AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C N H N 8.6 .8321 99.7 YES
AFFECTED Product Versions Fixed Cisco Unified Communications Manager 14 – —
TIMELINE Oct 8 Reserved by CNA Jun 25 Added to CISA KEV, due Jun 28 Jun 25 Published (CNA: cisco)
468 CVEs published June 25, 2026: 42 critical, 219 high, 172 medium, 35 low; 2 in KEV; 48 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 443 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 6643 | 11015 | 1173 | 2563 |
| KEV catalog size | 1670 | |||
490 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 466 | 1432 | 118 | 845 | 466 | 1 | 27 | 3 | 0.2 | 7.8 | .0013 | +240 |
| 707 | 881 | 85 | 464 | 300 | 29 | 74 | 6 | 0.7 | 8.1 | .0023 | +691 | |
| microsoft | 220 | 710 | 55 | 474 | 160 | 4 | 378 | 27 | 3.8 | 7.8 | .0044 | +56 |
| red hat | 106 | 170 | 9 | 73 | 81 | 7 | 4 | 0 | 0.0 | 6.8 | .0026 | +97 |
| apple | 15 | 62 | 0 | 16 | 37 | 2 | 93 | 7 | 11.3 | 5.5 | .0023 | +2 |
| canonical | 2 | 16 | 1 | 4 | 6 | 5 | 0 | 0 | 0.0 | 5.5 | .0010 | +2 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | -7 |
| suse | 4 | 6 | 1 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 10 | 23 | 4 | 4 | 8 | 0 | 96 | 11 | 47.8 | 7.0 | .0431 | +5 |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | +17 |
| palo alto networks | 9 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | +8 |
| ubiquiti | 8 | 11 | 7 | 4 | 0 | 0 | 4 | 3 | 27.3 | 9.9 | .0083 | +6 |
| f5 | 6 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | +4 |
| ivanti | 4 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | +2 |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 |
| fortinet | 2 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 99 | 131 | 20 | 45 | 55 | 10 | 40 | 1 | 0.8 | 6.5 | .0046 | +81 |
| mozilla | 49 | 55 | 11 | 18 | 26 | 0 | 13 | 0 | 0.0 | 7.3 | .0026 | +43 |
| gitlab | 24 | 33 | 0 | 5 | 21 | 5 | 4 | 2 | 6.1 | 4.4 | .0022 | +24 |
| docker | 4 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | +1 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | -3 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 243 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | +243 |
| adobe | 132 | 136 | 4 | 50 | 77 | 2 | 75 | 3 | 2.2 | 5.5 | .0021 | +131 |
| ibm | 32 | 81 | 19 | 35 | 27 | 0 | 7 | 0 | 0.0 | 7.5 | .0028 | +32 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +1 |
| solarwinds | 3 | 6 | 1 | 2 | 1 | 0 | 11 | 4 | 66.7 | 7.5 | .3995 | +3 |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | +1 |
| zohocorp | 1 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 9 | 12 | 0 | 4 | 2 | 5 | 26 | 1 | 8.3 | 5.5 | .0058 | +8 |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 1 | 0 | 0.0 | 7.5 | .0020 | +6 |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 |
| abb | 6 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +6 |
| schneider electric | 6 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | +6 |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | +3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 72 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | +71 |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +61 |
| sourcecodester | 37 | 59 | 0 | 0 | 25 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +21 |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 |
| edimax | 5 | 56 | 0 | 33 | 0 | 23 | 1 | 0 | 0.0 | 7.4 | .0070 | -39 |
| dell | 37 | 55 | 1 | 29 | 24 | 0 | 2 | 1 | 1.8 | 7.2 | .0015 | +25 |
| jenkins project | 36 | 49 | 0 | 9 | 39 | 1 | 0 | 0 | 0.0 | 4.8 | .0021 | +36 |
| capgo | 46 | 46 | 2 | 22 | 21 | 1 | 0 | 0 | 0.0 | 7.0 | .0034 | +46 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE-2026-48907 | .6883 | 99.3 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 |
| Vendor | CVEs |
|---|---|
| linux | 877 |
| 859 | |
| oracle | 268 |
| microsoft | 226 |
| adobe | 132 |
| red hat | 131 |
| apache | 101 |
| spring | 72 |
| openclaw | 67 |
| ibm | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 39 |
| Packagist | 22 |
| PyPI | 10 |
| npm | 4 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1681 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1681 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1681 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1681 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1681 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1681 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1681 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1681 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1681 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1681 |
EXPLOIT PUBLISHED — CVE-2025-60464. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60465. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71324 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71327 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71328 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71333 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71334 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71335 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71336 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71338 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13351 (zephyrproject-rtos Zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-40080 (cacti). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-40082 (cacti). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-40083 (cacti). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-40084 (cacti). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47770 (jqlang jq). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48995 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49839 (jqlang jq). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50014 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50015 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50016 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50017 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50021 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50573 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54024 (danny-avila LibreChat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54025 (danny-avila LibreChat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54027 (danny-avila LibreChat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54029 (danny-avila LibreChat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54030 (danny-avila LibreChat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54033 (danny-avila LibreChat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54036 (danny-avila LibreChat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54037 (danny-avila LibreChat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54040 (danny-avila LibreChat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54917 (seaweedfs). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55180 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55487 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55697 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55698 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55699 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55700 (pnpm). Public exploit reference added.
468 CVEs published. 25 box scores and 375 table rows below; the remaining 68 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C N H N 8.6 .8321 99.7 YES
AFFECTED Product Versions Fixed Cisco Unified Communications Manager 14 – —
TIMELINE Oct 8 Reserved by CNA Jun 25 Added to CISA KEV, due Jun 28 Jun 25 Published (CNA: cisco)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .3020 98.1 YES
AFFECTED Product Versions Fixed Windchill PDMLink unspecified — FlexPLM unspecified —
TIMELINE Jun 18 Reserved by CNA Jun 25 Added to CISA KEV, due Jun 28 Jun 25 Published (CNA: PTC)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0390 89.4 —
AFFECTED Product Versions Fixed Flowise unspecified 3.0.6
TIMELINE Jun 20 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A H H H 8.6 .0198 78.9 —
AFFECTED Product Versions Fixed thc-hydra unspecified 9cc84c20e75f5fef6bb1790bb9ada2afad2204e2
TIMELINE Jun 22 Reserved by CNA Jun 25 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0156 73.2 —
AFFECTED Product Versions Fixed Flowise unspecified 3.0.6
TIMELINE Jun 20 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0138 69.8 —
AFFECTED Product Versions Fixed Flowise unspecified 3.0.6
TIMELINE Jun 8 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0127 67.3 —
AFFECTED Product Versions Fixed cursor < 3.0 – —
TIMELINE Jun 4 Reserved by CNA Jun 25 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0119 65.3 —
AFFECTED Product Versions Fixed PowerLogic™ P7 Version V02.003.001.000 and prior – —
TIMELINE May 27 Reserved by CNA Jun 25 Published (CNA: schneider)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N L 9.3 .0105 61.4 —
AFFECTED Product Versions Fixed YMC Filter n/a – 3.11.6
TIMELINE Jun 16 Reserved by CNA Jun 25 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0096 58.5 —
AFFECTED Product Versions Fixed cursor < 3.0 – —
TIMELINE Jun 4 Reserved by CNA Jun 25 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0092 57.2 —
AFFECTED Product Versions Fixed InsightConnect Sed Plugin unspecified 2.0.5
TIMELINE May 21 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0086 55.6 —
AFFECTED Product Versions Fixed Flowise unspecified —
TIMELINE Jun 20 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0083 54.6 —
AFFECTED Product Versions Fixed InsightConnect Tcpdump Plugin unspecified 2.0.0
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0083 54.6 —
AFFECTED Product Versions Fixed InsightConnect SQLmap Plugin unspecified 2.0.1
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0083 54.6 —
AFFECTED Product Versions Fixed InsightConnect Finger Plugin unspecified 1.0.3
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0080 53.6 —
AFFECTED Product Versions Fixed Flowise unspecified —
TIMELINE Jun 20 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.3 —
AFFECTED Product Versions Fixed Linux b8d26b3be8b33682cf163274ed07479a70554633 – — Linux 3.10 – 5.10.259
TIMELINE Jun 9 Reserved by CNA Jun 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.2 —
AFFECTED Product Versions Fixed InsightConnect AWK Plugin unspecified 1.2.2
TIMELINE May 14 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.2 —
AFFECTED Product Versions Fixed InsightConnect Ping Plugin unspecified 1.0.4
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.2 —
AFFECTED Product Versions Fixed InsightConnect TR Plugin unspecified 2.0.3
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.2 —
AFFECTED Product Versions Fixed InsightConnect Traceroute Plugin unspecified 1.0.3
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U H H H 7.8 .0065 48.0 —
AFFECTED Product Versions Fixed Display and Peripheral Manager unspecified —
TIMELINE May 17 Reserved by CNA Jun 25 Published (CNA: dell)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0063 47.3 —
AFFECTED Product Versions Fixed filebrowser < 2.63.6 – —
TIMELINE Jun 11 Reserved by CNA Jun 25 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H N 9.3 .0058 45.0 —
AFFECTED Product Versions Fixed Flowise 3.0.1 – —
TIMELINE Jun 8 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0058 45.1 —
AFFECTED Product Versions Fixed GitLab 19.1 – —
TIMELINE Jun 11 Reserved by CNA Jun 25 Published (CNA: GitLab)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-49506 | 7.2 | 44.9 | Dell | Wyse Management Suite | CWE-22 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Imprope… |
| CVE-2026-6679 | 8.8 | 44.8 | wolfSSL | wolfSSL | CWE-787 | DTLS 1.3 ACK serialization heap buffer overflow via integer truncation |
| CVE-2026-45233 | 7.2 | 44.3 | danpros | htmly | CWE-22 | HTMLy CMS 3.1.1 Path Traversal via oldfile Parameter in Autosave |
| CVE-2026-54823 | 9.9 | 44.0 | MarketingFire | Widget Options | CWE-94 | WordPress Widget Options plugin <= 4.2.3 - Remote Code Execution (RCE) vulner… |
| CVE-2026-43920 | 6.9 | 43.2 | FOSSBilling | FOSSBilling | CWE-306 | FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenanc… |
| CVE-2026-9083 | 4.9 | 41.7 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-22 | Keycloak: keycloak: information disclosure through arbitrary filesystem path … |
| CVE-2026-53224 | 9.1 | 41.6 | Linux | Linux | CWE-125 | sctp: validate embedded INIT chunk and address list lengths in cookie |
| CVE-2026-53221 | 9.8 | 41.4 | Linux | Linux | — | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() |
| CVE-2026-53228 | 9.8 | 41.4 | Linux | Linux | — | ipv6: sit: reload inner IPv6 header after GSO offloads |
| CVE-2026-53186 | 9.1 | 41.4 | Linux | Linux | — | RDMA/srp: bound SRP_RSP sense copy by the received length |
| CVE-2026-53225 | 9.1 | 41.4 | Linux | Linux | CWE-908 | sctp: fix uninit-value in __sctp_rcv_asconf_lookup() |
| CVE-2026-53215 | 9.8 | 40.7 | Linux | Linux | — | net: mvpp2: refill RX buffers before XDP or skb use |
| CVE-2026-53216 | 9.8 | 40.7 | Linux | Linux | — | net: mvpp2: limit XDP frame size to the RX buffer |
| CVE-2026-53199 | 7.5 | 40.6 | Linux | Linux | — | hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf |
| CVE-2026-54092 | 6.5 | 39.6 | filebrowser | filebrowser | CWE-400 | File Browser: DoS Vulnerability on Public Login API |
| CVE-2026-53183 | 7.5 | 39.3 | Linux | Linux | — | mptcp: allow subflow rcv wnd to shrink |
| CVE-2026-53184 | 7.5 | 39.3 | Linux | Linux | — | udp: clear skb->dev before running a sockmap verdict |
| CVE-2026-50016 | 8.8 | 38.9 | pnpm | pnpm | CWE-23 | pnpm: Transitive dependency alias path traversal allows project path override… |
| CVE-2026-54091 | 7.5 | 38.8 | filebrowser | filebrowser | CWE-863 | File Browser: Incorrect access control in public directory shares via rule pa… |
| CVE-2026-54094 | 7.5 | 38.6 | filebrowser | filebrowser | CWE-22 | File Browser: Symlink following lets scoped users read, overwrite, and share … |
| CVE-2026-53247 | 9.8 | 38.5 | Linux | Linux | CWE-416 | net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown |
| CVE-2026-53151 | 9.8 | 37.9 | Linux | Linux | — | rxrpc: Fix the ACK parser to extract the SACK table for parsing |
| CVE-2026-41120 | 9.8 | 37.5 | Dell | Wyse Management Suite | CWE-349 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Accepta… |
| CVE-2026-56054 | 7.7 | 37.5 | Ahmad | JS Help Desk | CWE-22 | WordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerability |
| CVE-2026-38637 | 7.5 | 37.1 | n/a | n/a | CWE-400 | An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f… |
| CVE-2026-38640 | 7.5 | 37.1 | n/a | n/a | CWE-400 | A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc c… |
| CVE-2026-55667 | 8.2 | 36.9 | filebrowser | filebrowser | CWE-22 | File Browser: Out-of-scope file deletion by a Create-only scoped user via sym… |
| CVE-2026-53246 | 9.8 | 36.8 | Linux | Linux | CWE-787 | sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing |
| CVE-2026-53229 | 7.5 | 36.7 | Linux | Linux | CWE-401 | net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure |
| CVE-2026-53235 | 7.5 | 36.7 | Linux | Linux | — | net: add pskb_may_pull() to skb_gro_receive_list() |
| CVE-2026-56786 | 9.3 | 36.5 | tomojitakasu | RTKLIB | CWE-787 | RTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 Message |
| CVE-2026-53198 | 8.8 | 36.2 | Linux | Linux | CWE-416 | ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL |
| CVE-2026-56445 | 8.8 | 36.1 | pydicom | pynetdicom Library | CWE-22 | pydicom pynetdicom Library Path Traversal |
| CVE-2026-54089 | 9.1 | 35.9 | filebrowser | filebrowser | CWE-287 | File Browser: Authentication Bypass via Proxy Auth Header Forgery |
| CVE-2026-50176 | 8.7 | 35.7 | EVoke | EVoke CSMS | CWE-307 | EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Att… |
| CVE-2026-53131 | 9.4 | 35.5 | Linux | Linux | — | netfilter: require Ethernet MAC header before using eth_hdr() |
| CVE-2026-56091 | 8.2 | 35.3 | Apache Software Foundation | Apache Shiro | CWE-289 | Apache Shiro: Authentication bypass in Guice-Web integration |
| CVE-2026-9086 | 7.3 | 35.0 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-79 | Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri valid… |
| CVE-2026-40702 | 9.3 | 34.6 | EVoke | EVoke CSMS | CWE-306 | EVoke Systems EVoke CSMS Missing Authentication for Critical Function |
| CVE-2026-55699 | 6.5 | 34.4 | pnpm | pnpm | CWE-22 | pnpm: reserved bin name deletes PNPM_HOME during global remove |
| CVE-2026-55958 | 8.3 | 34.4 | wolfSSL | wolfSSL | CWE-787 | Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage |
| CVE-2026-54097 | 7.2 | 34.2 | filebrowser | filebrowser | CWE-639 | File Browser: Cross-user unauthorized share-link deletion via unbounded prefi… |
| CVE-2025-71328 | 8.7 | 33.7 | Flowise | Flowise | CWE-620 | Flowise - Unverified Password Change via Account Settings |
| CVE-2026-12844 | 7.5 | 33.0 | DROLSKY | List::SomeUtils::XS | CWE-122 | List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow… |
| CVE-2026-37452 | 7.5 | 33.0 | n/a | n/a | CWE-200 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120… |
| CVE-2026-37453 | 7.5 | 33.0 | n/a | n/a | CWE-200 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120… |
| CVE-2026-46752 | 10.0 | 32.7 | Apache Software Foundation | Apache Kvrocks | CWE-122 | Apache Kvrocks: Stack buffer overflow in Lua bit.tohex() |
| CVE-2026-53240 | 8.8 | 32.2 | Linux | Linux | CWE-416 | xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload |
| CVE-2026-40084 | 6.5 | 31.8 | Cacti | cacti | CWE-22 | Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter |
| CVE-2026-42387 | 5.9 | 31.7 | PowerDNS | Recursor | CWE-20 | Insufficient input validation in ZoneToCache |
| CVE-2026-42388 | 5.9 | 31.7 | PowerDNS | Recursor | CWE-20 | Missing input validation for catalog zones |
| CVE-2026-54917 | 7.8 | 31.6 | seaweedfs | seaweedfs | CWE-22 | SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bu… |
| CVE-2026-53217 | 8.6 | 31.6 | Linux | Linux | — | net: mvpp2: sync RX data at the hardware packet offset |
| CVE-2026-56768 | 8.7 | 31.2 | haiwen | seahub | CWE-862 | Seahub < 13.0.23 - Authentication Bypass in ShareLinkZipTaskView GET Method |
| CVE-2026-56053 | 8.8 | 31.1 | EventPrime | EventPrime | CWE-502 | WordPress EventPrime plugin <= 4.3.4.1 - PHP Object Injection vulnerability |
| CVE-2026-56122 | 8.7 | 30.8 | rickknowles | Winstone Servlet Container | CWE-22 | Winstone Servlet Engine 0.9.10 Path Traversal via HTTP Request Paths |
| CVE-2026-50017 | 6.9 | 30.7 | pnpm | pnpm | CWE-200 | pnpm binds unscoped user-level npm auth credentials to a repository-selected … |
| CVE-2026-5305 | 8.8 | 30.3 | Unknown | Email Address Encoder | — | Email Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Sto… |
| CVE-2026-53260 | 9.8 | 29.9 | Linux | Linux | CWE-416 | tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). |
| CVE-2026-57435 | 1.7 | 29.8 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogi… |
| CVE-2026-50015 | 7.3 | 29.6 | pnpm | pnpm | CWE-22 | pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal) |
| CVE-2026-57700 | 10.0 | 29.3 | Daan.dev | OMGF Pro | CWE-434 | WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability |
| CVE-2026-13311 | 8.7 | 29.1 | ljharb | shell-quote | CWE-407 | shell-quote parse() is quadratic in token count, enabling denial of service |
| CVE-2026-9800 | 8.1 | 28.8 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-1025 | Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via … |
| CVE-2026-57434 | 1.7 | 28.9 | sparklemotion | nokogiri | CWE-476 | Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper c… |
| CVE-2026-10712 | 6.1 | 28.7 | GitLab | GitLab | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… |
| CVE-2026-53248 | 8.8 | 28.4 | Linux | Linux | CWE-416 | net: airoha: Fix use-after-free in metadata dst teardown |
| CVE-2026-57520 | 7.1 | 28.4 | bitwarden | server | CWE-862 | Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint |
| CVE-2026-57587 | 2.9 | 28.3 | tenable | Nessus | CWE-89 | SQL Injection in Nessus via Reverse DNS Lookup |
| CVE-2026-55700 | 7.1 | 28.3 | pnpm | pnpm | CWE-22 | pnpm: stage download writes outside destination via manifest version traversal |
| CVE-2026-54226 | 6.4 | 27.9 | Apache Software Foundation | Apache Kvrocks | CWE-190 | Apache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoS |
| CVE-2026-7531 | 2.3 | 27.7 | wolfSSL | wolfSSL | CWE-416 | Use-after-free in PQC hybrid key-share handling |
| CVE-2026-57588 | 1.8 | 27.6 | tenable | Nessus | CWE-89 | SQL Injection in Nessus via Malicious Scan Result File Import |
| CVE-2026-54037 | 6.5 | 27.5 | danny-avila | LibreChat | CWE-770 | LibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rat… |
| CVE-2026-13225 | 5.3 | 27.5 | pretix | pretix | CWE-80 | Stored XSS in ticket confirmation page |
| CVE-2026-53268 | 8.2 | 27.4 | Linux | Linux | CWE-125 | netfilter: conntrack_irc: fix possible out-of-bounds read |
| CVE-2026-53165 | 7.5 | 27.4 | Linux | Linux | CWE-476 | iomap: avoid potential null folio->mapping deref during error reporting |
| CVE-2026-53244 | 7.5 | 27.4 | Linux | Linux | — | VFS: fix possible failure to unlock in nfsd4_create_file() |
| CVE-2026-42005 | 4.3 | 27.4 | PowerDNS | Authoritative | CWE-400 | Insufficient input validation of internal web server |
| CVE-2026-55477 | 7.2 | 27.2 | MHSanaei | 3x-ui | CWE-73 | Authenticated Arbitrary File Write via Database Import and Xray Log Path Mani… |
| CVE-2026-57235 | 6.3 | 27.1 | sparklemotion | nokogiri | CWE-125 | Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` |
| CVE-2026-57236 | 1.7 | 27.1 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` ra… |
| CVE-2026-56049 | 8.5 | 27.0 | Post Snippets | Post Snippets | CWE-94 | WordPress Post Snippets plugin <= 4.0.19 - Remote Code Execution (RCE) vulner… |
| CVE-2026-53180 | 7.5 | 27.0 | Linux | Linux | CWE-667 | timers/migration: Fix livelock in tmigr_handle_remote_up() |
| CVE-2026-56770 | 8.7 | 26.9 | schwehr | libais | CWE-129 | libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid S… |
| CVE-2026-52690 | 5.9 | 26.9 | PowerDNS | Recursor | CWE-290 | Spoofed answers can mark an authoritative non-EDNS capable |
| CVE-2026-10086 | 5.4 | 26.8 | GitLab | GitLab | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… |
| CVE-2026-55439 | 5.5 | 26.6 | halo-dev | halo | CWE-22 | Halo: Path Traversal in Backup Download Leads to Arbitrary File Read |
| CVE-2026-46601 | 7.5 | 26.4 | golang.org/x/image | golang.org/x/image/webp | — | Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image |
| CVE-2026-46602 | 7.5 | 26.4 | golang.org/x/image | golang.org/x/image/tiff | — | Lack of limit on tile sizes in x/image/tiff in golang.org/x/image |
| CVE-2026-56787 | 6.9 | 26.5 | tomojitakasu | RTKLIB | CWE-193 | RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Mes… |
| CVE-2026-40083 | 7.2 | 26.2 | Cacti | cacti | CWE-89 | Cacti: SQL Injection in managers.php |
| CVE-2026-57532 | 8.8 | 25.8 | pretix | pretix | CWE-80 | Malicious HTML content contained in the layout specification of a PDF ticket … |
| CVE-2026-56767 | 8.7 | 25.9 | getmaxun | maxun | CWE-862 | Maxun < 0.0.42 - Cross-Tenant IDOR in Storage and Webhook API Handlers |
| CVE-2026-57534 | 2.1 | 25.8 | pretix | pretix-pages | CWE-80 | Stored XSS in pretix-pages |
| CVE-2026-13314 | 2.0 | 25.8 | pretix | pretix-digital | CWE-80 | Stored XSS in pretix-digital |
| CVE-2026-55180 | 6.5 | 25.5 | pnpm | pnpm | CWE-200 | pnpm: Repository config can expand victim environment secrets into registry r… |
| CVE-2026-12244 | 8.7 | 25.4 | NLnet Labs | NSD | CWE-122 | Heap overflow and crash with crafted SVCB RR |
| CVE-2026-13351 | 7.5 | 25.2 | zephyrproject-rtos | Zephyr | CWE-772 | net: Maliciously fragmented IPv6 packets can prevent receiving/processing fut… |
| CVE-2026-46751 | 5.5 | 25.2 | Apache Software Foundation | Apache Kvrocks | — | Apache Kvrocks: Does not remove the unsafe loadstring function from its Lua s… |
| CVE-2026-54090 | 8.7 | 25.1 | filebrowser | filebrowser | CWE-77 | File Browser: Command Allowlist Bypass via Shell Metacharacter Injection |
| CVE-2025-71335 | 8.6 | 24.8 | Flowise | Flowise | CWE-613 | Flowise - Session Invalidation Failure After Password Change |
| CVE-2026-22879 | 8.1 | 24.8 | vtk | vtk | CWE-129 | vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnera… |
| CVE-2026-57436 | 1.7 | 24.9 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid… |
| CVE-2026-57437 | 1.7 | 24.9 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathCo… |
| CVE-2026-12245 | 8.7 | 24.7 | NLnet Labs | NSD | CWE-416 | Denial of DNS over TLS service by any DoT client |
| CVE-2026-40012 | 5.3 | 24.6 | PowerDNS | Recursor | CWE-524 | Information about ECS zero scoped answers might leak to clients that use a sp… |
| CVE-2026-53175 | 9.8 | 24.0 | Linux | Linux | CWE-416 | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-56123 | 9.2 | 23.4 | socat | socat | CWE-122 | socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser |
| CVE-2026-9153 | 6.5 | 23.5 | Rapid7 | InsightConnect Sed Plugin | CWE-22 | Arbitrary File Read in Rapid7 InsightConnect Sed Plugin |
| CVE-2026-6432 | 5.3 | 23.5 | Silicon Labs | SiSDK | CWE-130 | Improper bounds validation in EmberZNet SDK |
| CVE-2026-57535 | 2.1 | 23.4 | pretix | pretix | CWE-80 | Content injected to PDF rendering contexts could, in many places, include HTM… |
| CVE-2026-12937 | 7.5 | 23.0 | themefic | Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin | CWE-89 | Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter |
| CVE-2025-71340 | 7.6 | 22.6 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.ru… |
| CVE-2026-12246 | 7.2 | 22.5 | NLnet Labs | NSD | CWE-20 | Out of bounds stack write with crafted APL RR |
| CVE-2026-57429 | 6.5 | 22.5 | eLightUp | Slim SEO | CWE-862 | WordPress Slim SEO plugin <= 4.6.2 - Broken Access Control vulnerability |
| CVE-2026-54024 | 6.5 | 22.4 | danny-avila | LibreChat | CWE-770 | LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Ins… |
| CVE-2026-40211 | 5.3 | 22.2 | PowerDNS | DNSdist | CWE-770 | Denial of service via crafted DoH3 queries |
| CVE-2026-48944 | 6.5 | 22.1 | getk2.org | K2 extension for Joomla | CWE-22 | Joomla Extension - getk2.org - Exposure of sensitive files via attachment cop… |
| CVE-2026-6094 | 6.3 | 22.0 | wolfSSL | wolfSSL | CWE-125 | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 En… |
| CVE-2026-54841 | 7.5 | 21.9 | Appsbd | Vitepos | CWE-201 | WordPress Vitepos plugin <= 3.4.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-41566 | 9.4 | 21.9 | Apache Software Foundation | Apache Kvrocks | CWE-280 | Apache Kvrocks: Improper permission for the APPLYBATCH command |
| CVE-2026-55092 | 7.0 | 21.7 | aquasecurity | trivy | CWE-22 | Trivy: Path traversal via a crafted vulnerability database or other downloade… |
| CVE-2026-40209 | 5.3 | 21.5 | PowerDNS | DNSdist | CWE-772 | Denial of service via IXFR queries |
| CVE-2026-9099 | 7.7 | 21.4 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-639 | Keycloak: group-admin escalation to realm-admin |
| CVE-2026-54573 | 5.3 | 21.0 | outline | outline | CWE-863 | Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy |
| CVE-2026-54479 | 6.9 | 20.5 | EVoke | EVoke CSMS | CWE-613 | EVoke Systems EVoke CSMS Insufficient Session Expiration |
| CVE-2026-9154 | 6.5 | 19.9 | Rapid7 | InsightConnect Sed Plugin | CWE-22 | Arbitrary File Write in Rapid7 InsightConnect Sed Plugin |
| CVE-2026-2238 | 5.3 | 19.9 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-54845 | 8.1 | 19.8 | PluginUs.Net | MDTF | CWE-98 | WordPress MDTF plugin <= 1.3.8 - Local File Inclusion vulnerability |
| CVE-2026-12077 | 7.5 | 19.7 | wedevs | Dokan Pro | CWE-89 | Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longit… |
| CVE-2026-27366 | 7.5 | 19.6 | MainWP | MainWP Child | CWE-862 | WordPress MainWP Child plugin <= 6.1.1 - Broken Access Control vulnerability |
| CVE-2026-44622 | 6.9 | 19.6 | EVoke | EVoke CSMS | CWE-522 | EVoke Systems EVoke CSMS Insufficiently Protected Credentials |
| CVE-2026-54822 | 8.5 | 19.2 | SALESmanago | SALESmanago & Leadoo | CWE-89 | WordPress SALESmanago & Leadoo plugin <= 3.11.2 - SQL Injection vulnerability |
| CVE-2026-54838 | 8.5 | 19.2 | Rymera Web Co | WC Vendors Marketplace | CWE-89 | WordPress WC Vendors Marketplace plugin <= 2.6.8 - SQL Injection vulnerability |
| CVE-2026-53147 | 8.1 | 19.0 | Linux | Linux | CWE-125 | thunderbolt: Validate XDomain request packet size before type cast |
| CVE-2026-53254 | 8.1 | 19.0 | Linux | Linux | CWE-125 | Bluetooth: RFCOMM: validate skb length in MCC handlers |
| CVE-2026-9705 | 6.5 | 18.9 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-613 | Keycloak: keycloak: attacker can re-enable and take over disabled clients via… |
| CVE-2026-56774 | 5.3 | 18.5 | kanboard | kanboard | CWE-639 | Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated S… |
| CVE-2026-55698 | 8.8 | 18.5 | pnpm | pnpm | CWE-345 | pnpm: Project env lockfile can short-circuit package-manager resolution and e… |
| CVE-2026-54448 | 6.9 | 18.4 | aquasecurity | trivy | CWE-770 | Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser |
| CVE-2026-54821 | 7.4 | 18.3 | Bootstrapped Ventures | Visual Link Preview | CWE-201 | WordPress Visual Link Preview plugin <= 2.3.1 - Sensitive Data Exposure vulne… |
| CVE-2026-9716 | 8.7 | 18.2 | Schneider Electric | PowerLogic™ P7 | CWE-476 | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a deni… |
| CVE-2026-50014 | 7.3 | 18.2 | pnpm | pnpm | CWE-88 | pnpm: Git Fetch Argument Injection via Lockfile resolution.commit |
| CVE-2026-10512 | 2.3 | 18.2 | wolfSSL | wolfSSL | CWE-682 | X25519 x86_64 assembly final reduction leaves non-canonical field element |
| CVE-2026-37454 | 7.5 | 18.1 | n/a | n/a | CWE-200 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120… |
| CVE-2026-57619 | 6.5 | 18.1 | Elementor | Elementor Website Builder | CWE-862 | WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure… |
| CVE-2026-53196 | 6.8 | 18.0 | Linux | Linux | CWE-787 | USB: serial: io_ti: fix heap overflow in get_manuf_info() |
| CVE-2026-40210 | 4.8 | 18.0 | PowerDNS | DNSdist | CWE-126 | Out-of-bounds read in SetMacAddrAction |
| CVE-2026-57522 | 2.3 | 18.0 | bitwarden | server | CWE-74 | Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates |
| CVE-2026-53253 | 7.1 | 17.7 | Linux | Linux | CWE-125 | Bluetooth: bnep: reject short frames before parsing |
| CVE-2026-56005 | 7.1 | 17.5 | Melapress | WP Activity Log | CWE-79 | WordPress WP Activity Log plugin <= 5.6.3.1 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-13222 | 6.3 | 17.5 | pretix | pretix-oppwa | CWE-841 | Insufficient validation of payment status in pretix-oppwa |
| CVE-2026-13223 | 6.3 | 17.5 | pretix | pretix-computop | CWE-841 | Insufficient validation of payment status in pretix-computop |
| CVE-2026-57536 | 6.3 | 17.5 | pretix | pretix-mollie | CWE-841 | Insufficient validation of payment status in pretix-mollie |
| CVE-2026-6681 | 1.0 | 17.4 | wolfSSL | wolfSSL | CWE-120 | PKCS#7 decode ignores caller output buffer size, writing past buffer bounds |
| CVE-2026-55413 | 9.4 | 17.3 | ToolJet | ToolJet | CWE-94 | ToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Exec… |
| CVE-2026-10833 | 6.4 | 17.4 | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | CWE-79 | Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= … |
| CVE-2026-53232 | 8.8 | 17.1 | Linux | Linux | — | net: phy: clean the sfp upstream if phy probing fails |
| CVE-2026-57521 | 5.3 | 17.0 | bitwarden | server | CWE-862 | Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController |
| CVE-2026-54036 | 8.1 | 16.6 | danny-avila | LibreChat | CWE-306 | LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Ver… |
| CVE-2026-4526 | 7.1 | 16.5 | Silicon Labs | EmberZNet | CWE-125 | Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2 |
| CVE-2026-47145 | 7.1 | 16.5 | Silicon Labs | EmberZNet | CWE-617 | Color Control hue/saturation assertion abort in EmberZNet v9.0.2 |
| CVE-2026-47146 | 7.1 | 16.5 | Silicon Labs | EmberZNet | CWE-617 | Color Control color-temperature assertion abort in EmberZNet v9.0.2 |
| CVE-2026-47148 | 7.1 | 16.5 | Silicon Labs | EmberZNet | CWE-125 | Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2 |
| CVE-2026-47149 | 7.1 | 16.5 | Silicon Labs | EmberZNet | CWE-125 | Door Lock GetUserType invalid table index in EmberZNet v9.0.2 |
| CVE-2026-47152 | 7.1 | 16.5 | Silicon Labs | EmberZNet | CWE-369 | Level Control Move divide-by-zero in EmberZNet v9.0.2 |
| CVE-2026-47153 | 7.1 | 16.5 | Silicon Labs | EmberZNet | CWE-369 | Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2 |
| CVE-2026-47154 | 7.1 | 16.5 | Silicon Labs | EmberZNet | CWE-125 | Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2 |
| CVE-2026-56789 | 7.1 | 16.5 | tomojitakasu | RTKLIB | CWE-122 | RTKLIB 2.4.3 - Heap Buffer Overflow and Stack Read via Oversized RINEX Epoch … |
| CVE-2026-53256 | 8.0 | 16.4 | Linux | Linux | CWE-416 | Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() |
| CVE-2026-57533 | 2.1 | 16.4 | pretix | pretix | CWE-80 | Malicious HTML content could be injected into the page pretix shows when redi… |
| CVE-2026-54033 | 6.5 | 16.1 | danny-avila | LibreChat | CWE-918 | LibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP val… |
| CVE-2026-9718 | 6.9 | 15.8 | Schneider Electric | PowerLogic™ P7 | CWE-617 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenti… |
| CVE-2026-12993 | 6.5 | 15.8 | Red Hat | Red Hat build of Apicurio Registry 3 | CWE-776 | Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of… |
| CVE-2026-9222 | 9.2 | 15.6 | Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | CWE-836 | Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of pa… |
| CVE-2026-53146 | 7.1 | 15.6 | Linux | Linux | — | thunderbolt: Limit XDomain response copy to actual frame size |
| CVE-2026-9650 | 8.7 | 15.3 | Schneider Electric | EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller | CWE-522 | CWE-522 Insufficiently Protected Credentials vulnerability that could cause u… |
| CVE-2026-49319 | 6.9 | 15.3 | Alps Electric Co., Ltd. | Remote Keyless Entry System (RKES) R53R0 | CWE-294 | Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack |
| CVE-2026-54828 | 7.5 | 15.1 | StylemixThemes | Motors | CWE-862 | WordPress Motors plugin <= 1.4.109 - Broken Access Control vulnerability |
| CVE-2026-54830 | 7.5 | 15.1 | Etoile Web Design Incorporated | Five Star Restaurant Reservations | CWE-862 | WordPress Five Star Restaurant Reservations plugin <= 2.7.19 - Broken Access … |
| CVE-2026-54844 | 7.5 | 15.1 | CheckView | CheckView Automated Testing | CWE-862 | WordPress CheckView Automated Testing plugin <= 2.1.0 - Broken Access Control… |
| CVE-2026-56013 | 6.5 | 14.7 | myCred | License Manager for WooCommerce | CWE-639 | WordPress License Manager for WooCommerce plugin <= 3.0.15 - Insecure Direct … |
| CVE-2026-2508 | 6.5 | 14.5 | GravityMore | Gravity Bookings | CWE-89 | Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL I… |
| CVE-2026-12975 | 8.5 | 14.5 | Red Hat | Red Hat build of Apicurio Registry 3 | CWE-611 | Apicurio/apicurio-registry: apicurio-registry: unhardened saxparser in conten… |
| CVE-2026-53275 | 8.8 | 14.3 | Linux | Linux | CWE-416 | ipv6: mcast: Fix use-after-free when processing MLD queries |
| CVE-2026-9220 | 8.7 | 14.3 | Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | CWE-321 | Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key |
| CVE-2026-12473 | 8.3 | 14.3 | Open Health Imaging Foundation (OHIF) | DICOM Web Viewer Framework | CWE-918 | OHIF Viewers DICOM Server-Side request forgery |
| CVE-2026-46608 | 7.4 | 14.3 | nicolargo | glances | CWE-183 | Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildc… |
| CVE-2026-47147 | 7.1 | 14.1 | Silicon Labs | EmberZNet | CWE-125 | OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2 |
| CVE-2026-56014 | 7.1 | 14.1 | Averta | Master Slider | CWE-79 | WordPress Master Slider plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-56042 | 7.1 | 14.1 | Algolplus | Advanced Order Export For WooCommerce | CWE-79 | WordPress Advanced Order Export For WooCommerce plugin <= 4.0.9 - Cross Site … |
| CVE-2026-56051 | 7.1 | 14.1 | TablePress | TablePress | CWE-79 | WordPress TablePress plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) v… |
| CVE-2026-56071 | 7.1 | 14.1 | WPMU DEV | Forminator | CWE-79 | WordPress Forminator plugin <= 1.53.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-54843 | 9.3 | 14.0 | PluginUs.Net | MDTF | CWE-89 | WordPress MDTF plugin <= 1.3.7 - SQL Injection vulnerability |
| CVE-2026-54849 | 9.3 | 14.0 | Premmerce | Premmerce Wishlist for WooCommerce | CWE-89 | WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.11 - SQL Injection… |
| CVE-2026-13283 | 7.5 | 13.9 | Chrome | CWE-416 | Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.20… | |
| CVE-2026-40082 | 5.4 | 13.9 | Cacti | cacti | CWE-384 | Cacti: Session Fixation via missing session_regenerate_id() after login |
| CVE-2026-12340 | 6.3 | 13.6 | wolfSSL | wolfSSL | CWE-125 | Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computa… |
| CVE-2026-56130 | 2.0 | 13.3 | Apache Software Foundation | Apache Shiro | CWE-294 | Apache Shiro: Remember-me cookie isn't checked for expiry on the server |
| CVE-2026-1606 | 4.3 | 13.2 | GitLab | GitLab | CWE-94 | Improper Control of Generation of Code ('Code Injection') in GitLab |
| CVE-2026-11310 | 8.7 | 12.7 | wolfSSL | wolfSSL | CWE-295 | X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermed… |
| CVE-2026-11999 | 8.2 | 12.7 | wolfSSL | wolfSSL | CWE-295 | X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert() |
| CVE-2026-55960 | 8.2 | 12.7 | wolfSSL | wolfSSL | CWE-295 | Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing… |
| CVE-2026-47150 | 7.1 | 12.4 | Silicon Labs | EmberZNet | CWE-787 | IAS Zone enroll invalid table index and write in EmberZNet 9.0.2 |
| CVE-2026-47151 | 7.1 | 12.4 | Silicon Labs | EmberZNet | CWE-787 | Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2 |
| CVE-2026-12079 | 6.5 | 12.4 | wedevs | Dokan Pro | CWE-89 | Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' … |
| CVE-2026-54027 | 6.5 | 12.3 | danny-avila | LibreChat | CWE-862 | LibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fi… |
| CVE-2026-56769 | 6.3 | 12.3 | hcengineering | platform | CWE-918 | Huly Platform - Server-Side Request Forgery via /import Endpoint |
| CVE-2026-8662 | 4.3 | 12.3 | Rapid7 | InsightConnect Compression Plugin | CWE-22 | Path Traversal in Rapid7 InsightConnect Compression Plugin |
| CVE-2026-12755 | 2.7 | 12.2 | Devolutions | Server | CWE-1284 | Improper input validation in the PAM AD discovery endpoints in Devolutions Se… |
| CVE-2026-37149 | 7.7 | 12.2 | n/a | n/a | CWE-89 | GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was disco… |
| CVE-2026-56790 | 7.0 | 12.2 | canboat | canboat | CWE-193 | CANBoat - Off-by-One Global Buffer Overflow in searchForPgn() |
| CVE-2026-11703 | 6.0 | 11.6 | wolfSSL | wolfSSL | CWE-287 | Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption |
| CVE-2026-6092 | 2.1 | 11.3 | wolfSSL | wolfSSL | CWE-757 | Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_M… |
| CVE-2026-9702 | 7.5 | 11.2 | Unknown | InPost PL | — | InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking |
| CVE-2026-53178 | 8.1 | 10.8 | Linux | Linux | CWE-191 | staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction |
| CVE-2026-53264 | 7.8 | 10.8 | Linux | Linux | CWE-416 | net/sched: act_api: use RCU with deferred freeing for action lifecycle |
| CVE-2026-42390 | 5.3 | 10.8 | PowerDNS | Recursor | CWE-20 | ZONEMD validation can be bypassed |
| CVE-2026-40208 | 3.7 | 10.8 | PowerDNS | DNSdist | CWE-705 | Denial of service via DoH3 queries |
| CVE-2026-56771 | 6.3 | 10.6 | samuelclay | NewsBlur | CWE-918 | NewsBlur < 14.5.0 - Server-Side Request Forgery via add_url Endpoint |
| CVE-2026-56772 | 5.3 | 10.7 | samuelclay | NewsBlur | CWE-639 | NewsBlur < 14.5.0 - Insecure Direct Object Reference in Social Interactions E… |
| CVE-2026-9219 | 8.3 | 10.6 | Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | CWE-340 | Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers … |
| CVE-2026-56023 | 5.4 | 10.6 | Knit Pay | UPI QR Code Payment Gateway for WooCommerce | CWE-862 | WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.6.2 - Broke… |
| CVE-2026-0934 | 3.8 | 10.3 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-48945 | 5.3 | 9.8 | getk2.org | K2 extension for Joomla | CWE-434 | Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension f… |
| CVE-2026-5952 | 4.3 | 9.6 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-54842 | 8.1 | 9.5 | Royal Plugins | Royal MCP | CWE-862 | WordPress Royal MCP plugin <= 1.4.25 - Broken Access Control vulnerability |
| CVE-2026-54829 | 7.5 | 9.5 | Jacob N. Breetvelt | WP Photo Album Plus | CWE-89 | WordPress WP Photo Album Plus plugin <= 9.1.13.005 - SQL Injection vulnerability |
| CVE-2026-55412 | 8.3 | 9.3 | ToolJet | ToolJet | CWE-918 | ToolJet Cloud - SSRF to Azure Cloud Infrastructure Compromise |
| CVE-2026-54093 | 6.8 | 9.3 | filebrowser | filebrowser | CWE-22 | File Browser: Path traversal in download-as-zip/tar via Windows-style backsla… |
| CVE-2026-5796 | 4.3 | 9.3 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-40080 | 6.1 | 9.2 | Cacti | cacti | CWE-601 | Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect |
| CVE-2026-28898 | 5.3 | 9.2 | Apple | swift-nio-http2 | CWE-116 | swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header val… |
| CVE-2026-56050 | 6.5 | 9.0 | Themeisle | PPOM for WooCommerce | CWE-284 | WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vuln… |
| CVE-2026-6678 | 1.0 | 9.0 | wolfSSL | wolfSSL | CWE-191 | Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info |
| CVE-2026-11379 | 5.3 | 8.7 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-12992 | 7.4 | 8.6 | Red Hat | Red Hat build of Apicurio Registry 3 | CWE-918 | Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import derefer… |
| CVE-2025-60464 | 7.8 | 8.5 | n/a | n/a | CWE-416 | A use-after-free in the gf_sei_load_from_state_internal function (/filters/se… |
| CVE-2026-54848 | 8.3 | 8.1 | Saad Iqbal | APIExperts Square for WooCommerce | CWE-201 | WordPress APIExperts Square for WooCommerce plugin <= 4.7.3 - Sensitive Data … |
| CVE-2026-48943 | 6.5 | 8.0 | getk2.org | K2 extension for Joomla | CWE-915 | Joomla Extension - getk2.org - Authenticated user property mass-assignment in… |
| CVE-2026-54029 | 6.5 | 8.1 | danny-avila | LibreChat | CWE-862 | LibreChat: IDOR in Message Deletion — Incomplete Fix for CVE-2024-41703 Leave… |
| CVE-2026-3176 | 3.1 | 8.1 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-11800 | 8.1 | 7.9 | Red Hat | Red Hat build of Keycloak 26.6 | CWE-347 | Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algor… |
| CVE-2026-6450 | 1.0 | 7.8 | wolfSSL | wolfSSL | CWE-295 | CRL critical extension bypass in ParseCRL_Extensions |
| CVE-2026-13281 | 8.3 | 7.6 | Chrome | CWE-472 | Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a r… | |
| CVE-2026-54040 | 7.1 | 7.6 | danny-avila | LibreChat | CWE-306 | LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA B… |
| CVE-2026-13083 | 6.9 | 7.4 | Red Hat | Pen Drive Powered by Red Hat Lightspeed | CWE-79 | Pen-drive: pen-drive: stored xss via unescaped cluster data in html report |
| CVE-2026-54096 | 8.4 | 7.2 | filebrowser | filebrowser | CWE-863 | File Browser: Improper Access Control Occurs via Pre-Created Public Share for… |
| CVE-2026-56006 | 7.1 | 7.2 | H5P | H5P | CWE-79 | WordPress H5P plugin <= 1.17.6 - Reflected Cross Site Scripting (XSS) vulnera… |
| CVE-2026-42389 | 5.3 | 7.3 | PowerDNS | Recursor | CWE-20 | Reject more queries with invalid header values |
| CVE-2026-6325 | 2.0 | 7.3 | wolfSSL | wolfSSL | CWE-787 | Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms… |
| CVE-2026-55697 | 8.8 | 7.1 | pnpm | pnpm | CWE-78 | pnpm: Repository-controlled configDependencies can select a pacquet native in… |
| CVE-2026-50021 | 8.1 | 7.1 | pnpm | pnpm | CWE-354 | pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field |
| CVE-2026-5309 | 5.4 | 6.9 | GitLab | GitLab | CWE-639 | Authorization Bypass Through User-Controlled Key in GitLab |
| CVE-2025-60465 | 6.1 | 6.9 | n/a | n/a | CWE-416 | A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter… |
| CVE-2026-7511 | 5.9 | 6.8 | wolfSSL | wolfSSL | CWE-347 | PKCS7_verify signer confusion allows forged signatures to be accepted |
| CVE-2026-56779 | 5.3 | 6.9 | 1Panel-dev | MaxKB | CWE-918 | MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and down… |
| CVE-2026-13350 | 2.3 | 6.7 | pretix | Venueless | CWE-639 | Permissions where checked incorrectly during room creation, allowing attacker… |
| CVE-2026-48946 | 6.3 | 6.5 | getk2.org | K2 extension for Joomla | CWE-434 | Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension f… |
| CVE-2020-37256 | 5.1 | 6.4 | Grav | Grav | CWE-79 | Grav - Cross-Site Scripting in Admin Plugin Page Editor |
| CVE-2026-48940 | 3.4 | 6.4 | getk2.org | K2 extension for Joomla | CWE-79 | Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26 |
| CVE-2026-9799 | 4.6 | 6.3 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-639 | Keycloak: keycloak: unauthorized access to resources via uma permission ticke… |
| CVE-2026-57234 | 2.6 | 6.3 | sparklemotion | nokogiri | CWE-178 | Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, byp… |
| CVE-2026-10824 | 6.5 | 6.1 | Unknown | Masteriyo LMS | — | Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion |
| CVE-2026-55487 | 8.8 | 5.8 | pnpm | pnpm | CWE-346 | pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle |
| CVE-2026-13282 | 6.8 | 5.9 | Chrome | CWE-416 | Use after free in Payments in Google Chrome on Android prior to 149.0.7827.20… | |
| CVE-2026-54025 | 5.4 | 5.9 | danny-avila | LibreChat | CWE-79 | LibreChat: Stored XSS via unescaped image alt text in markdown artifact preview |
| CVE-2026-9221 | 8.7 | 5.7 | Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | CWE-327 | Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptogra… |
| CVE-2026-10097 | 8.3 | 5.7 | wolfSSL | wolfSSL | CWE-697 | ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break… |
| CVE-2026-48995 | 4.8 | 5.7 | pnpm | pnpm | CWE-353 | pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile |
| CVE-2026-12635 | 3.1 | 5.8 | GitLab | GitLab | CWE-350 | Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab |
| CVE-2026-6329 | 6.0 | 5.7 | wolfSSL | wolfSSL | CWE-347 | PKCS#12 MAC verification uses attacker-controlled comparison length |
| CVE-2026-2815 | 8.4 | 5.6 | Silicon Labs | SiSDK | CWE-339 | Incorrect use of the PUF key for user key generation in EFR32xG27 results in … |
| CVE-2026-40941 | 7.1 | 5.5 | Cacti | cacti | CWE-347 | Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages |
| CVE-2026-48941 | 6.5 | 5.6 | getk2.org | K2 extension for Joomla | CWE-862 | Joomla Extension - getk2.org - Unauthenticated folder delete in K2 extension … |
| CVE-2026-12490 | 8.2 | 5.3 | NLnet Labs | NSD | CWE-284 | Bypass of client certificate verification with transfer over TLS |
| CVE-2026-42004 | 3.7 | 5.2 | PowerDNS | DNSdist | CWE-115 | EDNS options smuggling |
| CVE-2026-50573 | 8.1 | 5.1 | pnpm | pnpm | CWE-345 | pnpm: Unsafe default behavior breaks integrity check |
| CVE-2026-7532 | 5.7 | 5.1 | wolfSSL | wolfSSL | CWE-295 | iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined |
| CVE-2026-45188 | 2.4 | 5.2 | Apache Software Foundation | Apache Kvrocks | CWE-23 | Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename … |
| CVE-2026-40011 | 3.7 | 4.9 | PowerDNS | DNSdist | CWE-116 | Prometheus denial of service via crafted DNS queries |
| CVE-2026-6291 | 6.0 | 4.9 | wolfSSL | wolfSSL | CWE-208 | Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption |
| CVE-2026-55895 | 5.7 | 4.9 | vim | vim | CWE-78 | Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename |
| CVE-2026-53212 | 7.8 | 4.8 | Linux | Linux | CWE-416 | netfilter: nft_tunnel: fix use-after-free on object destroy |
| CVE-2026-53202 | 7.8 | 4.6 | Linux | Linux | CWE-674 | accel/ivpu: Fix signed integer truncation in IPC receive |
| CVE-2026-13318 | 6.4 | 4.7 | Red Hat | Red Hat OpenShift Virtualization 4 | CWE-918 | Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalid… |
| CVE-2026-48942 | 6.1 | 4.6 | getk2.org | K2 extension for Joomla | CWE-79 | Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26 |
| CVE-2026-53194 | 7.8 | 4.5 | Linux | Linux | CWE-787 | USB: serial: kl5kusb105: fix bulk-out buffer overflow |
| CVE-2026-49839 | 7.1 | 4.6 | jqlang | jq | CWE-787 | jq --rawfile invalid-state reuse after String too long causes heap-buffer-ove… |
| CVE-2026-6331 | 2.1 | 4.5 | wolfSSL | wolfSSL | CWE-347 | HMAC zero-length tag forgery in EVP_DigestVerifyFinal |
| CVE-2026-47770 | 6.8 | 4.5 | jqlang | jq | CWE-674 | jq: stack overflow in deep structural equality |
| CVE-2026-55961 | 8.2 | 4.4 | wolfSSL | wolfSSL | CWE-347 | wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 wit… |
| CVE-2026-57456 | 8.4 | 4.3 | vim | vim | CWE-94 | Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings |
| CVE-2026-56788 | 4.8 | 4.2 | tomojitakasu | RTKLIB | CWE-125 | RTKLIB 2.4.3 - Out-of-bounds Read via Negative Array Index in getcodepri |
| CVE-2026-53137 | 7.8 | 4.2 | Linux | Linux | CWE-787 | drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size |
| CVE-2026-53143 | 7.8 | 4.1 | Linux | Linux | CWE-787 | drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 |
| CVE-2026-53195 | 7.8 | 4.1 | Linux | Linux | CWE-787 | USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() |
| CVE-2026-53203 | 7.1 | 4.1 | Linux | Linux | CWE-787 | accel/ivpu: Add buffer overflow check in MS get_info_ioctl |
| CVE-2026-55962 | 6.0 | 4.1 | wolfSSL | wolfSSL | CWE-287 | TLS 1.3 post-handshake authentication: server accepts Finished without client… |
| CVE-2026-46606 | 7.8 | 4.0 | nicolargo | glances | CWE-78 | Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vm… |
| CVE-2026-53193 | 7.8 | 3.9 | Linux | Linux | CWE-416 | ALSA: timer: Forcibly close timer instances at closing |
| CVE-2026-57453 | 7.3 | 3.9 | vim | vim | CWE-77 | Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction |
| CVE-2026-53132 | 7.1 | 3.7 | Linux | Linux | CWE-401 | vsock/virtio: fix potential unbounded skb queue |
| CVE-2026-53925 | 7.8 | 3.6 | nicolargo | glances | CWE-22 | Glances: Arbitrary file write and command execution via `secure_popen` redire… |
| CVE-2026-53148 | 7.8 | 3.4 | Linux | Linux | CWE-787 | thunderbolt: Clamp XDomain response data copy to allocation size |
| CVE-2026-6330 | 6.3 | 3.4 | wolfSSL | wolfSSL | CWE-327 | ML-KEM ARM64 NEON ciphertext comparison only compares half of the input |
| CVE-2026-12897 | 8.4 | 3.3 | Horner Automation | Cscape | CWE-125 | Out-of-bounds read in Horner Automation Cscape |
| CVE-2026-53234 | 7.8 | 3.2 | Linux | Linux | CWE-416 | net: ibm: emac: Fix use-after-free during device removal |
| CVE-2026-53227 | 5.5 | 3.1 | Linux | Linux | CWE-401 | net: openvswitch: fix possible kfree_skb of ERR_PTR |
| CVE-2026-53252 | 5.5 | 3.1 | Linux | Linux | CWE-401 | Bluetooth: fix memory leak in error path of hci_alloc_dev() |
| CVE-2026-8330 | 4.4 | 3.1 | GitLab | GitLab | CWE-532 | Insertion of Sensitive Information into Log File in GitLab |
| CVE-2026-54030 | 9.3 | 3.0 | danny-avila | LibreChat | CWE-346 | LibreChat: Missing Resource Parameter Validation in MCP OAuth Flow |
| CVE-2026-46607 | 7.8 | 3.0 | nicolargo | glances | CWE-502 | Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary … |
| CVE-2026-53133 | 7.8 | 3.0 | Linux | Linux | CWE-681 | RDMA/umem: Fix truncation for block sizes >= 4G |
| CVE-2026-53136 | 7.8 | 3.0 | Linux | Linux | CWE-787 | drm/amd/display: Clamp VBIOS HDMI retimer register count to array size |
| CVE-2026-53182 | 7.8 | 3.0 | Linux | Linux | — | wifi: nl80211: reject oversized EMA RNR lists |
| CVE-2026-53189 | 7.8 | 3.0 | Linux | Linux | — | mm/huge_memory: update file PMD counter before folio_put() |
| CVE-2026-53191 | 7.8 | 2.9 | Linux | Linux | — | io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries |
| CVE-2026-53209 | 7.8 | 3.0 | Linux | Linux | CWE-787 | Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend |
| CVE-2026-53233 | 7.8 | 2.9 | Linux | Linux | CWE-415 | netdev: fix double-free in netdev_nl_bind_rx_doit() |
| CVE-2026-53242 | 7.8 | 3.0 | Linux | Linux | CWE-476 | ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams |
| CVE-2026-53159 | 5.5 | 3.0 | Linux | Linux | — | misc: fastrpc: fix DMA address corruption due to find_vma misuse |
| CVE-2026-53170 | 8.8 | 2.9 | Linux | Linux | CWE-908 | accel/ethosu: reject DMA commands with uninitialized length |
| CVE-2026-53171 | 8.8 | 2.9 | Linux | Linux | — | accel/ethosu: fix arithmetic issues in dma_length() |
| CVE-2026-12921 | 8.4 | 2.9 | AzeoTech | DAQFactory | CWE-416 | Use after free in AzeoTech DAQFactory |
| CVE-2026-53201 | 7.8 | 2.9 | Linux | Linux | — | Revert "drm/xe: Skip exec queue schedule toggle if queue is idle during suspend" |
| CVE-2026-53188 | 8.8 | 2.8 | Linux | Linux | — | RDMA/core: Validate the passed in fops for ib_get_ucaps() |
| CVE-2026-53162 | 7.8 | 2.8 | Linux | Linux | — | memcg: use round-robin victim selection in refill_stock |
| CVE-2026-53157 | 7.8 | 2.7 | Linux | Linux | CWE-416 | net: phonet: free phonet_device after RCU grace period |
| CVE-2026-53160 | 7.8 | 2.7 | Linux | Linux | CWE-416 | misc: fastrpc: fix use-after-free race in fastrpc_map_create |
| CVE-2026-53161 | 7.8 | 2.7 | Linux | Linux | CWE-416 | misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context |
| CVE-2026-53239 | 7.8 | 2.7 | Linux | Linux | CWE-416 | xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() |
| CVE-2026-53138 | 7.1 | 2.7 | Linux | Linux | CWE-125 | drm/amd/display: Bound VBIOS record-chain walk loops |
| CVE-2026-53149 | 7.1 | 2.7 | Linux | Linux | CWE-125 | thunderbolt: Bound root directory content to block size |
| CVE-2026-53223 | 7.1 | 2.7 | Linux | Linux | — | net: guard timestamp cmsgs to real error queue skbs |
| CVE-2026-55411 | 6.8 | 2.7 | ToolJet | ToolJet | CWE-639 | ToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/… |
| CVE-2026-53230 | 8.7 | 2.6 | Linux | Linux | CWE-125 | net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list |
| CVE-2026-53156 | 7.8 | 2.6 | Linux | Linux | CWE-416 | nvmem: core: fix use-after-free bugs in error paths |
| CVE-2026-53192 | 7.8 | 2.6 | Linux | Linux | CWE-416 | ALSA: timer: Fix UAF at snd_timer_user_params() |
| CVE-2026-53179 | 7.1 | 2.6 | Linux | Linux | CWE-125 | staging: rtl8723bs: fix buffer over-read in rtw_update_protection |
| CVE-2026-53205 | 7.1 | 2.6 | Linux | Linux | CWE-787 | accel/ivpu: Add bounds checks for firmware log indices |
| CVE-2026-53167 | 5.5 | 2.6 | Linux | Linux | CWE-908 | fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios |
| CVE-2026-53187 | 7.1 | 2.5 | Linux | Linux | CWE-787 | RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc |
| CVE-2026-10592 | 6.3 | 2.5 | wolfSSL | wolfSSL | CWE-295 | Wildcard DNS SAN bypasses CA name-constraint checks |
| CVE-2026-6731 | 6.0 | 2.5 | wolfSSL | wolfSSL | CWE-295 | X.509 name constraint bypass via Subject CN treated as a DNS name |
| CVE-2026-55693 | 5.7 | 2.6 | vim | vim | CWE-787 | Vim: Out-of-bounds Write in Spell File Word Count |
| CVE-2026-4522 | 6.7 | 2.5 | HYPR | Passwordless | CWE-306 | Missing authentication for critical function vulnerability in HYPR Passwordle… |
| CVE-2026-53134 | 5.5 | 2.5 | Linux | Linux | CWE-401 | netfilter: nft_fib: fix stale stack leak via the OIFNAME register |
| CVE-2026-53135 | 5.5 | 2.5 | Linux | Linux | CWE-476 | drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs |
| CVE-2026-53139 | 5.5 | 2.5 | Linux | Linux | — | drm/v3d: Skip CSD when it has zeroed workgroups |
| CVE-2026-53150 | 5.5 | 2.4 | Linux | Linux | CWE-191 | thunderbolt: Reject zero-length property entries in validator |
| CVE-2026-53158 | 5.5 | 2.4 | Linux | Linux | CWE-476 | misc: fastrpc: Fix NULL pointer dereference in rpmsg callback |
| CVE-2026-53163 | 5.5 | 2.5 | Linux | Linux | CWE-476 | locking/rtmutex: Skip remove_waiter() when waiter is not enqueued |
| CVE-2026-53168 | 5.5 | 2.4 | Linux | Linux | — | fuse: reject fuse_notify() pagecache ops on directories |
| CVE-2026-53177 | 5.5 | 2.4 | Linux | Linux | CWE-476 | bnxt_en: Fix NULL pointer dereference |
| CVE-2026-53181 | 5.5 | 2.4 | Linux | Linux | CWE-401 | vsock/vmci: fix sk_ack_backlog leak on failed handshake |
| CVE-2026-53208 | 5.5 | 2.4 | Linux | Linux | — | Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig |
| CVE-2026-53213 | 5.5 | 2.4 | Linux | Linux | CWE-401 | drm/vc4: fix krealloc() memory leak |
| CVE-2026-53218 | 5.5 | 2.4 | Linux | Linux | CWE-908 | netfilter: nft_exthdr: fix register tracking for F_PRESENT flag |
| CVE-2026-53219 | 5.5 | 2.4 | Linux | Linux | — | netfilter: x_tables: avoid leaking percpu counter pointers |
| CVE-2026-53236 | 5.5 | 2.4 | Linux | Linux | — | tcp: restrict SO_ATTACH_FILTER to priv users |
| CVE-2026-53238 | 5.5 | 2.4 | Linux | Linux | — | netlabel: validate unlabeled address and mask attribute lengths |
| CVE-2026-53245 | 5.5 | 2.4 | Linux | Linux | — | net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr |
| CVE-2026-53249 | 5.5 | 2.4 | Linux | Linux | — | ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options |
| CVE-2026-54250 | 5.8 | 2.4 | k3s-io | k3s | CWE-22 | K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression |
| CVE-2026-53140 | 5.5 | 2.3 | Linux | Linux | CWE-401 | drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups |
| CVE-2026-53142 | 5.5 | 2.3 | Linux | Linux | CWE-908 | drm/xe/display: fix oops in suspend/shutdown without display |
| CVE-2026-53144 | 5.5 | 2.3 | Linux | Linux | CWE-476 | drm/amdkfd: fix NULL dereference in get_queue_ids() |
| CVE-2026-53152 | 5.5 | 2.4 | Linux | Linux | CWE-476 | mmc: dw_mmc-rockchip: Add missing private data for very old controllers |
| CVE-2026-53154 | 5.5 | 2.3 | Linux | Linux | CWE-772 | mm/hugetlb: restore reservation on error in hugetlb folio copy paths |
| CVE-2026-53190 | 5.5 | 2.4 | Linux | Linux | — | drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() |
| CVE-2026-53210 | 5.5 | 2.4 | Linux | Linux | CWE-401 | tee: shm: fix shm leak in register_shm_helper() |
| CVE-2026-53214 | 5.5 | 2.4 | Linux | Linux | CWE-476 | ipv6: Fix a potential NPD in cleanup_prefix_route() |
| CVE-2026-53220 | 5.5 | 2.4 | Linux | Linux | CWE-476 | netfilter: revalidate bridge ports |
Results continue: ranks 401–468.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-25 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.