boxscore/security
Thursday, July 2, 2026 · all times UTC← 2026-07-01 · archive · 2026-07-03 →

265 CVEs published July 2, 2026: 32 critical, 149 high, 78 medium, 6 low; 0 in KEV; 4 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 240 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published6301294811862563
KEV catalog size1670

566 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux33151312086252812730.27.5.0013+31
google521316148586542377460.57.8.0023-9
microsoft7718574801604378283.97.8.0044+6
red hat92011183998400.06.6.0026+4
apple0991236629377.16.5.00310
canonical0202585000.05.5.00110
freebsd01601240000.07.8.00150
suse2154830000.08.8.0036+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+25
cisco83141280961135.57.5.0056+8
netgear01700161800.04.3.00240
palo alto networks011017114218.24.8.00220
checkpoint0915303111.17.5.04100
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-1
fortinet08132028337.57.3.00660
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache2155245961104010.67.3.0048-28
mozilla25812182801300.07.3.0025-2
gitlab03305215426.14.4.00220
github171150000.06.0.0026+1
docker070520100.08.2.0016-1
drupal0511305120.05.1.00260
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-1
adobe014611527827532.15.5.00210
ibm01243642460700.07.5.0025-5
progress2111910900.07.5.0035-3
solarwinds07122011457.17.5.0835-1
veeam042200400.09.0.00460
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.00250
d-link01305252617.75.8.0059-2
siemens090450100.06.9.0019-1
rockwell automation071510000.08.7.00300
abb060420000.07.2.00180
schneider electric060420100.07.8.00240
moxa050320000.07.0.00290
dahua030111200.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring073231391000.06.5.0024-2
sourcecodester071003635000.05.5.0026-15
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00590
capgo061231271000.07.1.00310
themerex26055410000.08.1.0043+2
dell157131240211.87.3.0015-1
nvidia1756113870000.07.8.0019+15

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
CVE-2026-4827610.0.0505
CVE-2026-1377310.0.0341
CVE-2026-5641310.0.0316
CVE-2026-5641510.0.0315
Most disclosures (vendor)
VendorCVEs
google1081
linux545
oracle242
microsoft227
adobe142
red hat132
apache93
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven40
Packagist15
PyPI8
npm6
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171688
CVE-2021-27102Accellion2021-11-171688
CVE-2021-27101Accellion2021-11-171688
CVE-2021-27103Accellion2021-11-171688
CVE-2021-21017Adobe2021-11-171688
CVE-2021-28550Adobe2021-11-171688
CVE-2021-42013Apache2021-11-171688
CVE-2021-41773Apache2021-11-171688
CVE-2021-30858Apple2021-11-171688
CVE-2021-30860Apple2021-11-171688

Transactions

EXPLOIT PUBLISHEDCVE-2026-38971. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-38972. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44941 (SUSE libzypp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8147 (mlflow/mlflow). Public exploit reference added.

Yesterday's Results

265 CVEs published. 25 box scores, 240 table rows — nothing truncated.

Notifiarr dockwatch — Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0486   91.3     —
AFFECTED
  Product    Versions     Fixed
  dockwatch  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-78, CWE-698 · CNA: VulnCheck · 2 references · NVD status: Deferred
Ubiquiti Inc UniFi Connect Application — A malicious actor with access to the network could exploit an Improper Access Control vulnerability found i…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0250   83.4     —
AFFECTED
  Product                    Versions     Fixed
  UniFi Connect Application  unspecified  —
TIMELINE
  Jun 6   Reserved by CNA
  Jul 2   Published (CNA: hackerone)
CWE-284 · CNA: hackerone · 1 reference · NVD status: Analyzed
databasebackup WP Database Backup – Unlimited Database & Files Backup by Backup for WP — WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0154   72.8     —
AFFECTED
  Product                                                                  Versions     Fixed
  WP Database Backup – Unlimited Database & Files Backup by Backup for WP  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jul 2   Published (CNA: Wordfence)
CWE-77 · CNA: Wordfence · 8 references · NVD status: Deferred
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0131   68.1     —
AFFECTED
  Product                      Versions     Fixed
  UniFi OS Server              unspecified  —
  Dream Machines               unspecified  —
  Enterprise Fortress Gateway  unspecified  —
  Dream Wall                   unspecified  —
  Dream Routers                unspecified  —
  Express 7                    unspecified  —
  Cloud Keys                   unspecified  —
  Network Video Recorders      unspecified  —
  Enterprise Video Recorders   unspecified  —
  Cloud Gateways               unspecified  —
  + 2 more
TIMELINE
  Jun 13  Reserved by CNA
  Jul 2   Published (CNA: hackerone)
CWE-77, CWE-20 · CNA: hackerone · 1 reference · NVD status: Analyzed
Ubiquiti Inc UniFi Access Application — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0121   65.8     —
AFFECTED
  Product                   Versions     Fixed
  UniFi Access Application  unspecified  —
TIMELINE
  Jun 6   Reserved by CNA
  Jul 2   Published (CNA: hackerone)
CWE-20 · CNA: hackerone · 1 reference · NVD status: Analyzed
WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0101   60.3     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2025.1 –  12.0
  Fireware OS  12.0 –    —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 2   Published (CNA: WatchGuard)
CWE-416 · CNA: WatchGuard · 2 references · NVD status: Analyzed
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0086   55.5     —
AFFECTED
  Product  Versions  Fixed
  KSOA     9.0 –     —
TIMELINE
  Jan 11  Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 5 references · NVD status: Deferred
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0072   51.0     —
AFFECTED
  Product            Versions     Fixed
  Divi Form Builder  unspecified  —
TIMELINE
  Apr 4   Reserved by CNA
  Jul 2   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 2 references · NVD status: Deferred
Guangzhou Red Sea Cloud Computing Co., Ltd. Red Sea Cloud eHR — Redsea Cloud eHR Unauthenticated File Upload RCE via PtFjk.mob
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0071   50.5     —
AFFECTED
  Product            Versions     Fixed
  Red Sea Cloud eHR  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 4 references · NVD status: Deferred
Creative Themes Blocksy Companion Pro — WordPress Blocksy Companion Pro plugin <= 2.1.46 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0068   49.3     —
AFFECTED
  Product                Versions  Fixed
  Blocksy Companion Pro  n/a –     2.1.47
TIMELINE
  Jun 25  Reserved by CNA
  Jul 2   Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · 1 reference · NVD status: Deferred
Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0065   48.3     —
AFFECTED
  Product                               Versions  Fixed
  Microsoft Entra Provisioning Service  - –       —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 2   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · 1 reference · NVD status: Analyzed
WatchGuard Firebox networkd Out of Bounds Write Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0065   48.2     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2025.1 –  —
  Fireware OS  12.0 –    —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 2   Published (CNA: WatchGuard)
CWE-787 · CNA: WatchGuard · 2 references · NVD status: Analyzed
TinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0065   48.2     —
AFFECTED
  Product                                       Versions     Fixed
  TinyPNG – JPEG, PNG & WebP image compression  unspecified  —
TIMELINE
  Apr 28  Reserved by CNA
  Jul 2   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 6 references · NVD status: Deferred
Microsoft Exchange Online Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0065   48.1     —
AFFECTED
  Product                    Versions  Fixed
  Microsoft Exchange Online  - –       —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 2   Published (CNA: microsoft)
CWE-863 · CNA: microsoft · 1 reference · NVD status: Analyzed
Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0064   47.8     —
AFFECTED
  Product      Versions     Fixed
  Perfmatters  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 2   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 3 references · NVD status: Deferred
WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0062   46.9     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2025.1 –  —
  Fireware OS  12.0 –    —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 2   Published (CNA: WatchGuard)
CWE-22 · CNA: WatchGuard · 2 references · NVD status: Modified
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0062   46.9     —
AFFECTED
  Product                      Versions     Fixed
  UniFi OS Server              unspecified  —
  Dream Machines               unspecified  —
  Enterprise Fortress Gateway  unspecified  —
  Dream Wall                   unspecified  —
  Dream Routers                unspecified  —
  Express 7                    unspecified  —
  Cloud Keys                   unspecified  —
  Network Video Recorders      unspecified  —
  Enterprise Video Recorders   unspecified  —
  Cloud Gateways               unspecified  —
  + 2 more
TIMELINE
  Jun 13  Reserved by CNA
  Jul 2   Published (CNA: hackerone)
CWE-22 · CNA: hackerone · 1 reference · NVD status: Analyzed
Microsoft Azure Open AI — Azure OpenAI Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0061   46.3     —
AFFECTED
  Product        Versions  Fixed
  Azure Open AI  - –       —
TIMELINE
  May 12  Reserved by CNA
  Jul 2   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · 1 reference · NVD status: Analyzed
WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command Handler
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0061   46.2     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2025.1 –  —
  Fireware OS  12.0 –    —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 2   Published (CNA: WatchGuard)
CWE-787 · CNA: WatchGuard · 2 references · NVD status: Modified
The Libreswan Project libreswan — IKEv2 Denial of Service via malformed fragmentation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0060   45.8     —
AFFECTED
  Product    Versions  Fixed
  libreswan  4.6 –     5.3.1
TIMELINE
  Jun 16  Reserved by CNA
  Jul 2   Published (CNA: libreswan)
CWE-193, CWE-617 · CNA: libreswan · 2 references · NVD status: Analyzed
WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0060   45.8     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2025.1 –  —
  Fireware OS  12.1 –    —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 2   Published (CNA: WatchGuard)
CWE-787 · CNA: WatchGuard · 2 references · NVD status: Modified
WatchGuard Firebox wgagent Out of Bounds Write Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0060   45.8     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2025.1 –  —
  Fireware OS  12.1 –    —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 2   Published (CNA: WatchGuard)
CWE-787 · CNA: WatchGuard · 2 references · NVD status: Modified
Gardyn IoT Hub Use of Hard-coded Credentials
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   L    9.5   .0058   45.1     —
AFFECTED
  Product                 Versions     Fixed
  Gardyn Home Firmware    unspecified  —
  Gardyn Studio Firmware  unspecified  —
  Gardyn Cloud API        unspecified  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 2   Published (CNA: icscert)
CWE-798 · CNA: icscert · 3 references · NVD status: Deferred
Shenzhen Landray Software Co., Ltd. Landry Office Automation (OA) — Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0056   44.2     —
AFFECTED
  Product                        Versions     Fixed
  Landry Office Automation (OA)  unspecified  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-564 · CNA: VulnCheck · 4 references · NVD status: Deferred
eclipse-wakaama wakaama — Eclipse Wakaama CoAP Block1 Handler Unbounded Memory Allocation DoS
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0056   43.7     —
AFFECTED
  Product  Versions     Fixed
  wakaama  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-770 · CNA: VulnCheck · 4 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-528309.443.2leshchenko1979fast-mcp-telegramCWE-22fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram ses…
CVE-2026-411069.342.4MicrosoftMicrosoft 365 CopilotCWE-601Microsoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-551159.941.9Ubiquiti IncUniFi Protect ApplicationCWE-918A malicious actor with access to the network and low privileges could exploit…
CVE-2026-449418.841.8SUSElibzyppCWE-23libzypp path traversal via "keyhint" in repomd.xml
CVE-2026-544009.141.7Ubiquiti IncUniFi Access ApplicationCWE-284A malicious actor with access to the network and high privileges could exploi…
CVE-2026-389719.141.1n/an/aCWE-125ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issu…
CVE-2026-584669.340.9EstrellaXDAuto_BangumiCWE-1392AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user()
CVE-2026-130848.740.5WatchGuardFireware OSCWE-476Null Pointer Dereference in WatchGuard Fireware OS iked Process
CVE-2026-507479.939.9Ubiquiti IncUniFi Talk ApplicationCWE-89A malicious actor with access to the network and low privileges could exploit…
CVE-2026-586527.739.4openwrtluci-app-travelmateCWE-78luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameter
CVE-2026-559528.239.4ErlangOTPCWE-1284TLS 1.3 server denial of service via malformed ClientHello pre-shared key ext…
CVE-2026-590948.738.7pathwaycompathwayCWE-407Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matc…
CVE-2026-521877.537.5n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-521897.537.5n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-521917.537.5n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-389707.537.4n/an/aCWE-674pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service i…
CVE-2026-551169.834.5Ubiquiti IncDream MachinesCWE-284A malicious actor with access to the network and under certain network config…
CVE-2026-449359.934.4SUSERancherCWE-1287Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated…
CVE-2026-521927.534.1n/an/aCWE-400An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker …
CVE-2026-133697.534.0SaturdayDriveNinja Forms - File UploadsCWE-22Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read vi…
CVE-2026-584678.233.9cockpit-hqcockpitCWE-22Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php
CVE-2026-557266.932.5GardynGardyn Home FirmwareCWE-497Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Co…
CVE-2026-590938.732.0weaviateweaviateCWE-266Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Ro…
CVE-2025-691337.532.0GoodLayersTourmasterCWE-98WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability
CVE-2026-507215.931.8The Libreswan ProjectlibreswanCWE-347IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentic…
CVE-2026-274369.131.7RustauriusFive Star Business Profile and SchemaCWE-94WordPress Five Star Business Profile and Schema plugin <= 2.3.19 - Arbitrary …
CVE-2026-551178.631.3Ubiquiti IncUniFi Access ApplicationCWE-22A malicious actor with access to the network could exploit a Path Traversal v…
CVE-2026-335927.531.4open62541 project / o6 Automation GmbHopen62541CWE-770FindServers Memory Exhaustion in open62541
CVE-2026-119467.531.2open62541 project / o6 Automation GmbHopen62541CWE-770GetEndpoints Memory Exhaustion in open62541
CVE-2026-126575.331.3latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-639LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbi…
CVE-2026-389689.831.1n/an/aCWE-341ntopng through 6.6 is vulnerable to Predictable Session Identifier which can …
CVE-2026-559508.731.1ErlangOTPCWE-367DTLS listener crash via race condition in dtls_packet_demux causes denial of …
CVE-2026-544068.730.8Ubiquiti IncUniFi Network ApplicationCWE-22A malicious actor with access to the network and high privileges could exploi…
CVE-2026-590927.030.8juicedatajuicefsCWE-489JuiceFS - Authentication Bypass via pprof and metrics Endpoints
CVE-2026-81478.130.7mlflowmlflow/mlflowCWE-284Authorization Bypass in mlflow/mlflow
CVE-2026-5600410.030.6openSUSEbuildserviceCWE-78obs-service-tar_scm: command injection via mercurial handler
CVE-2026-573476.530.2jetmonstersHotel Booking LiteCWE-201WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulner…
CVE-2026-261459.829.0MicrosoftAzure SynapseCWE-284Microsoft Azure Synapse Elevation of Privilege Vulnerability
CVE-2026-590999.328.7apereocasCWE-323Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
CVE-2026-274199.928.2ZozothemesZegenCWE-434WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability
CVE-2026-133716.928.1WatchGuardFireware OSCWE-502WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserializa…
CVE-2026-95637.527.6Eclipse FoundationEclipse ParssonCWE-400In Eclipse Parsson published Maven Central artifacts before version 1.1.8, th…
CVE-2026-507225.927.7The Libreswan ProjectlibreswanCWE-347IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authenticatio…
CVE-2026-124725.327.6themeumKirki – Freeform Page Builder, Website Builder & CustomizerCWE-862Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Co…
CVE-2025-691326.527.5ZozothemesCorpkitCWE-201WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability
CVE-2026-58218.127.4elemntorImage Optimizer – Optimize Images and Convert to WebP or AVIFCWE-73Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion vi…
CVE-2026-590976.927.4taigataiga-backCWE-862Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets
CVE-2026-497796.527.3AddifyTax Exempt for WooCommerceCWE-35WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerab…
CVE-2026-576696.527.0Vsourz DigitalAdvanced Contact form 7 DBCWE-862WordPress Advanced Contact form 7 DB plugin <= 2.0.9 - Broken Access Control …
CVE-2026-544057.526.9Ubiquiti IncUniFi Network ApplicationCWE-20A malicious actor with access to the network could exploit an Improper Input …
CVE-2026-551117.526.4Ubiquiti IncUniFi Protect FloodlightCWE-22A malicious actor with access to the network could exploit a Path Traversal v…
CVE-2026-47679.826.2TR7 Cyber ​​Defense Inc.WAF-ASPCWE-306Improper Access Control in TR7's WAF-ASP
CVE-2026-142497.526.2emarket-designRequest a Quote – Quote Forms for Any WordPress SiteCWE-74Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'pa…
CVE-2026-134595.326.2jetmonstersJetFormBuilder — Dynamic Blocks Form BuilderCWE-862JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive …
CVE-2026-548865.326.0ErlangOTPCWE-400SSH SFTP server denial of service via extended channel data infinite loop
CVE-2026-576219.825.5ArrayticsBookticsCWE-502WordPress Booktics plugin <= 1.0.21 - PHP Object Injection vulnerability
CVE-2026-576779.825.5NovalnetNovalnet Payment Gateway for WooCommerceCWE-502WordPress Novalnet Payment Gateway for WooCommerce plugin <= 12.10.3 - PHP Ob…
CVE-2026-576239.025.1BoldGridW3 Total CacheCWE-1284WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerabi…
CVE-2026-591016.924.9EstrellaXDAuto_BangumiCWE-918AutoBangumi < 3.2.8 - SSRF via /api/v1/setup/test-downloader
CVE-2026-140296.524.6trainingbusinessprosGroundhogg — CRM, Newsletters, and Marketing AutomationCWE-89Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Para…
CVE-2026-118965.324.0joedolsonMy Calendar – Accessible Event ManagerCWE-639My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated S…
CVE-2026-544078.623.7Ubiquiti IncUniFi Protect ApplicationCWE-284A malicious actor with access to the network could exploit an Improper Access…
CVE-2026-91456.523.4crmperksDatabase for Contact Form 7, WPforms, Elementor formsCWE-22Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthentica…
CVE-2026-585787.123.1lobehublobehubCWE-1333LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub …
CVE-2026-544089.823.0Ubiquiti IncUniFi Protect ApplicationCWE-284A malicious actor with access to the network could exploit an Improper Access…
CVE-2026-560378.822.5ThemifyThemify PopupCWE-502WordPress Themify Popup plugin <= 1.4.3 - PHP Object Injection vulnerability
CVE-2026-573536.522.5LinkWhisperLink Whisper PremiumCWE-862WordPress Link Whisper Premium plugin <= 2.9.0 - Broken Access Control vulner…
CVE-2026-573556.522.5RadiusThemeClassified ListingCWE-862WordPress Classified Listing plugin <= 5.4.2 - Broken Access Control vulnerab…
CVE-2026-91885.322.3wappointmentAppointment Bookings for Zoom GoogleMeet and more – WappointmentCWE-639Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - U…
CVE-2026-423828.121.9Elated-ThemesAudreyCWE-98WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability
CVE-2026-572688.321.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572738.321.9GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-572748.321.9GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-572758.321.9GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-572768.321.9GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2025-691347.521.6MerkuloveOpenAI Chatbot for WordPress – HelperCWE-862WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary C…
CVE-2026-572778.321.2GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-572788.321.2GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-121225.321.0themeumKirki – Freeform Page Builder, Website Builder & CustomizerCWE-862Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Informat…
CVE-2026-577528.520.6iNETiNET WebkitCWE-89WordPress iNET Webkit plugin 1.2.4 - SQL Injection vulnerability
CVE-2026-544048.820.5Ubiquiti IncUniFi OS ServerCWE-89A malicious actor with access to the network and low privileges could exploit…
CVE-2026-568418.820.5Ubiquiti IncUniFi Protect ApplicationCWE-89A malicious actor with access to the network and low privileges could exploit…
CVE-2026-270608.820.4Repute InfosystemsARMember PremiumCWE-502WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability
CVE-2026-274148.820.4FuelthemesWerkstattCWE-502WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability
CVE-2026-133574.920.4propertyhiveHouzez Property FeedCWE-89Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection…
CVE-2026-577487.520.0Shopify Help CenterShopifyCWE-98WordPress Shopify plugin <= 1.0.0 - Local File Inclusion vulnerability
CVE-2025-589028.119.8AncoraThemesLighthouseCWE-98WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability
CVE-2026-274128.119.8StylemixThemesPearl - Corporate BusinessCWE-98WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion v…
CVE-2026-84417.519.7https://wpreviewslider.com/WP Review Slider ProCWE-89WP Review Slider Pro <= 12.7.2 - Unauthenticated SQL Injection via 'notinstri…
CVE-2026-137228.619.6WatchGuardFireware OSCWE-347WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS
CVE-2026-544098.119.6Ubiquiti IncUniFi Protect ApplicationCWE-665A malicious actor with access to the network and under certain conditions cou…
CVE-2026-115924.319.6icegramEmail Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressCWE-862Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenti…
CVE-2026-544775.119.3GardynGardyn Home FirmwareCWE-644Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2025-690948.519.2ThemeMoveUnicampCWE-89WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability
CVE-2026-577497.519.2ThemeBoySportsPress ProCWE-98WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerability
CVE-2026-144496.419.1u5CMSu5CMSCWE-79POST-based reflected XSS via the thanks parameter in form components
CVE-2026-82477.719.0WatchGuardFireware OSCWE-787WatchGuard Firebox admd Out of Bounds Write Vulnerability
CVE-2026-101044.418.4nikhilgadhiyaProduct Video Gallery for WoocommerceCWE-79Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manage…
CVE-2026-53485.318.1kodezenAcademy LMS – WordPress LMS Plugin for Complete eLearning SolutionCWE-639Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Pr…
CVE-2026-534222.318.1ErlangOTPCWE-204SFTP REALPATH path-existence oracle allowing filesystem enumeration outside c…
CVE-2026-576259.618.0ASEAdmin and Site Enhancements (ASE) ProCWE-79WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site …
CVE-2026-551148.817.9Ubiquiti IncUniFi Network ApplicationCWE-284A malicious actor with access to the network and low privileges could exploit…
CVE-2026-533578.017.6LinuxLinuxCWE-416Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
CVE-2026-394487.517.4CoderPressNOWPayments for WooCommerceCWE-862WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control…
CVE-2026-576854.317.1drfuriMartfury - WooCommerce Marketplace WordPress ThemeCWE-862WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 -…
CVE-2026-572728.317.0GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-502817.117.0craftcmscmsCWE-915Craft CMS: Mass assignment via id in newAttributes during bulk duplicate over…
CVE-2026-576806.516.9ThemeumKirkiCWE-639WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) v…
CVE-2026-92728.716.9Progress SoftwareFlowmon ADSCWE-89Possibility of unintended database operations when querying data related to d…
CVE-2026-572698.316.1GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-590968.216.1daprdaprCWE-346Dapr - OIDC Discovery Issuer and JWKS URI Injection via Unvalidated X-Forward…
CVE-2026-274336.516.0StylemixThemesMotorsCWE-862WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerability
CVE-2026-548876.315.7ErlangOTPCWE-1394DTLS server cookie bypass during startup window due to empty initial cookie s…
CVE-2026-572718.315.4GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-576799.315.3AhmadgbGeekyBotCWE-89WordPress GeekyBot plugin <= 1.2.5 - SQL Injection vulnerability
CVE-2026-576839.315.3EpsiloncoolWP Fast Total SearchCWE-89WordPress WP Fast Total Search plugin <= 1.80.280 - SQL Injection vulnerability
CVE-2026-100776.815.4UnknownyoothemeYOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes
CVE-2026-544018.815.2Ubiquiti IncUniFi OS ServerCWE-918A malicious actor with access to the network and low privileges could exploit…
CVE-2026-590987.115.1lobehublobehubCWE-639LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search
CVE-2026-131258.815.0GeoVision Inc.GeoWebPlayerCWE-306GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability
CVE-2026-521886.515.0n/an/aCWE-119Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2025-713855.114.9netdatanetdataCWE-79Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.…
CVE-2026-116004.314.8envothemesEnvo's Templates & Widgets for Elementor and WooCommerceCWE-862Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing …
CVE-2026-590958.314.7lobehublobehubCWE-918LobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl
CVE-2026-576888.214.6GurmehubPOS EntegratörCWE-862WordPress POS Entegratör plugin <= 3.7.103 - Broken Access Control vulnerability
CVE-2026-577467.114.6ThemeREXBookedCWE-862WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability
CVE-2026-137046.414.4stellarwpGiveWP – Donation Plugin and Fundraising PlatformCWE-79GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting v…
CVE-2026-121344.314.3beardevJoomSport – for Sports: Team & League, Football, Hockey & moreCWE-862JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arb…
CVE-2026-143368.213.7Eclipse FoundationEclipse CSI - PIACWE-918PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix chec…
CVE-2026-572678.313.4GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572708.313.4GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-576816.413.2PaoloGeoDirectoryCWE-918WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF)…
CVE-2026-551137.513.2Ubiquiti IncUniFi Talk ApplicationCWE-918A malicious actor with access to the network could exploit a Server-Side Requ…
CVE-2026-576894.313.0FuelthemesWerkstattCWE-862WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability
CVE-2026-577304.313.0UX-themesFlatsomeCWE-862WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVE-2026-131318.312.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-131328.312.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572648.312.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572658.312.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572668.312.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-551198.112.9Ubiquiti IncUniFi Talk ApplicationCWE-284A malicious actor with access to the network and low privileges could exploit…
CVE-2026-573426.512.5ShortPixelShortPixel Adaptive ImagesCWE-79WordPress ShortPixel Adaptive Images plugin <= 3.11.3 - Cross Site Scripting …
CVE-2026-573546.512.5Crocoblock. Jetimpex Inc.JetReviewsCWE-79WordPress JetReviews plugin <= 3.0.0.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-576878.512.0Hiroaki MiyashitaCustom Field TemplateCWE-89WordPress Custom Field Template plugin <= 2.7.8 - SQL Injection vulnerability
CVE-2026-577568.512.0友人a丶nicen-localize-imageCWE-89WordPress nicen-localize-image plugin <= 1.4.9 - SQL Injection vulnerability
CVE-2026-577658.512.0LevelfourdevelopmentWP EasyCartCWE-89WordPress WP EasyCart plugin <= 5.9.0 - SQL Injection vulnerability
CVE-2026-568427.512.0Ubiquiti IncUniFi Network ApplicationCWE-863A malicious actor with access to the network and under certain conditions cou…
CVE-2026-100896.411.6figureoneInsert PagesCWE-79Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting …
CVE-2026-577316.511.4UX-themesFlatsomeCWE-862WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVE-2026-121665.511.3Little OrbitGameFirst Anti-CheatCVE-2026-12166
CVE-2025-660765.311.2dylan ngoWoostify Sites LibraryCWE-862WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vuln…
CVE-2026-86997.011.0TP-Link Systems Inc.Archer C5 v6.8CWE-79Stored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management Interface
CVE-2026-502824.911.1craftcmscmsCWE-862Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves
CVE-2026-551188.310.7Ubiquiti IncUniFi Network ApplicationCWE-284A malicious actor with access to the network,low privileges and under certain…
CVE-2026-573524.810.7VillaThemeALD – Dropshipping and Fulfillment for AliExpress and WooCommerceCWE-1390WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce p…
CVE-2026-577535.310.2NathanbarryKit (formerly ConvertKit) for WooCommerceCWE-497WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensiti…
CVE-2026-591022.110.0forgejoforgejoCWE-79Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering
CVE-2026-551128.89.9Ubiquiti IncDream MachinesCWE-284A malicious actor with access to the network and low privileges and under cer…
CVE-2026-573487.29.7CozmoslabsPaid Member SubscriptionsCWE-918WordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request For…
CVE-2026-533588.89.6LinuxLinuxCWE-667Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
CVE-2026-132526.49.6themeisleRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds AggregatorCWE-79RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross…
CVE-2026-117812.78.8UnknownAdminifyAdminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global …
CVE-2026-274267.18.5ThemesuiteAutomotive Car Dealership BusinessCWE-79WordPress Automotive Car Dealership Business theme <= 13.3.3 - Reflected Cros…
CVE-2026-274307.18.5tranmautritamTheFoxCWE-79WordPress TheFox theme <= 3.9.76 - Reflected Cross Site Scripting (XSS) vulne…
CVE-2026-573437.18.5ContempoincReal Estate 7CWE-79WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-573447.18.5RadiusThemeClassified ListingCWE-79WordPress Classified Listing plugin <= 5.4.2 - Cross Site Scripting (XSS) vul…
CVE-2026-573457.18.5WebraketenInternal Links ManagerCWE-79WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS)…
CVE-2026-573497.18.5etruelWPeMatico RSS Feed FetcherCWE-79WordPress WPeMatico RSS Feed Fetcher plugin <= 2.8.17 - Cross Site Scripting …
CVE-2026-573507.18.5Andy FragenWP DebuggingCWE-79WordPress WP Debugging plugin <= 2.12.2 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-573517.18.5Haktan SurenHandL UTM GrabberCWE-79WordPress HandL UTM Grabber plugin <= 2.9.2 - Cross Site Scripting (XSS) vuln…
CVE-2026-573567.18.5Moreconvert TeamMC Woocommerce WishlistCWE-79WordPress MC Woocommerce Wishlist plugin <= 1.9.19 - Cross Site Scripting (XS…
CVE-2026-573577.18.5Search Atlas GroupSearch Atlas SEOCWE-79WordPress Search Atlas SEO plugin <= 2.6.6 - Reflected Cross Site Scripting (…
CVE-2026-573587.18.5SysBasicsCustomize My Account for WooCommerceCWE-79WordPress Customize My Account for WooCommerce plugin <= 4.3.9 - Reflected Cr…
CVE-2026-573597.18.5ReviewXReviewXCWE-79WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573607.18.5impleCodeeCommerce Product CatalogCWE-79WordPress eCommerce Product Catalog plugin <= 3.5.4 - Cross Site Scripting (X…
CVE-2026-573617.18.5Ays ProSurvey MakerCWE-79WordPress Survey Maker plugin <= 5.2.2.5 - Cross Site Scripting (XSS) vulnera…
CVE-2026-573627.18.5QuantumCloudChatBotCWE-79WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vuln…
CVE-2026-573667.18.5Greg WiniarskiWPAdvertsCWE-79WordPress WPAdverts plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-574267.18.5Chill Media Labs S.R.L.Modula - PROCWE-79WordPress Modula - PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-576707.18.5CodepeopleGoogle Maps CPCWE-79WordPress Google Maps CP plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnera…
CVE-2026-576717.18.5PerfmattersperfmattersCWE-79WordPress perfmatters plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576727.18.5Melograno Venture StudiowpDataTablesCWE-79WordPress wpDataTables plugin <= 6.5.1.1 - Cross Site Scripting (XSS) vulnera…
CVE-2026-576737.18.5OptimoleOptimoleCWE-79WordPress Optimole plugin <= 4.2.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576747.18.5ArrayticsTimeticsCWE-79WordPress Timetics plugin <= 1.0.58 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576757.18.5Jacob N. BreetveltWP Photo Album PlusCWE-79WordPress WP Photo Album Plus plugin <= 9.2.02.004 - Cross Site Scripting (XS…
CVE-2026-576827.18.5QuantumCloudSimple Link DirectoryCWE-79WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS)…
CVE-2026-576867.18.5WPXPOWowAddonsCWE-79WordPress WowAddons plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability
CVE-2026-80798.78.0Progress SoftwareFlowmonCWE-863Unintended limited set of actions with elevated privileges may be performed d…
CVE-2026-585795.18.0infiniflowragflowCWE-79RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name
CVE-2026-389727.87.9n/an/aCWE-427Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerabili…
CVE-2026-591002.37.9lobehublobehubCWE-639LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Opera…
CVE-2026-577505.37.7Keksdiebez Form Calculator PremiumCWE-862WordPress ez Form Calculator Premium plugin <= 2.14.1.2 - Broken Access Contr…
CVE-2026-577605.37.7SendcloudSendcloud ShippingCWE-862WordPress Sendcloud Shipping plugin <= 1.0.29 - Broken Access Control vulnera…
CVE-2025-691527.17.2ThemeGoodsArtale | Wedding Photography WordPressCWE-79WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site …
CVE-2025-691537.17.2designthemesTrendy TravelCWE-79WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) v…
CVE-2025-691547.17.2designthemesSpaLab | Beauty Salon WordPress ThemeCWE-79WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scr…
CVE-2025-691557.17.2DesignthemesFitness Zone WordPress ThemeCWE-79WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (X…
CVE-2025-691567.17.2Design themesKids Zone - Children WordPress ThemeCWE-79WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scri…
CVE-2026-274027.17.2DesignthemesKids Life | Children School WordPressCWE-79WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scr…
CVE-2026-274047.17.3DesignthemesLMSCWE-79WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability
CVE-2026-274087.17.3imithemesNativeChurchCWE-79WordPress NativeChurch theme <= 4.8.8.2 - Reflected Cross Site Scripting (XSS…
CVE-2026-274257.17.3ThemesuiteAutomotive ListingsCWE-79WordPress Automotive Listings plugin <= 18.6 - Reflected Cross Site Scripting…
CVE-2026-121677.86.8Little OrbitGameFirst Anti-CheatCVE-2026-12167
CVE-2026-133734.86.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpa…
CVE-2026-133744.86.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Connect…
CVE-2026-133754.86.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotas…
CVE-2026-133764.86.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlo…
CVE-2026-133774.86.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Pro…
CVE-2026-115782.76.6UnknownFluent FormsFluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via…
CVE-2026-576846.56.3tranmautritamTheFoxCWE-79WordPress TheFox theme <= 3.9.70 - Cross Site Scripting (XSS) vulnerability
CVE-2026-119656.56.1UnknownUser Registration & MembershipUser Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass
CVE-2026-121687.86.0Little OrbitGameFirst Anti-CheatCVE-2026-12168
CVE-2026-586535.35.5PraisonAIPraisonAICWE-639PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/U…
CVE-2026-585806.05.1lobehublobehubCWE-639LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Wr…
CVE-2026-576787.14.8ThemePunchSlider RevolutionCWE-79WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) …
CVE-2026-551106.14.5Ubiquiti IncUniFi OS ServerCWE-942A malicious actor who lures an authenticated user to a malicious page could e…
CVE-2026-137285.94.5WatchGuardFireware OSCWE-798WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resourc…
CVE-2026-84824.34.3StormshieldStormshield Network SecurityCWE-532Information leak in NSRPC client history
CVE-2026-577625.94.2Andrew FiebertSimple URLsCWE-79WordPress Simple URLs plugin <= 151 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577598.84.0MetagaussProfileGridCWE-352WordPress ProfileGrid plugin <= 5.9.9.7 - CSRF to Account Takeover vulnerability
CVE-2026-577668.84.0XplodedThemesWPIDE – File Manager & Code EditorCWE-352WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.6 - Cross Site Req…
CVE-2026-130797.33.9WatchGuardMobile VPN with SSL ClientCWE-732WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation
CVE-2026-577518.13.8Heateor SupportHeateor Social LoginCWE-352WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery …
CVE-2026-584607.03.7ajith-abreact-native-receive-sharing-intentCWE-22react-native-receive-sharing-intent Path Traversal via _display_name
CVE-2026-577546.53.4LivemeshLivemesh Addons for WPBakery Page BuilderCWE-79WordPress Livemesh Addons for WPBakery Page Builder plugin <= 3.9.4 - Cross S…
CVE-2026-577556.53.4Misbah WPMosaic Gallery &#8211; Advanced GalleryCWE-79WordPress Mosaic Gallery &#8211; Advanced Gallery plugin <= 1.2.0 - Cross Sit…
CVE-2026-577636.53.4Gordon BöhmeStructured ContentCWE-79WordPress Structured Content plugin <= 1.7.0 - Cross Site Scripting (XSS) vul…
CVE-2026-577646.53.4SurbmaSurbma | Yoast SEO Breadcrumb ShortcodeCWE-79WordPress Surbma | Yoast SEO Breadcrumb Shortcode plugin <= 1.2 - Cross Site …
CVE-2026-548916.33.4ErlangOTPCWE-924Plaintext APPLICATION_DATA injected during TLS handshake delivered to client …
CVE-2026-47725.43.3TR7 Cyber ​​Defense Inc.WAF-ASPCWE-79Stored XSS in TR7's WAF-ASP
CVE-2026-47704.63.3TR7 Cyber ​​Defense Inc.WAF-ASPCWE-79DOM-Based XSS in TR7's WAF-ASP
CVE-2026-544315.12.9OpenIDCliboauth2CWE-358Improper Data Validation in liboauth2
CVE-2026-577476.52.5ThemeREXBookedCWE-352WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerab…
CVE-2026-544305.12.3OpenIDCliboauth2CWE-918Server-Site Request Forgery in liboauth2
CVE-2026-583816.12.0Red HatRed Hat Enterprise Linux 6CWE-415Gimp: gimp: double-free in read_layer_block()
CVE-2026-577577.11.8ploudapppCloud WP BackupCWE-352WordPress pCloud WP Backup plugin <= 2.0.2 - Cross Site Request Forgery (CSRF…
CVE-2026-137433.31.9CubeSpaceCW0057 Reaction WheelCWE-347Improper verification of cryptographic signature in CubeSpace CW0057 Reaction…
CVE-2026-576904.31.2FuelthemesWerkstattCWE-352WordPress Werkstatt theme <= 4.7.2 - Cross Site Request Forgery (CSRF) vulner…
CVE-2026-577587.10.7BeRocketPermalink Manager for WooCommerceCWE-352WordPress Permalink Manager for WooCommerce plugin <= 1.0.8.2 - CSRF to Store…
CVE-2026-577617.10.7BlueAstralThemesSEOWPCWE-352WordPress SEOWP theme <= 3.12.2 - CSRF to Stored XSS vulnerability

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-02 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.