AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L L 7.3 .0880 94.7 —
AFFECTED Product Versions Fixed Apache OpenNLP :: Core :: ML :: LibSVM 3.0.0-M1 – —
TIMELINE May 2 Reserved by CNA Jul 6 Published (CNA: apache)
196 CVEs published July 6, 2026: 30 critical, 80 high, 60 medium, 26 low; 0 in KEV; 20 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 171 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1161 | 13479 | 1248 | 2563 |
| KEV catalog size | 1670 | |||
587 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 37 | 1517 | 120 | 866 | 528 | 1 | 27 | 3 | 0.2 | 7.5 | .0013 | +3 |
| 52 | 1316 | 148 | 586 | 542 | 37 | 74 | 6 | 0.5 | 7.8 | .0023 | -436 | |
| microsoft | 50 | 761 | 58 | 506 | 176 | 4 | 378 | 28 | 3.7 | 7.8 | .0044 | +43 |
| red hat | 19 | 211 | 12 | 86 | 104 | 9 | 4 | 0 | 0.0 | 6.5 | .0026 | 0 |
| apple | 0 | 99 | 1 | 23 | 66 | 2 | 93 | 7 | 7.1 | 6.5 | .0031 | 0 |
| canonical | 0 | 20 | 2 | 5 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | 0 |
| suse | 5 | 18 | 4 | 10 | 4 | 0 | 0 | 0 | 0.0 | 8.6 | .0034 | +5 |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 4 | 3 | 8.3 | 8.8 | .0036 | +25 |
| cisco | 8 | 31 | 4 | 12 | 8 | 0 | 96 | 11 | 35.5 | 7.5 | .0056 | +6 |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | 0 |
| palo alto networks | 0 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | 0 |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | 0 |
| f5 | 0 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | 0 |
| ivanti | 0 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | -1 |
| fortinet | 0 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 44 | 197 | 36 | 79 | 70 | 11 | 40 | 1 | 0.5 | 7.3 | .0050 | +12 |
| mozilla | 3 | 59 | 12 | 18 | 29 | 0 | 13 | 0 | 0.0 | 7.3 | .0025 | -1 |
| gitlab | 0 | 33 | 0 | 5 | 21 | 5 | 4 | 2 | 6.1 | 4.4 | .0022 | 0 |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0026 | +1 |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | -2 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | -1 |
| adobe | 2 | 148 | 12 | 52 | 79 | 2 | 75 | 3 | 2.0 | 5.5 | .0021 | +2 |
| ibm | 0 | 124 | 36 | 42 | 46 | 0 | 7 | 0 | 0.0 | 7.5 | .0025 | -5 |
| progress | 2 | 11 | 1 | 9 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0035 | -3 |
| solarwinds | 0 | 7 | 1 | 2 | 2 | 0 | 11 | 4 | 57.1 | 7.5 | .0835 | -2 |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | 0 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 |
| d-link | 0 | 13 | 0 | 5 | 2 | 5 | 26 | 1 | 7.7 | 5.8 | .0059 | -5 |
| siemens | 0 | 9 | 0 | 4 | 5 | 0 | 1 | 0 | 0.0 | 6.9 | .0019 | -1 |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 27 | 98 | 0 | 0 | 52 | 46 | 0 | 0 | 0.0 | 5.5 | .0026 | +6 |
| dell | 20 | 76 | 1 | 34 | 38 | 2 | 2 | 1 | 1.3 | 6.7 | .0016 | +17 |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -2 |
| openclaw | 0 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | 0 |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| itsourcecode | 10 | 63 | 0 | 0 | 19 | 44 | 0 | 0 | 0.0 | 2.1 | .0020 | -9 |
| capgo | 0 | 61 | 2 | 31 | 27 | 1 | 0 | 0 | 0.0 | 7.1 | .0031 | 0 |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE-2026-48907 | .6883 | 99.3 | 10.0 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-50160 | 10.0 | .1775 | |
| CVE-2026-48276 | 10.0 | .0505 | |
| CVE-2026-13773 | 10.0 | .0341 | |
| CVE-2026-56413 | 10.0 | .0316 | |
| CVE-2026-56415 | 10.0 | .0315 |
| Vendor | CVEs |
|---|---|
| 654 | |
| linux | 517 |
| microsoft | 264 |
| oracle | 242 |
| adobe | 144 |
| apache | 133 |
| red hat | 128 |
| ibm | 70 |
| spring | 70 |
| capgo | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 68 |
| Packagist | 15 |
| npm | 6 |
| NuGet | 3 |
| PyPI | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1692 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1692 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1692 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1692 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1692 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1692 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1692 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1692 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1692 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1692 |
EXPLOIT PUBLISHED — CVE-2026-41516 (OP-TEE optee_os). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44936 (SUSE Rancher). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49297 (Apache Software Foundation Apache Airflow Google provider). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54059 (python-pillow Pillow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54060 (python-pillow Pillow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54234 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55379 (python-pillow Pillow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55380 (python-pillow Pillow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55798 (python-pillow Pillow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-57571 (unclecode crawl4ai). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58203 (pydantic-settings). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58380 (Red Hat Enterprise Linux 9). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59089 (Red Hat Enterprise Linux 6). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59194 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59195 (pnpm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59196 (pnpm). Public exploit reference added.
196 CVEs published. 25 box scores, 171 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L L 7.3 .0880 94.7 —
AFFECTED Product Versions Fixed Apache OpenNLP :: Core :: ML :: LibSVM 3.0.0-M1 – —
TIMELINE May 2 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0178 76.4 —
AFFECTED Product Versions Fixed Apache Camel 4.15.0 – —
TIMELINE Apr 8 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0175 75.9 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.469 – —
TIMELINE Mar 25 Reserved by CNA Jul 6 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0162 74.0 —
AFFECTED Product Versions Fixed firmware US_AC6V2.0RTL_V15.03.06.51_multi_T – — firmware US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 – — firmware US_AC10V1.0re_V15.03.06.46_multi_TDE01 – — firmware US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE – — firmware US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD – —
TIMELINE Jun 5 Reserved by CNA Jul 6 Published (CNA: certcc)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H N 10.0 .0160 73.7 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jul 6 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0135 69.2 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.471 – —
TIMELINE Mar 30 Reserved by CNA Jul 6 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0132 68.5 —
AFFECTED Product Versions Fixed create-react-app 5.0.0 – —
TIMELINE Jul 5 Reserved by CNA Jul 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0097 59.0 —
AFFECTED Product Versions Fixed Apache Camel 4.0.0 – —
TIMELINE May 4 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0094 58.1 —
AFFECTED Product Versions Fixed ArcGIS Server unspecified —
TIMELINE May 21 Reserved by CNA Jul 6 Published (CNA: Esri)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0090 56.8 —
AFFECTED Product Versions Fixed FileOrganizer unspecified — Advanced File Manager unspecified — File Manager Pro unspecified — File Manager unspecified —
TIMELINE Apr 15 Reserved by CNA Jul 6 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0089 56.5 —
AFFECTED Product Versions Fixed Apache Camel 4.18.0 – —
TIMELINE May 4 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0088 56.1 —
AFFECTED Product Versions Fixed Apache Camel 4.0.0 – —
TIMELINE Apr 15 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0078 53.0 —
AFFECTED Product Versions Fixed Apache Camel Vertx Websocket 4.0.0 – —
TIMELINE May 16 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0078 53.0 —
AFFECTED Product Versions Fixed Apache Camel Atmosphere Websocket 4.0.0 – —
TIMELINE Jun 18 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0075 51.8 —
AFFECTED Product Versions Fixed Apache Camel Keycloak 4.15.0 – —
TIMELINE Jun 11 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0071 50.7 —
AFFECTED Product Versions Fixed Apache Camel 4.18.0 – —
TIMELINE May 15 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0071 50.4 —
AFFECTED Product Versions Fixed Apache Camel 4.0.0 – —
TIMELINE May 14 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H H 8.1 .0070 50.0 —
AFFECTED Product Versions Fixed Apache Airflow Google provider unspecified —
TIMELINE May 28 Reserved by CNA Jul 6 Public exploit reference published Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0068 49.3 —
AFFECTED Product Versions Fixed Apache IoTDB 1.3.3 – —
TIMELINE Jan 20 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0067 49.2 —
AFFECTED Product Versions Fixed Remote Support unspecified — Privileged Remote Access unspecified —
TIMELINE Apr 9 Reserved by CNA Jul 6 Published (CNA: BT)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0064 47.8 —
AFFECTED Product Versions Fixed Apache Camel 4.0.0 – —
TIMELINE May 14 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0063 47.1 —
AFFECTED Product Versions Fixed Apache Camel 4.14.0 – —
TIMELINE Apr 28 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0062 46.9 —
AFFECTED Product Versions Fixed Apache Camel Iggy 4.17.0 – —
TIMELINE Jun 18 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L L 7.3 .0062 46.7 —
AFFECTED Product Versions Fixed Apache Camel 3.0.0 – — Apache Camel 3.0.0 – —
TIMELINE May 4 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H H 9.6 .0060 45.7 —
AFFECTED Product Versions Fixed crawl4ai < 0.9.0 – —
TIMELINE Jun 24 Reserved by CNA Jul 6 Public exploit reference published Jul 6 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-24014 | 9.8 | 45.1 | Apache Software Foundation | Apache IoTDB | CWE-284 | Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allo… |
| CVE-2026-46453 | 5.3 | 44.8 | Apache Software Foundation | Apache Camel | CWE-639 | Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants with… |
| CVE-2026-40140 | 8.7 | 44.7 | BeyondTrust | Remote Support | CWE-400 | High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support … |
| CVE-2026-49097 | 6.5 | 44.1 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header con… |
| CVE-2026-57572 | 10.0 | 42.6 | unclecode | crawl4ai | CWE-88 | Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in brows… |
| CVE-2026-49098 | 5.3 | 42.5 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Excha… |
| CVE-2026-56139 | 5.3 | 42.4 | Apache Software Foundation | Apache Camel Undertow | CWE-209 | Apache Camel Undertow: The muteException consumer option defaulted to false, … |
| CVE-2026-46587 | 7.3 | 42.1 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFil… |
| CVE-2026-46588 | 7.3 | 42.1 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilte… |
| CVE-2026-49042 | 7.3 | 42.1 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: langchain4j-tools: filter tool argument headers against declare… |
| CVE-2026-24013 | 9.1 | 41.9 | Apache Software Foundation | Apache IoTDB | CWE-290 | Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC |
| CVE-2026-49365 | 5.3 | 40.6 | Apache Software Foundation | Apache Camel | CWE-209 | Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted t… |
| CVE-2026-40141 | 8.5 | 40.2 | BeyondTrust | Remote Support | CWE-943 | High-Severity Vulnerability In Web Application Component of BeyondTrust Remot… |
| CVE-2026-14808 | 9.3 | 38.8 | PROG MIS | Prog Management System | CWE-497 | PROG MIS|Prog Management System - Exposure of Sensitive Information |
| CVE-2026-48204 | 9.8 | 37.5 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Cam… |
| CVE-2026-38976 | 7.5 | 37.1 | n/a | n/a | CWE-476 | mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/v… |
| CVE-2026-40138 | 9.2 | 36.7 | BeyondTrust | Remote Support | CWE-287 | Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and P… |
| CVE-2026-58226 | 8.7 | 36.5 | elixir-mint | hpax | CWE-407 | Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax |
| CVE-2026-11962 | 8.8 | 36.3 | Unknown | FileOrganizer | — | FileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File… |
| CVE-2026-14807 | 9.3 | 36.0 | PROG MIS | ERP App | CWE-798 | PROG MIS|ERP App - Use of Hard-coded Credentials |
| CVE-2026-56140 | 9.8 | 35.6 | Apache Software Foundation | Apache Camel AWS2 SNS | CWE-20 | Apache Camel AWS2 SNS: An inbound Camel-namespace filter was added to Sns2Hea… |
| CVE-2026-46455 | 9.8 | 35.5 | Apache Software Foundation | Apache Camel | CWE-613 | Apache Camel: Camel-Keycloak: The access-token validity window is not verifie… |
| CVE-2026-49086 | 6.5 | 35.5 | Apache Software Foundation | Apache Camel Dapr | CWE-20 | Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-n… |
| CVE-2026-46457 | 7.5 | 35.3 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Ex… |
| CVE-2026-55379 | 7.5 | 35.2 | python-pillow | Pillow | CWE-789 | Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check(… |
| CVE-2026-5268 | 9.1 | 35.0 | CIENA | 6500 S-Series | CWE-288 | SFTP Server Authentication Weakness |
| CVE-2026-53647 | 6.9 | 35.0 | FOSSBilling | FOSSBilling | CWE-200 | FOSSBilling vulnerable to unauthenticated API key configuration disclosure vi… |
| CVE-2026-14809 | 8.7 | 34.9 | PROG MIS | Prog Management System | CWE-89 | PROG MIS|Prog Management System - SQL Injection |
| CVE-2026-54060 | 7.5 | 34.9 | python-pillow | Pillow | CWE-789 | Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bo… |
| CVE-2026-55380 | 7.5 | 34.9 | python-pillow | Pillow | CWE-789 | Pillow GdImageFile decompression bomb protection bypass |
| CVE-2026-54059 | 7.5 | 34.1 | python-pillow | Pillow | CWE-789 | Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_de… |
| CVE-2026-34153 | 8.8 | 33.5 | coollabsio | coolify | CWE-78 | Coolify LocalFileVolume fs_path command injection enables RCE |
| CVE-2026-46585 | 7.5 | 33.1 | Apache Software Foundation | Apache Camel Lucene | CWE-20 | Apache Camel Lucene: The query control headers used non-Camel-prefixed names … |
| CVE-2026-13753 | 7.5 | 32.7 | HP Inc. | HP 2800 Printer Series | — | CVE-2026-13753 |
| CVE-2026-46592 | 7.5 | 32.8 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-… |
| CVE-2026-46584 | 3.7 | 32.3 | Apache Software Foundation | Apache Camel Mail | CWE-20 | Apache Camel Mail: The mail producer applied attacker-supplied message header… |
| CVE-2026-44937 | 8.3 | 31.4 | SUSE | Rancher | CWE-918 | SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsani… |
| CVE-2026-13708 | 7.5 | 30.6 | TONYC | Imager::File::JPEG | CWE-401 | Imager::File::JPEG versions before 1.003 for Perl leak heap memory when readi… |
| CVE-2026-48203 | 9.1 | 30.1 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefi… |
| CVE-2026-48205 | 9.1 | 30.1 | Apache Software Foundation | Apache Camel DNS | CWE-20 | Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel… |
| CVE-2026-55514 | 7.1 | 30.1 | vllm-project | vllm | CWE-617 | vLLM denial of service via prompt embeds on M-RoPE models |
| CVE-2026-14792 | 6.9 | 29.7 | n/a | Formbricks | CWE-266 | Formbricks Survey actions.ts access control |
| CVE-2026-54234 | 7.5 | 29.3 | vllm-project | vllm | CWE-20 | vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection |
| CVE-2025-53827 | 9.1 | 29.3 | owncloud | ownCloud Core | CWE-749 | ownCloud Core: Updater has an exposed dangerous method or function |
| CVE-2026-42153 | 8.8 | 29.0 | coollabsio | coolify | CWE-78 | Coolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution … |
| CVE-2026-42204 | 8.8 | 29.0 | coollabsio | coolify | CWE-78 | Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root |
| CVE-2026-9182 | 9.8 | 28.3 | Esri | ArcGIS Server | CWE-434 | Unvalidated File Upload vulnerability in ArcGIS Server. |
| CVE-2026-48206 | 5.3 | 28.0 | Apache Software Foundation | Apache Camel JIRA | CWE-20 | Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypa… |
| CVE-2026-56810 | 8.7 | 27.4 | elixir-mint | mint | CWE-770 | mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_… |
| CVE-2026-49099 | 5.3 | 27.1 | Apache Software Foundation | Apache Camel Salesforce | CWE-74 | Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass … |
| CVE-2026-4249 | 8.6 | 26.8 | WSO2 | WSO2 Universal Gateway | CWE-707 | Denial of Service via Malicious JSON Payloads in Throttling Events in Multipl… |
| CVE-2025-53829 | 8.0 | 26.4 | owncloud | ownCloud 10 | CWE-23 | ownCloud 10 is vulnerable to Relative Path Traversal |
| CVE-2026-14803 | 6.5 | 26.0 | SRI | Mojo::JSON | CWE-674 | Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounde… |
| CVE-2026-48614 | 9.9 | 25.9 | WebPros | Plesk | CWE-94 | An improper authorization vulnerability in the Plesk XML API allows an authen… |
| CVE-2026-44936 | 5.0 | 25.9 | SUSE | Rancher | CWE-918 | Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fl… |
| CVE-2026-46591 | 8.2 | 25.7 | Apache Software Foundation | Apache Camel | CWE-943 | Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProper… |
| CVE-2026-14471 | 8.6 | 25.3 | AWS | MCP Gateway & Registry | CWE-89 | Authenticated SQL injection in the metrics-service retention policy subsystem… |
| CVE-2026-55574 | 8.7 | 25.3 | vllm-project | vllm | CWE-1333 | vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar… |
| CVE-2026-14898 | 6.5 | 25.2 | OpenAI | Codex desktop app for macOS | CWE-200 | The OpenAI Codex desktop app for macOS rendered remote images from Markdown i… |
| CVE-2024-6228 | 7.5 | 24.6 | Unknown | Notifications for Forms & WordPress Actions | — | WANotifier < 2.6 - Subscriber+ LFI |
| CVE-2026-58403 | 5.9 | 24.6 | gohugoio | hugo | CWE-59 | Hugo symlink confinement bypass in os.ReadFile |
| CVE-2026-13698 | 6.0 | 24.1 | OpenVPN | OpenVPN | CWE-401 | A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 a… |
| CVE-2026-9165 | 7.7 | 23.8 | Red Hat | Red Hat Advanced Cluster Security 4.9 | CWE-400 | Stackrox: stackrox: unbounded graphql query depth allows authenticated denial… |
| CVE-2026-12686 | 9.3 | 23.6 | Adiss | Biloop | CWE-639 | Incorrect authorisation in Adiss’s Biloop |
| CVE-2026-41899 | 6.5 | 22.5 | coollabsio | coolify | CWE-306 | Coolify unauthenticated feedback endpoint allows Discord webhook abuse |
| CVE-2026-43925 | 6.9 | 22.4 | FOSSBilling | FOSSBilling | CWE-915 | FOSSBilling: Mass assignment of group_id in guest client registration allows … |
| CVE-2026-12083 | 8.1 | 22.0 | Unknown | Admin and Site Enhancements (ASE) | — | Admin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Rest… |
| CVE-2026-14468 | 7.7 | 22.1 | HashiCorp | Terraform Enterprise | CWE-22 | Path traversal allows arbitrary file read in Terraform Enterprise container |
| CVE-2026-13122 | 5.9 | 21.9 | Openvpn | OpenVPN | CWE-617 | OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remo… |
| CVE-2026-59196 | 7.1 | 21.9 | pnpm | pnpm | CWE-22 | pnpm: hoisted install imports lockfile alias outside node_modules |
| CVE-2026-7185 | 6.0 | 21.7 | T-Systems | Archivo | CWE-22 | Unauthorized access to files in T-Systems products |
| CVE-2026-55727 | 7.5 | 21.6 | Genetec Inc. | Genetec Security Center | CWE-287 | A flaw in the authentication mechanism for video stream requests in Genetec S… |
| CVE-2026-55646 | 6.5 | 21.4 | vllm-project | vllm | CWE-400 | vLLM speech-to-text endpoints allocate full upload before enforcing the audio… |
| CVE-2026-59195 | 8.2 | 21.2 | pnpm | pnpm | CWE-22 | pnpm: Path traversal in configDependencies env lockfile allows symlink creati… |
| CVE-2026-59194 | 7.1 | 21.2 | pnpm | pnpm | CWE-22 | pnpm: patch-remove could delete project-selected files outside the patches di… |
| CVE-2026-53641 | 4.8 | 21.1 | FOSSBilling | FOSSBilling | CWE-79 | FOSSBilling has stored XSS in client email views via unescaped content in Jav… |
| CVE-2026-11855 | 8.8 | 20.0 | Unknown | Simple Membership | — | Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API… |
| CVE-2026-54765 | 6.3 | 20.1 | traefik | traefik | CWE-284 | Traefik: Gateway HTTPRoute backendRef filters can leak backend context across… |
| CVE-2026-43921 | 8.9 | 19.8 | FOSSBilling | FOSSBilling | CWE-94 | FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config s… |
| CVE-2026-43928 | 2.3 | 19.8 | FOSSBilling | FOSSBilling | CWE-754 | FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoi… |
| CVE-2026-50135 | 6.9 | 19.4 | gohugoio | hugo | CWE-59 | Hugo: Symlink confinement bypass in resources.Get |
| CVE-2026-53648 | 5.1 | 18.4 | FOSSBilling | FOSSBilling | CWE-73 | FOSSBilling: Downloadable product files can be overwritten through filename c… |
| CVE-2026-57573 | 8.6 | 18.1 | unclecode | crawl4ai | CWE-918 | Crawl4AI unauthenticated SSRF in Docker streaming crawl endpoint |
| CVE-2025-53830 | 9.1 | 17.5 | owncloud | Anti-Virus for ownCloud | CWE-918 | Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2026-58380 | 7.8 | 17.5 | Red Hat | Red Hat Enterprise Linux 9 | CWE-193 | Gimp: gimp: stack buffer overflow in pnmscanner_gettoken() |
| CVE-2026-53644 | 8.6 | 16.7 | FOSSBilling | FOSSBilling | CWE-639 | FOSSBilling's missing order-state validation allows clients to read and reset… |
| CVE-2026-59712 | 8.6 | 16.6 | Leantime | Leantime | CWE-639 | Leantime - JSON-RPC API Broken Access Control via users.getUser |
| CVE-2026-50134 | 6.3 | 16.5 | gohugoio | hugo | CWE-918 | Hugo: security.http.urls allow-list bypass via HTTP redirects |
| CVE-2026-42331 | 7.7 | 16.3 | FOSSBilling | FOSSBilling | CWE-306 | FOSSBilling missing authorization in guest Invoice API endpoints |
| CVE-2026-59089 | 5.5 | 16.3 | Red Hat | Red Hat Enterprise Linux 6 | CWE-190 | Gimp: gimp: denial of service via integer overflow in playstation tim loader |
| CVE-2026-53645 | 8.5 | 15.4 | FOSSBilling | FOSSBilling | CWE-269 | FOSSBilling's missing self-edit prevention in staff permission management all… |
| CVE-2026-10830 | 8.8 | 15.3 | Unknown | AllCoach | — | AllCoach < 1.0.2 - Unauthenticated Account Takeover |
| CVE-2026-43918 | 8.7 | 14.7 | FOSSBilling | FOSSBilling | CWE-613 | Suspended or inactive FOSSBilling accounts can retain or regain access throug… |
| CVE-2026-54764 | 6.9 | 14.4 | traefik | traefik | CWE-345 | ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwar… |
| CVE-2025-53828 | 8.5 | 14.3 | owncloud | SharePoint | CWE-918 | SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2026-14536 | 8.8 | 14.2 | Devolutions | Server | CWE-863 | Improper enforcement of a mandatory multi-factor authentication policy in Dev… |
| CVE-2026-14784 | 5.3 | 13.8 | vxcontrol | PentAGI | CWE-264 | vxcontrol PentAGI Docker API client.go sandbox |
| CVE-2026-53643 | 8.7 | 13.6 | FOSSBilling | FOSSBilling | CWE-200 | FOSSBilling allows low-privileged staff accounts to perform unauthorized acti… |
| CVE-2026-11766 | 8.0 | 13.5 | Unknown | Ultimate Member | — | Ultimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile… |
| CVE-2026-53642 | 5.3 | 13.6 | FOSSBilling | FOSSBilling | CWE-863 | FOSSBilling: Unverified clients can access client-area pages when email confi… |
| CVE-2026-53640 | 2.3 | 13.6 | FOSSBilling | FOSSBilling | CWE-200 | FOSSBilling missing authorization checks on read-only admin API endpoints exp… |
| CVE-2026-14793 | 5.3 | 13.3 | Craft | CMS | CWE-285 | Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets autho… |
| CVE-2026-14794 | 5.3 | 13.0 | Craft | CMS | CWE-266 | Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper… |
| CVE-2026-43927 | 6.9 | 12.8 | FOSSBilling | FOSSBilling | CWE-367 | FOSSBilling has race condition in cart checkout that bypasses promo code usag… |
| CVE-2026-33734 | 6.9 | 12.5 | FOSSBilling | FOSSBilling | CWE-89 | FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters |
| CVE-2026-53646 | 7.7 | 12.1 | FOSSBilling | FOSSBilling | CWE-640 | FOSSBilling: Client password reset token reuse allows persistent account take… |
| CVE-2026-32718 | 6.5 | 11.9 | coollabsio | coolify | CWE-863 | Coolify read-scoped API tokens can perform state-changing validation operations |
| CVE-2026-34050 | 6.5 | 11.9 | coollabsio | coolify | CWE-862 | Coolify Settings/Updates Livewire component missing instance administrator au… |
| CVE-2026-54763 | 7.8 | 11.1 | traefik | traefik | CWE-178 | Traefik: headerField underscore-variant identity spoofing in BasicAuth / Dige… |
| CVE-2026-1433 | 4.8 | 11.2 | NT-ware | uniFLOW ULM (Universal Login Manager) Standalone | CWE-522 | uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensi… |
| CVE-2026-58404 | 4.6 | 11.2 | gohugoio | hugo | CWE-918 | Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings |
| CVE-2026-14796 | 2.1 | 10.7 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System report.php sql injection |
| CVE-2026-14799 | 2.1 | 10.7 | CodeAstro | Ecommerce Website | CWE-74 | CodeAstro Ecommerce Website my_account.php sql injection |
| CVE-2026-54291 | 8.2 | 10.5 | pgjdbc | pgjdbc | CWE-636 | Silent channel-binding authentication downgrade via unsupported certificate a… |
| CVE-2026-14791 | 2.0 | 10.5 | crater-invoice-inc | crater | CWE-79 | crater-invoice-inc crater Invoice Note InvoicesRequest.php getFormattedString… |
| CVE-2026-38979 | 5.4 | 10.1 | n/a | n/a | CWE-1021 | ajenti through v2.2.13 has a clickjacking weakness in the browser-facing logi… |
| CVE-2026-14795 | 2.1 | 10.2 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System action-visitor.php sql injection |
| CVE-2026-14797 | 2.1 | 10.2 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System edit-apartment.php sql injection |
| CVE-2026-14798 | 2.1 | 10.2 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System visitor-entry.php sql injection |
| CVE-2026-34167 | 5.0 | 10.1 | coollabsio | coolify | CWE-639 | Coolify: Cross-tenant activity log disclosure via unlocked Livewire property … |
| CVE-2026-59710 | 5.3 | 9.9 | showdown | showdown | CWE-79 | showdown - Stored XSS via Unescaped Table Header ID Attribute Injection |
| CVE-2026-34049 | 3.3 | 9.6 | coollabsio | coolify | CWE-78 | Coolify: Command Injection via unsanitized MongoDB collection names in databa… |
| CVE-2026-14789 | 1.9 | 9.0 | radareorg | radare2 | CWE-119 | radareorg radare2 Memory64ListStream mdmp.c stack-based overflow |
| CVE-2026-12154 | 6.4 | 8.7 | widgetpack | Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations | CWE-79 | Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Cont… |
| CVE-2026-59711 | 5.3 | 8.7 | showdown | showdown | CWE-79 | showdown - Cross-Site Scripting via Unescaped Metadata Title in completeHTMLD… |
| CVE-2026-50133 | 5.1 | 8.4 | gohugoio | hugo | CWE-79 | Hugo: XSS via text/html content files |
| CVE-2026-42341 | 9.2 | 8.3 | FOSSBilling | FOSSBilling | CWE-306 | FOSSBilling has an unauthenticated payment bypass via IPN callback forgery |
| CVE-2026-58203 | 5.3 | 7.8 | pydantic | pydantic-settings | CWE-22 | NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling lo… |
| CVE-2026-55798 | 4.5 | 7.6 | python-pillow | Pillow | CWE-78 | Pillow: WindowsViewer.get_command() OS command injection via unescaped shell … |
| CVE-2026-59152 | 5.0 | 7.1 | langchain-ai | langsmith-sdk | CWE-22 | Arbitrary server-side file read in LangSmith SDK TracingMiddleware |
| CVE-2026-58402 | 5.1 | 7.0 | gohugoio | hugo | CWE-79 | Hugo default code block renderer XSS via unescaped code-fence language |
| CVE-2026-14787 | 1.9 | 6.5 | radareorg | radare2 | CWE-189 | radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow |
| CVE-2026-14788 | 1.9 | 6.3 | radareorg | radare2 | CWE-119 | radareorg radare2 cfile.c r_core_bin_load use after free |
| CVE-2025-53831 | 8.2 | 6.0 | owncloud | DrawIO for ownCloud | CWE-79 | DrawIO for ownCloud 10 is vulnerable to Stored XSS |
| CVE-2025-8591 | 6.1 | 5.8 | WSO2 | WSO2 Identity Server | CWE-79 | Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products En… |
| CVE-2026-14800 | 2.1 | 5.5 | imhamzaazam | ecommerceFlask | CWE-352 | imhamzaazam ecommerceFlask cross-site request forgery |
| CVE-2026-14786 | 1.9 | 5.6 | radareorg | radare2 | CWE-189 | radareorg radare2 str.c r_str_word_get0set integer overflow |
| CVE-2026-38973 | 4.4 | 5.5 | n/a | n/a | CWE-125 | mrubyc through release3.4.1 was found to contain an out-of-bounds read in bui… |
| CVE-2026-59713 | 8.6 | 5.0 | Leantime | Leantime | CWE-352 | Leantime - OIDC Login CSRF via Unconditional State Verification Stub |
| CVE-2026-53763 | 3.8 | 4.6 | OP-TEE | optee_os | CWE-190 | OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks aut… |
| CVE-2026-54893 | 2.1 | 4.1 | swoosh | swoosh | CWE-116 | Email-derived URL path injection in the Swoosh Microsoft Graph adapter |
| CVE-2026-6900 | 9.1 | 4.1 | B&R Industrial Automation GmbH | APROL | CWE-295 | Improper Certificate Validation |
| CVE-2026-48267 | 5.5 | 3.8 | Adobe | DNG SDK | CWE-476 | DNG SDK | NULL Pointer Dereference (CWE-476) |
| CVE-2026-13705 | 7.1 | 3.5 | TONYC | Imager | CWE-125 | Imager versions before 1.032 for Perl have a heap out-of-bounds read in the b… |
| CVE-2026-41516 | 3.3 | 3.3 | OP-TEE | optee_os | CWE-208 | OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle |
| CVE-2026-13356 | 6.3 | 3.2 | Mozilla | Firefox for iOS | CWE-451 | Interrupted navigation could allow address bar origin spoofing in Firefox for… |
| CVE-2025-15668 | 1.9 | 2.6 | n/a | GPAC | CWE-119 | GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow |
| CVE-2026-44362 | 5.5 | 2.4 | OP-TEE | optee_os | CWE-285 | OP-TEE's subkey rollback protection can be bypassed with older subkey versions |
| CVE-2026-42148 | 3.8 | 2.2 | coollabsio | coolify | CWE-78 | Coolify: Command Injection via Unescaped Version String in Docker Build |
| CVE-2026-6901 | 8.4 | 2.2 | B&R Industrial Automation GmbH | APROL | CWE-426 | Untrusted Search Path |
| CVE-2026-14790 | 1.9 | 1.8 | n/a | GPAC | CWE-404 | GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference |
| CVE-2026-44934 | 7.0 | 1.8 | SUSE | Rancher | CWE-215 | Exposed tokens in SUSE Rancher AI Agent logs |
| CVE-2026-14801 | 4.8 | 1.6 | n/a | GPAC | CWE-369 | GPAC TeXML File load_text.c txtin_probe_duration divide by zero |
| CVE-2025-15667 | 1.9 | 1.6 | n/a | GPAC | CWE-119 | GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free |
| CVE-2024-56141 | 5.0 | 1.5 | Bixilon | Minosoft | CWE-329 | Minosoft has IV equal to key |
| CVE-2026-40257 | 5.5 | 1.4 | OP-TEE | optee_os | CWE-787 | OP-TEE has SHA-3 accelerated finalize heap overflow |
| CVE-2026-42546 | 3.8 | 1.2 | OP-TEE | optee_os | CWE-770 | OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj … |
| CVE-2026-41434 | 3.3 | 1.2 | OP-TEE | optee_os | CWE-121 | OP-TEE has unbounded recursion in sanitize_client_object() |
| CVE-2026-41514 | 3.3 | 0.8 | OP-TEE | optee_os | CWE-208 | OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext re… |
| CVE-2026-41515 | 3.3 | 0.7 | OP-TEE | optee_os | CWE-208 | OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery |
| CVE-2026-25268 | 8.8 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-121 | Stack-based Buffer Overflow in WLAN Host |
| CVE-2026-21379 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in Windows Compute |
| CVE-2026-21383 | 7.1 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-323 | Reusing a Nonce, Key Pair in Encryption in HLOS |
| CVE-2025-59617 | 7.3 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in Computer Vision |
| CVE-2025-59615 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in Computer Vision |
| CVE-2025-59616 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in Computer Vision |
| CVE-2026-21368 | 5.3 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-21369 | 5.3 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-21370 | 5.3 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-21384 | 5.3 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-25271 | 7.0 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-06 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.