boxscore/security
Sunday, July 5, 2026 · all times UTC← 2026-07-04 · archive · 2026-07-06 →

86 CVEs published July 5, 2026: 1 critical, 6 high, 44 medium, 35 low; 0 in KEV; 7 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 61 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published9651328312482563
KEV catalog size1670

572 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux37151712086652812730.27.5.0013+3
google521316148586542377460.57.8.0023-436
microsoft50761585061764378283.77.8.0044+43
red hat1620812841039400.06.5.0026-3
apple0991236629377.16.5.00310
canonical0202585000.05.5.00110
freebsd01601240000.07.8.00150
suse2154830000.08.8.0036+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+25
cisco83141280961135.57.5.0056+6
netgear01700161800.04.3.00240
palo alto networks011017114218.24.8.00220
checkpoint0915303111.17.5.04100
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-1
fortinet08132028337.57.3.00660
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache5158246162104010.67.3.0048-27
mozilla25812182801300.07.3.0025-2
gitlab03305215426.14.4.00220
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
drupal0511305120.05.1.00260
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-1
adobe014611527827532.15.5.00210
ibm01243642460700.07.5.0025-5
progress2111910900.07.5.0035-3
solarwinds07122011457.17.5.0835-2
veeam042200400.09.0.00460
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link01305252617.75.8.0059-5
siemens090450100.06.9.0019-1
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4
schneider electric060420100.07.8.00240
moxa050320000.07.0.00290
dahua030111200.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2798005246000.05.5.0026+6
dell2076134382211.36.7.0016+17
spring073231391000.06.5.0024-2
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00590
itsourcecode1063001944000.02.1.0020-9
capgo061231271000.07.1.00310
themerex26055410000.08.1.0043+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
CVE-2026-4827610.0.0505
CVE-2026-1377310.0.0341
CVE-2026-5641310.0.0316
CVE-2026-5641510.0.0315
Most disclosures (vendor)
VendorCVEs
google654
linux517
microsoft264
oracle242
adobe142
red hat125
apache94
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven38
Packagist15
npm6
NuGet3
PyPI3
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171691
CVE-2021-27102Accellion2021-11-171691
CVE-2021-27101Accellion2021-11-171691
CVE-2021-27103Accellion2021-11-171691
CVE-2021-21017Adobe2021-11-171691
CVE-2021-28550Adobe2021-11-171691
CVE-2021-42013Apache2021-11-171691
CVE-2021-41773Apache2021-11-171691
CVE-2021-30858Apple2021-11-171691
CVE-2021-30860Apple2021-11-171691

Transactions

EXPLOIT PUBLISHEDCVE-2026-10656 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10657 (zephyrproject zephyr). Public exploit reference added.

DUE DATE PASSEDCVE-2026-45659 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 4, 2026; still in catalog.

Yesterday's Results

86 CVEs published. 25 box scores, 61 table rows — nothing truncated.

zhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    5.5   .0046   38.2     —
AFFECTED
  Product                     Versions  Fixed
  chatgpt-on-wechat CowAgent  2.1.0 –   2.1.1
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · 7 references · NVD status: Deferred
UTT HiPER 1250GW Web Endpoint ConfigWirelessBase_5g stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0045   37.2     —
AFFECTED
  Product       Versions               Fixed
  HiPER 1250GW  3.2.7-210907-180535 –  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Deferred
ail-project ail-framework — Authenticated Path Traversal in AIL Framework PDF Object Handling Enables Potential Arbitrary File Read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0037   30.4     —
AFFECTED
  Product        Versions     Fixed
  ail-framework  unspecified  —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: CIRCL)
CWE-22 · CNA: CIRCL · 1 reference · NVD status: Deferred
cve-search cve-search — Unauthenticated arbitrary MongoDB collection read in cve-search
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    9.2   .0035   28.0     —
AFFECTED
  Product     Versions  Fixed
  cve-search  v4.0 –    —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: CIRCL)
CWE-20 · CNA: CIRCL · 2 references · NVD status: Deferred
NousResearch hermes-agent skills_tool.py skill_view path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    2.1   .0033   26.2     —
AFFECTED
  Product       Versions       Fixed
  hermes-agent  2026.5.29.2 –  —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-22 · CNA: VulDB · 8 references · NVD status: Deferred
666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   N    5.5   .0033   26.1     —
AFFECTED
  Product    Versions  Fixed
  BettaFish  1.2.0 –   —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-187, CWE-697 · CNA: VulDB · 7 references · NVD status: Deferred
code-projects Hotel and Tourism Reservation Room Management rooms.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0032   25.3     —
AFFECTED
  Product                        Versions  Fixed
  Hotel and Tourism Reservation  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0032   25.0     —
AFFECTED
  Product        Versions  Fixed
  TidGi-Desktop  0.1 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-94 · CNA: VulDB · 6 references · NVD status: Deferred
mjperpinosa stumasy calculate.php eval code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0032   25.0     —
AFFECTED
  Product  Versions                                    Fixed
  stumasy  327d1b0f2915ba79d7ef8ebb74553e987609d9be –  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-94 · CNA: VulDB · 6 references · NVD status: Deferred
TIMLEGGE Crypt::DSA — Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0032   24.2     —
AFFECTED
  Product     Versions     Fixed
  Crypt::DSA  unspecified  —
TIMELINE
  Jul 3   Reserved by CNA
  Jul 5   Published (CNA: CPANSec)
CWE-330 · CNA: CPANSec · 4 references · NVD status: Deferred
mjperpinosa stumasy Note Handler/Assignment notes authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0031   23.5     —
AFFECTED
  Product  Versions                                    Fixed
  stumasy  327d1b0f2915ba79d7ef8ebb74553e987609d9be –  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · 6 references · NVD status: Deferred
SourceCodester Multi-Vendor Online Grocery Management System Users.php save_users improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0029   21.9     —
AFFECTED
  Product                                        Versions  Fixed
  Multi-Vendor Online Grocery Management System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · 6 references · NVD status: Deferred
SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0029   21.9     —
AFFECTED
  Product                                         Versions  Fixed
  Onlne Examination & Learning Management System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-266, CWE-269 · CNA: VulDB · 6 references · NVD status: Deferred
SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0029   21.9     —
AFFECTED
  Product                                         Versions  Fixed
  Onlne Examination & Learning Management System  1.0 –     —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · 6 references · NVD status: Deferred
stephen-kruger bluebox cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0029   21.2     —
AFFECTED
  Product  Versions  Fixed
  bluebox  4.5.0 –   —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · 7 references · NVD status: Deferred
zephyrproject zephyr — Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0029   21.0     —
AFFECTED
  Product  Versions  Fixed
  zephyr   1.10.0 –  —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 5   Public exploit reference published
  Jul 5   Published (CNA: zephyr)
CWE-125 · CNA: zephyr · 2 references · NVD status: Modified
SourceCodester Class and Exam Timetabling System edit_exam.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0028   20.9     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System edit_coursea.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0028   20.9     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System edit_product.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0028   20.9     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
Ruijie RG-UAC user_auth_commit.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0028   20.9     —
AFFECTED
  Product  Versions         Fixed
  RG-UAC   1.0-R1.8.2.p5 –  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · 5 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System edit_room.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0028   20.9     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System edit_exam1.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0028   20.9     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System edit_course1.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0028   20.9     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
itsourcecode Online Hotel Management System login.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0028   20.5     —
AFFECTED
  Product                         Versions  Fixed
  Online Hotel Management System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
code-projects Real State Services addprojectsale.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0027   19.1     —
AFFECTED
  Product              Versions  Fixed
  Real State Services  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-147005.519.1code-projectsInternship Management SystemCWE-74code-projects Internship Management System Employer Login Endpoint login.php …
CVE-2026-147055.519.1code-projectsOnline ExaminationCWE-74code-projects Online Examination head.php sql injection
CVE-2026-147135.519.1SourceCodesterPizzafy E-Commerce SystemCWE-74SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection
CVE-2026-147355.519.1code-projectsSmart Parking SystemCWE-74code-projects Smart Parking System parkings.php sql injection
CVE-2026-147465.519.1code-projectsReal State ServicesCWE-74code-projects Real State Services addprojectrent.php sql injection
CVE-2026-147505.519.1mjperpinosastumasyCWE-74mjperpinosa stumasy accessing_dictionary_authorization.php accessing_dictiona…
CVE-2026-147545.519.1code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation add_room.php sql injection
CVE-2026-147555.519.1code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation Reservations Management reservati…
CVE-2026-147565.519.1code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation Tour Management add_tour.php sql …
CVE-2026-147635.519.1code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation Tour Reservations tour_reserves.p…
CVE-2026-147645.519.1code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation Event Management add_event.php sq…
CVE-2026-147685.519.1code-projectsReal State ServicesCWE-74code-projects Real State Services builderHome.php sql injection
CVE-2026-147695.519.1code-projectsReal State ServicesCWE-74code-projects Real State Services pay.php sql injection
CVE-2026-146955.518.2SourceCodesterMulti-Vendor Online Grocery Management SystemCWE-74SourceCodester Multi-Vendor Online Grocery Management System Registration Use…
CVE-2026-147435.518.2code-projectsReal State ServicesCWE-74code-projects Real State Services normalHomeSale.php sql injection
CVE-2026-147445.518.2code-projectsReal State ServicesCWE-74code-projects Real State Services normalHomeRent.php sql injection
CVE-2026-147455.518.2code-projectsReal State ServicesCWE-74code-projects Real State Services single-list_rent.php sql injection
CVE-2026-147375.517.8Hanwange-Face General Management PlatformCWE-74Hanwang e-Face General Management Platform querySysAuthStr.do sql injection
CVE-2026-106564.617.2zephyrprojectzephyrCWE-476NULL-pointer dereference DoS in MAX32 USB device controller transfer-completi…
CVE-2026-147162.116.1nextlevelbuilderGoClawCWE-285nextlevelbuilder GoClaw WebSocket RPC router.go MethodRouter.Handle authoriza…
CVE-2026-146912.115.6SourceCodesterMulti-Vendor Online Grocery Management SystemCWE-74SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSe…
CVE-2026-146932.114.6SourceCodesterMulti-Vendor Online Grocery Management SystemCWE-266SourceCodester Multi-Vendor Online Grocery Management System Master.php cance…
CVE-2026-147482.114.2AIAnytimeAwesome-MCP-ServerCWE-918AIAnytime Awesome-MCP-Server mcp-wiki/wiki-summary server.py server-side requ…
CVE-2026-147382.912.3exo-exploreexoCWE-327exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
CVE-2026-146982.112.0SourceCodesterSyllabus-Aligned Learning Management and Examination SystemCWE-284SourceCodester Syllabus-Aligned Learning Management and Examination System up…
CVE-2026-147252.112.0SourceCodesterOnline Boat Reservation SystemCWE-613SourceCodester Online Boat Reservation System session expiration
CVE-2026-147752.112.0SourceCodesterOnlne Examination & Learning Management SystemCWE-284SourceCodester Onlne Examination & Learning Management System process_lesson.…
CVE-2026-147762.112.0SourceCodesterOnlne Examination & Learning Management SystemCWE-284SourceCodester Onlne Examination & Learning Management System Filename Extens…
CVE-2026-147772.112.0SourceCodesterOnlne Examination & Learning Management SystemCWE-284SourceCodester Onlne Examination & Learning Management System announcements.p…
CVE-2026-146922.110.7SourceCodesterMulti-Vendor Online Grocery Management SystemCWE-74SourceCodester Multi-Vendor Online Grocery Management System POST Parameter M…
CVE-2026-147032.110.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientorder.php sql injection
CVE-2026-147062.110.7code-projectsOnline ExaminationCWE-74code-projects Online Examination Quiz Creation Feature update.php sql injection
CVE-2026-147172.110.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientlogin.php sql injection
CVE-2026-147302.110.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientprofile.php sql injection
CVE-2026-147312.110.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientreport.php sql injection
CVE-2026-147512.110.7mjperpinosastumasyCWE-74mjperpinosa stumasy search_scratch_data.php search_scratch_data sql injection
CVE-2026-147662.110.7CodeAstroApartment Visitor Management SystemCWE-74CodeAstro Apartment Visitor Management System POST Parameter search-result.ph…
CVE-2026-147672.110.7CodeAstroEcommerce WebsiteCWE-74CodeAstro Ecommerce Website POST Parameter confirm.php sql injection
CVE-2026-147732.110.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System payment.php sql injection
CVE-2026-147742.110.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System paymentdischarge.php sql injection
CVE-2026-147522.010.5mjperpinosastumasyCWE-79mjperpinosa stumasy add_into_dictionary.php add_definition cross site scripting
CVE-2026-146892.110.2CodeAstroApartment Visitor Management SystemCWE-74CodeAstro Apartment Visitor Management System add-apartment.php sql injection
CVE-2026-146942.110.2SourceCodesterMulti-Vendor Online Grocery Management SystemCWE-74SourceCodester Multi-Vendor Online Grocery Management System POST Parameter M…
CVE-2026-147012.110.2code-projectsInternship Management SystemCWE-74code-projects Internship Management System Password Change Endpoint change_pa…
CVE-2026-595115.39.6Tim StriflerExclusive Addons ElementorCWE-201WordPress Exclusive Addons Elementor plugin <= 2.7.9.9 - Sensitive Data Expos…
CVE-2026-595195.39.6SoftaculousFormLayerCWE-201WordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerability
CVE-2026-147591.99.0radareorgradare2CWE-119radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes…
CVE-2026-147814.87.6Red HatRed Hat Build of KeycloakCWE-1288Keycloak-services: keycloak-services: oidc email_verified claim incorrectly a…
CVE-2026-147571.97.3radareorgradare2CWE-189radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow
CVE-2026-147601.96.3radareorgradare2CWE-119radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free
CVE-2026-147581.95.9radareorgradare2CWE-189radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow
CVE-2026-147611.95.9radareorgradare2CWE-189radareorg radare2 str.c r_str_append integer overflow
CVE-2026-147421.35.6langchain-ailanggraphCWE-327langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
CVE-2026-146994.83.8zcaceresmarkdownify-mcpCWE-59zcaceres markdownify-mcp Markdownify.ts assertPathAllowed symlink
CVE-2026-147234.82.5AD-SecurityAD_MinerCWE-20AD-Security AD_Miner Cache analyse_cache.py request_a deserialization
CVE-2026-147021.11.5zcaceresmarkdownify-mcpCWE-310zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile ra…
CVE-2026-122507.91.3TUBITAK BILGEM Software Technologies Research InstitutePardus Domain JoinerCWE-214Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner
CVE-2026-90858.81.0TUBITAK BILGEM Software Technologies Research InstitutePardus-Parental-ControlCWE-284DNS Hijacking in TUBITAK BILGEM's Pardus-Parental-Control
CVE-2026-65097.81.0TUBITAK BILGEM Software Technologies Research InstitutePardus UpdateCWE-862Privilege Escalation in TUBITAK BILGEM's Pardus Update
CVE-2026-595204.31.0properfractionCrawlWP SEOCWE-352WordPress CrawlWP SEO plugin <= 3.0.16 - Cross Site Request Forgery (CSRF) vu…
CVE-2026-123863.90.8TUBITAK BILGEM Software Technologies Research InstitutePardus PenCWE-170Buffer Overflow in TUBITAK BILGEM's Pardus Pen

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-05 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.