boxscore/security
Tuesday, July 7, 2026 · all times UTC← 2026-07-06 · archive · 2026-07-08 →

170 CVEs published July 7, 2026: 25 critical, 70 high, 64 medium, 11 low; 4 in KEV; 7 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 145 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published13311364912522563
KEV catalog size1670

598 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux37151712086652812730.27.5.0013+3
google521316148586542377460.57.8.0023-436
microsoft50761585061764378283.77.8.0044+43
red hat27219129010710400.06.5.0026+8
apple0991236629377.16.5.00310
canonical0202585000.05.5.00110
suse61941140000.08.6.0036+6
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+25
cisco83141280961135.57.5.0056+6
netgear01700161800.04.3.00240
palo alto networks011017114218.24.8.00220
checkpoint0915303111.17.5.04100
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-1
fortinet08132028337.57.3.00660
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache50203377975114010.57.3.0049+18
mozilla35912182901300.07.3.0025-1
gitlab03305215426.14.4.00220
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
drupal0511305120.05.1.00260
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-1
adobe314913527927542.75.8.0021+3
ibm01243642460700.07.5.0025-5
progress2111910900.07.5.0035-3
solarwinds07122011457.17.5.0835-2
veeam042200400.09.0.00460
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link01305252617.75.8.0059-5
siemens090450100.06.9.0019-1
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4
schneider electric060420100.07.8.00240
moxa050320000.07.0.00290
dahua030111200.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2798005246000.05.5.0026+5
dell2379335382211.36.7.0018+20
spring073231391000.06.5.0024-2
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00590
itsourcecode1063001944000.02.1.0020-9
capgo061231271000.07.1.00310
themerex26055410000.08.1.0043+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-42271.830199.6
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
CVE-2026-4827610.0.0505
Most disclosures (vendor)
VendorCVEs
google654
linux517
microsoft264
oracle242
adobe145
apache139
red hat136
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
adobe4
solarwinds4
synacor4
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven68
Packagist15
npm7
PyPI6
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171693
CVE-2021-27102Accellion2021-11-171693
CVE-2021-27101Accellion2021-11-171693
CVE-2021-27103Accellion2021-11-171693
CVE-2021-21017Adobe2021-11-171693
CVE-2021-28550Adobe2021-11-171693
CVE-2021-42013Apache2021-11-171693
CVE-2021-41773Apache2021-11-171693
CVE-2021-30858Apple2021-11-171693
CVE-2021-30860Apple2021-11-171693

Transactions

EXPLOIT PUBLISHEDCVE-2026-10659 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49471 (oraios serena). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55255 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55490 (openwrt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56812 (phoenixframework phoenix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58384 (Red Hat Enterprise Linux 9). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58583 (FluxInk Color Management Driver). Public exploit reference added.

Yesterday's Results

170 CVEs published. 25 box scores, 145 table rows — nothing truncated.

Adobe ColdFusion — ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .9924   99.9   YES
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jul 7   Added to CISA KEV, due Jul 10
  Jul 7   Published (CNA: adobe)
CWE-22 · CNA: adobe · 2 references · NVD status: Analyzed · KEV due July 10, 2026
joomshaper.net SP Page Builder extension for Joomla — Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .8813   99.8   YES
AFFECTED
  Product                               Versions       Fixed
  SP Page Builder extension for Joomla  1.0.0-6.6.1 –  —
TIMELINE
  May 26  Reserved by CNA
  Jul 7   Added to CISA KEV, due Jul 10
  Jul 7   Published (CNA: Joomla)
CWE-434 · CNA: Joomla · 5 references · NVD status: Analyzed · KEV due July 10, 2026
joomlack.fr JoomlaCK.fr Page Builder CK extension for Joomla — Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .8325   99.7   YES
AFFECTED
  Product                                           Versions     Fixed
  JoomlaCK.fr Page Builder CK extension for Joomla  1.0-3.6.0 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jul 7   Public exploit reference published
  Jul 7   Added to CISA KEV, due Jul 10
  Jul 7   Published (CNA: Joomla)
CWE-434 · CNA: Joomla · 4 references · NVD status: Analyzed · KEV due July 10, 2026
langflow-ai langflow — Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  C  H  H  L    8.4   .2905   98.0   YES
AFFECTED
  Product   Versions   Fixed
  langflow  < 1.9.1 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 7   Public exploit reference published
  Jul 7   Added to CISA KEV, due Jul 10
  Jul 7   Published (CNA: GitHub_M)
CWE-639 · CNA: GitHub_M · 5 references · NVD status: Analyzed · KEV due July 10, 2026
Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0135   69.2     —
AFFECTED
  Product  Versions    Fixed
  coder    < 2.29.7 –  —
TIMELINE
  May 6   Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 7 references · NVD status: Analyzed
decolua 9router — 9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0134   68.9     —
AFFECTED
  Product  Versions     Fixed
  9router  unspecified  0.4.44
TIMELINE
  Jul 7   Reserved by CNA
  Jul 7   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Deferred
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0114   64.0     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 7   Published (CNA: dell)
CWE-78 · CNA: dell · 1 reference · NVD status: Analyzed
Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0107   62.1     —
AFFECTED
  Product     Versions     Fixed
  Vtiger CRM  unspecified  8.4.0
TIMELINE
  Jan 14  Reserved by CNA
  Jul 7   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 3 references · NVD status: Deferred
Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0099   59.7     —
AFFECTED
  Product         Versions     Fixed
  Apache Airflow  unspecified  —
TIMELINE
  Mar 18  Reserved by CNA
  Jul 7   Published (CNA: apache)
CWE-502 · CNA: apache · 4 references · NVD status: Analyzed
OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   N  U  N  N  H    6.5   .0099   59.5     —
AFFECTED
  Product  Versions     Fixed
  openwrt  < 25.12.5 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 7   Public exploit reference published
  Jul 7   Published (CNA: GitHub_M)
CWE-191 · CNA: GitHub_M · 3 references · NVD status: Analyzed
Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0087   55.7     —
AFFECTED
  Product     Versions     Fixed
  Vtiger CRM  unspecified  —
TIMELINE
  Jan 14  Reserved by CNA
  Jul 7   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 3 references · NVD status: Deferred
getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell — WPFunnels <= 3.12.7 - Unauthenticated Remote Code Execution via 'postData' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0075   51.8     —
AFFECTED
  Product                                                                      Versions     Fixed
  WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 7   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 11 references · NVD status: Deferred
Red Hat Red Hat Enterprise Linux 10 — Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  H  H  H    8.0   .0067   49.0     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:2.12.0-3.el10_2.1
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:2.10.2-3.el10_0.5
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.16.5-10.el7_9.18
  Red Hat Enterprise Linux 8                                             unspecified  0:2.9.4-5.el8_10.5
  Red Hat Enterprise Linux 8                                             unspecified  0:2.9.4-5.el8_10.5
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:2.4.0-9.el8_4.5
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:2.4.0-9.el8_4.5
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:2.6.2-4.el8_6.5
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:2.6.2-4.el8_6.5
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:2.8.2-4.el8_8.4
  + 10 more
TIMELINE
  Jul 2   Reserved by CNA
  Jul 7   Published (CNA: redhat)
CWE-23 · CNA: redhat · 16 references · NVD status: Awaiting Analysis
mohammed_kaludi AMP for WP – Accelerated Mobile Pages — AMP for WP <= 1.1.12 - Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0063   47.2     —
AFFECTED
  Product                                Versions     Fixed
  AMP for WP – Accelerated Mobile Pages  unspecified  —
TIMELINE
  Apr 10  Reserved by CNA
  Jul 7   Published (CNA: Wordfence)
CWE-73 · CNA: Wordfence · 10 references · NVD status: Deferred
389ds 389-ds-base — 389-ds-base: 389-ds-base: heap buffer overflow in sasl_io_recv() via padded sasl unbind
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0063   47.2     —
AFFECTED
  Product                                                Versions     Fixed
  389-ds-base                                            1.3.2 –      —
  Red Hat Directory Server 11.5 E4S for RHEL 8           unspecified  8060020260702180044.0ca98e7e
  Red Hat Directory Server 11.7 E4S for RHEL 8           unspecified  8080020260702180836.f969626e
  Red Hat Directory Server 11.9 for RHEL 8               unspecified  8100020260702145313.37ed7c03
  Red Hat Directory Server 12.2 E4S for RHEL 9           unspecified  9020020260703060155.1674d574
  Red Hat Directory Server 12.4 E4S for RHEL 9           unspecified  9040020260703055735.1674d574
  Red Hat Enterprise Linux 10                            unspecified  0:3.2.0-8.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support  unspecified  0:3.0.6-19.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support  unspecified  0:1.3.11.1-13.el7_9
  Red Hat Enterprise Linux 8                             unspecified  8100020260626120929.25e700aa
  + 14 more
TIMELINE
  Jun 8   Reserved by CNA
  Jul 7   Published (CNA: redhat)
CWE-122 · CNA: redhat · 19 references · NVD status: Awaiting Analysis
coollabsio coolify — Coolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team servers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0058   44.7     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.471 –  —
TIMELINE
  Mar 25  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-285, CWE-862 · CNA: GitHub_M · 3 references · NVD status: Deferred
Red Hat Red Hat Enterprise Linux 10 — Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0057   44.4     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:2.12.0-3.el10_2.1
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:2.10.2-3.el10_0.5
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.16.5-10.el7_9.18
  Red Hat Enterprise Linux 8                                             unspecified  0:2.9.4-5.el8_10.5
  Red Hat Enterprise Linux 8                                             unspecified  0:2.9.4-5.el8_10.5
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:2.4.0-9.el8_4.5
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:2.4.0-9.el8_4.5
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:2.6.2-4.el8_6.5
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:2.6.2-4.el8_6.5
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:2.8.2-4.el8_8.4
  + 10 more
TIMELINE
  Jul 2   Reserved by CNA
  Jul 7   Published (CNA: redhat)
CWE-1188 · CNA: redhat · 16 references · NVD status: Awaiting Analysis
coollabsio coolify — Coolify: PostgreSQL Init Script Path Traversal Leads to Arbitrary File Write and Root RCE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0054   43.0     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.474 –  —
TIMELINE
  Apr 25  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 4 references · NVD status: Deferred
phoenixframework phoenix — Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0051   41.0     —
AFFECTED
  Product  Versions                                    Fixed
  phoenix  1.2.0-rc.0 –                                —
  phoenix  1.2.0-rc.0 –                                —
  phoenix  2270aaf21bd02c6a6a1022820564efb605a97655 –  7f7b971c1ea0994e3fbd1c11ddb05e780bd38ad8
TIMELINE
  Jun 23  Reserved by CNA
  Jul 7   Public exploit reference published
  Jul 7   Published (CNA: EEF)
CWE-754 · CNA: EEF · 7 references · NVD status: Analyzed
DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0050   40.6     —
AFFECTED
  Product   Versions     Fixed
  dataease  < 2.10.24 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-434 · CNA: GitHub_M · 4 references · NVD status: Deferred
mem0 - OpenMemory API Unauthenticated Access via Memory Endpoints
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0050   40.4     —
AFFECTED
  Product  Versions     Fixed
  mem0     unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 7   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 4 references · NVD status: Deferred
HMBRAND DBI — DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0048   39.3     —
AFFECTED
  Product  Versions     Fixed
  DBI      unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 7   Published (CNA: CPANSec)
CWE-95 · CNA: CPANSec · 4 references · NVD status: Analyzed
coollabsio coolify — Coolify: WebSocket Endpoint Access Control Flaw Leading to Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0045   37.3     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.471 –  —
TIMELINE
  Mar 25  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-863 · CNA: GitHub_M · 4 references · NVD status: Deferred
BINGOS Module::Load — Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0045   37.2     —
AFFECTED
  Product       Versions     Fixed
  Module::Load  unspecified  —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 7   Published (CNA: CPANSec)
CWE-145 · CNA: CPANSec · 3 references · NVD status: Deferred
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0044   36.9     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 7   Published (CNA: dell)
CWE-22 · CNA: dell · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-421438.836.2coollabsiocoolifyCWE-78Coolify: OS Command Injection via Persistent Volume Names - Root RCE on Manag…
CVE-2026-130199.836.1EsriPortal for ArcGISCWE-640Missing Authentication
CVE-2026-568118.735.0phoenixframeworkphoenixCWE-770Phoenix transports do not limit channel joins per connection, enabling proces…
CVE-2026-488286.534.1Apache Software FoundationApache AirflowCWE-200Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact…
CVE-2026-488926.534.1Apache Software FoundationApache AirflowCWE-200Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypa…
CVE-2026-494876.534.1Apache Software FoundationApache AirflowCWE-200Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
CVE-2026-340348.833.5coollabsiocoolifyCWE-78Coolify: Host RCE via Sentinel token injection
CVE-2026-341688.833.5coollabsiocoolifyCWE-78Coolify: Command injection via unsanitized persistent storage name in docker …
CVE-2026-492966.533.1Apache Software FoundationApache AirflowCWE-639Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET…
CVE-2026-537518.732.8dataeasedataeaseCWE-94DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE)
CVE-2026-488914.332.4Apache Software FoundationApache AirflowCWE-200Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identi…
CVE-2026-147399.832.3HMBRANDDBICWE-787DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL s…
CVE-2026-537298.732.2dataeasedataeaseCWE-639DataEase ExportCenter IDOR allows cross-user export task access
CVE-2026-147409.131.8HMBRANDDBICWE-125DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse wh…
CVE-2026-148957.531.9BAKERSCOTString::UtilCWE-1333String::Util versions before 1.36 for Perl are susceptible to a regular expre…
CVE-2026-149047.131.3AWSresCWE-59RES Auth.GetUserPrivateKey Arbitrary File Read
CVE-2026-372709.830.6n/an/aCWE-287Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypa…
CVE-2026-578678.830.5MicroRealEstateMicroRealEstateCWE-288MicroRealEstate allows adversaries to bypass authentication due to a lack of …
CVE-2026-372719.830.4n/an/aCWE-287Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Imp…
CVE-2026-534839.830.3DellPowerProtect Data DomainCWE-287Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-584739.330.3topoteretescogneeCWE-306Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings
CVE-2026-341528.830.3coollabsiocoolifyCWE-78Coolify: Command Injection via Newline in Pre/Post Deployment Commands (Hered…
CVE-2026-578717.129.2MicroRealEstateMicroRealEstateCWE-23Relative path traversal vulnerability in MicroRealEstate file upload function…
CVE-2026-485882.329.2djangoprojectDjangoCWE-524Potential exposure of private data via cached Set-Cookie response
CVE-2026-597079.229.1LocalAILocalAICWE-918LocalAI - Server-Side Request Forgery via POST /models/apply
CVE-2026-449388.828.9SUSERancherCWE-522Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
CVE-2026-136968.828.6HAVELSAN Inc.Liman MYSCWE-90LDAP Injection in HAVELSAN's Liman MYS
CVE-2026-341588.828.5coollabsiocoolifyCWE-78Coolify: Command injection via single-quote breakout in Docker Compose custom…
CVE-2026-340588.828.2coollabsiocoolifyCWE-78Coolify: OS Command Injection via Unmanaged Container Operations - Remote Cod…
CVE-2026-584698.728.2gnuwgetwgetCWE-125GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing
CVE-2026-519377.528.0n/an/aCWE-306An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive infor…
CVE-2026-340578.827.8coollabsiocoolifyCWE-78Coolify: Authenticated Remote Code Execution via Command Injection in Databas…
CVE-2026-597088.727.3ghostfolioghostfolioCWE-862Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint
CVE-2026-340358.827.0coollabsiocoolifyCWE-78Coolify: Host RCE via Log Drain secret/env command injection
CVE-2026-550786.526.7codercoderCWE-409Coder: Zip upload decompression lacks aggregate size limit, enabling denial o…
CVE-2026-550777.226.5codercoderCWE-285Coder: User-admin role can reset owner account password
CVE-2026-550796.526.5codercoderCWE-789Coder's unbounded memory allocation in provisioner file upload allows authent…
CVE-2026-457966.526.4codercoderCWE-918Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint
CVE-2026-556317.224.0dataeasedataeaseCWE-22DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management
CVE-2026-550767.423.4codercoderCWE-287Coder's OIDC email_verified type coercion bypass enables account takeover via…
CVE-2026-554346.523.3codercoderCWE-770Coder vulnerable to denial of service via unbounded request body in AI Bridge…
CVE-2026-123759.822.9Unknownuncanny-automator-proUncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server
CVE-2026-546077.722.6labringFastGPTCWE-918FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (by…
CVE-2026-554188.622.4labringFastGPTCWE-639FastGPT: S3 presign/read handlers do not bind the object key to the caller's …
CVE-2026-340379.922.2coollabsiocoolifyCWE-639Cross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo()
CVE-2026-149405.321.9Red HatRed Hat Directory Server 11CWE-122389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted…
CVE-2026-494718.321.6oraiosserenaCWE-306Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding →…
CVE-2026-571728.321.4dataeasedataeaseCWE-321DataEase: Hardcoded JWT Signing Secret in ShareLink
CVE-2026-122778.721.2UnknownFrontend File Manager PluginFrontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletio…
CVE-2026-505298.721.0dataeasedataeaseCWE-863DataEase: Link Token Leakage Prior to Share Password/Ticket Validation
CVE-2026-550757.421.0codercoderCWE-287Coder vulnerable to OIDC account takeover via email-based user matching and e…
CVE-2026-538776.320.6djangoprojectDjangoCWE-805Heap buffer over-read in GDALRaster
CVE-2026-508116.520.3n/an/aCWE-125An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions be…
CVE-2026-448776.520.1Hewlett Packard Enterprise (HPE)HPE Networking Instant OnCWE-200Unauthenticated Remote Disclosure of Cryptographic Secrets
CVE-2026-556475.119.1dataeasedataeaseCWE-79DataEase: authenticated stored XSS in the dashboard text components
CVE-2026-129484.819.1Digi InternationalDigi PortServer TSCWE-79Stored Cross-Site Scripting (XSS)
CVE-2026-130209.818.6EsriPortal for ArcGISCWE-640Weak Password Recovery Mechanism in Portal for ArcGIS
CVE-2026-556358.718.5dataeasedataeaseCWE-89DataEase: Authenticated SQL Injection in Chart Quota Filters
CVE-2026-554278.318.8codercoderCWE-74Coder vulnerable to SSH config injection via unsanitized server-supplied valu…
CVE-2026-489586.418.1Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice…
CVE-2026-463549.117.8codercoderCWE-347Coder: PKCS#7 signature bypass in Azure instance identity allows unauthentica…
CVE-2026-597069.217.7mem0mem0CWE-306mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url
CVE-2026-123525.917.7Digi InternationalPortServer TS 1/2/4CWE-863Incorrect Authorization
CVE-2026-583847.817.5Red HatRed Hat Enterprise Linux 9CWE-190Gimp: gimp: integer overflow in read_rle_channel()
CVE-2026-70177.117.5HAARGHTTP::TinyCWE-522HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross…
CVE-2026-421474.917.3coollabsiocoolifyCWE-918Coolify: SSRF via S3 Storage Endpoint in testConnection()
CVE-2026-555923.917.2lissy93dashyCWE-79Dashy: XSS in workspace url parameter
CVE-2026-492298.316.9actualbudgetactualCWE-613Actual: Disabled OpenID users keep access through existing session tokens
CVE-2026-57997.516.8Idvlabs Software and Consulting Services Inc.OntimeCWE-639IDOR in Idvlabs' Ontime
CVE-2026-421453.116.6coollabsiocoolifyCWE-434Coolify: File Upload Without Type or Size Validation in Database Backup Restore
CVE-2026-554176.916.5cheveretocheveretoCWE-862Chevereto private profile setting leaks username on /json endpoint
CVE-2026-43759.016.4UnknownDoLeads IntegratorDoLeads Integrator <= 1.2.2 & wp2epub <= 0.65 - Unauthenticated RCE
CVE-2026-584706.916.2gnuwgetwgetCWE-190GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing
CVE-2025-127996.516.2Red HatRed Hat JBoss Enterprise Application Platform 8.1.7.GACWE-79Jastow: jastow cross-site scripting attack due to unsanitized uri
CVE-2026-554288.216.1codercoderCWE-285Coder: Route hijacking through lack of validation of agent-supplied AllowedIP…
CVE-2026-57307.516.2Idvlabs Software and Consulting Services Inc.OntimeCWE-639IDOR in Idvlabs' Ontime
CVE-2026-500077.216.1actualbudgetactualCWE-862Actual: Shared users can perform owner-only file management actions
CVE-2026-546016.316.1labringFastGPTCWE-915FastGPT: reTrainingCollection allows server-owned datasetId override causing …
CVE-2026-340447.715.8coollabsiocoolifyCWE-639Coolify: Cross-team IDOR in logs component (resource lookup not team-scoped)
CVE-2026-489486.415.4Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
CVE-2026-489576.415.4Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservic…
CVE-2026-505307.115.1dataeasedataeaseCWE-639DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshare…
CVE-2026-537308.714.7dataeasedataeaseCWE-862DataEase: Unauthorized Access to Engine Database via previewSql Endpoint
CVE-2026-578687.114.7MicroRealEstateMicroRealEstateCWE-639MicroRealEstate is affected by broken object-level access controls in PDF gen…
CVE-2026-113286.414.3timstriflerExclusive Addons for ElementorCWE-79Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stor…
CVE-2026-546027.113.7labringFastGPTCWE-639FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/r…
CVE-2026-277902.713.7GallagherT-20 ReadersCWE-248Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and a…
CVE-2026-278442.713.7GallagherController 7000 and 6000CWE-248Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagn…
CVE-2026-584716.012.9gnuwgetwgetCWE-122GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c
CVE-2026-584726.012.9gnuwgetwgetCWE-190GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding
CVE-2026-341493.312.9coollabsiocoolifyCWE-78Coolify: Authenticated Host-Level RCE via Unescaped Database Credentials in B…
CVE-2026-597047.112.3CapCapCWE-862Cap - Missing Access Control in Video AI Metadata Endpoint
CVE-2026-578697.112.2MicroRealEstateMicroRealEstateCWE-639Broken object-level access controls and the use of a deterministic pattern du…
CVE-2026-578705.312.2MicroRealEstateMicroRealEstateCWE-639Broken object-level access control on the Template API in MicroRealEstate all…
CVE-2026-539356.911.6ciliumciliumCWE-863CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traff…
CVE-2026-489556.411.2Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260709] - Incorrect Access Control in com_workflow
CVE-2026-538785.311.0djangoprojectDjangoCWE-144Header injection possibility since DomainNameValidator accepted newlines in i…
CVE-2026-597095.310.2GhostfolioGhostfolioCWE-862Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Perm…
CVE-2026-584685.110.2nocobasenocobaseCWE-918NocoBase 2.1.20 Server-Side Request Forgery via serverRequest wrapper
CVE-2026-467004.310.1actualbudgetactualCWE-285Actual: Missing authorization on GET /secret/:name allows non-admin OpenID us…
CVE-2026-83778.29.9Armiya Information Technologies Ltd. Co.Access Control System (GKS)CWE-862Improper Authorization in Armiya Technologies' Access Control System
CVE-2026-489476.49.8Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice …
CVE-2026-554355.49.6codercoderCWE-863Suspended Coder users retain access to AI Bridge LLM proxy endpoints
CVE-2026-113408.39.5HAVELSAN Inc.Liman MYSCWE-862Authorization Bypass in HAVELSAN's Open Source Project Liman MYS
CVE-2026-422013.39.6coollabsiocoolifyCWE-78Coolify: OS Command Injection via Database Credential Fields in Docker Compos…
CVE-2026-554088.48.7koodo-readerkoodo-readerCWE-94Koodo Reader: Remote code execution via malicious epub file
CVE-2026-421723.18.7coollabsiocoolifyCWE-613Coolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanen…
CVE-2026-113488.18.4HAVELSAN Inc.Liman MYSCWE-347Authentication Bypass in HAVELSAN's Open Source Project Liman MYS
CVE-2026-591532.17.7ankitectsankiCWE-346Anki's local HTTP server does not sufficiently validate requests
CVE-2026-501794.27.2actualbudgetactualCWE-1236Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes …
CVE-2026-546986.06.9hasuragraphql-engineCWE-863Hasura: Row-level authorization bypass on table computed fields
CVE-2026-341704.36.8coollabsiocoolifyCWE-918Coolify: Server-Side Request Forgery via attacker-controlled GitHub App API URL
CVE-2026-578518.56.7Micro-Star International (MSI)KernCoreLib64.sysCWE-782MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
CVE-2026-489566.46.5Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260710] - Incorrect Access Control in com_modules
CVE-2026-582666.56.3ankitectsankiCWE-346Anki: User scripts in iframes have access to the internal Anki API
CVE-2026-260535.34.9GallagherCommand Centre ServerCWE-266An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Cent…
CVE-2026-535118.54.8kovidgoyalcalibreCWE-94calibre: Arbitrary Code Execution in Template Formatter via Book Metadata
CVE-2026-149353.74.7Red HatRed Hat Enterprise Linux 10CWE-670Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due …
CVE-2026-73806.14.6Armiya Information Technologies Ltd. Co.Access Control System (GKS)CWE-80HTML Injection in Armiya Technologies' Access Control System
CVE-2026-83066.14.6Armiya Information Technologies Ltd. Co.Access Control System (GKS)CWE-79Stored XSS in Armiya Technologies' Access Control System
CVE-2026-489495.94.5Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260703] - XSS in MFA method management
CVE-2026-489505.94.4Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260704] - XSS in com_templates
CVE-2026-489515.94.4Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260705] - XSS in various modalreturn layouts
CVE-2026-489525.94.5Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260706] - XSS in com_installer
CVE-2026-489535.94.4Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260707] - XSS in the generic image output layout
CVE-2026-489545.94.5Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260708] - XSS through language overrides
CVE-2026-341718.04.4coollabsiocoolifyCWE-352Coolify: Account takeover via CSRF-able GET endpoint that resets password to …
CVE-2026-108344.64.0UnknownWP Travel EngineWP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_pro…
CVE-2026-361625.43.9n/an/aCWE-79An authenticated stored cross-site scripting (XSS) vulnerability in the Uploa…
CVE-2026-361635.43.9n/an/aCWE-79An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2…
CVE-2026-429538.43.9LabcenterProteusCWE-787Out-of-bounds write in Labcenter Proteus
CVE-2026-341985.33.8coollabsiocoolifyCWE-346Coolify: Password reset link poisoning via X-Forwarded-Host header spoofing
CVE-2026-283782.73.5GrafanaGrafana EnterpriseCWE-284Cross-Organization Public Dashboard Deletion via Missing Org Isolation
CVE-2026-106594.73.4zephyrprojectzephyrCWE-476NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error …
CVE-2026-83095.43.3Armiya Information Technologies Ltd. Co.Access Control System (GKS)CWE-79Reflected XSS in Armiya Technologies' Access Control System
CVE-2026-466724.63.2actualbudgetactualCWE-1236Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via …
CVE-2026-490338.43.1LabcenterProteusCWE-121Stack-Based Buffer Overflow in Labcenter Proteus
CVE-2026-429588.42.9LabcenterProteusCWE-416Use After Free in Labcenter Proteus
CVE-2026-508105.52.3n/an/aCWE-476A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/…
CVE-2026-131995.11.8Raspberry PiRaspberry Pi 5 and Compute Module 5CWE-331Insufficient Entropy in Raspberry Pi 5 and Compute Module 5
CVE-2026-583155.11.1SEIKO EPSON CORPORATIONWeb ConfigCWE-352Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If…
CVE-2026-585838.41.1FluxInkColor Management DriverCWE-269FluxInk Color Management Driver local privilege escalation
CVE-2026-148676.80.6arcinfoPcVueCWE-256Insecure password storage in User directory
CVE-2026-149694.40.1Red HatRed Hat Directory Server 11CWE-329389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc at…
CVE-2026-148688.40.0arcinfoPcVueCWE-326Weak encryption mechanism for User directory

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-07 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.