boxscore/security
Friday, July 10, 2026 · all times UTC← 2026-07-09 · archive · 2026-07-11 →

350 CVEs published July 10, 2026: 36 critical, 122 high, 163 medium, 29 low; 2 in KEV; 27 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 325 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published23191463712942563
KEV catalog size1670

651 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux38151812186652812730.27.5.0013-58
google791343149604549387460.47.8.0023-484
microsoft52763585071774378283.77.8.0044-155
red hat36228149211012400.06.5.0026+2
apple0991236629377.16.5.0031-2
canonical1212685000.05.5.0011+1
suse61941140000.08.6.0036+6
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+25
cisco83141280961135.57.5.0056+5
palo alto networks1425021471428.04.7.0021+5
netgear01700161800.04.3.0024-17
checkpoint0915303111.17.5.0410-2
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-3
fortinet08132028337.57.3.0066-2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache61214418477114010.57.3.0048+5
mozilla35912182901300.07.3.0025-2
drupal465165355512.05.9.0018+46
gitlab74005276425.04.7.0024+7
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-2
adobe314913527927542.75.8.0021-120
ibm21263842460700.07.5.0025-3
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-3
veeam042200400.09.0.0046-1
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link11405352617.16.0.0058-7
siemens4130760100.07.1.0019-3
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4
schneider electric060420100.07.8.0024-1
moxa050320000.07.0.00290
dahua030111200.06.9.0036-3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2899005346000.05.5.0026-7
dell3389441403211.17.0.0020+26
capgo1374237341000.07.0.0029+13
spring073231391000.06.5.0024-53
openclaw1680362210000.07.0.0021+1
edimax065039026100.07.4.00590
itsourcecode1063001944000.02.1.0020-12
themerex26055410000.08.1.0043+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
Most disclosures (vendor)
VendorCVEs
google606
linux456
oracle241
red hat130
apache126
capgo74
ibm72
microsoft66
dell64
openclaw62
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
adobe4
solarwinds4
synacor4
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven71
npm6
PyPI5
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-10520ivanti0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-35273Oracle Corporation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171696
CVE-2021-27102Accellion2021-11-171696
CVE-2021-27101Accellion2021-11-171696
CVE-2021-27103Accellion2021-11-171696
CVE-2021-21017Adobe2021-11-171696
CVE-2021-28550Adobe2021-11-171696
CVE-2021-42013Apache2021-11-171696
CVE-2021-41773Apache2021-11-171696
CVE-2021-30858Apple2021-11-171696
CVE-2021-30860Apple2021-11-171696

Transactions

EXPLOIT PUBLISHEDCVE-2026-52747 (owasp-modsecurity ModSecurity). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53448 (coturn). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53449 (coturn). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54063 (qax-os excelize). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55460 (grokability snipe-it). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55462 (grokability snipe-it). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55466 (grokability snipe-it). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55515 (grokability snipe-it). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55827 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56291 (balbooa.com Balbooa Forms extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57156 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57157 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57158 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57211 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57212 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57213 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57215 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57216 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57217 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57218 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57220 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57221 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59161 (qax-os excelize). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59162 (qax-os excelize). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59193 (getgrav grav). Public exploit reference added.

Yesterday's Results

350 CVEs published. 25 box scores, 325 table rows — nothing truncated.

icagenda.com iCagenda extension for Joomla — Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .8250   99.6   YES
AFFECTED
  Product                        Versions       Fixed
  iCagenda extension for Joomla  3.2.1-4.0.7 –  —
TIMELINE
  May 26  Reserved by CNA
  Jul 10  Added to CISA KEV, due Jul 13
  Jul 10  Published (CNA: Joomla)
CWE-434 · CNA: Joomla · 6 references · NVD status: Analyzed · KEV due July 13, 2026
balbooa.com balbooa.com Balbooa Forms extension for Joomla — Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .7607   99.5   YES
AFFECTED
  Product                                         Versions     Fixed
  balbooa.com Balbooa Forms extension for Joomla  1.0-2.4.0 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jul 10  Public exploit reference published
  Jul 10  Added to CISA KEV, due Jul 13
  Jul 10  Published (CNA: Joomla)
CWE-434 · CNA: Joomla · 3 references · NVD status: Analyzed · KEV due July 13, 2026
WebRehab Super Forms – Drag & Drop Form Builder — Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0280   85.3     —
AFFECTED
  Product                                 Versions     Fixed
  Super Forms – Drag & Drop Form Builder  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 10  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 2 references · NVD status: Deferred
Flux159 mcp-server-kubernetes — MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0210   80.2     —
AFFECTED
  Product                Versions     Fixed
  mcp-server-kubernetes  unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 10  Published (CNA: VulnCheck)
CWE-88 · CNA: VulnCheck · 5 references · NVD status: Analyzed
HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Management
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0199   78.9     —
AFFECTED
  Product   Versions     Fixed
  hestiacp  unspecified  —
TIMELINE
  Mar 13  Reserved by CNA
  Jul 10  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 4 references · NVD status: Analyzed
Drupal LocalGov Workflows — LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0126   67.1     —
AFFECTED
  Product             Versions  Fixed
  LocalGov Workflows  0.0.0 –   —
TIMELINE
  Jun 3   Reserved by CNA
  Jul 10  Published (CNA: drupal)
CWE-862 · CNA: drupal · 1 reference · NVD status: Analyzed
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0120   65.6     —
AFFECTED
  Product            Versions     Fixed
  PowerFlex Manager  unspecified  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 10  Published (CNA: dell)
CWE-78 · CNA: dell · 1 reference · NVD status: Analyzed
tenteeglobal Instant Appointment — Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0102   60.5     —
AFFECTED
  Product              Versions     Fixed
  Instant Appointment  unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 10  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 4 references · NVD status: Deferred
R-SOFT SERWIS DMS — OS Command Injection in R-SOFT DMS
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   H   H   H    9.0   .0101   60.3     —
AFFECTED
  Product  Versions     Fixed
  DMS      unspecified  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 10  Published (CNA: CERT-PL)
CWE-78 · CNA: CERT-PL · 1 reference · NVD status: Deferred
R-SOFT SERWIS DMS — OS Command Injection in R-SOFT DMS
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0083   54.5     —
AFFECTED
  Product  Versions     Fixed
  DMS      unspecified  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 10  Published (CNA: CERT-PL)
CWE-78 · CNA: CERT-PL · 1 reference · NVD status: Deferred
RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   A   H   H   N    8.7   .0078   53.0     —
AFFECTED
  Product          Versions             Fixed
  rabbitmq-server  >= 4.2.0, < 4.2.6 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 10  Published (CNA: GitHub_M)
CWE-522, CWE-200 · CNA: GitHub_M · 6 references · NVD status: Analyzed
Spinnaker: Improper yaml processing on kustomize bake operations
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0062   46.6     —
AFFECTED
  Product    Versions                   Fixed
  spinnaker  >= 2026.1.0, < 2026.1.1 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 10  Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · 11 references · NVD status: Analyzed
templatic1 Hide My WP Lite — Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0060   45.9     —
AFFECTED
  Product          Versions     Fixed
  Hide My WP Lite  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 10  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 3 references · NVD status: Deferred
wpazleen Post Export Import with Media — Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0060   45.8     —
AFFECTED
  Product                        Versions     Fixed
  Post Export Import with Media  unspecified  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 10  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 7 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI before 4.6.78 Allowlist Bypass via find -exec
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0058   44.9     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  4.6.78
TIMELINE
  Jul 9   Reserved by CNA
  Jul 10  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Deferred
elixir-plug plug — Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0058   44.9     —
AFFECTED
  Product  Versions                                    Fixed
  plug     1.4.0 –                                     —
  plug     c52b2f32c90bccd718202bafccb5f95594e30183 –  981597d3a4271ede64373c7a731702a42c500dd6
TIMELINE
  Jun 23  Reserved by CNA
  Jul 10  Published (CNA: EEF)
CWE-770 · CNA: EEF · 9 references · NVD status: Deferred
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   N    6.3   .0057   44.7     —
AFFECTED
  Product           Versions  Fixed
  Apache Log4j API  2.13.1 –  —
TIMELINE
  Jun 1   Reserved by CNA
  Jul 10  Published (CNA: apache)
CWE-116 · CNA: apache · 4 references · NVD status: Analyzed
n/a n/a — An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Tec…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0056   44.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 9   Reserved by CNA
  Jul 10  Published (CNA: mitre)
CWE-22 · CNA: mitre · 2 references · NVD status: Deferred
Hydro-Québec Le Circuit Electrique charging station backend Improper Access Control
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0056   44.1     —
AFFECTED
  Product                                         Versions     Fixed
  Le Circuit Electrique charging station backend  unspecified  —
TIMELINE
  Jan 27  Reserved by CNA
  Jul 10  Published (CNA: icscert)
CWE-284 · CNA: icscert · 3 references · NVD status: Deferred
RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0055   43.3     —
AFFECTED
  Product          Versions             Fixed
  rabbitmq-server  >= 4.2.0, < 4.2.6 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 10  Public exploit reference published
  Jul 10  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · 6 references · NVD status: Analyzed
Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0054   43.1     —
AFFECTED
  Product    Versions                   Fixed
  spinnaker  >= 2025.4.0, < 2025.4.4 –  —
TIMELINE
  May 7   Reserved by CNA
  Jul 10  Published (CNA: GitHub_M)
CWE-470, CWE-502 · CNA: GitHub_M · 4 references · NVD status: Analyzed
reputeinfosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup — ARMember <= 4.0.27 - Directory Traversal via X-FILENAME
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0053   42.5     —
AFFECTED
  Product                                                                                       Versions     Fixed
  ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup  unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 10  Published (CNA: Wordfence)
CWE-36 · CNA: Wordfence · 2 references · NVD status: Deferred
owasp-modsecurity ModSecurity — ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  H  N    8.6   .0052   41.8     —
AFFECTED
  Product      Versions    Fixed
  ModSecurity  < 3.0.16 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 10  Public exploit reference published
  Jul 10  Published (CNA: GitHub_M)
CWE-180 · CNA: GitHub_M · 3 references · NVD status: Analyzed
miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) — WordPress OAuth Single Sign On - SSO (OAuth Client) plugin <= 38.5.8 - Broken Authentication vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.1     —
AFFECTED
  Product                                    Versions  Fixed
  OAuth Single Sign On - SSO (OAuth Client)  n/a –     38.5.8.1
TIMELINE
  Jun 25  Reserved by CNA
  Jul 10  Published (CNA: Patchstack)
CWE-288 · CNA: Patchstack · 1 reference · NVD status: Deferred
RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0050   40.8     —
AFFECTED
  Product          Versions             Fixed
  rabbitmq-server  >= 4.2.0, < 4.2.6 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 10  Public exploit reference published
  Jul 10  Published (CNA: GitHub_M)
CWE-287 · CNA: GitHub_M · 6 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2025-119776.640.6happyformsHappyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose FormsCWE-98HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
CVE-2026-152917.538.7themeatelierChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat FormCWE-862Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to U…
CVE-2026-210458.338.3Samsung MobileSamsung Mobile DevicesOut-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so pr…
CVE-2026-127619.838.2cyberlord92miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)CWE-287miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= …
CVE-2026-597929.838.1JetBrainsIntelliJ IDEACWE-23In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path tr…
CVE-2026-571585.138.0FreeRDPFreeRDPCWE-125FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for …
CVE-2026-558528.637.9frappefrappeCWE-22Frappe: TarSlip RCE in Package Import
CVE-2026-422196.937.9frappefrappeCWE-22Frappe: Path Traversal via /backups Route
CVE-2026-443838.737.2Hydro-QuébecLe Circuit Electrique charging station backendCWE-613Hydro-Québec Le Circuit Electrique charging station backend Insufficient Sess…
CVE-2026-285649.836.7Apache Software FoundationApache IoTDBCWE-294Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CVE-2026-144808.736.6OpenPLCOpenPLCCWE-73OpenPLC v3 External Control of File Name or Path
CVE-2026-544698.836.0DellUnisphere for PowerMaxCWE-502Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Dese…
CVE-2026-572127.136.1rabbitmqrabbitmq-serverCWE-770RabbitMQ management HTTP API accepts request bodies larger than configured ma…
CVE-2026-380598.735.9ST Engineering iDirectEvolution iQ‑Series terminalsCWE-306ST Engineering iDirect iQ-Series Terminals Missing authentication for critica…
CVE-2026-534487.235.9coturncoturnCWE-89Coturn: SQL Injection in HTTPS Admin Panel Delete Operations
CVE-2026-5721110.035.7rabbitmqrabbitmq-serverCWE-36RabbitMQ: UNC SSRF affecting the management UI on Windows
CVE-2026-392447.535.5n/an/aCWE-400adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP fi…
CVE-2026-400089.835.3Apache Software FoundationApache IoTDBCWE-470Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
CVE-2026-578508.735.0RustDeskRustDeskCWE-862RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Messag…
CVE-2026-575848.735.0phalconcphalconCWE-1333Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router rout…
CVE-2026-400067.534.9Apache Software FoundationApache IoTDBCWE-306Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in…
CVE-2026-571568.634.8FreeRDPFreeRDPCWE-122FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Poi…
CVE-2026-527615.334.5owasp-modsecurityModSecurityCWE-467ModSecurity: Transformation utf8toUnicode produces wrong output on i386 archi…
CVE-2026-400059.134.3Apache Software FoundationApache IoTDBCWE-22Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
CVE-2026-572215.334.2rabbitmqrabbitmq-serverCWE-862RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, l…
CVE-2026-58019.833.6Semtek Informatics Software Consulting Trade Ltd. Co.SEM-PMPCWE-89SQLi in Semtek Informatics' SEM-PMP
CVE-2026-429528.733.6Hydro-QuébecLe Circuit Electrique charging station backendCWE-307Hydro-Québec Le Circuit Electrique charging station backend Improper Restrict…
CVE-2026-471992.333.3frappefrappeCWE-89Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE
CVE-2026-558849.233.0tilt-devtiltCWE-306Tilt: Missing authentication on the network-exposed Tilt HUD server
CVE-2026-591618.733.0qax-osexcelizeCWE-400Excelize: Streaming GetRows row-bound bypass causes attacker-controlled alloc…
CVE-2026-86097.532.9GrafanaGrafana OSSCWE-400Pre-authentication denial of service via the OAuth login route
CVE-2026-152907.532.4ultimatememberUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-89Ultimate Member – User Profile, Registration, Login, Member Directory, Conten…
CVE-2026-614449.432.4MervinPraisonPraisonAICWE-94PraisonAI before 4.6.78 Code Injection via f-string
CVE-2026-614926.132.2JetBrainsYouTrackCWE-79In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in di…
CVE-2026-591626.932.2qax-osexcelizeCWE-248Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
CVE-2026-591936.932.2getgravgravCWE-409Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()
CVE-2026-333827.532.0GrafanaGrafana OSSCWE-400Denial of service via unbounded request body size
CVE-2026-540637.531.9qax-osexcelizeCWE-770Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/…
CVE-2026-555009.931.9decolua9routerCWE-2009router: Exposure of Sensitive Information and Unprotected Database Import/Ex…
CVE-2026-210488.331.9Samsung MobileSamsung Mobile DevicesOut-of-bounds write in parsing DNG format in libimagecodec.media.quram.so pri…
CVE-2026-125359.831.8DrupalFormatter FieldCWE-915Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
CVE-2026-295196.231.8luceeLuceeCWE-79Lucee CFML Server Reflected XSS via URL Path Parsing
CVE-2026-556877.531.6espressifesp-idfCWE-121ESF-IDF: Stack-Based Out-of-Bounds Write in JPEG Decoder DQT Marker Parsing
CVE-2026-541498.831.61Panel-devMaxKBCWE-78MaxKB MCP tool import validation bypass allows post-authentication remote cod…
CVE-2026-558828.331.6tilt-devtiltCWE-200Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
CVE-2026-511199.131.3n/an/aCWE-269An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privi…
CVE-2026-572157.031.4rabbitmqrabbitmq-serverCWE-863RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-…
CVE-2026-554696.530.9grokabilitysnipe-itCWE-22Snipe-IT: Path traversal vulnerability via CSV import `image` field
CVE-2026-153315.330.9zhayujieCowAgentCWE-22zhayujie CowAgent Skill Installation service.py _add_package path traversal
CVE-2026-597938.830.8JetBrainsTeamCityCWE-73In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via …
CVE-2026-556388.630.3decolua9routerCWE-8629router: Unauthenticated LLM proxy access via /codex rewrite authorization by…
CVE-2026-562619.230.3Crawl4AICrawl4AICWE-918Crawl4AI - Server-Side Request Forgery via Webhook URLs
CVE-2026-481275.330.0frappefrappeCWE-862Frappe: Arbitrary Attachment Injection via add_attachments and upload_file
CVE-2026-571576.529.8FreeRDPFreeRDPCWE-125Out-of-bounds read in the camera device enumerator server (rdpecam) via unter…
CVE-2026-153262.029.5halo-devhaloCWE-22halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path…
CVE-2026-567659.328.9VikunjaVikunjaCWE-639Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Discl…
CVE-2026-563058.728.8CapgoCapgoCWE-620Capgo - Authentication Bypass in Password Change via Missing Current Password…
CVE-2026-584998.228.7EverMind-AIEverOSCWE-22Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id
CVE-2026-552297.528.6gotenberggotenbergCWE-918Gotenberg: SSRF via LibreOffice document processing
CVE-2026-585036.928.6frappefrappeCWE-203Frappe: Unauthenticated User Enumeration via reset_password
CVE-2026-614618.728.2langgeniusdifyCWE-89Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text
CVE-2026-572177.028.2rabbitmqrabbitmq-serverCWE-863RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
CVE-2026-153305.528.3zhayujieCowAgentCWE-918zhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side req…
CVE-2026-572184.928.2rabbitmqrabbitmq-serverCWE-863RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can le…
CVE-2026-153009.128.0ninjewGEO my WPCWE-89GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / '…
CVE-2026-152938.027.8joeyoungbloodWP Business Intelligence LiteCWE-862WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing …
CVE-2026-554057.627.9langchain4jlangchain4jCWE-89LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and la…
CVE-2026-575756.927.8misskey-devmisskeyCWE-918Misskey: SSRF bypass in URL Preview
CVE-2026-554666.227.7grokabilitysnipe-itCWE-79Snipe-IT: Stored XSS via inline-served attachment
CVE-2026-152895.927.7wpdevartBooking calendar, Appointment Booking SystemCWE-89Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time…
CVE-2026-552137.527.4h2oh2oCWE-789h2o: musl libc stack overflow (QPACK)
CVE-2026-552337.527.3openrestyopenrestyCWE-787OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream
CVE-2026-119905.327.2iqonicdesignKiviCare – Clinic & Patient Management System (EHR)CWE-862KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass a…
CVE-2026-152887.527.0brainstormforceSureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & CalculatorCWE-20SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticat…
CVE-2026-575747.427.0misskey-devmisskeyCWE-294Misskey: TOTP tokens can be reused
CVE-2026-574756.927.0DeloitteAI Assist for CustomerCWE-306Deloitte AI Assist for Customer unauthenticated configuration write
CVE-2026-558278.826.9FreeRDPFreeRDPCWE-131FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode
CVE-2026-414827.126.7frappefrappeCWE-22Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Gener…
CVE-2026-399037.126.2SimpleMachinesSMFCWE-863Simple Machines Forum Authorization Bypass via AttachmentApprove.php
CVE-2026-400077.525.8Apache Software FoundationApache IoTDBCWE-400Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's …
CVE-2026-404547.525.8Apache Software FoundationApache IoTDB C++ clientCWE-20Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializ…
CVE-2026-554747.125.8grokabilitysnipe-itCWE-23Snipe-IT: Directory traversal in displaySig
CVE-2026-449185.525.7OpenStackIronicCWE-862OpenStack Ironic through before 37.0.1 allows creation or modification of nod…
CVE-2026-226608.625.7flaskbbflaskbbCWE-697FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
CVE-2026-153195.525.1SipeedPicoClawCWE-266Sipeed PicoClaw Launcher access_control.go IPAllowlist access control
CVE-2026-556658.525.0gristlabsgrist-coreCWE-79DOM-based XSS in Grist via unsanitized links, enabling privilege escalation
CVE-2026-119139.824.8DrupalMother May ICWE-79Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045
CVE-2026-555017.324.8decolua9routerCWE-3079router: Login brute-force protection bypass via spoofed X-Forwarded-For header
CVE-2026-492138.124.7baptisteArnotypebot.ioCWE-918TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP …
CVE-2026-129184.924.7getwpfunnelsMail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce EmailsCWE-89Mail Mint <= 1.24.1 - Authenticated (Administrator+) SQL Injection via 'recip…
CVE-2026-153789.324.3Red HatRed Hat OpenShift AI (RHOAI)CWE-918Guardrails-detectors: guardrails-detectors: ssrf and local file read via user…
CVE-2026-566758.324.3decolua9routerCWE-2879router: Reverse proxy locality collapse allows unauthenticated access to 9ro…
CVE-2026-152987.224.1pechenkiTelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram botCWE-79TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegr…
CVE-2026-113217.124.1pluginsGLPIdatainjectionCWE-89GLPI DataInjection Plugin Authenticated SQL Injection via CSV Import
CVE-2026-97269.824.1DrupalDrupal AlternativeCommerce (Basket)CWE-915Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code ex…
CVE-2026-562798.724.0CapgoCapgoCWE-862Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint
CVE-2026-557802.423.5M2TeamNanaZipCWE-248NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-fil…
CVE-2026-558098.123.3DrupalFlag attendance fieldCWE-915Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049
CVE-2026-493947.123.3frappefrappeCWE-862Frappe: Auth. bypass via update_page
CVE-2026-591556.923.0nezhahqnezhaCWE-200Nezha Monitoring: DDNS and Notification credential exposure via unredacted li…
CVE-2026-144615.123.0BitWizardmtrCWE-125Out-of-bound read in mtr
CVE-2026-584929.222.8getgravgravCWE-89grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized …
CVE-2026-544238.222.8OpenStackIronicCWE-424In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy …
CVE-2026-544686.522.8DellUnisphere for PowerMaxCWE-22Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path…
CVE-2026-536538.722.7getgravgravCWE-770Grav: Unauthenticated denial of service via unbounded image derivative dimens…
CVE-2026-150899.122.3DrupalCommerce guest registrationCWE-287Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079
CVE-2026-557898.522.4logto-iologtoCWE-91Logto: SAML IdP injects user-controlled profile attributes raw into signed as…
CVE-2026-558437.022.4grokabilitysnipe-itCWE-269Snipe-IT: Improper Privilege Management
CVE-2026-152846.422.3kingaddonsKing Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup BuilderCWE-79King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cro…
CVE-2026-591519.622.1prowler-cloudprowlerCWE-287Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
CVE-2026-98386.122.1room34ICS CalendarCWE-79ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Pa…
CVE-2026-533639.822.1LinuxLinuxxfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
CVE-2026-563357.122.1CapgoCapgoCWE-284Capgo - Channel Configuration Mutation via Write-Scoped API Keys
CVE-2026-144754.922.0wplegalpagesCookie Banner for GDPR / CCPA – WPLP Cookie ConsentCWE-89Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL I…
CVE-2026-418787.121.8R-SOFT SERWISDMSCWE-639Insecure Direct Object Reference in R-SOFT DMS
CVE-2026-574746.921.7DeloitteAI Assist for CustomerCWE-200Deloitte AI Assist for Customer information disclosure
CVE-2026-558799.321.5openreplayopenreplayCWE-79OpenReplay: Unauthenticated stored XSS leads to dashboard account takeover
CVE-2026-584935.121.3getgravgravCWE-74grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration V…
CVE-2026-98574.321.3saskaita123Invoice123CWE-862Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Se…
CVE-2026-404527.521.2Apache Software FoundationApache IoTDBCWE-284Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-val…
CVE-2026-556702.321.1zitadelzitadelCWE-284ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
CVE-2026-554607.121.0grokabilitysnipe-itCWE-863Snipe-IT: Authorization bypass on bulk editing users
CVE-2026-226597.220.9flaskbbflaskbbCWE-863FlaskBB Authorization Bypass via Topic ID Manipulation
CVE-2026-152876.520.7rtcamprtMedia for WordPress, BuddyPress and bbPressCWE-89rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subs…
CVE-2026-551875.820.7axllentmailpitCWE-918Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mec…
CVE-2026-614608.720.5krayinlaravel-crmCWE-639Krayin CRM Insecure Direct Object Reference via Controllers
CVE-2026-119924.320.5easyappointmentsEasy AppointmentsCWE-862Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author…
CVE-2026-614326.920.2MervinPraisonPraisonAICWE-22PraisonAI FastContext before 1.6.78 Path Traversal
CVE-2026-474225.320.2frappefrappeCWE-862Frappe: Unrestricted API access to save_report
CVE-2026-554624.320.3grokabilitysnipe-itCWE-863Snipe-IT: Authorization bypass on print inventory page
CVE-2026-556727.420.0zitadelzitadelCWE-287ZITADEL: Missing client_id binding in OIDC authorization code exchange and re…
CVE-2026-150865.920.1DrupalRaw Formatter [Meta Tag Formatter]Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026…
CVE-2026-556597.719.9gristlabsgrist-coreCWE-79Grist: XSS through unsafe value interpolation in server-rendered pages
CVE-2026-563126.919.9CapgoCapgoCWE-287Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint
CVE-2026-597968.119.6JetBrainsTeamCityCWE-862In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due …
CVE-2026-579615.119.2phpMyFAQphpMyFAQCWE-22phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Fu…
CVE-2026-571675.119.1ChocobozzzPeerTubeCWE-80PeerTube: Improper Neutralization of Script-Related HTML Tags in a Web Page (…
CVE-2026-555155.019.1grokabilitysnipe-itCWE-639Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped…
CVE-2026-113926.119.0thimpressWP Hotel BookingCWE-79WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date…
CVE-2026-124004.319.0priyanshuchaudharyFlowForms – Conversational Form BuilderCWE-639FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Refe…
CVE-2026-152864.319.0stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-863Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - In…
CVE-2026-400096.518.5Apache Software FoundationApache IoTDBCWE-269Apache IoTDB: Authenticated users can escalate to full tree-path access by re…
CVE-2026-23979.818.5Adam Retail Automation Ltd.MobilMen 20TCWE-89SQLi in AdamPOS' MobilMen 20T
CVE-2026-597956.118.4JetBrainsTeamCityCWE-79In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent re…
CVE-2026-152856.418.0posimyththemesThe Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerceCWE-79The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored…
CVE-2026-150708.817.7wordpresschefSalon Booking System – Free VersionCWE-352Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code …
CVE-2026-553778.117.7logto-iologtoCWE-287Logto: Account Center MFA management step-up bypass via WebAuthn registration…
CVE-2026-614316.817.7MervinPraisonPraisonAICWE-22PraisonAI before 4.6.78 Path Traversal via ContextGatherer
CVE-2026-563095.317.7CapgoCapgoCWE-770Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint
CVE-2026-150817.417.5DrupalLocation SelectorCWE-89Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072
CVE-2026-130395.317.5arrayticsEventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)CWE-862Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment By…
CVE-2026-152976.117.4neeraj_slitBrevo – Email, SMS, Web Push, Chat, and more.CWE-79Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendi…
CVE-2026-153732.117.4EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software userAddAction.do improper authorization
CVE-2026-153742.117.4EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software Group roleAddAction.do improper authorization
CVE-2026-153762.117.4EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software statisticReportAction.do improper authorization
CVE-2026-151439.317.2Red HatRed Hat OpenShift AI (RHOAI)CWE-918Guardrails-detectors: guardrails-detectors: ssrf and local file read via user…
CVE-2026-39076.417.2prasunsenHostelCWE-79Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…
CVE-2026-152966.417.2cservitaffiliate-toolkit – Multi-Network Affiliate & Amazon Product DisplayCWE-79affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 - Authenticated …
CVE-2026-153772.117.3EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software sendlogfile improper authorization
CVE-2026-547146.117.0logto-iologtoCWE-79Logto: XSS via unescaped RelayState in SAML auto-submit form
CVE-2026-572135.716.8rabbitmqrabbitmq-serverCWE-79RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_ta…
CVE-2026-556712.316.8zitadelzitadelCWE-918ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing H…
CVE-2026-62128.816.8Teracity Software Technologies Inc.TeraMISCWE-639IDOR in Teracity's TeraMIS
CVE-2026-418775.116.8R-SOFT SERWISDMSCWE-79Stored XSS in R-SOFT DMS
CVE-2026-23988.816.7Adam Retail Automation Ltd.MobilMen 20TCWE-639IDOR in AdamPOS' MobilMen 20T
CVE-2026-614557.116.5getgravgravCWE-409Grav before 2.0.1 Decompression Bomb via ZipArchiver
CVE-2026-132448.116.4DrupalTealium iQ Tag ManagementCWE-915Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026…
CVE-2026-558108.116.4DrupalPlotly.js GraphingCWE-915Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050
CVE-2026-574766.316.3DeloitteAI Assist for CustomerCWE-306Deloitte AI Assist for Customer unauthenticated RAG corpus read and write
CVE-2026-130106.516.2beardevJoomSport – for Sports: Team & League, Football, Hockey & moreCWE-89JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' S…
CVE-2026-153172.116.2SipeedPicoClawCWE-918Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-sid…
CVE-2026-556418.216.2decolua9routerCWE-2909router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open…
CVE-2026-558817.116.1openreplayopenreplayCWE-639OpenReplay: Cross-tenant session replay disclosure via missing session owners…
CVE-2026-614507.116.2getgravgravCWE-94Grav before 2.0.2 Config Exfiltration via offsetGet Filter
CVE-2026-534496.016.0coturncoturnCWE-73Coturn: Arbitrary File Write via CLI psd Command
CVE-2026-150875.915.8DrupalClean RESTfulCWE-287Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078
CVE-2026-118185.415.8arrayticsWPCafe – Restaurant Menu, Online Food Ordering & Table Booking SystemCWE-862WPCafe <= 3.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbit…
CVE-2026-152926.415.7tibouilleSudoku ShortcodeCWE-79Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting…
CVE-2026-68025.315.8fahadmahmoodEasy Upload Files During CheckoutCWE-639Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthe…
CVE-2026-556644.315.7gristlabsgrist-coreCWE-200Grist: Insufficient access control in the /forms endpoint exposes table metadata
CVE-2026-151046.515.5wpdevteamBetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with ChatbotCWE-89BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter
CVE-2026-153292.115.5zhayujieCowAgentCWE-200zhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate infor…
CVE-2026-566908.515.4DellPowerFlex ManagerCWE-89Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neut…
CVE-2026-85955.415.3GrafanaGrafana OSSCWE-79Stored XSS in the table panel (TableNG)
CVE-2026-614417.115.3MervinPraisonPraisonAICWE-862PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies
CVE-2026-121236.415.1plugins360All-in-One Video GalleryCWE-918All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side R…
CVE-2026-563295.314.9CapgoCapgoCWE-436Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore…
CVE-2026-554816.214.8grokabilitysnipe-itCWE-79Snipe-IT: CSS Injection via `header_color` Setting
CVE-2026-554524.814.5grokabilitysnipe-itCWE-1236Snipe-IT: CSV formula injection in Activity Report export
CVE-2026-153202.114.6SipeedPicoClawCWE-862Sipeed PicoClaw pico.go rt.ReloadConfig authorization
CVE-2026-554616.114.3grokabilitysnipe-itCWE-601Snipe-IT: Open Redirect After User Edit
CVE-2026-566688.114.1zitadelzitadelCWE-862ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
CVE-2026-563736.314.1ImageMagickImageMagickCWE-416ImageMagick - Use-After-Free Write in PDB Decoder
CVE-2026-380577.013.5ST Engineering iDirectEvolution iQ‑Series terminalsCWE-352ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery
CVE-2026-586615.313.5n8nn8nCWE-770n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint
CVE-2026-543297.713.5grokabilitysnipe-itCWE-862Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API
CVE-2026-566677.313.3zitadelzitadelCWE-79ZITADEL: Stored XSS via Default URI Redirect in Login V2
CVE-2026-150264.313.1carazoImport and export users and customersCWE-862Import and export users and customers <= 2.4.0 - Missing Authorization to Aut…
CVE-2026-558838.313.0tilt-devtiltCWE-345Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream
CVE-2026-126857.513.1UnknownescortwpEscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor
CVE-2026-19464.313.0nandhiniwpGW AI Website BuilderCWE-862GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subs…
CVE-2026-153752.113.0EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization
CVE-2026-566897.712.8DellPowerFlex ManagerCWE-89Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neut…
CVE-2026-572147.112.7rabbitmqrabbitmq-serverCWE-79RabbitMQ: Stored XSS in RabbitMQ management UI
CVE-2026-600866.912.8MervinPraisonPraisonAICWE-693PraisonAI before 4.6.78 Prompt Injection Defense Bypass
CVE-2026-153211.912.7n/aMyEMSCWE-79MyEMS Admin Backend svg.py on_post cross site scripting
CVE-2026-555167.712.5grokabilitysnipe-itCWE-639Snipe-IT: Cross-company asset maintenance re-parenting via API update
CVE-2026-119145.912.4DrupalComposerCWE-20Composer - Critical - Unsupported - SA-CONTRIB-2026-046
CVE-2026-591908.712.2getgravgravCWE-639Grav Admin Plugin — IDOR Privilege Escalation via saveUser()
CVE-2026-558035.912.2DrupalDrupal coreCWE-915Drupal core - Critical - PHP object injection - SA-CORE-2026-005
CVE-2026-558045.912.2DrupalDrupal coreCWE-915Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
CVE-2026-579946.912.0phpMyFAQphpMyFAQCWE-200phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endp…
CVE-2026-153182.112.0SipeedPicoClawCWE-285Sipeed PicoClaw MQTT Channel mqtt.go authorization
CVE-2026-150795.411.3DrupalLogin DisableCWE-307Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070
CVE-2026-153322.111.4zhayujieCowAgentCWE-862zhayujie CowAgent Message Endpoint channel.py authorization
CVE-2026-597945.411.2JetBrainsTeamCityCWE-79In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page wa…
CVE-2026-121084.411.2looswebstudioHighlighting Code BlockCWE-79Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cros…
CVE-2026-591544.311.3wekanwekanCWE-863Wekan: Checklist direct DDP updates can write checklist data into private boards
CVE-2026-572305.411.0openreplayopenreplayCWE-89OpenReplay: Authenticated ClickHouse SQL injection via session search
CVE-2026-558065.910.9DrupalDrupal coreCWE-601Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-202…
CVE-2026-132333.310.7DrupalOpenAI ProviderCWE-918OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONT…
CVE-2026-566644.210.6zitadelzitadelCWE-613ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
CVE-2026-150283.910.6Red HatRed Hat Hardened ImagesCWE-805Libarchive: heap overflow oob read while parsing a tar archive contains a pax…
CVE-2026-129246.410.1arrayticsEventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)CWE-79Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-137106.410.1jegthemeJeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPressCWE-79Jeg Kit for Elementor <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Si…
CVE-2026-554765.310.2grokabilitysnipe-itCWE-862Snipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_adm…
CVE-2026-418798.210.0R-SOFT SERWISDMSCWE-328Weak password hashing in R-SOFT DMS
CVE-2026-553706.410.0logto-iologtoCWE-294Logto: TOTP code can be replayed within the RFC 6238 validity window (one-tim…
CVE-2026-554724.39.8grokabilitysnipe-itCWE-863Snipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary V…
CVE-2026-129554.39.6wplegalpagesCookie Banner for GDPR / CCPA – WPLP Cookie ConsentCWE-862Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticat…
CVE-2026-558807.19.5openreplayopenreplayCWE-639OpenReplay: Cross-user IDOR in notes and dashboard widgets
CVE-2026-591803.19.5caroncappriseCWE-200Apprise forwards configured auth headers across cross-origin HTTP redirects
CVE-2026-152996.49.3wealcoderAnimation Addons for Elementor – GSAP Motion Elementor Addons & Website TemplatesCWE-79Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored…
CVE-2026-119155.99.2DrupalBrute force attack protectionCWE-307Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047
CVE-2026-554755.79.2grokabilitysnipe-itCWE-863Snipe-IT: Import created_by can be overwritten
CVE-2026-544705.39.0DellUnisphere for PowerMaxCWE-611Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Impr…
CVE-2026-554795.38.9grokabilitysnipe-itCWE-863Snipe-IT: Incorrect permission for legacy license checkin API
CVE-2026-152954.49.0dcooneyAjax Load More – Infinite Scroll, Load More, & Lazy LoadCWE-692Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Sc…
CVE-2026-566664.88.9zitadelzitadelCWE-287ZITADEL: Auto-linking by email: IdP-side email verification is not checked
CVE-2026-132476.48.7logichuntLogo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo ShowcaseCWE-79Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-558904.88.7getgravgravCWE-79Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTra…
CVE-2026-152834.48.6wpvividpluginsWPvivid Backup for MainWPCWE-79WPvivid Backup for MainWP <= 0.9.33 - Authenticated (Admin+) Stored Cross-Sit…
CVE-2026-16677.28.5cifiGEO Plugin by Squirrly SEOCWE-862SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creatio…
CVE-2026-122765.38.0UnknownLA-Studio Element Kit for ElementorLA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration
CVE-2026-107706.18.0DrupalAnti-Spam by CleanTalkCWE-79Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONT…
CVE-2026-132316.18.0DrupalAdvanced Content Feedback (aka admin_feedback)CWE-79Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-…
CVE-2026-132346.18.0DrupalAI (Artificial Intelligence)CWE-79AI (Artificial Intelligence) - Moderately critical - Information Disclosure /…
CVE-2026-600916.97.9MervinPraisonPraisonAICWE-918PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url
CVE-2026-150834.27.8DrupalECA: Event - Condition - ActionCWE-915ECA: Event - Condition - Action - Less critical - Information disclosure - SA…
CVE-2025-300085.17.6hestiacphestiacpCWE-79HestiaCP < 1.9.5 Stored XSS via DNS Record Management Interface
CVE-2026-554785.37.3grokabilitysnipe-itCWE-639Snipe-IT: Missing object-level authorization in Kits API
CVE-2026-558856.87.1getgravgravCWE-312Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Sec…
CVE-2026-534507.47.0coturncoturnCWE-918Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection
CVE-2026-554644.87.0grokabilitysnipe-itCWE-79Snipe-IT: Stored XSS via Markdown custom field
CVE-2026-210558.57.0Samsung MobileBixbyImproper export of android application components in Bixby prior to version 4…
CVE-2026-50695.46.9wpmanageninjaFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-863Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+…
CVE-2026-563545.16.6n8nn8nCWE-79n8n - Cross-Site Scripting and Open Redirect in Form Node
CVE-2026-563664.86.7ImageMagickImageMagickCWE-401ImageMagick - Memory Leak in META Reader APP1JPEG Error Path
CVE-2026-132374.86.5DrupalAI AgentsCWE-863AI Agents - Moderately critical - Information disclosure, Access bypass - SA-…
CVE-2026-566654.26.4zitadelzitadelCWE-613ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
CVE-2026-132426.56.2DrupalGeolocation FieldCWE-89Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062
CVE-2026-107695.46.2DrupalCommerce CoreCWE-79Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041
CVE-2026-150825.46.2DrupalSiteimprove AnalyticsCWE-79Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTR…
CVE-2026-150845.46.2DrupalUI Patterns (SDC in Drupal UI)CWE-79UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting -…
CVE-2026-150855.46.2DrupalAI SEO/GEO AnalyzerCWE-79AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB…
CVE-2026-549197.46.0yhirosecpp-httplibCWE-295cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts…
CVE-2026-151465.96.1GNU wgetWgetCVE-2026-15146
CVE-2026-582252.15.9elixir-ectopostgrexCWE-89SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect …
CVE-2026-119085.45.9DrupalTagifyCWE-79Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043
CVE-2026-132323.15.9DrupalAdvanced Content Feedback (aka admin_feedback)CWE-863Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access…
CVE-2026-558085.45.8DrupalDrupal coreCWE-79Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
CVE-2026-119093.35.7DrupalExamples for DevelopersCWE-862Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-20…
CVE-2026-132353.35.7DrupalAI (Artificial Intelligence)CWE-862AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTR…
CVE-2026-132396.55.6DrupalWissKICWE-862WissKI - Critical - Access bypass - SA-CONTRIB-2026-059
CVE-2026-132406.55.6DrupalParagraphsCWE-862Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
CVE-2026-132416.55.6DrupalParagraphsCWE-862Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061
CVE-2026-64404.35.5sovlixGoodMeet – Google Meet Integration for Webinar, Meeting & Video ConferenceCWE-352GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Rese…
CVE-2026-153016.45.3digibloggerBuddyHolis TableSearchCWE-79BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-S…
CVE-2026-566767.45.1decolua9routerCWE-3679router: Image prefetch DNS rebinding allows SSRF to internal services
CVE-2026-585886.14.9DrupalDrupal CanvasCWE-79Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066
CVE-2026-562548.34.8capacitor-updatercapacitor-updaterCWE-320capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution
CVE-2026-585876.14.6DrupalDrupal CanvasCWE-79Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065
CVE-2026-32516.44.5Webremium Istanbul Web DesignMezunum SatiyorumCWE-79XSS in Webremium's Mezunum Satiyorum
CVE-2026-547368.24.5phalconcphalconCWE-208Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (…
CVE-2026-568132.14.4elixir-plugplugCWE-141Cookie attribute injection in Plug.Conn.Cookies.encode/2
CVE-2026-132364.24.3DrupalAI AgentsCWE-862AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056
CVE-2026-600896.93.9MervinPraisonPraisonAICWE-22PraisonAI before 1.6.78 Path Traversal via config.toml
CVE-2026-585895.43.9DrupalFlowDropCWE-862FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067
CVE-2026-585905.43.9DrupalFlowDropCWE-862FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068
CVE-2026-614565.13.9getgravgravCWE-79Grav before 1.0.3 Stored XSS via SVG Upload API
CVE-2026-558073.13.9DrupalDrupal coreCWE-918Drupal core - Moderately critical - Server-side request forgery - SA-CORE-202…
CVE-2026-132384.83.7DrupalCommerce Realex / Global PaymentsCWE-863Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-…
CVE-2026-585915.43.5DrupalColorboxCWE-79Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069
CVE-2026-597913.53.4JetBrainsYouTrackCWE-1021In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram r…
CVE-2026-411547.83.2Imagination TechnologiesGraphics DDKCWE-787GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse
CVE-2026-210526.83.2Samsung MobileSamsung Mobile DevicesPath traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows …
CVE-2026-614378.53.0MervinPraisonPraisonAICWE-693PraisonAI before 1.6.78 Remote Code Execution via tools.py
CVE-2026-536578.23.0lima-vmlimaCWE-276Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM …
CVE-2026-210436.73.0Samsung MobileSamsung Mobile DevicesPath traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows lo…
CVE-2026-210498.42.8Samsung MobileSamsung Mobile DevicesOut-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 all…
CVE-2026-76397.82.4Imagination TechnologiesGraphics DDKCWE-459GPU DDK - Page UAF read in PMMETA_PROTECT heap memory
CVE-2026-341967.82.0Imagination TechnologiesGraphics DDKCWE-416GPU DDK - UAF read and/or write of arbitrary physical memory due to integer t…
CVE-2026-150804.32.0DrupalRay Enterprise TranslationCWE-352Ray Enterprise Translation - Moderately critical - Cross site request forgery…
CVE-2026-210428.41.9Samsung MobileSamsung Mobile DevicesOut-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows lo…
CVE-2026-210576.81.9Samsung MobileSamsung PassImproper input validation in Samsung Pass prior to version 5.2.10.3 allows lo…
CVE-2026-210546.91.8Samsung MobileInputSharingImproper export of android application components in InputSharing prior to ve…
CVE-2026-557822.41.7M2TeamNanaZipCWE-400NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via …
CVE-2026-556694.21.6zitadelzitadelCWE-346ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
CVE-2026-557812.41.6M2TeamNanaZipCWE-400NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalida…
CVE-2026-557832.41.6M2TeamNanaZipCWE-476NanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom ar…
CVE-2026-210535.11.5Samsung MobileSamsung EmailImproper input validation in Samsung Email prior to version 6.2.13.1 allows l…
CVE-2026-540007.01.4osqueryosqueryCWE-122osquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processe…
CVE-2026-540017.01.4osqueryosqueryCWE-122osquery: Heap buffer overflow via `authenticode` table (Windows)
CVE-2026-451967.81.2Imagination TechnologiesGraphics DDKCWE-280GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized …
CVE-2026-210396.91.2Samsung MobileSamsung Mobile DevicesImproper access control in Settings prior to SMR Jul-2026 Release 1 allows lo…
CVE-2026-210416.91.2Samsung MobileSamsung Mobile DevicesImproper access control in SamsungSEAgentService prior to SMR Jul-2026 Releas…
CVE-2026-210505.11.2Samsung MobileSamsung Mobile DevicesImproper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 all…
CVE-2026-210515.11.2Samsung MobileSamsung Mobile DevicesIncorrect default permissions in WLAN security prior to SMR Jul-2026 Release …
CVE-2026-210406.90.9Samsung MobileSamsung Mobile DevicesImproper access control in IAFDService prior to SMR Jul-2026 Release 1 allows…
CVE-2026-210564.80.9Samsung MobileSamsung HealthImproper authorization in Samsung Health prior to version 7.00.0.107 allows l…
CVE-2026-210468.40.8Samsung MobileSamsung Mobile DevicesTime-of-check time-of-use race condition in fabricKeymaster trustlet prior to…
CVE-2026-210445.80.8Samsung MobileSamsung Mobile DevicesImproper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 al…
CVE-2026-463884.40.7osqueryosqueryCWE-279osquery: Unprivileged users can temporarily read file carve contents
CVE-2026-452037.80.6Imagination TechnologiesGraphics DDKCWE-367GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial …
CVE-2026-132434.80.5DrupalSalesforce SuiteCWE-352Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONT…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-10 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.