boxscore/security
Tuesday, June 30, 2026 · all times UTC← 2026-06-29 · archive · 2026-07-01 →

641 CVEs published June 30, 2026: 97 critical, 200 high, 327 medium, 17 low; 0 in KEV; 16 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 616 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published79461231811822563
KEV catalog size1670

535 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux514148011985450412730.27.8.0013-126
google10901264133564527377460.57.5.0023+922
microsoft221711554751604378273.87.8.0044+51
red hat1281921082928400.06.8.0026+87
apple52991236629377.16.5.0031+32
canonical6202585000.05.5.0011-8
freebsd91601240000.07.8.0015+2
suse11133730000.08.6.0029+9
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco10234480961147.87.0.0431+5
netgear171700161800.04.3.0024+17
palo alto networks911017114218.24.8.0022+7
ubiquiti81174004327.39.9.0083+6
f56943107111.18.9.0221+4
ivanti49230033555.68.8.5187+2
checkpoint3915303111.17.5.0410-3
fortinet28132028337.57.3.0066+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache121153245761104010.77.2.0048+100
mozilla505612182601300.07.3.0026+44
gitlab243305215426.14.4.0022+17
docker470520100.08.2.0016+1
github461140000.06.2.0023+2
drupal0511305120.05.1.0026-5
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2432701311161844020.78.8.0040+218
adobe14214611527827532.15.5.0021+141
ibm751243642460700.07.5.0025+26
progress591710900.07.5.0036+1
solarwinds47122011457.17.5.0835+4
veeam142200400.09.0.0046-2
zohocorp131110000.08.4.0170-1
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025-13
d-link101305252617.75.8.0059+8
siemens890450100.06.9.0019+7
rockwell automation771510000.08.7.0030+7
abb660420000.07.2.0018+6
schneider electric660420100.07.8.0024+6
moxa550320000.07.0.0029+5
dahua330111200.06.9.0036+3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+71
sourcecodester4971003635000.05.5.0026+29
openclaw61670352210000.07.0.0021+55
edimax1465039026100.07.4.0059-33
capgo6161231271000.07.1.0031+61
themerex585855300000.08.1.0043+58
dell3856130240211.87.2.0016+26
itsourcecode4353001835000.02.1.0025+33

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4827610.0.0505
CVE-2026-1377310.0.0341
CVE-2026-5641310.0.0316
CVE-2026-5641510.0.0315
CVE-2026-5357610.0.0219
Most disclosures (vendor)
VendorCVEs
google1090
linux514
oracle243
microsoft221
adobe142
red hat128
apache121
ibm75
spring72
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco11
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven49
Packagist15
PyPI9
npm6
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-48595Google0
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171686
CVE-2021-27102Accellion2021-11-171686
CVE-2021-27101Accellion2021-11-171686
CVE-2021-27103Accellion2021-11-171686
CVE-2021-21017Adobe2021-11-171686
CVE-2021-28550Adobe2021-11-171686
CVE-2021-42013Apache2021-11-171686
CVE-2021-41773Apache2021-11-171686
CVE-2021-30858Apple2021-11-171686
CVE-2021-30860Apple2021-11-171686

Transactions

EXPLOIT PUBLISHEDCVE-2026-10652 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10653 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10654 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10655 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-4629 (Red Hat build of Keycloak 26.4). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54672 (electron-userland electron-builder). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56364 (ImageMagick). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58010 (GNOME GLib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58012 (GNOME GLib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58013 (GNOME GLib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58014 (GNOME GLib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58015 (GNOME GLib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58016 (GNOME GLib). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-9263 (zephyrproject zephyr). Public exploit reference added.

DUE DATE PASSEDCVE-2026-20262 (Cisco Catalyst SD-WAN Manager). CISA remediation deadline was June 29, 2026; still in catalog.

Yesterday's Results

641 CVEs published. 25 box scores and 375 table rows below; the remaining 241 continue on page 2 — every CVE is listed, nothing truncated.

NetScaler ADC — Insufficient input validation leading to memory overread
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   H    8.8   .1565   96.6     —
AFFECTED
  Product  Versions  Fixed
  ADC      14.1 –    —
  Gateway  14.1 –    —
TIMELINE
  May 13  Reserved by CNA
  Jun 30  Published (CNA: NetScaler)
CWE-125 · CNA: NetScaler · 1 reference · NVD status: Analyzed
conductor-oss conductor — Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0718   93.8     —
AFFECTED
  Product    Versions   Fixed
  conductor  3.21.21 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 5 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0505   91.6     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-434 · CNA: adobe · 1 reference · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  L  N    9.3   .0416   90.0     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-22 · CNA: adobe · 1 reference · NVD status: Analyzed
IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0341   87.9     —
AFFECTED
  Product                  Versions   Fixed
  WebSphere Extreme Scale  8.6.1.0 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jun 30  Published (CNA: ibm)
CWE-918 · CNA: ibm · 1 reference · NVD status: Analyzed
StoneFly Storage Concentrator — OS Command Injection in StoneFly Storage Concentrator
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0316   86.9     —
AFFECTED
  Product                               Versions     Fixed
  Storage Concentrator                  unspecified  8.0.4.29
  Storage Concentrator Virtual Machine  unspecified  8.0.4.29
TIMELINE
  Jun 22  Reserved by CNA
  Jun 30  Published (CNA: icscert)
CWE-78 · CNA: icscert · 3 references · NVD status: Deferred
Stonefly Storage Concentrator — OS Command Injection in StoneFly Storage Concentrator
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0315   86.8     —
AFFECTED
  Product                               Versions     Fixed
  Storage Concentrator                  unspecified  8.0.4.29
  Storage Concentrator Virtual Machine  unspecified  8.0.4.29
TIMELINE
  Jun 22  Reserved by CNA
  Jun 30  Published (CNA: icscert)
CWE-78 · CNA: icscert · 3 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Improper Input Validation (CWE-20)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0182   76.9     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-20 · CNA: adobe · 1 reference · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Improper Input Validation (CWE-20)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0182   76.9     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-20 · CNA: adobe · 1 reference · NVD status: Analyzed
Grav - Multiple Remote Code Execution Vulnerabilities via Unsafe Unserialize and Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0168   75.0     —
AFFECTED
  Product  Versions     Fixed
  Grav     unspecified  2.0.0-beta.2
TIMELINE
  Jun 22  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-78, CWE-502 · CNA: VulnCheck · 2 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0155   73.0     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-434 · CNA: adobe · 1 reference · NVD status: Analyzed
AVTECH Security Corporation DGM3103SCT — DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which ma…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0155   73.0     —
AFFECTED
  Product     Versions                              Fixed
  DGM3103SCT  firmware version 3.2.5.4 and prior –  —
TIMELINE
  Jun 23  Reserved by CNA
  Jun 30  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · 2 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Improper Input Validation (CWE-20)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  N    9.3   .0145   71.2     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-20 · CNA: adobe · 1 reference · NVD status: Analyzed
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0118   65.0     —
AFFECTED
  Product                 Versions     Fixed
  Apache ActiveMQ         unspecified  —
  Apache ActiveMQ All     unspecified  —
  Apache ActiveMQ Client  unspecified  —
  Apache ActiveMQ Broker  unspecified  —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 30  Published (CNA: apache)
CWE-789 · CNA: apache · 2 references · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0094   58.0     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-918 · CNA: adobe · 1 reference · NVD status: Analyzed
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0090   56.8     —
AFFECTED
  Product                 Versions     Fixed
  Apache ActiveMQ Broker  unspecified  —
  Apache ActiveMQ All     unspecified  —
  Apache ActiveMQ         unspecified  —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 30  Published (CNA: apache)
CWE-862 · CNA: apache · 2 references · NVD status: Analyzed
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0087   55.8     —
AFFECTED
  Product                       Versions     Fixed
  Adobe Campaign Classic (ACC)  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-863 · CNA: adobe · 1 reference · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   R  C  H  H  H    8.8   .0080   53.5     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-79 · CNA: adobe · 1 reference · NVD status: Analyzed
Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0078   52.9     —
AFFECTED
  Product          Versions     Fixed
  Apache ActiveMQ  unspecified  —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 30  Published (CNA: apache)
CWE-285 · CNA: apache · 2 references · NVD status: Analyzed
picklescan - Arbitrary Code Execution via Undetected doctest.debug_script
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   N    7.6   .0077   52.6     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  0.0.30
TIMELINE
  Jun 20  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 2 references · NVD status: Deferred
SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0077   52.5     —
AFFECTED
  Product    Versions     Fixed
  seaweedfs  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 6 references · NVD status: Deferred
neuml txtai — txtai - Unauthenticated Remote Code Execution via Unsafe Reflection in API /reindex function Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0073   51.1     —
AFFECTED
  Product  Versions     Fixed
  txtai    unspecified  11b32da720f03276199ebc5583c15fc5d1ccafd3
TIMELINE
  Jun 30  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 4 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0071   50.6     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-22 · CNA: adobe · 1 reference · NVD status: Analyzed
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0069   50.0     —
AFFECTED
  Product      Versions                       Fixed
  OpenAPI.NET  >= 2.0.0-preview11, < 2.7.5 –  —
TIMELINE
  May 30  Reserved by CNA
  Jun 30  Published (CNA: GitHub_M)
CWE-674 · CNA: GitHub_M · 1 reference · NVD status: Awaiting Analysis
Gotcha Gotcha Games Inc. RPG MAKER MV — RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   A   H   H   H    8.4   .0068   49.3     —
AFFECTED
  Product       Versions              Fixed
  RPG MAKER MV  1.6.3 and earlier –   —
  RPG MAKER MZ  1.10.0 and earlier –  —
TIMELINE
  Jun 19  Reserved by CNA
  Jun 30  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · 3 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-115957.548.8IBMWebSphere Application ServerCWE-22IBM WebSphere Application Server is affected by a Path Traversal vulnerability
CVE-2026-279578.848.5coollabsiocoolifyCWE-78Coolify: Authenticated RCE via command injection in CA certificate management…
CVE-2026-581169.347.9hiyougaLlamaFactoryCWE-94LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
CVE-2025-713747.647.6picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected profile.Profile.run
CVE-2025-713527.647.6picklescanpicklescanCWE-693picklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickl…
CVE-2026-581668.847.2OpenBMBChatDevCWE-22OpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arb…
CVE-2025-713637.645.2picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected cProfile.run in Pickle D…
CVE-2026-494327.544.8Apache Software FoundationApache ActiveMQCWE-20Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative c…
CVE-2026-139678.844.7GoogleChromeCWE-843Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2025-713497.644.1picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickl…
CVE-2026-137878.144.0GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.…
CVE-2025-713557.643.6PicklescanPicklescanCWE-184Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass
CVE-2026-583709.243.2woodpecker-ciwoodpeckerCWE-290Woodpecker < 3.15.0 - GitLab Approval Gate Bypass via Spoofable Commit Author…
CVE-2026-580169.143.2GNOMEGLibCWE-191Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new…
CVE-2026-101099.843.1IBMDb2CWE-94IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRD…
CVE-2026-507347.543.1Apache Software FoundationApache ActiveMQ ClientCWE-789Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authenticat…
CVE-2026-539167.543.1Apache Software FoundationApache ActiveMQCWE-789Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header…
CVE-2026-113676.542.1andraswebPixMagix – WordPress Image EditorCWE-22PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' P…
CVE-2026-137798.142.0GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871…
CVE-2026-138988.841.1GoogleChromeCWE-416Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allow…
CVE-2026-138998.841.1GoogleChromeCWE-416Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-137888.840.7GoogleChromeCWE-416Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.…
CVE-2025-713717.640.5picklescanpicklescanCWE-502picklescan - Remote Code Execution via code.InteractiveInterpreter Detection …
CVE-2026-500039.340.4OFFIS DICOMDCMTK ToolkitCWE-22OFFIS DCMTK Toolkit Path Traversal
CVE-2026-86558.840.2NetScalerADCCWE-119Multiple Memory overflow vulnerabilities leading to unpredictable or erroneou…
CVE-2026-507507.539.9Apache Software FoundationApache ActiveMQ BrokerCWE-400Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authenticat…
CVE-2026-536918.639.9RedeightRedeight CMSCWE-434Remote Code Execution in Redeight CMS
CVE-2026-84528.839.8NetScalerADCCWE-119Memory overflow vulnerability leading to unpredictable or erroneous behavior …
CVE-2026-137868.839.3GoogleChromeCWE-416Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-138158.839.3GoogleChromeCWE-416Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-580157.539.3GNOMEGLibCWE-22Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_…
CVE-2026-141629.338.8AdvantechHospital Quering ManagementCWE-306Advantech|Hospital Quering Management - Missing Authentication
CVE-2026-134748.738.8NetScalerADCCWE-401Denial of service via malformed HTTP/2 requests
CVE-2026-527606.138.8Apache Software FoundationApache ActiveMQCWE-79Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values…
CVE-2026-494347.538.5Apache Software FoundationApache ActiveMQ BrokerCWE-20Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConn…
CVE-2026-137947.538.2GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-139257.538.2GoogleChromeCWE-20Inappropriate implementation in Downloads in Google Chrome on Windows prior t…
CVE-2026-138708.838.1GoogleChromeCWE-416Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 …
CVE-2026-138858.838.1GoogleChromeCWE-416Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 all…
CVE-2026-139658.838.1GoogleChromeCWE-416Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-583758.737.9jeecgbootjimureportCWE-306JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export
CVE-2026-141647.537.9Red HatRed Hat Enterprise Linux 10CWE-415Libarchive: double-free vulnerability in rar5 decompression logic via danglin…
CVE-2026-108176.937.9NetScalerADCCWE-125Insufficient input validation leading to memory overread
CVE-2026-410538.837.6SUSERancherCWE-303Over-inclusive team membership expansion in GitHub App authentication provide…
CVE-2026-521957.537.5n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-521967.537.5n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-562338.737.5CapgoCapgoCWE-22Capgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload Proxy
CVE-2026-78719.837.3IBMLangflow OSSCWE-502Insecure Deserialization in Redis Cache Backend
CVE-2026-557219.237.1StoneFlyStorage ConcentratorCWE-89SQL Injection in StoneFly Storage Concentrator
CVE-2026-137769.836.9GoogleChromeCWE-843Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-138058.836.9GoogleChromeCWE-416Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed …
CVE-2026-138118.836.9GoogleChromeCWE-416Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remot…
CVE-2026-138218.836.9GoogleChromeCWE-416Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-138458.836.9GoogleChromeCWE-416Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remot…
CVE-2026-138488.836.9GoogleChromeCWE-416Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-138888.836.9GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-137989.636.9GoogleChromeCWE-122Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 al…
CVE-2026-141618.736.4AdvantechHospital Queuing ManagementCWE-200Advantech|Hospital Queuing Management - Sensitive Data Exposure
CVE-2026-584466.936.4presentonpresentonCWE-306Presenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotecte…
CVE-2026-139019.636.3GoogleChromeCWE-20Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.787…
CVE-2026-139038.836.3GoogleChromeCWE-602Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.…
CVE-2026-137998.136.3GoogleChromeCWE-416Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-137899.636.2GoogleChromeCWE-416Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remot…
CVE-2026-446288.736.1OFFIS DICOMDCMTK ToolkitCWE-843OFFIS DCMTK Toolkit Type Confusion
CVE-2026-138027.536.0GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-137918.135.5GoogleChromeCWE-20Insufficient validation of untrusted input in Downloads in Google Chrome prio…
CVE-2026-137748.135.4GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-521937.535.3n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-521987.535.3n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-355058.734.7OFFIS DICOMDCMTK ToolkitCWE-401OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime
CVE-2026-502548.734.7OFFIS DICOMDCMTK ToolkitCWE-401OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime
CVE-2026-581707.234.7HKUDSVibe-TradingCWE-22Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging …
CVE-2026-78039.834.6IBMLangflow OSSCWE-20Flow Validation Bypass via Empty Component Type Field
CVE-2026-108167.134.6NetScalerADCCWE-610Arbitrary File Read (Unauthenticated)
CVE-2026-138308.834.6GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47…
CVE-2026-139196.534.5GoogleChromeCWE-602Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0…
CVE-2026-139216.534.5GoogleChromeCWE-20Insufficient validation of untrusted input in DeviceBoundSessionCredentials i…
CVE-2026-139306.534.5GoogleChromeCWE-602Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871…
CVE-2026-581729.334.3ThreeMammalsOcelotCWE-288Ocelot - IP Allow/Block List Bypass for WebSocket Upgrade Requests
CVE-2026-581687.734.3HKUDSDeepTutorCWE-862DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to …
CVE-2026-137929.634.2GoogleChromeCWE-416Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 all…
CVE-2026-138439.634.2GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-138469.634.2GoogleChromeCWE-416Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed …
CVE-2026-138699.634.2GoogleChromeCWE-416Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 a…
CVE-2026-139099.634.2GoogleChromeCWE-693Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7…
CVE-2026-139209.634.2GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome on Windo…
CVE-2026-139349.634.2GoogleChromeCWE-20Insufficient validation of untrusted input in Dawn in Google Chrome on Androi…
CVE-2026-138178.834.2GoogleChromeCWE-20Insufficient validation of untrusted input in Glic in Google Chrome prior to …
CVE-2026-138358.834.2GoogleChromeCWE-122Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-139158.834.2GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.…
CVE-2026-139188.834.2GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.…
CVE-2026-139288.834.2GoogleChromeCWE-20Insufficient validation of untrusted input in Enterprise in Google Chrome pri…
CVE-2026-139388.834.2GoogleChromeCWE-472Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-528688.834.2OFFIS DICOMDCMTK ToolkitCWE-22OFFIS DCMTK Toolkit Path Traversal
CVE-2026-139687.534.1GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-521977.534.1n/an/aCWE-400An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker …
CVE-2026-137759.833.9GoogleChromeCWE-416Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remot…
CVE-2026-137809.633.9GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-137819.633.9GoogleChromeCWE-20Insufficient validation of untrusted input in Skia in Google Chrome prior to …
CVE-2026-137859.633.9GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al…
CVE-2026-137838.833.9GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-137848.833.9GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-139236.533.8GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 a…
CVE-2026-139436.533.8GoogleChromeCWE-457Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 a…
CVE-2026-138038.333.7GoogleChromeCWE-843Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed…
CVE-2026-138317.533.6GoogleChromeCWE-416Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-138557.533.6GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo…
CVE-2026-139066.533.3GoogleChromeCWE-125Out of bounds read in Codecs in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-536909.333.2RedeightRedeight CMSCWE-89SQL Injection in Redeight CMS
CVE-2026-138198.133.1GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 al…
CVE-2026-141049.833.0GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-140678.832.9GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.…
CVE-2026-139246.532.9GoogleChromeCWE-20Insufficient validation of untrusted input in WebView in Google Chrome on And…
CVE-2026-139266.532.9GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-138839.632.8GoogleChromeCWE-843Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-138258.832.8GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-138298.332.8GoogleChromeCWE-20Insufficient validation of untrusted input in Settings in Google Chrome on Wi…
CVE-2026-138348.332.8GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-138978.832.7GoogleChromeCWE-284Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0…
CVE-2025-713507.632.7picklescanpicklescanCWE-502picklescan - Undetected Remote Code Execution via torch.utils.collect_env.run
CVE-2026-138917.532.4GoogleChromeCWE-20Insufficient validation of untrusted input in Extensions in Google Chrome pri…
CVE-2026-139586.532.3GoogleChromeCWE-457Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.4…
CVE-2026-138068.132.3GoogleChromeCWE-20Insufficient validation of untrusted input in Accessibility in Google Chrome …
CVE-2026-137906.532.0GoogleChromeCWE-1300Side-channel information leakage in Scroll in Google Chrome prior to 150.0.78…
CVE-2026-138106.532.0GoogleChromeCWE-200Inappropriate implementation in Input in Google Chrome on Linux prior to 150.…
CVE-2026-138476.532.0GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-139226.532.0GoogleChromeCWE-1300Side-channel information leakage in Paint in Google Chrome prior to 150.0.787…
CVE-2026-139356.532.0GoogleChromeCWE-1300Side-channel information leakage in ComputePressure in Google Chrome prior to…
CVE-2026-139475.331.9GoogleChromeCWE-457Uninitialized Use in XR in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-139505.331.9GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-138896.531.6GoogleChromeCWE-20Side-channel information leakage in WebAuthentication in Google Chrome on iOS…
CVE-2026-1378210.031.1GoogleChromeCWE-416Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-137969.631.1GoogleChromeCWE-472Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe…
CVE-2026-137979.631.1GoogleChromeCWE-20Insufficient validation of untrusted input in Chromecast in Google Chrome pri…
CVE-2026-137778.831.1GoogleChromeCWE-20Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS …
CVE-2026-139115.331.1GoogleChromeCWE-20Insufficient policy enforcement in Spellcheck in Google Chrome prior to 150.0…
CVE-2026-138336.530.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 all…
CVE-2026-139006.530.7GoogleChromeCWE-20Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.78…
CVE-2026-139376.530.5GoogleChromeCWE-284Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.…
CVE-2026-139546.530.5GoogleChromeCWE-284Insufficient policy enforcement in XML in Google Chrome on Android prior to 1…
CVE-2026-138077.530.4GoogleChromeCWE-416Use after free in Import in Google Chrome on iOS prior to 150.0.7871.47 allow…
CVE-2026-138166.530.4GoogleChromeCWE-20Insufficient validation of untrusted input in File Input in Google Chrome on …
CVE-2026-139106.530.4GoogleChromeCWE-693Insufficient policy enforcement in WebXR in Google Chrome on Android prior to…
CVE-2026-105625.930.4TP-Link Systems Inc.Archer AX20 V2.0CWE-601Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface
CVE-2026-138018.330.3GoogleChromeCWE-472Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe…
CVE-2026-138048.330.3GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-138238.330.3GoogleChromeCWE-416Use after free in Glic in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-138328.330.3GoogleChromeCWE-416Use after free in Headless in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-138418.330.3GoogleChromeCWE-472Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-139518.330.3GoogleChromeCWE-693Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.4…
CVE-2026-580138.230.2GNOMEGLibCWE-126Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
CVE-2026-138147.530.3GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-138736.530.3GoogleChromeCWE-125Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-138138.330.1GoogleChromeCWE-20Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2026-138247.530.1GoogleChromeCWE-20Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0…
CVE-2026-138567.530.1GoogleChromeCWE-20Insufficient validation of untrusted input in Speech in Google Chrome on Andr…
CVE-2026-138936.530.1GoogleChromeCWE-20Insufficient validation of untrusted input in WebUI in Google Chrome prior to…
CVE-2026-562789.329.8FlowiseFlowiseCWE-798Flowise - Session Hijacking via Weak Default Express Session Secret
CVE-2026-580117.529.8GNOMEGLibCWE-125Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid …
CVE-2026-138755.329.7GoogleChromeCWE-20Insufficient validation of untrusted input in GPU in Google Chrome on Windows…
CVE-2026-138539.629.4GoogleChromeCWE-416Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-138549.629.4GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo…
CVE-2026-138599.629.4GoogleChromeCWE-693Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47…
CVE-2026-138619.629.4GoogleChromeCWE-416Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-138789.629.4GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al…
CVE-2026-138809.629.4GoogleChromeCWE-416Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed …
CVE-2026-580108.229.4GNOMEGLibCWE-126Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
CVE-2026-580128.229.4GNOMEGLibCWE-126Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append()…
CVE-2026-583696.929.3woodpecker-ciwoodpeckerCWE-476Woodpecker < 3.15.0 - Unauthenticated NULL Pointer Dereference in /api/orgs/l…
CVE-2026-139695.329.2GoogleChromeCWE-457Uninitialized Use in UI in Google Chrome on Android prior to 150.0.7871.47 al…
CVE-2026-139705.329.2GoogleChromeCWE-457Uninitialized Use in Media in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-139715.329.2GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-117089.329.1IBMWebSphere Application ServerCWE-79IBM WebSphere Application Server is affected by a cross-site scripting vulner…
CVE-2026-138096.529.0GoogleChromeCWE-1300Side-channel information leakage in Safe Browsing in Google Chrome on iOS pri…
CVE-2026-139326.529.0GoogleChromeCWE-284Inappropriate implementation in Sharing in Google Chrome on Android prior to …
CVE-2026-139366.529.0GoogleChromeCWE-284Inappropriate implementation in Passwords in Google Chrome on Android prior t…
CVE-2026-138648.128.9GoogleChromeCWE-284Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.787…
CVE-2026-138586.528.9GoogleChromeCWE-125Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-1013410.028.8IBMLangflow OSSCWE-94Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
CVE-2026-138926.528.7GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-138775.328.5GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-139615.328.5GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome on Wi…
CVE-2026-562867.028.4CapgoCapgoCWE-306Capgo - Account Deletion Without Password Confirmation
CVE-2026-138716.528.4GoogleChromeCWE-602Insufficient policy enforcement in GuestView in Google Chrome prior to 150.0.…
CVE-2026-139626.528.4GoogleChromeCWE-20Insufficient data validation in PDF in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-132078.728.3FrangoteamFUXA SCADA/HMICWE-290Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing
CVE-2026-141785.928.2openGauss-serveropenGauss-server-7.0.0-RC2CWE-416openGauss存在非法内存访问导致DoS漏洞
CVE-2026-137669.828.0EXODISTDBIx::QuickORMCWE-89DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unqu…
CVE-2026-563008.727.9CapgoCapgoCWE-200Capgo - Unauthenticated API Key Validity and Permission Oracle via RPC Functions
CVE-2026-138519.127.9GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-138529.127.9GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-131497.727.9juliangruberbrace-expansionCWE-400brace-expansion through 5.0.6 is vulnerable to denial of service. The expand(…
CVE-2025-536485.427.9Apache Software FoundationApache GravitinoCWE-89Apache Gravitino: SQL misconfiguration can access or truncate files
CVE-2026-138286.527.6GoogleChromeCWE-284Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.78…
CVE-2026-139646.527.6GoogleChromeCWE-284Insufficient policy enforcement in WebView in Google Chrome on Android prior …
CVE-2026-69535.127.5Intermark ITWebControl CMSCWE-79Multiple vulnerabilities in Intermark IT's WebControl CMS
CVE-2026-138206.527.4GoogleChromeCWE-125Out of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871.47 all…
CVE-2026-138905.327.3GoogleChromeCWE-125Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allo…
CVE-2026-139335.327.2GoogleChromeCWE-284Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.…
CVE-2026-562198.727.1CapgoCapgoCWE-287Capgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_a…
CVE-2026-138186.527.0GoogleChromeCWE-284Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787…
CVE-2026-139536.527.0GoogleChromeCWE-284Inappropriate implementation in SplitView in Google Chrome prior to 150.0.787…
CVE-2026-141219.826.9GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47…
CVE-2026-138848.826.9GoogleChromeCWE-122Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe…
CVE-2026-138666.526.9GoogleChromeCWE-20Inappropriate implementation in Input in Google Chrome on Android prior to 15…
CVE-2026-545026.326.7ohler55ojCWE-121Oj: Stack Buffer Overflow in Oj.dump via Large Indent
CVE-2026-117129.326.5IBMWebSphere Application ServerCWE-79IBM WebSphere Application Server is affected by a cross-site scripting vulner…
CVE-2026-78739.926.4IBMLangflow OSSCWE-94Code Injection Vulnerability in Code Validation Endpoint
CVE-2026-562649.226.3Crawl4AICrawl4AICWE-94Crawl4AI - Arbitrary JavaScript Execution via /execute_js Endpoint
CVE-2026-139046.526.2GoogleChromeCWE-693Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior t…
CVE-2026-122408.026.0qlstudioExport User DataCWE-502Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection …
CVE-2026-139316.525.9GoogleChromeCWE-284Inappropriate implementation in Media in Google Chrome on Windows prior to 15…
CVE-2026-76639.825.7IBMLangflow OSSCWE-863Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streama…
CVE-2026-138729.125.6GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-137956.525.6GoogleChromeCWE-602Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2026-141498.825.3GoogleChromeCWE-416Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allo…
CVE-2026-579958.725.4phpMyFAQphpMyFAQCWE-269phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupCo…
CVE-2026-46296.525.4Red HatRed Hat build of Keycloak 26.4CWE-266Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
CVE-2026-138508.825.2GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-350986.925.1KTM Systeme-BOKCWE-307Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK
CVE-2026-562308.725.0CapgoCapgoCWE-639Capgo - Broken Object Level Authorization via x-limited-key-id Header
CVE-2026-84029.824.9Eksagate Electronic Engineering and Computer Industry Trade Inc.SYSGUARD 6001CWE-89SQLi in Exagate's SYSGUARD 6001
CVE-2026-580148.624.9GNOMEGLibCWE-193Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_l…
CVE-2026-563995.324.8open-webuiopen-webuiCWE-918Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/ret…
CVE-2026-140236.524.7GoogleChromeCWE-20Insufficient validation of untrusted input in SanitizerAPI in Google Chrome p…
CVE-2026-140656.524.6GoogleChromeCWE-20Insufficient validation of untrusted input in PageInfo in Google Chrome prior…
CVE-2026-141118.124.6GoogleChromeCWE-416Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-140248.824.4GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo…
CVE-2026-140258.824.4GoogleChromeCWE-416Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowe…
CVE-2026-120769.324.1RaythaRaythaCWE-89SQL Injection in Raytha CMS
CVE-2026-140868.824.2GoogleChromeCWE-602Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.4…
CVE-2026-92638.124.1zephyrprojectzephyrCWE-125Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks a…
CVE-2026-138866.524.0GoogleChromeCWE-693Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior t…
CVE-2026-138966.524.0GoogleChromeCWE-602Insufficient policy enforcement in Glic in Google Chrome prior to 150.0.7871.…
CVE-2026-139176.524.0GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-140106.523.8GoogleChromeCWE-457Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.4…
CVE-2026-120739.823.7metagaussProfileGrid – User Profiles, Groups and CommunitiesCWE-639ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthentica…
CVE-2026-128199.323.7deltawwDVP-12SECWE-306DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability
CVE-2026-106527.423.5zephyrprojectzephyrCWE-125Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated…
CVE-2026-581736.023.3HKUDSVibe-TradingCWE-22Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type
CVE-2026-570795.323.2SANKONet::BitTorrentCWE-22Net::BitTorrent versions before 2.1.0 for Perl write files outside the downlo…
CVE-2026-137598.823.0IBMWebSphere Extreme ScaleCWE-502IBM WebSphere eXtreme Scale is affected by Insecure Deserilization
CVE-2026-562478.722.9CapgoCapgoCWE-266Capgo - Privilege Escalation via Cross-Scope RBAC Role Assignment
CVE-2026-139594.322.9GoogleChromeCWE-20Insufficient validation of untrusted input in Blink in Google Chrome prior to…
CVE-2026-65569.122.7@fastify/express@fastify/expressCWE-285@fastify/express vulnerable to middleware bypass via non-string mount paths i…
CVE-2026-137936.522.8GoogleChromeCWE-346Insufficient policy enforcement in SVG in Google Chrome prior to 150.0.7871.4…
CVE-2026-138406.522.8GoogleChromeCWE-346Insufficient policy enforcement in Canvas in Google Chrome prior to 150.0.787…
CVE-2026-138626.522.7GoogleChromeCWE-693Insufficient policy enforcement in Web Authentication (Passkeys & Security Ke…
CVE-2026-139136.522.8GoogleChromeCWE-346Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to …
CVE-2026-106555.922.7zephyrprojectzephyrCWE-416Use-after-free race in SNTP async client when closing the socket while the so…
CVE-2026-546963.722.7rubyjsonCWE-122Ruby JSON: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-97119.822.6EventONEventON (Pro) - WordPress Virtual Event Calendar PluginCWE-89EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated…
CVE-2026-140046.522.5GoogleChromeCWE-200Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-140226.522.5GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-583747.122.0w1.fihostapdCWE-193In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.1…
CVE-2026-138374.322.0GoogleChromeCWE-451Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-138654.322.0GoogleChromeCWE-20Insufficient validation of untrusted input in Enterprise in Google Chrome pri…
CVE-2026-138674.322.0GoogleChromeCWE-451Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7…
CVE-2026-139024.322.0GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-139124.322.0GoogleChromeCWE-451Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior t…
CVE-2026-139164.322.0GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-139414.322.0GoogleChromeCWE-451Inappropriate implementation in SiteSettings in Google Chrome on Android prio…
CVE-2026-139604.322.0GoogleChromeCWE-451Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787…
CVE-2026-139664.322.0GoogleChromeCWE-451Inappropriate implementation in History in Google Chrome prior to 150.0.7871.…
CVE-2026-449485.321.7SUSERancherCWE-23Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler
CVE-2026-449469.521.6SUSERancherCWE-294SAML Authentication Replay in Rancher
CVE-2026-140068.821.6GoogleChromeCWE-416Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-140918.821.6GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-141078.821.6GoogleChromeCWE-416Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-458226.621.6SamVerschuerendecode-uri-componentCWE-400decode-uri-component through 0.4.1 is vulnerable to denial of service. The de…
CVE-2026-138829.621.5GoogleChromeCWE-362Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker…
CVE-2026-140878.821.5GoogleChromeCWE-787Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871…
CVE-2026-138266.521.5GoogleChromeCWE-346Inappropriate implementation in Autofill in Google Chrome on Android prior to…
CVE-2026-138876.521.5GoogleChromeCWE-346Inappropriate implementation in NFC in Google Chrome on Android prior to 150.…
CVE-2026-139086.521.4GoogleChromeCWE-20Insufficient validation of untrusted input in Omnibox in Google Chrome on iOS…
CVE-2026-139496.521.3GoogleChromeCWE-284Insufficient policy enforcement in Payments in Google Chrome on Android prior…
CVE-2026-140746.521.2GoogleChromeCWE-1300Side-channel information leakage in WebAuthentication in Google Chrome on iOS…
CVE-2026-138366.121.2GoogleChromeCWE-79Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-581697.721.1HKUDSVibe-TradingCWE-346Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS…
CVE-2026-119066.521.0IBMDb2CWE-1284IBM® Db2® federated server is vulnerable to a denial of service due to improp…
CVE-2026-552236.320.9swaldmanc3p0CWE-502c3p0 exposes a deserialization "sink" via JDBC DataSource bean properties
CVE-2026-563656.320.9ImageMagickImageMagickCWE-401ImageMagick - Memory Leak in PNG Encoder via MNG Image Writing
CVE-2026-137729.920.8IBMWebSphere Extreme ScaleCWE-470IBM WebSphere eXtreme Scale's OQL is affected by remote code execution
CVE-2026-138386.520.7GoogleChromeCWE-346Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-138396.520.7GoogleChromeCWE-346Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-138424.320.7GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-139464.320.7GoogleChromeCWE-352Inappropriate implementation in ScriptInjections in Google Chrome on iOS prio…
CVE-2026-139524.320.7GoogleChromeCWE-352Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150…
CVE-2025-713816.920.4HonoHonoCWE-113Hono - Vary Header Injection in CORS Middleware
CVE-2026-106538.120.3zephyrprojectzephyrCWE-415Non-atomic `net_buf` reference counts cause double-free / free-list corruptio…
CVE-2026-575857.520.4msgpackmsgpack-pythonCWE-416MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error
CVE-2026-545927.520.3ohler55ojCWE-125Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
CVE-2026-570807.520.3SANKONet::BitTorrentCWE-400Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustio…
CVE-2026-570817.520.3SANKONet::BitTorrentCWE-400Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustio…
CVE-2026-43602.020.1Python Software FoundationCPythonCWE-281Tarfile.extract() doesn't fully respect filter parameter
CVE-2026-115898.820.0UnknownWP Support Plus Responsive Ticket SystemWP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XS…
CVE-2026-139393.120.1GoogleChromeCWE-20Insufficient validation of untrusted input in WebShare in Google Chrome on An…
CVE-2026-140647.519.9GoogleChromeCWE-416Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47…
CVE-2026-139724.319.9GoogleChromeCWE-451Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47…
CVE-2026-140336.519.8GoogleChromeCWE-602Insufficient policy enforcement in Media in Google Chrome on Windows prior to…
CVE-2026-105609.119.6IBMLangflow OSSCWE-287Unauthenticated Access to Private Flow Build Events and Cancellation in Langf…
CVE-2026-69545.119.6Intermark ITWebControl CMSCWE-79Multiple vulnerabilities in Intermark IT's WebControl CMS
CVE-2026-138686.519.4GoogleChromeCWE-346Inappropriate implementation in Network in Google Chrome on Android prior to …
CVE-2026-138954.219.3GoogleChromeCWE-451Inappropriate implementation in Autofill in Google Chrome prior to 150.0.7871…
CVE-2026-139074.219.3GoogleChromeCWE-451Inappropriate implementation in iOSWeb in Google Chrome on iOS prior to 150.0…
CVE-2026-140328.119.2GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al…
CVE-2026-141088.819.1GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-138766.519.1GoogleChromeCWE-693Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.…
CVE-2026-139748.118.8GoogleChromeCWE-472Integer overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871…
CVE-2026-138816.518.6GoogleChromeCWE-346Inappropriate implementation in WebAppInstalls in Google Chrome prior to 150.…
CVE-2026-141209.618.5GoogleChromeCWE-20Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871…
CVE-2026-141256.518.5GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-581746.018.4nesquenahermes-webuiCWE-732Hermes WebUI < 0.51.521 - Cross-Profile Authorization Bypass via Unset Sessio…
CVE-2026-138745.318.4GoogleChromeCWE-362Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote…
CVE-2026-581767.118.4dromaraRuoYi-Vue-PlusCWE-862RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints
CVE-2026-140076.518.3GoogleChromeCWE-602Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior t…
CVE-2026-140179.618.2GoogleChromeCWE-693Inappropriate implementation in Navigation in Google Chrome prior to 150.0.78…
CVE-2026-140439.618.2GoogleChromeCWE-416Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowe…
CVE-2026-140449.618.2GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-140559.618.2GoogleChromeCWE-20Insufficient validation of untrusted input in Device Trust in Google Chrome o…
CVE-2026-141099.618.2GoogleChromeCWE-20Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.…
CVE-2026-140278.818.2GoogleChromeCWE-416Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-140368.818.2GoogleChromeCWE-602Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.…
CVE-2026-140418.818.2GoogleChromeCWE-602Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.787…
CVE-2026-140788.818.2GoogleChromeCWE-20Insufficient validation of untrusted input in WebRTC in Google Chrome prior t…
CVE-2026-583778.618.2jeecgbootJeecgBootCWE-862JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endp…
CVE-2026-140908.118.2GoogleChromeCWE-125Insufficient validation of untrusted input in CameraCapture in Google Chrome …
CVE-2026-141069.618.1GoogleChromeCWE-20Insufficient validation of untrusted input in Text in Google Chrome on Androi…
CVE-2026-115908.618.1UnknownWP Support Plus Responsive Ticket SystemWP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injec…
CVE-2026-118067.518.1IBMWebSphere Application Server - LibertyCWE-444IBM WebSphere Application Server Liberty is affected by a an arbitrary file r…
CVE-2026-138574.218.1GoogleChromeCWE-451Inappropriate implementation in Geometry in Google Chrome prior to 150.0.7871…
CVE-2026-138604.218.1GoogleChromeCWE-451Incorrect security UI in Autofill in Google Chrome on Windows prior to 150.0.…
CVE-2026-139564.218.1GoogleChromeCWE-451Incorrect security UI in PageInfo in Google Chrome prior to 150.0.7871.47 all…
CVE-2026-563186.917.9CapgoCapgoCWE-200Capgo - Information Disclosure via /private/validate_password_compliance Endp…
CVE-2026-563276.917.9CapgoCapgoCWE-203Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_…
CVE-2026-138124.718.0GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-140516.517.8GoogleChromeCWE-457Uninitialized Use in GamepadAPI in Google Chrome prior to 150.0.7871.47 allow…
CVE-2026-140706.517.7GoogleChromeCWE-457Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-140886.517.8GoogleChromeCWE-457Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.4…
CVE-2026-500405.117.7StoneFlyStorage ConcentratorCWE-79Cross-site Scripting in StoneFly Storage Concentrator
CVE-2026-563506.017.7n8nn8nCWE-285n8n - SSO Enforcement Bypass via API
CVE-2026-140389.317.5GoogleChromeCWE-20Insufficient validation of untrusted input in New Tab Page in Google Chrome p…
CVE-2026-562497.217.5CapgoCapgoCWE-285Capgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /chann…
CVE-2026-140216.517.5GoogleChromeCWE-20Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to…
CVE-2026-140506.517.5GoogleChromeCWE-693Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.…
CVE-2026-140596.517.5GoogleChromeCWE-693Insufficient policy enforcement in Related-Website-Sets in Google Chrome prio…
CVE-2026-140856.517.5GoogleChromeCWE-1300Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.…
CVE-2026-141036.517.5GoogleChromeCWE-416Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 all…
CVE-2026-91326.017.5GitHubEnterprise ServerCWE-862Missing authorization vulnerability in GitHub Enterprise Server allowed discl…
CVE-2026-115419.817.4IBMCICS Transaction Gateway for MultiplatformsCWE-444Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for …
CVE-2026-140998.817.3GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.…
CVE-2026-139856.517.2GoogleChromeCWE-290Inappropriate implementation in MediaCapture in Google Chrome prior to 150.0.…
CVE-2026-141139.617.1GoogleChromeCWE-416Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 …
CVE-2026-141466.517.1GoogleChromeCWE-200Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-128189.316.9deltawwDVP-12SECWE-770DVP-12SE Exposure of Sensitive Information Vulnerability
CVE-2026-140098.816.9GoogleChromeCWE-20Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787…
CVE-2026-107637.016.9Hitachi EnergyPROMOD VCWE-1428PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerabi…
CVE-2026-548996.317.0ohler55ojCWE-416Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
CVE-2026-549006.317.0ohler55ojCWE-190Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
CVE-2026-549016.317.0ohler55ojCWE-416Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
CVE-2026-549026.317.0ohler55ojCWE-416Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
CVE-2026-549036.317.0ohler55ojCWE-190Oj: Integer Overflow in Oj.load 2GB String Handling
CVE-2026-581712.317.0HKUDSVibe-TradingCWE-22Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier
CVE-2026-142419.816.8MozillaFirefoxCWE-787Memory safety bugs fixed in Firefox 152.0.4
CVE-2026-140379.616.9GoogleChromeCWE-693Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.4…
CVE-2026-141028.816.9GoogleChromeCWE-416Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a…
CVE-2026-138796.516.7GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a…
CVE-2026-138946.516.7GoogleChromeCWE-602Insufficient policy enforcement in Network in Google Chrome prior to 150.0.78…
CVE-2026-139443.116.7GoogleChromeCWE-352Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to…
CVE-2026-139633.116.7GoogleChromeCWE-352Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871…
CVE-2026-563316.916.6CapgoCapgoCWE-209Capgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Mag…
CVE-2026-140086.516.6GoogleChromeCWE-457Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47…
CVE-2026-141186.516.6GoogleChromeCWE-290Insufficient data validation in DevTools in Google Chrome prior to 150.0.7871…
CVE-2025-363194.316.6IBMwatsonx.data intelligenceCWE-770Vulnerabilities found in Watson Data Intelligence
CVE-2026-350976.916.5KTM Systeme-BOKCWE-521Weak Password Requirements in KTM System e-BOK

Results continue: ranks 401–641.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-30 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.