AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0446 90.6 —
AFFECTED Product Versions Fixed Adserver unspecified —
TIMELINE Jun 6 Reserved by CNA Jun 26 Published (CNA: hackerone)
353 CVEs published June 26, 2026: 47 critical, 147 high, 152 medium, 7 low; 0 in KEV; 39 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 328 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 6996 | 11368 | 1176 | 2563 |
| KEV catalog size | 1670 | |||
506 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 513 | 1479 | 119 | 854 | 503 | 1 | 27 | 3 | 0.2 | 7.8 | .0013 | +284 |
| 707 | 881 | 85 | 464 | 300 | 29 | 74 | 6 | 0.7 | 8.1 | .0023 | +691 | |
| microsoft | 220 | 710 | 55 | 474 | 160 | 4 | 378 | 27 | 3.8 | 7.8 | .0044 | +56 |
| red hat | 108 | 172 | 9 | 73 | 82 | 8 | 4 | 0 | 0.0 | 6.8 | .0026 | +92 |
| apple | 15 | 62 | 0 | 16 | 37 | 2 | 93 | 7 | 11.3 | 5.5 | .0023 | -5 |
| canonical | 6 | 20 | 2 | 5 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +6 |
| freebsd | 2 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | -5 |
| suse | 4 | 6 | 1 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 10 | 23 | 4 | 4 | 8 | 0 | 96 | 11 | 47.8 | 7.0 | .0431 | +5 |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | +17 |
| palo alto networks | 9 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | +8 |
| ubiquiti | 8 | 11 | 7 | 4 | 0 | 0 | 4 | 3 | 27.3 | 9.9 | .0083 | +6 |
| f5 | 6 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | +4 |
| ivanti | 4 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | +2 |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 |
| fortinet | 2 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 104 | 136 | 22 | 47 | 56 | 10 | 40 | 1 | 0.7 | 7.0 | .0044 | +85 |
| mozilla | 49 | 55 | 11 | 18 | 26 | 0 | 13 | 0 | 0.0 | 7.3 | .0026 | +43 |
| gitlab | 24 | 33 | 0 | 5 | 21 | 5 | 4 | 2 | 6.1 | 4.4 | .0022 | +24 |
| docker | 4 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | +1 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | -3 |
| github | 1 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.0 | .0039 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 243 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | +243 |
| adobe | 132 | 136 | 4 | 50 | 77 | 2 | 75 | 3 | 2.2 | 5.5 | .0021 | +131 |
| ibm | 32 | 81 | 19 | 35 | 27 | 0 | 7 | 0 | 0.0 | 7.5 | .0028 | +12 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +1 |
| solarwinds | 3 | 6 | 1 | 2 | 1 | 0 | 11 | 4 | 66.7 | 7.5 | .3995 | +3 |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | +1 |
| zohocorp | 1 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | -1 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 9 | 12 | 0 | 4 | 2 | 5 | 26 | 1 | 8.3 | 5.5 | .0058 | +8 |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 1 | 0 | 0.0 | 7.5 | .0020 | +6 |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 |
| abb | 6 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +6 |
| schneider electric | 6 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | +6 |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | +3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 72 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | +71 |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +61 |
| sourcecodester | 37 | 59 | 0 | 0 | 25 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +17 |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 |
| dell | 38 | 56 | 1 | 30 | 24 | 0 | 2 | 1 | 1.8 | 7.2 | .0016 | +26 |
| edimax | 5 | 56 | 0 | 33 | 0 | 23 | 1 | 0 | 0.0 | 7.4 | .0070 | -39 |
| jenkins project | 36 | 49 | 0 | 9 | 39 | 1 | 0 | 0 | 0.0 | 4.8 | .0021 | +36 |
| capgo | 46 | 46 | 2 | 22 | 21 | 1 | 0 | 0 | 0.0 | 7.0 | .0034 | +46 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE-2026-48907 | .6883 | 99.3 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-53576 | 10.0 | .0219 | |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-49257 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| 858 | |
| linux | 649 |
| oracle | 268 |
| microsoft | 220 |
| adobe | 132 |
| red hat | 128 |
| apache | 106 |
| spring | 72 |
| openclaw | 67 |
| themerex | 58 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 41 |
| Packagist | 22 |
| PyPI | 9 |
| npm | 5 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1682 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1682 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1682 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1682 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1682 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1682 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1682 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1682 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1682 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1682 |
EXPLOIT PUBLISHED — CVE-2026-12411 (Canonical lxd). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-28385 (Canonical lxd). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45807 (kestra-io kestra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47204 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47205 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47207 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47220 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47221 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47775 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47778 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48042 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48044 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48090 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48743 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48770 (notepad-plus-plus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48778 (notepad-plus-plus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48800 (notepad-plus-plus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49869 (kestra-io kestra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49984 (kestra-io kestra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50132 (budibase). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50136 (budibase). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50137 (budibase). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50765. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50766. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50767. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52884 (notepad-plus-plus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52885 (notepad-plus-plus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53576 (kestra-io kestra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53577 (kestra-io kestra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54350 (budibase). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54351 (budibase). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54352 (budibase). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54353 (budibase). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55069 (kestra-io kestra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55686 (podman-container-tools podman). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56876 (max-mapper extract-zip). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-57920 (Peplink InControl). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-9639 (Canonical LXD). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-9640 (Canonical LXD). Public exploit reference added.
353 CVEs published. 25 box scores, 328 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0446 90.6 —
AFFECTED Product Versions Fixed Adserver unspecified —
TIMELINE Jun 6 Reserved by CNA Jun 26 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0371 88.8 —
AFFECTED Product Versions Fixed node 22.22.3 – —
TIMELINE May 26 Reserved by CNA Jun 26 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0323 87.2 —
AFFECTED Product Versions Fixed node 22.22.3 – —
TIMELINE May 22 Reserved by CNA Jun 26 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0219 80.9 —
AFFECTED Product Versions Fixed kestra < 1.0.45 – —
TIMELINE Jun 9 Reserved by CNA Jun 26 Public exploit reference published Jun 26 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0144 71.0 —
AFFECTED Product Versions Fixed GV-LPCLPC2011/2211 1.12 – 1.13
TIMELINE Jun 26 Reserved by CNA Jun 26 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0135 69.1 —
AFFECTED Product Versions Fixed YMC Filter unspecified —
TIMELINE Jun 4 Reserved by CNA Jun 26 Published (CNA: WPScan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0134 68.9 —
AFFECTED Product Versions Fixed LT300 3.0 unspecified —
TIMELINE Mar 16 Reserved by CNA Jun 26 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L N R U H H H 7.8 .0131 68.3 —
AFFECTED Product Versions Fixed notepad-plus-plus < 8.9.6.1 – —
TIMELINE May 22 Reserved by CNA Jun 26 Public exploit reference published Jun 26 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0100 60.1 —
AFFECTED Product Versions Fixed GV-LPCLPC2011/2211 1.12 – 1.13
TIMELINE Jun 26 Reserved by CNA Jun 26 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N C H H H 8.0 .0095 58.4 —
AFFECTED Product Versions Fixed Container Storage Modules unspecified —
TIMELINE Apr 15 Reserved by CNA Jun 26 Published (CNA: dell)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0089 56.5 —
AFFECTED Product Versions Fixed kestra < 1.0.45 – —
TIMELINE Jun 1 Reserved by CNA Jun 26 Public exploit reference published Jun 26 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N R U H L N 5.9 .0081 54.0 —
AFFECTED Product Versions Fixed nx >= 17.0.4, < 22.7.2 – —
TIMELINE Jun 15 Reserved by CNA Jun 26 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.1 —
AFFECTED Product Versions Fixed Genshi unspecified —
TIMELINE Jan 7 Reserved by CNA Jun 26 Published (CNA: certcc)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0064 47.7 —
AFFECTED Product Versions Fixed node 22.22.3 – —
TIMELINE May 22 Reserved by CNA Jun 26 Published (CNA: hackerone)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0063 47.4 —
AFFECTED Product Versions Fixed VFC-DMP-5000 unspecified — DMP-5000 unspecified — DMP-8000 unspecified —
TIMELINE Mar 30 Reserved by CNA Jun 26 Published (CNA: icscert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0055 43.5 —
AFFECTED Product Versions Fixed Ollama v0.13.5 – —
TIMELINE Apr 7 Reserved by CNA Jun 26 Published (CNA: certcc)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0053 42.4 —
AFFECTED Product Versions Fixed GV-LPCLPC2011/2211 1.12 – 1.13
TIMELINE Jun 26 Reserved by CNA Jun 26 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0053 42.4 —
AFFECTED Product Versions Fixed GV-LPCLPC2011/2211 1.12 – 1.13
TIMELINE Jun 26 Reserved by CNA Jun 26 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0053 42.4 —
AFFECTED Product Versions Fixed GV-LPCLPC2011/2211 1.12 – 1.13
TIMELINE Jun 26 Reserved by CNA Jun 26 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0052 41.9 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 4 Reserved by CNA Jun 26 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0051 41.2 —
AFFECTED Product Versions Fixed Buddyboss Platform n/a – 3.0.5
TIMELINE Jun 18 Reserved by CNA Jun 26 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0048 39.3 —
AFFECTED Product Versions Fixed pagekit unspecified —
TIMELINE Jun 24 Reserved by CNA Jun 26 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0047 38.7 —
AFFECTED Product Versions Fixed budibase < 3.39.12 – —
TIMELINE Jun 12 Reserved by CNA Jun 26 Public exploit reference published Jun 26 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P H H H 8.7 .0046 38.2 —
AFFECTED Product Versions Fixed zap-extensions unspecified —
TIMELINE Jun 24 Reserved by CNA Jun 26 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0046 38.1 —
AFFECTED Product Versions Fixed Endpoint Client 10.5.75.0 – — Endpoint Client 11.11.4.0 – —
TIMELINE Jan 9 Reserved by CNA Jun 26 Published (CNA: certcc)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-45807 | 7.7 | 37.9 | kestra-io | kestra | CWE-22 | Kestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace fi… |
| CVE-2026-49984 | 7.7 | 37.9 | kestra-io | kestra | CWE-22 | Kestra: Path traversal in `LocalStorage` allows any authenticated user to rea… |
| CVE-2026-30040 | 6.5 | 37.6 | n/a | n/a | CWE-122 | A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 al… |
| CVE-2026-38639 | 7.5 | 37.1 | n/a | n/a | CWE-20 | An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6… |
| CVE-2026-38641 | 7.5 | 37.1 | n/a | n/a | CWE-404 | An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows at… |
| CVE-2026-55677 | 7.5 | 35.9 | labstack | echo | CWE-22 | Echo: Encoded slash (%2F) bypasses route-level protection and exposes static … |
| CVE-2026-53284 | 7.5 | 35.5 | Linux | Linux | CWE-476 | btrfs: only release the dirty pages io tree after successful writes |
| CVE-2026-48090 | 5.9 | 35.6 | envoyproxy | envoy | CWE-416 | Envoy HTTP: OAuth2 filter late async token completion after stream teardown (… |
| CVE-2026-47220 | 7.5 | 35.4 | envoyproxy | envoy | CWE-476 | Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format |
| CVE-2026-48615 | 7.5 | 35.1 | nodejs | node | CWE-359 | A flaw in Node.js proxy tunnel error handling could expose proxy credentials … |
| CVE-2026-9639 | 6.5 | 35.1 | Canonical | LXD | CWE-476 | Authenticated Denial of Service via Malicious Backup Tarball in LXD |
| CVE-2026-31928 | 9.3 | 34.6 | Daktronics | VFC-DMP-5000 | CWE-798 | Daktronics Controller Firmware Use of Hard-coded Credentials |
| CVE-2026-56057 | 9.8 | 34.5 | Uncanny Owl | Uncanny Automator Pro | CWE-502 | WordPress Uncanny Automator Pro plugin <= 7.3.0.6 - PHP Object Injection vuln… |
| CVE-2025-11919 | 9.6 | 33.2 | Wolfram Research Inc. | Cloud | — | Unprotected temporary directories in Wolfram Cloud may result in privilege es… |
| CVE-2026-53309 | 9.8 | 33.1 | Linux | Linux | CWE-193 | ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison |
| CVE-2026-54341 | 7.5 | 33.1 | dragonflydb | dragonfly | CWE-125 | Dragonfly: RESTORE operations may crash the server |
| CVE-2026-50739 | 4.3 | 32.5 | Revive | Adserver | CWE-284 | A bypass for CVE‑2026‑34913 exists with proper ownership validation that had … |
| CVE-2026-56876 | 8.6 | 32.2 | max-mapper | extract-zip | CWE-22 | extract-zip unvalidated symlink path traversal |
| CVE-2026-8380 | 6.5 | 31.9 | Unknown | Frontend File Manager Plugin | — | Frontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post Deletion |
| CVE-2026-36478 | 7.5 | 31.8 | n/a | n/a | CWE-400 | An issue in Technitium DNS Server v.14.3 and before allows a remote attacker … |
| CVE-2026-33646 | 9.6 | 31.4 | jdx | mise | CWE-94 | mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Tr… |
| CVE-2025-55017 | 9.1 | 31.4 | Apache Software Foundation | Apache IoTDB | CWE-22 | Apache IoTDB: Path Traversal Vulnerability |
| CVE-2025-64152 | 9.1 | 31.4 | Apache Software Foundation | Apache IoTDB | CWE-22 | Apache IoTDB: Path Traversal Vulnerability |
| CVE-2026-56055 | 8.8 | 31.1 | InspiryThemes | RealHomes | CWE-502 | WordPress RealHomes theme <= 4.5.3 - PHP Object Injection vulnerability |
| CVE-2026-56010 | 8.8 | 30.9 | Tyche Softwares. | Abandoned Cart Pro for WooCommerce | CWE-266 | WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Esc… |
| CVE-2026-57881 | 9.8 | 30.7 | GeoVision Inc. | GV-LPCLPC2011/2211 | CWE-121 | GV-LPC2011/LPC2211 - unauthorized stack-based buffer overflow vulnerability (… |
| CVE-2026-48706 | 7.5 | 30.8 | envoyproxy | envoy | CWE-120 | Envoy Heap Buffer Overflow in TcpStatsdSink |
| CVE-2026-55686 | 5.3 | 30.5 | podman-container-tools | podman | CWE-61 | Podman: WORKDIR symlink traversal vulnerability |
| CVE-2026-54352 | 9.6 | 30.4 | Budibase | budibase | CWE-22 | Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload |
| CVE-2026-56773 | 8.7 | 30.2 | teableio | teable | CWE-862 | Teable - Missing Authorization in v2 REST API |
| CVE-2026-9640 | 7.2 | 29.7 | Canonical | LXD | CWE-863 | LXD Snapshot Import Privilege Escalation Vulnerability |
| CVE-2026-48042 | 7.5 | 29.6 | envoyproxy | envoy | CWE-1124 | Envoy: Stack overflow in destructor of highly nested JSON |
| CVE-2026-54825 | 9.3 | 29.4 | wpDataTables | wpDataTables | CWE-89 | WordPress wpDataTables plugin <= 7.4 - SQL Injection vulnerability |
| CVE-2026-56028 | 9.8 | 29.1 | themewant | Easy Elements for Elementor – Addons & Website Templates | CWE-266 | WordPress Easy Elements for Elementor – Addons & Website Templates plugin <= … |
| CVE-2026-48800 | 7.8 | 29.1 | notepad-plus-plus | notepad-plus-plus | CWE-78 | Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection |
| CVE-2026-57876 | 7.5 | 28.7 | GeoVision Inc. | GV-LPCLPC2011/2211 | CWE-787 | GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.… |
| CVE-2026-55975 | 8.6 | 28.4 | H.VIEW | HV-500S6 IP Camera | CWE-78 | H.VIEW HV-500S6 IP Camera OS Command Injection |
| CVE-2026-56058 | 9.9 | 28.2 | ThemeCatcher | Quform | CWE-434 | WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerability |
| CVE-2026-56059 | 9.9 | 28.2 | PhysCode | Travel Booking | CWE-434 | WordPress Travel Booking theme <= 2.2.5 - Arbitrary File Upload vulnerability |
| CVE-2026-57315 | 8.5 | 28.1 | Creative Themes | Blocksy Companion Pro | CWE-94 | WordPress Blocksy Companion Pro plugin <= 2.1.45 - Remote Code Execution (RCE… |
| CVE-2025-10268 | 5.3 | 28.0 | Unknown | Printcart Web to Print Product Designer for WooCommerce | — | Printcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenti… |
| CVE-2026-57628 | 7.6 | 27.8 | WP All Import | WP All Import | CWE-89 | WordPress WP All Import plugin <= 4.0.1 - SQL Injection vulnerability |
| CVE-2026-57631 | 7.6 | 27.8 | Ays Pro | Popup box | CWE-89 | WordPress Popup box plugin <= 6.0.1 - SQL Injection vulnerability |
| CVE-2026-57316 | 6.5 | 27.5 | Roxnor | GetGenie | CWE-497 | WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-57318 | 6.5 | 27.5 | Gemini Labs | Site Reviews | CWE-201 | WordPress Site Reviews plugin <= 8.0.11 - Sensitive Data Exposure vulnerability |
| CVE-2026-46604 | 7.5 | 27.2 | golang.org/x/image | golang.org/x/image/tiff | CWE-787 | Panic decoding image with out-of-bounds strip offset in x/image/tiff in golan… |
| CVE-2026-11625 | 7.5 | 26.8 | DAVIDO | Bytes::Random::Secure | CWE-335 | Bytes::Random::Secure versions through 0.29 for Perl share internal state acr… |
| CVE-2026-11702 | 7.5 | 26.8 | DAVIDO | Bytes::Random::Secure::Tiny | CWE-335 | Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal st… |
| CVE-2026-56066 | 5.8 | 26.5 | ShortPixel | ShortPixel Adaptive Images | CWE-22 | WordPress ShortPixel Adaptive Images plugin <= 3.11.4 - Arbitrary File Deleti… |
| CVE-2026-54351 | 9.6 | 26.3 | Budibase | budibase | CWE-915 | Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automatio… |
| CVE-2026-33560 | 8.4 | 26.0 | Daktronics | VFC-DMP-5000 | CWE-434 | Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type |
| CVE-2026-47221 | 7.5 | 25.6 | envoyproxy | envoy | CWE-476 | Envoy: Null pointer deref in internal redirects |
| CVE-2026-9699 | 6.8 | 25.4 | Mattermost | Mattermost | CWE-532 | Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication e… |
| CVE-2026-48930 | 9.8 | 25.2 | nodejs | node | CWE-284 | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can … |
| CVE-2026-56030 | 9.8 | 24.9 | paytiumsupport | Paytium | CWE-266 | WordPress Paytium plugin <= 5.0.2 - Privilege Escalation vulnerability |
| CVE-2026-56033 | 9.8 | 24.9 | Dokan Multivendor Plugin | Dokan Pro | CWE-266 | WordPress Dokan Pro plugin <= 5.0.4 - Privilege Escalation vulnerability |
| CVE-2026-57915 | 7.3 | 24.9 | Apache Software Foundation | Apache Kerby | CWE-304 | Apache Kerby: Kerberos Pre-Authentication Bypass |
| CVE-2026-48044 | 7.5 | 24.8 | envoyproxy | envoy | CWE-409 | Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explo… |
| CVE-2026-56027 | 9.9 | 24.7 | Pluggabl | Booster for WooCommerce | CWE-434 | WordPress Booster for WooCommerce plugin <= 8.0.1 - Arbitrary File Upload vul… |
| CVE-2026-57874 | 7.5 | 24.6 | GeoVision Inc. | GV-LPCLPC2011/2211 | CWE-120 | GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_up… |
| CVE-2026-50745 | 6.1 | 24.5 | Revive | Adserver | CWE-79 | A missing sanitisation vulnerability exists with user input in the stats-vide… |
| CVE-2026-50740 | 5.4 | 24.3 | Revive | Adserver | CWE-79 | A missing sanitisation vulnerability of user input in the zone-include.php sc… |
| CVE-2026-57231 | 7.5 | 23.9 | podman-container-tools | podman | CWE-200 | Podman: Malformed Image can trick podman run into leaking host environment va… |
| CVE-2026-53577 | 6.5 | 23.8 | kestra-io | kestra | CWE-863 | Kestra: Cross-Execution File Read via Preview Endpoint (IDOR) |
| CVE-2025-68063 | 7.5 | 23.7 | StylemixThemes | Splash - Sport Club WordPress Theme for Basketball, Football, Hockey | CWE-98 | WordPress Splash - Sport Club WordPress theme for Basketball, Football, Hocke… |
| CVE-2025-68064 | 7.5 | 23.7 | Everthemess | Goya Core | CWE-98 | WordPress Goya Core plugin < 1.0.9.4 - Local File Inclusion vulnerability |
| CVE-2026-56031 | 8.1 | 23.4 | Uncanny Owl | Uncanny Automator | CWE-502 | WordPress Uncanny Automator plugin <= 7.3.1.2 - PHP Object Injection vulnerab… |
| CVE-2026-54824 | 7.5 | 23.0 | Ads WPQuads | Ads by WPQuads | CWE-497 | WordPress Ads by WPQuads plugin <= 3.0.3 - Sensitive Data Exposure vulnerability |
| CVE-2026-50137 | 8.2 | 22.7 | Budibase | budibase | CWE-862 | Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets… |
| CVE-2026-47204 | 7.5 | 22.7 | envoyproxy | envoy | CWE-476 | Envoy: grpc_stats filter segfault on Connect protocol requests to direct_resp… |
| CVE-2026-49486 | 7.5 | 22.1 | Apache Software Foundation | Apache Airflow FTP provider | CWE-319 | Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel … |
| CVE-2026-54834 | 7.5 | 21.9 | fpuenteonline | Object Cache 4 everyone | CWE-201 | WordPress Object Cache 4 everyone plugin <= 2.3.2 - Sensitive Data Exposure v… |
| CVE-2026-56060 | 7.5 | 21.9 | tychesoftwares | Print Invoice & Delivery Notes for WooCommerce | CWE-497 | WordPress Print Invoice & Delivery Notes for WooCommerce plugin <= 7.1.1 - Se… |
| CVE-2026-57914 | 6.5 | 21.9 | Apache Software Foundation | Apache Kerby | CWE-400 | Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures |
| CVE-2026-47207 | 6.5 | 21.8 | envoyproxy | envoy | CWE-416 | Envoy crashes if multiple unexpected ext_proc responses are packed into one g… |
| CVE-2026-56069 | 7.5 | 21.6 | Site Building with Toolset | Toolset Forms | CWE-639 | WordPress Toolset Forms plugin <= 2.6.24 - Insecure Direct Object References … |
| CVE-2026-57632 | 5.4 | 21.6 | Omnisend | Email Marketing for WooCommerce by Omnisend | CWE-862 | WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.19.0 - Brok… |
| CVE-2026-45405 | 8.8 | 21.4 | dokku | dokku | CWE-59 | Dokku: Arbitrary File Write via Tar Symlink Traversal in git:from-archive and… |
| CVE-2026-54826 | 7.6 | 21.3 | PSM Plugins | SupportCandy | CWE-639 | WordPress SupportCandy plugin <= 3.4.6 - Insecure Direct Object References (I… |
| CVE-2026-54846 | 7.5 | 21.3 | akosglys | Syncee Premium Dropshipping & Wholesale | CWE-862 | WordPress Syncee Premium Dropshipping & Wholesale plugin <= 1.0.27 - Broken A… |
| CVE-2026-44736 | 6.5 | 21.1 | opf | openproject | CWE-200 | OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Pr… |
| CVE-2026-56029 | 7.5 | 21.0 | corvuspay | CorvusPay WooCommerce Payment Gateway | CWE-288 | WordPress CorvusPay WooCommerce Payment Gateway plugin <= 2.7.4 - Broken Auth… |
| CVE-2026-57321 | 7.1 | 21.0 | icc0rz | H5P | CWE-22 | WordPress H5P plugin <= 1.17.7 - Arbitrary File Deletion vulnerability |
| CVE-2026-54820 | 9.3 | 20.8 | Crocoblock. Jetimpex Inc. | JetBooking | CWE-89 | WordPress JetBooking plugin <= 4.0.4.1 - SQL Injection vulnerability |
| CVE-2026-54827 | 9.3 | 20.8 | contempoinc | Real Estate 7 | CWE-89 | WordPress Real Estate 7 theme <= 3.5.9 - SQL Injection vulnerability |
| CVE-2026-54831 | 9.3 | 20.8 | Paolo | GeoDirectory | CWE-89 | WordPress GeoDirectory plugin <= 2.8.162 - SQL Injection vulnerability |
| CVE-2026-56034 | 9.3 | 20.8 | Online Web Tutor | Library Management System | CWE-89 | WordPress Library Management System plugin <= 3.5.7 - SQL Injection vulnerabi… |
| CVE-2026-47206 | 2.3 | 20.8 | dragonflydb | dragonfly | CWE-116 | Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer |
| CVE-2026-50742 | 5.4 | 20.7 | Revive | Adserver | CWE-79 | A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `m… |
| CVE-2026-29509 | 5.3 | 20.6 | wummel | patool | CWE-22 | Patool < 4.0.5 Path Traversal via safe_extract() Function |
| CVE-2026-57877 | 8.6 | 20.6 | GeoVision Inc. | GV-LPCLPC2011/2211 | CWE-134 | GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr) |
| CVE-2026-45406 | 8.8 | 20.5 | dokku | dokku | CWE-95 | Dokku: Host RCE via Maliciously Named OpenResty Include Files Injected Throug… |
| CVE-2026-56008 | 8.8 | 20.2 | ThemeFusion | Fusion Builder | CWE-266 | WordPress Fusion Builder plugin <= 3.15.4 - Privilege Escalation vulnerability |
| CVE-2026-54837 | 7.5 | 20.3 | Syed Balkhi | Intranet & Private Site – All-In-One Intranet | CWE-862 | WordPress Intranet & Private Site – All-In-One Intranet plugin <= 1.8.1 - Bro… |
| CVE-2026-54839 | 7.5 | 20.3 | kingaddons | Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups | CWE-639 | WordPress Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups… |
| CVE-2026-54847 | 7.5 | 20.3 | Design | Stylish Cost Calculator | CWE-862 | WordPress Stylish Cost Calculator plugin <= 8.3.9 - Broken Access Control vul… |
| CVE-2026-13372 | 7.2 | 20.2 | Devolutions | Remote Desktop Manager | CWE-706 | Incorrect link resolution by display name in the custom PowerShell VPN editor… |
| CVE-2026-54636 | 9.9 | 19.8 | dokku | dokku | CWE-78 | Dokku: OS Command Injection via app.json managed Cron |
| CVE-2026-47205 | 5.9 | 19.8 | envoyproxy | envoy | CWE-416 | Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides |
| CVE-2026-49991 | 8.6 | 19.7 | rustfs | rustfs | CWE-22 | RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injec… |
| CVE-2026-13226 | 6.5 | 19.7 | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | CWE-89 | Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Param… |
| CVE-2026-46386 | 9.9 | 19.6 | opf | openproject | CWE-502 | OpenProject: Pre-authentication RCE in openproject/openproject Docker image v… |
| CVE-2026-57658 | 9.1 | 19.2 | Templatespare | TemplateSpare | CWE-434 | WordPress TemplateSpare plugin <= 4.2.0 - Arbitrary File Upload vulnerability |
| CVE-2026-56064 | 8.5 | 19.2 | Themefic | Tourfic | CWE-89 | WordPress Tourfic plugin <= 2.22.5 - SQL Injection vulnerability |
| CVE-2026-44735 | 6.5 | 19.2 | opf | openproject | CWE-863 | OpenProject: Shares API Information Disclosure |
| CVE-2026-56035 | 8.6 | 18.9 | Cory Marsh | BitFire Security | CWE-1284 | WordPress BitFire Security plugin <= 5.0.3 - Multiple Vulnerabilities vulnera… |
| CVE-2026-57920 | 7.7 | 17.7 | Peplink | InControl | CWE-551 | Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolo… |
| CVE-2026-52782 | 9.9 | 17.6 | opf | openproject | CWE-639 | OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> v… |
| CVE-2026-48770 | 5.0 | 17.7 | notepad-plus-plus | notepad-plus-plus | CWE-125 | Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash |
| CVE-2026-48934 | 4.3 | 17.6 | nodejs | node | CWE-295 | A flaw in Node.js TLS host verification can cause an attacker to bypass certi… |
| CVE-2026-47193 | 7.5 | 16.9 | opf | openproject | CWE-200 | OpenProject: Journal diff endpoint bypasses object, journal, and field visibi… |
| CVE-2026-57647 | 7.5 | 16.8 | bPlugins | Panorama Viewer – 360 Degree Image + Video Viewer | CWE-98 | WordPress Panorama Viewer – 360 Degree Image + Video Viewer plugin <= 1.6.1 -… |
| CVE-2026-1869 | 6.5 | 16.8 | wpeverest | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | CWE-862 | User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenti… |
| CVE-2026-57622 | 4.3 | 16.8 | Arraytics | WPCafe | CWE-862 | WordPress WPCafe plugin <= 3.0.14 - Broken Access Control vulnerability |
| CVE-2026-50765 | 6.1 | 16.4 | n/a | n/a | CWE-79 | A stored cross-site scripting (XSS) vulnerability in the patron restriction t… |
| CVE-2025-32394 | 5.3 | 16.2 | Significant-Gravitas | AutoGPT | CWE-405 | AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock |
| CVE-2025-32423 | 5.3 | 16.2 | Significant-Gravitas | AutoGPT | CWE-770 | AutoGPT: There is a DoS vulnerability in ExtractTextInformationBlock |
| CVE-2026-57912 | 7.5 | 16.0 | Johnson & Johnson | Campus Recruiting | CWE-602 | Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data … |
| CVE-2026-57913 | 7.5 | 16.0 | Johnson & Johnson | Audit Tracking Management System | CWE-602 | Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 a… |
| CVE-2026-8661 | 4.8 | 16.0 | Rapid7 | InsightConnect Markdown Plugin | CWE-79 | Server-Side Cross-Site Scripting and SSRF in Rapid7 InsightConnect Markdown t… |
| CVE-2026-54832 | 7.5 | 15.1 | Jegstudio | Gutenverse Companion | CWE-862 | WordPress Gutenverse Companion plugin <= 2.5.0 - Broken Access Control vulner… |
| CVE-2026-54835 | 7.5 | 15.1 | Rustaurius | Five Star Restaurant Menu | CWE-862 | WordPress Five Star Restaurant Menu plugin <= 2.5.2 - Broken Access Control v… |
| CVE-2026-56025 | 7.5 | 15.1 | Paymob | Paymob for WooCommerce | CWE-862 | WordPress Paymob for WooCommerce plugin <= 4.1.2 - Broken Access Control vuln… |
| CVE-2026-56061 | 7.5 | 15.1 | WP Swings | Subscriptions for WooCommerce | CWE-862 | WordPress Subscriptions for WooCommerce plugin <= 1.9.5 - Broken Access Contr… |
| CVE-2026-56044 | 7.1 | 15.0 | Adenion | Blog2Social | CWE-79 | WordPress Blog2Social plugin <= 8.9.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-2053 | 10.0 | 14.9 | WSO2 | WSO2 API Manager | CWE-918 | Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Man… |
| CVE-2026-12411 | 9.6 | 14.8 | Canonical | lxd | CWE-639 | Broken Access Control in Canonical LXD DevLXD API |
| CVE-2026-54833 | 7.4 | 14.8 | Dev Kabir | Enable CORS | CWE-321 | WordPress Enable CORS plugin <= 2.0.3 - Backdoor vulnerability |
| CVE-2025-63078 | 4.3 | 14.9 | jetmonsters | Restaurant Menu by MotoPress | CWE-862 | WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Contr… |
| CVE-2026-50744 | 4.3 | 14.9 | Revive | Adserver | CWE-284 | A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver … |
| CVE-2026-57640 | 4.3 | 14.9 | Stylemix | MasterStudy LMS | CWE-862 | WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability |
| CVE-2026-57873 | 7.5 | 14.7 | GeoVision Inc. | GV-LPCLPC2011/2211 | CWE-476 | GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEE… |
| CVE-2026-56048 | 6.5 | 14.7 | tychesoftwares | Payment Gateway Based Fees and Discounts for WooCommerce | CWE-639 | WordPress Payment Gateway Based Fees and Discounts for WooCommerce plugin <= … |
| CVE-2026-57324 | 6.5 | 14.7 | VillaTheme | GIFT4U | CWE-862 | WordPress GIFT4U plugin <= 1.0.10 - Broken Access Control vulnerability |
| CVE-2026-11779 | 5.3 | 14.7 | PayloadCMS | PayloadCMS | CWE-307 | PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlo… |
| CVE-2026-45408 | 9.0 | 14.5 | dokku | dokku | CWE-78 | Dokku: OS Command Injection via App Name in Git Pre-Receive Hook |
| CVE-2026-52701 | 6.5 | 14.5 | Themegrill | User Registration | CWE-862 | WordPress User Registration plugin <= 5.2.2 - Broken Access Control vulnerabi… |
| CVE-2025-64637 | 5.3 | 14.4 | Opal_WP | Auros Core | CWE-80 | WordPress Auros Core plugin <= 5.3.1 - Content Injection vulnerability |
| CVE-2026-57633 | 5.3 | 14.4 | WCBoost | WCBoost – Products Compare | CWE-497 | WordPress WCBoost – Products Compare plugin <= 1.1.0 - Sensitive Data E… |
| CVE-2026-52780 | 9.6 | 14.1 | opf | openproject | CWE-20 | OpenProject: Cache store poisoning leads to Remote Code Execution (RCE) |
| CVE-2026-48497 | 7.5 | 14.2 | envoyproxy | envoy | CWE-480 | Envoy: Abnormal process termination in DNS UDP filter |
| CVE-2026-44734 | 6.5 | 14.2 | opf | openproject | CWE-862 | OpenProject: Improper Access Control on OpenProject through the POST request … |
| CVE-2026-56041 | 7.1 | 14.1 | dFactory | Responsive Lightbox | CWE-79 | WordPress Responsive Lightbox plugin <= 2.7.6 - Cross Site Scripting (XSS) vu… |
| CVE-2026-56043 | 7.1 | 14.1 | CusRev | Customer Reviews for WooCommerce | CWE-79 | WordPress Customer Reviews for WooCommerce plugin <= 5.110.1 - Cross Site Scr… |
| CVE-2026-57312 | 7.1 | 14.1 | wpeverest | Everest Forms | CWE-79 | WordPress Everest Forms plugin <= 3.4.8 - Reflected Cross Site Scripting (XSS… |
| CVE-2026-57314 | 7.1 | 14.1 | SureCart | SureCart | CWE-79 | WordPress SureCart plugin <= 4.3.2 - Reflected Cross Site Scripting (XSS) vul… |
| CVE-2026-57317 | 7.1 | 14.1 | NSquared | Simply Schedule Appointments | CWE-79 | WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Script… |
| CVE-2026-57319 | 7.1 | 14.1 | RealMag777 | FOX | CWE-79 | WordPress FOX plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-56036 | 9.3 | 14.0 | codemstory | 워드프레스 결제 심플페이 | CWE-89 | WordPress 워드프레스 결제 심플페이 plugin <= 5.5.6 - SQL Injection vulnerability |
| CVE-2026-56062 | 9.3 | 14.0 | oooorgle | Quotes llama | CWE-89 | WordPress Quotes llama plugin <= 3.1.5 - SQL Injection vulnerability |
| CVE-2026-56067 | 9.3 | 14.0 | Crocoblock. Jetimpex Inc. | JetSmartFilters | CWE-89 | WordPress JetSmartFilters plugin <= 3.8.3 - SQL Injection vulnerability |
| CVE-2026-56068 | 9.3 | 14.0 | Crocoblock. Jetimpex Inc. | JetEngine | CWE-89 | WordPress JetEngine plugin <= 3.8.10.2 - SQL Injection vulnerability |
| CVE-2026-56070 | 9.3 | 14.0 | ThemeHunk | Advance Product Search | CWE-89 | WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerability |
| CVE-2026-57313 | 6.5 | 14.0 | SureCart | SureCart | CWE-79 | WordPress SureCart plugin <= 4.2.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57940 | 2.1 | 13.9 | danpros | HTMLy | CWE-918 | HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in th… |
| CVE-2026-56414 | 8.6 | 13.5 | H.VIEW | HV-500S6 IP Camera | CWE-434 | H.VIEW HV-500S6 IP Camera Unrestricted Upload of File with Dangerous Type |
| CVE-2026-56038 | 8.8 | 13.5 | Frisbii | Frisbii Pay | CWE-862 | WordPress Frisbii Pay plugin <= 1.8.2 - Privilege Escalation vulnerability |
| CVE-2026-56663 | 8.5 | 13.3 | Significant-Gravitas | AutoGPT | CWE-918 | AutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass … |
| CVE-2026-50766 | 5.4 | 13.0 | n/a | n/a | CWE-79 | A stored cross-site scripting (XSS) vulnerability in the OPAC item detail pag… |
| CVE-2026-50767 | 5.4 | 13.0 | n/a | n/a | CWE-79 | A stored cross-site scripting (XSS) vulnerability in the item type administra… |
| CVE-2026-52785 | 9.9 | 12.9 | opf | openproject | CWE-89 | OpenProject: SQL injection in timestamps functionality |
| CVE-2026-57323 | 5.8 | 12.9 | bPlugins | Flash & HTML5 Video | CWE-862 | WordPress Flash & HTML5 Video plugin <= 2.11.0 - Broken Access Control vulner… |
| CVE-2025-66123 | 5.3 | 12.9 | About Envato | BookPro | CWE-639 | WordPress BookPro plugin <= 1.1.0 - Insecure Direct Object References (IDOR) … |
| CVE-2026-57630 | 5.3 | 12.9 | Creative Themes | Blocksy Companion Pro | CWE-639 | WordPress Blocksy Companion Pro plugin <= 2.1.46 - Insecure Direct Object Ref… |
| CVE-2026-48743 | 7.5 | 12.4 | envoyproxy | envoy | CWE-444 | Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonze… |
| CVE-2026-47214 | 7.1 | 12.4 | docling-project | docling | CWE-73 | Docling: Unsafe URI and Path Handling in HTML Backend |
| CVE-2026-57661 | 5.4 | 12.4 | Nexcess | WPComplete | CWE-862 | WordPress WPComplete plugin <= 2.9.5.5 - Broken Access Control vulnerability |
| CVE-2026-48928 | 5.4 | 12.3 | nodejs | node | CWE-284 | A inconsistency in Node.js hostname matching can cause a trust-policy bypass … |
| CVE-2026-10835 | 7.7 | 12.2 | Unknown | SALESmanago & Leadoo | — | SALESmanago & Leadoo < 3.11.3 - Subscriber+ SQL Injection |
| CVE-2026-56026 | 6.4 | 12.0 | Chris Carlevato | utm.codes | CWE-918 | WordPress utm.codes plugin <= 1.9.0 - Server Side Request Forgery (SSRF) vuln… |
| CVE-2026-49355 | 4.3 | 12.0 | opf | openproject | CWE-200 | OpenProject: Private work package data disclosure through single meeting agen… |
| CVE-2026-54840 | 7.3 | 11.8 | Tribulant Software | Newsletters | CWE-862 | WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability |
| CVE-2026-57643 | 8.5 | 11.7 | AF themes | WP Post Author | CWE-89 | WordPress WP Post Author plugin <= 3.9.1 - SQL Injection vulnerability |
| CVE-2026-57667 | 8.5 | 11.7 | Adrian Tobey | Groundhogg | CWE-89 | WordPress Groundhogg plugin <= 4.5 - SQL Injection vulnerability |
| CVE-2026-52884 | 7.8 | 11.6 | notepad-plus-plus | notepad-plus-plus | CWE-42 | Notepad++: CVE-2026-48800 Bypass |
| CVE-2026-44696 | 5.7 | 11.6 | opf | openproject | CWE-79 | OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables… |
| CVE-2026-56011 | 7.1 | 11.5 | chrisvrichardson | MapPress Maps for WordPress | CWE-79 | WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting… |
| CVE-2025-64636 | 5.3 | 11.2 | rhewlif | Donation Thermometer | CWE-862 | WordPress Donation Thermometer plugin <= 2.2.7 - Broken Access Control vulner… |
| CVE-2026-24547 | 5.3 | 11.2 | SiteGround | SiteGround Email Marketing | CWE-862 | WordPress SiteGround Email Marketing plugin <= 1.7.5 - Broken Access Control … |
| CVE-2026-57629 | 6.5 | 10.9 | StatCounter | StatCounter | CWE-79 | WordPress StatCounter plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57649 | 4.3 | 11.0 | studiowombat | Shoppable Images Lite | CWE-862 | WordPress Shoppable Images Lite plugin <= 1.3 - Broken Access Control vulnera… |
| CVE-2026-57636 | 8.5 | 10.8 | Tomdever | wpForo Forum | CWE-89 | WordPress wpForo Forum plugin <= 3.0.9 - SQL Injection vulnerability |
| CVE-2026-57642 | 8.5 | 10.8 | bestwebsoft | Gallery | CWE-89 | WordPress Gallery plugin <= 4.7.8 - SQL Injection vulnerability |
| CVE-2026-57644 | 8.5 | 10.8 | jetmonsters | Restaurant Menu by MotoPress | CWE-89 | WordPress Restaurant Menu by MotoPress plugin <= 2.4.10 - SQL Injection vulne… |
| CVE-2026-57653 | 8.5 | 10.8 | wpjobportal | WP Job Portal | CWE-89 | WordPress WP Job Portal plugin <= 2.5.2 - SQL Injection vulnerability |
| CVE-2026-57662 | 8.5 | 10.8 | Wasiliy Strecker | Contest Gallery | CWE-89 | WordPress Contest Gallery plugin <= 30.0.0 - SQL Injection vulnerability |
| CVE-2026-57663 | 8.5 | 10.8 | Igor Benic | Recipe Maker For Your Food Blog from Zip Recipes | CWE-89 | WordPress Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.2.7 - … |
| CVE-2026-56046 | 6.5 | 10.8 | CridioStudio | ListingPro | CWE-79 | WordPress ListingPro theme <= 2.9.11 - Cross Site Scripting (XSS) vulnerability |
| CVE-2025-63041 | 5.4 | 10.6 | Code Amp | Forget About Shortcode Buttons | CWE-862 | WordPress Forget About Shortcode Buttons plugin <= 2.1.3 - Broken Access Cont… |
| CVE-2026-55189 | 7.7 | 10.3 | rustfs | rustfs | CWE-862 | RustFS: FTP frontend skips IAM authorization on object reads |
| CVE-2026-44732 | 4.3 | 10.3 | opf | openproject | CWE-639 | OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH par… |
| CVE-2026-50136 | 5.3 | 9.9 | Budibase | budibase | CWE-306 | Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary wr… |
| CVE-2025-7958 | 7.1 | 9.7 | Trellix | Trellix Network Security NX, EX, FX, AX, and CMS | CWE-94 | A Code Injection vulnerability existed in Trellix Network Security CM and NX.… |
| CVE-2026-13426 | 5.4 | 9.8 | Mattermost | github.com/mattermost/mattermost/server/public | CWE-22 | Client4 fails to validate path parameters |
| CVE-2026-53914 | 9.8 | 9.6 | JetBrains | Kotlin | CWE-502 | In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe dese… |
| CVE-2026-57918 | 7.1 | 9.5 | sahlberg | libnfs | CWE-191 | libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVE… |
| CVE-2026-55069 | 8.7 | 9.5 | kestra-io | kestra | CWE-916 | Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack |
| CVE-2026-3472 | 3.5 | 9.4 | Mattermost | Mattermost | CWE-693 | Markdown image rendering bypass in AI bot tool result posts in Mattermost |
| CVE-2025-63079 | 4.3 | 9.1 | bdthemes | Live Copy Paste for Elementor | CWE-862 | WordPress Live Copy Paste for Elementor plugin <= 1.5.3 - Broken Access Contr… |
| CVE-2026-57926 | 9.8 | 8.7 | JetBrains | YouTrack | CWE-1321 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerabl… |
| CVE-2026-44731 | 4.3 | 8.5 | opf | openproject | CWE-639 | OpenProject: Improper Access Control on OpenProject through /projects/[projec… |
| CVE-2026-52779 | 5.4 | 8.3 | opf | openproject | CWE-639 | OpenProject: Cross-project authorization bypass allows deleting public Calend… |
| CVE-2026-48935 | 3.3 | 8.4 | nodejs | node | CWE-276 | A flaw in Node.js Permission API can cause a file metadata to be modified eve… |
| CVE-2026-57645 | 8.1 | 8.3 | Tribulant Software | Newsletters | CWE-862 | WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability |
| CVE-2026-28385 | 5.0 | 8.2 | Canonical | lxd | CWE-918 | SSRF via image import from URL allows internal network probing by authenticat… |
| CVE-2026-57652 | 5.3 | 8.0 | JoomSky | JS Help Desk | CWE-639 | WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (I… |
| CVE-2026-57665 | 5.3 | 8.0 | GravityKit | GravityView | CWE-639 | WordPress GravityView plugin <= 3.0.0 - Insecure Direct Object References (ID… |
| CVE-2026-55188 | 8.2 | 7.9 | rustfs | rustfs | CWE-200 | RustFS: ListRemoteTargetHandler authorization bypass leaks replication target… |
| CVE-2026-57430 | 4.3 | 7.8 | SEOPress Free | SEOPress PRO | CWE-862 | WordPress SEOPress PRO plugin <= 9.1.1 - Broken Access Control vulnerability |
| CVE-2026-57634 | 4.3 | 7.8 | WP Folio Team | PPWP | CWE-639 | WordPress PPWP plugin <= 1.9.19 - Insecure Direct Object References (IDOR) vu… |
| CVE-2026-57921 | 7.5 | 7.5 | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed rea… |
| CVE-2026-57620 | 6.5 | 7.5 | Tim Strifler | Exclusive Addons Elementor | CWE-79 | WordPress Exclusive Addons Elementor plugin <= 2.7.9.8 - Cross Site Scripting… |
| CVE-2026-57646 | 5.4 | 7.4 | Majestic Support | Majestic Support | CWE-639 | WordPress Majestic Support plugin <= 1.1.7 - Insecure Direct Object Reference… |
| CVE-2026-47778 | 4.4 | 7.4 | envoyproxy | envoy | CWE-158 | Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate … |
| CVE-2026-56039 | 7.1 | 7.3 | WordPress.com | Quick Interest Slider | CWE-79 | WordPress Quick Interest Slider plugin <= 3.1.6 - Reflected Cross Site Script… |
| CVE-2026-56040 | 7.1 | 7.3 | WordPress.com | Gutenverse Form | CWE-79 | WordPress Gutenverse Form plugin <= 2.4.7 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-56045 | 7.1 | 7.2 | ValvePress | Automatic | CWE-79 | WordPress Automatic plugin < 3.135.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-56047 | 7.1 | 7.2 | Perfmatters, Powered Kinsta + GeneratePress Docs Changelog Feature requests Legal Affiliate Contact | perfmatters | CWE-79 | WordPress perfmatters plugin <= 2.6.3 - Reflected Cross Site Scripting (XSS) … |
| CVE-2026-56072 | 7.1 | 7.2 | Xtemos | WoodMart | CWE-79 | WordPress WoodMart theme <= 8.5.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57322 | 7.1 | 7.2 | weDevs | weMail | CWE-79 | WordPress weMail plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulne… |
| CVE-2026-57325 | 7.1 | 7.3 | Jellywp | NanoMag | CWE-79 | WordPress NanoMag theme <= 1.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-44733 | 5.9 | 7.3 | opf | openproject | CWE-620 | OpenProject: Business Logic Error on OpenProject through PATCH request to /ap… |
| CVE-2026-57627 | 4.9 | 7.2 | Themeum | Kirki | CWE-918 | WordPress Kirki plugin <= 6.0.11 - Server Side Request Forgery (SSRF) vulnera… |
| CVE-2026-56063 | 8.3 | 7.0 | bPlugins | MailChimp Block | CWE-862 | WordPress MailChimp Block plugin <= 1.1.15 - Broken Access Control vulnerability |
| CVE-2026-57660 | 5.3 | 6.8 | magepeopleteam | Booking and Rental Manager | CWE-862 | WordPress Booking and Rental Manager plugin <= 2.7.1 - Broken Access Control … |
| CVE-2026-57664 | 4.3 | 6.9 | VillaTheme | Bopo – WooCommerce Product Bundle Builder | CWE-497 | WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensiti… |
| CVE-2026-57654 | 6.5 | 6.7 | wp.insider | Affiliates Manager | CWE-862 | WordPress Affiliates Manager plugin <= 2.9.49 - Broken Access Control vulnera… |
| CVE-2026-57924 | 5.3 | 6.4 | JetBrains | YouTrack | CWE-276 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed … |
| CVE-2026-57925 | 5.3 | 6.4 | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed rea… |
| CVE-2026-52784 | 8.8 | 5.9 | opf | openproject | CWE-352 | OpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]" |
| CVE-2026-47775 | 6.8 | 5.9 | envoyproxy | envoy | CWE-209 | Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption |
| CVE-2026-55838 | 4.3 | 5.9 | rustfs | rustfs | CWE-862 | RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any au… |
| CVE-2026-57923 | 7.5 | 5.5 | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app c… |
| CVE-2026-54353 | 7.1 | 5.4 | Budibase | budibase | CWE-367 | Budibase: Potential SSRF DNS rebinding bypass in outbound fetch validation |
| CVE-2025-68074 | 6.5 | 5.3 | GhozyLab | Image Carousel | CWE-79 | WordPress Image Carousel plugin <= 1.0.0.41 - Cross Site Scripting (XSS) vuln… |
| CVE-2025-68075 | 6.5 | 5.3 | Kerry | BNE Testimonials | CWE-79 | WordPress BNE Testimonials plugin <= 2.0.8 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-57431 | 6.5 | 5.3 | Mervin Praison | Featured Image | CWE-79 | WordPress Featured Image plugin <= 2.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57617 | 6.5 | 5.3 | SeedProd LLC. | SeedProd Pro | CWE-79 | WordPress SeedProd Pro plugin < 6.19.5 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57618 | 6.5 | 5.3 | Themeisle | Neve PRO | CWE-79 | WordPress Neve PRO theme <= 3.1.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57638 | 6.5 | 5.3 | WPManageNinja LLC | Fluent Booking | CWE-79 | WordPress Fluent Booking plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-13434 | 4.9 | 5.2 | Red Hat | Red Hat OpenShift Virtualization 4 | CWE-20 | Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation … |
| CVE-2026-45257 | 7.8 | 5.0 | FreeBSD | FreeBSD | CWE-123 | Arbitrary file overwrite via the KTLS receive path |
| CVE-2026-48936 | 3.3 | 5.1 | nodejs | node | CWE-284 | A flaw in Node.js Permission API can cause a local server to be started (via … |
| CVE-2026-50132 | 7.3 | 4.7 | Budibase | budibase | CWE-284 | Budibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account I… |
| CVE-2026-52781 | 6.4 | 4.7 | opf | openproject | CWE-79 | OpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{… |
| CVE-2026-56823 | 5.4 | 4.7 | Significant-Gravitas | AutoGPT | CWE-284 | AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping… |
| CVE-2026-57648 | 4.3 | 4.5 | Nelio Software | Nelio Content | CWE-862 | WordPress Nelio Content plugin <= 4.3.4 - Broken Access Control vulnerability |
| CVE-2026-57473 | 5.8 | 4.3 | Reolink | Home Hub | CWE-1391 | A vulnerability exists in the netclient and factory services of Reolink Home … |
| CVE-2026-57922 | 5.3 | 4.1 | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the… |
| CVE-2026-36908 | 5.5 | 4.0 | n/a | n/a | CWE-121 | A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity compon… |
| CVE-2025-68052 | 8.8 | 3.7 | Eagle-Themes | Eagle Booking | CWE-352 | WordPress Eagle Booking plugin <= 1.3.4.3 - Cross Site Request Forgery (CSRF)… |
| CVE-2026-48529 | 6.0 | 3.8 | github | github-mcp-server | CWE-284 | GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user G… |
| CVE-2026-47692 | 4.3 | 3.7 | envoyproxy | envoy | CWE-130 | Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB… |
| CVE-2026-57656 | 5.9 | 3.5 | peregrinethemes | Hester Core | CWE-79 | WordPress Hester Core plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-6658 | 5.4 | 3.3 | jupyter | jupyter/jupyter | CWE-79 | Cross-site Scripting (XSS) in jupyter/nbconvert |
| CVE-2026-54557 | 5.5 | 3.3 | jdx | mise | CWE-22 | mise HTTP backend uses raw version path for install symlink destination |
| CVE-2026-53281 | 8.8 | 3.0 | Linux | Linux | CWE-476 | iommu/vt-d: Avoid NULL pointer dereference or refcount corruption |
| CVE-2026-53294 | 7.8 | 3.0 | Linux | Linux | CWE-415 | mailbox: mailbox-test: don't free the reused channel |
| CVE-2026-53322 | 8.8 | 3.0 | Linux | Linux | CWE-415 | vfio/pci: Clean up DMABUFs before disabling function |
| CVE-2026-52783 | 8.2 | 3.0 | opf | openproject | CWE-313 | OpenProject: Information Disclosure (cleartext storage of data) on localhost … |
| CVE-2026-53296 | 7.8 | 3.0 | Linux | Linux | CWE-416 | mailbox: mailbox-test: free channels on probe error |
| CVE-2026-52885 | 7.5 | 3.0 | notepad-plus-plus | notepad-plus-plus | CWE-367 | Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory |
| CVE-2026-55441 | 8.6 | 2.9 | jdx | mise | CWE-78 | mise: Arbitrary command execution via task-include files in an untrusted, con… |
| CVE-2026-57659 | 8.8 | 2.8 | Stranger Studios | Paid Memberships Pro - Add Member From Admin | CWE-352 | WordPress Paid Memberships Pro - Add Member From Admin plugin <= 0.7.2 - Cros… |
| CVE-2026-57650 | 6.5 | 2.7 | BlockArt | Magazine Blocks | CWE-79 | WordPress Magazine Blocks plugin <= 1.8.3 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-57651 | 6.5 | 2.7 | nK | Ghost Kit | CWE-79 | WordPress Ghost Kit plugin <= 3.6.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-53295 | 5.5 | 2.8 | Linux | Linux | — | mailbox: add sanity check for channel array |
| CVE-2026-53286 | 7.8 | 2.7 | Linux | Linux | CWE-415 | idpf: fix double free and use-after-free in aux device error paths |
| CVE-2026-53303 | 7.1 | 2.7 | Linux | Linux | CWE-125 | f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show() |
| CVE-2026-36907 | 5.5 | 2.6 | n/a | n/a | CWE-121 | A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-sys… |
| CVE-2026-53290 | 7.8 | 2.5 | Linux | Linux | CWE-416 | drm/xe/eustall: Fix drm_dev_put called before stream disable in close |
| CVE-2026-53300 | 7.8 | 2.5 | Linux | Linux | CWE-416 | net: enetc: fix NTMP DMA use-after-free issue |
| CVE-2026-57641 | 6.5 | 2.5 | Contempoinc | Real Estate 7 | CWE-352 | WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Request Forgery (CSRF) vu… |
| CVE-2026-53279 | 5.5 | 2.4 | Linux | Linux | — | drm/gma500/oaktrail_lvds: fix hang on init failure |
| CVE-2026-53287 | 5.5 | 2.4 | Linux | Linux | — | audit: fix incorrect inheritable capability in CAPSET records |
| CVE-2026-53289 | 5.5 | 2.4 | Linux | Linux | CWE-476 | ice: fix NULL pointer dereference in ice_reset_all_vfs() |
| CVE-2026-53291 | 5.5 | 2.4 | Linux | Linux | CWE-476 | ALSA: hda/conexant: Fix missing error check for jack detection |
| CVE-2026-53306 | 5.5 | 2.5 | Linux | Linux | CWE-193 | tty: hvc_iucv: fix off-by-one in number of supported devices |
| CVE-2026-8797 | 8.5 | 2.4 | NEC Corporation | ExpressUpdate Agent for Windows | CWE-782 | An access control deficiency vulnerability exists in ExpressUpdate Agent for … |
| CVE-2026-53288 | 5.5 | 2.4 | Linux | Linux | CWE-674 | arm64: Reserve an extra page for early kernel mapping |
| CVE-2026-53298 | 5.5 | 2.4 | Linux | Linux | CWE-476 | net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue() |
| CVE-2026-53282 | 5.5 | 2.2 | Linux | Linux | — | x86/kexec: Push kjump return address even for non-kjump kexec |
| CVE-2026-53283 | 5.5 | 2.2 | Linux | Linux | CWE-476 | iommu/amd: Bounds-check devid in __rlookup_amd_iommu() |
| CVE-2026-53297 | 5.5 | 2.2 | Linux | Linux | CWE-476 | net: mana: Guard mana_remove against double invocation |
| CVE-2026-53299 | 5.5 | 2.3 | Linux | Linux | CWE-476 | net: airoha: Move ndesc initialization at end of airoha_qdma_init_tx() |
| CVE-2026-53301 | 5.5 | 2.3 | Linux | Linux | CWE-476 | reset: amlogic: t7: Fix null reset ops |
| CVE-2026-53302 | 5.5 | 2.2 | Linux | Linux | CWE-476 | crypto: eip93 - fix hmac setkey algo selection |
| CVE-2026-53305 | 5.5 | 2.3 | Linux | Linux | CWE-476 | usb: typec: ps883x: Fix Oops at unbind |
| CVE-2026-53320 | 5.5 | 2.3 | Linux | Linux | — | nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() |
| CVE-2026-57635 | 6.5 | 2.1 | FunnelKit | FunnelKit Payment Gateway for Stripe WooCommerce | CWE-352 | WordPress FunnelKit Payment Gateway for Stripe WooCommerce plugin <= 1.14.0.3… |
| CVE-2026-21734 | 7.7 | 2.0 | Imagination Technologies | Graphics DDK | CWE-823 | GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation |
| CVE-2026-53314 | 5.5 | 2.0 | Linux | Linux | — | padata: Put CPU offline callback in ONLINE section to allow failure |
| CVE-2026-39031 | 5.5 | 1.9 | n/a | n/a | CWE-321 | Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded… |
| CVE-2026-55448 | 6.3 | 1.8 | jdx | mise | CWE-78 | mise: Local credential_command executes untrusted config |
| CVE-2026-53324 | 5.5 | 1.8 | Linux | Linux | CWE-476 | net: mana: Use pci_name() for debugfs directory naming |
| CVE-2023-20572 | 5.6 | 1.7 | AMD | AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics | CWE-208 | An observable timing discrepancy in the ASP could allow a privileged attacker… |
| CVE-2026-53317 | 5.5 | 1.7 | Linux | Linux | — | wifi: mt76: mt7921: Place upper limit on station AID |
| CVE-2026-53318 | 5.5 | 1.7 | Linux | Linux | CWE-476 | wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr() |
| CVE-2023-20540 | 1.8 | 1.7 | AMD | AMD Ryzen™ 3000 Series Desktop Processors | CWE-208 | An observable timing discrepancy in the ASP could allow a privileged attacker… |
| CVE-2026-44018 | 7.1 | 1.7 | docling-project | docling | CWE-409 | Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend |
| CVE-2026-38571 | 4.6 | 1.7 | n/a | n/a | CWE-312 | Cleartext storage and exposure of WPA2 credentials, and missing authenticatio… |
| CVE-2026-53307 | 5.5 | 1.6 | Linux | Linux | CWE-476 | pinctrl: pinconf-generic: Fully validate 'pinmux' property |
| CVE-2026-53310 | 5.5 | 1.6 | Linux | Linux | — | soc/tegra: cbb: Fix cross-fabric target timeout lookup |
| CVE-2026-53311 | 5.5 | 1.6 | Linux | Linux | CWE-908 | fuse: fix uninit-value in fuse_dentry_revalidate() |
| CVE-2026-53312 | 5.5 | 1.6 | Linux | Linux | CWE-835 | iommu/riscv: Remove overflows on the invalidation path |
| CVE-2026-53321 | 5.5 | 1.6 | Linux | Linux | — | io_uring/napi: cap busy_poll_to 10 msec |
| CVE-2026-57655 | 8.2 | 1.4 | Jay Versluis | Child Theme Wizard | CWE-352 | WordPress Child theme Wizard plugin <= 1.4 - Cross Site Request Forgery (CSRF… |
| CVE-2026-46710 | 7.5 | 1.4 | notepad-plus-plus | notepad-plus-plus | CWE-426 | Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable … |
| CVE-2026-53278 | 5.5 | 1.3 | Linux | Linux | CWE-476 | arm_mpam: Check whether the config array is allocated before destroying it |
| CVE-2026-53280 | 5.5 | 1.3 | Linux | Linux | CWE-476 | iommu: Fix NULL group->domain dereference in pci_dev_reset_iommu_done() |
| CVE-2026-53285 | 5.5 | 1.3 | Linux | Linux | CWE-617 | drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTIO… |
| CVE-2026-53292 | 5.5 | 1.3 | Linux | Linux | CWE-617 | net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind |
| CVE-2026-45195 | 7.8 | 1.2 | Imagination Technologies | Graphics DDK | CWE-280 | GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted |
| CVE-2026-4339 | 6.5 | 1.2 | Mattermost | Mattermost | CWE-918 | SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server |
| CVE-2026-57637 | 4.3 | 1.2 | tychesoftwares | Abandoned Cart Lite for WooCommerce | CWE-352 | WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Re… |
| CVE-2026-53315 | 5.5 | 1.1 | Linux | Linux | CWE-476 | drm/amd/ras: Fix NULL deref in ras_core_get_utc_second_timestamp() |
| CVE-2026-53304 | 5.5 | 1.0 | Linux | Linux | CWE-667 | scsi: sg: Resolve soft lockup issue when opening /dev/sgX |
| CVE-2026-53308 | 5.5 | 1.0 | Linux | Linux | CWE-401 | power: supply: max77705: Free allocated workqueue and fix removal order |
| CVE-2026-53313 | 5.5 | 1.0 | Linux | Linux | CWE-476 | drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths |
| CVE-2026-53316 | 5.5 | 1.0 | Linux | Linux | CWE-476 | drm/amd/ras: Fix NULL deref in ras_core_ras_interrupt_detected() |
| CVE-2026-53319 | 5.5 | 1.0 | Linux | Linux | CWE-617 | blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default() |
| CVE-2026-53293 | 5.5 | 0.9 | Linux | Linux | CWE-667 | drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG |
| CVE-2026-57657 | 4.3 | 0.8 | Noor Alam | Gmail SMTP | CWE-352 | WordPress Gmail SMTP plugin <= 1.2.3.19 - Cross Site Request Forgery (CSRF) v… |
| CVE-2026-13322 | 3.8 | 0.7 | Red Hat | Red Hat OpenShift Virtualization 4 | CWE-770 | Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in v… |
| CVE-2026-45256 | 5.5 | 0.6 | FreeBSD | FreeBSD | CWE-269 | Missing permission check in thr_kill2(2) |
| CVE-2026-53323 | 5.5 | 0.5 | Linux | Linux | CWE-667 | net: dsa: remove redundant netdev_lock_ops() from conduit ethtool ops |
| CVE-2026-45407 | 5.5 | 0.5 | dokku | dokku | CWE-522 | Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch |
| CVE-2024-23581 | 7.8 | 0.0 | HCLSoftware | Traveler for Microsoft Outlook | CWE-347 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application mo… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-26 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.