boxscore/security
Friday, July 3, 2026 · all times UTC← 2026-07-02 · archive · 2026-07-04 →

180 CVEs published July 3, 2026: 25 critical, 77 high, 70 medium, 8 low; 0 in KEV; 19 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 155 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published8101312812202563
KEV catalog size1670

569 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux33151312086252812730.27.5.0013-1
google521316148586542377460.57.8.0023-9
microsoft50761585061764378283.77.8.0044+49
red hat1520712841029400.06.5.0026+10
apple0991236629377.16.5.00310
canonical0202585000.05.5.00110
freebsd01601240000.07.8.00150
suse2154830000.08.8.0036+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+25
cisco83141280961135.57.5.0056+6
netgear01700161800.04.3.00240
palo alto networks011017114218.24.8.00220
checkpoint0915303111.17.5.04100
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-1
fortinet08132028337.57.3.00660
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache5158246162104010.67.3.0048-26
mozilla25812182801300.07.3.0025-2
gitlab03305215426.14.4.00220
github171150000.06.0.0026+1
docker070520100.08.2.0016-1
drupal0511305120.05.1.00260
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-1
adobe014611527827532.15.5.00210
ibm01243642460700.07.5.0025-5
progress2111910900.07.5.0035-3
solarwinds07122011457.17.5.0835-1
veeam042200400.09.0.00460
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link01305252617.75.8.0059-2
siemens090450100.06.9.0019-1
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4
schneider electric060420100.07.8.00240
moxa050320000.07.0.00290
dahua030111200.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell2076134382211.36.7.0016+18
sourcecodester273003637000.02.9.0026-16
spring073231391000.06.5.0024-2
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00590
capgo061231271000.07.1.00310
themerex26055410000.08.1.0043+2
nvidia1756113870000.07.8.0019+15

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
CVE-2026-4827610.0.0505
CVE-2026-1377310.0.0341
CVE-2026-5641310.0.0316
CVE-2026-5641510.0.0315
Most disclosures (vendor)
VendorCVEs
google1081
linux513
microsoft270
oracle242
adobe142
red hat138
apache95
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven39
Packagist15
npm6
NuGet3
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171689
CVE-2021-27102Accellion2021-11-171689
CVE-2021-27101Accellion2021-11-171689
CVE-2021-27103Accellion2021-11-171689
CVE-2021-21017Adobe2021-11-171689
CVE-2021-28550Adobe2021-11-171689
CVE-2021-42013Apache2021-11-171689
CVE-2021-41773Apache2021-11-171689
CVE-2021-30858Apple2021-11-171689
CVE-2021-30860Apple2021-11-171689

Transactions

EXPLOIT PUBLISHEDCVE-2026-10536 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11352 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11564 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11586 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11856 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-12064 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-12481 (keras-team/keras). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8286 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8458 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8924 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8925 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8926 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8927 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8932 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-9079 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-9080 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-9545 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-9546 (curl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-9547 (curl). Public exploit reference added.

DUE DATE PASSEDCVE-2026-48558 (SimpleHelp). CISA remediation deadline was July 2, 2026; still in catalog.

Yesterday's Results

180 CVEs published. 25 box scores, 155 table rows — nothing truncated.

Gitea Composer package source links use insufficient permission checks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  L  N    8.2   .4307   98.6     —
AFFECTED
  Product                       Versions     Fixed
  Gitea Open Source Git Server  unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 3   Published (CNA: Gitea)
CWE-862 · CNA: Gitea · 4 references · NVD status: Deferred
Gitea Docker image trusts spoofable reverse-proxy headers by default
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .3181   98.2     —
AFFECTED
  Product                       Versions     Fixed
  Gitea Open Source Git Server  unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 3   Published (CNA: Gitea)
CWE-284 · CNA: Gitea · 4 references · NVD status: Deferred
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  H  H    8.3   .0177   76.2     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-843 · CNA: microsoft · 1 reference · NVD status: Analyzed
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0122   66.0     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Jun 1   Reserved by CNA
  Jul 3   Published (CNA: dell)
CWE-78 · CNA: dell · 1 reference · NVD status: Analyzed
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0122   66.0     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 3   Published (CNA: dell)
CWE-78 · CNA: dell · 1 reference · NVD status: Analyzed
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0110   62.8     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Jun 1   Reserved by CNA
  Jul 3   Published (CNA: dell)
CWE-78 · CNA: dell · 1 reference · NVD status: Analyzed
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  H  H    6.5   .0105   61.5     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Feb 13  Reserved by CNA
  Jul 3   Published (CNA: dell)
CWE-78 · CNA: dell · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Hplip: incomplete fix for cve-2026-8631
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0086   55.6     —
AFFECTED
  Product                      Versions     Fixed
  Red Hat Enterprise Linux 10  unspecified  0:3.23.12-10.el10_2.5
  Red Hat Enterprise Linux 8   unspecified  0:3.18.4-14.el8_10
  Red Hat Enterprise Linux 9   unspecified  0:3.21.2-6.el9_8.5
  Red Hat Enterprise Linux 6   unspecified  —
  Red Hat Enterprise Linux 7   unspecified  —
TIMELINE
  Jul 3   Reserved by CNA
  Jul 3   Published (CNA: redhat)
CWE-190 · CNA: redhat · 5 references · NVD status: Awaiting Analysis
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  N  N    7.4   .0075   51.8     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-59 · CNA: microsoft · 1 reference · NVD status: Analyzed
Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0074   51.7     —
AFFECTED
  Product                                                  Versions     Fixed
  Printcart Web to Print Product Designer for WooCommerce  unspecified  —
TIMELINE
  May 27  Reserved by CNA
  Jul 3   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 6 references · NVD status: Deferred
Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   N   N    8.9   .0072   51.0     —
AFFECTED
  Product            Versions           Fixed
  Apache Lucene.Net  4.8.0-beta00005 –  —
TIMELINE
  May 20  Reserved by CNA
  Jul 3   Published (CNA: apache)
CWE-22 · CNA: apache · 2 references · NVD status: Analyzed
Microsoft Edge (Chromium-based) Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  N  N    6.5   .0065   48.3     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-200 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Edge (Chromium-based) Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  N  H  N    7.4   .0063   47.1     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Edge (Chromium-based) Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  N  N    6.5   .0062   46.7     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  U  H  H  H    7.5   .0061   46.2     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-416 · CNA: microsoft · 1 reference · NVD status: Analyzed
Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   N   N    8.9   .0060   46.1     —
AFFECTED
  Product            Versions           Fixed
  Apache Lucene.Net  4.8.0-beta00005 –  —
TIMELINE
  May 20  Reserved by CNA
  Jul 3   Published (CNA: apache)
CWE-22 · CNA: apache · 2 references · NVD status: Analyzed
curl curl — cross-origin Digest auth state leak
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0060   46.1     —
AFFECTED
  Product  Versions  Fixed
  curl     8.20.0 –  —
TIMELINE
  Jun 10  Reserved by CNA
  Jul 3   Public exploit reference published
  Jul 3   Published (CNA: curl)
CWE-294 · CNA: curl · 3 references · NVD status: Analyzed
curl curl — SASL double-free
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0059   45.5     —
AFFECTED
  Product  Versions  Fixed
  curl     8.20.0 –  —
TIMELINE
  May 19  Reserved by CNA
  Jul 3   Public exploit reference published
  Jul 3   Published (CNA: curl)
CWE-415 · CNA: curl · 3 references · NVD status: Analyzed
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  N  N    6.1   .0059   45.3     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-672 · CNA: microsoft · 1 reference · NVD status: Analyzed
curl curl — stale proxy password leak
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0058   45.1     —
AFFECTED
  Product  Versions  Fixed
  curl     8.20.0 –  —
TIMELINE
  May 20  Reserved by CNA
  Jul 3   Public exploit reference published
  Jul 3   Published (CNA: curl)
CWE-522 · CNA: curl · 3 references · NVD status: Analyzed
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0058   44.8     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-190 · CNA: microsoft · 1 reference · NVD status: Analyzed
curl curl — QUIC zero-length UDP datagrams busy-loop
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0058   44.8     —
AFFECTED
  Product  Versions  Fixed
  curl     8.20.0 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jul 3   Public exploit reference published
  Jul 3   Published (CNA: curl)
CWE-835 · CNA: curl · 3 references · NVD status: Analyzed
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0057   44.4     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-416 · CNA: microsoft · 1 reference · NVD status: Analyzed
Gitea pre-receive hook permission cache allows full repository write access
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0057   44.4     —
AFFECTED
  Product                       Versions  Fixed
  Gitea Open Source Git Server  1.25.5 –  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 3   Published (CNA: Gitea)
CWE-863 · CNA: Gitea · 4 references · NVD status: Deferred
Gitea Basic Auth bypasses OAuth2 access token scopes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0057   44.3     —
AFFECTED
  Product                       Versions     Fixed
  Gitea Open Source Git Server  unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 3   Published (CNA: Gitea)
CWE-284, CWE-863 · CNA: Gitea · 4 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-89249.144.0curlcurltrailing dot domain super cookie
CVE-2026-566458.843.7MicrosoftMicrosoft Edge (Chromium-based)CWE-122Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-228749.643.6GiteaGitea Open Source Git ServerCWE-918Gitea webhook and migration allow-list filtering permits SSRF
CVE-2026-560159.142.7TPODERNet::IP::LPMCWE-125Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read v…
CVE-2026-579887.142.5MicrosoftMicrosoft Edge (Chromium-based)CWE-23Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-146204.742.0webpack-dev-serverwebpack-dev-serverCWE-352webpack-dev-server vulnerable to cross-site request forgery via internal deve…
CVE-2026-105369.841.0curlcurlCWE-416HTTP/2 stream-dependency tree UAF
CVE-2026-207069.140.1GiteaGitea Open Source Git ServerCWE-284Gitea repository archive downloads bypass token scope checks
CVE-2026-115867.540.1curlcurlCWE-770WS Auto-PONG memory exhaustion
CVE-2026-262929.839.5GiteaGitea Open Source Git ServerCWE-284Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions
CVE-2026-579858.839.3MicrosoftMicrosoft Edge (Chromium-based)CWE-20Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-454896.539.0MicrosoftMicrosoft Edge (Chromium-based)CWE-749Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-585236.539.0MicrosoftMicrosoft Edge (Chromium-based)CWE-284Microsoft Edge for Android Security Feature Bypass Vulnerability
CVE-2026-143527.538.9webandprintAR for WooCommerceCWE-22AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File…
CVE-2026-5798310.038.8MicrosoftMicrosoft Edge (Chromium-based)CWE-285Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-277809.838.8GiteaGitea Open Source Git ServerCWE-863Gitea pre-receive hook can miss branch-protection checks after scanner errors
CVE-2026-124819.838.5keras-teamkeras-team/kerasCWE-502Deserialization of Untrusted Data in keras-team/keras
CVE-2026-263077.538.4GiteaGitea Open Source Git ServerCWE-400Gitea git grep search lacks a timeout
CVE-2026-498136.738.0DellPowerProtect Data DomainCWE-78Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-143277.538.0webandprintAR for WordPressCWE-22AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Par…
CVE-2026-582858.337.7MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-582878.337.7MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-544836.737.4DellPowerProtect Data DomainCWE-78Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-579757.537.0MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-89279.136.6curlcurlCWE-294env-set cross-proxy Digest auth state leak
CVE-2026-582888.336.5MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-582937.536.5MicrosoftMicrosoft Edge (Chromium-based)CWE-73Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-277797.535.9GiteaGitea Open Source Git ServerCWE-284Gitea forwarded-proto handling allows public URL spoofing
CVE-2026-579847.535.8MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-579867.535.8MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-582767.535.8MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-257189.135.7GiteaGitea Open Source Git ServerCWE-59Gitea template repository generation mishandles symlinked paths
CVE-2026-250387.535.4GiteaGitea Open Source Git ServerCWE-200Gitea private organization labels are visible to unauthorized users
CVE-2026-464644.935.2DellPowerProtect Data DomainCWE-59Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-582848.335.1MicrosoftMicrosoft Edge (Chromium-based)CWE-285Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-579777.134.4MicrosoftMicrosoft Edge (Chromium-based)CWE-79Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-146315.333.7webpack-dev-serverwebpack-dev-serverCWE-20webpack-dev-server vulnerable to denial of service via a malformed Host or Or…
CVE-2026-49677.533.6Unisoc (Shanghai) Technologies Co., Ltd.SC7731E/SC9832E/SC9863A/T310/T610/T618/T7200/T7225/T7250/T7255/T7280/T7300/T8100/T9100/T8200/T8300In IMS, there is a possible out of bounds read due to a missing bounds check.…
CVE-2026-592346.933.5RoskusProspero Flow CRMCWE-639Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calenda…
CVE-2026-95467.533.1curlcurlsending old referer
CVE-2026-207797.133.0GiteaGitea Open Source Git ServerCWE-294Gitea TOTP single-use enforcement defect allows OTP replay
CVE-2026-585974.333.0MicrosoftMicrosoft Edge (Chromium-based)CWE-357Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-89327.532.8curlcurlincomplete mTLS config matching in conn reuse
CVE-2026-262329.131.0GiteaGitea Open Source Git ServerCWE-294Gitea OAuth2 authorization codes lack expiry and reuse enforcement
CVE-2026-262479.131.0GiteaGitea Open Source Git ServerCWE-284Gitea OAuth2 PKCE S256 challenges are not enforced during token exchange
CVE-2026-89269.130.8curlcurlCWE-522password leak with netrc and user in URL
CVE-2026-225479.130.4GiteaGitea Open Source Git ServerCWE-20Gitea repository creation accepts invalid field values
CVE-2026-582958.330.3MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-287055.329.9GiteaGitea Open Source Git ServerCWE-22Gitea repository dumps write release assets using unsafe path names
CVE-2026-277614.329.6GiteaGitea Open Source Git ServerCWE-863Gitea repository feeds bypass API token scope enforcement
CVE-2026-115649.129.4curlcurlCWE-295Native CA trust persist
CVE-2026-244517.528.4GiteaGitea Open Source Git ServerCWE-200Gitea fork synchronization can expose private parent repository data
CVE-2026-257127.528.4GiteaGitea Open Source Git ServerCWE-284Gitea organization permission APIs expose private visibility information
CVE-2026-478984.027.9Apache Software FoundationApache Lucene.NetCWE-611Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser
CVE-2026-276577.527.5GiteaGitea Open Source Git ServerCWE-639Gitea email settings allow changing another user's primary email address
CVE-2026-276607.527.5GiteaGitea Open Source Git ServerCWE-284Gitea draft releases use insufficient permission checks
CVE-2026-287448.127.3GiteaGitea Open Source Git ServerCWE-863Gitea Git smart HTTP bypasses repository token scopes for bearer tokens
CVE-2026-582836.927.2MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-91805.327.2jetmonstersMotoPress Appointment BookingCWE-639MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Obje…
CVE-2026-582947.527.0MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-584229.826.8GiteaGitea Open Source Git ServerCWE-284Improper authorization on OAuth sign-in callback silently re-enables administ…
CVE-2026-120647.526.8curlcurlCWE-295proto-default skips SSH verification
CVE-2026-287378.726.6GiteaGitea Open Source Git ServerCWE-79Gitea 3D file viewer allows stored XSS through glTF extensionsRequired
CVE-2026-583005.526.7MicrosoftMicrosoft Edge (Chromium-based)CWE-36Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-257144.326.1GiteaGitea Open Source Git ServerCWE-862Gitea user organization API bypasses public-only token filtering
CVE-2026-584217.525.5GiteaGitea Open Source Git ServerCWE-284Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-95477.425.4curlcurlSSH improper host validation
CVE-2026-582826.925.2MicrosoftMicrosoft Edge (Chromium-based)CWE-284Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-582866.925.2MicrosoftMicrosoft Edge (Chromium-based)CWE-284Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-585225.525.1MicrosoftMicrosoft Edge (Chromium-based)CWE-23Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-113985.325.1latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-862LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Custo…
CVE-2026-246907.525.0GiteaGitea Open Source Git ServerCWE-284Gitea pull-request branch updates use insufficient permission checks
CVE-2026-146092.924.9SourceCodesterCET Automated Grading System with AI Predictive AnalyticsCWE-384SourceCodester CET Automated Grading System with AI Predictive Analytics sess…
CVE-2026-146152.724.4Red HatRed Hat build of Keycloak 26.4CWE-1220Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses …
CVE-2026-84586.524.2curlcurlwrong reuse for different services
CVE-2026-584237.723.8GiteaGitea Open Source Git ServerCWE-287LFS authentication bypass via malformed SSH sub-verb allows unauthorized read…
CVE-2026-82868.123.6curlcurlCWE-295wrong STARTTLS connection reuse
CVE-2026-582977.123.5MicrosoftMicrosoft Edge (Chromium-based)CWE-359Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-225558.123.1GiteaGitea Open Source Git ServerCWE-284Gitea organization forks can expose organization secrets without create permi…
CVE-2026-130407.223.0webawaysNEX-Forms – Ultimate Forms Plugin for WordPressCWE-79NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_va…
CVE-2026-582967.122.9MicrosoftMicrosoft Edge (Chromium-based)CWE-359Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-92304.322.4expresstechQuiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-862Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticat…
CVE-2026-584197.522.4GiteaGitea Open Source Git ServerCWE-200Notification API leaks private issue metadata after access revocation
CVE-2026-100558.522.2Eclipse FoundationEclipse TheiaCWE-200In Eclipse Theia since version 1.26.0, the backend /services/request-service …
CVE-2026-90807.322.1curlcurlCWE-416UAF after pause in socket callback
CVE-2026-91487.221.8advancedcodingComments – wpDiscuzCWE-79Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website…
CVE-2026-129204.921.7wplegalpagesCookie Banner for GDPR / CCPA – WPLP Cookie ConsentCWE-89Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL I…
CVE-2026-262318.521.7GiteaGitea Open Source Git ServerCWE-863Gitea maintainer-edit permissions allow unauthorized commits to readable repo…
CVE-2026-209095.321.1GiteaGitea Open Source Git ServerCWE-284Gitea tracked-time list endpoint has insufficient permission checks
CVE-2026-257825.321.1GiteaGitea Open Source Git ServerCWE-639Gitea tracked-time deletion can target entries from another issue
CVE-2026-277834.320.9GiteaGitea Open Source Git ServerCWE-862Gitea issue-template APIs bypass repository unit authorization
CVE-2026-582785.420.7MicrosoftMicrosoft Edge (Chromium-based)CWE-918Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-582927.520.4MicrosoftMicrosoft Edge (Chromium-based)CWE-20Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-143555.320.4phpphpCWE-122ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
CVE-2026-582997.519.2MicrosoftMicrosoft Edge (Chromium-based)CWE-367Microsoft Edge for Android Remote Code Execution Vulnerability
CVE-2026-95457.519.0curlcurlexposing HTTP/3 early data
CVE-2026-287407.118.9GiteaGitea Open Source Git ServerCWE-639Gitea LFS object reuse bypasses Code-unit authorization
CVE-2026-119004.318.9spacetimeAd Inserter – Ad Manager & AdSense AdsCWE-639Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Co…
CVE-2026-43219.818.5Raera - Ankara Web Design and Digital Advertising AgencyDestekzCWE-89SQLi in Raera's Destekz
CVE-2026-51374.318.6romethemeRTMKitCWE-98RTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion v…
CVE-2026-133417.417.7KongHQmcp-konnectCWE-20Prompt Injection and Credential Exposure via Untrusted Analytics Data in Kong…
CVE-2026-146115.316.9DeepMystMystiCWE-200DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exp…
CVE-2026-117785.416.6villathemeCURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.xCWE-94CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange…
CVE-2026-582907.516.6MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-454885.916.5MicrosoftMicrosoft Edge (Chromium-based)CWE-451Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-257796.116.3GiteaGitea Open Source Git ServerCWE-601Gitea redirect handling permits open redirects through backslash paths
CVE-2026-584186.515.8GiteaGitea Open Source Git ServerCWE-918SSRF via HTTP Redirect in Repository Migration
CVE-2026-464636.515.7DellPowerProtect Data DomainCWE-190Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-582986.115.3MicrosoftMicrosoft Edge (Chromium-based)CWE-79Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-585246.115.3MicrosoftMicrosoft Edge (Chromium-based)CWE-79Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-464655.515.0DellPowerProtect Data DomainCWE-134Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-146171.314.9NousResearchhermes-agentCWE-178NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py G…
CVE-2026-84896.414.6ultimatememberUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-79Ultimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scr…
CVE-2026-583797.314.4Red HatRed Hat Enterprise Linux 9CWE-122Gimp: gimp: heap buffer overflow in read_channel_data()
CVE-2026-146042.114.5Open Asset Import LibraryAssimpCWE-119Open Asset Import Library Assimp PLY Model PlyLoader.cpp ExportToBlob double …
CVE-2026-83516.413.8romethemeRTMKitCWE-79RTMKit <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…
CVE-2026-113975.513.8vjinfotechWP Import Export LiteCWE-918WP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side …
CVE-2026-125575.313.1SaturdayDriveNinja Forms - File UploadsCWE-862Ninja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticat…
CVE-2026-146082.113.1SourceCodesterCET Automated Grading System with AI Predictive AnalyticsCWE-285SourceCodester CET Automated Grading System with AI Predictive Analytics POST…
CVE-2026-96266.412.9parorreyJSON API UserCWE-79JSON API User <= 4.1.0 - Authenticated (Subscriber+) Stored Cross-Site Script…
CVE-2026-127294.311.8wedevsweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI ChatbotCWE-862weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= …
CVE-2026-88926.411.0creativemindssolutionsCM Business Directory – Optimise and showcase local businessCWE-79CM Business Directory <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Si…
CVE-2026-584248.910.4GiteaGitea Open Source Git ServerCWE-285Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-97566.410.1edge22GenerateBlocksCWE-79GenerateBlocks <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-127316.410.2wedevsweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI ChatbotCWE-79weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= …
CVE-2026-127346.410.2wedevsweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI ChatbotCWE-79weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= …
CVE-2026-144598.89.9TUBITAK BILGEM Software Technologies Research Institutepardus-softwareCWE-88Argument Injection in TUBITAK BILGEM's pardus-software
CVE-2026-584269.68.7GiteaGitea Open Source Git ServerCWE-347Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository …
CVE-2026-351595.38.6DellInspiron 15 3520CWE-305Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakne…
CVE-2026-146145.48.4Red HatRed Hat build of Keycloak 26.4CWE-639Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass …
CVE-2026-146134.97.9Red HatRed Hat build of Keycloak 26.6CWE-284Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint …
CVE-2026-48046.47.6themegrillZakraCWE-79Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…
CVE-2026-144608.86.0TUBITAK BILGEM Software Technologies Research Institutepardus-softwareCWE-862Missing Authorization in TUBITAK BILGEM's pardus-software
CVE-2026-100548.85.6Eclipse FoundationEclipse TheiaCWE-306In affected versions of Eclipse Theia (1.8.1 and later), the browser backend …
CVE-2026-411234.34.9DellPowerProtect Data DomainCWE-284Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-43226.14.6Raera - Ankara Web Design and Digital Advertising AgencyDestekzCWE-79XSS in Raera's Destekz
CVE-2026-559454.24.2MicrosoftMicrosoft Edge (Chromium-based)CWE-362Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-146124.24.0Red HatRed Hat Enterprise Linux 10CWE-787Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c …
CVE-2026-146057.13.9n/aRT-ThreadCWE-119RT-Thread ls1c CAN ls1c_can.h recvmsg stack-based overflow
CVE-2026-146067.13.9n/aRT-ThreadCWE-119RT-Thread SWM341 CAN SWM341.h CAN_Receive stack-based overflow
CVE-2026-442694.43.3DellPowerProtect Data DomainCWE-59Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-464684.43.3DellPowerProtect Data DomainCWE-59Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-146101.92.8Open Asset Import LibraryAssimpCWE-119Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile heap-b…
CVE-2026-411244.42.8DellPowerProtect Data DomainCWE-22Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-89218.52.5ASUSASUS Business ManagerCWE-73External Control of File Name or Path vulnerability in ASUS Business Manager …
CVE-2026-129606.02.0ASUSRouter appCWE-926An Improper Export of Android Application Components vulnerability in ASUS Ro…
CVE-2026-146075.42.1n/aRT-ThreadCWE-119RT-Thread lwp_syscall.c sys_getaddrinfo memory corruption
CVE-2026-467304.21.9DellPowerProtect Data DomainCWE-863Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-464662.71.4DellPowerProtect Data DomainCWE-348Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-442684.41.2DellPowerProtect Data DomainCWE-732Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2022-49898.51.1ASUSAI Suite 3CWE-1284** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in …
CVE-2022-49907.30.8ASUSAI Suite 3CWE-1284** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in …
CVE-2026-560853.30.8DellPowerProtect Data DomainCWE-908Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-464675.80.4DellPowerProtect Data DomainCWE-532Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-88046.70.2PerforcePuppet CoreCWE-312Cleartext Storage of Sensitive Information for Puppet Resource API

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-03 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.