boxscore/security
Friday, June 26, 2026 · all times UTC← 2026-06-25 · archive · 2026-06-27 →

353 CVEs published June 26, 2026: 47 critical, 147 high, 152 medium, 7 low; 0 in KEV; 39 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 328 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published69961136811762563
KEV catalog size1670

506 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux513147911985450312730.27.8.0013+284
google70788185464300297460.78.1.0023+691
microsoft220710554741604378273.87.8.0044+56
red hat108172973828400.06.8.0026+92
apple156201637293711.35.5.0023-5
canonical6202585000.05.5.0011+6
freebsd290630000.07.8.0019-5
suse461410000.08.6.0029+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco10234480961147.87.0.0431+5
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
ubiquiti81174004327.39.9.0083+6
f56943107111.18.9.0221+4
ivanti49230033555.68.8.5187+2
checkpoint3915303111.17.5.0410-3
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache104136224756104010.77.0.0044+85
mozilla495511182601300.07.3.0026+43
gitlab243305215426.14.4.0022+24
docker470520100.08.2.0016+1
drupal0511305120.05.1.0026-3
github131110000.07.0.00390
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1321364507727532.25.5.0021+131
ibm32811935270700.07.5.0028+12
progress591710900.07.5.0036+1
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp131110000.08.4.0170-1
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+8
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb660420000.07.2.0018+6
schneider electric660420100.07.8.0024+6
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+71
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+17
themerex585855300000.08.1.0043+58
dell3856130240211.87.2.0016+26
edimax556033023100.07.4.0070-39
jenkins project364909391000.04.8.0021+36
capgo4646222211000.07.0.0034+46

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5357610.0.0219
CVE-2026-4977710.0.0166
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4925710.0.0093
Most disclosures (vendor)
VendorCVEs
google858
linux649
oracle268
microsoft220
adobe132
red hat128
apache106
spring72
openclaw67
themerex58
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco11
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven41
Packagist22
PyPI9
npm5
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-48595Google0
CVE-2025-67038Lantronix0
CVE-2026-0257Palo Alto Networks0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171682
CVE-2021-27102Accellion2021-11-171682
CVE-2021-27101Accellion2021-11-171682
CVE-2021-27103Accellion2021-11-171682
CVE-2021-21017Adobe2021-11-171682
CVE-2021-28550Adobe2021-11-171682
CVE-2021-42013Apache2021-11-171682
CVE-2021-41773Apache2021-11-171682
CVE-2021-30858Apple2021-11-171682
CVE-2021-30860Apple2021-11-171682

Transactions

EXPLOIT PUBLISHEDCVE-2026-12411 (Canonical lxd). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-28385 (Canonical lxd). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45807 (kestra-io kestra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47204 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47205 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47207 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47220 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47221 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47775 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47778 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48042 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48044 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48090 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48743 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48770 (notepad-plus-plus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48778 (notepad-plus-plus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48800 (notepad-plus-plus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49869 (kestra-io kestra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49984 (kestra-io kestra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50132 (budibase). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50136 (budibase). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50137 (budibase). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50765. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50766. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50767. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52884 (notepad-plus-plus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-52885 (notepad-plus-plus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53576 (kestra-io kestra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53577 (kestra-io kestra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54350 (budibase). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54351 (budibase). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54352 (budibase). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54353 (budibase). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55069 (kestra-io kestra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55686 (podman-container-tools podman). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56876 (max-mapper extract-zip). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57920 (Peplink InControl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-9639 (Canonical LXD). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-9640 (Canonical LXD). Public exploit reference added.

Yesterday's Results

353 CVEs published. 25 box scores, 328 table rows — nothing truncated.

Revive Adserver — Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offse…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0446   90.6     —
AFFECTED
  Product   Versions     Fixed
  Adserver  unspecified  —
TIMELINE
  Jun 6   Reserved by CNA
  Jun 26  Published (CNA: hackerone)
CWE-94 · CNA: hackerone · 2 references · NVD status: Analyzed
nodejs node — A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a mu…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0371   88.8     —
AFFECTED
  Product  Versions   Fixed
  node     22.22.3 –  —
TIMELINE
  May 26  Reserved by CNA
  Jun 26  Published (CNA: hackerone)
CWE-190, CWE-770 · CNA: hackerone · 17 references · NVD status: Modified
nodejs node — A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0323   87.2     —
AFFECTED
  Product  Versions   Fixed
  node     22.22.3 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 26  Published (CNA: hackerone)
CWE-176, CWE-289 · CNA: hackerone · 17 references · NVD status: Modified
kestra-io kestra — Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0219   80.9     —
AFFECTED
  Product  Versions    Fixed
  kestra   < 1.0.45 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jun 26  Public exploit reference published
  Jun 26  Published (CNA: GitHub_M)
CWE-94, CWE-288 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0144   71.0     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-476 · CNA: GV · 1 reference · NVD status: Deferred
Unknown YMC Filter — YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0135   69.1     —
AFFECTED
  Product     Versions     Fixed
  YMC Filter  unspecified  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 26  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Deferred
Shenzhen Cudy Technology Co., Ltd. LT300 3.0 — Cudy LT300 3.0 OS Command Injection via NTP Configuration
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0134   68.9     —
AFFECTED
  Product    Versions     Fixed
  LT300 3.0  unspecified  —
TIMELINE
  Mar 16  Reserved by CNA
  Jun 26  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Deferred
notepad-plus-plus notepad-plus-plus — Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0131   68.3     —
AFFECTED
  Product            Versions     Fixed
  notepad-plus-plus  < 8.9.6.1 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 26  Public exploit reference published
  Jun 26  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 2 references · NVD status: Analyzed
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0100   60.1     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-22 · CNA: GV · 1 reference · NVD status: Deferred
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  H  H  H    8.0   .0095   58.4     —
AFFECTED
  Product                    Versions     Fixed
  Container Storage Modules  unspecified  —
TIMELINE
  Apr 15  Reserved by CNA
  Jun 26  Published (CNA: dell)
CWE-78 · CNA: dell · 1 reference · NVD status: Awaiting Analysis
kestra-io kestra — Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0089   56.5     —
AFFECTED
  Product  Versions    Fixed
  kestra   < 1.0.45 –  —
TIMELINE
  Jun 1   Reserved by CNA
  Jun 26  Public exploit reference published
  Jun 26  Published (CNA: GitHub_M)
CWE-78, CWE-184, CWE-287, CWE-918 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
nrwl nx — Nx: `nx graph` dev server permissive CORS policy
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  U  H  L  N    5.9   .0081   54.0     —
AFFECTED
  Product  Versions               Fixed
  nx       >= 17.0.4, < 22.7.2 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 26  Published (CNA: GitHub_M)
CWE-749, CWE-942 · CNA: GitHub_M · 2 references · NVD status: Deferred
Edgewall *Genshi* Genshi — Server side template inject (SSTI) in Edgewall Genshi Template Engine
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.1     —
AFFECTED
  Product  Versions     Fixed
  Genshi   unspecified  —
TIMELINE
  Jan 7   Reserved by CNA
  Jun 26  Published (CNA: certcc)
CNA: certcc · 2 references · NVD status: Awaiting Analysis
nodejs node — A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could l…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0064   47.7     —
AFFECTED
  Product  Versions   Fixed
  node     22.22.3 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 26  Published (CNA: hackerone)
CWE-400 · CNA: hackerone · 1 reference · NVD status: Analyzed
Daktronics Controller Firmware Path Traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0063   47.4     —
AFFECTED
  Product       Versions     Fixed
  VFC-DMP-5000  unspecified  —
  DMP-5000      unspecified  —
  DMP-8000      unspecified  —
TIMELINE
  Mar 30  Reserved by CNA
  Jun 26  Published (CNA: icscert)
CWE-22 · CNA: icscert · 2 references · NVD status: Analyzed
Ollama AI Ollama — There exists an unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0055   43.5     —
AFFECTED
  Product  Versions   Fixed
  Ollama   v0.13.5 –  —
TIMELINE
  Apr 7   Reserved by CNA
  Jun 26  Published (CNA: certcc)
CWE-125 · CNA: certcc · 3 references · NVD status: Analyzed
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.4     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-121 · CNA: GV · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.4     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-121 · CNA: GV · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.4     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-121 · CNA: GV · 1 reference · NVD status: Deferred
n/a n/a — An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute a…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0052   41.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jun 26  Published (CNA: mitre)
CWE-400 · CNA: mitre · 2 references · NVD status: Deferred
BuddyBoss Buddyboss Platform — WordPress Buddyboss Platform plugin <= 3.0.4 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.2     —
AFFECTED
  Product             Versions  Fixed
  Buddyboss Platform  n/a –     3.0.5
TIMELINE
  Jun 18  Reserved by CNA
  Jun 26  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · 1 reference · NVD status: Deferred
Pagekit CMS 1.0.18 Privilege Escalation via UserApiController
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0048   39.3     —
AFFECTED
  Product  Versions     Fixed
  pagekit  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jun 26  Published (CNA: VulnCheck)
CWE-862 · CNA: VulnCheck · 2 references · NVD status: Deferred
Budibase: Anonymous NoSQL operator injection via published-app query templates
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0047   38.7     —
AFFECTED
  Product   Versions     Fixed
  budibase  < 3.39.12 –  —
TIMELINE
  Jun 12  Reserved by CNA
  Jun 26  Public exploit reference published
  Jun 26  Published (CNA: GitHub_M)
CWE-89, CWE-943 · CNA: GitHub_M · 1 reference · NVD status: Modified
zaproxy zap-extensions — ZAP ViewState Add-on Insecure Deserialization via JSFViewState.decode()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0046   38.2     —
AFFECTED
  Product         Versions     Fixed
  zap-extensions  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jun 26  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 5 references · NVD status: Awaiting Analysis
Safetica Endpoint Client — Kernel driver vulnerability in Safetica Endpoint Client
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0046   38.1     —
AFFECTED
  Product          Versions     Fixed
  Endpoint Client  10.5.75.0 –  —
  Endpoint Client  11.11.4.0 –  —
TIMELINE
  Jan 9   Reserved by CNA
  Jun 26  Published (CNA: certcc)
CNA: certcc · 2 references · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-458077.737.9kestra-iokestraCWE-22Kestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace fi…
CVE-2026-499847.737.9kestra-iokestraCWE-22Kestra: Path traversal in `LocalStorage` allows any authenticated user to rea…
CVE-2026-300406.537.6n/an/aCWE-122A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 al…
CVE-2026-386397.537.1n/an/aCWE-20An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6…
CVE-2026-386417.537.1n/an/aCWE-404An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows at…
CVE-2026-556777.535.9labstackechoCWE-22Echo: Encoded slash (%2F) bypasses route-level protection and exposes static …
CVE-2026-532847.535.5LinuxLinuxCWE-476btrfs: only release the dirty pages io tree after successful writes
CVE-2026-480905.935.6envoyproxyenvoyCWE-416Envoy HTTP: OAuth2 filter late async token completion after stream teardown (…
CVE-2026-472207.535.4envoyproxyenvoyCWE-476Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format
CVE-2026-486157.535.1nodejsnodeCWE-359A flaw in Node.js proxy tunnel error handling could expose proxy credentials …
CVE-2026-96396.535.1CanonicalLXDCWE-476Authenticated Denial of Service via Malicious Backup Tarball in LXD
CVE-2026-319289.334.6DaktronicsVFC-DMP-5000CWE-798Daktronics Controller Firmware Use of Hard-coded Credentials
CVE-2026-560579.834.5Uncanny OwlUncanny Automator ProCWE-502WordPress Uncanny Automator Pro plugin <= 7.3.0.6 - PHP Object Injection vuln…
CVE-2025-119199.633.2Wolfram Research Inc.CloudUnprotected temporary directories in Wolfram Cloud may result in privilege es…
CVE-2026-533099.833.1LinuxLinuxCWE-193ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
CVE-2026-543417.533.1dragonflydbdragonflyCWE-125Dragonfly: RESTORE operations may crash the server
CVE-2026-507394.332.5ReviveAdserverCWE-284A bypass for CVE‑2026‑34913 exists with proper ownership validation that had …
CVE-2026-568768.632.2max-mapperextract-zipCWE-22extract-zip unvalidated symlink path traversal
CVE-2026-83806.531.9UnknownFrontend File Manager PluginFrontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post Deletion
CVE-2026-364787.531.8n/an/aCWE-400An issue in Technitium DNS Server v.14.3 and before allows a remote attacker …
CVE-2026-336469.631.4jdxmiseCWE-94mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Tr…
CVE-2025-550179.131.4Apache Software FoundationApache IoTDBCWE-22Apache IoTDB: Path Traversal Vulnerability
CVE-2025-641529.131.4Apache Software FoundationApache IoTDBCWE-22Apache IoTDB: Path Traversal Vulnerability
CVE-2026-560558.831.1InspiryThemesRealHomesCWE-502WordPress RealHomes theme <= 4.5.3 - PHP Object Injection vulnerability
CVE-2026-560108.830.9Tyche Softwares.Abandoned Cart Pro for WooCommerceCWE-266WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Esc…
CVE-2026-578819.830.7GeoVision Inc.GV-LPCLPC2011/2211CWE-121GV-LPC2011/LPC2211 - unauthorized stack-based buffer overflow vulnerability (…
CVE-2026-487067.530.8envoyproxyenvoyCWE-120Envoy Heap Buffer Overflow in TcpStatsdSink
CVE-2026-556865.330.5podman-container-toolspodmanCWE-61Podman: WORKDIR symlink traversal vulnerability
CVE-2026-543529.630.4BudibasebudibaseCWE-22Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
CVE-2026-567738.730.2teableioteableCWE-862Teable - Missing Authorization in v2 REST API
CVE-2026-96407.229.7CanonicalLXDCWE-863LXD Snapshot Import Privilege Escalation Vulnerability
CVE-2026-480427.529.6envoyproxyenvoyCWE-1124Envoy: Stack overflow in destructor of highly nested JSON
CVE-2026-548259.329.4wpDataTableswpDataTablesCWE-89WordPress wpDataTables plugin <= 7.4 - SQL Injection vulnerability
CVE-2026-560289.829.1themewantEasy Elements for Elementor &#8211; Addons &amp; Website TemplatesCWE-266WordPress Easy Elements for Elementor – Addons & Website Templates plugin <= …
CVE-2026-488007.829.1notepad-plus-plusnotepad-plus-plusCWE-78Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection
CVE-2026-578767.528.7GeoVision Inc.GV-LPCLPC2011/2211CWE-787GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.…
CVE-2026-559758.628.4H.VIEWHV-500S6 IP CameraCWE-78H.VIEW HV-500S6 IP Camera OS Command Injection
CVE-2026-560589.928.2ThemeCatcherQuformCWE-434WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerability
CVE-2026-560599.928.2PhysCodeTravel BookingCWE-434WordPress Travel Booking theme <= 2.2.5 - Arbitrary File Upload vulnerability
CVE-2026-573158.528.1Creative ThemesBlocksy Companion ProCWE-94WordPress Blocksy Companion Pro plugin <= 2.1.45 - Remote Code Execution (RCE…
CVE-2025-102685.328.0UnknownPrintcart Web to Print Product Designer for WooCommercePrintcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenti…
CVE-2026-576287.627.8WP All ImportWP All ImportCWE-89WordPress WP All Import plugin <= 4.0.1 - SQL Injection vulnerability
CVE-2026-576317.627.8Ays ProPopup boxCWE-89WordPress Popup box plugin <= 6.0.1 - SQL Injection vulnerability
CVE-2026-573166.527.5RoxnorGetGenieCWE-497WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability
CVE-2026-573186.527.5Gemini LabsSite ReviewsCWE-201WordPress Site Reviews plugin <= 8.0.11 - Sensitive Data Exposure vulnerability
CVE-2026-466047.527.2golang.org/x/imagegolang.org/x/image/tiffCWE-787Panic decoding image with out-of-bounds strip offset in x/image/tiff in golan…
CVE-2026-116257.526.8DAVIDOBytes::Random::SecureCWE-335Bytes::Random::Secure versions through 0.29 for Perl share internal state acr…
CVE-2026-117027.526.8DAVIDOBytes::Random::Secure::TinyCWE-335Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal st…
CVE-2026-560665.826.5ShortPixelShortPixel Adaptive ImagesCWE-22WordPress ShortPixel Adaptive Images plugin <= 3.11.4 - Arbitrary File Deleti…
CVE-2026-543519.626.3BudibasebudibaseCWE-915Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automatio…
CVE-2026-335608.426.0DaktronicsVFC-DMP-5000CWE-434Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type
CVE-2026-472217.525.6envoyproxyenvoyCWE-476Envoy: Null pointer deref in internal redirects
CVE-2026-96996.825.4MattermostMattermostCWE-532Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication e…
CVE-2026-489309.825.2nodejsnodeCWE-284A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can …
CVE-2026-560309.824.9paytiumsupportPaytiumCWE-266WordPress Paytium plugin <= 5.0.2 - Privilege Escalation vulnerability
CVE-2026-560339.824.9Dokan Multivendor PluginDokan ProCWE-266WordPress Dokan Pro plugin <= 5.0.4 - Privilege Escalation vulnerability
CVE-2026-579157.324.9Apache Software FoundationApache KerbyCWE-304Apache Kerby: Kerberos Pre-Authentication Bypass
CVE-2026-480447.524.8envoyproxyenvoyCWE-409Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explo…
CVE-2026-560279.924.7PluggablBooster for WooCommerceCWE-434WordPress Booster for WooCommerce plugin <= 8.0.1 - Arbitrary File Upload vul…
CVE-2026-578747.524.6GeoVision Inc.GV-LPCLPC2011/2211CWE-120GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_up…
CVE-2026-507456.124.5ReviveAdserverCWE-79A missing sanitisation vulnerability exists with user input in the stats-vide…
CVE-2026-507405.424.3ReviveAdserverCWE-79A missing sanitisation vulnerability of user input in the zone-include.php sc…
CVE-2026-572317.523.9podman-container-toolspodmanCWE-200Podman: Malformed Image can trick podman run into leaking host environment va…
CVE-2026-535776.523.8kestra-iokestraCWE-863Kestra: Cross-Execution File Read via Preview Endpoint (IDOR)
CVE-2025-680637.523.7StylemixThemesSplash - Sport Club WordPress Theme for Basketball, Football, HockeyCWE-98WordPress Splash - Sport Club WordPress theme for Basketball, Football, Hocke…
CVE-2025-680647.523.7EverthemessGoya CoreCWE-98WordPress Goya Core plugin < 1.0.9.4 - Local File Inclusion vulnerability
CVE-2026-560318.123.4Uncanny OwlUncanny AutomatorCWE-502WordPress Uncanny Automator plugin <= 7.3.1.2 - PHP Object Injection vulnerab…
CVE-2026-548247.523.0Ads WPQuadsAds by WPQuadsCWE-497WordPress Ads by WPQuads plugin <= 3.0.3 - Sensitive Data Exposure vulnerability
CVE-2026-501378.222.7BudibasebudibaseCWE-862Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets…
CVE-2026-472047.522.7envoyproxyenvoyCWE-476Envoy: grpc_stats filter segfault on Connect protocol requests to direct_resp…
CVE-2026-494867.522.1Apache Software FoundationApache Airflow FTP providerCWE-319Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel …
CVE-2026-548347.521.9fpuenteonlineObject Cache 4 everyoneCWE-201WordPress Object Cache 4 everyone plugin <= 2.3.2 - Sensitive Data Exposure v…
CVE-2026-560607.521.9tychesoftwaresPrint Invoice & Delivery Notes for WooCommerceCWE-497WordPress Print Invoice & Delivery Notes for WooCommerce plugin <= 7.1.1 - Se…
CVE-2026-579146.521.9Apache Software FoundationApache KerbyCWE-400Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
CVE-2026-472076.521.8envoyproxyenvoyCWE-416Envoy crashes if multiple unexpected ext_proc responses are packed into one g…
CVE-2026-560697.521.6Site Building with ToolsetToolset FormsCWE-639WordPress Toolset Forms plugin <= 2.6.24 - Insecure Direct Object References …
CVE-2026-576325.421.6OmnisendEmail Marketing for WooCommerce by OmnisendCWE-862WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.19.0 - Brok…
CVE-2026-454058.821.4dokkudokkuCWE-59Dokku: Arbitrary File Write via Tar Symlink Traversal in git:from-archive and…
CVE-2026-548267.621.3PSM PluginsSupportCandyCWE-639WordPress SupportCandy plugin <= 3.4.6 - Insecure Direct Object References (I…
CVE-2026-548467.521.3akosglysSyncee Premium Dropshipping &amp; WholesaleCWE-862WordPress Syncee Premium Dropshipping & Wholesale plugin <= 1.0.27 - Broken A…
CVE-2026-447366.521.1opfopenprojectCWE-200OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Pr…
CVE-2026-560297.521.0corvuspayCorvusPay WooCommerce Payment GatewayCWE-288WordPress CorvusPay WooCommerce Payment Gateway plugin <= 2.7.4 - Broken Auth…
CVE-2026-573217.121.0icc0rzH5PCWE-22WordPress H5P plugin <= 1.17.7 - Arbitrary File Deletion vulnerability
CVE-2026-548209.320.8Crocoblock. Jetimpex Inc.JetBookingCWE-89WordPress JetBooking plugin <= 4.0.4.1 - SQL Injection vulnerability
CVE-2026-548279.320.8contempoincReal Estate 7CWE-89WordPress Real Estate 7 theme <= 3.5.9 - SQL Injection vulnerability
CVE-2026-548319.320.8PaoloGeoDirectoryCWE-89WordPress GeoDirectory plugin <= 2.8.162 - SQL Injection vulnerability
CVE-2026-560349.320.8Online Web TutorLibrary Management SystemCWE-89WordPress Library Management System plugin <= 3.5.7 - SQL Injection vulnerabi…
CVE-2026-472062.320.8dragonflydbdragonflyCWE-116Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer
CVE-2026-507425.420.7ReviveAdserverCWE-79A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `m…
CVE-2026-295095.320.6wummelpatoolCWE-22Patool < 4.0.5 Path Traversal via safe_extract() Function
CVE-2026-578778.620.6GeoVision Inc.GV-LPCLPC2011/2211CWE-134GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr)
CVE-2026-454068.820.5dokkudokkuCWE-95Dokku: Host RCE via Maliciously Named OpenResty Include Files Injected Throug…
CVE-2026-560088.820.2ThemeFusionFusion BuilderCWE-266WordPress Fusion Builder plugin <= 3.15.4 - Privilege Escalation vulnerability
CVE-2026-548377.520.3Syed BalkhiIntranet &amp; Private Site &#8211; All-In-One IntranetCWE-862WordPress Intranet & Private Site – All-In-One Intranet plugin <= 1.8.1 - Bro…
CVE-2026-548397.520.3kingaddonsTrinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule BackupsCWE-639WordPress Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups…
CVE-2026-548477.520.3DesignStylish Cost CalculatorCWE-862WordPress Stylish Cost Calculator plugin <= 8.3.9 - Broken Access Control vul…
CVE-2026-133727.220.2DevolutionsRemote Desktop ManagerCWE-706Incorrect link resolution by display name in the custom PowerShell VPN editor…
CVE-2026-546369.919.8dokkudokkuCWE-78Dokku: OS Command Injection via app.json managed Cron
CVE-2026-472055.919.8envoyproxyenvoyCWE-416Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides
CVE-2026-499918.619.7rustfsrustfsCWE-22RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injec…
CVE-2026-132266.519.7trainingbusinessprosGroundhogg — CRM, Newsletters, and Marketing AutomationCWE-89Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Param…
CVE-2026-463869.919.6opfopenprojectCWE-502OpenProject: Pre-authentication RCE in openproject/openproject Docker image v…
CVE-2026-576589.119.2TemplatespareTemplateSpareCWE-434WordPress TemplateSpare plugin <= 4.2.0 - Arbitrary File Upload vulnerability
CVE-2026-560648.519.2ThemeficTourficCWE-89WordPress Tourfic plugin <= 2.22.5 - SQL Injection vulnerability
CVE-2026-447356.519.2opfopenprojectCWE-863OpenProject: Shares API Information Disclosure
CVE-2026-560358.618.9Cory MarshBitFire SecurityCWE-1284WordPress BitFire Security plugin <= 5.0.3 - Multiple Vulnerabilities vulnera…
CVE-2026-579207.717.7PeplinkInControlCWE-551Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolo…
CVE-2026-527829.917.6opfopenprojectCWE-639OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> v…
CVE-2026-487705.017.7notepad-plus-plusnotepad-plus-plusCWE-125Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash
CVE-2026-489344.317.6nodejsnodeCWE-295A flaw in Node.js TLS host verification can cause an attacker to bypass certi…
CVE-2026-471937.516.9opfopenprojectCWE-200OpenProject: Journal diff endpoint bypasses object, journal, and field visibi…
CVE-2026-576477.516.8bPluginsPanorama Viewer – 360 Degree Image + Video ViewerCWE-98WordPress Panorama Viewer – 360 Degree Image + Video Viewer plugin <= 1.6.1 -…
CVE-2026-18696.516.8wpeverestUser Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-862User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenti…
CVE-2026-576224.316.8ArrayticsWPCafeCWE-862WordPress WPCafe plugin <= 3.0.14 - Broken Access Control vulnerability
CVE-2026-507656.116.4n/an/aCWE-79A stored cross-site scripting (XSS) vulnerability in the patron restriction t…
CVE-2025-323945.316.2Significant-GravitasAutoGPTCWE-405AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock
CVE-2025-324235.316.2Significant-GravitasAutoGPTCWE-770AutoGPT: There is a DoS vulnerability in ExtractTextInformationBlock
CVE-2026-579127.516.0Johnson & JohnsonCampus RecruitingCWE-602Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data …
CVE-2026-579137.516.0Johnson & JohnsonAudit Tracking Management SystemCWE-602Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 a…
CVE-2026-86614.816.0Rapid7InsightConnect Markdown PluginCWE-79Server-Side Cross-Site Scripting and SSRF in Rapid7 InsightConnect Markdown t…
CVE-2026-548327.515.1JegstudioGutenverse CompanionCWE-862WordPress Gutenverse Companion plugin <= 2.5.0 - Broken Access Control vulner…
CVE-2026-548357.515.1RustauriusFive Star Restaurant MenuCWE-862WordPress Five Star Restaurant Menu plugin <= 2.5.2 - Broken Access Control v…
CVE-2026-560257.515.1PaymobPaymob for WooCommerceCWE-862WordPress Paymob for WooCommerce plugin <= 4.1.2 - Broken Access Control vuln…
CVE-2026-560617.515.1WP SwingsSubscriptions for WooCommerceCWE-862WordPress Subscriptions for WooCommerce plugin <= 1.9.5 - Broken Access Contr…
CVE-2026-560447.115.0AdenionBlog2SocialCWE-79WordPress Blog2Social plugin <= 8.9.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-205310.014.9WSO2WSO2 API ManagerCWE-918Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Man…
CVE-2026-124119.614.8CanonicallxdCWE-639Broken Access Control in Canonical LXD DevLXD API
CVE-2026-548337.414.8Dev KabirEnable CORSCWE-321WordPress Enable CORS plugin <= 2.0.3 - Backdoor vulnerability
CVE-2025-630784.314.9jetmonstersRestaurant Menu by MotoPressCWE-862WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Contr…
CVE-2026-507444.314.9ReviveAdserverCWE-284A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver …
CVE-2026-576404.314.9StylemixMasterStudy LMSCWE-862WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability
CVE-2026-578737.514.7GeoVision Inc.GV-LPCLPC2011/2211CWE-476GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEE…
CVE-2026-560486.514.7tychesoftwaresPayment Gateway Based Fees and Discounts for WooCommerceCWE-639WordPress Payment Gateway Based Fees and Discounts for WooCommerce plugin <= …
CVE-2026-573246.514.7VillaThemeGIFT4UCWE-862WordPress GIFT4U plugin <= 1.0.10 - Broken Access Control vulnerability
CVE-2026-117795.314.7PayloadCMSPayloadCMSCWE-307PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlo…
CVE-2026-454089.014.5dokkudokkuCWE-78Dokku: OS Command Injection via App Name in Git Pre-Receive Hook
CVE-2026-527016.514.5ThemegrillUser RegistrationCWE-862WordPress User Registration plugin <= 5.2.2 - Broken Access Control vulnerabi…
CVE-2025-646375.314.4Opal_WPAuros CoreCWE-80WordPress Auros Core plugin <= 5.3.1 - Content Injection vulnerability
CVE-2026-576335.314.4WCBoostWCBoost &#8211; Products CompareCWE-497WordPress WCBoost &#8211; Products Compare plugin <= 1.1.0 - Sensitive Data E…
CVE-2026-527809.614.1opfopenprojectCWE-20OpenProject: Cache store poisoning leads to Remote Code Execution (RCE)
CVE-2026-484977.514.2envoyproxyenvoyCWE-480Envoy: Abnormal process termination in DNS UDP filter
CVE-2026-447346.514.2opfopenprojectCWE-862OpenProject: Improper Access Control on OpenProject through the POST request …
CVE-2026-560417.114.1dFactoryResponsive LightboxCWE-79WordPress Responsive Lightbox plugin <= 2.7.6 - Cross Site Scripting (XSS) vu…
CVE-2026-560437.114.1CusRevCustomer Reviews for WooCommerceCWE-79WordPress Customer Reviews for WooCommerce plugin <= 5.110.1 - Cross Site Scr…
CVE-2026-573127.114.1wpeverestEverest FormsCWE-79WordPress Everest Forms plugin <= 3.4.8 - Reflected Cross Site Scripting (XSS…
CVE-2026-573147.114.1SureCartSureCartCWE-79WordPress SureCart plugin <= 4.3.2 - Reflected Cross Site Scripting (XSS) vul…
CVE-2026-573177.114.1NSquaredSimply Schedule AppointmentsCWE-79WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Script…
CVE-2026-573197.114.1RealMag777FOXCWE-79WordPress FOX plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-560369.314.0codemstory워드프레스 결제 심플페이CWE-89WordPress 워드프레스 결제 심플페이 plugin <= 5.5.6 - SQL Injection vulnerability
CVE-2026-560629.314.0oooorgleQuotes llamaCWE-89WordPress Quotes llama plugin <= 3.1.5 - SQL Injection vulnerability
CVE-2026-560679.314.0Crocoblock. Jetimpex Inc.JetSmartFiltersCWE-89WordPress JetSmartFilters plugin <= 3.8.3 - SQL Injection vulnerability
CVE-2026-560689.314.0Crocoblock. Jetimpex Inc.JetEngineCWE-89WordPress JetEngine plugin <= 3.8.10.2 - SQL Injection vulnerability
CVE-2026-560709.314.0ThemeHunkAdvance Product SearchCWE-89WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerability
CVE-2026-573136.514.0SureCartSureCartCWE-79WordPress SureCart plugin <= 4.2.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-579402.113.9danprosHTMLyCWE-918HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in th…
CVE-2026-564148.613.5H.VIEWHV-500S6 IP CameraCWE-434H.VIEW HV-500S6 IP Camera Unrestricted Upload of File with Dangerous Type
CVE-2026-560388.813.5FrisbiiFrisbii PayCWE-862WordPress Frisbii Pay plugin <= 1.8.2 - Privilege Escalation vulnerability
CVE-2026-566638.513.3Significant-GravitasAutoGPTCWE-918AutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass …
CVE-2026-507665.413.0n/an/aCWE-79A stored cross-site scripting (XSS) vulnerability in the OPAC item detail pag…
CVE-2026-507675.413.0n/an/aCWE-79A stored cross-site scripting (XSS) vulnerability in the item type administra…
CVE-2026-527859.912.9opfopenprojectCWE-89OpenProject: SQL injection in timestamps functionality
CVE-2026-573235.812.9bPluginsFlash & HTML5 VideoCWE-862WordPress Flash & HTML5 Video plugin <= 2.11.0 - Broken Access Control vulner…
CVE-2025-661235.312.9About EnvatoBookProCWE-639WordPress BookPro plugin <= 1.1.0 - Insecure Direct Object References (IDOR) …
CVE-2026-576305.312.9Creative ThemesBlocksy Companion ProCWE-639WordPress Blocksy Companion Pro plugin <= 2.1.46 - Insecure Direct Object Ref…
CVE-2026-487437.512.4envoyproxyenvoyCWE-444Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonze…
CVE-2026-472147.112.4docling-projectdoclingCWE-73Docling: Unsafe URI and Path Handling in HTML Backend
CVE-2026-576615.412.4NexcessWPCompleteCWE-862WordPress WPComplete plugin <= 2.9.5.5 - Broken Access Control vulnerability
CVE-2026-489285.412.3nodejsnodeCWE-284A inconsistency in Node.js hostname matching can cause a trust-policy bypass …
CVE-2026-108357.712.2UnknownSALESmanago & LeadooSALESmanago & Leadoo < 3.11.3 - Subscriber+ SQL Injection
CVE-2026-560266.412.0Chris Carlevatoutm.codesCWE-918WordPress utm.codes plugin <= 1.9.0 - Server Side Request Forgery (SSRF) vuln…
CVE-2026-493554.312.0opfopenprojectCWE-200OpenProject: Private work package data disclosure through single meeting agen…
CVE-2026-548407.311.8Tribulant SoftwareNewslettersCWE-862WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability
CVE-2026-576438.511.7AF themesWP Post AuthorCWE-89WordPress WP Post Author plugin <= 3.9.1 - SQL Injection vulnerability
CVE-2026-576678.511.7Adrian TobeyGroundhoggCWE-89WordPress Groundhogg plugin <= 4.5 - SQL Injection vulnerability
CVE-2026-528847.811.6notepad-plus-plusnotepad-plus-plusCWE-42Notepad++: CVE-2026-48800 Bypass
CVE-2026-446965.711.6opfopenprojectCWE-79OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables…
CVE-2026-560117.111.5chrisvrichardsonMapPress Maps for WordPressCWE-79WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting…
CVE-2025-646365.311.2rhewlifDonation ThermometerCWE-862WordPress Donation Thermometer plugin <= 2.2.7 - Broken Access Control vulner…
CVE-2026-245475.311.2SiteGroundSiteGround Email MarketingCWE-862WordPress SiteGround Email Marketing plugin <= 1.7.5 - Broken Access Control …
CVE-2026-576296.510.9StatCounterStatCounterCWE-79WordPress StatCounter plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576494.311.0studiowombatShoppable Images LiteCWE-862WordPress Shoppable Images Lite plugin <= 1.3 - Broken Access Control vulnera…
CVE-2026-576368.510.8TomdeverwpForo ForumCWE-89WordPress wpForo Forum plugin <= 3.0.9 - SQL Injection vulnerability
CVE-2026-576428.510.8bestwebsoftGalleryCWE-89WordPress Gallery plugin <= 4.7.8 - SQL Injection vulnerability
CVE-2026-576448.510.8jetmonstersRestaurant Menu by MotoPressCWE-89WordPress Restaurant Menu by MotoPress plugin <= 2.4.10 - SQL Injection vulne…
CVE-2026-576538.510.8wpjobportalWP Job PortalCWE-89WordPress WP Job Portal plugin <= 2.5.2 - SQL Injection vulnerability
CVE-2026-576628.510.8Wasiliy StreckerContest GalleryCWE-89WordPress Contest Gallery plugin <= 30.0.0 - SQL Injection vulnerability
CVE-2026-576638.510.8Igor BenicRecipe Maker For Your Food Blog from Zip RecipesCWE-89WordPress Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.2.7 - …
CVE-2026-560466.510.8CridioStudioListingProCWE-79WordPress ListingPro theme <= 2.9.11 - Cross Site Scripting (XSS) vulnerability
CVE-2025-630415.410.6Code AmpForget About Shortcode ButtonsCWE-862WordPress Forget About Shortcode Buttons plugin <= 2.1.3 - Broken Access Cont…
CVE-2026-551897.710.3rustfsrustfsCWE-862RustFS: FTP frontend skips IAM authorization on object reads
CVE-2026-447324.310.3opfopenprojectCWE-639OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH par…
CVE-2026-501365.39.9BudibasebudibaseCWE-306Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary wr…
CVE-2025-79587.19.7TrellixTrellix Network Security NX, EX, FX, AX, and CMSCWE-94A Code Injection vulnerability existed in Trellix Network Security CM and NX.…
CVE-2026-134265.49.8Mattermostgithub.com/mattermost/mattermost/server/publicCWE-22Client4 fails to validate path parameters
CVE-2026-539149.89.6JetBrainsKotlinCWE-502In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe dese…
CVE-2026-579187.19.5sahlberglibnfsCWE-191libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVE…
CVE-2026-550698.79.5kestra-iokestraCWE-916Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack
CVE-2026-34723.59.4MattermostMattermostCWE-693Markdown image rendering bypass in AI bot tool result posts in Mattermost
CVE-2025-630794.39.1bdthemesLive Copy Paste for ElementorCWE-862WordPress Live Copy Paste for Elementor plugin <= 1.5.3 - Broken Access Contr…
CVE-2026-579269.88.7JetBrainsYouTrackCWE-1321In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerabl…
CVE-2026-447314.38.5opfopenprojectCWE-639OpenProject: Improper Access Control on OpenProject through /projects/[projec…
CVE-2026-527795.48.3opfopenprojectCWE-639OpenProject: Cross-project authorization bypass allows deleting public Calend…
CVE-2026-489353.38.4nodejsnodeCWE-276A flaw in Node.js Permission API can cause a file metadata to be modified eve…
CVE-2026-576458.18.3Tribulant SoftwareNewslettersCWE-862WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability
CVE-2026-283855.08.2CanonicallxdCWE-918SSRF via image import from URL allows internal network probing by authenticat…
CVE-2026-576525.38.0JoomSkyJS Help DeskCWE-639WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (I…
CVE-2026-576655.38.0GravityKitGravityViewCWE-639WordPress GravityView plugin <= 3.0.0 - Insecure Direct Object References (ID…
CVE-2026-551888.27.9rustfsrustfsCWE-200RustFS: ListRemoteTargetHandler authorization bypass leaks replication target…
CVE-2026-574304.37.8SEOPress FreeSEOPress PROCWE-862WordPress SEOPress PRO plugin <= 9.1.1 - Broken Access Control vulnerability
CVE-2026-576344.37.8WP Folio TeamPPWPCWE-639WordPress PPWP plugin <= 1.9.19 - Insecure Direct Object References (IDOR) vu…
CVE-2026-579217.57.5JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.16593 improper access control allowed rea…
CVE-2026-576206.57.5Tim StriflerExclusive Addons ElementorCWE-79WordPress Exclusive Addons Elementor plugin <= 2.7.9.8 - Cross Site Scripting…
CVE-2026-576465.47.4Majestic SupportMajestic SupportCWE-639WordPress Majestic Support plugin <= 1.1.7 - Insecure Direct Object Reference…
CVE-2026-477784.47.4envoyproxyenvoyCWE-158Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate …
CVE-2026-560397.17.3WordPress.comQuick Interest SliderCWE-79WordPress Quick Interest Slider plugin <= 3.1.6 - Reflected Cross Site Script…
CVE-2026-560407.17.3WordPress.comGutenverse FormCWE-79WordPress Gutenverse Form plugin <= 2.4.7 - Cross Site Scripting (XSS) vulner…
CVE-2026-560457.17.2ValvePressAutomaticCWE-79WordPress Automatic plugin < 3.135.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-560477.17.2Perfmatters, Powered Kinsta + GeneratePress Docs Changelog Feature requests Legal Affiliate ContactperfmattersCWE-79WordPress perfmatters plugin <= 2.6.3 - Reflected Cross Site Scripting (XSS) …
CVE-2026-560727.17.2XtemosWoodMartCWE-79WordPress WoodMart theme <= 8.5.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573227.17.2weDevsweMailCWE-79WordPress weMail plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulne…
CVE-2026-573257.17.3JellywpNanoMagCWE-79WordPress NanoMag theme <= 1.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-447335.97.3opfopenprojectCWE-620OpenProject: Business Logic Error on OpenProject through PATCH request to /ap…
CVE-2026-576274.97.2ThemeumKirkiCWE-918WordPress Kirki plugin <= 6.0.11 - Server Side Request Forgery (SSRF) vulnera…
CVE-2026-560638.37.0bPluginsMailChimp BlockCWE-862WordPress MailChimp Block plugin <= 1.1.15 - Broken Access Control vulnerability
CVE-2026-576605.36.8magepeopleteamBooking and Rental ManagerCWE-862WordPress Booking and Rental Manager plugin <= 2.7.1 - Broken Access Control …
CVE-2026-576644.36.9VillaThemeBopo – WooCommerce Product Bundle BuilderCWE-497WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensiti…
CVE-2026-576546.56.7wp.insiderAffiliates ManagerCWE-862WordPress Affiliates Manager plugin <= 2.9.49 - Broken Access Control vulnera…
CVE-2026-579245.36.4JetBrainsYouTrackCWE-276In JetBrains YouTrack before 2026.2.16593 default role configuration exposed …
CVE-2026-579255.36.4JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.16593 improper access control allowed rea…
CVE-2026-527848.85.9opfopenprojectCWE-352OpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]"
CVE-2026-477756.85.9envoyproxyenvoyCWE-209Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
CVE-2026-558384.35.9rustfsrustfsCWE-862RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any au…
CVE-2026-579237.55.5JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app c…
CVE-2026-543537.15.4BudibasebudibaseCWE-367Budibase: Potential SSRF DNS rebinding bypass in outbound fetch validation
CVE-2025-680746.55.3GhozyLabImage CarouselCWE-79WordPress Image Carousel plugin <= 1.0.0.41 - Cross Site Scripting (XSS) vuln…
CVE-2025-680756.55.3KerryBNE TestimonialsCWE-79WordPress BNE Testimonials plugin <= 2.0.8 - Cross Site Scripting (XSS) vulne…
CVE-2026-574316.55.3Mervin PraisonFeatured ImageCWE-79WordPress Featured Image plugin <= 2.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-576176.55.3SeedProd LLC.SeedProd ProCWE-79WordPress SeedProd Pro plugin < 6.19.5 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-576186.55.3ThemeisleNeve PROCWE-79WordPress Neve PRO theme <= 3.1.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576386.55.3WPManageNinja LLCFluent BookingCWE-79WordPress Fluent Booking plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnera…
CVE-2026-134344.95.2Red HatRed Hat OpenShift Virtualization 4CWE-20Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation …
CVE-2026-452577.85.0FreeBSDFreeBSDCWE-123Arbitrary file overwrite via the KTLS receive path
CVE-2026-489363.35.1nodejsnodeCWE-284A flaw in Node.js Permission API can cause a local server to be started (via …
CVE-2026-501327.34.7BudibasebudibaseCWE-284Budibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account I…
CVE-2026-527816.44.7opfopenprojectCWE-79OpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{…
CVE-2026-568235.44.7Significant-GravitasAutoGPTCWE-284AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping…
CVE-2026-576484.34.5Nelio SoftwareNelio ContentCWE-862WordPress Nelio Content plugin <= 4.3.4 - Broken Access Control vulnerability
CVE-2026-574735.84.3ReolinkHome HubCWE-1391A vulnerability exists in the netclient and factory services of Reolink Home …
CVE-2026-579225.34.1JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the…
CVE-2026-369085.54.0n/an/aCWE-121A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity compon…
CVE-2025-680528.83.7Eagle-ThemesEagle BookingCWE-352WordPress Eagle Booking plugin <= 1.3.4.3 - Cross Site Request Forgery (CSRF)…
CVE-2026-485296.03.8githubgithub-mcp-serverCWE-284GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user G…
CVE-2026-476924.33.7envoyproxyenvoyCWE-130Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB…
CVE-2026-576565.93.5peregrinethemesHester CoreCWE-79WordPress Hester Core plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-66585.43.3jupyterjupyter/jupyterCWE-79Cross-site Scripting (XSS) in jupyter/nbconvert
CVE-2026-545575.53.3jdxmiseCWE-22mise HTTP backend uses raw version path for install symlink destination
CVE-2026-532818.83.0LinuxLinuxCWE-476iommu/vt-d: Avoid NULL pointer dereference or refcount corruption
CVE-2026-532947.83.0LinuxLinuxCWE-415mailbox: mailbox-test: don't free the reused channel
CVE-2026-533228.83.0LinuxLinuxCWE-415vfio/pci: Clean up DMABUFs before disabling function
CVE-2026-527838.23.0opfopenprojectCWE-313OpenProject: Information Disclosure (cleartext storage of data) on localhost …
CVE-2026-532967.83.0LinuxLinuxCWE-416mailbox: mailbox-test: free channels on probe error
CVE-2026-528857.53.0notepad-plus-plusnotepad-plus-plusCWE-367Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory
CVE-2026-554418.62.9jdxmiseCWE-78mise: Arbitrary command execution via task-include files in an untrusted, con…
CVE-2026-576598.82.8Stranger StudiosPaid Memberships Pro - Add Member From AdminCWE-352WordPress Paid Memberships Pro - Add Member From Admin plugin <= 0.7.2 - Cros…
CVE-2026-576506.52.7BlockArtMagazine BlocksCWE-79WordPress Magazine Blocks plugin <= 1.8.3 - Cross Site Scripting (XSS) vulner…
CVE-2026-576516.52.7nKGhost KitCWE-79WordPress Ghost Kit plugin <= 3.6.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-532955.52.8LinuxLinuxmailbox: add sanity check for channel array
CVE-2026-532867.82.7LinuxLinuxCWE-415idpf: fix double free and use-after-free in aux device error paths
CVE-2026-533037.12.7LinuxLinuxCWE-125f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()
CVE-2026-369075.52.6n/an/aCWE-121A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-sys…
CVE-2026-532907.82.5LinuxLinuxCWE-416drm/xe/eustall: Fix drm_dev_put called before stream disable in close
CVE-2026-533007.82.5LinuxLinuxCWE-416net: enetc: fix NTMP DMA use-after-free issue
CVE-2026-576416.52.5ContempoincReal Estate 7CWE-352WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Request Forgery (CSRF) vu…
CVE-2026-532795.52.4LinuxLinuxdrm/gma500/oaktrail_lvds: fix hang on init failure
CVE-2026-532875.52.4LinuxLinuxaudit: fix incorrect inheritable capability in CAPSET records
CVE-2026-532895.52.4LinuxLinuxCWE-476ice: fix NULL pointer dereference in ice_reset_all_vfs()
CVE-2026-532915.52.4LinuxLinuxCWE-476ALSA: hda/conexant: Fix missing error check for jack detection
CVE-2026-533065.52.5LinuxLinuxCWE-193tty: hvc_iucv: fix off-by-one in number of supported devices
CVE-2026-87978.52.4NEC CorporationExpressUpdate Agent for WindowsCWE-782An access control deficiency vulnerability exists in ExpressUpdate Agent for …
CVE-2026-532885.52.4LinuxLinuxCWE-674arm64: Reserve an extra page for early kernel mapping
CVE-2026-532985.52.4LinuxLinuxCWE-476net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue()
CVE-2026-532825.52.2LinuxLinuxx86/kexec: Push kjump return address even for non-kjump kexec
CVE-2026-532835.52.2LinuxLinuxCWE-476iommu/amd: Bounds-check devid in __rlookup_amd_iommu()
CVE-2026-532975.52.2LinuxLinuxCWE-476net: mana: Guard mana_remove against double invocation
CVE-2026-532995.52.3LinuxLinuxCWE-476net: airoha: Move ndesc initialization at end of airoha_qdma_init_tx()
CVE-2026-533015.52.3LinuxLinuxCWE-476reset: amlogic: t7: Fix null reset ops
CVE-2026-533025.52.2LinuxLinuxCWE-476crypto: eip93 - fix hmac setkey algo selection
CVE-2026-533055.52.3LinuxLinuxCWE-476usb: typec: ps883x: Fix Oops at unbind
CVE-2026-533205.52.3LinuxLinuxnilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
CVE-2026-576356.52.1FunnelKitFunnelKit Payment Gateway for Stripe WooCommerceCWE-352WordPress FunnelKit Payment Gateway for Stripe WooCommerce plugin <= 1.14.0.3…
CVE-2026-217347.72.0Imagination TechnologiesGraphics DDKCWE-823GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation
CVE-2026-533145.52.0LinuxLinuxpadata: Put CPU offline callback in ONLINE section to allow failure
CVE-2026-390315.51.9n/an/aCWE-321Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded…
CVE-2026-554486.31.8jdxmiseCWE-78mise: Local credential_command executes untrusted config
CVE-2026-533245.51.8LinuxLinuxCWE-476net: mana: Use pci_name() for debugfs directory naming
CVE-2023-205725.61.7AMDAMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsCWE-208An observable timing discrepancy in the ASP could allow a privileged attacker…
CVE-2026-533175.51.7LinuxLinuxwifi: mt76: mt7921: Place upper limit on station AID
CVE-2026-533185.51.7LinuxLinuxCWE-476wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr()
CVE-2023-205401.81.7AMDAMD Ryzen™ 3000 Series Desktop ProcessorsCWE-208An observable timing discrepancy in the ASP could allow a privileged attacker…
CVE-2026-440187.11.7docling-projectdoclingCWE-409Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVE-2026-385714.61.7n/an/aCWE-312Cleartext storage and exposure of WPA2 credentials, and missing authenticatio…
CVE-2026-533075.51.6LinuxLinuxCWE-476pinctrl: pinconf-generic: Fully validate 'pinmux' property
CVE-2026-533105.51.6LinuxLinuxsoc/tegra: cbb: Fix cross-fabric target timeout lookup
CVE-2026-533115.51.6LinuxLinuxCWE-908fuse: fix uninit-value in fuse_dentry_revalidate()
CVE-2026-533125.51.6LinuxLinuxCWE-835iommu/riscv: Remove overflows on the invalidation path
CVE-2026-533215.51.6LinuxLinuxio_uring/napi: cap busy_poll_to 10 msec
CVE-2026-576558.21.4Jay VersluisChild Theme WizardCWE-352WordPress Child theme Wizard plugin <= 1.4 - Cross Site Request Forgery (CSRF…
CVE-2026-467107.51.4notepad-plus-plusnotepad-plus-plusCWE-426Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable …
CVE-2026-532785.51.3LinuxLinuxCWE-476arm_mpam: Check whether the config array is allocated before destroying it
CVE-2026-532805.51.3LinuxLinuxCWE-476iommu: Fix NULL group->domain dereference in pci_dev_reset_iommu_done()
CVE-2026-532855.51.3LinuxLinuxCWE-617drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTIO…
CVE-2026-532925.51.3LinuxLinuxCWE-617net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind
CVE-2026-451957.81.2Imagination TechnologiesGraphics DDKCWE-280GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted
CVE-2026-43396.51.2MattermostMattermostCWE-918SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server
CVE-2026-576374.31.2tychesoftwaresAbandoned Cart Lite for WooCommerceCWE-352WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Re…
CVE-2026-533155.51.1LinuxLinuxCWE-476drm/amd/ras: Fix NULL deref in ras_core_get_utc_second_timestamp()
CVE-2026-533045.51.0LinuxLinuxCWE-667scsi: sg: Resolve soft lockup issue when opening /dev/sgX
CVE-2026-533085.51.0LinuxLinuxCWE-401power: supply: max77705: Free allocated workqueue and fix removal order
CVE-2026-533135.51.0LinuxLinuxCWE-476drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
CVE-2026-533165.51.0LinuxLinuxCWE-476drm/amd/ras: Fix NULL deref in ras_core_ras_interrupt_detected()
CVE-2026-533195.51.0LinuxLinuxCWE-617blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default()
CVE-2026-532935.50.9LinuxLinuxCWE-667drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG
CVE-2026-576574.30.8Noor AlamGmail SMTPCWE-352WordPress Gmail SMTP plugin <= 1.2.3.19 - Cross Site Request Forgery (CSRF) v…
CVE-2026-133223.80.7Red HatRed Hat OpenShift Virtualization 4CWE-770Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in v…
CVE-2026-452565.50.6FreeBSDFreeBSDCWE-269Missing permission check in thr_kill2(2)
CVE-2026-533235.50.5LinuxLinuxCWE-667net: dsa: remove redundant netdev_lock_ops() from conduit ethtool ops
CVE-2026-454075.50.5dokkudokkuCWE-522Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch
CVE-2024-235817.80.0HCLSoftwareTraveler for Microsoft OutlookCWE-347HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application mo…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-26 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.