boxscore/security
Thursday, June 25, 2026 · all times UTC← 2026-06-24 · archive · 2026-06-26 →

468 CVEs published June 25, 2026: 42 critical, 219 high, 172 medium, 35 low; 2 in KEV; 48 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 443 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published66431101511732563
KEV catalog size1670

490 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux466143211884546612730.27.8.0013+240
google70788185464300297460.78.1.0023+691
microsoft220710554741604378273.87.8.0044+56
red hat106170973817400.06.8.0026+97
apple156201637293711.35.5.0023+2
canonical2161465000.05.5.0010+2
freebsd070520000.07.8.0020-7
suse461410000.08.6.0029+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco10234480961147.87.0.0431+5
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
ubiquiti81174004327.39.9.0083+6
f56943107111.18.9.0221+4
ivanti49230033555.68.8.5187+2
checkpoint3915303111.17.5.0410+3
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache99131204555104010.86.5.0046+81
mozilla495511182601300.07.3.0026+43
gitlab243305215426.14.4.0022+24
docker470520100.08.2.0016+1
drupal0511305120.05.1.0026-3
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1321364507727532.25.5.0021+131
ibm32811935270700.07.5.0028+32
progress591710900.07.5.0036+1
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp131110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+8
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb660420000.07.2.0018+6
schneider electric660420100.07.8.0024+6
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+71
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+21
themerex585855300000.08.1.0043+58
edimax556033023100.07.4.0070-39
dell3755129240211.87.2.0015+25
jenkins project364909391000.04.8.0021+36
capgo4646222211000.07.0.0034+46

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
Most disclosures (vendor)
VendorCVEs
linux877
google859
oracle268
microsoft226
adobe132
red hat131
apache101
spring72
openclaw67
ibm61
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco11
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven39
Packagist22
PyPI10
npm4
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-48595Google0
CVE-2025-67038Lantronix0
CVE-2026-0257Palo Alto Networks0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171681
CVE-2021-27102Accellion2021-11-171681
CVE-2021-27101Accellion2021-11-171681
CVE-2021-27103Accellion2021-11-171681
CVE-2021-21017Adobe2021-11-171681
CVE-2021-28550Adobe2021-11-171681
CVE-2021-42013Apache2021-11-171681
CVE-2021-41773Apache2021-11-171681
CVE-2021-30858Apple2021-11-171681
CVE-2021-30860Apple2021-11-171681

Transactions

EXPLOIT PUBLISHEDCVE-2025-60464. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-60465. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71324 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71327 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71328 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71333 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71334 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71335 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71336 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-71338 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13351 (zephyrproject-rtos Zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-40080 (cacti). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-40082 (cacti). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-40083 (cacti). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-40084 (cacti). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47770 (jqlang jq). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48995 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49839 (jqlang jq). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50014 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50015 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50016 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50017 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50021 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50573 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54024 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54025 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54027 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54029 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54030 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54033 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54036 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54037 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54040 (danny-avila LibreChat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54917 (seaweedfs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55180 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55487 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55697 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55698 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55699 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55700 (pnpm). Public exploit reference added.

Yesterday's Results

468 CVEs published. 25 box scores and 375 table rows below; the remaining 68 continue on page 2 — every CVE is listed, nothing truncated.

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  H  N    8.6   .8321   99.7   YES
AFFECTED
  Product                               Versions  Fixed
  Cisco Unified Communications Manager  14 –      —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 25  Added to CISA KEV, due Jun 28
  Jun 25  Published (CNA: cisco)
CWE-918 · CNA: cisco · 3 references · NVD status: Analyzed · KEV due June 28, 2026
PTC Windchill PDMLink — Remote Code Execution (RCE) vulnerability in Windchill PDMlink
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .3020   98.1   YES
AFFECTED
  Product            Versions     Fixed
  Windchill PDMLink  unspecified  —
  FlexPLM            unspecified  —
TIMELINE
  Jun 18  Reserved by CNA
  Jun 25  Added to CISA KEV, due Jun 28
  Jun 25  Published (CNA: PTC)
CWE-20, CWE-502 · CNA: PTC · 2 references · NVD status: Analyzed · KEV due June 28, 2026
Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0390   89.4     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.0.6
TIMELINE
  Jun 20  Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-73 · CNA: VulnCheck · 4 references · NVD status: Analyzed
vanhauser-thc thc-hydra — Hydra - Stack Buffer Overflow in NTLM Authentication Handler
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    8.6   .0198   78.9     —
AFFECTED
  Product    Versions     Fixed
  thc-hydra  unspecified  9cc84c20e75f5fef6bb1790bb9ada2afad2204e2
TIMELINE
  Jun 22  Reserved by CNA
  Jun 25  Published (CNA: VulnCheck)
CWE-121 · CNA: VulnCheck · 2 references · NVD status: Deferred
Flowise - Unsandboxed Remote Code Execution via Custom MCP
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0156   73.2     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.0.6
TIMELINE
  Jun 20  Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Analyzed
Flowise - Arbitrary File Read via chatId Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0138   69.8     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.0.6
TIMELINE
  Jun 8   Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-73 · CNA: VulnCheck · 2 references · NVD status: Modified
Cursor Desktop sandbox escape via symlink and failed path canonicalization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0127   67.3     —
AFFECTED
  Product  Versions  Fixed
  cursor   < 3.0 –   —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 25  Published (CNA: GitHub_M)
CWE-59 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
Schneider Electric PowerLogic™ P7 — CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exis…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0119   65.3     —
AFFECTED
  Product         Versions                             Fixed
  PowerLogic™ P7  Version V02.003.001.000 and prior –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 25  Published (CNA: schneider)
CWE-78 · CNA: schneider · 1 reference · NVD status: Analyzed
YMC YMC Filter — WordPress Filter & Grids plugin <= 3.11.5 - SQL Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  L    9.3   .0105   61.4     —
AFFECTED
  Product     Versions  Fixed
  YMC Filter  n/a –     3.11.6
TIMELINE
  Jun 16  Reserved by CNA
  Jun 25  Published (CNA: Patchstack)
CWE-89 · CNA: Patchstack · 1 reference · NVD status: Deferred
Cursor Desktop sandbox escape via agent-controlled working directory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0096   58.5     —
AFFECTED
  Product  Versions  Fixed
  cursor   < 3.0 –   —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 25  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect Sed Plugin — OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0092   57.2     —
AFFECTED
  Product                    Versions     Fixed
  InsightConnect Sed Plugin  unspecified  2.0.5
TIMELINE
  May 21  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · 1 reference · NVD status: Analyzed
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0086   55.6     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-73 · CNA: VulnCheck · 2 references · NVD status: Analyzed
Rapid7 InsightConnect Tcpdump Plugin — OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0083   54.6     —
AFFECTED
  Product                        Versions     Fixed
  InsightConnect Tcpdump Plugin  unspecified  2.0.0
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect SQLmap Plugin — OS Command Injection in Rapid7 InsightConnect SQLmap Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0083   54.6     —
AFFECTED
  Product                       Versions     Fixed
  InsightConnect SQLmap Plugin  unspecified  2.0.1
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect Finger Plugin — OS Command Injection in Rapid7 InsightConnect Finger Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0083   54.6     —
AFFECTED
  Product                       Versions     Fixed
  InsightConnect Finger Plugin  unspecified  1.0.3
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · 1 reference · NVD status: Analyzed
Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0080   53.6     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-73 · CNA: VulnCheck · 2 references · NVD status: Analyzed
Linux Linux — IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    b8d26b3be8b33682cf163274ed07479a70554633 –  —
  Linux    3.10 –                                      5.10.259
TIMELINE
  Jun 9   Reserved by CNA
  Jun 25  Published (CNA: Linux)
CWE-191, CWE-839 · CNA: Linux · 11 references · NVD status: Analyzed
Rapid7 InsightConnect AWK Plugin — OS Command Injection in Rapid7 InsightConnect AWK Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.2     —
AFFECTED
  Product                    Versions     Fixed
  InsightConnect AWK Plugin  unspecified  1.2.2
TIMELINE
  May 14  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect Ping Plugin — OS Command Injection in Rapid7 InsightConnect Ping Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.2     —
AFFECTED
  Product                     Versions     Fixed
  InsightConnect Ping Plugin  unspecified  1.0.4
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect TR Plugin — OS Command Injection in Rapid7 InsightConnect Translate Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.2     —
AFFECTED
  Product                   Versions     Fixed
  InsightConnect TR Plugin  unspecified  2.0.3
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect Traceroute Plugin — OS Command Injection in Rapid7 InsightConnect Traceroute Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.2     —
AFFECTED
  Product                           Versions     Fixed
  InsightConnect Traceroute Plugin  unspecified  1.0.3
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · 1 reference · NVD status: Analyzed
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization o…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0065   48.0     —
AFFECTED
  Product                         Versions     Fixed
  Display and Peripheral Manager  unspecified  —
TIMELINE
  May 17  Reserved by CNA
  Jun 25  Published (CNA: dell)
CWE-78 · CNA: dell · 1 reference · NVD status: Analyzed
filebrowser filebrowser — File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0063   47.3     —
AFFECTED
  Product      Versions    Fixed
  filebrowser  < 2.63.6 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 25  Published (CNA: GitHub_M)
CWE-78, CWE-88, CWE-306 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Flowise - Authentication Bypass via Unprotected Registration Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0058   45.0     —
AFFECTED
  Product  Versions  Fixed
  Flowise  3.0.1 –   —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 2 references · NVD status: Analyzed
GitLab GitLab — Insertion of Sensitive Information into Log File in GitLab
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0058   45.1     —
AFFECTED
  Product  Versions  Fixed
  GitLab   19.1 –    —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 25  Published (CNA: GitLab)
CWE-532 · CNA: GitLab · 3 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-495067.244.9DellWyse Management SuiteCWE-22Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Imprope…
CVE-2026-66798.844.8wolfSSLwolfSSLCWE-787DTLS 1.3 ACK serialization heap buffer overflow via integer truncation
CVE-2026-452337.244.3danproshtmlyCWE-22HTMLy CMS 3.1.1 Path Traversal via oldfile Parameter in Autosave
CVE-2026-548239.944.0MarketingFireWidget OptionsCWE-94WordPress Widget Options plugin <= 4.2.3 - Remote Code Execution (RCE) vulner…
CVE-2026-439206.943.2FOSSBillingFOSSBillingCWE-306FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenanc…
CVE-2026-90834.941.7Red HatRed Hat build of Keycloak 26.4CWE-22Keycloak: keycloak: information disclosure through arbitrary filesystem path …
CVE-2026-532249.141.6LinuxLinuxCWE-125sctp: validate embedded INIT chunk and address list lengths in cookie
CVE-2026-532219.841.4LinuxLinuxip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
CVE-2026-532289.841.4LinuxLinuxipv6: sit: reload inner IPv6 header after GSO offloads
CVE-2026-531869.141.4LinuxLinuxRDMA/srp: bound SRP_RSP sense copy by the received length
CVE-2026-532259.141.4LinuxLinuxCWE-908sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
CVE-2026-532159.840.7LinuxLinuxnet: mvpp2: refill RX buffers before XDP or skb use
CVE-2026-532169.840.7LinuxLinuxnet: mvpp2: limit XDP frame size to the RX buffer
CVE-2026-531997.540.6LinuxLinuxhv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
CVE-2026-540926.539.6filebrowserfilebrowserCWE-400File Browser: DoS Vulnerability on Public Login API
CVE-2026-531837.539.3LinuxLinuxmptcp: allow subflow rcv wnd to shrink
CVE-2026-531847.539.3LinuxLinuxudp: clear skb->dev before running a sockmap verdict
CVE-2026-500168.838.9pnpmpnpmCWE-23pnpm: Transitive dependency alias path traversal allows project path override…
CVE-2026-540917.538.8filebrowserfilebrowserCWE-863File Browser: Incorrect access control in public directory shares via rule pa…
CVE-2026-540947.538.6filebrowserfilebrowserCWE-22File Browser: Symlink following lets scoped users read, overwrite, and share …
CVE-2026-532479.838.5LinuxLinuxCWE-416net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
CVE-2026-531519.837.9LinuxLinuxrxrpc: Fix the ACK parser to extract the SACK table for parsing
CVE-2026-411209.837.5DellWyse Management SuiteCWE-349Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Accepta…
CVE-2026-560547.737.5AhmadJS Help DeskCWE-22WordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerability
CVE-2026-386377.537.1n/an/aCWE-400An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f…
CVE-2026-386407.537.1n/an/aCWE-400A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc c…
CVE-2026-556678.236.9filebrowserfilebrowserCWE-22File Browser: Out-of-scope file deletion by a Create-only scoped user via sym…
CVE-2026-532469.836.8LinuxLinuxCWE-787sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
CVE-2026-532297.536.7LinuxLinuxCWE-401net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure
CVE-2026-532357.536.7LinuxLinuxnet: add pskb_may_pull() to skb_gro_receive_list()
CVE-2026-567869.336.5tomojitakasuRTKLIBCWE-787RTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 Message
CVE-2026-531988.836.2LinuxLinuxCWE-416ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
CVE-2026-564458.836.1pydicompynetdicom LibraryCWE-22pydicom pynetdicom Library Path Traversal
CVE-2026-540899.135.9filebrowserfilebrowserCWE-287File Browser: Authentication Bypass via Proxy Auth Header Forgery
CVE-2026-501768.735.7EVokeEVoke CSMSCWE-307EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Att…
CVE-2026-531319.435.5LinuxLinuxnetfilter: require Ethernet MAC header before using eth_hdr()
CVE-2026-560918.235.3Apache Software FoundationApache ShiroCWE-289Apache Shiro: Authentication bypass in Guice-Web integration
CVE-2026-90867.335.0Red HatRed Hat build of Keycloak 26.4CWE-79Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri valid…
CVE-2026-407029.334.6EVokeEVoke CSMSCWE-306EVoke Systems EVoke CSMS Missing Authentication for Critical Function
CVE-2026-556996.534.4pnpmpnpmCWE-22pnpm: reserved bin name deletes PNPM_HOME during global remove
CVE-2026-559588.334.4wolfSSLwolfSSLCWE-787Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
CVE-2026-540977.234.2filebrowserfilebrowserCWE-639File Browser: Cross-user unauthorized share-link deletion via unbounded prefi…
CVE-2025-713288.733.7FlowiseFlowiseCWE-620Flowise - Unverified Password Change via Account Settings
CVE-2026-128447.533.0DROLSKYList::SomeUtils::XSCWE-122List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow…
CVE-2026-374527.533.0n/an/aCWE-200Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120…
CVE-2026-374537.533.0n/an/aCWE-200Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120…
CVE-2026-4675210.032.7Apache Software FoundationApache KvrocksCWE-122Apache Kvrocks: Stack buffer overflow in Lua bit.tohex()
CVE-2026-532408.832.2LinuxLinuxCWE-416xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload
CVE-2026-400846.531.8CacticactiCWE-22Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter
CVE-2026-423875.931.7PowerDNSRecursorCWE-20Insufficient input validation in ZoneToCache
CVE-2026-423885.931.7PowerDNSRecursorCWE-20Missing input validation for catalog zones
CVE-2026-549177.831.6seaweedfsseaweedfsCWE-22SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bu…
CVE-2026-532178.631.6LinuxLinuxnet: mvpp2: sync RX data at the hardware packet offset
CVE-2026-567688.731.2haiwenseahubCWE-862Seahub < 13.0.23 - Authentication Bypass in ShareLinkZipTaskView GET Method
CVE-2026-560538.831.1EventPrimeEventPrimeCWE-502WordPress EventPrime plugin <= 4.3.4.1 - PHP Object Injection vulnerability
CVE-2026-561228.730.8rickknowlesWinstone Servlet ContainerCWE-22Winstone Servlet Engine 0.9.10 Path Traversal via HTTP Request Paths
CVE-2026-500176.930.7pnpmpnpmCWE-200pnpm binds unscoped user-level npm auth credentials to a repository-selected …
CVE-2026-53058.830.3UnknownEmail Address EncoderEmail Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Sto…
CVE-2026-532609.829.9LinuxLinuxCWE-416tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
CVE-2026-574351.729.8sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogi…
CVE-2026-500157.329.6pnpmpnpmCWE-22pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
CVE-2026-5770010.029.3Daan.devOMGF ProCWE-434WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability
CVE-2026-133118.729.1ljharbshell-quoteCWE-407shell-quote parse() is quadratic in token count, enabling denial of service
CVE-2026-98008.128.8Red HatRed Hat build of Keycloak 26.4CWE-1025Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via …
CVE-2026-574341.728.9sparklemotionnokogiriCWE-476Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper c…
CVE-2026-107126.128.7GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-532488.828.4LinuxLinuxCWE-416net: airoha: Fix use-after-free in metadata dst teardown
CVE-2026-575207.128.4bitwardenserverCWE-862Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint
CVE-2026-575872.928.3tenableNessusCWE-89SQL Injection in Nessus via Reverse DNS Lookup
CVE-2026-557007.128.3pnpmpnpmCWE-22pnpm: stage download writes outside destination via manifest version traversal
CVE-2026-542266.427.9Apache Software FoundationApache KvrocksCWE-190Apache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoS
CVE-2026-75312.327.7wolfSSLwolfSSLCWE-416Use-after-free in PQC hybrid key-share handling
CVE-2026-575881.827.6tenableNessusCWE-89SQL Injection in Nessus via Malicious Scan Result File Import
CVE-2026-540376.527.5danny-avilaLibreChatCWE-770LibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rat…
CVE-2026-132255.327.5pretixpretixCWE-80Stored XSS in ticket confirmation page
CVE-2026-532688.227.4LinuxLinuxCWE-125netfilter: conntrack_irc: fix possible out-of-bounds read
CVE-2026-531657.527.4LinuxLinuxCWE-476iomap: avoid potential null folio->mapping deref during error reporting
CVE-2026-532447.527.4LinuxLinuxVFS: fix possible failure to unlock in nfsd4_create_file()
CVE-2026-420054.327.4PowerDNSAuthoritativeCWE-400Insufficient input validation of internal web server
CVE-2026-554777.227.2MHSanaei3x-uiCWE-73Authenticated Arbitrary File Write via Database Import and Xray Log Path Mani…
CVE-2026-572356.327.1sparklemotionnokogiriCWE-125Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVE-2026-572361.727.1sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` ra…
CVE-2026-560498.527.0Post SnippetsPost SnippetsCWE-94WordPress Post Snippets plugin <= 4.0.19 - Remote Code Execution (RCE) vulner…
CVE-2026-531807.527.0LinuxLinuxCWE-667timers/migration: Fix livelock in tmigr_handle_remote_up()
CVE-2026-567708.726.9schwehrlibaisCWE-129libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid S…
CVE-2026-526905.926.9PowerDNSRecursorCWE-290Spoofed answers can mark an authoritative non-EDNS capable
CVE-2026-100865.426.8GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-554395.526.6halo-devhaloCWE-22Halo: Path Traversal in Backup Download Leads to Arbitrary File Read
CVE-2026-466017.526.4golang.org/x/imagegolang.org/x/image/webpPanic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image
CVE-2026-466027.526.4golang.org/x/imagegolang.org/x/image/tiffLack of limit on tile sizes in x/image/tiff in golang.org/x/image
CVE-2026-567876.926.5tomojitakasuRTKLIBCWE-193RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Mes…
CVE-2026-400837.226.2CacticactiCWE-89Cacti: SQL Injection in managers.php
CVE-2026-575328.825.8pretixpretixCWE-80Malicious HTML content contained in the layout specification of a PDF ticket …
CVE-2026-567678.725.9getmaxunmaxunCWE-862Maxun < 0.0.42 - Cross-Tenant IDOR in Storage and Webhook API Handlers
CVE-2026-575342.125.8pretixpretix-pagesCWE-80Stored XSS in pretix-pages
CVE-2026-133142.025.8pretixpretix-digitalCWE-80Stored XSS in pretix-digital
CVE-2026-551806.525.5pnpmpnpmCWE-200pnpm: Repository config can expand victim environment secrets into registry r…
CVE-2026-122448.725.4NLnet LabsNSDCWE-122Heap overflow and crash with crafted SVCB RR
CVE-2026-133517.525.2zephyrproject-rtosZephyrCWE-772net: Maliciously fragmented IPv6 packets can prevent receiving/processing fut…
CVE-2026-467515.525.2Apache Software FoundationApache KvrocksApache Kvrocks: Does not remove the unsafe loadstring function from its Lua s…
CVE-2026-540908.725.1filebrowserfilebrowserCWE-77File Browser: Command Allowlist Bypass via Shell Metacharacter Injection
CVE-2025-713358.624.8FlowiseFlowiseCWE-613Flowise - Session Invalidation Failure After Password Change
CVE-2026-228798.124.8vtkvtkCWE-129vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnera…
CVE-2026-574361.724.9sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid…
CVE-2026-574371.724.9sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathCo…
CVE-2026-122458.724.7NLnet LabsNSDCWE-416Denial of DNS over TLS service by any DoT client
CVE-2026-400125.324.6PowerDNSRecursorCWE-524Information about ECS zero scoped answers might leak to clients that use a sp…
CVE-2026-531759.824.0LinuxLinuxCWE-416inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
CVE-2026-561239.223.4socatsocatCWE-122socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser
CVE-2026-91536.523.5Rapid7InsightConnect Sed PluginCWE-22Arbitrary File Read in Rapid7 InsightConnect Sed Plugin
CVE-2026-64325.323.5Silicon LabsSiSDKCWE-130Improper bounds validation in EmberZNet SDK
CVE-2026-575352.123.4pretixpretixCWE-80Content injected to PDF rendering contexts could, in many places, include HTM…
CVE-2026-129377.523.0themeficTourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress PluginCWE-89Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter
CVE-2025-713407.622.6picklescanpicklescanCWE-502picklescan - Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.ru…
CVE-2026-122467.222.5NLnet LabsNSDCWE-20Out of bounds stack write with crafted APL RR
CVE-2026-574296.522.5eLightUpSlim SEOCWE-862WordPress Slim SEO plugin <= 4.6.2 - Broken Access Control vulnerability
CVE-2026-540246.522.4danny-avilaLibreChatCWE-770LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Ins…
CVE-2026-402115.322.2PowerDNSDNSdistCWE-770Denial of service via crafted DoH3 queries
CVE-2026-489446.522.1getk2.orgK2 extension for JoomlaCWE-22Joomla Extension - getk2.org - Exposure of sensitive files via attachment cop…
CVE-2026-60946.322.0wolfSSLwolfSSLCWE-125Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 En…
CVE-2026-548417.521.9AppsbdViteposCWE-201WordPress Vitepos plugin <= 3.4.2 - Sensitive Data Exposure vulnerability
CVE-2026-415669.421.9Apache Software FoundationApache KvrocksCWE-280Apache Kvrocks: Improper permission for the APPLYBATCH command
CVE-2026-550927.021.7aquasecuritytrivyCWE-22Trivy: Path traversal via a crafted vulnerability database or other downloade…
CVE-2026-402095.321.5PowerDNSDNSdistCWE-772Denial of service via IXFR queries
CVE-2026-90997.721.4Red HatRed Hat build of Keycloak 26.4CWE-639Keycloak: group-admin escalation to realm-admin
CVE-2026-545735.321.0outlineoutlineCWE-863Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy
CVE-2026-544796.920.5EVokeEVoke CSMSCWE-613EVoke Systems EVoke CSMS Insufficient Session Expiration
CVE-2026-91546.519.9Rapid7InsightConnect Sed PluginCWE-22Arbitrary File Write in Rapid7 InsightConnect Sed Plugin
CVE-2026-22385.319.9GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-548458.119.8PluginUs.NetMDTFCWE-98WordPress MDTF plugin <= 1.3.8 - Local File Inclusion vulnerability
CVE-2026-120777.519.7wedevsDokan ProCWE-89Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longit…
CVE-2026-273667.519.6MainWPMainWP ChildCWE-862WordPress MainWP Child plugin <= 6.1.1 - Broken Access Control vulnerability
CVE-2026-446226.919.6EVokeEVoke CSMSCWE-522EVoke Systems EVoke CSMS Insufficiently Protected Credentials
CVE-2026-548228.519.2SALESmanagoSALESmanago & LeadooCWE-89WordPress SALESmanago & Leadoo plugin <= 3.11.2 - SQL Injection vulnerability
CVE-2026-548388.519.2Rymera Web CoWC Vendors MarketplaceCWE-89WordPress WC Vendors Marketplace plugin <= 2.6.8 - SQL Injection vulnerability
CVE-2026-531478.119.0LinuxLinuxCWE-125thunderbolt: Validate XDomain request packet size before type cast
CVE-2026-532548.119.0LinuxLinuxCWE-125Bluetooth: RFCOMM: validate skb length in MCC handlers
CVE-2026-97056.518.9Red HatRed Hat build of Keycloak 26.4CWE-613Keycloak: keycloak: attacker can re-enable and take over disabled clients via…
CVE-2026-567745.318.5kanboardkanboardCWE-639Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated S…
CVE-2026-556988.818.5pnpmpnpmCWE-345pnpm: Project env lockfile can short-circuit package-manager resolution and e…
CVE-2026-544486.918.4aquasecuritytrivyCWE-770Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
CVE-2026-548217.418.3Bootstrapped VenturesVisual Link PreviewCWE-201WordPress Visual Link Preview plugin <= 2.3.1 - Sensitive Data Exposure vulne…
CVE-2026-97168.718.2Schneider ElectricPowerLogic™ P7CWE-476CWE-476 NULL Pointer Dereference vulnerability exists that could cause a deni…
CVE-2026-500147.318.2pnpmpnpmCWE-88pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
CVE-2026-105122.318.2wolfSSLwolfSSLCWE-682X25519 x86_64 assembly final reduction leaves non-canonical field element
CVE-2026-374547.518.1n/an/aCWE-200Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120…
CVE-2026-576196.518.1ElementorElementor Website BuilderCWE-862WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure…
CVE-2026-531966.818.0LinuxLinuxCWE-787USB: serial: io_ti: fix heap overflow in get_manuf_info()
CVE-2026-402104.818.0PowerDNSDNSdistCWE-126Out-of-bounds read in SetMacAddrAction
CVE-2026-575222.318.0bitwardenserverCWE-74Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates
CVE-2026-532537.117.7LinuxLinuxCWE-125Bluetooth: bnep: reject short frames before parsing
CVE-2026-560057.117.5MelapressWP Activity LogCWE-79WordPress WP Activity Log plugin <= 5.6.3.1 - Cross Site Scripting (XSS) vuln…
CVE-2026-132226.317.5pretixpretix-oppwaCWE-841Insufficient validation of payment status in pretix-oppwa
CVE-2026-132236.317.5pretixpretix-computopCWE-841Insufficient validation of payment status in pretix-computop
CVE-2026-575366.317.5pretixpretix-mollieCWE-841Insufficient validation of payment status in pretix-mollie
CVE-2026-66811.017.4wolfSSLwolfSSLCWE-120PKCS#7 decode ignores caller output buffer size, writing past buffer bounds
CVE-2026-554139.417.3ToolJetToolJetCWE-94ToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Exec…
CVE-2026-108336.417.4wpdevteamGutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= …
CVE-2026-532328.817.1LinuxLinuxnet: phy: clean the sfp upstream if phy probing fails
CVE-2026-575215.317.0bitwardenserverCWE-862Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController
CVE-2026-540368.116.6danny-avilaLibreChatCWE-306LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Ver…
CVE-2026-45267.116.5Silicon LabsEmberZNetCWE-125Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2
CVE-2026-471457.116.5Silicon LabsEmberZNetCWE-617Color Control hue/saturation assertion abort in EmberZNet v9.0.2
CVE-2026-471467.116.5Silicon LabsEmberZNetCWE-617Color Control color-temperature assertion abort in EmberZNet v9.0.2
CVE-2026-471487.116.5Silicon LabsEmberZNetCWE-125Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2
CVE-2026-471497.116.5Silicon LabsEmberZNetCWE-125Door Lock GetUserType invalid table index in EmberZNet v9.0.2
CVE-2026-471527.116.5Silicon LabsEmberZNetCWE-369Level Control Move divide-by-zero in EmberZNet v9.0.2
CVE-2026-471537.116.5Silicon LabsEmberZNetCWE-369Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2
CVE-2026-471547.116.5Silicon LabsEmberZNetCWE-125Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2
CVE-2026-567897.116.5tomojitakasuRTKLIBCWE-122RTKLIB 2.4.3 - Heap Buffer Overflow and Stack Read via Oversized RINEX Epoch …
CVE-2026-532568.016.4LinuxLinuxCWE-416Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
CVE-2026-575332.116.4pretixpretixCWE-80Malicious HTML content could be injected into the page pretix shows when redi…
CVE-2026-540336.516.1danny-avilaLibreChatCWE-918LibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP val…
CVE-2026-97186.915.8Schneider ElectricPowerLogic™ P7CWE-617CWE-617 Reachable Assertion vulnerability exists that could allow an authenti…
CVE-2026-129936.515.8Red HatRed Hat build of Apicurio Registry 3CWE-776Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of…
CVE-2026-92229.215.6Shenzhen i365-Tech Co. Ltd.Setracker2 Parental Control App (Android) package com.tgelec.setrackerCWE-836Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of pa…
CVE-2026-531467.115.6LinuxLinuxthunderbolt: Limit XDomain response copy to actual frame size
CVE-2026-96508.715.3Schneider ElectricEasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & ControllerCWE-522CWE-522 Insufficiently Protected Credentials vulnerability that could cause u…
CVE-2026-493196.915.3Alps Electric Co., Ltd.Remote Keyless Entry System (RKES) R53R0CWE-294Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack
CVE-2026-548287.515.1StylemixThemesMotorsCWE-862WordPress Motors plugin <= 1.4.109 - Broken Access Control vulnerability
CVE-2026-548307.515.1Etoile Web Design IncorporatedFive Star Restaurant ReservationsCWE-862WordPress Five Star Restaurant Reservations plugin <= 2.7.19 - Broken Access …
CVE-2026-548447.515.1CheckViewCheckView Automated TestingCWE-862WordPress CheckView Automated Testing plugin <= 2.1.0 - Broken Access Control…
CVE-2026-560136.514.7myCredLicense Manager for WooCommerceCWE-639WordPress License Manager for WooCommerce plugin <= 3.0.15 - Insecure Direct …
CVE-2026-25086.514.5GravityMoreGravity BookingsCWE-89Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL I…
CVE-2026-129758.514.5Red HatRed Hat build of Apicurio Registry 3CWE-611Apicurio/apicurio-registry: apicurio-registry: unhardened saxparser in conten…
CVE-2026-532758.814.3LinuxLinuxCWE-416ipv6: mcast: Fix use-after-free when processing MLD queries
CVE-2026-92208.714.3Shenzhen i365-Tech Co. Ltd.Setracker2 Parental Control App (Android) package com.tgelec.setrackerCWE-321Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key
CVE-2026-124738.314.3Open Health Imaging Foundation (OHIF)DICOM Web Viewer FrameworkCWE-918OHIF Viewers DICOM Server-Side request forgery
CVE-2026-466087.414.3nicolargoglancesCWE-183Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildc…
CVE-2026-471477.114.1Silicon LabsEmberZNetCWE-125OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2
CVE-2026-560147.114.1AvertaMaster SliderCWE-79WordPress Master Slider plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnera…
CVE-2026-560427.114.1AlgolplusAdvanced Order Export For WooCommerceCWE-79WordPress Advanced Order Export For WooCommerce plugin <= 4.0.9 - Cross Site …
CVE-2026-560517.114.1TablePressTablePressCWE-79WordPress TablePress plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) v…
CVE-2026-560717.114.1WPMU DEVForminatorCWE-79WordPress Forminator plugin <= 1.53.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-548439.314.0PluginUs.NetMDTFCWE-89WordPress MDTF plugin <= 1.3.7 - SQL Injection vulnerability
CVE-2026-548499.314.0PremmercePremmerce Wishlist for WooCommerceCWE-89WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.11 - SQL Injection…
CVE-2026-132837.513.9GoogleChromeCWE-416Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.20…
CVE-2026-400825.413.9CacticactiCWE-384Cacti: Session Fixation via missing session_regenerate_id() after login
CVE-2026-123406.313.6wolfSSLwolfSSLCWE-125Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computa…
CVE-2026-561302.013.3Apache Software FoundationApache ShiroCWE-294Apache Shiro: Remember-me cookie isn't checked for expiry on the server
CVE-2026-16064.313.2GitLabGitLabCWE-94Improper Control of Generation of Code ('Code Injection') in GitLab
CVE-2026-113108.712.7wolfSSLwolfSSLCWE-295X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermed…
CVE-2026-119998.212.7wolfSSLwolfSSLCWE-295X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
CVE-2026-559608.212.7wolfSSLwolfSSLCWE-295Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing…
CVE-2026-471507.112.4Silicon LabsEmberZNetCWE-787IAS Zone enroll invalid table index and write in EmberZNet 9.0.2
CVE-2026-471517.112.4Silicon LabsEmberZNetCWE-787Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2
CVE-2026-120796.512.4wedevsDokan ProCWE-89Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' …
CVE-2026-540276.512.3danny-avilaLibreChatCWE-862LibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fi…
CVE-2026-567696.312.3hcengineeringplatformCWE-918Huly Platform - Server-Side Request Forgery via /import Endpoint
CVE-2026-86624.312.3Rapid7InsightConnect Compression PluginCWE-22Path Traversal in Rapid7 InsightConnect Compression Plugin
CVE-2026-127552.712.2DevolutionsServerCWE-1284Improper input validation in the PAM AD discovery endpoints in Devolutions Se…
CVE-2026-371497.712.2n/an/aCWE-89GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was disco…
CVE-2026-567907.012.2canboatcanboatCWE-193CANBoat - Off-by-One Global Buffer Overflow in searchForPgn()
CVE-2026-117036.011.6wolfSSLwolfSSLCWE-287Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
CVE-2026-60922.111.3wolfSSLwolfSSLCWE-757Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_M…
CVE-2026-97027.511.2UnknownInPost PLInPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking
CVE-2026-531788.110.8LinuxLinuxCWE-191staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction
CVE-2026-532647.810.8LinuxLinuxCWE-416net/sched: act_api: use RCU with deferred freeing for action lifecycle
CVE-2026-423905.310.8PowerDNSRecursorCWE-20ZONEMD validation can be bypassed
CVE-2026-402083.710.8PowerDNSDNSdistCWE-705Denial of service via DoH3 queries
CVE-2026-567716.310.6samuelclayNewsBlurCWE-918NewsBlur < 14.5.0 - Server-Side Request Forgery via add_url Endpoint
CVE-2026-567725.310.7samuelclayNewsBlurCWE-639NewsBlur < 14.5.0 - Insecure Direct Object Reference in Social Interactions E…
CVE-2026-92198.310.6Shenzhen i365-Tech Co. Ltd.Setracker2 Parental Control App (Android) package com.tgelec.setrackerCWE-340Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers …
CVE-2026-560235.410.6Knit PayUPI QR Code Payment Gateway for WooCommerceCWE-862WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.6.2 - Broke…
CVE-2026-09343.810.3GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-489455.39.8getk2.orgK2 extension for JoomlaCWE-434Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension f…
CVE-2026-59524.39.6GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-548428.19.5Royal PluginsRoyal MCPCWE-862WordPress Royal MCP plugin <= 1.4.25 - Broken Access Control vulnerability
CVE-2026-548297.59.5Jacob N. BreetveltWP Photo Album PlusCWE-89WordPress WP Photo Album Plus plugin <= 9.1.13.005 - SQL Injection vulnerability
CVE-2026-554128.39.3ToolJetToolJetCWE-918ToolJet Cloud - SSRF to Azure Cloud Infrastructure Compromise
CVE-2026-540936.89.3filebrowserfilebrowserCWE-22File Browser: Path traversal in download-as-zip/tar via Windows-style backsla…
CVE-2026-57964.39.3GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-400806.19.2CacticactiCWE-601Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect
CVE-2026-288985.39.2Appleswift-nio-http2CWE-116swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header val…
CVE-2026-560506.59.0ThemeislePPOM for WooCommerceCWE-284WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vuln…
CVE-2026-66781.09.0wolfSSLwolfSSLCWE-191Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info
CVE-2026-113795.38.7GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-129927.48.6Red HatRed Hat build of Apicurio Registry 3CWE-918Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import derefer…
CVE-2025-604647.88.5n/an/aCWE-416A use-after-free in the gf_sei_load_from_state_internal function (/filters/se…
CVE-2026-548488.38.1Saad IqbalAPIExperts Square for WooCommerceCWE-201WordPress APIExperts Square for WooCommerce plugin <= 4.7.3 - Sensitive Data …
CVE-2026-489436.58.0getk2.orgK2 extension for JoomlaCWE-915Joomla Extension - getk2.org - Authenticated user property mass-assignment in…
CVE-2026-540296.58.1danny-avilaLibreChatCWE-862LibreChat: IDOR in Message Deletion — Incomplete Fix for CVE-2024-41703 Leave…
CVE-2026-31763.18.1GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-118008.17.9Red HatRed Hat build of Keycloak 26.6CWE-347Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algor…
CVE-2026-64501.07.8wolfSSLwolfSSLCWE-295CRL critical extension bypass in ParseCRL_Extensions
CVE-2026-132818.37.6GoogleChromeCWE-472Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a r…
CVE-2026-540407.17.6danny-avilaLibreChatCWE-306LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA B…
CVE-2026-130836.97.4Red HatPen Drive Powered by Red Hat LightspeedCWE-79Pen-drive: pen-drive: stored xss via unescaped cluster data in html report
CVE-2026-540968.47.2filebrowserfilebrowserCWE-863File Browser: Improper Access Control Occurs via Pre-Created Public Share for…
CVE-2026-560067.17.2H5PH5PCWE-79WordPress H5P plugin <= 1.17.6 - Reflected Cross Site Scripting (XSS) vulnera…
CVE-2026-423895.37.3PowerDNSRecursorCWE-20Reject more queries with invalid header values
CVE-2026-63252.07.3wolfSSLwolfSSLCWE-787Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms…
CVE-2026-556978.87.1pnpmpnpmCWE-78pnpm: Repository-controlled configDependencies can select a pacquet native in…
CVE-2026-500218.17.1pnpmpnpmCWE-354pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field
CVE-2026-53095.46.9GitLabGitLabCWE-639Authorization Bypass Through User-Controlled Key in GitLab
CVE-2025-604656.16.9n/an/aCWE-416A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter…
CVE-2026-75115.96.8wolfSSLwolfSSLCWE-347PKCS7_verify signer confusion allows forged signatures to be accepted
CVE-2026-567795.36.91Panel-devMaxKBCWE-918MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and down…
CVE-2026-133502.36.7pretixVenuelessCWE-639Permissions where checked incorrectly during room creation, allowing attacker…
CVE-2026-489466.36.5getk2.orgK2 extension for JoomlaCWE-434Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension f…
CVE-2020-372565.16.4GravGravCWE-79Grav - Cross-Site Scripting in Admin Plugin Page Editor
CVE-2026-489403.46.4getk2.orgK2 extension for JoomlaCWE-79Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
CVE-2026-97994.66.3Red HatRed Hat build of Keycloak 26.4CWE-639Keycloak: keycloak: unauthorized access to resources via uma permission ticke…
CVE-2026-572342.66.3sparklemotionnokogiriCWE-178Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, byp…
CVE-2026-108246.56.1UnknownMasteriyo LMSMasteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion
CVE-2026-554878.85.8pnpmpnpmCWE-346pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVE-2026-132826.85.9GoogleChromeCWE-416Use after free in Payments in Google Chrome on Android prior to 149.0.7827.20…
CVE-2026-540255.45.9danny-avilaLibreChatCWE-79LibreChat: Stored XSS via unescaped image alt text in markdown artifact preview
CVE-2026-92218.75.7Shenzhen i365-Tech Co. Ltd.Setracker2 Parental Control App (Android) package com.tgelec.setrackerCWE-327Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptogra…
CVE-2026-100978.35.7wolfSSLwolfSSLCWE-697ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break…
CVE-2026-489954.85.7pnpmpnpmCWE-353pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
CVE-2026-126353.15.8GitLabGitLabCWE-350Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab
CVE-2026-63296.05.7wolfSSLwolfSSLCWE-347PKCS#12 MAC verification uses attacker-controlled comparison length
CVE-2026-28158.45.6Silicon LabsSiSDKCWE-339Incorrect use of the PUF key for user key generation in EFR32xG27 results in …
CVE-2026-409417.15.5CacticactiCWE-347Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages
CVE-2026-489416.55.6getk2.orgK2 extension for JoomlaCWE-862Joomla Extension - getk2.org - Unauthenticated folder delete in K2 extension …
CVE-2026-124908.25.3NLnet LabsNSDCWE-284Bypass of client certificate verification with transfer over TLS
CVE-2026-420043.75.2PowerDNSDNSdistCWE-115EDNS options smuggling
CVE-2026-505738.15.1pnpmpnpmCWE-345pnpm: Unsafe default behavior breaks integrity check
CVE-2026-75325.75.1wolfSSLwolfSSLCWE-295iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined
CVE-2026-451882.45.2Apache Software FoundationApache KvrocksCWE-23Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename …
CVE-2026-400113.74.9PowerDNSDNSdistCWE-116Prometheus denial of service via crafted DNS queries
CVE-2026-62916.04.9wolfSSLwolfSSLCWE-208Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption
CVE-2026-558955.74.9vimvimCWE-78Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename
CVE-2026-532127.84.8LinuxLinuxCWE-416netfilter: nft_tunnel: fix use-after-free on object destroy
CVE-2026-532027.84.6LinuxLinuxCWE-674accel/ivpu: Fix signed integer truncation in IPC receive
CVE-2026-133186.44.7Red HatRed Hat OpenShift Virtualization 4CWE-918Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalid…
CVE-2026-489426.14.6getk2.orgK2 extension for JoomlaCWE-79Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
CVE-2026-531947.84.5LinuxLinuxCWE-787USB: serial: kl5kusb105: fix bulk-out buffer overflow
CVE-2026-498397.14.6jqlangjqCWE-787jq --rawfile invalid-state reuse after String too long causes heap-buffer-ove…
CVE-2026-63312.14.5wolfSSLwolfSSLCWE-347HMAC zero-length tag forgery in EVP_DigestVerifyFinal
CVE-2026-477706.84.5jqlangjqCWE-674jq: stack overflow in deep structural equality
CVE-2026-559618.24.4wolfSSLwolfSSLCWE-347wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 wit…
CVE-2026-574568.44.3vimvimCWE-94Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings
CVE-2026-567884.84.2tomojitakasuRTKLIBCWE-125RTKLIB 2.4.3 - Out-of-bounds Read via Negative Array Index in getcodepri
CVE-2026-531377.84.2LinuxLinuxCWE-787drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
CVE-2026-531437.84.1LinuxLinuxCWE-787drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
CVE-2026-531957.84.1LinuxLinuxCWE-787USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
CVE-2026-532037.14.1LinuxLinuxCWE-787accel/ivpu: Add buffer overflow check in MS get_info_ioctl
CVE-2026-559626.04.1wolfSSLwolfSSLCWE-287TLS 1.3 post-handshake authentication: server accepts Finished without client…
CVE-2026-466067.84.0nicolargoglancesCWE-78Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vm…
CVE-2026-531937.83.9LinuxLinuxCWE-416ALSA: timer: Forcibly close timer instances at closing
CVE-2026-574537.33.9vimvimCWE-77Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction
CVE-2026-531327.13.7LinuxLinuxCWE-401vsock/virtio: fix potential unbounded skb queue
CVE-2026-539257.83.6nicolargoglancesCWE-22Glances: Arbitrary file write and command execution via `secure_popen` redire…
CVE-2026-531487.83.4LinuxLinuxCWE-787thunderbolt: Clamp XDomain response data copy to allocation size
CVE-2026-63306.33.4wolfSSLwolfSSLCWE-327ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
CVE-2026-128978.43.3Horner AutomationCscapeCWE-125Out-of-bounds read in Horner Automation Cscape
CVE-2026-532347.83.2LinuxLinuxCWE-416net: ibm: emac: Fix use-after-free during device removal
CVE-2026-532275.53.1LinuxLinuxCWE-401net: openvswitch: fix possible kfree_skb of ERR_PTR
CVE-2026-532525.53.1LinuxLinuxCWE-401Bluetooth: fix memory leak in error path of hci_alloc_dev()
CVE-2026-83304.43.1GitLabGitLabCWE-532Insertion of Sensitive Information into Log File in GitLab
CVE-2026-540309.33.0danny-avilaLibreChatCWE-346LibreChat: Missing Resource Parameter Validation in MCP OAuth Flow
CVE-2026-466077.83.0nicolargoglancesCWE-502Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary …
CVE-2026-531337.83.0LinuxLinuxCWE-681RDMA/umem: Fix truncation for block sizes >= 4G
CVE-2026-531367.83.0LinuxLinuxCWE-787drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
CVE-2026-531827.83.0LinuxLinuxwifi: nl80211: reject oversized EMA RNR lists
CVE-2026-531897.83.0LinuxLinuxmm/huge_memory: update file PMD counter before folio_put()
CVE-2026-531917.82.9LinuxLinuxio_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries
CVE-2026-532097.83.0LinuxLinuxCWE-787Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
CVE-2026-532337.82.9LinuxLinuxCWE-415netdev: fix double-free in netdev_nl_bind_rx_doit()
CVE-2026-532427.83.0LinuxLinuxCWE-476ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-531595.53.0LinuxLinuxmisc: fastrpc: fix DMA address corruption due to find_vma misuse
CVE-2026-531708.82.9LinuxLinuxCWE-908accel/ethosu: reject DMA commands with uninitialized length
CVE-2026-531718.82.9LinuxLinuxaccel/ethosu: fix arithmetic issues in dma_length()
CVE-2026-129218.42.9AzeoTechDAQFactoryCWE-416Use after free in AzeoTech DAQFactory
CVE-2026-532017.82.9LinuxLinuxRevert "drm/xe: Skip exec queue schedule toggle if queue is idle during suspend"
CVE-2026-531888.82.8LinuxLinuxRDMA/core: Validate the passed in fops for ib_get_ucaps()
CVE-2026-531627.82.8LinuxLinuxmemcg: use round-robin victim selection in refill_stock
CVE-2026-531577.82.7LinuxLinuxCWE-416net: phonet: free phonet_device after RCU grace period
CVE-2026-531607.82.7LinuxLinuxCWE-416misc: fastrpc: fix use-after-free race in fastrpc_map_create
CVE-2026-531617.82.7LinuxLinuxCWE-416misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
CVE-2026-532397.82.7LinuxLinuxCWE-416xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
CVE-2026-531387.12.7LinuxLinuxCWE-125drm/amd/display: Bound VBIOS record-chain walk loops
CVE-2026-531497.12.7LinuxLinuxCWE-125thunderbolt: Bound root directory content to block size
CVE-2026-532237.12.7LinuxLinuxnet: guard timestamp cmsgs to real error queue skbs
CVE-2026-554116.82.7ToolJetToolJetCWE-639ToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/…
CVE-2026-532308.72.6LinuxLinuxCWE-125net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
CVE-2026-531567.82.6LinuxLinuxCWE-416nvmem: core: fix use-after-free bugs in error paths
CVE-2026-531927.82.6LinuxLinuxCWE-416ALSA: timer: Fix UAF at snd_timer_user_params()
CVE-2026-531797.12.6LinuxLinuxCWE-125staging: rtl8723bs: fix buffer over-read in rtw_update_protection
CVE-2026-532057.12.6LinuxLinuxCWE-787accel/ivpu: Add bounds checks for firmware log indices
CVE-2026-531675.52.6LinuxLinuxCWE-908fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
CVE-2026-531877.12.5LinuxLinuxCWE-787RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
CVE-2026-105926.32.5wolfSSLwolfSSLCWE-295Wildcard DNS SAN bypasses CA name-constraint checks
CVE-2026-67316.02.5wolfSSLwolfSSLCWE-295X.509 name constraint bypass via Subject CN treated as a DNS name
CVE-2026-556935.72.6vimvimCWE-787Vim: Out-of-bounds Write in Spell File Word Count
CVE-2026-45226.72.5HYPRPasswordlessCWE-306Missing authentication for critical function vulnerability in HYPR Passwordle…
CVE-2026-531345.52.5LinuxLinuxCWE-401netfilter: nft_fib: fix stale stack leak via the OIFNAME register
CVE-2026-531355.52.5LinuxLinuxCWE-476drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
CVE-2026-531395.52.5LinuxLinuxdrm/v3d: Skip CSD when it has zeroed workgroups
CVE-2026-531505.52.4LinuxLinuxCWE-191thunderbolt: Reject zero-length property entries in validator
CVE-2026-531585.52.4LinuxLinuxCWE-476misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
CVE-2026-531635.52.5LinuxLinuxCWE-476locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
CVE-2026-531685.52.4LinuxLinuxfuse: reject fuse_notify() pagecache ops on directories
CVE-2026-531775.52.4LinuxLinuxCWE-476bnxt_en: Fix NULL pointer dereference
CVE-2026-531815.52.4LinuxLinuxCWE-401vsock/vmci: fix sk_ack_backlog leak on failed handshake
CVE-2026-532085.52.4LinuxLinuxBluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
CVE-2026-532135.52.4LinuxLinuxCWE-401drm/vc4: fix krealloc() memory leak
CVE-2026-532185.52.4LinuxLinuxCWE-908netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
CVE-2026-532195.52.4LinuxLinuxnetfilter: x_tables: avoid leaking percpu counter pointers
CVE-2026-532365.52.4LinuxLinuxtcp: restrict SO_ATTACH_FILTER to priv users
CVE-2026-532385.52.4LinuxLinuxnetlabel: validate unlabeled address and mask attribute lengths
CVE-2026-532455.52.4LinuxLinuxnet/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
CVE-2026-532495.52.4LinuxLinuxipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
CVE-2026-542505.82.4k3s-iok3sCWE-22K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
CVE-2026-531405.52.3LinuxLinuxCWE-401drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups
CVE-2026-531425.52.3LinuxLinuxCWE-908drm/xe/display: fix oops in suspend/shutdown without display
CVE-2026-531445.52.3LinuxLinuxCWE-476drm/amdkfd: fix NULL dereference in get_queue_ids()
CVE-2026-531525.52.4LinuxLinuxCWE-476mmc: dw_mmc-rockchip: Add missing private data for very old controllers
CVE-2026-531545.52.3LinuxLinuxCWE-772mm/hugetlb: restore reservation on error in hugetlb folio copy paths
CVE-2026-531905.52.4LinuxLinuxdrm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-532105.52.4LinuxLinuxCWE-401tee: shm: fix shm leak in register_shm_helper()
CVE-2026-532145.52.4LinuxLinuxCWE-476ipv6: Fix a potential NPD in cleanup_prefix_route()
CVE-2026-532205.52.4LinuxLinuxCWE-476netfilter: revalidate bridge ports

Results continue: ranks 401–468.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-25 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.