boxscore/security
Monday, July 6, 2026 · all times UTC← 2026-07-05 · archive · 2026-07-07 →

196 CVEs published July 6, 2026: 30 critical, 80 high, 60 medium, 26 low; 0 in KEV; 20 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 171 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published11611347912482563
KEV catalog size1670

587 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux37151712086652812730.27.5.0013+3
google521316148586542377460.57.8.0023-436
microsoft50761585061764378283.77.8.0044+43
red hat1921112861049400.06.5.00260
apple0991236629377.16.5.00310
canonical0202585000.05.5.00110
suse51841040000.08.6.0034+5
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+25
cisco83141280961135.57.5.0056+6
netgear01700161800.04.3.00240
palo alto networks011017114218.24.8.00220
checkpoint0915303111.17.5.04100
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-1
fortinet08132028337.57.3.00660
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache44197367970114010.57.3.0050+12
mozilla35912182901300.07.3.0025-1
gitlab03305215426.14.4.00220
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
drupal0511305120.05.1.00260
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-1
adobe214812527927532.05.5.0021+2
ibm01243642460700.07.5.0025-5
progress2111910900.07.5.0035-3
solarwinds07122011457.17.5.0835-2
veeam042200400.09.0.00460
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link01305252617.75.8.0059-5
siemens090450100.06.9.0019-1
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4
schneider electric060420100.07.8.00240
moxa050320000.07.0.00290
dahua030111200.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2798005246000.05.5.0026+6
dell2076134382211.36.7.0016+17
spring073231391000.06.5.0024-2
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00590
itsourcecode1063001944000.02.1.0020-9
capgo061231271000.07.1.00310
themerex26055410000.08.1.0043+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
CVE-2026-48907.688399.310.0
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
CVE-2026-4827610.0.0505
CVE-2026-1377310.0.0341
CVE-2026-5641310.0.0316
CVE-2026-5641510.0.0315
Most disclosures (vendor)
VendorCVEs
google654
linux517
microsoft264
oracle242
adobe144
apache133
red hat128
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven68
Packagist15
npm6
NuGet3
PyPI3
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171692
CVE-2021-27102Accellion2021-11-171692
CVE-2021-27101Accellion2021-11-171692
CVE-2021-27103Accellion2021-11-171692
CVE-2021-21017Adobe2021-11-171692
CVE-2021-28550Adobe2021-11-171692
CVE-2021-42013Apache2021-11-171692
CVE-2021-41773Apache2021-11-171692
CVE-2021-30858Apple2021-11-171692
CVE-2021-30860Apple2021-11-171692

Transactions

EXPLOIT PUBLISHEDCVE-2026-41516 (OP-TEE optee_os). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44936 (SUSE Rancher). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49297 (Apache Software Foundation Apache Airflow Google provider). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54059 (python-pillow Pillow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54060 (python-pillow Pillow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54234 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55379 (python-pillow Pillow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55380 (python-pillow Pillow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55798 (python-pillow Pillow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57571 (unclecode crawl4ai). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58203 (pydantic-settings). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58380 (Red Hat Enterprise Linux 9). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59089 (Red Hat Enterprise Linux 6). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59194 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59195 (pnpm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59196 (pnpm). Public exploit reference added.

Yesterday's Results

196 CVEs published. 25 box scores, 171 table rows — nothing truncated.

Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0880   94.7     —
AFFECTED
  Product                                 Versions    Fixed
  Apache OpenNLP :: Core :: ML :: LibSVM  3.0.0-M1 –  —
TIMELINE
  May 2   Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-502 · CNA: apache · 2 references · NVD status: Analyzed
Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0178   76.4     —
AFFECTED
  Product       Versions  Fixed
  Apache Camel  4.15.0 –  —
TIMELINE
  Apr 8   Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-88 · CNA: apache · 2 references · NVD status: Analyzed
coollabsio coolify — Coolify authenticated remote command injection leading to RCE and secret exfiltration
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0175   75.9     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.469 –  —
TIMELINE
  Mar 25  Reserved by CNA
  Jul 6   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 4 references · NVD status: Deferred
Tenda firmware — Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0162   74.0     —
AFFECTED
  Product   Versions                                          Fixed
  firmware  US_AC6V2.0RTL_V15.03.06.51_multi_T –              —
  firmware  US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 –          —
  firmware  US_AC10V1.0re_V15.03.06.46_multi_TDE01 –          —
  firmware  US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE –  —
  firmware  US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD –            —
TIMELINE
  Jun 5   Reserved by CNA
  Jul 6   Published (CNA: certcc)
CNA: certcc · 3 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Improper Input Validation (CWE-20)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  N   10.0   .0160   73.7     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jul 6   Published (CNA: adobe)
CWE-20 · CNA: adobe · 1 reference · NVD status: Analyzed
coollabsio coolify — Coolify: Authenticated Remote Code Execution in GetLogs Livewire Component
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0135   69.2     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.471 –  —
TIMELINE
  Mar 30  Reserved by CNA
  Jul 6   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 4 references · NVD status: Deferred
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0132   68.5     —
AFFECTED
  Product           Versions  Fixed
  create-react-app  5.0.0 –   —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0097   59.0     —
AFFECTED
  Product       Versions  Fixed
  Apache Camel  4.0.0 –   —
TIMELINE
  May 4   Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-502 · CNA: apache · 2 references · NVD status: Analyzed
Esri ArcGIS Server — Directory Traversal in ArcGIS Server
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0094   58.1     —
AFFECTED
  Product        Versions     Fixed
  ArcGIS Server  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jul 6   Published (CNA: Esri)
CWE-22 · CNA: Esri · 1 reference · NVD status: Modified
Unknown FileOrganizer — Multiple elFinder Plugins - Authenticated OS Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0090   56.8     —
AFFECTED
  Product                Versions     Fixed
  FileOrganizer          unspecified  —
  Advanced File Manager  unspecified  —
  File Manager Pro       unspecified  —
  File Manager           unspecified  —
TIMELINE
  Apr 15  Reserved by CNA
  Jul 6   Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Deferred
Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0089   56.5     —
AFFECTED
  Product       Versions  Fixed
  Apache Camel  4.18.0 –  —
TIMELINE
  May 4   Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-502 · CNA: apache · 1 reference · NVD status: Analyzed
Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0088   56.1     —
AFFECTED
  Product       Versions  Fixed
  Apache Camel  4.0.0 –   —
TIMELINE
  Apr 15  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-502 · CNA: apache · 2 references · NVD status: Analyzed
Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0078   53.0     —
AFFECTED
  Product                       Versions  Fixed
  Apache Camel Vertx Websocket  4.0.0 –   —
TIMELINE
  May 16  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-20, CWE-200, CWE-918 · CNA: apache · 2 references · NVD status: Analyzed
Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviour
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0078   53.0     —
AFFECTED
  Product                            Versions  Fixed
  Apache Camel Atmosphere Websocket  4.0.0 –   —
TIMELINE
  Jun 18  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-20, CWE-200, CWE-918 · CNA: apache · 2 references · NVD status: Analyzed
Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is accepted
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0075   51.8     —
AFFECTED
  Product                Versions  Fixed
  Apache Camel Keycloak  4.15.0 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-287, CWE-306, CWE-636 · CNA: apache · 1 reference · NVD status: Analyzed
Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0071   50.7     —
AFFECTED
  Product       Versions  Fixed
  Apache Camel  4.18.0 –  —
TIMELINE
  May 15  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-502 · CNA: apache · 1 reference · NVD status: Analyzed
Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0071   50.4     —
AFFECTED
  Product       Versions  Fixed
  Apache Camel  4.0.0 –   —
TIMELINE
  May 14  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-20 · CNA: apache · 2 references · NVD status: Analyzed
Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0070   50.0     —
AFFECTED
  Product                         Versions     Fixed
  Apache Airflow Google provider  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jul 6   Public exploit reference published
  Jul 6   Published (CNA: apache)
CWE-22 · CNA: apache · 3 references · NVD status: Analyzed
Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0068   49.3     —
AFFECTED
  Product       Versions  Fixed
  Apache IoTDB  1.3.3 –   —
TIMELINE
  Jan 20  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-400 · CNA: apache · 2 references · NVD status: Analyzed
BeyondTrust Remote Support — Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0067   49.2     —
AFFECTED
  Product                   Versions     Fixed
  Remote Support            unspecified  —
  Privileged Remote Access  unspecified  —
TIMELINE
  Apr 9   Reserved by CNA
  Jul 6   Published (CNA: BT)
CWE-287 · CNA: BT · 1 reference · NVD status: Analyzed
Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0064   47.8     —
AFFECTED
  Product       Versions  Fixed
  Apache Camel  4.0.0 –   —
TIMELINE
  May 14  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-20 · CNA: apache · 2 references · NVD status: Analyzed
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0063   47.1     —
AFFECTED
  Product       Versions  Fixed
  Apache Camel  4.14.0 –  —
TIMELINE
  Apr 28  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-502 · CNA: apache · 2 references · NVD status: Analyzed
Apache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviour
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0062   46.9     —
AFFECTED
  Product            Versions  Fixed
  Apache Camel Iggy  4.17.0 –  —
TIMELINE
  Jun 18  Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-20, CWE-200, CWE-918 · CNA: apache · 2 references · NVD status: Analyzed
Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0062   46.7     —
AFFECTED
  Product       Versions  Fixed
  Apache Camel  3.0.0 –   —
  Apache Camel  3.0.0 –   —
TIMELINE
  May 4   Reserved by CNA
  Jul 6   Published (CNA: apache)
CWE-502 · CNA: apache · 1 reference · NVD status: Analyzed
unclecode crawl4ai — Crawl4AI arbitrary file write via download filename path traversal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0060   45.7     —
AFFECTED
  Product   Versions   Fixed
  crawl4ai  < 0.9.0 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 6   Public exploit reference published
  Jul 6   Published (CNA: GitHub_M)
CWE-22, CWE-59 · CNA: GitHub_M · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-240149.845.1Apache Software FoundationApache IoTDBCWE-284Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allo…
CVE-2026-464535.344.8Apache Software FoundationApache CamelCWE-639Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants with…
CVE-2026-401408.744.7BeyondTrustRemote SupportCWE-400High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support …
CVE-2026-490976.544.1Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header con…
CVE-2026-5757210.042.6unclecodecrawl4aiCWE-88Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in brows…
CVE-2026-490985.342.5Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Excha…
CVE-2026-561395.342.4Apache Software FoundationApache Camel UndertowCWE-209Apache Camel Undertow: The muteException consumer option defaulted to false, …
CVE-2026-465877.342.1Apache Software FoundationApache CamelCWE-20Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFil…
CVE-2026-465887.342.1Apache Software FoundationApache CamelCWE-20Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilte…
CVE-2026-490427.342.1Apache Software FoundationApache CamelCWE-20Apache Camel: langchain4j-tools: filter tool argument headers against declare…
CVE-2026-240139.141.9Apache Software FoundationApache IoTDBCWE-290Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC
CVE-2026-493655.340.6Apache Software FoundationApache CamelCWE-209Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted t…
CVE-2026-401418.540.2BeyondTrustRemote SupportCWE-943High-Severity Vulnerability In Web Application Component of BeyondTrust Remot…
CVE-2026-148089.338.8PROG MISProg Management SystemCWE-497PROG MIS|Prog Management System - Exposure of Sensitive Information
CVE-2026-482049.837.5Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Cam…
CVE-2026-389767.537.1n/an/aCWE-476mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/v…
CVE-2026-401389.236.7BeyondTrustRemote SupportCWE-287Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and P…
CVE-2026-582268.736.5elixir-minthpaxCWE-407Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax
CVE-2026-119628.836.3UnknownFileOrganizerFileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File…
CVE-2026-148079.336.0PROG MISERP AppCWE-798PROG MIS|ERP App - Use of Hard-coded Credentials
CVE-2026-561409.835.6Apache Software FoundationApache Camel AWS2 SNSCWE-20Apache Camel AWS2 SNS: An inbound Camel-namespace filter was added to Sns2Hea…
CVE-2026-464559.835.5Apache Software FoundationApache CamelCWE-613Apache Camel: Camel-Keycloak: The access-token validity window is not verifie…
CVE-2026-490866.535.5Apache Software FoundationApache Camel DaprCWE-20Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-n…
CVE-2026-464577.535.3Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Ex…
CVE-2026-553797.535.2python-pillowPillowCWE-789Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check(…
CVE-2026-52689.135.0CIENA6500 S-SeriesCWE-288SFTP Server Authentication Weakness
CVE-2026-536476.935.0FOSSBillingFOSSBillingCWE-200FOSSBilling vulnerable to unauthenticated API key configuration disclosure vi…
CVE-2026-148098.734.9PROG MISProg Management SystemCWE-89PROG MIS|Prog Management System - SQL Injection
CVE-2026-540607.534.9python-pillowPillowCWE-789Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bo…
CVE-2026-553807.534.9python-pillowPillowCWE-789Pillow GdImageFile decompression bomb protection bypass
CVE-2026-540597.534.1python-pillowPillowCWE-789Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_de…
CVE-2026-341538.833.5coollabsiocoolifyCWE-78Coolify LocalFileVolume fs_path command injection enables RCE
CVE-2026-465857.533.1Apache Software FoundationApache Camel LuceneCWE-20Apache Camel Lucene: The query control headers used non-Camel-prefixed names …
CVE-2026-137537.532.7HP Inc.HP 2800 Printer SeriesCVE-2026-13753
CVE-2026-465927.532.8Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-…
CVE-2026-465843.732.3Apache Software FoundationApache Camel MailCWE-20Apache Camel Mail: The mail producer applied attacker-supplied message header…
CVE-2026-449378.331.4SUSERancherCWE-918SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsani…
CVE-2026-137087.530.6TONYCImager::File::JPEGCWE-401Imager::File::JPEG versions before 1.003 for Perl leak heap memory when readi…
CVE-2026-482039.130.1Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefi…
CVE-2026-482059.130.1Apache Software FoundationApache Camel DNSCWE-20Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel…
CVE-2026-555147.130.1vllm-projectvllmCWE-617vLLM denial of service via prompt embeds on M-RoPE models
CVE-2026-147926.929.7n/aFormbricksCWE-266Formbricks Survey actions.ts access control
CVE-2026-542347.529.3vllm-projectvllmCWE-20vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection
CVE-2025-538279.129.3owncloudownCloud CoreCWE-749ownCloud Core: Updater has an exposed dangerous method or function
CVE-2026-421538.829.0coollabsiocoolifyCWE-78Coolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution …
CVE-2026-422048.829.0coollabsiocoolifyCWE-78Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root
CVE-2026-91829.828.3EsriArcGIS ServerCWE-434Unvalidated File Upload vulnerability in ArcGIS Server.
CVE-2026-482065.328.0Apache Software FoundationApache Camel JIRACWE-20Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypa…
CVE-2026-568108.727.4elixir-mintmintCWE-770mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_…
CVE-2026-490995.327.1Apache Software FoundationApache Camel SalesforceCWE-74Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass …
CVE-2026-42498.626.8WSO2WSO2 Universal GatewayCWE-707Denial of Service via Malicious JSON Payloads in Throttling Events in Multipl…
CVE-2025-538298.026.4owncloudownCloud 10CWE-23ownCloud 10 is vulnerable to Relative Path Traversal
CVE-2026-148036.526.0SRIMojo::JSONCWE-674Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounde…
CVE-2026-486149.925.9WebProsPleskCWE-94An improper authorization vulnerability in the Plesk XML API allows an authen…
CVE-2026-449365.025.9SUSERancherCWE-918Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fl…
CVE-2026-465918.225.7Apache Software FoundationApache CamelCWE-943Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProper…
CVE-2026-144718.625.3AWSMCP Gateway & RegistryCWE-89Authenticated SQL injection in the metrics-service retention policy subsystem…
CVE-2026-555748.725.3vllm-projectvllmCWE-1333vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar…
CVE-2026-148986.525.2OpenAICodex desktop app for macOSCWE-200The OpenAI Codex desktop app for macOS rendered remote images from Markdown i…
CVE-2024-62287.524.6UnknownNotifications for Forms & WordPress ActionsWANotifier < 2.6 - Subscriber+ LFI
CVE-2026-584035.924.6gohugoiohugoCWE-59Hugo symlink confinement bypass in os.ReadFile
CVE-2026-136986.024.1OpenVPNOpenVPNCWE-401A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 a…
CVE-2026-91657.723.8Red HatRed Hat Advanced Cluster Security 4.9CWE-400Stackrox: stackrox: unbounded graphql query depth allows authenticated denial…
CVE-2026-126869.323.6AdissBiloopCWE-639Incorrect authorisation in Adiss’s Biloop
CVE-2026-418996.522.5coollabsiocoolifyCWE-306Coolify unauthenticated feedback endpoint allows Discord webhook abuse
CVE-2026-439256.922.4FOSSBillingFOSSBillingCWE-915FOSSBilling: Mass assignment of group_id in guest client registration allows …
CVE-2026-120838.122.0UnknownAdmin and Site Enhancements (ASE)Admin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Rest…
CVE-2026-144687.722.1HashiCorpTerraform EnterpriseCWE-22Path traversal allows arbitrary file read in Terraform Enterprise container
CVE-2026-131225.921.9OpenvpnOpenVPNCWE-617OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remo…
CVE-2026-591967.121.9pnpmpnpmCWE-22pnpm: hoisted install imports lockfile alias outside node_modules
CVE-2026-71856.021.7T-SystemsArchivoCWE-22Unauthorized access to files in T-Systems products
CVE-2026-557277.521.6Genetec Inc.Genetec Security CenterCWE-287A flaw in the authentication mechanism for video stream requests in Genetec S…
CVE-2026-556466.521.4vllm-projectvllmCWE-400vLLM speech-to-text endpoints allocate full upload before enforcing the audio…
CVE-2026-591958.221.2pnpmpnpmCWE-22pnpm: Path traversal in configDependencies env lockfile allows symlink creati…
CVE-2026-591947.121.2pnpmpnpmCWE-22pnpm: patch-remove could delete project-selected files outside the patches di…
CVE-2026-536414.821.1FOSSBillingFOSSBillingCWE-79FOSSBilling has stored XSS in client email views via unescaped content in Jav…
CVE-2026-118558.820.0UnknownSimple MembershipSimple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API…
CVE-2026-547656.320.1traefiktraefikCWE-284Traefik: Gateway HTTPRoute backendRef filters can leak backend context across…
CVE-2026-439218.919.8FOSSBillingFOSSBillingCWE-94FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config s…
CVE-2026-439282.319.8FOSSBillingFOSSBillingCWE-754FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoi…
CVE-2026-501356.919.4gohugoiohugoCWE-59Hugo: Symlink confinement bypass in resources.Get
CVE-2026-536485.118.4FOSSBillingFOSSBillingCWE-73FOSSBilling: Downloadable product files can be overwritten through filename c…
CVE-2026-575738.618.1unclecodecrawl4aiCWE-918Crawl4AI unauthenticated SSRF in Docker streaming crawl endpoint
CVE-2025-538309.117.5owncloudAnti-Virus for ownCloudCWE-918Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2026-583807.817.5Red HatRed Hat Enterprise Linux 9CWE-193Gimp: gimp: stack buffer overflow in pnmscanner_gettoken()
CVE-2026-536448.616.7FOSSBillingFOSSBillingCWE-639FOSSBilling's missing order-state validation allows clients to read and reset…
CVE-2026-597128.616.6LeantimeLeantimeCWE-639Leantime - JSON-RPC API Broken Access Control via users.getUser
CVE-2026-501346.316.5gohugoiohugoCWE-918Hugo: security.http.urls allow-list bypass via HTTP redirects
CVE-2026-423317.716.3FOSSBillingFOSSBillingCWE-306FOSSBilling missing authorization in guest Invoice API endpoints
CVE-2026-590895.516.3Red HatRed Hat Enterprise Linux 6CWE-190Gimp: gimp: denial of service via integer overflow in playstation tim loader
CVE-2026-536458.515.4FOSSBillingFOSSBillingCWE-269FOSSBilling's missing self-edit prevention in staff permission management all…
CVE-2026-108308.815.3UnknownAllCoachAllCoach < 1.0.2 - Unauthenticated Account Takeover
CVE-2026-439188.714.7FOSSBillingFOSSBillingCWE-613Suspended or inactive FOSSBilling accounts can retain or regain access throug…
CVE-2026-547646.914.4traefiktraefikCWE-345ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwar…
CVE-2025-538288.514.3owncloudSharePointCWE-918SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2026-145368.814.2DevolutionsServerCWE-863Improper enforcement of a mandatory multi-factor authentication policy in Dev…
CVE-2026-147845.313.8vxcontrolPentAGICWE-264vxcontrol PentAGI Docker API client.go sandbox
CVE-2026-536438.713.6FOSSBillingFOSSBillingCWE-200FOSSBilling allows low-privileged staff accounts to perform unauthorized acti…
CVE-2026-117668.013.5UnknownUltimate MemberUltimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile…
CVE-2026-536425.313.6FOSSBillingFOSSBillingCWE-863FOSSBilling: Unverified clients can access client-area pages when email confi…
CVE-2026-536402.313.6FOSSBillingFOSSBillingCWE-200FOSSBilling missing authorization checks on read-only admin API endpoints exp…
CVE-2026-147935.313.3CraftCMSCWE-285Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets autho…
CVE-2026-147945.313.0CraftCMSCWE-266Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper…
CVE-2026-439276.912.8FOSSBillingFOSSBillingCWE-367FOSSBilling has race condition in cart checkout that bypasses promo code usag…
CVE-2026-337346.912.5FOSSBillingFOSSBillingCWE-89FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters
CVE-2026-536467.712.1FOSSBillingFOSSBillingCWE-640FOSSBilling: Client password reset token reuse allows persistent account take…
CVE-2026-327186.511.9coollabsiocoolifyCWE-863Coolify read-scoped API tokens can perform state-changing validation operations
CVE-2026-340506.511.9coollabsiocoolifyCWE-862Coolify Settings/Updates Livewire component missing instance administrator au…
CVE-2026-547637.811.1traefiktraefikCWE-178Traefik: headerField underscore-variant identity spoofing in BasicAuth / Dige…
CVE-2026-14334.811.2NT-wareuniFLOW ULM (Universal Login Manager) StandaloneCWE-522uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensi…
CVE-2026-584044.611.2gohugoiohugoCWE-918Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings
CVE-2026-147962.110.7CodeAstroApartment Visitor Management SystemCWE-74CodeAstro Apartment Visitor Management System report.php sql injection
CVE-2026-147992.110.7CodeAstroEcommerce WebsiteCWE-74CodeAstro Ecommerce Website my_account.php sql injection
CVE-2026-542918.210.5pgjdbcpgjdbcCWE-636Silent channel-binding authentication downgrade via unsupported certificate a…
CVE-2026-147912.010.5crater-invoice-inccraterCWE-79crater-invoice-inc crater Invoice Note InvoicesRequest.php getFormattedString…
CVE-2026-389795.410.1n/an/aCWE-1021ajenti through v2.2.13 has a clickjacking weakness in the browser-facing logi…
CVE-2026-147952.110.2CodeAstroApartment Visitor Management SystemCWE-74CodeAstro Apartment Visitor Management System action-visitor.php sql injection
CVE-2026-147972.110.2CodeAstroApartment Visitor Management SystemCWE-74CodeAstro Apartment Visitor Management System edit-apartment.php sql injection
CVE-2026-147982.110.2CodeAstroApartment Visitor Management SystemCWE-74CodeAstro Apartment Visitor Management System visitor-entry.php sql injection
CVE-2026-341675.010.1coollabsiocoolifyCWE-639Coolify: Cross-tenant activity log disclosure via unlocked Livewire property …
CVE-2026-597105.39.9showdownshowdownCWE-79showdown - Stored XSS via Unescaped Table Header ID Attribute Injection
CVE-2026-340493.39.6coollabsiocoolifyCWE-78Coolify: Command Injection via unsanitized MongoDB collection names in databa…
CVE-2026-147891.99.0radareorgradare2CWE-119radareorg radare2 Memory64ListStream mdmp.c stack-based overflow
CVE-2026-121546.48.7widgetpackReviews Widgets for Google, TripAdvisor, Yelp & RecommendationsCWE-79Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Cont…
CVE-2026-597115.38.7showdownshowdownCWE-79showdown - Cross-Site Scripting via Unescaped Metadata Title in completeHTMLD…
CVE-2026-501335.18.4gohugoiohugoCWE-79Hugo: XSS via text/html content files
CVE-2026-423419.28.3FOSSBillingFOSSBillingCWE-306FOSSBilling has an unauthenticated payment bypass via IPN callback forgery
CVE-2026-582035.37.8pydanticpydantic-settingsCWE-22NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling lo…
CVE-2026-557984.57.6python-pillowPillowCWE-78Pillow: WindowsViewer.get_command() OS command injection via unescaped shell …
CVE-2026-591525.07.1langchain-ailangsmith-sdkCWE-22Arbitrary server-side file read in LangSmith SDK TracingMiddleware
CVE-2026-584025.17.0gohugoiohugoCWE-79Hugo default code block renderer XSS via unescaped code-fence language
CVE-2026-147871.96.5radareorgradare2CWE-189radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow
CVE-2026-147881.96.3radareorgradare2CWE-119radareorg radare2 cfile.c r_core_bin_load use after free
CVE-2025-538318.26.0owncloudDrawIO for ownCloudCWE-79DrawIO for ownCloud 10 is vulnerable to Stored XSS
CVE-2025-85916.15.8WSO2WSO2 Identity ServerCWE-79Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products En…
CVE-2026-148002.15.5imhamzaazamecommerceFlaskCWE-352imhamzaazam ecommerceFlask cross-site request forgery
CVE-2026-147861.95.6radareorgradare2CWE-189radareorg radare2 str.c r_str_word_get0set integer overflow
CVE-2026-389734.45.5n/an/aCWE-125mrubyc through release3.4.1 was found to contain an out-of-bounds read in bui…
CVE-2026-597138.65.0LeantimeLeantimeCWE-352Leantime - OIDC Login CSRF via Unconditional State Verification Stub
CVE-2026-537633.84.6OP-TEEoptee_osCWE-190OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks aut…
CVE-2026-548932.14.1swooshswooshCWE-116Email-derived URL path injection in the Swoosh Microsoft Graph adapter
CVE-2026-69009.14.1B&R Industrial Automation GmbHAPROLCWE-295Improper Certificate Validation
CVE-2026-482675.53.8AdobeDNG SDKCWE-476DNG SDK | NULL Pointer Dereference (CWE-476)
CVE-2026-137057.13.5TONYCImagerCWE-125Imager versions before 1.032 for Perl have a heap out-of-bounds read in the b…
CVE-2026-415163.33.3OP-TEEoptee_osCWE-208OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle
CVE-2026-133566.33.2MozillaFirefox for iOSCWE-451Interrupted navigation could allow address bar origin spoofing in Firefox for…
CVE-2025-156681.92.6n/aGPACCWE-119GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow
CVE-2026-443625.52.4OP-TEEoptee_osCWE-285OP-TEE's subkey rollback protection can be bypassed with older subkey versions
CVE-2026-421483.82.2coollabsiocoolifyCWE-78Coolify: Command Injection via Unescaped Version String in Docker Build
CVE-2026-69018.42.2B&R Industrial Automation GmbHAPROLCWE-426Untrusted Search Path
CVE-2026-147901.91.8n/aGPACCWE-404GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference
CVE-2026-449347.01.8SUSERancherCWE-215Exposed tokens in SUSE Rancher AI Agent logs
CVE-2026-148014.81.6n/aGPACCWE-369GPAC TeXML File load_text.c txtin_probe_duration divide by zero
CVE-2025-156671.91.6n/aGPACCWE-119GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
CVE-2024-561415.01.5BixilonMinosoftCWE-329Minosoft has IV equal to key
CVE-2026-402575.51.4OP-TEEoptee_osCWE-787OP-TEE has SHA-3 accelerated finalize heap overflow
CVE-2026-425463.81.2OP-TEEoptee_osCWE-770OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj …
CVE-2026-414343.31.2OP-TEEoptee_osCWE-121OP-TEE has unbounded recursion in sanitize_client_object()
CVE-2026-415143.30.8OP-TEEoptee_osCWE-208OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext re…
CVE-2026-415153.30.7OP-TEEoptee_osCWE-208OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery
CVE-2026-252688.80.1Qualcomm, Inc.SnapdragonCWE-121Stack-based Buffer Overflow in WLAN Host
CVE-2026-213797.80.0Qualcomm, Inc.SnapdragonCWE-126Buffer Over-read in Windows Compute
CVE-2026-213837.10.0Qualcomm, Inc.SnapdragonCWE-323Reusing a Nonce, Key Pair in Encryption in HLOS
CVE-2025-596177.30.0Qualcomm, Inc.SnapdragonCWE-416Use After Free in Computer Vision
CVE-2025-596157.80.0Qualcomm, Inc.SnapdragonCWE-416Use After Free in Computer Vision
CVE-2025-596167.80.0Qualcomm, Inc.SnapdragonCWE-416Use After Free in Computer Vision
CVE-2026-213685.30.0Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Camera Driver
CVE-2026-213695.30.0Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Camera Driver
CVE-2026-213705.30.0Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Camera Driver
CVE-2026-213845.30.0Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Camera Driver
CVE-2026-252717.00.0Qualcomm, Inc.SnapdragonCWE-367Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-06 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.