boxscore/security
Wednesday, July 1, 2026 · all times UTC← 2026-06-30 · archive · 2026-07-02 →

365 CVEs published July 1, 2026: 58 critical, 123 high, 166 medium, 8 low; 1 in KEV; 13 with a public exploit reference; 10 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 340 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published3651268311842563
KEV catalog size1670

553 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux31151112086052812730.27.5.0013+30
google521316148586542377460.57.8.0023-8
microsoft2713554771604378283.97.8.0044+1
red hat82001183988400.06.7.0026+4
apple0991236629377.16.5.00310
canonical0202585000.05.5.00110
freebsd01601240000.07.8.00150
suse0133730000.08.6.00290
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco83141280961135.57.5.0056+8
netgear01700161800.04.3.00240
palo alto networks011017114218.24.8.00220
ubiquiti01174004327.39.9.00830
checkpoint0915303111.17.5.04100
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-1
fortinet08132028337.57.3.00660
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache2155245961104010.67.3.0048-26
mozilla25812182801300.07.3.00250
gitlab03305215426.14.4.00220
github171150000.06.0.0026+1
docker070520100.08.2.00160
drupal0511305120.05.1.00260
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-1
adobe014611527827532.15.5.00210
ibm01243642460700.07.5.0025-5
progress091710900.07.5.00360
solarwinds07122011457.17.5.08350
veeam042200400.09.0.00460
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.00250
d-link01305252617.75.8.0059-2
siemens090450100.06.9.00190
rockwell automation071510000.08.7.00300
abb060420000.07.2.00180
schneider electric060420100.07.8.00240
moxa050320000.07.0.00290
dahua030111200.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring073231391000.06.5.0024-2
sourcecodester071003635000.05.5.0026-12
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00590
capgo061231271000.07.1.00310
themerex05855300000.08.1.00430
dell157131240211.87.3.0015+1
nvidia1756113870000.07.8.0019+17

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
CVE-2026-4827610.0.0505
CVE-2026-1377310.0.0341
CVE-2026-5641310.0.0316
CVE-2026-5641510.0.0315
Most disclosures (vendor)
VendorCVEs
google1082
linux544
oracle242
microsoft222
adobe142
red hat132
apache95
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven41
Packagist15
PyPI8
npm6
Fastest to KEV
CVEVendorDays
CVE-2022-0492Linux0
CVE-2025-48595Google0
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171687
CVE-2021-27102Accellion2021-11-171687
CVE-2021-27101Accellion2021-11-171687
CVE-2021-27103Accellion2021-11-171687
CVE-2021-21017Adobe2021-11-171687
CVE-2021-28550Adobe2021-11-171687
CVE-2021-42013Apache2021-11-171687
CVE-2021-41773Apache2021-11-171687
CVE-2021-30858Apple2021-11-171687
CVE-2021-30860Apple2021-11-171687

Transactions

EXPLOIT PUBLISHEDCVE-2026-13323 (Eclipse Foundation Eclipse Open VSX). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50160 (hoppscotch). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57516 (Anyscale, Inc Ray). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-6682 (ChaN FatFs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-6683 (ChaN FatFs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-6684 (ChaN FatFs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-6686 (ChaN FatFs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-6687 (ChaN FatFs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-6688 (ChaN FatFs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8857 (Wikimedia Foundation timeline). Public exploit reference added.

Yesterday's Results

365 CVEs published. 25 box scores, 340 table rows — nothing truncated.

Microsoft SharePoint Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0986   95.2   YES
AFFECTED
  Product                                           Versions  Fixed
  Microsoft SharePoint Enterprise Server 2016       16.0.0 –  —
  Microsoft SharePoint Server 2019                  16.0.0 –  —
  Microsoft SharePoint Server Subscription Edition  16.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jul 1   Added to CISA KEV, due Jul 4
  Jul 1   Published (CNA: microsoft)
CWE-502 · CNA: microsoft · 2 references · NVD status: Analyzed · KEV due July 4, 2026
hoppscotch hoppscotch — Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  N   10.0   .1775   96.9     —
AFFECTED
  Product     Versions       Fixed
  hoppscotch  <= 2026.4.1 –  —
TIMELINE
  Jun 3   Reserved by CNA
  Jul 1   Public exploit reference published
  Jul 1   Published (CNA: GitHub_M)
CWE-915 · CNA: GitHub_M · 3 references · NVD status: Analyzed
JAIOTlink C492A-W6 4.8.30.57701411 OS Command Injection via SetMAC Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0242   82.8     —
AFFECTED
  Product                   Versions           Fixed
  C492A-W6 Wi-Fi IP Camera  4.8.30.57701411 –  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 3 references · NVD status: Deferred
JAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0169   75.1     —
AFFECTED
  Product                   Versions           Fixed
  C492A-W6 Wi-Fi IP Camera  4.8.30.57701411 –  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 1   Published (CNA: VulnCheck)
CWE-1392 · CNA: VulnCheck · 3 references · NVD status: Deferred
Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0166   74.6     —
AFFECTED
  Product              Versions     Fixed
  M300 Wi-Fi Repeater  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 3 references · NVD status: Deferred
uvnc UltraVNC — UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0158   73.4     —
AFFECTED
  Product   Versions     Fixed
  UltraVNC  unspecified  —
TIMELINE
  May 5   Reserved by CNA
  Jul 1   Published (CNA: securin)
CWE-787 · CNA: securin · 3 references · NVD status: Modified
Wikimedia Foundation timeline — Full RCE using EasyTimeline Extension
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   N    0.0   .0147   71.5     —
AFFECTED
  Product   Versions     Fixed
  timeline  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jul 1   Public exploit reference published
  Jul 1   Published (CNA: wikimedia-foundation)
CWE-94 · CNA: wikimedia-foundation · 1 reference · NVD status: Analyzed
uvnc UltraVNC — UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason length
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0140   70.3     —
AFFECTED
  Product   Versions     Fixed
  UltraVNC  unspecified  —
TIMELINE
  May 5   Reserved by CNA
  Jul 1   Published (CNA: securin)
CWE-190, CWE-787 · CNA: securin · 3 references · NVD status: Modified
Seiko Solutions Inc. SkyBridge MB-A100/MB-A110 — Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0137   69.5     —
AFFECTED
  Product                    Versions        Fixed
  SkyBridge MB-A100/MB-A110  all versions –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 1   Published (CNA: jpcert)
CWE-78 · CNA: jpcert · 2 references · NVD status: Deferred
Hyland PACSgear MediaWriter — PACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0127   67.4     —
AFFECTED
  Product               Versions  Fixed
  PACSgear MediaWriter  5.2.1 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 1   Published (CNA: VulnCheck)
CWE-306, CWE-502 · CNA: VulnCheck · 3 references · NVD status: Analyzed
Hyland PACSgear PACS Scan — PACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0120   65.7     —
AFFECTED
  Product             Versions  Fixed
  PACSgear PACS Scan  5.2.1 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 1   Published (CNA: VulnCheck)
CWE-306, CWE-502 · CNA: VulnCheck · 3 references · NVD status: Analyzed
Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0115   64.2     —
AFFECTED
  Product            Versions     Fixed
  Control Web Panel  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 1   Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · 4 references · NVD status: Awaiting Analysis
n/a n/a — An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal C…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0113   63.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 1   Published (CNA: mitre)
CWE-502 · CNA: mitre · 3 references · NVD status: Awaiting Analysis
uvnc UltraVNC — UltraVNC repeater integer overflow in win_log malloc leading to heap overflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0106   61.6     —
AFFECTED
  Product   Versions     Fixed
  UltraVNC  unspecified  —
TIMELINE
  May 5   Reserved by CNA
  Jul 1   Published (CNA: securin)
CWE-190 · CNA: securin · 3 references · NVD status: Modified
Cisco Catalyst Center Arbitrary File Read Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0092   57.3     —
AFFECTED
  Product                Versions      Fixed
  Cisco Catalyst Center  2.3.7.0-VA –  —
TIMELINE
  Oct 8   Reserved by CNA
  Jul 1   Published (CNA: cisco)
CWE-22 · CNA: cisco · 1 reference · NVD status: Awaiting Analysis
RARLAB WinRAR — WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0089   56.3     —
AFFECTED
  Product    Versions     Fixed
  WinRAR     unspecified  —
  RAR        unspecified  —
  UnRAR      unspecified  —
  UnRAR.dll  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 1   Published (CNA: securin)
CWE-129, CWE-787 · CNA: securin · 3 references · NVD status: Deferred
gradio-app gradio — Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0069   49.8     —
AFFECTED
  Product  Versions     Fixed
  gradio   unspecified  —
TIMELINE
  May 27  Reserved by CNA
  Jul 1   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 4 references · NVD status: Analyzed
n/a n/a — An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Ten…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0069   49.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 1   Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Deferred
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in subtitles.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0068   49.4     —
AFFECTED
  Product          Versions     Fixed
  language-system  unspecified  —
TIMELINE
  Mar 25  Reserved by CNA
  Jul 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Deferred
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0068   49.4     —
AFFECTED
  Product          Versions     Fixed
  language-system  unspecified  —
TIMELINE
  Mar 25  Reserved by CNA
  Jul 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Deferred
quantumcloud WPBot – AI ChatBot for Live Support, Lead Generation, AI Services — WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0066   48.5     —
AFFECTED
  Product                                                            Versions     Fixed
  WPBot – AI ChatBot for Live Support, Lead Generation, AI Services  unspecified  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 1   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 7 references · NVD status: Deferred
Feast: unauthenticated arbitrary file write
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0065   48.0     —
AFFECTED
  Product                       Versions     Fixed
  Feast Feature Server          unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  + 5 more
TIMELINE
  Jan 13  Reserved by CNA
  Jul 1   Published (CNA: redhat)
CWE-862 · CNA: redhat · 4 references · NVD status: Awaiting Analysis
AWS AWS CDK — OS Command Injection in aws-cdk-lib Docker Bundling
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   A   H   H   H    7.0   .0063   47.1     —
AFFECTED
  Product  Versions     Fixed
  AWS CDK  unspecified  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 1   Published (CNA: AMZN)
CWE-78 · CNA: AMZN · 3 references · NVD status: Awaiting Analysis
Altium Altium Enterprise Server — Path Traversal in Altium Git Service Allows Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0060   45.9     —
AFFECTED
  Product                   Versions       Fixed
  Altium Enterprise Server  unspecified    —
  Altium 365                unspecified –  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 1   Published (CNA: Altium)
CWE-22, CWE-94 · CNA: Altium · 1 reference · NVD status: Deferred
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0059   45.3     —
AFFECTED
  Product                     Versions     Fixed
  Apache HttpComponents Core  5.5-alpha –  —
TIMELINE
  Jun 14  Reserved by CNA
  Jul 1   Published (CNA: apache)
CWE-400, CWE-770 · CNA: apache · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-78297.244.5uvncUltraVNCCWE-787UltraVNC repeater authenticated out-of-bounds write in rule parser via oversi…
CVE-2026-543997.544.2Apache Software FoundationApache HttpComponents CoreCWE-400Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Conf…
CVE-2026-202137.544.1CiscoCisco Secure EndpointCWE-120ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability
CVE-2026-202147.544.1CiscoCisco Secure EndpointCWE-120ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability
CVE-2026-575168.643.6Anyscale, IncRayCWE-502Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader
CVE-2026-341089.343.4guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-341109.343.4guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-341119.343.4guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-341169.343.4guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-583998.743.1antonio-castellonmodule-authCWE-287@acastellon/auth has an authentication bypass via spoofable headers in valida…
CVE-2026-341099.342.8guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-341129.342.8guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-341139.342.8guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-341149.342.8guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-341159.342.8guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-341179.342.8guardianlanguage-systemCWE-78Guardian Language-System Unauthenticated OS Command Injection via id Paramete…
CVE-2026-521869.842.2n/an/aCWE-89SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows…
CVE-2026-78317.642.1uvncUltraVNCCWE-193UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing
CVE-2026-584547.741.9JAIOTlinkC492A-W6 Wi-Fi IP CameraCWE-94JAIOTlink C492A-W6 4.8.30.57701411 RCE via /Anyka/config Endpoint
CVE-2026-113879.841.5cozyvision1SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart RecoveryCWE-287SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Passw…
CVE-2026-242709.841.3NVIDIAAIStore frameworkCWE-290NVIDIA AIStore framework contains a vulnerability where an attacker could byp…
CVE-2025-156469.841.3BPSHTML::GumboCWE-125HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confu…
CVE-2026-202157.540.6CiscoCisco Secure EndpointCWE-120ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability
CVE-2026-202167.540.6CiscoCisco Secure EndpointCWE-770ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability
CVE-2026-202177.540.6CiscoCisco Secure EndpointCWE-120ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerab…
CVE-2026-202437.540.6CiscoCisco Secure EndpointCWE-120ClamAV ALZ Archive Processing Denial of Service Vulnerability
CVE-2026-202447.540.6CiscoCisco Secure EndpointCWE-120ClamAV DMG File Processing Denial of Service Vulnerability
CVE-2026-242647.539.4NVIDIATriton Inference ServerCWE-409NVIDIA Triton Inference Server for Linux contains a vulnerability where an at…
CVE-2026-340999.338.0guardianlanguage-systemCWE-89Guardian Language-System Unauthenticated SQL Injection via id Parameter in jo…
CVE-2026-66877.637.9ChaNFatFsCWE-121FatFs Stack Buffer Overflow via Uncapped exFAT Label Length
CVE-2026-505218.337.8MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-521907.537.5n/an/aCWE-121Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-242667.537.1NVIDIATriton Inference ServerCWE-416NVIDIA Triton Inference Server for Linux contains a vulnerability where an at…
CVE-2026-66834.635.8ChaNFatFsCWE-369FatFs Divide-by-Zero in exFAT Sync
CVE-2026-66844.635.8ChaNFatFsCWE-835FatFs Infinite Loop in GPT Partition Scan
CVE-2026-66827.635.7ChaNFatFsCWE-190FatFs Integer Overflow in FAT32 Volume Mount
CVE-2026-66887.635.7ChaNFatFsCWE-120FatFs Buffer Overflow via Unbounded LFN Filename Copy
CVE-2026-78399.135.5uvncUltraVNCCWE-798UltraVNC repeater ships hardcoded default admin password allowing unauthentic…
CVE-2026-142657.734.7AWSAWS Advanced JDBC WrapperCWE-502RCE via Deserialization in AWS Advanced JDBC Wrapper
CVE-2026-60709.134.0cmsjunkieWP-BusinessDirectory – Business directory plugin for WordPressCWE-73WP-BusinessDirectory <= 4.0.1 - Unauthenticated Arbitrary File Deletion via P…
CVE-2026-584517.134.1hordeimpCWE-22Horde IMP < 7.0.1 Path Traversal via Compose.php img src
CVE-2026-533559.833.1LinuxLinuxCWE-476net: rds: clear i_sends on setup unwind
CVE-2026-440423.732.0uvncUltraVNCCWE-193UltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check
CVE-2026-66864.630.9ChaNFatFsCWE-908FatFs Use of Uninitialized Clusters After Seek Past EOF
CVE-2026-341009.330.4guardianlanguage-systemCWE-89Guardian Language-System Unauthenticated SQL Injection via id Parameter in me…
CVE-2026-341019.330.4guardianlanguage-systemCWE-89Guardian Language-System Unauthenticated SQL Injection via id Parameter in te…
CVE-2026-341029.330.4guardianlanguage-systemCWE-89Guardian Language-System Unauthenticated SQL Injection via id Parameter in jo…
CVE-2026-341039.330.4guardianlanguage-systemCWE-89Guardian Language-System Unauthenticated SQL Injection via id Parameter in su…
CVE-2026-341049.330.4guardianlanguage-systemCWE-89Guardian Language-System Unauthenticated SQL Injection via name Parameter in …
CVE-2026-341059.330.4guardianlanguage-systemCWE-89Guardian Language-System Unauthenticated SQL Injection via id Parameter in tr…
CVE-2026-561494.929.9ElasticElasticsearchCWE-770Allocation of Resources Without Limits or Throttling in Elasticsearch Leading…
CVE-2026-134687.529.8themeisleVisualizer – Tables & Charts Manager with Built-in AI GeneratorCWE-862Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Info…
CVE-2026-118837.229.6UnknownWebAuthn Provider for Two FactorWebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass
CVE-2026-560165.929.3MARKSTOSCGI::Session::ID::md5CWE-338CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable sess…
CVE-2026-83872.428.8allegroaiallegroai/clearmlCWE-23Relative Path Traversal in allegroai/clearml
CVE-2026-561507.528.1ElasticFleet ServerCWE-770Allocation of Resources Without Limits or Throttling in Fleet Server Leading …
CVE-2026-143838.827.9GoogleChromeCWE-94Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 al…
CVE-2026-534928.427.8containerdcontainerdCWE-20containerd CRI checkpoint restore CDI annotation smuggling
CVE-2026-561486.527.8ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-369127.527.3n/an/aCWE-476A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function o…
CVE-2026-388917.527.3n/an/aCWE-20An improper input validation in the gazebo_ros_diff_drive.cpp component of ga…
CVE-2026-121275.327.3smubWPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & MoreCWE-93WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthentica…
CVE-2026-539065.127.0MyComplianceOfficeMCOCWE-22Path Disclosure and Path Traversal in MCO
CVE-2026-519466.526.6n/an/aCWE-89SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) al…
CVE-2026-501955.626.1containerdcontainerdCWE-345containerd: CRI checkpoint import allows local image tag poisoning
CVE-2026-557916.925.9craftcmscmsCWE-79Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Pois…
CVE-2026-137060.025.7Wikimedia FoundationUrlShortenerCWE-20UrlShortener extension url validation can be bypassed due to difference betwe…
CVE-2026-143858.825.6GoogleChromeCWE-122Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 …
CVE-2026-551537.125.6swaldmanmchange-commons-javaCWE-470mchange-commons-java contains elements susceptible to abuse via JNDI injectio…
CVE-2026-51368.825.5Red HatRed Hat Satellite 6.16 for RHEL 8CWE-266Foreman: foreman: privilege escalation to administrator-level access via user…
CVE-2026-580255.925.3Wikimedia FoundationMediaWikiCWE-94Remote Code Execution via Unsafe Deserialization in LogItem Import
CVE-2026-549086.324.8piondtlsCWE-125Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK Serv…
CVE-2026-144078.824.6GoogleChromeCWE-94Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 al…
CVE-2026-121106.524.6taskbuilderTaskbuilder – Project Management & Task Management Tool With Kanban BoardCWE-89Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'task_se…
CVE-2026-242608.524.4NVIDIAContainer ToolkitCWE-367NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker…
CVE-2026-440416.524.4uvncUltraVNCCWE-125UltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NU…
CVE-2026-558866.324.3xdanjoditCWE-1321Jodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()
CVE-2026-585928.923.8LadybirdBrowserLadybirdCWE-787Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference i…
CVE-2026-557907.423.7craftcmscmsCWE-79Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
CVE-2026-129237.523.6emarket-designVideo Gallery – YouTube Gallery, Playlist & Video GridCWE-98Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call …
CVE-2026-120906.523.7taskbuilderTaskbuilder – Project Management & Task Management Tool With Kanban BoardCWE-89Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_pr…
CVE-2026-144059.623.3GoogleChromeCWE-457Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a rem…
CVE-2026-121427.223.0webawaysNEX-Forms – Ultimate Forms Plugin for WordPressCWE-79NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]…
CVE-2026-132288.822.5latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-269LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administ…
CVE-2026-141989.122.4@fastify/middie@fastify/middieCWE-436@fastify/middie vulnerable to authorization bypass via encoded slash in path …
CVE-2026-12397.522.4kstoverNinja Forms – The Contact Form Builder That Grows With YouCWE-862Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive In…
CVE-2026-143636.921.9The Wikimedia FoundationMediawiki - Cargo ExtensionCWE-89Cargo Extension: SQLi in Special:Drilldown
CVE-2026-557948.721.8craftcmscmsCWE-94Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
CVE-2026-129044.321.8stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-639Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (…
CVE-2026-144308.821.6GoogleChromeCWE-190Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remo…
CVE-2026-141817.521.6@fastify/middie@fastify/middieCWE-248@fastify/middie standalone engine vulnerable to Denial of Service via malform…
CVE-2026-136039.021.3pretixpretix-oppwaCWE-20SSRF with API key leak in pretix-oppwa
CVE-2026-118237.521.0Repute InfosystemsBookingPress Appointment Booking ProCWE-89BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection…
CVE-2026-115687.520.9UnknownProduct Configurator for WooCommerceProduct Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft …
CVE-2026-576929.820.8LCwebPrivateContentCWE-266WordPress PrivateContent plugin <= 9.9.2 - Privilege Escalation vulnerability
CVE-2026-585216.920.8The Wikimedia FoundationMediawiki - Cargo ExtensionCWE-89SQLi in Cargo extension via year range filter
CVE-2026-440406.520.8uvncUltraVNCCWE-338UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authenticatio…
CVE-2026-490876.520.6ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-561516.520.6ElasticKibanaCWE-20Improper Input Validation in Kibana Leading to Denial of Service
CVE-2026-143938.820.6GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote…
CVE-2026-580245.120.6Wikimedia FoundationMediaWikiCWE-200API identification of users on private wikis
CVE-2026-125757.520.2deltawwDVP80ES3CWE-404DVP80ES3 Improper Resource Shutdown or Release Vulnerability
CVE-2026-51426.520.2Red HatRed Hat Satellite 6.16 for RHEL 8CWE-639Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scopin…
CVE-2026-50514.420.3HashiCorpVaultCWE-22Audit Log Plugin Directory Guard Bypass via Legacy path Option
CVE-2026-143879.620.0GoogleChromeCWE-472Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a re…
CVE-2026-143929.620.0GoogleChromeCWE-787Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a…
CVE-2026-125797.419.7deltawwAS228TCWE-288AS228T - Authentication Bypass Vulnerability
CVE-2026-547566.319.7xdanjoditCWE-1321Jodit Editor: Prototype pollution via Jodit.configure() / ConfigMerge
CVE-2026-502806.019.6craftcmscmsCWE-284Craft CMS: Authorization bypass in `entries/move-to-section` via missing targ…
CVE-2026-144228.819.5GoogleChromeCWE-125Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 …
CVE-2026-129024.319.6stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-862Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor…
CVE-2026-136027.719.5pretixpretixCWE-20Session takeover vulnerability
CVE-2025-233509.019.1NVIDIABlueField GACWE-787NVIDIA ConnectX and BlueField contain a vulnerability in the command interfac…
CVE-2025-233519.019.1NVIDIABlueField GACWE-787NVIDIA ConnectX and BlueField contain a vulnerability in the command interfac…
CVE-2026-105399.519.0BMCControl-M/ServerCWE-305Unauthenticated command injection in Control-M/Server communication command
CVE-2026-557926.019.0craftcmscmsCWE-200Craft CMS: Sensitive File Disclosure / Server-Side File Read
CVE-2026-107508.118.9UnknownRoyal MCPRoyal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
CVE-2026-119886.518.9thimpressLearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-639LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Su…
CVE-2026-51356.518.5Red HatRed Hat Satellite 6.16 for RHEL 8CWE-639Foreman: foreman: unauthorized modification of host configurations via broken…
CVE-2026-142586.518.5Red HatRed Hat Enterprise Linux 10CWE-835Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd o…
CVE-2026-143829.618.5GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-144097.518.5GoogleChromeCWE-693Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 al…
CVE-2026-472625.318.5containerdcontainerdCWE-400containerd image-triggered runtime DoS via unbounded group parsing
CVE-2026-502835.318.5craftcmscmsCWE-639Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
CVE-2026-143958.818.4GoogleChromeCWE-787Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a r…
CVE-2026-144318.818.4GoogleChromeCWE-843Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote…
CVE-2026-141937.518.2deltawwDVP80ES300TCWE-129DVP80ES300T - Improper Validation of Array Index Vulnerability
CVE-2026-547127.518.2open-telemetryopentelemetry-java-instrumentationCWE-400OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
CVE-2026-143846.518.2GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.4…
CVE-2026-143866.518.2GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a…
CVE-2026-143886.518.2GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a…
CVE-2026-134546.518.0jetmonstersMotoPress Appointment BookingCWE-89MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection…
CVE-2026-143405.317.8GitHubEnterprise ServerCWE-863An incorrect authorization vulnerability in GitHub Enterprise Server allows i…
CVE-2026-144038.817.6GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote…
CVE-2026-557935.917.5craftcmscmsCWE-79Craft CMS: Stored XSS via Structure entry title in table view
CVE-2026-124084.317.5rilwisSlim SEO – A Fast & Automated SEO Plugin For WordPressCWE-200Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization t…
CVE-2026-580335.317.2Wikimedia FoundationMediaWikiCWE-200"Total number of distinct authors" statistic at action=info does not exclude …
CVE-2026-144119.617.0GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-144209.617.0GoogleChromeCWE-125Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 …
CVE-2026-144158.817.0GoogleChromeCWE-122Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 al…
CVE-2026-125778.716.9deltawwDVP80ES3CWE-358DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
CVE-2026-28918.216.9HP IncCCXCWE-400Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
CVE-2026-490906.516.7ElasticElasticsearchCWE-400Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-121334.316.6beardevJoomSport – for Sports: Team & League, Football, Hockey & moreCWE-862JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arb…
CVE-2026-144288.316.5GoogleChromeCWE-20Insufficient validation of untrusted input in Dawn in Google Chrome on Androi…
CVE-2026-502847.116.5craftcmscmsCWE-862Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFo…
CVE-2026-51384.316.5Red HatRed Hat Satellite 6.16 for RHEL 8CWE-639Foreman: foreman: information disclosure via improper validation of nested re…
CVE-2026-144328.816.3GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote…
CVE-2026-75177.216.2dhruvinCustom Payment Gateways for WooCommerceCWE-79Custom Payment Gateways for WooCommerce <= 2.1.0 - Unauthenticated Stored Cro…
CVE-2026-132466.416.3stellarwpGiveWP – Donation Plugin and Fundraising PlatformCWE-79GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'b…
CVE-2026-105388.916.1BMCControl-M/Enterprise ManagerCWE-502Improper deserialization handling in Control-M Components
CVE-2026-144278.316.0GoogleChromeCWE-122Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed …
CVE-2026-502797.616.0craftcmscmsCWE-285Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mut…
CVE-2026-539035.315.8MyComplianceOfficeMCOCWE-639Insecure Direct Object Reference in MCO
CVE-2026-580362.115.8Wikimedia FoundationMediaWikiCWE-200Users API leaks whether privileged users have their user groups disabled for …
CVE-2026-143979.615.7GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 a…
CVE-2026-144169.615.7GoogleChromeCWE-125Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a …
CVE-2026-555945.315.5ImageMagickImageMagickCWE-400ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
CVE-2026-137070.015.3Wikimedia FoundationOAuthCWE-384Session fixation attacks on improperly configured OAuth 1.0a tools
CVE-2026-122248.815.2wedevsDokan ProCWE-269Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_…
CVE-2026-556614.815.2tinacmstinacmsCWE-79TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, al…
CVE-2026-143966.515.0GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a…
CVE-2026-144018.315.0GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome on Andro…
CVE-2026-144128.315.0GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-117948.114.9UnknownAdvanced Form Integration — Connect Forms to 200+ AppsAdvanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via …
CVE-2026-143909.614.6GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a rem…
CVE-2026-143948.814.6GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote…
CVE-2026-144145.314.6GoogleChromeCWE-20Insufficient validation of untrusted input in Skia in Google Chrome prior to …
CVE-2026-91076.414.5wpchillKali Forms — Contact Form & Drag-and-Drop BuilderCWE-79Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-100956.414.6opajaapWP Photo Album PlusCWE-79WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross…
CVE-2026-143915.314.5GoogleChromeCWE-190Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 …
CVE-2026-580275.314.5Wikimedia FoundationAbuseFilterCWE-200QueryAbuseFilter API can be used to see the hit count of private filters, whi…
CVE-2026-143898.314.4GoogleChromeCWE-472Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a re…
CVE-2026-124354.314.3stylemixMotors – Car Dealership & Classified Listings PluginCWE-862Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbi…
CVE-2026-580260.014.3Wikimedia FoundationMediaWikiCWE-200$wgNonincludableNamespaces can be bypassed by embedding redirect in other nam…
CVE-2026-144298.313.8GoogleChromeCWE-20Insufficient validation of untrusted input in Skia in Google Chrome prior to …
CVE-2026-121134.313.7codepeopleAppointment Booking CalendarCWE-862Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticat…
CVE-2026-539095.313.7MyComplianceOfficeMCOCWE-434Arbitrary File Upload in MCO
CVE-2026-555775.913.5ImageMagickImageMagickCWE-754ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder
CVE-2026-143996.513.3GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a r…
CVE-2026-144026.513.3GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46…
CVE-2026-144086.513.3GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a r…
CVE-2026-547046.513.2open-telemetryopentelemetry-java-instrumentationCWE-532OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-T…
CVE-2026-144008.313.1GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed …
CVE-2026-144239.612.8GoogleChromeCWE-843Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remo…
CVE-2026-466807.312.9containerdcontainerdCWE-269containerd user ID handling bypass allows runAsNonRoot evasion
CVE-2026-580295.312.9Wikimedia FoundationMediaWikiCWE-287Full Account Takeover from BotPasswords and OAuth via action=changeauthentica…
CVE-2026-78307.412.7uvncUltraVNCCWE-326UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabli…
CVE-2026-534666.512.8ImageMagickImageMagickCWE-190ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion o…
CVE-2026-579625.312.7MozillaThunderbirdCWE-400Denial-of-service via malicious LDAP address-book server
CVE-2026-556884.012.7AsyncHttpClientasync-http-clientCWE-1275AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via T…
CVE-2026-542602.712.8wagtailwagtailCWE-400Wagtail: Denial of service via unbounded filter specs in the image preview
CVE-2026-144259.612.6GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a rem…
CVE-2026-144267.512.4GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote…
CVE-2026-547862.312.4bytecodealliancewasmtimeCWE-400Wasmtime: Leak in WASIp1 `fd_renumber` implementation
CVE-2026-143989.612.2GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a rem…
CVE-2026-144199.612.2GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remo…
CVE-2026-144249.612.2GoogleChromeCWE-416Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed…
CVE-2026-144216.512.2GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46…
CVE-2026-127546.112.2e4jvikwpVikBooking Hotel Booking Engine & PMSCWE-79VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Script…
CVE-2026-133238.711.7Eclipse FoundationEclipse Open VSXCWE-79In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-su…
CVE-2026-143816.511.7GoogleChromeCWE-290Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.…
CVE-2026-585938.711.6NodeBBNodeBBCWE-290NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to L…
CVE-2026-539086.911.6MyComplianceOfficeMCOCWE-204User Enumeration in MCO
CVE-2026-130156.111.6jgwhite33WP Google Review SliderCWE-79WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' …
CVE-2026-490884.411.7ElasticKibanaCWE-532Insertion of Sensitive Information into Log File in Kibana Leading to Informa…
CVE-2026-51208.111.4Dassault SystèmesBIOVIA WorkbookCWE-362Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 thro…
CVE-2026-539027.111.3MyComplianceOfficeMCOCWE-266Privilege Escalation in MCO
CVE-2026-498585.911.3api-platformcoreCWE-524API Platform Core: Cross-user attribute leak in JSON:API and HAL item normali…
CVE-2026-144179.611.0GoogleChromeCWE-416Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remo…
CVE-2026-121588.810.8metagaussRegistrationMagic – Custom Registration Forms, User Registration, Payment, and User LoginCWE-352RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escala…
CVE-2026-204587.510.7MediaTek, Inc.MediaTek chipsetCWE-787In Modem, there is a possible memory corruption due to a missing bounds check…
CVE-2026-539046.310.6MyComplianceOfficeMCOCWE-307Account Denial of Service in MCO
CVE-2026-542637.310.6wagtailwagtailCWE-79Wagtail: Reflected XSS in dynamic image URL generator view
CVE-2026-577204.310.6Codexpert IncThumbPressCWE-862WordPress ThumbPress plugin <= 6.3.2 - Broken Access Control vulnerability
CVE-2026-144138.310.5GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a …
CVE-2026-144046.510.4GoogleChromeCWE-451Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.4…
CVE-2026-490918.010.3ElasticKibanaCWE-116Improper Output Neutralization for Logs in Kibana Leading to Log Injection
CVE-2026-542616.510.3wagtailwagtailCWE-280Wagtail: Improper permission handling in image preview
CVE-2026-134436.410.1themeumTutor LMS – eLearning and online course solutionCWE-79Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via…
CVE-2026-137336.410.1codename065Download ManagerCWE-79Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-121356.410.1foliovisionFV Flowplayer Video PlayerCWE-79FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stor…
CVE-2026-561525.310.1ElasticElastic DefendCWE-863Incorrect Authorization in Elastic Defend Leading to Information Disclosure
CVE-2026-534675.39.9ImageMagickImageMagickCWE-200ImageMagick: Information Disclosure in MNG decoder because allocated memory i…
CVE-2026-556607.69.6tinacmstinacmsCWE-79TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization byp…
CVE-2026-100964.39.6qodeinteractiveQi BlocksCWE-639Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Autho…
CVE-2026-144407.69.6CloudflareUniversal SSLCWE-693Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-…
CVE-2026-541646.59.6api-platformcoreCWE-843API Platform Core: Missing IRI type check enables resource type confusion
CVE-2026-585176.99.5The Wikimedia FoundationMediawiki - WikiLambda ExtensionCWE-288Blocked users can create and edit WikiLambda objects
CVE-2026-274095.39.4Webba PluginsWebba BookingCWE-862WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerability
CVE-2026-539055.39.3MyComplianceOfficeMCOCWE-863Unauthorized Access to Administrator ACL View in MCO
CVE-2026-579636.59.1MozillaThunderbirdCWE-79Chat UI manipulation by injection
CVE-2026-580325.39.1Wikimedia FoundationMediaWikiCWE-79mw.Api.getErrorMessage() may return injected HTML if used without errorformat…
CVE-2026-144104.39.0GoogleChromeCWE-451Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 …
CVE-2026-144065.98.9GoogleChromeCWE-125Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an a…
CVE-2026-127326.48.7thimpressLearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-79LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-534898.28.6containerdcontainerdCWE-61containerd: Arbitrary host CRI log file read via symlink following in CRI che…
CVE-2026-144184.38.4GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a …
CVE-2026-415793.38.5opencontainersruncCWE-61runc: Malicious image with /dev symlink can trigger limited host filesystem i…
CVE-2026-204575.38.1MediaTek, Inc.MediaTek chipsetCWE-476In Modem, there is a possible system crash due to improper input validation. …
CVE-2026-204615.37.9MediaTek, Inc.MediaTek chipsetCWE-787In Modem, there is a possible out of bounds write due to a missing bounds che…
CVE-2026-582637.27.8xdanjoditCWE-79Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext car…
CVE-2026-577215.37.7WP ReloadedApplyOnlineCWE-862WordPress ApplyOnline plugin <= 2.6.7.6 - Broken Access Control vulnerability
CVE-2026-118874.37.6UnknownSalon Booking SystemSalon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass
CVE-2026-534889.47.4containerdcontainerdCWE-20containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binar…
CVE-2026-585206.97.5The Wikimedia FoundationMediawiki - UrlShortener ExtensionCWE-601UrlShortener defaults to ineffective validation open to third-party redirects
CVE-2026-242437.87.3NVIDIAMegatron-BridgeCWE-502NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-242487.87.3NVIDIAMegatron-BridgeCWE-94NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-577367.47.3HubSpotHubSpotCWE-201WordPress HubSpot plugin <= 11.3.51 - Sensitive Data Exposure vulnerability
CVE-2026-143586.97.3The Wikimedia FoundationMediawiki - Charts ExtensionCWE-79Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title
CVE-2026-143246.57.3Red HatRed Hat Enterprise Linux 10CWE-476Pipewire: raop rtsp null deref
CVE-2026-204605.37.2MediaTek, Inc.MediaTek chipsetCWE-288In Modem, there is a possible information disclosure due to improper input va…
CVE-2026-580305.37.0Wikimedia FoundationSyntaxHighlight_GeSHiCWE-79SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute
CVE-2026-274355.36.8WofficeIOWofficeCWE-862WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability
CVE-2026-580280.06.8Wikimedia FoundationMediaWikiCWE-79Pretty-printed API output combined with centralauthtoken allows XSS with cert…
CVE-2026-540747.86.8tinacmstinacmsCWE-94@tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TI…
CVE-2026-242467.86.6NVIDIAMegatron-BridgeCWE-470NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-242477.86.6NVIDIAMegatron-BridgeCWE-502NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-204595.36.6MediaTek, Inc.MediaTek chipsetCWE-288In Modem, there is a possible system crash due to improper input validation. …
CVE-2026-580340.06.6Wikimedia FoundationCheckUserCWE-79Stored XSS through a system message when blocking a temporary account that's …
CVE-2026-580350.06.6Wikimedia FoundationMediaWikiCWE-79Stored XSS through a system message in the codex version of Special:Block
CVE-2026-580370.06.6Wikimedia FoundationMediaWikiCWE-79Core log entries for exceptions and XSS issues in log entry formatting code t…
CVE-2026-580380.06.6Wikimedia FoundationtimelineCWE-79Stored XSS through javascript URLs in SVGs generated by EasyTimeline
CVE-2026-242407.86.2NVIDIAMegatron-BridgeCWE-502NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-242497.86.1NVIDIAMegatron-BridgeCWE-94NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-115624.35.9UnknownWS Form LITEWS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
CVE-2026-542594.35.8wagtailwagtailCWE-280Wagtail: Improper restriction handling on Documents and Images chosen endpoints
CVE-2026-542624.35.8wagtailwagtailCWE-280Wagtail: Pages translations can be created without page permissions when usin…
CVE-2026-580310.05.4Wikimedia FoundationMediaWikiCWE-79Stored i18n XSS in Special:ApiSandbox when a deprecated module is selected
CVE-2026-242507.85.2NVIDIAMegatron-BridgeCWE-502NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-242517.85.2NVIDIAMegatron-BridgeCWE-502NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-547205.45.1silverstripesilverstripe-frameworkCWE-79Silverstripe Framework: Possible XSS attack through media embed
CVE-2026-242447.85.1NVIDIAMegatron-BridgeCWE-502NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-242457.85.1NVIDIAMegatron-BridgeCWE-502NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-119814.35.1stellarwpGiveWP – Donation Plugin and Fundraising PlatformCWE-352GiveWP <= 4.15.3 - Cross-Site Request Forgery
CVE-2026-125767.55.0deltawwDVP80ES3CWE-924DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a C…
CVE-2026-23876.44.8stephenharrisEvent OrganiserCWE-79Event Organiser <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Sc…
CVE-2026-113806.44.8jetmonstersJetWidgets For ElementorCWE-79JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Sit…
CVE-2026-242427.84.6NVIDIAMegatron-BridgeCWE-918NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker c…
CVE-2026-52206.44.5DivvyDrive Information Technologies Inc.DivvyDriveCWE-79Stored XSS in DivvyDrive Information Technologies' DivvyDrive
CVE-2026-577225.94.6ShortPixelEnable Media ReplaceCWE-79WordPress Enable Media Replace plugin <= 4.2.1 - Cross Site Scripting (XSS) v…
CVE-2026-340964.84.4guardianlanguage-systemCWE-79Guardian Language-System XSS via name Parameter in designer.php
CVE-2026-340974.84.4guardianlanguage-systemCWE-79Guardian Language-System XSS via id Parameter in text_file.php
CVE-2026-340984.84.4guardianlanguage-systemCWE-79Guardian Language-System XSS via id Parameter in media.php
CVE-2026-539074.83.9MyComplianceOfficeMCOCWE-79Stored Cross‑Site Scripting in MCO
CVE-2026-132114.33.8genuagenucenterCWE-201Genucenter Disclosure of SNMP Credentials
CVE-2026-118803.13.8UnknownFluent FormsFluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
CVE-2026-115704.23.6UnknownUser Submitted PostsUser Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name
CVE-2026-577376.53.4Averta LTDShortcodes and extra features for Phlox themeCWE-79WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.16 - C…
CVE-2026-533297.03.4LinuxLinuxCWE-674drm/amd/display: Use krealloc_array() in dal_vector_reserve()
CVE-2026-585196.93.3The Wikimedia FoundationMediawiki - Cargo ExtensionCWE-79Stored XSS through Cargo's map format
CVE-2026-62835.43.3DivvyDrive Information Technologies Inc.DivvyDriveCWE-79Stored XSS in DivvyDrive Information Technologies' DivvyDrive
CVE-2026-533548.83.0LinuxLinuxarm64: errata: Mitigate TLBI errata on various Arm CPUs
CVE-2026-533275.53.0LinuxLinuxdebugobjects: Do not fill_pool() if pi_blocked_on
CVE-2026-124805.52.8keras-teamkeras-team/kerasCWE-73Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras
CVE-2026-533417.82.7LinuxLinuxCWE-416fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
CVE-2026-577237.42.5e4jvikwpVikBooking Hotel Booking Engine & PMSCWE-352WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Ar…
CVE-2026-533307.12.5LinuxLinuxCWE-125drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
CVE-2026-411217.82.5DellDevice Management AgentCWE-59Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improp…
CVE-2026-533315.52.4LinuxLinuxslimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
CVE-2026-533325.52.4LinuxLinuxslimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
CVE-2025-156661.92.5Open Asset Import LibraryAssimpCWE-119Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based…
CVE-2026-533285.52.4LinuxLinuxsched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task()
CVE-2026-533567.82.2LinuxLinuxdrm/i915/gem: Fix phys BO pread/pwrite with offset
CVE-2026-369096.22.2n/an/aCWE-476A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Alek…
CVE-2026-533345.52.1LinuxLinuxCWE-476mm/damon/reclaim: handle ctx allocation failure
CVE-2026-533355.52.1LinuxLinuxCWE-476mm/damon/lru_sort: handle ctx allocation failure
CVE-2026-137696.82.0AWSAWS CLICWE-732Overly permissive File Permissions in AWS CLI
CVE-2026-533467.11.9LinuxLinuxCWE-125rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES
CVE-2026-533365.51.7LinuxLinuxnvmem: layouts: onie-tlv: fix hang on unknown types
CVE-2026-533375.51.8LinuxLinuxCWE-476net: bonding: fix NULL pointer dereference in bond_do_ioctl()
CVE-2026-533395.51.7LinuxLinuxCWE-476i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
CVE-2026-533435.51.7LinuxLinuxARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
CVE-2026-533455.51.7LinuxLinuxCWE-401KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
CVE-2026-533475.51.7LinuxLinuxCWE-908drm/virtio: Fix driver removal with disabled KMS
CVE-2026-533495.51.7LinuxLinuxnetfilter: nf_conntrack: destroy stale expectfn expectations on unregister
CVE-2026-533505.51.7LinuxLinuxCWE-476ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
CVE-2026-533535.51.7LinuxLinuxhsr: Remove WARN_ONCE() in hsr_addr_is_self().
CVE-2026-369105.51.7n/an/aCWE-119An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MP…
CVE-2026-533335.51.6LinuxLinuxmm/mincore: handle non-swap entries before !CONFIG_SWAP guard
CVE-2026-533385.51.6LinuxLinuxCWE-476net: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_…
CVE-2026-533405.51.6LinuxLinuxi2c: imx: fix clock and pinctrl state inconsistency in runtime PM
CVE-2026-533425.51.6LinuxLinuxarm64: mm: call pagetable dtor when freeing hot-removed page tables
CVE-2026-204626.71.5MediaTek, Inc.MediaTek chipsetCWE-122In Telephony, there is a possible memory corruption due to a heap buffer over…
CVE-2026-369115.51.5n/an/aCWE-369A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBuffe…
CVE-2026-204636.71.5MediaTek, Inc.MediaTek chipsetCWE-280In Modem, there is a possible escalation of privilege due to a permissions by…
CVE-2026-555105.51.1ImageMagickImageMagickCWE-416ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
CVE-2026-555975.51.1ImageMagickImageMagickCWE-682ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect hand…
CVE-2026-143305.51.0Red HatRed Hat Enterprise Linux 10CWE-770Pipewire: pulse server alloca stack overflow
CVE-2026-533445.51.0LinuxLinuxCWE-908pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init
CVE-2026-533485.51.0LinuxLinuxCWE-476ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions
CVE-2026-533515.51.0LinuxLinuxriscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI
CVE-2026-556285.50.9ImageMagickImageMagickCWE-73ImageMagick: Policy Bypass in concatenate operation due to missing checks
CVE-2026-533265.50.7LinuxLinuxCWE-667debugobjects: Don't call fill_pool() in early boot hardirq context
CVE-2026-555954.70.5ImageMagickImageMagickCWE-400ImageMagick: Infinite Loop in connected-components when providing invalid arg…
CVE-2026-585186.90.5The Wikimedia FoundationMediawiki - RedirectManager ExtensionCWE-352Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation M…
CVE-2026-84804.30.4StormshieldStormshield Network SecurityCWE-295Connection possible to the Administration portal with a revoked certificate
CVE-2026-533524.70.4LinuxLinuxCWE-362signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
CVE-2026-105405.60.1BMCControl-M/Enterprise ManagerCWE-328Weak password hash protection in Control-M/Entreprise Manager
CVE-2026-123746.40.0Cato NetworksSDP ClientCWE-295Improper XPC caller certificate validation and TOCTOU race condition in macOS…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-01 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.