boxscore/security
Wednesday, July 8, 2026 · all times UTC← 2026-07-07 · archive · 2026-07-09 →

362 CVEs published July 8, 2026: 26 critical, 170 high, 148 medium, 18 low; 0 in KEV; 45 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 337 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published16931401112542563
KEV catalog size1670

614 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux37151712086652812730.27.5.0013-38
google791343149604549387460.47.8.0023-482
microsoft52763585071774378283.77.8.0044+45
red hat31223129011011400.06.5.0026+9
apple0991236629377.16.5.00310
canonical1212685000.05.5.0011+1
suse61941140000.08.6.0036+6
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+25
cisco83141280961135.57.5.0056+6
netgear01700161800.04.3.00240
palo alto networks112027114216.75.3.0024+1
checkpoint0915303111.17.5.0410-2
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-1
fortinet08132028337.57.3.00660
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache51204387975114010.57.3.0049+5
mozilla35912182901300.07.3.0025-1
gitlab74005276425.04.7.0024+7
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
drupal0511305120.05.1.00260
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-1
adobe314913527927542.75.8.0021+3
ibm21263842460700.07.5.0025-3
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-2
veeam042200400.09.0.00460
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link01305252617.75.8.0059-8
siemens090450100.06.9.0019-1
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4
schneider electric060420100.07.8.00240
moxa050320000.07.0.00290
dahua030111200.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2798005246000.05.5.0026-8
dell2783338383211.26.8.0019+24
spring073231391000.06.5.0024-2
capgo768234311000.07.0.0030+7
openclaw1680362210000.07.0.0021+1
edimax065039026100.07.4.00590
itsourcecode1063001944000.02.1.0020-12
themerex26055410000.08.1.0043+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48907.688399.310.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
CVE-2026-4827610.0.0505
Most disclosures (vendor)
VendorCVEs
google608
linux476
microsoft266
oracle242
adobe145
red hat137
apache126
ibm72
spring70
capgo68
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
adobe4
solarwinds4
synacor4
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven69
Packagist13
PyPI6
npm6
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171694
CVE-2021-27102Accellion2021-11-171694
CVE-2021-27101Accellion2021-11-171694
CVE-2021-27103Accellion2021-11-171694
CVE-2021-21017Adobe2021-11-171694
CVE-2021-28550Adobe2021-11-171694
CVE-2021-42013Apache2021-11-171694
CVE-2021-41773Apache2021-11-171694
CVE-2021-30858Apple2021-11-171694
CVE-2021-30860Apple2021-11-171694

Transactions

EXPLOIT PUBLISHEDCVE-2026-15105 (davenardella snap7). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15164 (Wireshark Foundation ciscodump). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15165 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15166 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15167 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15168 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15169 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15170 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15171 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15172 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-24700. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44332 (gofiber fiber). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44512 (onnx). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45045 (gofiber fiber). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53624 (gofiber fiber). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54499 (stanfordnlp stanza). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54527 (jupyterlab-git). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54528 (jupyterlab-git). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55470 (hapifhir org.hl7.fhir.core). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55471 (hapifhir org.hl7.fhir.core). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55761 (portainer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56297 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58191 (appium). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59868 (nodeca js-yaml). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59869 (nodeca js-yaml). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59870 (nodeca js-yaml). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59871 (isaacs node-tar). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59873 (isaacs node-tar). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59874 (isaacs node-tar). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59879 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59880 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59890 (pypa setuptools). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59922 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59923 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59924 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59925 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59927 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59928 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59929 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59930 (lepture mistune). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59939 (httplib2). Public exploit reference added.

Yesterday's Results

362 CVEs published. 25 box scores, 337 table rows — nothing truncated.

Creative Themes Blocksy Companion — Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0195   78.5     —
AFFECTED
  Product            Versions     Fixed
  Blocksy Companion  unspecified  2.1.47
TIMELINE
  Jun 30  Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 4 references · NVD status: Deferred
Horde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb Driver
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    7.7   .0176   76.1     —
AFFECTED
  Product  Versions     Fixed
  Vfs      unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 4 references · NVD status: Deferred
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0155   72.9     —
AFFECTED
  Product  Versions  Fixed
  OpenLLM  0.6.30 –  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 8   Published (CNA: VulDB)
CWE-78, CWE-74, CWE-77 · CNA: VulDB · 7 references · NVD status: Analyzed
n/a n/a — An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0152   72.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 23  Reserved by CNA
  Jul 8   Public exploit reference published
  Jul 8   Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Analyzed
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0109   62.6     —
AFFECTED
  Product  Versions    Fixed
  fluentd  < 1.19.3 –  —
TIMELINE
  May 4   Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 4 references · NVD status: Analyzed
christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0107   62.0     —
AFFECTED
  Product                  Versions  Fixed
  check-peer-dependencies  4.3.0 –   —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 8   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
Palo Alto Networks Cloud NGFW — PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    7.2   .0096   58.5     —
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         12.1.0 –     12.1.8
  Prisma Access  11.2.0 –     11.2.7-h18
TIMELINE
  Nov 3   Reserved by CNA
  Jul 8   Published (CNA: palo_alto)
CWE-787 · CNA: palo_alto · 2 references · NVD status: Modified
n/a n/a — An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0096   58.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 23  Reserved by CNA
  Jul 8   Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Analyzed
n/a n/a — An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0096   58.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 23  Reserved by CNA
  Jul 8   Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Analyzed
n/a n/a — An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0096   58.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 23  Reserved by CNA
  Jul 8   Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Analyzed
joedolson My Calendar – Accessible Event Manager — My Calendar <= 3.7.8 - Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0095   58.4     —
AFFECTED
  Product                                 Versions     Fixed
  My Calendar – Accessible Event Manager  unspecified  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 2 references · NVD status: Deferred
tombgtn Simple Coherent Form — Simple Coherent Form <= 2.4.13 - Unauthenticated Arbitrary File Deletion via 'id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0074   51.7     —
AFFECTED
  Product               Versions     Fixed
  Simple Coherent Form  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 6 references · NVD status: Deferred
Jssor Slider by jssor.com <= 3.1.24 - Unauthenticated Arbitrary File Read via 'url' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0069   49.9     —
AFFECTED
  Product                    Versions     Fixed
  Jssor Slider by jssor.com  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 7 references · NVD status: Deferred
n/a n/a — An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.4     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 8   Published (CNA: mitre)
CWE-94 · CNA: mitre · 2 references · NVD status: Deferred
U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   H    8.8   .0056   43.8     —
AFFECTED
  Product  Versions     Fixed
  u-boot   unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-120 · CNA: VulnCheck · 6 references · NVD status: Modified
U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0055   43.5     —
AFFECTED
  Product  Versions     Fixed
  u-boot   unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-191 · CNA: VulnCheck · 4 references · NVD status: Analyzed
U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0055   43.3     —
AFFECTED
  Product  Versions     Fixed
  u-boot   unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-125 · CNA: VulnCheck · 4 references · NVD status: Analyzed
globalprogramming WHMCS Bridge — WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0054   43.2     —
AFFECTED
  Product       Versions     Fixed
  WHMCS Bridge  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 6 references · NVD status: Deferred
nats-io nats-server — NATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0050   40.9     —
AFFECTED
  Product      Versions     Fixed
  nats-server  < 2.12.12 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · 5 references · NVD status: Analyzed
nats-io nats-server — NATS Server: Pre-auth server crash via double INFO in leafnode handshake
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0050   40.9     —
AFFECTED
  Product      Versions     Fixed
  nats-server  < 2.11.17 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-476 · CNA: GitHub_M · 5 references · NVD status: Analyzed
totalbounty Widget Logic Visual — Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0050   40.6     —
AFFECTED
  Product              Versions     Fixed
  Widget Logic Visual  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 4 references · NVD status: Deferred
Progress MOVEit Transfer — Table scope bypass vulnerability in custom reports
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0050   40.3     —
AFFECTED
  Product          Versions    Fixed
  MOVEit Transfer  2025.0.0 –  —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 8   Published (CNA: ProgressSoftware)
CWE-943 · CNA: ProgressSoftware · 1 reference · NVD status: Analyzed
Monsta FTP < 2.14.5 SSRF via IPv4-Mapped IPv6 Address Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   N    7.7   .0047   39.0     —
AFFECTED
  Product     Versions     Fixed
  Monsta FTP  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-918 · CNA: VulnCheck · 3 references · NVD status: Deferred
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0047   38.6     —
AFFECTED
  Product  Versions             Fixed
  CoreWCF  >= 1.9.0, < 1.9.1 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-400, CWE-835 · CNA: GitHub_M · 6 references · NVD status: Deferred
open-telemetry opentelemetry-js — OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   37.7     —
AFFECTED
  Product           Versions   Fixed
  opentelemetry-js  < 2.9.0 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-248 · CNA: GitHub_M · 3 references · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-554707.537.0hapifhirorg.hl7.fhir.coreCWE-1333HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection all…
CVE-2026-498667.536.7libp2pjs-libp2pCWE-770libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
CVE-2026-600007.536.7OpenBSDOpenSSHCWE-770sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of serv…
CVE-2026-313099.836.6n/an/aCWE-862Improper authorization in the /tequilapi/config/user endpoint of Mysterium No…
CVE-2026-598798.736.5immutable-jsimmutable-jsCWE-190Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
CVE-2026-144958.836.2wpdo5eaDoLogin SecurityCWE-338DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insuffici…
CVE-2026-598808.736.0immutable-jsimmutable-jsCWE-407Immutable.js: Hash-collision algorithmic complexity denial of service in Immu…
CVE-2026-560028.835.7X.OrglibXfont2CWE-122libXfont2 PCF Font Parsing Heap Buffer Overflow
CVE-2026-598739.235.4isaacsnode-tarCWE-770node-tar: Decompression/parse DoS via unlimited input
CVE-2026-598697.535.3nodecajs-yamlCWE-407js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVE-2026-598748.734.9isaacsnode-tarCWE-835node-tar: Negative tar entry size causes infinite loop in archive replace
CVE-2026-599227.534.9lepturemistuneCWE-407Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `…
CVE-2026-557607.534.6jknackhandlebars.javaCWE-22handlebars.java FileTemplateLoader Path Traversal
CVE-2026-440257.534.5fluentfluentdCWE-306Fluentd: Exposure of Sensitive Information via Monitor Agent API
CVE-2026-599287.534.4lepturemistuneCWE-407Mistune block_parser: quadratic-time parsing on long lists of repeated refere…
CVE-2026-554048.834.4yt-dlpyt-dlpCWE-74yt-dlp: Downstream command injection via improper sanitization of yt-dlp --wr…
CVE-2026-443325.334.2gofiberfiberCWE-203Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
CVE-2026-598687.534.1nodecajs-yamlCWE-770js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVE-2026-598707.534.1nodecajs-yamlCWE-770js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
CVE-2026-598717.534.1isaacsnode-tarCWE-704node-tar: Process crash via PAX numeric path type confusion
CVE-2026-599257.534.1lepturemistuneCWE-407inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` e…
CVE-2026-599397.534.1httplib2httplib2CWE-409httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Res…
CVE-2026-598038.734.0smallnestrpcxCWE-409rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol
CVE-2026-557782.133.8parse-communityparse-serverCWE-434Parse Server: Stored XSS via non-standard file extension bypassing file uploa…
CVE-2026-598906.133.7pypasetuptoolsCWE-176setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization c…
CVE-2026-150537.533.5TaniumTanium ServerCWE-789Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-151128.833.3GoogleChromeCWE-416Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-599245.933.2lepturemistuneCWE-22Mistune: Arbitrary File Read via Include directive path traversal
CVE-2026-582076.532.9nats-ionats-serverCWE-190NATS Server: Remote crash via integer overflow in Connz pagination
CVE-2026-123788.132.1UnknownAppointment Booking Calendar Plugin and Scheduling PluginBookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
CVE-2026-68965.432.0GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-540619.131.9dgraph-iodgraphCWE-306Dgraph Alpha group stores can be replaced via unauthenticated external snapsh…
CVE-2026-597038.731.8repomixrepomixCWE-552repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint
CVE-2026-574812.331.8parse-communityparse-serverCWE-200Parse Server: LiveQuery discloses object data to a subscriber across an ACL r…
CVE-2026-121539.831.7rabilalWP Learn ManagerCWE-862WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrar…
CVE-2026-555758.231.5harttleliquidjsCWE-770LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filte…
CVE-2026-425055.331.4Go standard librarycrypto/tlsCWE-201Invoking Encrypted Client Hello privacy leak in crypto/tls
CVE-2026-560018.831.2X.OrglibXfont2CWE-122libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
CVE-2026-554718.730.8hapifhirorg.hl7.fhir.coreCWE-611HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon Transform…
CVE-2026-107067.530.7Adalo No-Code App BuilderApp BuilderExposure of Sensitive Information to an Unauthorized attacker
CVE-2026-491467.530.6PETDANCEApp::AckCWE-770App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbou…
CVE-2026-144549.830.5TONYCImagerCWE-196Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as…
CVE-2026-560038.830.5X.OrglibXfont2CWE-122libXfont2 computeProps Property Buffer Heap Buffer Overflow
CVE-2026-534827.530.3DellPowerProtect Data DomainCWE-190Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-150678.830.2SnowflakeTerraform Provider for SnowflakeCWE-89Multiple Security Vulnerabilities in Terraform Provider for Snowflake Could A…
CVE-2026-585258.230.1MicrosoftMicrosoft Edge (Chromium-based)CWE-284Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-598777.530.1protobufjsprotobuf.jsCWE-835protobufjs: Denial of Service via infinite loop in .proto option parsing
CVE-2026-352116.530.1OpenCTI-PlatformopenctiCWE-94OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter …
CVE-2026-448407.529.9dgraph-iodgraphCWE-943Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
CVE-2026-599358.729.8py-pdfpypdfCWE-835pypdf: Possible infinite loop for not terminated inline images (ASCII85 and A…
CVE-2026-151298.829.7GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-86507.529.6ProgressMOVEit TransferCWE-23Authenticated Path Traversal allows MOVEit admins to view arbitrary system files
CVE-2026-568439.929.5WebprosPleskCWE-522Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 …
CVE-2026-450455.329.4gofiberfiberCWE-290Fiber: X-Real-IP Spoofing via Header.Add() in BalancerForward
CVE-2026-545279.329.2jupyterlabjupyterlab-gitCWE-79JupyterLab Git: Stored XSS leading to RCE
CVE-2026-562978.329.2FreeRDPFreeRDPCWE-362FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback
CVE-2026-441607.529.1fluentfluentdCWE-409Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and…
CVE-2026-566697.528.9elysiajselysiaCWE-407Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict
CVE-2026-598212.128.6BerriAIlitellmCWE-94LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
CVE-2026-597257.528.5socketiosocket.ioCWE-404Socket.IO: Engine.IO Polling Transport Connection Exhaustion
CVE-2026-599275.328.2lepturemistuneCWE-674Mistune directives/include: mutual `.. include::` recursion crashes the rende…
CVE-2026-545287.128.1jupyterlabjupyterlab-gitCWE-178jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded…
CVE-2026-88019.827.5ProgressMOVEit TransferCWE-46File Extension Restriction Bypass in MOVEit Transfer
CVE-2026-96959.827.5Dassault SystèmesDELMIA AprisoCWE-287Improper Authentication vulnerability affecting DELMIA Apriso from Release 20…
CVE-2026-581928.627.5appiumappiumCWE-22Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-…
CVE-2026-544997.527.4stanfordnlpstanzaCWE-502Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
CVE-2026-598877.527.2markdown-itlinkify-itCWE-407linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on…
CVE-2026-582526.527.1nats-ionats-serverCWE-285NATS Server: Subscribe Authz Bypass via Wildcard-Overlap
CVE-2026-599368.727.0py-pdfpypdfCWE-400pypdf: Possible infinite loop for not terminated inline images
CVE-2026-106997.527.0ProgressMOVEit TransferCWE-401Memory leak in SFTP service can result in a denial of service in MOVEit Transfer
CVE-2026-599376.927.0py-pdfpypdfCWE-400pypdf: Possible long runtimes for repeated malformed cross-reference entries
CVE-2026-582516.526.9nats-ionats-serverCWE-285NATS Server: Queue Subscribe Authz Bypass
CVE-2026-597247.526.8socketiosocket.ioCWE-20Socket.IO: Engine.IO WebTransport SID DoS
CVE-2026-582087.526.6nats-ionats-serverCWE-248NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Serv…
CVE-2026-547756.526.5CoreWCFCoreWCFCWE-248CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-valu…
CVE-2026-574808.726.4parse-communityparse-serverCWE-407Parse Server: Denial of service via exponential-time processing of deeply nes…
CVE-2026-145005.326.1sayantandas20Bulk Order Update for WooCommerceCWE-22Bulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Rea…
CVE-2026-151328.826.1GoogleChromeCWE-457Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-133205.426.1GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-360276.826.0n/an/aCWE-1313An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proxi…
CVE-2026-562734.925.9FlowiseFlowiseCWE-22Flowise - Path Traversal in Vector Store basePath Parameter
CVE-2026-491457.525.8PETDANCEApp::AckCWE-73App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-fr…
CVE-2026-491477.525.8PETDANCEApp::AckCWE-150App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape s…
CVE-2026-558747.725.6seaweedfsseaweedfsCWE-22SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows c…
CVE-2026-597029.225.2repomixrepomixCWE-918repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST…
CVE-2026-582137.125.2nats-ionats-serverCWE-74NATS Server: MQTT SUBSCRIBE Protocol Injection via Leaf Node/Route Forwarding…
CVE-2026-598188.124.7etcd-ioetcdCWE-295etcd: gRPC client listener does not enforce `--client-crl-file` certificate r…
CVE-2026-144828.824.6shen2多说社会化评论框CWE-269多说社会化评论框 <= 1.2 - Unauthenticated Privilege Escalation via api.php 'option'/'…
CVE-2026-148918.724.4HashiCorpNomadCWE-59Nomad vulnerable to sandbox escape in Docker task driver
CVE-2026-560868.824.1DellPowerProtect Data DomainCWE-863Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-592575.324.2n8nn8nCWE-89n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpo…
CVE-2026-545918.124.0ronfasyncsshCWE-22AsyncSSH: SCP Path Traversal to Arbitrary File Write
CVE-2026-598206.124.1BerriAIlitellmCWE-22LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path T…
CVE-2026-441617.223.2fluentfluentdCWE-918Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out…
CVE-2026-151338.823.1GoogleChromeCWE-416Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 all…
CVE-2026-598228.822.9BerriAIlitellmCWE-287LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
CVE-2026-599386.922.9py-pdfpypdfCWE-789pypdf: Possible large memory usage for wrong image dimensions
CVE-2026-151546.522.8Red HatRed Hat OpenShift AI 2.25CWE-1333Guardrails-detectors: guardrails-detectors: unauthenticated regular-expressio…
CVE-2026-600029.422.5OpenBSDOpenSSHCWE-416ssh in OpenSSH before 10.4 can have a use-after-free when a server changes it…
CVE-2026-150413.722.6Red HatRed Hat Directory Server 11CWE-208389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 passw…
CVE-2026-151078.822.4GoogleChromeCWE-416Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed …
CVE-2026-151168.822.4GoogleChromeCWE-416Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-151188.822.4GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-151218.822.4GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a r…
CVE-2026-151268.822.4GoogleChromeCWE-416Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-598755.321.7isaacsnode-tarCWE-248node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
CVE-2026-557617.121.6portainerportainerCWE-287Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitia…
CVE-2026-600016.521.6OpenBSDOpenSSHCWE-770sshd in OpenSSH before 10.4 does not always honor the minimum authentication …
CVE-2026-149663.121.6Black Lantern SecurityBBOTCWE-59Symlink guard bypass in unarchive module allows planting symlinks during extr…
CVE-2026-598078.921.4ComposioHQcomposioCWE-73Composio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts
CVE-2026-151258.821.2GoogleChromeCWE-863Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.11…
CVE-2026-554298.721.2codercoderCWE-639Coder's workspace app upsert allows cross-workspace agent rebinding via user-…
CVE-2026-545905.921.1ronfasyncsshCWE-22AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and enviro…
CVE-2026-150629.621.0SnowflakeSnowpark Python SDKCWE-89SQL Injection in Snowflake Snowpark Python SDK
CVE-2026-410429.121.0Apache Software FoundationApache GravitinoCWE-20Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL …
CVE-2026-84724.321.0GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-97019.820.7joe007EventerCWE-289Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privi…
CVE-2026-90749.820.6IBMAPI ConnectCWE-89IBM API Connect SQL Injection
CVE-2026-119035.420.6ProgressMOVEit TransferCWE-79Stored XSS in MOVEit Transfer Ad Hoc module
CVE-2026-515357.520.3n/an/aCWE-400In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) v…
CVE-2026-355528.120.1n/an/aCWE-862In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0…
CVE-2026-476466.119.8MicrosoftDynamics 365 Customer VoiceCWE-79Dynamics 365 Customer Voice Spoofing Vulnerability
CVE-2026-62307.519.7tainacanTainacanCWE-89Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Par…
CVE-2026-97007.519.7joe007EventerCWE-89Eventer <= 4.4.2 - Unauthenticated SQL Injection via 'code' Parameter
CVE-2026-151096.519.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a…
CVE-2026-586568.719.5getgravgravCWE-598Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and J…
CVE-2026-559997.819.1X.Orgxorg-serverCWE-122xorg-server / xwayland glamor font atlas Heap Buffer Overflow
CVE-2026-556686.319.1filebrowserfilebrowserCWE-22File Browser: ScopedFs follows a dangling symlink on write, letting a scoped …
CVE-2026-151355.519.1code-projectsOnline Food Order SystemCWE-74code-projects Online Food Order System edit_food_items.php sql injection
CVE-2026-547795.919.0CoreWCFCoreWCFCWE-294CoreWCF: SAML token replay protection is inoperative
CVE-2026-597318.218.9withastroastroCWE-647Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path …
CVE-2026-585015.918.9mvantellingenpython-zeepCWE-918Zeep SSRF because Settings.forbid_external is not enforced
CVE-2026-83079.818.5Webbeyaz Web DesignMediküm WebCWE-89SQLi in Webbeyaz's Mediküm Web
CVE-2026-129364.918.8devitemsllcRecurio – Ultimate Subscription for WooCommerceCWE-89Recurio <= 1.1.3 - Authenticated (Shop Manager+) SQL Injection via 'data' Par…
CVE-2026-151052.118.5davenardellasnap7CWE-119davenardella snap7 ReadVar Request s7_server.cpp PerformFunctionRead out-of-b…
CVE-2026-63522.718.4GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-151345.518.2CodeAstroSimple Online Leave Management SystemCWE-74CodeAstro Simple Online Leave Management System index.php sql injection
CVE-2026-534802.718.2DellPowerProtect Data DomainCWE-22Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-586545.318.0GravGravCWE-434Grav - Arbitrary File Upload via Avatar Endpoint
CVE-2025-31106.917.8OpenVPNAccess ServerCWE-444OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences in…
CVE-2026-86499.817.7ProgressMOVEit TransferCWE-943Institution scope bypass vulnerability in custom reports
CVE-2026-562508.717.6CapgoCapgoCWE-862Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions
CVE-2026-598192.117.6BerriAIlitellmCWE-73LiteLLM: Local file read via request-supplied OIDC file references
CVE-2026-352107.117.5OpenCTI-PlatformopenctiCWE-639OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
CVE-2026-98427.517.3pixelgradeBackstage – Customizer Demo AccessCWE-269Backstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo…
CVE-2026-118274.917.3GitLabGitLabCWE-522Insufficiently Protected Credentials in GitLab
CVE-2026-582144.317.4nats-ionats-serverCWE-863NATS Server: MQTT subscribe ACL bypass via $MQTT.deliver.pubrel prefix (incom…
CVE-2026-151139.617.2GoogleChromeCWE-416Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.11…
CVE-2026-151238.817.2GoogleChromeCWE-122Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 …
CVE-2026-562268.717.2Cap-gocapgoCWE-200Capgo - Unauthenticated Organization Data Disclosure via get_orgs_v6 RPC
CVE-2026-120975.317.3saadiqbalUser ManagementCWE-862User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Sett…
CVE-2026-74925.317.1GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-581916.116.8appiumappiumCWE-79Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig*…
CVE-2026-143624.916.8HashiCorpShared libraryCWE-770Denial of service via crafted push/pull gossip message in memberlist
CVE-2026-582094.316.7nats-ionats-serverCWE-863NATS Server: MQTT retained and QoS replay bypass subscribe deny filters
CVE-2026-599955.416.6OpenBSDOpenSSHCWE-23sftp in OpenSSH before 10.4 does not properly constrain the location of downl…
CVE-2026-599965.416.6OpenBSDOpenSSHCWE-23scp in OpenSSH before 10.4 may place a file in the parent directory of an int…
CVE-2026-143737.716.4HashiCorpNomadCWE-862Nomad Docker driver Linux host namespace bypass
CVE-2026-598064.916.2gradio-appgradioCWE-601Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint
CVE-2026-5478210.016.2CoreWCFCoreWCFCWE-290CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature vali…
CVE-2026-151228.316.2GoogleChromeCWE-20Insufficient validation of untrusted input in Codecs in Google Chrome on Wind…
CVE-2026-555968.715.5udecodeplateCWE-79Plate: Media embed provider metadata can bypass URL sanitization and execute …
CVE-2026-599236.115.1lepturemistuneCWE-79Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
CVE-2026-592627.115.1affinemonorepoCWE-862AFFiNE - Unauthorized Document Edit History Access via GraphQL histories Field
CVE-2026-547735.915.1CoreWCFCoreWCFCWE-347CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVE-2026-150362.115.1n/aHarnessCWE-285Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization
CVE-2026-360286.814.9n/an/aCWE-288A protection mechanism failure in the Code 27 Companion Hub allows an attacke…
CVE-2026-68187.214.9e4jvikwpVikBooking Hotel Booking Engine & PMSCWE-79VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross…
CVE-2026-151148.814.7GoogleChromeCWE-125Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.1…
CVE-2026-31449.814.5IBMAPI ConnectCWE-1392IBM API Connect Default Credentials
CVE-2026-59225.914.5HP Inc.Poly CCXCWE-79Poly Voice – Potential Unauthorized Modification of WebUI using XSS Attack
CVE-2026-398227.814.3Go standard libraryosCWE-61Root escape via symlink plus trailing slash in os
CVE-2026-151208.314.2GoogleChromeCWE-416Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 al…
CVE-2026-546528.114.1blakeblackshearfrigateCWE-269Frigate viewer can read logs exposing admin and camera credentials
CVE-2026-151117.514.2GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-151177.514.2GoogleChromeCWE-416Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a…
CVE-2026-68207.213.9e4jvikwpVikBooking Hotel Booking Engine & PMSCWE-79VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross…
CVE-2026-62806.513.7NOMYSOFT Informatics Education and Consulting Inc.NomysemCWE-213Improper Access Control in Nomysoft Informatics' Nomysem
CVE-2026-484924.913.7grokabilitysnipe-itCWE-862Snipe-IT's selectlist visibility is too permissive
CVE-2026-582538.813.5nats-ionats-serverCWE-287NATS Server: Route API Auth Bypass
CVE-2026-558308.313.6zopefoundationRestrictedPythonCWE-184RestrictedPython guard hooks can be shadowed via positional-only arguments
CVE-2026-601049.313.4bitwardenserverCWE-639Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request
CVE-2026-151697.513.3Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-599296.113.4lepturemistuneCWE-79Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and cha…
CVE-2026-554335.413.2codercoderCWE-862Coder: Devcontainer recreate endpoint missing write authorization allows read…
CVE-2026-562467.213.1CapgoCapgoCWE-285Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege …
CVE-2026-560009.013.0X.Orgxorg-x11-serverCWE-416xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
CVE-2026-411227.113.0DellPowerProtect Data DomainCWE-79Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-150342.113.0flask-dashboardFlask-MonitoringDashboardCWE-352flask-dashboard Flask-MonitoringDashboard cross-site request forgery
CVE-2026-598057.112.8antiworkgumroadCWE-862Gumroad < 2026.07.06.2 - Insecure Direct Object Reference in PurchasesController
CVE-2026-601245.312.7mispmispCWE-862MISP importModule missing authorization allows read-only users to modify even…
CVE-2026-598764.812.7protobufjsprotobuf.jsCWE-1321protobufjs: Text Format string map parsing can mutate returned map object pro…
CVE-2026-572596.512.4Foxit Software Inc.Foxit PDF EditorCWE-611Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read
CVE-2026-586574.812.4GravGravCWE-79Grav - Stored CSS Injection via Markdown Image resize() Action
CVE-2026-151304.312.4GoogleChromeCWE-602Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0…
CVE-2026-151314.312.4GoogleChromeCWE-20Inappropriate implementation in Navigation in Google Chrome prior to 150.0.78…
CVE-2026-36888.112.3wcloversWCFM Membership – WooCommerce Memberships for Multivendor MarketplaceCWE-639WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object…
CVE-2026-86517.512.1ProgressMOVEit TransferCWE-290IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit T…
CVE-2026-562175.312.2CapgoCapgoCWE-284Capgo - Encrypted Bundle Policy Bypass via Direct PostgREST Update
CVE-2026-562846.912.0Cap-gocapgoCWE-200Capgo - Unauthenticated Metrics Disclosure via get_total_metrics RPC
CVE-2026-598047.611.9web-infra-devmidsceneCWE-306Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket
CVE-2026-151244.311.8GoogleChromeCWE-20Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.…
CVE-2026-88008.811.4ProgressMOVEit TransferCWE-863Cross-Org External Token Metadata accessible to AuditUser role
CVE-2026-551958.711.4miurahrpy7zrCWE-409py7zr: Decompression bomb (zip bomb) denial of service via unchecked extracti…
CVE-2026-552068.711.4miurahrpy7zrCWE-407py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
CVE-2026-53567.511.5latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-862LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Un…
CVE-2026-142506.311.3themehunkTH Login RegistrationCWE-269Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation …
CVE-2026-582115.411.1nats-ionats-serverCWE-863NATS Server: `no_auth_user` pre-CONNECT fast path bypasses user connection re…
CVE-2026-601255.311.1mispmispCWE-863importModule function in MISP ignores per-organisation import module restrict…
CVE-2026-117986.110.7the_champSocial Share, Social Login and Social Comments Plugin – Super SocializerCWE-79Social Share, Social Login and Social Comments Plugin <= 7.14.5 - Reflected C…
CVE-2026-562207.110.5CapgoCapgoCWE-863Capgo - Unauthorized Manifest Insertion via Read-Only Org Member
CVE-2026-600925.110.1AVideoAVideoCWE-79AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants…
CVE-2026-558734.310.1seaweedfsseaweedfsCWE-863SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management A…
CVE-2026-598956.19.9honojshonoCWE-79Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-149673.110.0Black Lantern SecurityBBOTCWE-22Path traversal in github_workflows allows writing artifacts outside output di…
CVE-2026-107087.59.7Adalo No-Code App BuilderApp BuilderInsufficiently Protected Credentials
CVE-2026-120414.49.3chatraChatra Live Chat + ChatBot + Cart SaverCWE-79Chatra Live Chat + ChatBot + Cart Saver <= 1.0.12 - Authenticated (Administra…
CVE-2026-592618.49.2OpenClawOpenClawCWE-522OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files
CVE-2026-598026.39.2PasswordPusherPasswordPusherCWE-183PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload
CVE-2026-598966.59.1honojshonoCWE-362hono/jsx does not isolate context per request, leading to cross-request data …
CVE-2026-558776.19.1symfonyuxCWE-79Symfony UX: XSS in symfony/ux-icons via unsanitized SVG content in local file…
CVE-2026-151198.39.0GoogleChromeCWE-362Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remot…
CVE-2026-539518.88.9copier-orgcopierCWE-22Copier: trust-prefix bypass via path traversal runs tasks unprompted
CVE-2026-599265.38.8lepturemistuneCWE-79Mistune: XSS via unescaped class option in Admonition directive
CVE-2026-563622.18.8ImageMagickImageMagickCWE-125ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache M…
CVE-2026-562985.38.6CapgoCapgoCWE-200Capgo - EXIF Metadata Exposure in App Information Image Upload
CVE-2025-125064.38.6GitLabGitLabCWE-706Use of Incorrectly-Resolved Name or Reference in GitLab
CVE-2026-598826.58.5guzzlepsr7CWE-436guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
CVE-2026-563606.38.4n8nn8nCWE-290n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger
CVE-2026-151637.58.3Wireshark FoundationWiresharkCWE-835Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
CVE-2026-150636.38.3Red HatRed Hat OpenShift AI (RHOAI)CWE-306Trustyai-service-operator: trustyai service operator: gorch port bypass when …
CVE-2026-151108.88.1GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed…
CVE-2026-554316.18.1codercoderCWE-522Coder's session token leaked to arbitrary hosts via `coder open app` for exte…
CVE-2026-445125.58.2onnxonnxCWE-476ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero In…
CVE-2026-54595.38.2wedevsUser Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User RegistrationCWE-639User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membersh…
CVE-2026-64596.48.0wpdevteamEssential Addons for Elementor – Popular Elementor Templates & WidgetsCWE-79Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cros…
CVE-2026-105706.48.0idocohSympl Repeater for ACF and ElementorCWE-79Sympl Repeater for ACF and Elementor <= 2.3 - Authenticated (Author+) Stored …
CVE-2026-554325.48.0codercoderCWE-862Coder's sub-agent app registration bypasses template port-sharing policy enfo…
CVE-2026-599986.57.8OpenBSDOpenSSHCWE-573sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: G…
CVE-2026-582545.37.8nats-ionats-serverCWE-863NATS Server: Incomplete fix for CVE-2026-33249: Leaf node connections bypass …
CVE-2026-554375.47.7codercoderCWE-79Coder vulnerable to stored HTML injection via workspace agent logs in AgentLo…
CVE-2026-547817.47.7CoreWCFCoreWCFCWE-287CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are no…
CVE-2026-536244.87.7gofiberfiberCWE-319Fiber: HSTS header never set in helmet middleware due to incorrect protocol c…
CVE-2026-567755.37.4n8nn8nCWE-863n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints
CVE-2026-547847.47.2CoreWCFCoreWCFCWE-311CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CVE-2026-599975.47.2OpenBSDOpenSSHCWE-1284internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 comm…
CVE-2026-567785.37.2n8nn8nCWE-863n8n - Authorization Bypass in Public API Execution Retry Endpoint
CVE-2026-151276.17.0GoogleChromeCWE-79Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.11…
CVE-2026-151286.17.0GoogleChromeCWE-79Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.11…
CVE-2026-555421.36.9grokabilitysnipe-itCWE-862Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
CVE-2026-151675.56.8Wireshark FoundationWiresharkCWE-121Stack-based Buffer Overflow in Wireshark
CVE-2026-543444.76.8ToolJetToolJetCWE-78ToolJet GitHub Actions comment body shell injection exposes deployment secrets
CVE-2026-229277.86.8OmnissaOmnissa Workspace ONE® Tunnel for WindowsCWE-22Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalat…
CVE-2026-572397.86.7Foxit Software Inc.Foxit PDF EditorCWE-427Foxit PDF Editor/Reader Local Privilege Escalation
CVE-2026-572607.86.8Foxit Software Inc.Foxit PDF EditorCWE-787Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompress…
CVE-2026-150446.36.7Red HatRed Hat OpenShift AI (RHOAI)CWE-200Trustyai-service-operator: trustyai service operator: unauthenticated access …
CVE-2026-592535.36.3n8nn8nCWE-639n8n - Improper Authorization in Workflow Assignment to Folders
CVE-2026-131267.86.1Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-558498.55.8CycloneDXcyclonedx-node-npmCWE-78@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` Argument
CVE-2026-567765.35.8n8nn8nCWE-863n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint
CVE-2026-554367.45.7codercoderCWE-295Coder's AI Bridge Proxy skips TLS certificate verification in default configu…
CVE-2026-148964.25.7HashiCorpNomadCWE-863Nomad vulnerable to cross-namespace host volume claim deletion
CVE-2026-599997.55.6OpenBSDOpenSSHCWE-348In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take pr…
CVE-2026-391786.35.4n/an/aCWE-89A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated user…
CVE-2026-391796.35.4n/an/aCWE-89A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated user…
CVE-2026-151655.55.4Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-151665.55.3Wireshark FoundationWiresharkCWE-121Stack-based Buffer Overflow in Wireshark
CVE-2026-151705.55.3Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-563744.85.4ImageMagickImageMagickCWE-125ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter
CVE-2026-547803.75.4CoreWCFCoreWCFCWE-327CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVE-2025-147856.44.8seedprodWebsite Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance ModeCWE-79Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soo…
CVE-2026-67406.44.8posimyththemesNexter Blocks – Gutenberg Blocks, Page Builder & AI Website BuilderCWE-79Nexter Blocks <= 4.7.4 - Authenticated (Contributor+) Stored Cross-Site Scrip…
CVE-2026-67426.44.8mdempfleAdvanced iFrameCWE-79Advanced iFrame <= 2026.1 - Authenticated (Contributor+) Stored Cross-Site Sc…
CVE-2026-547747.44.7CoreWCFCoreWCFCWE-345CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing t…
CVE-2026-554386.84.7codercoderCWE-346Coder's workspace app CORS origin check can be bypassed via UUID-based subdom…
CVE-2026-83106.14.6Webbeyaz Web DesignMediküm WebCWE-79Reflected XSS in Webbeyaz's Mediküm Web
CVE-2026-572467.84.5Foxit Software Inc.Foxit PDF EditorCWE-120Foxit PDF Editor/Reader Signature Buffer Overflow Vulnerability
CVE-2026-63714.84.6Limatek System Inc.LimRAD NACCWE-79Stored XSS in Limatek's LimRAD NAC
CVE-2026-151084.34.5GoogleChromeCWE-190Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 a…
CVE-2026-572487.84.5Foxit Software Inc.Foxit PDF EditorCWE-763Foxit PDF Editor/Reader Annotation Improper Release Vulnerability
CVE-2026-558787.84.4symfonyuxCWE-22Symfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and…
CVE-2026-597238.84.3clineclineCWE-346Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` en…
CVE-2026-547837.44.1CoreWCFCoreWCFCWE-294CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature…
CVE-2026-562935.34.1CapgoCapgoCWE-285Capgo - Stale Cross-Organization Authorization via Incomplete deploy_history …
CVE-2026-599466.14.0composercomposerCWE-22Composer: Path traversal in package bin field lets dependencies chmod arbitra…
CVE-2026-563594.84.0n8nn8nCWE-79n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL
CVE-2026-554306.83.9codercoderCWE-345Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Ho…
CVE-2026-59236.03.8HP Inc.Poly CCXCWE-352Poly Voice – Potential Unauthorized Modification of WebUI using CSRF Attack
CVE-2026-599487.03.6composercomposerCWE-22Composer: Arbitrary file write outside vendor via malicious transitive packag…
CVE-2026-562834.83.7CapgoCapgoCWE-79Capgo - HTML Injection Leading to Open Redirection in Organization Settings
CVE-2026-599304.33.7lepturemistuneCWE-345Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` …
CVE-2026-564378.43.4Fuji Electric Co.,Ltd.PupsmanCWE-427Uncontrolled search path element issue exists in Pupsman versions prior to 3.…
CVE-2026-83155.43.3Webbeyaz Web DesignMediküm WebCWE-79Stored XSS in Webbeyaz's Mediküm Web
CVE-2026-572407.82.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Form Field Use-After-Free Remote Code Execution Vulne…
CVE-2026-97314.32.9wpkufWp Js DetectCWE-352Wp Js Detect <= 1.0.9 - Cross-Site Request Forgery to Plugin Settings Update
CVE-2026-151683.32.9Wireshark FoundationWiresharkCWE-457Use of Uninitialized Variable in Wireshark
CVE-2026-572567.82.7Foxit Software Inc.Foxit PDF EditorCWE-416Foxit Editor/Reader List Box Format Use-After-Free Vulnerability
CVE-2026-598975.32.7honojshonoCWE-348Hono: API Gateway v1 adapter can drop a distinct repeated request header valu…
CVE-2026-151645.52.3Wireshark FoundationciscodumpCWE-122Heap-based Buffer Overflow in ciscodump
CVE-2026-151715.52.3Wireshark FoundationWiresharkCWE-476NULL Pointer Dereference in Wireshark
CVE-2026-151725.52.4Wireshark FoundationWiresharkCWE-606Unchecked Input for Loop Condition in Wireshark
CVE-2026-100378.82.2CanonicalUbuntuCWE-20Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal
CVE-2026-599474.72.2composercomposerCWE-532Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT …
CVE-2026-584946.52.1bytecodealliancewasmtimeCWE-281Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
CVE-2026-572517.82.0Foxit Software Inc.Foxit PDF EditorCWE-129Foxit PDF Editor/Reader Cloud Appearance Buffer Overflow Vulnerability
CVE-2026-598836.12.0guzzleguzzleCWE-346Guzzle: Cookie Disclosure and Injection via IP-Address Domains
CVE-2026-131277.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-131287.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Doc Object Use-After-Free Remote Code Execution Vulne…
CVE-2026-131297.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-572377.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-572387.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-572427.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Page Use-After-Free Vulnerability
CVE-2026-572447.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability
CVE-2026-572457.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Signature Hyperlink Use-After-Free Vulnerability
CVE-2026-572477.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Field Use-After-Free Vulnerability
CVE-2026-572497.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Vulnerability
CVE-2026-572507.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Form Field Use-After-Free Vulnerability
CVE-2026-572527.81.9Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnera…
CVE-2026-572547.81.9Foxit Software Inc.Foxit PDF EditorCWE-843Foxit PDF Editor/Reader Annotation Type Confusion Vulnerability
CVE-2026-572586.11.6Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
CVE-2026-508125.51.6n/an/aCWE-476A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 a…
CVE-2026-578958.51.4Fuji Electric Co.,Ltd.PupsmanCWE-276Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0…
CVE-2026-508136.11.5n/an/aCWE-126An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacke…
CVE-2026-572556.11.4Foxit Software Inc.Foxit PDF EditorCWE-125Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass C…
CVE-2026-547764.41.4CoreWCFCoreWCFCWE-306CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that …
CVE-2026-572416.11.3Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
CVE-2026-572436.11.3Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
CVE-2026-572536.11.3Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Discl…
CVE-2026-572576.11.3Foxit Software Inc.Foxit PDF EditorCWE-125Security vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap…
CVE-2026-143614.71.2HashiCorpToolingCWE-59Consul-template is vulnerable to path redirection in writeToFile through syml…
CVE-2026-120024.71.1smubSmash Balloon Social Photo Feed – Easy Social Feeds PluginCWE-352Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-…
CVE-2026-547786.21.0CoreWCFCoreWCFCWE-362CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVE-2026-151153.30.9GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-574395.00.7gchqCyberChefCWE-79CyberChef: Prototype pollution in Series Chart operation
CVE-2026-151745.50.6Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-151735.50.5Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-547776.50.5CoreWCFCoreWCFCWE-367CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe in…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-08 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.