AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H L H 8.8 .1565 96.6 —
AFFECTED Product Versions Fixed ADC 14.1 – — Gateway 14.1 – —
TIMELINE May 13 Reserved by CNA Jun 30 Published (CNA: NetScaler)
641 CVEs published June 30, 2026: 97 critical, 200 high, 327 medium, 17 low; 0 in KEV; 16 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 616 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 7946 | 12318 | 1182 | 2563 |
| KEV catalog size | 1670 | |||
535 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 514 | 1480 | 119 | 854 | 504 | 1 | 27 | 3 | 0.2 | 7.8 | .0013 | -126 |
| 1090 | 1264 | 133 | 564 | 527 | 37 | 74 | 6 | 0.5 | 7.5 | .0023 | +922 | |
| microsoft | 221 | 711 | 55 | 475 | 160 | 4 | 378 | 27 | 3.8 | 7.8 | .0044 | +51 |
| red hat | 128 | 192 | 10 | 82 | 92 | 8 | 4 | 0 | 0.0 | 6.8 | .0026 | +87 |
| apple | 52 | 99 | 1 | 23 | 66 | 2 | 93 | 7 | 7.1 | 6.5 | .0031 | +32 |
| canonical | 6 | 20 | 2 | 5 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | -8 |
| freebsd | 9 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | +2 |
| suse | 11 | 13 | 3 | 7 | 3 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +9 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 10 | 23 | 4 | 4 | 8 | 0 | 96 | 11 | 47.8 | 7.0 | .0431 | +5 |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | +17 |
| palo alto networks | 9 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | +7 |
| ubiquiti | 8 | 11 | 7 | 4 | 0 | 0 | 4 | 3 | 27.3 | 9.9 | .0083 | +6 |
| f5 | 6 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | +4 |
| ivanti | 4 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | +2 |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 |
| fortinet | 2 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 121 | 153 | 24 | 57 | 61 | 10 | 40 | 1 | 0.7 | 7.2 | .0048 | +100 |
| mozilla | 50 | 56 | 12 | 18 | 26 | 0 | 13 | 0 | 0.0 | 7.3 | .0026 | +44 |
| gitlab | 24 | 33 | 0 | 5 | 21 | 5 | 4 | 2 | 6.1 | 4.4 | .0022 | +17 |
| docker | 4 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | +1 |
| github | 4 | 6 | 1 | 1 | 4 | 0 | 0 | 0 | 0.0 | 6.2 | .0023 | +2 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | -5 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 243 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | +218 |
| adobe | 142 | 146 | 11 | 52 | 78 | 2 | 75 | 3 | 2.1 | 5.5 | .0021 | +141 |
| ibm | 75 | 124 | 36 | 42 | 46 | 0 | 7 | 0 | 0.0 | 7.5 | .0025 | +26 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +1 |
| solarwinds | 4 | 7 | 1 | 2 | 2 | 0 | 11 | 4 | 57.1 | 7.5 | .0835 | +4 |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | -2 |
| zohocorp | 1 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | -1 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -13 |
| d-link | 10 | 13 | 0 | 5 | 2 | 5 | 26 | 1 | 7.7 | 5.8 | .0059 | +8 |
| siemens | 8 | 9 | 0 | 4 | 5 | 0 | 1 | 0 | 0.0 | 6.9 | .0019 | +7 |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 |
| abb | 6 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +6 |
| schneider electric | 6 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | +6 |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | +3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 72 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | +71 |
| sourcecodester | 49 | 71 | 0 | 0 | 36 | 35 | 0 | 0 | 0.0 | 5.5 | .0026 | +29 |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +55 |
| edimax | 14 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0059 | -33 |
| capgo | 61 | 61 | 2 | 31 | 27 | 1 | 0 | 0 | 0.0 | 7.1 | .0031 | +61 |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 |
| dell | 38 | 56 | 1 | 30 | 24 | 0 | 2 | 1 | 1.8 | 7.2 | .0016 | +26 |
| itsourcecode | 43 | 53 | 0 | 0 | 18 | 35 | 0 | 0 | 0.0 | 2.1 | .0025 | +33 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE-2026-48907 | .6883 | 99.3 | 10.0 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48276 | 10.0 | .0505 | |
| CVE-2026-13773 | 10.0 | .0341 | |
| CVE-2026-56413 | 10.0 | .0316 | |
| CVE-2026-56415 | 10.0 | .0315 | |
| CVE-2026-53576 | 10.0 | .0219 |
| Vendor | CVEs |
|---|---|
| 1090 | |
| linux | 514 |
| oracle | 243 |
| microsoft | 221 |
| adobe | 142 |
| red hat | 128 |
| apache | 121 |
| ibm | 75 |
| spring | 72 |
| capgo | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 49 |
| Packagist | 15 |
| PyPI | 9 |
| npm | 6 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1686 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1686 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1686 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1686 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1686 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1686 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1686 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1686 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1686 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1686 |
EXPLOIT PUBLISHED — CVE-2026-10652 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10653 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10654 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10655 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4629 (Red Hat build of Keycloak 26.4). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54672 (electron-userland electron-builder). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56364 (ImageMagick). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58016 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-9263 (zephyrproject zephyr). Public exploit reference added.
DUE DATE PASSED — CVE-2026-20262 (Cisco Catalyst SD-WAN Manager). CISA remediation deadline was June 29, 2026; still in catalog.
641 CVEs published. 25 box scores and 375 table rows below; the remaining 241 continue on page 2 — every CVE is listed, nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H L H 8.8 .1565 96.6 —
AFFECTED Product Versions Fixed ADC 14.1 – — Gateway 14.1 – —
TIMELINE May 13 Reserved by CNA Jun 30 Published (CNA: NetScaler)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0718 93.8 —
AFFECTED Product Versions Fixed conductor 3.21.21 – —
TIMELINE Jun 29 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0505 91.6 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H L N 9.3 .0416 90.0 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0341 87.9 —
AFFECTED Product Versions Fixed WebSphere Extreme Scale 8.6.1.0 – —
TIMELINE Jun 29 Reserved by CNA Jun 30 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0316 86.9 —
AFFECTED Product Versions Fixed Storage Concentrator unspecified 8.0.4.29 Storage Concentrator Virtual Machine unspecified 8.0.4.29
TIMELINE Jun 22 Reserved by CNA Jun 30 Published (CNA: icscert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0315 86.8 —
AFFECTED Product Versions Fixed Storage Concentrator unspecified 8.0.4.29 Storage Concentrator Virtual Machine unspecified 8.0.4.29
TIMELINE Jun 22 Reserved by CNA Jun 30 Published (CNA: icscert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0182 76.9 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0182 76.9 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0168 75.0 —
AFFECTED Product Versions Fixed Grav unspecified 2.0.0-beta.2
TIMELINE Jun 22 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0155 73.0 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0155 73.0 —
AFFECTED Product Versions Fixed DGM3103SCT firmware version 3.2.5.4 and prior – —
TIMELINE Jun 23 Reserved by CNA Jun 30 Published (CNA: jpcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H N 9.3 .0145 71.2 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0118 65.0 —
AFFECTED Product Versions Fixed Apache ActiveMQ unspecified — Apache ActiveMQ All unspecified — Apache ActiveMQ Client unspecified — Apache ActiveMQ Broker unspecified —
TIMELINE Jun 11 Reserved by CNA Jun 30 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N N 8.6 .0094 58.0 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0090 56.8 —
AFFECTED Product Versions Fixed Apache ActiveMQ Broker unspecified — Apache ActiveMQ All unspecified — Apache ActiveMQ unspecified —
TIMELINE Jun 15 Reserved by CNA Jun 30 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0087 55.8 —
AFFECTED Product Versions Fixed Adobe Campaign Classic (ACC) unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV A L N R C H H H 8.8 .0080 53.5 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0078 52.9 —
AFFECTED Product Versions Fixed Apache ActiveMQ unspecified —
TIMELINE Jun 2 Reserved by CNA Jun 30 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H N 7.6 .0077 52.6 —
AFFECTED Product Versions Fixed picklescan unspecified 0.0.30
TIMELINE Jun 20 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H H 7.2 .0077 52.5 —
AFFECTED Product Versions Fixed seaweedfs unspecified —
TIMELINE Jun 30 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0073 51.1 —
AFFECTED Product Versions Fixed txtai unspecified 11b32da720f03276199ebc5583c15fc5d1ccafd3
TIMELINE Jun 30 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L N 6.5 .0071 50.6 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0069 50.0 —
AFFECTED Product Versions Fixed OpenAPI.NET >= 2.0.0-preview11, < 2.7.5 – —
TIMELINE May 30 Reserved by CNA Jun 30 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N A H H H 8.4 .0068 49.3 —
AFFECTED Product Versions Fixed RPG MAKER MV 1.6.3 and earlier – — RPG MAKER MZ 1.10.0 and earlier – —
TIMELINE Jun 19 Reserved by CNA Jun 30 Published (CNA: jpcert)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-11595 | 7.5 | 48.8 | IBM | WebSphere Application Server | CWE-22 | IBM WebSphere Application Server is affected by a Path Traversal vulnerability |
| CVE-2026-27957 | 8.8 | 48.5 | coollabsio | coolify | CWE-78 | Coolify: Authenticated RCE via command injection in CA certificate management… |
| CVE-2026-58116 | 9.3 | 47.9 | hiyouga | LlamaFactory | CWE-94 | LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path |
| CVE-2025-71374 | 7.6 | 47.6 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Undetected profile.Profile.run |
| CVE-2025-71352 | 7.6 | 47.6 | picklescan | picklescan | CWE-693 | picklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickl… |
| CVE-2026-58166 | 8.8 | 47.2 | OpenBMB | ChatDev | CWE-22 | OpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arb… |
| CVE-2025-71363 | 7.6 | 45.2 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Undetected cProfile.run in Pickle D… |
| CVE-2026-49432 | 7.5 | 44.8 | Apache Software Foundation | Apache ActiveMQ | CWE-20 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative c… |
| CVE-2026-13967 | 8.8 | 44.7 | Chrome | CWE-843 | Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2025-71349 | 7.6 | 44.1 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickl… |
| CVE-2026-13787 | 8.1 | 44.0 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.… | |
| CVE-2025-71355 | 7.6 | 43.6 | Picklescan | Picklescan | CWE-184 | Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass |
| CVE-2026-58370 | 9.2 | 43.2 | woodpecker-ci | woodpecker | CWE-290 | Woodpecker < 3.15.0 - GitLab Approval Gate Bypass via Spoofable Commit Author… |
| CVE-2026-58016 | 9.1 | 43.2 | GNOME | GLib | CWE-191 | Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new… |
| CVE-2026-10109 | 9.8 | 43.1 | IBM | Db2 | CWE-94 | IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRD… |
| CVE-2026-50734 | 7.5 | 43.1 | Apache Software Foundation | Apache ActiveMQ Client | CWE-789 | Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authenticat… |
| CVE-2026-53916 | 7.5 | 43.1 | Apache Software Foundation | Apache ActiveMQ | CWE-789 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header… |
| CVE-2026-11367 | 6.5 | 42.1 | andrasweb | PixMagix – WordPress Image Editor | CWE-22 | PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' P… |
| CVE-2026-13779 | 8.1 | 42.0 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871… | |
| CVE-2026-13898 | 8.8 | 41.1 | Chrome | CWE-416 | Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allow… | |
| CVE-2026-13899 | 8.8 | 41.1 | Chrome | CWE-416 | Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-13788 | 8.8 | 40.7 | Chrome | CWE-416 | Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.… | |
| CVE-2025-71371 | 7.6 | 40.5 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via code.InteractiveInterpreter Detection … |
| CVE-2026-50003 | 9.3 | 40.4 | OFFIS DICOM | DCMTK Toolkit | CWE-22 | OFFIS DCMTK Toolkit Path Traversal |
| CVE-2026-8655 | 8.8 | 40.2 | NetScaler | ADC | CWE-119 | Multiple Memory overflow vulnerabilities leading to unpredictable or erroneou… |
| CVE-2026-50750 | 7.5 | 39.9 | Apache Software Foundation | Apache ActiveMQ Broker | CWE-400 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authenticat… |
| CVE-2026-53691 | 8.6 | 39.9 | Redeight | Redeight CMS | CWE-434 | Remote Code Execution in Redeight CMS |
| CVE-2026-8452 | 8.8 | 39.8 | NetScaler | ADC | CWE-119 | Memory overflow vulnerability leading to unpredictable or erroneous behavior … |
| CVE-2026-13786 | 8.8 | 39.3 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13815 | 8.8 | 39.3 | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-58015 | 7.5 | 39.3 | GNOME | GLib | CWE-22 | Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_… |
| CVE-2026-14162 | 9.3 | 38.8 | Advantech | Hospital Quering Management | CWE-306 | Advantech|Hospital Quering Management - Missing Authentication |
| CVE-2026-13474 | 8.7 | 38.8 | NetScaler | ADC | CWE-401 | Denial of service via malformed HTTP/2 requests |
| CVE-2026-52760 | 6.1 | 38.8 | Apache Software Foundation | Apache ActiveMQ | CWE-79 | Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values… |
| CVE-2026-49434 | 7.5 | 38.5 | Apache Software Foundation | Apache ActiveMQ Broker | CWE-20 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConn… |
| CVE-2026-13794 | 7.5 | 38.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-13925 | 7.5 | 38.2 | Chrome | CWE-20 | Inappropriate implementation in Downloads in Google Chrome on Windows prior t… | |
| CVE-2026-13870 | 8.8 | 38.1 | Chrome | CWE-416 | Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 … | |
| CVE-2026-13885 | 8.8 | 38.1 | Chrome | CWE-416 | Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 all… | |
| CVE-2026-13965 | 8.8 | 38.1 | Chrome | CWE-416 | Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-58375 | 8.7 | 37.9 | jeecgboot | jimureport | CWE-306 | JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export |
| CVE-2026-14164 | 7.5 | 37.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-415 | Libarchive: double-free vulnerability in rar5 decompression logic via danglin… |
| CVE-2026-10817 | 6.9 | 37.9 | NetScaler | ADC | CWE-125 | Insufficient input validation leading to memory overread |
| CVE-2026-41053 | 8.8 | 37.6 | SUSE | Rancher | CWE-303 | Over-inclusive team membership expansion in GitHub App authentication provide… |
| CVE-2026-52195 | 7.5 | 37.5 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52196 | 7.5 | 37.5 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-56233 | 8.7 | 37.5 | Capgo | Capgo | CWE-22 | Capgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload Proxy |
| CVE-2026-7871 | 9.8 | 37.3 | IBM | Langflow OSS | CWE-502 | Insecure Deserialization in Redis Cache Backend |
| CVE-2026-55721 | 9.2 | 37.1 | StoneFly | Storage Concentrator | CWE-89 | SQL Injection in StoneFly Storage Concentrator |
| CVE-2026-13776 | 9.8 | 36.9 | Chrome | CWE-843 | Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-13805 | 8.8 | 36.9 | Chrome | CWE-416 | Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed … | |
| CVE-2026-13811 | 8.8 | 36.9 | Chrome | CWE-416 | Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-13821 | 8.8 | 36.9 | Chrome | CWE-416 | Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-13845 | 8.8 | 36.9 | Chrome | CWE-416 | Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-13848 | 8.8 | 36.9 | Chrome | CWE-416 | Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13888 | 8.8 | 36.9 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-13798 | 9.6 | 36.9 | Chrome | CWE-122 | Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 al… | |
| CVE-2026-14161 | 8.7 | 36.4 | Advantech | Hospital Queuing Management | CWE-200 | Advantech|Hospital Queuing Management - Sensitive Data Exposure |
| CVE-2026-58446 | 6.9 | 36.4 | presenton | presenton | CWE-306 | Presenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotecte… |
| CVE-2026-13901 | 9.6 | 36.3 | Chrome | CWE-20 | Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.787… | |
| CVE-2026-13903 | 8.8 | 36.3 | Chrome | CWE-602 | Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.… | |
| CVE-2026-13799 | 8.1 | 36.3 | Chrome | CWE-416 | Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-13789 | 9.6 | 36.2 | Chrome | CWE-416 | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-44628 | 8.7 | 36.1 | OFFIS DICOM | DCMTK Toolkit | CWE-843 | OFFIS DCMTK Toolkit Type Confusion |
| CVE-2026-13802 | 7.5 | 36.0 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13791 | 8.1 | 35.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in Downloads in Google Chrome prio… | |
| CVE-2026-13774 | 8.1 | 35.4 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-52193 | 7.5 | 35.3 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52198 | 7.5 | 35.3 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-35505 | 8.7 | 34.7 | OFFIS DICOM | DCMTK Toolkit | CWE-401 | OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime |
| CVE-2026-50254 | 8.7 | 34.7 | OFFIS DICOM | DCMTK Toolkit | CWE-401 | OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime |
| CVE-2026-58170 | 7.2 | 34.7 | HKUDS | Vibe-Trading | CWE-22 | Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging … |
| CVE-2026-7803 | 9.8 | 34.6 | IBM | Langflow OSS | CWE-20 | Flow Validation Bypass via Empty Component Type Field |
| CVE-2026-10816 | 7.1 | 34.6 | NetScaler | ADC | CWE-610 | Arbitrary File Read (Unauthenticated) |
| CVE-2026-13830 | 8.8 | 34.6 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47… | |
| CVE-2026-13919 | 6.5 | 34.5 | Chrome | CWE-602 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0… | |
| CVE-2026-13921 | 6.5 | 34.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in DeviceBoundSessionCredentials i… | |
| CVE-2026-13930 | 6.5 | 34.5 | Chrome | CWE-602 | Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871… | |
| CVE-2026-58172 | 9.3 | 34.3 | ThreeMammals | Ocelot | CWE-288 | Ocelot - IP Allow/Block List Bypass for WebSocket Upgrade Requests |
| CVE-2026-58168 | 7.7 | 34.3 | HKUDS | DeepTutor | CWE-862 | DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to … |
| CVE-2026-13792 | 9.6 | 34.2 | Chrome | CWE-416 | Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 all… | |
| CVE-2026-13843 | 9.6 | 34.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-13846 | 9.6 | 34.2 | Chrome | CWE-416 | Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed … | |
| CVE-2026-13869 | 9.6 | 34.2 | Chrome | CWE-416 | Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 a… | |
| CVE-2026-13909 | 9.6 | 34.2 | Chrome | CWE-693 | Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7… | |
| CVE-2026-13920 | 9.6 | 34.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome on Windo… | |
| CVE-2026-13934 | 9.6 | 34.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on Androi… | |
| CVE-2026-13817 | 8.8 | 34.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Glic in Google Chrome prior to … | |
| CVE-2026-13835 | 8.8 | 34.2 | Chrome | CWE-122 | Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13915 | 8.8 | 34.2 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.… | |
| CVE-2026-13918 | 8.8 | 34.2 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.… | |
| CVE-2026-13928 | 8.8 | 34.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Enterprise in Google Chrome pri… | |
| CVE-2026-13938 | 8.8 | 34.2 | Chrome | CWE-472 | Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-52868 | 8.8 | 34.2 | OFFIS DICOM | DCMTK Toolkit | CWE-22 | OFFIS DCMTK Toolkit Path Traversal |
| CVE-2026-13968 | 7.5 | 34.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-52197 | 7.5 | 34.1 | n/a | n/a | CWE-400 | An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker … |
| CVE-2026-13775 | 9.8 | 33.9 | Chrome | CWE-416 | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-13780 | 9.6 | 33.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-13781 | 9.6 | 33.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Skia in Google Chrome prior to … | |
| CVE-2026-13785 | 9.6 | 33.9 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al… | |
| CVE-2026-13783 | 8.8 | 33.9 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13784 | 8.8 | 33.9 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13923 | 6.5 | 33.8 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 a… | |
| CVE-2026-13943 | 6.5 | 33.8 | Chrome | CWE-457 | Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 a… | |
| CVE-2026-13803 | 8.3 | 33.7 | Chrome | CWE-843 | Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed… | |
| CVE-2026-13831 | 7.5 | 33.6 | Chrome | CWE-416 | Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13855 | 7.5 | 33.6 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo… | |
| CVE-2026-13906 | 6.5 | 33.3 | Chrome | CWE-125 | Out of bounds read in Codecs in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-53690 | 9.3 | 33.2 | Redeight | Redeight CMS | CWE-89 | SQL Injection in Redeight CMS |
| CVE-2026-13819 | 8.1 | 33.1 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 al… | |
| CVE-2026-14104 | 9.8 | 33.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-14067 | 8.8 | 32.9 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.… | |
| CVE-2026-13924 | 6.5 | 32.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebView in Google Chrome on And… | |
| CVE-2026-13926 | 6.5 | 32.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … | |
| CVE-2026-13883 | 9.6 | 32.8 | Chrome | CWE-843 | Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13825 | 8.8 | 32.8 | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-13829 | 8.3 | 32.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in Settings in Google Chrome on Wi… | |
| CVE-2026-13834 | 8.3 | 32.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-13897 | 8.8 | 32.7 | Chrome | CWE-284 | Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0… | |
| CVE-2025-71350 | 7.6 | 32.7 | picklescan | picklescan | CWE-502 | picklescan - Undetected Remote Code Execution via torch.utils.collect_env.run |
| CVE-2026-13891 | 7.5 | 32.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-13958 | 6.5 | 32.3 | Chrome | CWE-457 | Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.4… | |
| CVE-2026-13806 | 8.1 | 32.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Accessibility in Google Chrome … | |
| CVE-2026-13790 | 6.5 | 32.0 | Chrome | CWE-1300 | Side-channel information leakage in Scroll in Google Chrome prior to 150.0.78… | |
| CVE-2026-13810 | 6.5 | 32.0 | Chrome | CWE-200 | Inappropriate implementation in Input in Google Chrome on Linux prior to 150.… | |
| CVE-2026-13847 | 6.5 | 32.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-13922 | 6.5 | 32.0 | Chrome | CWE-1300 | Side-channel information leakage in Paint in Google Chrome prior to 150.0.787… | |
| CVE-2026-13935 | 6.5 | 32.0 | Chrome | CWE-1300 | Side-channel information leakage in ComputePressure in Google Chrome prior to… | |
| CVE-2026-13947 | 5.3 | 31.9 | Chrome | CWE-457 | Uninitialized Use in XR in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13950 | 5.3 | 31.9 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-13889 | 6.5 | 31.6 | Chrome | CWE-20 | Side-channel information leakage in WebAuthentication in Google Chrome on iOS… | |
| CVE-2026-13782 | 10.0 | 31.1 | Chrome | CWE-416 | Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-13796 | 9.6 | 31.1 | Chrome | CWE-472 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe… | |
| CVE-2026-13797 | 9.6 | 31.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromecast in Google Chrome pri… | |
| CVE-2026-13777 | 8.8 | 31.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS … | |
| CVE-2026-13911 | 5.3 | 31.1 | Chrome | CWE-20 | Insufficient policy enforcement in Spellcheck in Google Chrome prior to 150.0… | |
| CVE-2026-13833 | 6.5 | 30.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 all… | |
| CVE-2026-13900 | 6.5 | 30.7 | Chrome | CWE-20 | Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.78… | |
| CVE-2026-13937 | 6.5 | 30.5 | Chrome | CWE-284 | Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.… | |
| CVE-2026-13954 | 6.5 | 30.5 | Chrome | CWE-284 | Insufficient policy enforcement in XML in Google Chrome on Android prior to 1… | |
| CVE-2026-13807 | 7.5 | 30.4 | Chrome | CWE-416 | Use after free in Import in Google Chrome on iOS prior to 150.0.7871.47 allow… | |
| CVE-2026-13816 | 6.5 | 30.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in File Input in Google Chrome on … | |
| CVE-2026-13910 | 6.5 | 30.4 | Chrome | CWE-693 | Insufficient policy enforcement in WebXR in Google Chrome on Android prior to… | |
| CVE-2026-10562 | 5.9 | 30.4 | TP-Link Systems Inc. | Archer AX20 V2.0 | CWE-601 | Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface |
| CVE-2026-13801 | 8.3 | 30.3 | Chrome | CWE-472 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe… | |
| CVE-2026-13804 | 8.3 | 30.3 | Chrome | CWE-416 | Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-13823 | 8.3 | 30.3 | Chrome | CWE-416 | Use after free in Glic in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-13832 | 8.3 | 30.3 | Chrome | CWE-416 | Use after free in Headless in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-13841 | 8.3 | 30.3 | Chrome | CWE-472 | Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-13951 | 8.3 | 30.3 | Chrome | CWE-693 | Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.4… | |
| CVE-2026-58013 | 8.2 | 30.2 | GNOME | GLib | CWE-126 | Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" |
| CVE-2026-13814 | 7.5 | 30.3 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13873 | 6.5 | 30.3 | Chrome | CWE-125 | Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-13813 | 8.3 | 30.1 | Chrome | CWE-20 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… | |
| CVE-2026-13824 | 7.5 | 30.1 | Chrome | CWE-20 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0… | |
| CVE-2026-13856 | 7.5 | 30.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Speech in Google Chrome on Andr… | |
| CVE-2026-13893 | 6.5 | 30.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebUI in Google Chrome prior to… | |
| CVE-2026-56278 | 9.3 | 29.8 | Flowise | Flowise | CWE-798 | Flowise - Session Hijacking via Weak Default Express Session Secret |
| CVE-2026-58011 | 7.5 | 29.8 | GNOME | GLib | CWE-125 | Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid … |
| CVE-2026-13875 | 5.3 | 29.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in GPU in Google Chrome on Windows… | |
| CVE-2026-13853 | 9.6 | 29.4 | Chrome | CWE-416 | Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-13854 | 9.6 | 29.4 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo… | |
| CVE-2026-13859 | 9.6 | 29.4 | Chrome | CWE-693 | Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-13861 | 9.6 | 29.4 | Chrome | CWE-416 | Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-13878 | 9.6 | 29.4 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al… | |
| CVE-2026-13880 | 9.6 | 29.4 | Chrome | CWE-416 | Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed … | |
| CVE-2026-58010 | 8.2 | 29.4 | GNOME | GLib | CWE-126 | Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() |
| CVE-2026-58012 | 8.2 | 29.4 | GNOME | GLib | CWE-126 | Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append()… |
| CVE-2026-58369 | 6.9 | 29.3 | woodpecker-ci | woodpecker | CWE-476 | Woodpecker < 3.15.0 - Unauthenticated NULL Pointer Dereference in /api/orgs/l… |
| CVE-2026-13969 | 5.3 | 29.2 | Chrome | CWE-457 | Uninitialized Use in UI in Google Chrome on Android prior to 150.0.7871.47 al… | |
| CVE-2026-13970 | 5.3 | 29.2 | Chrome | CWE-457 | Uninitialized Use in Media in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-13971 | 5.3 | 29.2 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-11708 | 9.3 | 29.1 | IBM | WebSphere Application Server | CWE-79 | IBM WebSphere Application Server is affected by a cross-site scripting vulner… |
| CVE-2026-13809 | 6.5 | 29.0 | Chrome | CWE-1300 | Side-channel information leakage in Safe Browsing in Google Chrome on iOS pri… | |
| CVE-2026-13932 | 6.5 | 29.0 | Chrome | CWE-284 | Inappropriate implementation in Sharing in Google Chrome on Android prior to … | |
| CVE-2026-13936 | 6.5 | 29.0 | Chrome | CWE-284 | Inappropriate implementation in Passwords in Google Chrome on Android prior t… | |
| CVE-2026-13864 | 8.1 | 28.9 | Chrome | CWE-284 | Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.787… | |
| CVE-2026-13858 | 6.5 | 28.9 | Chrome | CWE-125 | Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-10134 | 10.0 | 28.8 | IBM | Langflow OSS | CWE-94 | Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows |
| CVE-2026-13892 | 6.5 | 28.7 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-13877 | 5.3 | 28.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-13961 | 5.3 | 28.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome on Wi… | |
| CVE-2026-56286 | 7.0 | 28.4 | Capgo | Capgo | CWE-306 | Capgo - Account Deletion Without Password Confirmation |
| CVE-2026-13871 | 6.5 | 28.4 | Chrome | CWE-602 | Insufficient policy enforcement in GuestView in Google Chrome prior to 150.0.… | |
| CVE-2026-13962 | 6.5 | 28.4 | Chrome | CWE-20 | Insufficient data validation in PDF in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13207 | 8.7 | 28.3 | Frangoteam | FUXA SCADA/HMI | CWE-290 | Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing |
| CVE-2026-14178 | 5.9 | 28.2 | openGauss-server | openGauss-server-7.0.0-RC2 | CWE-416 | openGauss存在非法内存访问导致DoS漏洞 |
| CVE-2026-13766 | 9.8 | 28.0 | EXODIST | DBIx::QuickORM | CWE-89 | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unqu… |
| CVE-2026-56300 | 8.7 | 27.9 | Capgo | Capgo | CWE-200 | Capgo - Unauthenticated API Key Validity and Permission Oracle via RPC Functions |
| CVE-2026-13851 | 9.1 | 27.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-13852 | 9.1 | 27.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-13149 | 7.7 | 27.9 | juliangruber | brace-expansion | CWE-400 | brace-expansion through 5.0.6 is vulnerable to denial of service. The expand(… |
| CVE-2025-53648 | 5.4 | 27.9 | Apache Software Foundation | Apache Gravitino | CWE-89 | Apache Gravitino: SQL misconfiguration can access or truncate files |
| CVE-2026-13828 | 6.5 | 27.6 | Chrome | CWE-284 | Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.78… | |
| CVE-2026-13964 | 6.5 | 27.6 | Chrome | CWE-284 | Insufficient policy enforcement in WebView in Google Chrome on Android prior … | |
| CVE-2026-6953 | 5.1 | 27.5 | Intermark IT | WebControl CMS | CWE-79 | Multiple vulnerabilities in Intermark IT's WebControl CMS |
| CVE-2026-13820 | 6.5 | 27.4 | Chrome | CWE-125 | Out of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871.47 all… | |
| CVE-2026-13890 | 5.3 | 27.3 | Chrome | CWE-125 | Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allo… | |
| CVE-2026-13933 | 5.3 | 27.2 | Chrome | CWE-284 | Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.… | |
| CVE-2026-56219 | 8.7 | 27.1 | Capgo | Capgo | CWE-287 | Capgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_a… |
| CVE-2026-13818 | 6.5 | 27.0 | Chrome | CWE-284 | Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787… | |
| CVE-2026-13953 | 6.5 | 27.0 | Chrome | CWE-284 | Inappropriate implementation in SplitView in Google Chrome prior to 150.0.787… | |
| CVE-2026-14121 | 9.8 | 26.9 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47… | |
| CVE-2026-13884 | 8.8 | 26.9 | Chrome | CWE-122 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe… | |
| CVE-2026-13866 | 6.5 | 26.9 | Chrome | CWE-20 | Inappropriate implementation in Input in Google Chrome on Android prior to 15… | |
| CVE-2026-54502 | 6.3 | 26.7 | ohler55 | oj | CWE-121 | Oj: Stack Buffer Overflow in Oj.dump via Large Indent |
| CVE-2026-11712 | 9.3 | 26.5 | IBM | WebSphere Application Server | CWE-79 | IBM WebSphere Application Server is affected by a cross-site scripting vulner… |
| CVE-2026-7873 | 9.9 | 26.4 | IBM | Langflow OSS | CWE-94 | Code Injection Vulnerability in Code Validation Endpoint |
| CVE-2026-56264 | 9.2 | 26.3 | Crawl4AI | Crawl4AI | CWE-94 | Crawl4AI - Arbitrary JavaScript Execution via /execute_js Endpoint |
| CVE-2026-13904 | 6.5 | 26.2 | Chrome | CWE-693 | Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior t… | |
| CVE-2026-12240 | 8.0 | 26.0 | qlstudio | Export User Data | CWE-502 | Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection … |
| CVE-2026-13931 | 6.5 | 25.9 | Chrome | CWE-284 | Inappropriate implementation in Media in Google Chrome on Windows prior to 15… | |
| CVE-2026-7663 | 9.8 | 25.7 | IBM | Langflow OSS | CWE-863 | Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streama… |
| CVE-2026-13872 | 9.1 | 25.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-13795 | 6.5 | 25.6 | Chrome | CWE-602 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… | |
| CVE-2026-14149 | 8.8 | 25.3 | Chrome | CWE-416 | Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allo… | |
| CVE-2026-57995 | 8.7 | 25.4 | phpMyFAQ | phpMyFAQ | CWE-269 | phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupCo… |
| CVE-2026-4629 | 6.5 | 25.4 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-266 | Keycloak: keycloak: privilege escalation through hardcoded role mapper injection |
| CVE-2026-13850 | 8.8 | 25.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-35098 | 6.9 | 25.1 | KTM System | e-BOK | CWE-307 | Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK |
| CVE-2026-56230 | 8.7 | 25.0 | Capgo | Capgo | CWE-639 | Capgo - Broken Object Level Authorization via x-limited-key-id Header |
| CVE-2026-8402 | 9.8 | 24.9 | Eksagate Electronic Engineering and Computer Industry Trade Inc. | SYSGUARD 6001 | CWE-89 | SQLi in Exagate's SYSGUARD 6001 |
| CVE-2026-58014 | 8.6 | 24.9 | GNOME | GLib | CWE-193 | Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_l… |
| CVE-2026-56399 | 5.3 | 24.8 | open-webui | open-webui | CWE-918 | Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/ret… |
| CVE-2026-14023 | 6.5 | 24.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in SanitizerAPI in Google Chrome p… | |
| CVE-2026-14065 | 6.5 | 24.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in PageInfo in Google Chrome prior… | |
| CVE-2026-14111 | 8.1 | 24.6 | Chrome | CWE-416 | Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-14024 | 8.8 | 24.4 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo… | |
| CVE-2026-14025 | 8.8 | 24.4 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowe… | |
| CVE-2026-12076 | 9.3 | 24.1 | Raytha | Raytha | CWE-89 | SQL Injection in Raytha CMS |
| CVE-2026-14086 | 8.8 | 24.2 | Chrome | CWE-602 | Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.4… | |
| CVE-2026-9263 | 8.1 | 24.1 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks a… |
| CVE-2026-13886 | 6.5 | 24.0 | Chrome | CWE-693 | Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior t… | |
| CVE-2026-13896 | 6.5 | 24.0 | Chrome | CWE-602 | Insufficient policy enforcement in Glic in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-13917 | 6.5 | 24.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-14010 | 6.5 | 23.8 | Chrome | CWE-457 | Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.4… | |
| CVE-2026-12073 | 9.8 | 23.7 | metagauss | ProfileGrid – User Profiles, Groups and Communities | CWE-639 | ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthentica… |
| CVE-2026-12819 | 9.3 | 23.7 | deltaww | DVP-12SE | CWE-306 | DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability |
| CVE-2026-10652 | 7.4 | 23.5 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated… |
| CVE-2026-58173 | 6.0 | 23.3 | HKUDS | Vibe-Trading | CWE-22 | Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type |
| CVE-2026-57079 | 5.3 | 23.2 | SANKO | Net::BitTorrent | CWE-22 | Net::BitTorrent versions before 2.1.0 for Perl write files outside the downlo… |
| CVE-2026-13759 | 8.8 | 23.0 | IBM | WebSphere Extreme Scale | CWE-502 | IBM WebSphere eXtreme Scale is affected by Insecure Deserilization |
| CVE-2026-56247 | 8.7 | 22.9 | Capgo | Capgo | CWE-266 | Capgo - Privilege Escalation via Cross-Scope RBAC Role Assignment |
| CVE-2026-13959 | 4.3 | 22.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Blink in Google Chrome prior to… | |
| CVE-2026-6556 | 9.1 | 22.7 | @fastify/express | @fastify/express | CWE-285 | @fastify/express vulnerable to middleware bypass via non-string mount paths i… |
| CVE-2026-13793 | 6.5 | 22.8 | Chrome | CWE-346 | Insufficient policy enforcement in SVG in Google Chrome prior to 150.0.7871.4… | |
| CVE-2026-13840 | 6.5 | 22.8 | Chrome | CWE-346 | Insufficient policy enforcement in Canvas in Google Chrome prior to 150.0.787… | |
| CVE-2026-13862 | 6.5 | 22.7 | Chrome | CWE-693 | Insufficient policy enforcement in Web Authentication (Passkeys & Security Ke… | |
| CVE-2026-13913 | 6.5 | 22.8 | Chrome | CWE-346 | Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to … | |
| CVE-2026-10655 | 5.9 | 22.7 | zephyrproject | zephyr | CWE-416 | Use-after-free race in SNTP async client when closing the socket while the so… |
| CVE-2026-54696 | 3.7 | 22.7 | ruby | json | CWE-122 | Ruby JSON: JSON generator heap buffer overflow when streaming to an IO |
| CVE-2026-9711 | 9.8 | 22.6 | EventON | EventON (Pro) - WordPress Virtual Event Calendar Plugin | CWE-89 | EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated… |
| CVE-2026-14004 | 6.5 | 22.5 | Chrome | CWE-200 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-14022 | 6.5 | 22.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … | |
| CVE-2026-58374 | 7.1 | 22.0 | w1.fi | hostapd | CWE-193 | In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.1… |
| CVE-2026-13837 | 4.3 | 22.0 | Chrome | CWE-451 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13865 | 4.3 | 22.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Enterprise in Google Chrome pri… | |
| CVE-2026-13867 | 4.3 | 22.0 | Chrome | CWE-451 | Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7… | |
| CVE-2026-13902 | 4.3 | 22.0 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-13912 | 4.3 | 22.0 | Chrome | CWE-451 | Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior t… | |
| CVE-2026-13916 | 4.3 | 22.0 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-13941 | 4.3 | 22.0 | Chrome | CWE-451 | Inappropriate implementation in SiteSettings in Google Chrome on Android prio… | |
| CVE-2026-13960 | 4.3 | 22.0 | Chrome | CWE-451 | Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787… | |
| CVE-2026-13966 | 4.3 | 22.0 | Chrome | CWE-451 | Inappropriate implementation in History in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-44948 | 5.3 | 21.7 | SUSE | Rancher | CWE-23 | Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler |
| CVE-2026-44946 | 9.5 | 21.6 | SUSE | Rancher | CWE-294 | SAML Authentication Replay in Rancher |
| CVE-2026-14006 | 8.8 | 21.6 | Chrome | CWE-416 | Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-14091 | 8.8 | 21.6 | Chrome | CWE-416 | Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-14107 | 8.8 | 21.6 | Chrome | CWE-416 | Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-45822 | 6.6 | 21.6 | SamVerschueren | decode-uri-component | CWE-400 | decode-uri-component through 0.4.1 is vulnerable to denial of service. The de… |
| CVE-2026-13882 | 9.6 | 21.5 | Chrome | CWE-362 | Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker… | |
| CVE-2026-14087 | 8.8 | 21.5 | Chrome | CWE-787 | Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871… | |
| CVE-2026-13826 | 6.5 | 21.5 | Chrome | CWE-346 | Inappropriate implementation in Autofill in Google Chrome on Android prior to… | |
| CVE-2026-13887 | 6.5 | 21.5 | Chrome | CWE-346 | Inappropriate implementation in NFC in Google Chrome on Android prior to 150.… | |
| CVE-2026-13908 | 6.5 | 21.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Omnibox in Google Chrome on iOS… | |
| CVE-2026-13949 | 6.5 | 21.3 | Chrome | CWE-284 | Insufficient policy enforcement in Payments in Google Chrome on Android prior… | |
| CVE-2026-14074 | 6.5 | 21.2 | Chrome | CWE-1300 | Side-channel information leakage in WebAuthentication in Google Chrome on iOS… | |
| CVE-2026-13836 | 6.1 | 21.2 | Chrome | CWE-79 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-58169 | 7.7 | 21.1 | HKUDS | Vibe-Trading | CWE-346 | Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS… |
| CVE-2026-11906 | 6.5 | 21.0 | IBM | Db2 | CWE-1284 | IBM® Db2® federated server is vulnerable to a denial of service due to improp… |
| CVE-2026-55223 | 6.3 | 20.9 | swaldman | c3p0 | CWE-502 | c3p0 exposes a deserialization "sink" via JDBC DataSource bean properties |
| CVE-2026-56365 | 6.3 | 20.9 | ImageMagick | ImageMagick | CWE-401 | ImageMagick - Memory Leak in PNG Encoder via MNG Image Writing |
| CVE-2026-13772 | 9.9 | 20.8 | IBM | WebSphere Extreme Scale | CWE-470 | IBM WebSphere eXtreme Scale's OQL is affected by remote code execution |
| CVE-2026-13838 | 6.5 | 20.7 | Chrome | CWE-346 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13839 | 6.5 | 20.7 | Chrome | CWE-346 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13842 | 4.3 | 20.7 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-13946 | 4.3 | 20.7 | Chrome | CWE-352 | Inappropriate implementation in ScriptInjections in Google Chrome on iOS prio… | |
| CVE-2026-13952 | 4.3 | 20.7 | Chrome | CWE-352 | Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150… | |
| CVE-2025-71381 | 6.9 | 20.4 | Hono | Hono | CWE-113 | Hono - Vary Header Injection in CORS Middleware |
| CVE-2026-10653 | 8.1 | 20.3 | zephyrproject | zephyr | CWE-415 | Non-atomic `net_buf` reference counts cause double-free / free-list corruptio… |
| CVE-2026-57585 | 7.5 | 20.4 | msgpack | msgpack-python | CWE-416 | MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error |
| CVE-2026-54592 | 7.5 | 20.3 | ohler55 | oj | CWE-125 | Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input |
| CVE-2026-57080 | 7.5 | 20.3 | SANKO | Net::BitTorrent | CWE-400 | Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustio… |
| CVE-2026-57081 | 7.5 | 20.3 | SANKO | Net::BitTorrent | CWE-400 | Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustio… |
| CVE-2026-4360 | 2.0 | 20.1 | Python Software Foundation | CPython | CWE-281 | Tarfile.extract() doesn't fully respect filter parameter |
| CVE-2026-11589 | 8.8 | 20.0 | Unknown | WP Support Plus Responsive Ticket System | — | WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XS… |
| CVE-2026-13939 | 3.1 | 20.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebShare in Google Chrome on An… | |
| CVE-2026-14064 | 7.5 | 19.9 | Chrome | CWE-416 | Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47… | |
| CVE-2026-13972 | 4.3 | 19.9 | Chrome | CWE-451 | Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-14033 | 6.5 | 19.8 | Chrome | CWE-602 | Insufficient policy enforcement in Media in Google Chrome on Windows prior to… | |
| CVE-2026-10560 | 9.1 | 19.6 | IBM | Langflow OSS | CWE-287 | Unauthenticated Access to Private Flow Build Events and Cancellation in Langf… |
| CVE-2026-6954 | 5.1 | 19.6 | Intermark IT | WebControl CMS | CWE-79 | Multiple vulnerabilities in Intermark IT's WebControl CMS |
| CVE-2026-13868 | 6.5 | 19.4 | Chrome | CWE-346 | Inappropriate implementation in Network in Google Chrome on Android prior to … | |
| CVE-2026-13895 | 4.2 | 19.3 | Chrome | CWE-451 | Inappropriate implementation in Autofill in Google Chrome prior to 150.0.7871… | |
| CVE-2026-13907 | 4.2 | 19.3 | Chrome | CWE-451 | Inappropriate implementation in iOSWeb in Google Chrome on iOS prior to 150.0… | |
| CVE-2026-14032 | 8.1 | 19.2 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al… | |
| CVE-2026-14108 | 8.8 | 19.1 | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-13876 | 6.5 | 19.1 | Chrome | CWE-693 | Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-13974 | 8.1 | 18.8 | Chrome | CWE-472 | Integer overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871… | |
| CVE-2026-13881 | 6.5 | 18.6 | Chrome | CWE-346 | Inappropriate implementation in WebAppInstalls in Google Chrome prior to 150.… | |
| CVE-2026-14120 | 9.6 | 18.5 | Chrome | CWE-20 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871… | |
| CVE-2026-14125 | 6.5 | 18.5 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-58174 | 6.0 | 18.4 | nesquena | hermes-webui | CWE-732 | Hermes WebUI < 0.51.521 - Cross-Profile Authorization Bypass via Unset Sessio… |
| CVE-2026-13874 | 5.3 | 18.4 | Chrome | CWE-362 | Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote… | |
| CVE-2026-58176 | 7.1 | 18.4 | dromara | RuoYi-Vue-Plus | CWE-862 | RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints |
| CVE-2026-14007 | 6.5 | 18.3 | Chrome | CWE-602 | Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior t… | |
| CVE-2026-14017 | 9.6 | 18.2 | Chrome | CWE-693 | Inappropriate implementation in Navigation in Google Chrome prior to 150.0.78… | |
| CVE-2026-14043 | 9.6 | 18.2 | Chrome | CWE-416 | Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowe… | |
| CVE-2026-14044 | 9.6 | 18.2 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-14055 | 9.6 | 18.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Device Trust in Google Chrome o… | |
| CVE-2026-14109 | 9.6 | 18.2 | Chrome | CWE-20 | Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-14027 | 8.8 | 18.2 | Chrome | CWE-416 | Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-14036 | 8.8 | 18.2 | Chrome | CWE-602 | Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.… | |
| CVE-2026-14041 | 8.8 | 18.2 | Chrome | CWE-602 | Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.787… | |
| CVE-2026-14078 | 8.8 | 18.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebRTC in Google Chrome prior t… | |
| CVE-2026-58377 | 8.6 | 18.2 | jeecgboot | JeecgBoot | CWE-862 | JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endp… |
| CVE-2026-14090 | 8.1 | 18.2 | Chrome | CWE-125 | Insufficient validation of untrusted input in CameraCapture in Google Chrome … | |
| CVE-2026-14106 | 9.6 | 18.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Text in Google Chrome on Androi… | |
| CVE-2026-11590 | 8.6 | 18.1 | Unknown | WP Support Plus Responsive Ticket System | — | WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injec… |
| CVE-2026-11806 | 7.5 | 18.1 | IBM | WebSphere Application Server - Liberty | CWE-444 | IBM WebSphere Application Server Liberty is affected by a an arbitrary file r… |
| CVE-2026-13857 | 4.2 | 18.1 | Chrome | CWE-451 | Inappropriate implementation in Geometry in Google Chrome prior to 150.0.7871… | |
| CVE-2026-13860 | 4.2 | 18.1 | Chrome | CWE-451 | Incorrect security UI in Autofill in Google Chrome on Windows prior to 150.0.… | |
| CVE-2026-13956 | 4.2 | 18.1 | Chrome | CWE-451 | Incorrect security UI in PageInfo in Google Chrome prior to 150.0.7871.47 all… | |
| CVE-2026-56318 | 6.9 | 17.9 | Capgo | Capgo | CWE-200 | Capgo - Information Disclosure via /private/validate_password_compliance Endp… |
| CVE-2026-56327 | 6.9 | 17.9 | Capgo | Capgo | CWE-203 | Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_… |
| CVE-2026-13812 | 4.7 | 18.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-14051 | 6.5 | 17.8 | Chrome | CWE-457 | Uninitialized Use in GamepadAPI in Google Chrome prior to 150.0.7871.47 allow… | |
| CVE-2026-14070 | 6.5 | 17.7 | Chrome | CWE-457 | Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-14088 | 6.5 | 17.8 | Chrome | CWE-457 | Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.4… | |
| CVE-2026-50040 | 5.1 | 17.7 | StoneFly | Storage Concentrator | CWE-79 | Cross-site Scripting in StoneFly Storage Concentrator |
| CVE-2026-56350 | 6.0 | 17.7 | n8n | n8n | CWE-285 | n8n - SSO Enforcement Bypass via API |
| CVE-2026-14038 | 9.3 | 17.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in New Tab Page in Google Chrome p… | |
| CVE-2026-56249 | 7.2 | 17.5 | Capgo | Capgo | CWE-285 | Capgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /chann… |
| CVE-2026-14021 | 6.5 | 17.5 | Chrome | CWE-20 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to… | |
| CVE-2026-14050 | 6.5 | 17.5 | Chrome | CWE-693 | Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.… | |
| CVE-2026-14059 | 6.5 | 17.5 | Chrome | CWE-693 | Insufficient policy enforcement in Related-Website-Sets in Google Chrome prio… | |
| CVE-2026-14085 | 6.5 | 17.5 | Chrome | CWE-1300 | Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-14103 | 6.5 | 17.5 | Chrome | CWE-416 | Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 all… | |
| CVE-2026-9132 | 6.0 | 17.5 | GitHub | Enterprise Server | CWE-862 | Missing authorization vulnerability in GitHub Enterprise Server allowed discl… |
| CVE-2026-11541 | 9.8 | 17.4 | IBM | CICS Transaction Gateway for Multiplatforms | CWE-444 | Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for … |
| CVE-2026-14099 | 8.8 | 17.3 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.… | |
| CVE-2026-13985 | 6.5 | 17.2 | Chrome | CWE-290 | Inappropriate implementation in MediaCapture in Google Chrome prior to 150.0.… | |
| CVE-2026-14113 | 9.6 | 17.1 | Chrome | CWE-416 | Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 … | |
| CVE-2026-14146 | 6.5 | 17.1 | Chrome | CWE-200 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-12818 | 9.3 | 16.9 | deltaww | DVP-12SE | CWE-770 | DVP-12SE Exposure of Sensitive Information Vulnerability |
| CVE-2026-14009 | 8.8 | 16.9 | Chrome | CWE-20 | Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787… | |
| CVE-2026-10763 | 7.0 | 16.9 | Hitachi Energy | PROMOD V | CWE-1428 | PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerabi… |
| CVE-2026-54899 | 6.3 | 17.0 | ohler55 | oj | CWE-416 | Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle |
| CVE-2026-54900 | 6.3 | 17.0 | ohler55 | oj | CWE-190 | Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling |
| CVE-2026-54901 | 6.3 | 17.0 | ohler55 | oj | CWE-416 | Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking |
| CVE-2026-54902 | 6.3 | 17.0 | ohler55 | oj | CWE-416 | Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback |
| CVE-2026-54903 | 6.3 | 17.0 | ohler55 | oj | CWE-190 | Oj: Integer Overflow in Oj.load 2GB String Handling |
| CVE-2026-58171 | 2.3 | 17.0 | HKUDS | Vibe-Trading | CWE-22 | Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier |
| CVE-2026-14241 | 9.8 | 16.8 | Mozilla | Firefox | CWE-787 | Memory safety bugs fixed in Firefox 152.0.4 |
| CVE-2026-14037 | 9.6 | 16.9 | Chrome | CWE-693 | Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.4… | |
| CVE-2026-14102 | 8.8 | 16.9 | Chrome | CWE-416 | Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a… | |
| CVE-2026-13879 | 6.5 | 16.7 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a… | |
| CVE-2026-13894 | 6.5 | 16.7 | Chrome | CWE-602 | Insufficient policy enforcement in Network in Google Chrome prior to 150.0.78… | |
| CVE-2026-13944 | 3.1 | 16.7 | Chrome | CWE-352 | Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to… | |
| CVE-2026-13963 | 3.1 | 16.7 | Chrome | CWE-352 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871… | |
| CVE-2026-56331 | 6.9 | 16.6 | Capgo | Capgo | CWE-209 | Capgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Mag… |
| CVE-2026-14008 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47… | |
| CVE-2026-14118 | 6.5 | 16.6 | Chrome | CWE-290 | Insufficient data validation in DevTools in Google Chrome prior to 150.0.7871… | |
| CVE-2025-36319 | 4.3 | 16.6 | IBM | watsonx.data intelligence | CWE-770 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-35097 | 6.9 | 16.5 | KTM System | e-BOK | CWE-521 | Weak Password Requirements in KTM System e-BOK |
Results continue: ranks 401–641.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-30 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.