2.3 | 12.1 | RocketChat | Rocket.Chat | CWE-613 | Rocket.Chat: OAuth access and refresh tokens remain valid after account deact… |
| CVE-2026-53949 | 5.3 | 12.0 | TryGhost | Ghost | CWE-200 | Ghost Content API filter bypass reveals private fields |
| CVE-2026-48725 | 8.1 | 11.9 | warpdotdev | warp | CWE-276 | Warp may allow terminal output to access the local clipboard through OSC 52 |
| CVE-2026-9709 | 7.7 | 11.8 | Unknown | Cornerstone | — | Themeco Cornerstone < 7.8.9 (Premium, bundled with X Theme) - Subscriber+ Arb… |
| CVE-2026-9710 | 7.7 | 11.8 | Unknown | Cornerstone | — | Themeco Cornerstone < 7.8.8 (Premium, bundled with X Theme) - Subscriber+ Arb… |
| CVE-2026-9184 | 4.3 | 11.4 | 24liveblog | 24liveblog – live blog tool | CWE-862 | 24liveblog <= 2.2 - Missing Authorization to Authenticated (Author+) Settings… |
| CVE-2026-56302 | 6.9 | 11.2 | Capgo | Capgo | CWE-284 | Capgo - Unsecured Supabase Images Bucket via Missing Row Level Security |
| CVE-2026-57282 | 5.0 | 11.1 | Jenkins Project | Jenkins Git client Plugin | CWE-78 | Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the wor… |
| CVE-2026-53947 | 5.3 | 11.0 | TryGhost | Ghost | CWE-204 | Ghost: Member existence leak via magic link sign-in response |
| CVE-2026-45687 | 8.5 | 10.9 | RocketChat | Rocket.Chat | CWE-915 | Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in… |
| CVE-2026-8628 | 6.1 | 10.8 | owencutajar | EntreDroppers | CWE-79 | EntreDroppers <= 1.1.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter |
| CVE-2026-53950 | 7.5 | 10.7 | TryGhost | Ghost | CWE-79 | @tryghost/activitypub: XSS in Ghost's ActivityPub client |
| CVE-2026-9183 | 4.3 | 10.7 | 24liveblog | 24liveblog – live blog tool | CWE-200 | 24liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Inform… |
| CVE-2025-60468 | 5.5 | 10.6 | n/a | n/a | CWE-122 | GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88… |
| CVE-2026-12488 | 6.2 | 10.5 | GeoVision Inc. | GeoVision | CWE-121 | GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability |
| CVE-2026-9620 | 6.4 | 10.4 | joomunited | WP Latest Posts | CWE-79 | WP Latest Posts <= 5.0.11 - Authenticated (Author+) Stored Cross-Site Scripti… |
| CVE-2026-13026 | 8.8 | 10.1 | Chrome | CWE-416 | Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.… | |
| CVE-2026-13027 | 8.8 | 10.1 | Chrome | CWE-416 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed… | |
| CVE-2026-53944 | 5.8 | 9.7 | TryGhost | Ghost | CWE-184 | Ghost: Private IP filtering bypass to make server-side requests to internal s… |
| CVE-2026-53072 | 8.8 | 9.5 | Linux | Linux | CWE-667 | Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER |
| CVE-2026-52800 | 8.8 | 9.4 | gogs | gogs | CWE-352 | Gogs: CSRF Leading to Organization Owner Takeover |
| CVE-2026-56244 | 7.1 | 9.4 | Capgo | Capgo | CWE-200 | Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key |
| CVE-2026-49220 | 5.7 | 9.4 | jellyfin | jellyfin | CWE-79 | Jellyfin: Potential XSS in user management |
| CVE-2026-12681 | 8.9 | 9.1 | go-attestation | CWE-1285 | Improper Validation of Specified Index, Position, or Offset in Input vulnerab… | |
| CVE-2026-55583 | 7.6 | 9.1 | twentyhq | twenty | CWE-639 | Twenty: Cross-workspace IDOR in AgentTurnResolver |
| CVE-2026-3652 | 7.2 | 9.0 | n/a | ARforms | CWE-79 | ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Pa… |
| CVE-2026-54070 | 7.1 | 9.0 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS in Bazaar marketplace via package README event handlers |
| CVE-2026-8865 | 6.4 | 8.7 | paradigmatools | Avalon23 Products Filter for WooCommerce | CWE-79 | Avalon23 Products Filter for WooCommerce <= 1.1.6 - Authenticated (Contributo… |
| CVE-2026-13023 | 5.3 | 8.5 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a r… | |
| CVE-2026-13030 | 5.3 | 8.5 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 … | |
| CVE-2026-13140 | 1.1 | 8.4 | Thinkst Applied Research | Canarytokens | CWE-79 | Stored Cross-Site Scripting in Canarytokens.org |
| CVE-2026-13025 | 8.3 | 8.3 | Chrome | CWE-20 | Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote at… | |
| CVE-2026-56257 | 7.1 | 8.1 | Capgo | Capgo | CWE-284 | Capgo - Authorization Bypass in App Ownership Transfer via Direct PostgREST U… |
| CVE-2025-60473 | 5.5 | 8.1 | n/a | n/a | CWE-476 | A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter… |
| CVE-2026-56310 | 5.3 | 8.1 | Cap-go | capgo | CWE-285 | Cap-go - Authorization Bypass in Organization Members Endpoint via API Key Sc… |
| CVE-2026-12986 | 7.3 | 8.0 | Payara | Payara Server | CWE-352 | A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.… |
| CVE-2026-8896 | 6.4 | 8.0 | mirsoftware | MIR blocks and shortcodes | CWE-79 | MIR blocks and shortcodes <= 1.0.0 - Authenticated (Contributor+) Stored Cros… |
| CVE-2026-11877 | 6.3 | 7.6 | OpenText | Access Manager | CWE-648 | Missing Authorization Vulnerability in OpenText Access Manager |
| CVE-2026-57300 | 4.3 | 7.6 | Jenkins Project | Jenkins MCP Server Plugin | CWE-862 | A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe … |
| CVE-2026-57302 | 4.3 | 7.6 | Jenkins Project | Jenkins FitNesse Plugin | CWE-256 | Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job … |
| CVE-2026-48703 | 7.8 | 7.5 | warpdotdev | warp | CWE-78 | Warp: Command Injection via Warp code search tool arguments |
| CVE-2025-60471 | 5.5 | 7.5 | n/a | n/a | CWE-416 | A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/fil… |
| CVE-2026-56231 | 7.2 | 7.4 | Capgo | Capgo | CWE-285 | Capgo - Broken Object Level Authorization in Build Job Control via jobId Para… |
| CVE-2026-6292 | 4.3 | 7.4 | manuelpadillac | MP Customize Login Page | CWE-352 | MP Customize Login Page <= 1.0 - Cross-Site Request Forgery to Settings Update |
| CVE-2026-56761 | 5.3 | 7.2 | hono | hono | CWE-79 | hono - HTML Injection via Improper JSX Attribute Name Handling in SSR |
| CVE-2026-57293 | 4.3 | 6.8 | Jenkins Project | Jenkins Gitee Plugin | CWE-862 | An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ a… |
| CVE-2026-8622 | 6.1 | 6.6 | pixelwelt | Image Sizes on Demand | CWE-79 | Image Sizes on Demand <= 1.3 - Reflected Cross-Site Scripting via PHP_SELF Se… |
| CVE-2026-52795 | 4.3 | 6.5 | gogs | gogs | CWE-863 | Gogs: Authorization Bypass in Watch API allows any user to monitor private re… |
| CVE-2026-39897 | 5.3 | 6.4 | Cacti | cacti | CWE-79 | Cacti has a Reflected XSS Vulnerability via html_auth_footer |
| CVE-2026-39900 | 5.3 | 6.4 | Cacti | cacti | CWE-79 | Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context |
| CVE-2026-57297 | 4.3 | 6.4 | Jenkins Project | Jenkins Contrast Continuous Application Security Plugin | CWE-862 | A missing permission check in Jenkins Contrast Continuous Application Securit… |
| CVE-2026-57299 | 4.3 | 6.4 | Jenkins Project | Jenkins Contrast Continuous Application Security Plugin | CWE-862 | Missing permission checks in Jenkins Contrast Continuous Application Security… |
| CVE-2026-44022 | 5.5 | 5.9 | docling-project | docling | CWE-22 | Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands |
| CVE-2026-10753 | 2.7 | 6.0 | Unknown | Site Kit by Google | — | Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update |
| CVE-2026-13029 | 7.5 | 5.8 | Chrome | CWE-416 | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197… | |
| CVE-2026-46349 | 5.3 | 5.9 | mastodon | mastodon | CWE-347 | Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring |
| CVE-2026-57294 | 5.4 | 5.8 | Jenkins Project | Jenkins EC2 Fleet Plugin | CWE-862 | A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81… |
| CVE-2026-57304 | 5.4 | 5.8 | Jenkins Project | Jenkins Assembla Plugin | CWE-862 | A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows … |
| CVE-2026-54906 | 2.1 | 5.7 | ruby-concurrency | concurrent-ruby | CWE-414 | concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray re… |
| CVE-2025-60466 | 5.0 | 5.6 | n/a | n/a | CWE-416 | A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filte… |
| CVE-2026-57283 | 4.3 | 5.4 | Jenkins Project | Jenkins Pipeline: Groovy Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy… |
| CVE-2026-12537 | 10.0 | 5.0 | Google Cloud | Gemini CLI | CWE-78 | Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows |
| CVE-2026-52969 | 7.8 | 4.9 | Linux | Linux | CWE-129 | KVM: Reject wrapped offset in kvm_reset_dirty_gfn() |
| CVE-2026-57290 | 4.3 | 4.9 | Jenkins Project | Jenkins Priority Sorter Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter … |
| CVE-2026-52809 | 6.8 | 4.8 | gogs | gogs | CWE-324 | Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_P… |
| CVE-2026-46423 | 9.3 | 4.7 | RocketChat | Rocket.Chat | CWE-347 | Rocket.Chat: SAML signature validation skipped when IdP certificate field is … |
| CVE-2026-13201 | 7.3 | 4.5 | Red Hat | Red Hat Container Native Virtualization 4.13 | CWE-61 | Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-ha… |
| CVE-2026-39894 | 2.5 | 4.4 | Cacti | cacti | CWE-474 | Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting |
| CVE-2026-10552 | 4.3 | 4.4 | jotis | Blue Captcha | CWE-352 | Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter |
| CVE-2026-13024 | 4.2 | 4.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Navigation in Google Chrome pri… | |
| CVE-2026-48721 | 8.6 | 4.2 | warpdotdev | warp | CWE-180 | Warp: Env-var prefixes can lead to denylisted command autoexecution |
| CVE-2026-57291 | 5.4 | 4.3 | Jenkins Project | Jenkins Gitee Plugin | CWE-862 | Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and e… |
| CVE-2026-9724 | 4.3 | 4.3 | motordesk | MotorDesk | CWE-352 | MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update |
| CVE-2026-52961 | 5.5 | 4.2 | Linux | Linux | CWE-617 | ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size |
| CVE-2026-52972 | 5.5 | 4.2 | Linux | Linux | CWE-190 | crypto: af_alg - Cap AEAD AD length to 0x80000000 |
| CVE-2026-56358 | 5.1 | 4.2 | n8n | n8n | CWE-79 | n8n - Stored Cross-Site Scripting in Form Trigger Node |
| CVE-2026-52976 | 7.8 | 4.1 | Linux | Linux | CWE-416 | drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() |
| CVE-2026-13034 | 4.7 | 4.1 | Chrome | CWE-346 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-13021 | 4.3 | 4.1 | Chrome | CWE-346 | Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrom… | |
| CVE-2026-52912 | 7.8 | 4.0 | Linux | Linux | CWE-416 | netfilter: nf_queue: hold bridge skb->dev while queued |
| CVE-2026-52973 | 7.8 | 4.0 | Linux | Linux | CWE-416 | futex: Drop CLONE_THREAD requirement for private default hash alloc |
| CVE-2026-53016 | 7.8 | 3.9 | Linux | Linux | CWE-787 | crypto: ccp - copy IV using skcipher ivsize |
| CVE-2026-53059 | 7.8 | 3.9 | Linux | Linux | CWE-787 | dm log: fix out-of-bounds write due to region_count overflow |
| CVE-2026-57307 | 4.2 | 3.8 | Jenkins Project | Jenkins Zowe zDevOps Plugin | CWE-862 | A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_4… |
| CVE-2026-53945 | 4.0 | 3.9 | TryGhost | Ghost | CWE-367 | Ghost: Server-side request forgery via DNS rebinding in external request hand… |
| CVE-2026-52950 | 7.8 | 3.7 | Linux | Linux | CWE-416 | drm/xe/dma-buf: fix UAF with retry loop |
| CVE-2026-52951 | 7.8 | 3.7 | Linux | Linux | CWE-416 | drm/xe/dma-buf: handle empty bo and UAF races |
| CVE-2026-52962 | 7.8 | 3.7 | Linux | Linux | CWE-787 | ceph: fix a buffer leak in __ceph_setxattr() |
| CVE-2026-52975 | 7.8 | 3.7 | Linux | Linux | — | bonding: 3ad: implement proper RCU rules for port->aggregator |
| CVE-2026-52992 | 7.8 | 3.7 | Linux | Linux | CWE-787 | fs/adfs: validate nzones in adfs_validate_bblk() |
| CVE-2026-53036 | 7.8 | 3.7 | Linux | Linux | CWE-193 | bpf, arm64: Fix off-by-one in check_imm signed range check |
| CVE-2026-52968 | 7.1 | 3.7 | Linux | Linux | CWE-125 | KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic |
| CVE-2026-52952 | 8.8 | 3.7 | Linux | Linux | CWE-617 | iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset |
| CVE-2026-13022 | 6.5 | 3.7 | Chrome | CWE-346 | Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827… | |
| CVE-2026-52987 | 7.8 | 3.6 | Linux | Linux | CWE-1341 | drm/amdgpu: avoid double drm_exec_fini() in userq validate |
| CVE-2026-52947 | 7.8 | 3.4 | Linux | Linux | CWE-416 | net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove |
| CVE-2026-53033 | 7.8 | 3.4 | Linux | Linux | CWE-416 | bpf, sockmap: Take state lock for af_unix iter |
| CVE-2026-8905 | 6.1 | 3.4 | osiris8 | Osiris Signature Banner | CWE-352 | Osiris Signature Banner <= 0.5 - Cross-Site Request Forgery to Stored Cross-S… |
| CVE-2026-52996 | 5.5 | 3.5 | Linux | Linux | CWE-401 | ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open |
| CVE-2026-53047 | 5.5 | 3.5 | Linux | Linux | — | efi/capsule-loader: fix incorrect sizeof in phys array reallocation |
| CVE-2026-52923 | 7.8 | 3.4 | Linux | Linux | CWE-401 | ipc: limit next_id allocation to the valid ID range |
| CVE-2026-53005 | 7.8 | 3.4 | Linux | Linux | CWE-416 | af_unix: Drop all SCM attributes for SOCKMAP. |
| CVE-2026-52966 | 5.5 | 3.3 | Linux | Linux | — | drm: Replace old pointer to new idr |
| CVE-2026-52971 | 7.8 | 3.3 | Linux | Linux | CWE-416 | net: ena: PHC: Fix potential use-after-free in get_timestamp |
| CVE-2026-52953 | 7.1 | 3.3 | Linux | Linux | CWE-125 | iommu/vt-d: Fix oops due to out of scope access |
| CVE-2026-53948 | 5.4 | 3.3 | TryGhost | Ghost | CWE-434 | Ghost: File Upload Content-Type Spoofing |
| CVE-2026-54639 | 8.8 | 3.2 | style-dictionary | style-dictionary | CWE-1321 | Style Dictionary - Prototype Pollution in convertTokenData utility function |
| CVE-2026-11878 | 8.2 | 3.2 | OpenText | Access Manager | CWE-79 | Reflected Cross-Site Scripting vulnerability in OpenText Access Manager |
| CVE-2026-53096 | 7.8 | 3.2 | Linux | Linux | CWE-476 | bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path |
| CVE-2026-53090 | 7.8 | 3.1 | Linux | Linux | CWE-253 | bpf: Fix ld_{abs,ind} failure path analysis in subprogs |
| CVE-2026-53092 | 7.8 | 3.1 | Linux | Linux | CWE-393 | bpf: Fix linked reg delta tracking when src_reg == dst_reg |
| CVE-2026-53012 | 5.5 | 3.1 | Linux | Linux | CWE-476 | nexthop: fix IPv6 route referencing IPv4 nexthop |
| CVE-2026-57287 | 4.3 | 3.1 | Jenkins Project | Jenkins Job Configuration History Plugin | CWE-312 | Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier doe… |
| CVE-2026-53053 | 8.8 | 2.9 | Linux | Linux | — | iommu/amd: Fix clone_alias() to use the original device's devid |
| CVE-2026-53091 | 8.4 | 2.9 | Linux | Linux | CWE-131 | net: pull headers in qdisc_pkt_len_segs_init() |
| CVE-2026-53000 | 7.8 | 3.0 | Linux | Linux | CWE-763 | netfilter: nat: use kfree_rcu to release ops |
| CVE-2026-53004 | 7.8 | 3.0 | Linux | Linux | CWE-787 | sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks |
| CVE-2026-53009 | 7.8 | 3.0 | Linux | Linux | CWE-415 | ice: fix double-free of tx_buf skb |
| CVE-2026-53024 | 7.8 | 3.0 | Linux | Linux | CWE-416 | greybus: raw: fix use-after-free if write is called after disconnect |
| CVE-2026-53025 | 7.8 | 3.0 | Linux | Linux | CWE-416 | greybus: raw: fix use-after-free on cdev close |
| CVE-2026-53031 | 7.8 | 2.9 | Linux | Linux | — | bpf: Validate node_id in arena_alloc_pages() |
| CVE-2026-53094 | 7.8 | 2.9 | Linux | Linux | — | bpf: Fix stale offload->prog pointer after constant blinding |
| CVE-2026-53130 | 7.8 | 3.0 | Linux | Linux | CWE-191 | fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START |
| CVE-2026-52948 | 5.5 | 3.0 | Linux | Linux | CWE-190 | i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl |
| CVE-2026-10531 | 5.4 | 3.0 | Unknown | AI Share & Summarize | — | AI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortc… |
| CVE-2026-50128 | 5.3 | 2.9 | mastodon | mastodon | CWE-354 | Mastodon: Spoofing of attribution domains |
| CVE-2026-52963 | 5.5 | 2.9 | Linux | Linux | — | ALSA: usb-audio: Bound MIDI endpoint descriptor scans |
| CVE-2026-52970 | 5.5 | 2.9 | Linux | Linux | — | netfilter: nft_ct: fix missing expect put in obj eval |
| CVE-2026-52984 | 5.5 | 2.9 | Linux | Linux | — | net/sched: netem: fix queue limit check to include reordered packets |
| CVE-2026-53034 | 5.5 | 2.9 | Linux | Linux | CWE-476 | bpf, sockmap: Fix af_unix null-ptr-deref in proto update |
| CVE-2026-53056 | 5.5 | 2.9 | Linux | Linux | — | drm/msm/dpu: fix mismatch between power and frequency |
| CVE-2026-53060 | 5.5 | 2.9 | Linux | Linux | CWE-401 | dm cache metadata: fix memory leak on metadata abort retry |
| CVE-2026-53063 | 5.5 | 2.9 | Linux | Linux | — | dm cache: fix write hang in passthrough mode |
| CVE-2026-57295 | 5.4 | 2.8 | Jenkins Project | Jenkins EC2 Fleet Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin… |
| CVE-2026-57305 | 5.4 | 2.8 | Jenkins Project | Jenkins Assembla Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin … |
| CVE-2026-11997 | 4.3 | 2.9 | seo_tools | Bulk SEO Image | CWE-352 | Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update |
| CVE-2026-53057 | 8.8 | 2.8 | Linux | Linux | — | iommu/riscv: Add IOTINVAL after updating DDT/PDT entries |
| CVE-2026-53109 | 7.8 | 2.8 | Linux | Linux | CWE-416 | powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy |
| CVE-2026-52964 | 5.5 | 2.8 | Linux | Linux | — | ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans |
| CVE-2026-52990 | 5.5 | 2.8 | Linux | Linux | — | fsnotify: fix inode reference leak in fsnotify_recalc_mask() |
| CVE-2026-53051 | 5.5 | 2.8 | Linux | Linux | — | PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on |
| CVE-2026-53011 | 7.8 | 2.7 | Linux | Linux | CWE-416 | net/sched: taprio: fix use-after-free in advance_sched() on schedule switch |
| CVE-2026-52915 | 7.1 | 2.7 | Linux | Linux | CWE-129 | netfilter: ip6t_hbh: reject oversized option lists |
| CVE-2026-52917 | 7.1 | 2.7 | Linux | Linux | CWE-125 | sctp: diag: reject stale associations in dump_one path |
| CVE-2026-53041 | 7.1 | 2.7 | Linux | Linux | CWE-787 | ocfs2: fix listxattr handling when the buffer is full |
| CVE-2026-52978 | 5.5 | 2.7 | Linux | Linux | — | net: psp: require admin permission for dev-set and key-rotate |
| CVE-2026-52994 | 5.5 | 2.7 | Linux | Linux | — | vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting |
| CVE-2026-52997 | 5.5 | 2.7 | Linux | Linux | CWE-476 | net/sched: sch_dualpi2: drain both C-queue and L-queue in dualpi2_change() |
| CVE-2026-53097 | 7.8 | 2.6 | Linux | Linux | CWE-416 | wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() |
| CVE-2026-53098 | 7.8 | 2.6 | Linux | Linux | CWE-416 | wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() |
| CVE-2026-52942 | 7.1 | 2.7 | Linux | Linux | CWE-125 | netfilter: nf_log: validate MAC header was set before dumping it |
| CVE-2026-53044 | 7.1 | 2.5 | Linux | Linux | CWE-125 | soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric lookup tables |
| CVE-2026-48028 | 6.5 | 2.5 | mastodon | mastodon | CWE-354 | Mastodon: Removal of integrity-protected JSON entries from signed activities |
| CVE-2026-11968 | 5.5 | 2.6 | TortoiseGit team | TortoiseGit | CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Inject… |
| CVE-2026-52913 | 5.5 | 2.4 | Linux | Linux | CWE-476 | batman-adv: v: stop OGMv2 on disabled interface |
| CVE-2026-52916 | 5.5 | 2.5 | Linux | Linux | — | batman-adv: frag: disallow unicast fragment in fragment |
| CVE-2026-52965 | 5.5 | 2.5 | Linux | Linux | CWE-835 | drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure |
| CVE-2026-52977 | 5.5 | 2.4 | Linux | Linux | — | futex: Prevent lockup in requeue-PI during signal/ timeout wakeup |
| CVE-2026-52985 | 5.5 | 2.4 | Linux | Linux | CWE-908 | netdevsim: zero initialize struct iphdr in dummy sk_buff |
| CVE-2026-52995 | 5.5 | 2.4 | Linux | Linux | — | net/rds: zero per-item info buffer before handing it to visitors |
| CVE-2026-53001 | 5.5 | 2.4 | Linux | Linux | — | netfilter: xtables: restrict several matches to inet family |
| CVE-2026-53021 | 5.5 | 2.5 | Linux | Linux | CWE-190 | scsi: target: core: Fix integer overflow in UNMAP bounds check |
Results continue: ranks 401–520.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-24 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.