86 CVEs published July 5, 2026: 1 critical, 6 high, 44 medium, 35 low; 0 in KEV; 7 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 61 in the results table.
Yesterday's Results
86 CVEs published. 25 box scores, 61 table rows — nothing truncated.
zhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authentication
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N N L L 5.5 .0046 38.2 —
AFFECTED
Product Versions Fixed
chatgpt-on-wechat CowAgent 2.1.0 – 2.1.1
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
UTT HiPER 1250GW Web Endpoint ConfigWirelessBase_5g stack-based overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0045 37.2 —
AFFECTED
Product Versions Fixed
HiPER 1250GW 3.2.7-210907-180535 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
ail-project ail-framework — Authenticated Path Traversal in AIL Framework PDF Object Handling Enables Potential Arbitrary File Read
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H N N 7.1 .0037 30.4 —
AFFECTED
Product Versions Fixed
ail-framework unspecified —
TIMELINE
Jul 5 Reserved by CNA
Jul 5 Published (CNA: CIRCL)
cve-search cve-search — Unauthenticated arbitrary MongoDB collection read in cve-search
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H N N 9.2 .0035 28.0 —
AFFECTED
Product Versions Fixed
cve-search v4.0 – —
TIMELINE
Jul 5 Reserved by CNA
Jul 5 Published (CNA: CIRCL)
NousResearch hermes-agent skills_tool.py skill_view path traversal
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L N N 2.1 .0033 26.2 —
AFFECTED
Product Versions Fixed
hermes-agent 2026.5.29.2 – —
TIMELINE
Jul 5 Reserved by CNA
Jul 5 Published (CNA: VulDB)
666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N N L N 5.5 .0033 26.1 —
AFFECTED
Product Versions Fixed
BettaFish 1.2.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
code-projects Hotel and Tourism Reservation Room Management rooms.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0032 25.3 —
AFFECTED
Product Versions Fixed
Hotel and Tourism Reservation 1.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0032 25.0 —
AFFECTED
Product Versions Fixed
TidGi-Desktop 0.1 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
mjperpinosa stumasy calculate.php eval code injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0032 25.0 —
AFFECTED
Product Versions Fixed
stumasy 327d1b0f2915ba79d7ef8ebb74553e987609d9be – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
TIMLEGGE Crypt::DSA — Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N N 7.5 .0032 24.2 —
AFFECTED
Product Versions Fixed
Crypt::DSA unspecified —
TIMELINE
Jul 3 Reserved by CNA
Jul 5 Published (CNA: CPANSec)
mjperpinosa stumasy Note Handler/Assignment notes authorization
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0031 23.5 —
AFFECTED
Product Versions Fixed
stumasy 327d1b0f2915ba79d7ef8ebb74553e987609d9be – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
SourceCodester Multi-Vendor Online Grocery Management System Users.php save_users improper authorization
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0029 21.9 —
AFFECTED
Product Versions Fixed
Multi-Vendor Online Grocery Management System 1.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0029 21.9 —
AFFECTED
Product Versions Fixed
Onlne Examination & Learning Management System 1.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0029 21.9 —
AFFECTED
Product Versions Fixed
Onlne Examination & Learning Management System 1.0 – —
TIMELINE
Jul 5 Reserved by CNA
Jul 5 Published (CNA: VulDB)
stephen-kruger bluebox cross site scripting
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N P N L N 2.1 .0029 21.2 —
AFFECTED
Product Versions Fixed
bluebox 4.5.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
zephyrproject zephyr — Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N L 5.3 .0029 21.0 —
AFFECTED
Product Versions Fixed
zephyr 1.10.0 – —
TIMELINE
Jun 2 Reserved by CNA
Jul 5 Public exploit reference published
Jul 5 Published (CNA: zephyr)
SourceCodester Class and Exam Timetabling System edit_exam.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0028 20.9 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
SourceCodester Class and Exam Timetabling System edit_coursea.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0028 20.9 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
SourceCodester Class and Exam Timetabling System edit_product.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0028 20.9 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
Ruijie RG-UAC user_auth_commit.php unrestricted upload
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0028 20.9 —
AFFECTED
Product Versions Fixed
RG-UAC 1.0-R1.8.2.p5 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
SourceCodester Class and Exam Timetabling System edit_room.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0028 20.9 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jul 5 Reserved by CNA
Jul 5 Published (CNA: VulDB)
SourceCodester Class and Exam Timetabling System edit_exam1.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0028 20.9 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jul 5 Reserved by CNA
Jul 5 Published (CNA: VulDB)
SourceCodester Class and Exam Timetabling System edit_course1.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0028 20.9 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jul 5 Reserved by CNA
Jul 5 Published (CNA: VulDB)
itsourcecode Online Hotel Management System login.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0028 20.5 —
AFFECTED
Product Versions Fixed
Online Hotel Management System 1.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
code-projects Real State Services addprojectsale.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 6.9 .0027 19.1 —
AFFECTED
Product Versions Fixed
Real State Services 1.0 – —
TIMELINE
Jul 4 Reserved by CNA
Jul 5 Published (CNA: VulDB)
Remainder (ranked, continued)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
| CVE-2026-14700 | 5.5 | 19.1 | code-projects | Internship Management System | CWE-74 | code-projects Internship Management System Employer Login Endpoint login.php … |
| CVE-2026-14705 | 5.5 | 19.1 | code-projects | Online Examination | CWE-74 | code-projects Online Examination head.php sql injection |
| CVE-2026-14713 | 5.5 | 19.1 | SourceCodester | Pizzafy E-Commerce System | CWE-74 | SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection |
| CVE-2026-14735 | 5.5 | 19.1 | code-projects | Smart Parking System | CWE-74 | code-projects Smart Parking System parkings.php sql injection |
| CVE-2026-14746 | 5.5 | 19.1 | code-projects | Real State Services | CWE-74 | code-projects Real State Services addprojectrent.php sql injection |
| CVE-2026-14750 | 5.5 | 19.1 | mjperpinosa | stumasy | CWE-74 | mjperpinosa stumasy accessing_dictionary_authorization.php accessing_dictiona… |
| CVE-2026-14754 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation add_room.php sql injection |
| CVE-2026-14755 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation Reservations Management reservati… |
| CVE-2026-14756 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation Tour Management add_tour.php sql … |
| CVE-2026-14763 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation Tour Reservations tour_reserves.p… |
| CVE-2026-14764 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation Event Management add_event.php sq… |
| CVE-2026-14768 | 5.5 | 19.1 | code-projects | Real State Services | CWE-74 | code-projects Real State Services builderHome.php sql injection |
| CVE-2026-14769 | 5.5 | 19.1 | code-projects | Real State Services | CWE-74 | code-projects Real State Services pay.php sql injection |
| CVE-2026-14695 | 5.5 | 18.2 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-74 | SourceCodester Multi-Vendor Online Grocery Management System Registration Use… |
| CVE-2026-14743 | 5.5 | 18.2 | code-projects | Real State Services | CWE-74 | code-projects Real State Services normalHomeSale.php sql injection |
| CVE-2026-14744 | 5.5 | 18.2 | code-projects | Real State Services | CWE-74 | code-projects Real State Services normalHomeRent.php sql injection |
| CVE-2026-14745 | 5.5 | 18.2 | code-projects | Real State Services | CWE-74 | code-projects Real State Services single-list_rent.php sql injection |
| CVE-2026-14737 | 5.5 | 17.8 | Hanwang | e-Face General Management Platform | CWE-74 | Hanwang e-Face General Management Platform querySysAuthStr.do sql injection |
| CVE-2026-10656 | 4.6 | 17.2 | zephyrproject | zephyr | CWE-476 | NULL-pointer dereference DoS in MAX32 USB device controller transfer-completi… |
| CVE-2026-14716 | 2.1 | 16.1 | nextlevelbuilder | GoClaw | CWE-285 | nextlevelbuilder GoClaw WebSocket RPC router.go MethodRouter.Handle authoriza… |
| CVE-2026-14691 | 2.1 | 15.6 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-74 | SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSe… |
| CVE-2026-14693 | 2.1 | 14.6 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-266 | SourceCodester Multi-Vendor Online Grocery Management System Master.php cance… |
| CVE-2026-14748 | 2.1 | 14.2 | AIAnytime | Awesome-MCP-Server | CWE-918 | AIAnytime Awesome-MCP-Server mcp-wiki/wiki-summary server.py server-side requ… |
| CVE-2026-14738 | 2.9 | 12.3 | exo-explore | exo | CWE-327 | exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash |
| CVE-2026-14698 | 2.1 | 12.0 | SourceCodester | Syllabus-Aligned Learning Management and Examination System | CWE-284 | SourceCodester Syllabus-Aligned Learning Management and Examination System up… |
| CVE-2026-14725 | 2.1 | 12.0 | SourceCodester | Online Boat Reservation System | CWE-613 | SourceCodester Online Boat Reservation System session expiration |
| CVE-2026-14775 | 2.1 | 12.0 | SourceCodester | Onlne Examination & Learning Management System | CWE-284 | SourceCodester Onlne Examination & Learning Management System process_lesson.… |
| CVE-2026-14776 | 2.1 | 12.0 | SourceCodester | Onlne Examination & Learning Management System | CWE-284 | SourceCodester Onlne Examination & Learning Management System Filename Extens… |
| CVE-2026-14777 | 2.1 | 12.0 | SourceCodester | Onlne Examination & Learning Management System | CWE-284 | SourceCodester Onlne Examination & Learning Management System announcements.p… |
| CVE-2026-14692 | 2.1 | 10.7 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-74 | SourceCodester Multi-Vendor Online Grocery Management System POST Parameter M… |
| CVE-2026-14703 | 2.1 | 10.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientorder.php sql injection |
| CVE-2026-14706 | 2.1 | 10.7 | code-projects | Online Examination | CWE-74 | code-projects Online Examination Quiz Creation Feature update.php sql injection |
| CVE-2026-14717 | 2.1 | 10.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientlogin.php sql injection |
| CVE-2026-14730 | 2.1 | 10.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientprofile.php sql injection |
| CVE-2026-14731 | 2.1 | 10.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientreport.php sql injection |
| CVE-2026-14751 | 2.1 | 10.7 | mjperpinosa | stumasy | CWE-74 | mjperpinosa stumasy search_scratch_data.php search_scratch_data sql injection |
| CVE-2026-14766 | 2.1 | 10.7 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System POST Parameter search-result.ph… |
| CVE-2026-14767 | 2.1 | 10.7 | CodeAstro | Ecommerce Website | CWE-74 | CodeAstro Ecommerce Website POST Parameter confirm.php sql injection |
| CVE-2026-14773 | 2.1 | 10.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System payment.php sql injection |
| CVE-2026-14774 | 2.1 | 10.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System paymentdischarge.php sql injection |
| CVE-2026-14752 | 2.0 | 10.5 | mjperpinosa | stumasy | CWE-79 | mjperpinosa stumasy add_into_dictionary.php add_definition cross site scripting |
| CVE-2026-14689 | 2.1 | 10.2 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System add-apartment.php sql injection |
| CVE-2026-14694 | 2.1 | 10.2 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-74 | SourceCodester Multi-Vendor Online Grocery Management System POST Parameter M… |
| CVE-2026-14701 | 2.1 | 10.2 | code-projects | Internship Management System | CWE-74 | code-projects Internship Management System Password Change Endpoint change_pa… |
| CVE-2026-59511 | 5.3 | 9.6 | Tim Strifler | Exclusive Addons Elementor | CWE-201 | WordPress Exclusive Addons Elementor plugin <= 2.7.9.9 - Sensitive Data Expos… |
| CVE-2026-59519 | 5.3 | 9.6 | Softaculous | FormLayer | CWE-201 | WordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerability |
| CVE-2026-14759 | 1.9 | 9.0 | radareorg | radare2 | CWE-119 | radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes… |
| CVE-2026-14781 | 4.8 | 7.6 | Red Hat | Red Hat Build of Keycloak | CWE-1288 | Keycloak-services: keycloak-services: oidc email_verified claim incorrectly a… |
| CVE-2026-14757 | 1.9 | 7.3 | radareorg | radare2 | CWE-189 | radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow |
| CVE-2026-14760 | 1.9 | 6.3 | radareorg | radare2 | CWE-119 | radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free |
| CVE-2026-14758 | 1.9 | 5.9 | radareorg | radare2 | CWE-189 | radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow |
| CVE-2026-14761 | 1.9 | 5.9 | radareorg | radare2 | CWE-189 | radareorg radare2 str.c r_str_append integer overflow |
| CVE-2026-14742 | 1.3 | 5.6 | langchain-ai | langgraph | CWE-327 | langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash |
| CVE-2026-14699 | 4.8 | 3.8 | zcaceres | markdownify-mcp | CWE-59 | zcaceres markdownify-mcp Markdownify.ts assertPathAllowed symlink |
| CVE-2026-14723 | 4.8 | 2.5 | AD-Security | AD_Miner | CWE-20 | AD-Security AD_Miner Cache analyse_cache.py request_a deserialization |
| CVE-2026-14702 | 1.1 | 1.5 | zcaceres | markdownify-mcp | CWE-310 | zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile ra… |
| CVE-2026-12250 | 7.9 | 1.3 | TUBITAK BILGEM Software Technologies Research Institute | Pardus Domain Joiner | CWE-214 | Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner |
| CVE-2026-9085 | 8.8 | 1.0 | TUBITAK BILGEM Software Technologies Research Institute | Pardus-Parental-Control | CWE-284 | DNS Hijacking in TUBITAK BILGEM's Pardus-Parental-Control |
| CVE-2026-6509 | 7.8 | 1.0 | TUBITAK BILGEM Software Technologies Research Institute | Pardus Update | CWE-862 | Privilege Escalation in TUBITAK BILGEM's Pardus Update |
| CVE-2026-59520 | 4.3 | 1.0 | properfraction | CrawlWP SEO | CWE-352 | WordPress CrawlWP SEO plugin <= 3.0.16 - Cross Site Request Forgery (CSRF) vu… |
| CVE-2026-12386 | 3.9 | 0.8 | TUBITAK BILGEM Software Technologies Research Institute | Pardus Pen | CWE-170 | Buffer Overflow in TUBITAK BILGEM's Pardus Pen |