boxscore/security
Saturday, June 27, 2026 · all times UTC← 2026-06-26 · archive · 2026-06-28 →

33 CVEs published June 27, 2026: 1 critical, 10 high, 22 medium, 0 low; 0 in KEV; 0 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 8 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published70291140111762563
KEV catalog size1670

508 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux513147911985450312730.27.8.0013+9
google70788185464300297460.78.1.0023+690
microsoft220710554741604378273.87.8.0044+50
red hat108172973828400.06.8.0026+87
apple156201637293711.35.5.0023-5
canonical6202585000.05.5.0011+6
freebsd91601240000.07.8.0015+2
suse461410000.08.6.0029+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco10234480961147.87.0.0431+5
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+8
ubiquiti81174004327.39.9.0083+6
f56943107111.18.9.0221+4
ivanti49230033555.68.8.5187+2
checkpoint3915303111.17.5.0410-3
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache104136224756104010.77.0.0044+85
mozilla495511182601300.07.3.0026+43
gitlab243305215426.14.4.0022+18
docker470520100.08.2.0016+1
drupal0511305120.05.1.0026-3
github131110000.07.0.0039-1
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+243
adobe1321364507727532.25.5.0021+131
ibm32811935270700.07.5.0028-17
progress591710900.07.5.0036+1
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp131110000.08.4.0170-1
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025-13
d-link91204252618.35.5.0058+8
siemens780440100.07.5.0020+6
rockwell automation771510000.08.7.0030+7
abb660420000.07.2.0018+6
schneider electric660420100.07.8.0024+6
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+71
openclaw61670352210000.07.0.0021+61
sourcecodester3759002534000.02.1.0026+17
themerex585855300000.08.1.0043+58
dell3856130240211.87.2.0016+26
edimax556033023100.07.4.0070-39
jenkins project364909391000.04.8.0021+23
capgo4646222211000.07.0.0034+46

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5357610.0.0219
CVE-2026-4977710.0.0166
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4925710.0.0093
Most disclosures (vendor)
VendorCVEs
google707
linux514
oracle243
microsoft220
adobe132
red hat114
apache104
spring72
openclaw67
themerex58
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco11
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven39
Packagist22
PyPI9
npm5
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-48595Google0
CVE-2025-67038Lantronix0
CVE-2026-0257Palo Alto Networks0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171683
CVE-2021-27102Accellion2021-11-171683
CVE-2021-27101Accellion2021-11-171683
CVE-2021-27103Accellion2021-11-171683
CVE-2021-21017Adobe2021-11-171683
CVE-2021-28550Adobe2021-11-171683
CVE-2021-42013Apache2021-11-171683
CVE-2021-41773Apache2021-11-171683
CVE-2021-30858Apple2021-11-171683
CVE-2021-30860Apple2021-11-171683

Transactions

DUE DATE PASSEDCVE-2025-67038 (Lantronix EDS5000). CISA remediation deadline was June 26, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-34908 (Ubiquiti Inc UniFi OS Server). CISA remediation deadline was June 26, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-34909 (Ubiquiti Inc UniFi OS Server). CISA remediation deadline was June 26, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-34910 (Ubiquiti Inc UniFi OS Server). CISA remediation deadline was June 26, 2026; still in catalog.

Yesterday's Results

33 CVEs published. 25 box scores, 8 table rows — nothing truncated.

pravel Invoice Generator — Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0066   48.7     —
AFFECTED
  Product            Versions     Fixed
  Invoice Generator  unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · 4 references · NVD status: Deferred
themeisle Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions — Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0054   42.9     —
AFFECTED
  Product                                                                                       Versions     Fixed
  Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions  unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 10 references · NVD status: Deferred
nmedia Frontend File Manager Plugin — Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0040   33.7     —
AFFECTED
  Product                       Versions     Fixed
  Frontend File Manager Plugin  unspecified  —
TIMELINE
  May 7   Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-73 · CNA: Wordfence · 3 references · NVD status: Deferred
vinod-dalvi Ivory Search – WordPress Search Plugin — Ivory Search <= 5.5.15 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  L  L  N    4.4   .0034   27.4     —
AFFECTED
  Product                                 Versions     Fixed
  Ivory Search – WordPress Search Plugin  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 10 references · NVD status: Deferred
gpriday Page Builder by SiteOrigin — Page Builder by SiteOrigin <= 2.34.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0034   27.3     —
AFFECTED
  Product                     Versions     Fixed
  Page Builder by SiteOrigin  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 10 references · NVD status: Deferred
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation — Groundhogg <= 4.5.5 - Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0033   26.3     —
AFFECTED
  Product                                                  Versions     Fixed
  Groundhogg — CRM, Newsletters, and Marketing Automation  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 6 references · NVD status: Deferred
maxfoundry MaxButtons – Create buttons — MaxButtons <= 9.8.5 - Reflected Cross-Site Scripting via 'view' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0033   26.2     —
AFFECTED
  Product                      Versions     Fixed
  MaxButtons – Create buttons  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 4 references · NVD status: Deferred
webaways NEX-Forms – Ultimate Forms Plugin for WordPress — NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0031   24.1     —
AFFECTED
  Product                                          Versions     Fixed
  NEX-Forms – Ultimate Forms Plugin for WordPress  unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 8 references · NVD status: Deferred
reepaydenmark Frisbii Pay — Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .0027   19.8     —
AFFECTED
  Product      Versions     Fixed
  Frisbii Pay  unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 5 references · NVD status: Deferred
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation — Groundhogg <= 4.5.5 - Authenticated (Marketer+) SQL Injection via 'search' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0027   19.6     —
AFFECTED
  Product                                                  Versions     Fixed
  Groundhogg — CRM, Newsletters, and Marketing Automation  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 7 references · NVD status: Deferred
expresstech Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker — Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0027   19.2     —
AFFECTED
  Product                                                    Versions     Fixed
  Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 12 references · NVD status: Deferred
dokaninc Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  N    4.3   .0027   19.1     —
AFFECTED
  Product                                                                                             Versions     Fixed
  Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy  unspecified  —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · 14 references · NVD status: Deferred
jegstudio Gutenverse – WordPress Blocks, Page Builder & Site Editor — Gutenverse <= 3.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  L  L  N    4.4   .0024   15.8     —
AFFECTED
  Product                                                    Versions     Fixed
  Gutenverse – WordPress Blocks, Page Builder & Site Editor  unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 12 references · NVD status: Deferred
dokaninc Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0024   15.5     —
AFFECTED
  Product                                                                                             Versions     Fixed
  Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy  unspecified  —
TIMELINE
  Jun 9   Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 8 references · NVD status: Deferred
metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login — RegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0024   14.9     —
AFFECTED
  Product                                                                                    Versions     Fixed
  RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-345 · CNA: Wordfence · 14 references · NVD status: Deferred
Unknown Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content — ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0022   13.0     —
AFFECTED
  Product                                                                                                 Versions     Fixed
  Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content  unspecified  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 27  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Deferred
dornaweb Product Specifications for Woocommerce — Product Specifications for Woocommerce <= 0.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attribute/Group Creation, Modification, and Deletion via 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX Actions
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0021   11.7     —
AFFECTED
  Product                                 Versions     Fixed
  Product Specifications for Woocommerce  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 8 references · NVD status: Deferred
CodePeople Post Map for Google Maps <= 1.2.6 - Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0020   10.7     —
AFFECTED
  Product                              Versions     Fixed
  CodePeople Post Map for Google Maps  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 8 references · NVD status: Deferred
templatescoderthemes Spexo — Spexo <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0019    9.5     —
AFFECTED
  Product  Versions     Fixed
  Spexo    unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 4 references · NVD status: Deferred
Surbma | Infusionsoft Shortcode <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0019    9.1     —
AFFECTED
  Product                          Versions     Fixed
  Surbma | Infusionsoft Shortcode  unspecified  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 5 references · NVD status: Deferred
harmonic_design HD Quiz — HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  N  L  N    4.3   .0018    7.7     —
AFFECTED
  Product  Versions  Fixed
  HD Quiz  2.2.0 –   —
TIMELINE
  Jun 26  Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-352 · CNA: Wordfence · 16 references · NVD status: Deferred
FreeBSD FreeBSD — Multiple vulnerabilities in the sound(4) mmap path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0015    4.8     —
AFFECTED
  Product  Versions        Fixed
  FreeBSD  15.0-RELEASE –  —
TIMELINE
  May 11  Reserved by CNA
  Jun 27  Published (CNA: freebsd)
CWE-125, CWE-190, CWE-681, CWE-787 · CNA: freebsd · 1 reference · NVD status: Analyzed
FreeBSD FreeBSD — Flaw in Linuxulator execution of setugid binaries
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  N  H  H    7.1   .0015    4.7     —
AFFECTED
  Product  Versions        Fixed
  FreeBSD  15.0-RELEASE –  —
TIMELINE
  May 29  Reserved by CNA
  Jun 27  Published (CNA: freebsd)
CWE-266 · CNA: freebsd · 1 reference · NVD status: Analyzed
Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0015    4.6     —
AFFECTED
  Product                                                     Versions     Fixed
  Masteriyo LMS – LMS Course Builder, Quizzes & Certificates  unspecified  —
TIMELINE
  Jun 9   Reserved by CNA
  Jun 27  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 6 references · NVD status: Deferred
Unknown Shariff for WordPress — Shariff for WordPress <= 1.0.11 - Admin+ Stored Cross-Site Scripting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   R  C  L  L  N    4.8   .0014    4.3     —
AFFECTED
  Product                Versions     Fixed
  Shariff for WordPress  unspecified  —
TIMELINE
  May 27  Reserved by CNA
  Jun 27  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-494177.02.9FreeBSDFreeBSDCWE-416Multiple vulnerabilities in the sound(4) mmap path
CVE-2026-106437.82.6zephyrprojectzephyrCWE-787Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_p…
CVE-2025-598685.51.4HCLSoftwareTraveler for Microsoft OutlookCWE-532HCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data ex…
CVE-2026-494167.81.3FreeBSDFreeBSDCWE-190Integer overflow in vt(4) CONS_HISTORY ioctl
CVE-2026-494147.81.3FreeBSDFreeBSDCWE-179ASLR bypass for setuid executables via procctl(2)
CVE-2026-494127.81.2FreeBSDFreeBSDCWE-416Use-after-free bug in the IPV6_MSFILTER socket option handler
CVE-2023-375247.81.0HCLSoftwareTraveler for Microsoft OutlookCWE-1104HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities d…
CVE-2026-452596.50.7FreeBSDFreeBSDCWE-266sigqueue(2) missing capability mode restriction

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-27 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.