boxscore/security
Thursday, July 9, 2026 · all times UTC← 2026-07-08 · archive · 2026-07-10 →

276 CVEs published July 9, 2026: 33 critical, 103 high, 115 medium, 24 low; 0 in KEV; 16 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 251 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published19691428712672563
KEV catalog size1670

645 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux37151712086652812730.27.5.0013-59
google791343149604549387460.47.8.0023-483
microsoft52763585071774378283.77.8.0044-155
red hat33225129211011400.06.5.0026+2
apple0991236629377.16.5.00310
canonical1212685000.05.5.0011+1
suse61941140000.08.6.0036+6
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+25
cisco83141280961135.57.5.0056+5
palo alto networks1425021471428.04.7.0021+14
netgear01700161800.04.3.0024-17
checkpoint0915303111.17.5.0410-2
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-3
fortinet08132028337.57.3.0066-2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache52205388075114010.57.3.0049-1
mozilla35912182901300.07.3.0025-2
gitlab74005276425.04.7.0024+7
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
drupal0511305120.05.1.00260
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-2
adobe314913527927542.75.8.0021-120
ibm21263842460700.07.5.0025-3
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-3
veeam042200400.09.0.0046-1
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link11405352617.16.0.0058-7
siemens4130760100.07.1.0019-3
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4
schneider electric060420100.07.8.0024-1
moxa050320000.07.0.00290
dahua030111200.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2899005346000.05.5.0026-7
dell2783338383211.26.8.0019+20
spring073231391000.06.5.0024-53
capgo768234311000.07.0.0030+7
openclaw1680362210000.07.0.0021+1
edimax065039026100.07.4.00590
itsourcecode1063001944000.02.1.0020-12
themerex26055410000.08.1.0043+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48907.688399.310.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
CVE-2026-4827610.0.0505
Most disclosures (vendor)
VendorCVEs
google607
linux455
oracle241
red hat130
apache120
ibm72
capgo68
microsoft66
openclaw62
themerex60
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
adobe4
solarwinds4
synacor4
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven70
npm6
PyPI5
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-35273Oracle Corporation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171695
CVE-2021-27102Accellion2021-11-171695
CVE-2021-27101Accellion2021-11-171695
CVE-2021-27103Accellion2021-11-171695
CVE-2021-21017Adobe2021-11-171695
CVE-2021-28550Adobe2021-11-171695
CVE-2021-42013Apache2021-11-171695
CVE-2021-41773Apache2021-11-171695
CVE-2021-30858Apple2021-11-171695
CVE-2021-30860Apple2021-11-171695

Transactions

EXPLOIT PUBLISHEDCVE-2026-39243. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-39245. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-39246. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54695 (pipecat-ai pipecat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56292 (acymailing.com AcyMailing extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58459 (ntpsec gpsd). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59212 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59213 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59217 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59219 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59220 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59221 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59222 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59227 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59715 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59856 (vim). Public exploit reference added.

Yesterday's Results

276 CVEs published. 25 box scores, 251 table rows — nothing truncated.

ntpsec gpsd — gpsd gpsprof Command Injection via gnuplot plot title subtype field
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   A   H   H   H    8.4   .0180   76.6     —
AFFECTED
  Product  Versions     Fixed
  gpsd     unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 9   Public exploit reference published
  Jul 9   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 5 references · NVD status: Analyzed
Palo Alto Networks Cloud NGFW — PAN-OS: Authenticated Command Injection in CLI
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   N    6.0   .0116   64.5     —
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         12.1.0 –     12.1.8
  Prisma Access  unspecified  All
TIMELINE
  Nov 3   Reserved by CNA
  Jul 9   Published (CNA: palo_alto)
CWE-78 · CNA: palo_alto · 2 references · NVD status: Modified
nesquena hermes-webui — Hermes WebUI < 0.51.788 Unauthenticated RCE via Terminal API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0093   57.6     —
AFFECTED
  Product       Versions     Fixed
  hermes-webui  unspecified  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 9   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 4 references · NVD status: Deferred
Xerte Xerte Online Tools — CVE-2026-14261
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0085   55.1     —
AFFECTED
  Product             Versions     Fixed
  Xerte Online Tools  unspecified  —
  Xerte Online Tools  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 9   Published (CNA: certcc)
CNA: certcc · 3 references · NVD status: Deferred
LibreBooking path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0084   54.9     —
AFFECTED
  Product       Versions     Fixed
  LibreBooking  unspecified  5.1.0
TIMELINE
  Jul 8   Reserved by CNA
  Jul 9   Published (CNA: cisa-cg)
CWE-23 · CNA: cisa-cg · 5 references · NVD status: Awaiting Analysis
Metabase: Unsafe Deserialization of H2 Query Results
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0079   53.3     —
AFFECTED
  Product   Versions                Fixed
  metabase  >= 1.58.0, < 1.58.15 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · 6 references · NVD status: Analyzed
getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell — WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0069   49.8     —
AFFECTED
  Product                                                                      Versions     Fixed
  WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell  unspecified  —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · 10 references · NVD status: Deferred
AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0068   49.5     —
AFFECTED
  Product           Versions  Fixed
  openclaw-android  0.1 –     —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 9   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 7 references · NVD status: Deferred
bitpressadmin Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder — Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  H    7.1   .0067   49.0     —
AFFECTED
  Product                                                                                     Versions     Fixed
  Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 13 references · NVD status: Deferred
danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder — Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0064   47.7     —
AFFECTED
  Product                                                                                         Versions     Fixed
  Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 12 references · NVD status: Deferred
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0064   47.7     —
AFFECTED
  Product   Versions    Fixed
  langroid  < 0.65.2 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Python Software Foundation CPython — Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0064   47.6     —
AFFECTED
  Product  Versions     Fixed
  CPython  unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 9   Published (CNA: PSF)
CWE-400 · CNA: PSF · 11 references · NVD status: Modified
creativethemeshq Blocksy Companion — Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0061   46.4     —
AFFECTED
  Product            Versions     Fixed
  Blocksy Companion  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 3 references · NVD status: Deferred
cyberlord92 miniOrange OTP Login, Verification and SMS Notifications — miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account Takeover via 'username_b' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0059   45.3     —
AFFECTED
  Product                                                   Versions     Fixed
  miniOrange OTP Login, Verification and SMS Notifications  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 10 references · NVD status: Deferred
Red Hat Red Hat Enterprise Linux 10 — Gstreamer: gstreamer: dtls certificate subject dn stack buffer overflow in openssl_verify_callback
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0058   44.8     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:1.26.7-2.el10_2.6
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:1.24.11-3.el10_0.6
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.10.4-7.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  0:1.16.1-9.el8_10.1
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:1.16.1-4.el8_6.4
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:1.16.1-4.el8_6.4
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:1.16.1-4.el8_8.4
  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions         unspecified  0:1.16.1-4.el8_8.4
  Red Hat Enterprise Linux 9                                             unspecified  0:1.22.12-7.el9_8.3
  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions         unspecified  0:1.22.1-6.el9_4.6
  + 3 more
TIMELINE
  Jul 6   Reserved by CNA
  Jul 9   Published (CNA: redhat)
CWE-121 · CNA: redhat · 13 references · NVD status: Awaiting Analysis
mettle sendportal APIv1 Webhooks mailjet missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    5.5   .0057   44.6     —
AFFECTED
  Product     Versions  Fixed
  sendportal  3.0.0 –   —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 9   Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · 6 references · NVD status: Deferred
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0057   44.4     —
AFFECTED
  Product   Versions    Fixed
  langroid  < 0.64.0 –  —
TIMELINE
  Jun 3   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-22, CWE-89 · CNA: GitHub_M · 2 references · NVD status: Deferred
Xerte Xerte Online Tools — CVE-2026-12116
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0057   44.3     —
AFFECTED
  Product             Versions     Fixed
  Xerte Online Tools  unspecified  —
  Xerte Online Tools  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Jul 9   Published (CNA: certcc)
CNA: certcc · 3 references · NVD status: Deferred
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0056   43.9     —
AFFECTED
  Product   Versions    Fixed
  langroid  < 0.65.1 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-22, CWE-89 · CNA: GitHub_M · 1 reference · NVD status: Deferred
n/a n/a — decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlin…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0056   43.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 9   Public exploit reference published
  Jul 9   Published (CNA: mitre)
CWE-59 · CNA: mitre · 3 references · NVD status: Analyzed
getkirby kirby — Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   N    9.1   .0054   43.2     —
AFFECTED
  Product  Versions   Fixed
  kirby    < 4.9.4 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-454 · CNA: GitHub_M · 8 references · NVD status: Deferred
Metabase: Arbitrary Code Execution via Database Connection Detail Bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0054   42.9     —
AFFECTED
  Product   Versions                  Fixed
  metabase  >= 1.55.0, < 1.58.15.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 6 references · NVD status: Analyzed
coollabsio coolify — Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0052   42.0     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.469 –  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 4 references · NVD status: Deferred
Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0052   41.7     —
AFFECTED
  Product     Versions      Fixed
  hoppscotch  < 2026.6.0 –  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-77, CWE-78, CWE-915 · CNA: GitHub_M · 4 references · NVD status: Deferred
stiofansisland UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP — UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0051   41.2     —
AFFECTED
  Product                                                                                            Versions     Fixed
  UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP  unspecified  —
TIMELINE
  Jun 27  Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 8 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-601098.740.7zeekzeekCWE-476Zeek < 8.0.9 Null Pointer Dereference DoS via Kerberos KRB_ERROR Parsing
CVE-2026-539639.040.5discoursediscourseCWE-79Discourse: Stored-XSS in 2FA delete confirmation modal
CVE-2026-152045.539.9TOTOLINKX5000RCWE-22TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
CVE-2026-5972610.039.3ruvnetrufloCWE-78Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
CVE-2026-457886.338.4discoursediscourseCWE-200Discourse: Secure uploads exposed by hotlinked image copying
CVE-2026-600956.938.2VinchinBackup & Recovery 9.0CWE-121Vinchin Backup & Recovery 9.0.0.86562 Stack Buffer Overflow via ModuleHandShake
CVE-2026-152706.836.8D-linkDIR-823GCWE-266D-link DIR-823G Web boa.conf least privilege violation
CVE-2026-601088.736.3zeekzeekCWE-770Zeek < 8.0.9 Uncontrolled Memory Consumption DoS via FTP Analyzer
CVE-2026-515999.836.0n/an/aCWE-20An insufficient input validation vulnerability in the RTSP service of MERCURY…
CVE-2026-380767.536.0n/an/aCWE-190An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex com…
CVE-2026-134619.635.8PayRangePayRangePayRange version 7.0.7 contains a JavaScript injection vulnerability
CVE-2026-556055.335.8arikusideepseek-mcp-serverCWE-306@arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP E…
CVE-2026-125978.135.2LoginPressLoginPress ProCWE-287LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverifie…
CVE-2026-516037.534.2n/an/aCWE-121A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 …
CVE-2026-600946.934.2VinchinBackup & Recovery 9.0CWE-787Vinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_server
CVE-2026-516017.534.1n/an/aCWE-121Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in …
CVE-2026-516047.534.1n/an/aCWE-121A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 …
CVE-2026-516057.534.1n/an/aCWE-121A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 …
CVE-2026-540028.534.1getkirbykirbyCWE-79Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `D…
CVE-2026-134505.334.0rubengcGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-639GamiPress <= 7.9.4 - Insecure Direct Object Reference to Unauthenticated Sens…
CVE-2026-152717.733.9TOTOLINKA3000RUCWE-266TOTOLINK EX200 Web boa.conf least privilege violation
CVE-2026-516007.533.6n/an/aCWE-400Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length heade…
CVE-2026-516027.533.4n/an/aCWE-121A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 …
CVE-2026-598338.632.0siyuan-notesiyuanCWE-79SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer …
CVE-2026-556159.231.5langroidlangroidCWE-74Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (pr…
CVE-2026-519238.131.3n/an/aCWE-639An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm G…
CVE-2026-598347.531.2siyuan-notesiyuanCWE-89SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
CVE-2026-592067.131.2n8n-ion8nCWE-1321n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated Us…
CVE-2025-454228.130.6n/an/aCWE-284Incorrect access control in Proximus b-box v8c.725A allows authenticated atta…
CVE-2026-492566.330.4discoursediscourseCWE-200Discourse: Hidden tag names leaked via category serializers
CVE-2026-515979.130.3n/an/aCWE-294MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement …
CVE-2026-592206.530.4open-webuiopen-webuiCWE-1333Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on defau…
CVE-2026-546956.530.0pipecat-aipipecatCWE-862Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Att…
CVE-2026-464136.529.7discoursediscourseCWE-862Discourse: Regular users can route multipart uploads into the admin backup store
CVE-2026-457804.329.5discoursediscourseCWE-200Discourse: Private event sample invitees are serialized to non-invited event …
CVE-2026-592217.729.3open-webuiopen-webuiCWE-22open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVE-2026-519267.529.0n/an/aCWE-203An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obt…
CVE-2026-552078.828.1pimcorepimcoreCWE-640Pimcore: Account Takeover via Password Reset URL Injection allows unauthentic…
CVE-2026-554208.127.8discoursediscourseCWE-78Discourse: Remote code execution via pdf uploads
CVE-2026-114048.727.7CesantaMongooseCWE-125Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID …
CVE-2026-125958.127.7LoginPressLoginPress ProCWE-287LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverifie…
CVE-2026-125988.127.7LoginPressLoginPress ProCWE-287LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverifie…
CVE-2026-151382.127.7tumfmcp-text-editorCWE-22tumf mcp-text-editor text_editor.py _validate_file_path path traversal
CVE-2026-478268.527.4CloudFoundry FoundationBOSH CLI toolCWE-22blobs.yaml Path Traversal Allows File Writes
CVE-2026-539877.327.1Tag pluginGLPI 11CWE-79GLPI 11 before 2.14.4 Tag Plugin Stored Cross-Site Scripting in Kanban Badge …
CVE-2026-548018.627.0SiemensCPCI85 Central Processing/CommunicationCWE-620A vulnerability has been identified in CPCI85 Central Processing/Communicatio…
CVE-2026-150007.227.0rnzoConnect Contact Form 7 and MailchimpCWE-79Connect Contact Form 7 and Mailchimp <= 0.9.78.06 - Unauthenticated Stored Cr…
CVE-2026-392456.227.0n/an/aCWE-22decompress before 4.2.2 contains an improper path containment check that enab…
CVE-2026-597207.526.5hoppscotchhoppscotchCWE-200Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private …
CVE-2026-570216.926.5Juniper NetworksJunos OSCWE-787Junos OS: SRX Series: If VPN compliance-check is configured an attacker can c…
CVE-2026-02791.326.4Palo Alto NetworksCloud NGFWCWE-79PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
CVE-2026-570238.726.0Juniper NetworksJunos OSCWE-1284Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet cause…
CVE-2026-570268.726.0Juniper NetworksJunos OSCWE-1286Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malfo…
CVE-2026-519248.125.8n/an/aCWE-639An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute…
CVE-2026-591496.525.9mockoonmockoonCWE-22Mockoon: Path traversal in templated `filePath` lets a request escape the ser…
CVE-2026-592125.425.9open-webuiopen-webuiCWE-863Open WebUI: Model meta.knowledge read-only file access can be upgraded to fil…
CVE-2026-151905.525.7SourceCodesterSimple and Nice Shopping Cart ScriptCWE-74SourceCodester Simple and Nice Shopping Cart Script login.php sql injection
CVE-2026-392435.525.7n/an/aCWE-59decompress before 4.2.2 allows arbitrary hardlink creation during archive ext…
CVE-2026-596917.125.4Red HatRed Hat Enterprise Linux 10CWE-787Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16b…
CVE-2026-516067.525.2n/an/aCWE-20An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.…
CVE-2026-02876.625.1Palo Alto NetworksCloud NGFWCWE-754PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
CVE-2026-124065.325.1wedevsUser Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User RegistrationCWE-862User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary A…
CVE-2026-519258.125.0n/an/aCWE-639A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.1…
CVE-2026-592226.025.0open-webuiopen-webuiCWE-200Open WebUI: /api/v1/channels/{id}/members exposes full user model including s…
CVE-2026-598327.724.4siyuan-notesiyuanCWE-22SiYuan: Authenticated path traversal in /snippets/ static handler (serveSnipp…
CVE-2026-592087.624.1n8n-ion8nCWE-346n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Re…
CVE-2026-598285.324.1discoursediscourseCWE-200Discourse: Hidden post revisions leak through adjacent visible diffs
CVE-2026-540046.323.9getkirbykirbyCWE-862Kirby: Access to files of top-level drafts is not protected by permissions
CVE-2026-562929.223.8acymailing.comacymailing.com AcyMailing extension for JoomlaCWE-89Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 1…
CVE-2026-592169.023.5open-webuiopen-webuiCWE-94Open WebUI: Cross-user code-interpreter and tool execution via unvalidated So…
CVE-2026-598558.623.1siyuan-notesiyuanCWE-80SiYuan: Store XSS To Rce via Asset.render
CVE-2026-592197.123.1open-webuiopen-webuiCWE-613Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backch…
CVE-2026-592264.323.0open-webuiopen-webuiCWE-285Open WebUI: Scheduled automations continue after pending-user deactivation an…
CVE-2026-55238.822.6Divi EngineDivi Form BuilderCWE-639Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorizatio…
CVE-2026-556898.122.7openfgaopenfgaCWE-287OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
CVE-2026-554247.422.5discoursediscourseCWE-79Discourse: Topic featured link susceptible to stored XSS
CVE-2026-539625.422.5discoursediscourseCWE-79Discourse: Insufficient SVG sanitization logic
CVE-2026-90215.322.3matrixaddonsEasy Invoice – Invoice Generator, PDF Quotes & PaymentsCWE-862Easy Invoice <= 2.1.19 - Unauthenticated Arbitrary Quote Accept/Decline and I…
CVE-2026-592135.022.2open-webuiopen-webuiCWE-524Open WebUI: Cross-user model-list exposure via static cache key in get_all_mo…
CVE-2026-592097.122.0n8n-ion8nCWE-200n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVE-2026-581229.321.8nesquenahermes-webuiCWE-348Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoo…
CVE-2026-592174.321.7open-webuiopen-webuiCWE-862Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-…
CVE-2026-319848.721.6Nozomi NetworksGuardianCWE-770DoS through oversized audit log entries in Guardian/CMC before 26.2.0
CVE-2026-570228.221.7Juniper NetworksJunos OSCWE-754Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a T…
CVE-2026-501886.921.5getkirbykirbyCWE-93Kirby: Request header injection in `Http\Remote`
CVE-2026-575010.021.5zen-browserdesktopCWE-266Zen: Context-menu "Open link in glance" / "Split link in new tab" loads a pag…
CVE-2026-492767.421.4getkirbykirbyCWE-83Kirby: Self cross-site scripting (self-XSS) in the writer field
CVE-2026-437524.921.4ClarisFileMaker ServerCWE-434An authenticated administrator may be able to achieve arbitrary code executio…
CVE-2026-90285.321.3corvusinfoCorvusPay WooCommerce Payment GatewayCWE-862CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Una…
CVE-2026-592149.021.0open-webuiopen-webuiCWE-79Open WebUI: Stored web worker XSS via Pyodide
CVE-2026-592248.021.1open-webuiopen-webuiCWE-287Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user ident…
CVE-2026-134627.520.7PayRangePayRangePayRange for Android, version 7.0.7, contains an SSL bypass vulnerability
CVE-2026-125938.720.6QtAxivionCWE-862Privilege escalation via forged API token creation in Axivion Dashboard OIDC/…
CVE-2026-02844.720.5Palo Alto NetworksCloud NGFWCWE-74PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
CVE-2026-547718.120.2langroidlangroidCWE-75Langroid: handle_message() executes user-supplied tool JSON without sender ve…
CVE-2026-598544.920.3siyuan-notesiyuanCWE-693SiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir c…
CVE-2026-506448.620.1SOPlanningSOPlanningCWE-89SQL Injection in SOPlanning Audit Retention Configuration
CVE-2026-124286.520.1gamaupBlocks for ACF Fields — Display Custom Fields in the Block EditorCWE-862Blocks for ACF Fields <= 1.6.2 - Missing Authorization to Authenticated (Auth…
CVE-2026-555905.120.0cakephpauthenticationCWE-601CakePHP: Open redirect weakness via backslash bypass
CVE-2026-59559.819.9Inrove Software and Internet ServicesBiEticaretCWE-89SQLi in Inrove Software's BiEticaret
CVE-2026-492745.319.9getkirbykirbyCWE-862Kirby: `pages.access` permission is not checked in the pages picker for paren…
CVE-2026-570308.219.8Juniper NetworksJunos OSCWE-362Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS
CVE-2026-613446.919.6Superior Court of California, County of Los AngelesHearing Reminder ServiceCWE-306Superior Court of California Hearing Reminder Service unauthenticated informa…
CVE-2026-125905.919.3body-parserbody-parserCWE-770body-parser vulnerable to denial of service when invalid limit value silently…
CVE-2026-571117.519.1Apache Software FoundationApache Helix RESTCWE-1385Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestric…
CVE-2026-540057.119.1getkirbykirbyCWE-862Kirby: `pages.access` permission is not checked in the `site/find` REST API r…
CVE-2026-13656.519.1Sayax Energy Technologies Inc.OSOSCWE-201Information Disclosure in Sayax's OSOS
CVE-2026-447877.118.9discoursediscourseCWE-269Discourse: Signup-time primary_group_id assignment grants whisperer access
CVE-2026-143424.918.8getwpfunnelsMail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce EmailsCWE-89Mail Mint <= 1.24.2 - Authenticated (Administrator+) SQL Injection via 'conta…
CVE-2026-336557.718.5QuantumNousnew-apiCWE-918New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
CVE-2026-592077.118.2n8n-ion8nCWE-693n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Conn…
CVE-2026-151375.518.2code-projectsInterview Management SystemCWE-74code-projects Interview Management System View.php sql injection
CVE-2026-152022.118.3n/aYzmCMSCWE-79YzmCMS Header yzmphp.php get_url cross site scripting
CVE-2026-89966.518.1revmakxBackup and Staging by WP Time CapsuleCWE-862Backup and Staging by WP Time Capsule <= 1.22.26 - Missing Authorization to A…
CVE-2026-75585.318.1tokenoftrustAge Verification & Identity Verification by Token of TrustCWE-862Age Verification & Identity Verification by Token of Trust <= 4.0.2 - Missing…
CVE-2026-151952.118.1apidevtoolsjson-schema-ref-parserCWE-94apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution
CVE-2026-130116.518.0wedevsERP: Complete HR, Accounting & CRM Suite Built for WooCommerceCWE-89ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM…
CVE-2026-124334.318.0themeficHydra Booking — Appointment Scheduling & Booking CalendarCWE-639Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Refer…
CVE-2026-558657.117.8jg-rpliquidCWE-835Python Liquid: Infinite loop when parsing malformed `{% case %}` tags
CVE-2026-592275.417.7open-webuiopen-webuiCWE-862Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch an…
CVE-2026-598314.417.7clicliCWE-829GitHub CLI `gh codespace jupyter` could allow remote code execution when conn…
CVE-2026-338036.917.6Juniper NetworksJunos OS EvolvedCWE-923Junos OS Evolved: A port which has been inadvertently exposed can be reached …
CVE-2026-598175.317.5TryGhostGhostCWE-472Ghost: Paid gift memberships obtainable at minimal cost via the donations fea…
CVE-2026-115717.517.4UnknownEverest FormsEverest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Re…
CVE-2026-592153.117.3open-webuiopen-webuiCWE-639Open WebUI: Private channel messages can be disclosed through cross-channel t…
CVE-2026-19897.516.7PAVO Financial Technology Solutions Inc.PAVO PayCWE-639IDOR in PAVO Inc.'s PAVO Pay
CVE-2026-552087.716.5pimcorepimcoreCWE-89Pimcore: SQL Injection via Column Name in DateFilter allows authenticated use…
CVE-2026-121706.416.4acybaAcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressCWE-79AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-151872.116.4n/aenquirerCWE-94enquirer Public Package API Enquirer.set prototype pollution
CVE-2026-551702.116.4openfgaopenfgaCWE-178OpenFGA MySQL backend: case-insensitive collation on identifier columns cause…
CVE-2026-134417.216.2metagaussEventPrime – Events Calendar, Bookings and TicketsCWE-79EventPrime <= 4.3.4.2 - Unauthenticated Stored Cross-Site Scripting via 'new_…
CVE-2026-570246.916.2Juniper NetworksJunos OSCWE-694Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will ev…
CVE-2026-113594.316.2metagaussMemberships and User Profiles for WooCommerce – ProfileGrid WooCommerce IntegrationCWE-862Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization …
CVE-2026-319836.915.8Nozomi NetworksGuardianCWE-306Missing authentication in SSH keys synchronization endpoint in Guardian/CMC b…
CVE-2026-614745.315.8mispmispCWE-863MISP: Improper sharing group authorization check when adding attributes
CVE-2026-124185.315.8wedevsUser Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User RegistrationCWE-639User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membersh…
CVE-2026-583788.615.6AllwinnerH616CWE-489Allwinner TV Box TV98 ADB exposed on network
CVE-2026-547987.115.3SiemensCPCI85 Central Processing/CommunicationCWE-489A vulnerability has been identified in CPCI85 Central Processing/Communicatio…
CVE-2026-570327.115.4Juniper NetworksJunos OSCWE-236Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path caus…
CVE-2026-592185.315.4open-webuiopen-webuiCWE-208Open WebUI: Account enumeration via observable login timing discrepancy
CVE-2026-151862.114.9macrozhengmallCWE-99macrozheng mall Portal Endpoint create resource injection
CVE-2026-337948.214.9Juniper NetworksJunos OS EvolvedCWE-754Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates result…
CVE-2026-598536.514.7siyuan-notesiyuanCWE-862SiYuan: Publish-mode Reader can exfiltrate private saved-search Criteria via …
CVE-2026-501817.114.5langroidlangroidCWE-22Langroid: Path traversal in the file tools allows read/write outside configur…
CVE-2026-137716.414.6ivoleCustomer Reviews for WooCommerceCWE-79Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) St…
CVE-2026-570546.914.3Juniper NetworksJunos OSCWE-706Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
CVE-2026-539616.514.3discoursediscourseCWE-345Discourse: Forged AWS SNS bounce notifications can disable a targeted user's …
CVE-2026-337995.314.0Juniper NetworksJunos OSCWE-787Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results i…
CVE-2026-02854.713.9Palo Alto NetworksCloud NGFWCWE-918PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
CVE-2026-92374.313.6crewhrmEmployee, Leave and Recruitment Management System – Crew HRMCWE-862Employee, Leave and Recruitment Management System <= 1.2.2 - Missing Authoriz…
CVE-2026-556048.613.3arikusideepseek-mcp-serverCWE-639@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Control…
CVE-2026-478297.713.3CloudFoundry Foundationbosh-cliCWE-88Argument Injection in BOSH CLI Allows Local Command Execution on Operator Wor…
CVE-2026-564606.513.2HCLSoftwareHCL DevOps Deploy / HCL LaunchCWE-201HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive In…
CVE-2026-333907.213.1Nozomi NetworksGuardianCWE-266Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
CVE-2026-592234.313.2open-webuiopen-webuiCWE-693Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via UR…
CVE-2026-597156.513.1open-webuiopen-webuiCWE-306Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handle…
CVE-2026-90275.313.0corvusinfoCorvusPay WooCommerce Payment GatewayCWE-347CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Ver…
CVE-2026-23429.312.8OceanicSoft Informatics Systems Ltd.ValeAppCWE-79XSS in Oceanicsoft's ValeApp
CVE-2026-151912.112.7mettlesendportalCWE-285mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authori…
CVE-2026-598568.412.3vimvimCWE-94Vim: Arbitrary Code Execution via PHP Omni-Completion
CVE-2026-133346.112.2kitae-parkMang Board WPCWE-79Mang Board WP <= 2.3.4 - Reflected Cross-Site Scripting via 'stag' Parameter
CVE-2026-42568.211.9PEAKUP Technology Inc.PassGateCWE-90LDAP Injection in PEAKUP's PassGate
CVE-2026-02834.511.7Palo Alto NetworksCloud NGFWCWE-306PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
CVE-2026-592256.311.6open-webuiopen-webuiCWE-862Open WebUI: Arena task endpoints can bypass underlying model access controls
CVE-2026-151895.311.4aerostackdevaerostack-mcpCWE-918aerostackdev aerostack-mcp mcp-whatsapp upload_media server-side request forgery
CVE-2026-151882.111.4manjurulhoquedjango-job-portalCWE-266manjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmpl…
CVE-2026-69106.411.0safistudioBookero.pl – system rezerwacji onlineCWE-79Bookero.pl <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-92537.210.7loopusWP Cost Estimation & Payment Forms BuilderCWE-79WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthent…
CVE-2026-42984.310.6mlfactoryDSGVO All in one for WPCWE-862DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subs…
CVE-2026-312675.710.6n/an/aCWE-121Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Ove…
CVE-2026-153112.010.6NousResearchhermes-agentCWE-79NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to…
CVE-2026-601205.110.3WebkulBagistoCWE-79Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php
CVE-2026-132536.410.1wpxpoPost Grid Gutenberg Blocks – PostXCWE-79Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Aut…
CVE-2025-635797.510.1n/an/aCWE-200Unauthorized use of Kyocera printers, allows all information stored in the Ky…
CVE-2026-552127.110.1pimcorepimcoreCWE-285Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint …
CVE-2026-92354.39.6dhlparcelDHL eCommerce (Benelux) for WooCommerceCWE-862DHL eCommerce (Benelux) for WooCommerce <= 2.2.3 - Missing Authorization to A…
CVE-2026-92404.39.6iscpcolissimoColissimo shipping methods for WooCommerceCWE-862Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missin…
CVE-2026-46536.49.6bouncingsproutBlock, Suspend, Report for BuddyPressCWE-79Block, Suspend, Report for BuddyPress <= 3.6.4 - Authenticated (Subscriber+) …
CVE-2026-143436.49.6codename065Download ManagerCWE-79Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-118695.39.3UnknownWP DSGVO Tools (GDPR)WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclo…
CVE-2026-118755.39.3UnknownWP Support Plus Responsive Ticket SystemWP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support T…
CVE-2026-478317.79.0Cloud Foundry Foundationbosh-windows-stemcell-builderCryptographically Weak Password Generation in bosh-windows-stemcell-builder A…
CVE-2026-128795.98.7Google CloudApigeeCWE-441Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
CVE-2026-02801.78.8Palo Alto NetworksCloud NGFWCWE-131PAN-OS: IPv6 Firewall Policy Bypass
CVE-2026-42758.88.6badhonrocksDivi Torque Lite – Divi Modules for the Divi Builder & ThemeCWE-352Divi Torque Lite <= 4.2.3 - Cross-Site Request Forgery to Arbitrary Plugin In…
CVE-2026-125165.38.6UnknownFediverse EmbedsFediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy
CVE-2026-125175.38.6UnknownFediverse EmbedsFediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint
CVE-2026-515986.58.0n/an/aCWE-20An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP …
CVE-2026-122706.57.7UnknownEverest FormsEverest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assist…
CVE-2026-570286.97.6Juniper NetworksJunos OS EvolvedCWE-923Junos OS Evolved: A port which has been inadvertently exposed can be reached …
CVE-2026-570197.17.5Juniper NetworksJunos OSCWE-1284Junos OS: MX Series: Specific traffic causes an FPC to reset
CVE-2026-570207.17.5Juniper NetworksJunos OSCWE-754Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfa…
CVE-2026-02822.77.5Palo Alto NetworksCloud NGFWCWE-20PAN-OS: File Deletion Vulnerability in Management Web Interface
CVE-2026-581438.77.2CotontiCotontiCWE-352Cotonti Siena 0.9.26 CSRF via admin.php Config Update Endpoint
CVE-2026-591488.87.1mockoonmockoonCWE-306Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack a…
CVE-2026-319825.37.0Nozomi NetworksGuardianCWE-601Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
CVE-2026-338017.17.0Juniper NetworksJunos OSCWE-754Junos OS and Junos OS Evolved: When a specifically malformed BGP route update…
CVE-2026-592693.86.7VMwarePinnipedPrivilege Escalation via Active Directory LDAP injection in Pinniped Supervis…
CVE-2026-02812.16.5Palo Alto NetworksCloud NGFWCWE-524PAN-OS: Information Disclosure Vulnerability in Management Web Interface
CVE-2026-338007.16.2Juniper NetworksJunos OSCWE-606Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps …
CVE-2026-570277.16.2Juniper NetworksJunos OSCWE-401Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multi…
CVE-2026-443425.35.6QuantumNousnew-apiCWE-352New API CSRF in email and WeChat account binding endpoints
CVE-2025-274629.45.5XenWindows PV driversCWE-276WinPVDrivers: Excessive permissions on user-exposed devices
CVE-2025-274639.45.5XenWindows PV driversCWE-276WinPVDrivers: Excessive permissions on user-exposed devices
CVE-2025-274649.45.5XenWindows PV driversCWE-276WinPVDrivers: Excessive permissions on user-exposed devices
CVE-2026-564587.54.9HCLSoftwareHCL DevOps DeployCWE-942HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy…
CVE-2026-570315.34.8Juniper NetworksJunos OSCWE-754Junos OS: MX Series: For subscribers configured on static interfaces, input f…
CVE-2026-57936.14.6Inrove Software and Internet ServicesBiEticaretCWE-79XSS in Inrove Software's BiEticaret
CVE-2026-478288.94.5BOSH-Ecosystem / BOSH (bosh-cli)bosh-cliMissing TLS Certificate Verification in BOSH CLI Allows Root Code Execution v…
CVE-2026-418577.14.5CloudFoundry BOSHBOSH CLICWE-78BOSH CLI Shell Injection
CVE-2026-319814.84.5Nozomi NetworksGuardianCWE-79HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0
CVE-2026-548006.34.4SiemensCPCI85 Central Processing/CommunicationCWE-1188A vulnerability has been identified in CPCI85 Central Processing/Communicatio…
CVE-2026-235609.43.8XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2026-235619.43.8XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2025-581469.43.6XenXAPICWE-20XAPI UTF-8 string handling
CVE-2026-235569.43.6XenoxenstoredCWE-281oxenstored keeps quota related use counts across domain destruction
CVE-2026-598588.43.6vimvimCWE-94Vim: Arbitrary Code Execution via C Omni-Completion
CVE-2026-581445.13.5CotontiCotontiCWE-79Cotonti Siena 0.9.26 Stored XSS via PFS Module ntitle Parameter
CVE-2026-235599.43.4XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2026-235629.43.4XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2026-424869.43.4XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2026-50055.43.3Twiser Informatics Technology Consulting, Trade and Education Inc.OKRs & GoalsCWE-79Stored XSS in Twiser's OKRs & Goals
CVE-2026-151821.93.3GNULibreDWGCWE-119GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow
CVE-2026-478409.33.2CloudFoundry FoundationUAALDAP StartTLS unconditionally disables hostname verification
CVE-2026-547998.42.8SiemensCPCI85 Central Processing/CommunicationCWE-489A vulnerability has been identified in CPCI85 Central Processing/Communicatio…
CVE-2026-319858.32.3Nozomi NetworksRemote CollectorCWE-671Disabled and non-configurable TLS certificate validation in n2os-tui when con…
CVE-2026-570296.02.2Juniper NetworksJunos OS EvolvedCWE-820Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-p…
CVE-2026-151941.92.3n/aOpen5GSCWE-119Open5GS AMF context.c amf_context_final use after free
CVE-2025-581519.42.1XenvarstoredCWE-367varstored: TOCTOU issues with mapped guest memory
CVE-2026-152741.92.2lo48576fbxcelCWE-404lo48576 fbxcel Node Header parser.rs denial of service
CVE-2026-152761.92.2pdeljanovSymphoniaCWE-404pdeljanov Symphonia Metadata denial of service
CVE-2026-219016.72.0Juniper NetworksJunos OSCWE-476Junos OS and Junos OS Evolved: Configuration of a specific SSH option results…
CVE-2026-151841.92.0GNULibreDWGCWE-404GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
CVE-2026-583036.11.9Samsung Open SourceEscargotCWE-121Stack-based buffer overflow vulnerability in Samsung Open Source Escargot all…
CVE-2026-583066.11.9Samsung Open SourceEscargotCWE-122Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allo…
CVE-2026-562884.61.8GNUpatchCWE-476NULL Pointer Dereference in GNU patch
CVE-2026-562894.61.8GNUpatchCWE-835Loop with Unreachable Exit Condition in GNU patch
CVE-2026-02752.01.6Palo Alto NetworksPrisma BrowserCWE-269Prisma Browser: Local Privilege Escalation on macOS
CVE-2026-151851.91.6n/aGPACCWE-119GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds
CVE-2026-02775.71.5Palo Alto NetworksPrisma Access AgentCWE-295Prisma Access Agent: Improper Certificate Validation on iOS
CVE-2026-583076.11.3Samsung Open SourceEscargotCWE-125Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source …
CVE-2026-598575.61.3vimvimCWE-787Vim: Out-of-bounds Write in SAL Soundfolding
CVE-2026-583046.11.2Samsung Open SourceEscargotCWE-125Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source …
CVE-2026-583056.11.2Samsung Open SourceEscargotCWE-843Access of resource using incompatible type ('type confusion') vulnerability i…
CVE-2026-02785.81.2Palo Alto NetworksPrisma Access AgentCWE-693Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
CVE-2026-564595.51.1HCLSoftwareHCL DevOps Deploy / HCL LaunchCWE-532HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclo…
CVE-2026-478308.51.0Cloud Foundry Foundationbosh-windows-stemcell-builderIncorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM v…
CVE-2026-570256.80.9Juniper NetworksJunos OSCWE-466Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific '…
CVE-2026-02761.10.9Palo Alto NetworksCortex XDR Broker VMCWE-269Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability
CVE-2026-581985.50.8gunthercoxChatterBotCWE-59ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
CVE-2026-338026.80.6Juniper NetworksJunos OSCWE-862Junos OS: EX Series: Unauthorized users can execute service-impacting CLI com…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-09 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.