boxscore/security
Sunday, July 12, 2026 · all times UTC← 2026-07-11 · archive · 2026-07-13 →

63 CVEs published July 12, 2026: 3 critical, 17 high, 20 medium, 23 low; 0 in KEV; 4 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 38 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published24611477912952563
KEV catalog size1670

654 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux38151812186652812730.27.5.0013-58
google791343149604549387460.47.8.0023-511
microsoft54765585091774378283.77.8.0044-153
red hat36228149211012400.06.5.0026-4
apple0991236629377.16.5.0031-14
canonical1212685000.05.5.0011+1
suse61941140000.08.6.0036+6
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+20
cisco83141280961135.57.5.0056+5
palo alto networks1425021471428.04.7.0021+5
netgear01700161800.04.3.0024-17
checkpoint0915303111.17.5.0410-3
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-4
fortinet08132028337.57.3.0066-2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache61214418477114010.57.3.0048-6
mozilla35912182901300.07.3.0025-2
drupal465165355512.05.9.0018+46
gitlab74005276425.04.7.0024-4
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-3
adobe314913527927542.75.8.0021-121
ibm21263842460700.07.5.0025-9
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-3
veeam042200400.09.0.0046-1
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link11405352617.16.0.0058-7
siemens4130760100.07.1.0019-3
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-5
schneider electric060420100.07.8.0024-1
moxa050320000.07.0.0029-1
dahua030111200.06.9.0036-3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2899005346000.05.5.0026-7
dell3389441403211.17.0.0020+26
capgo2283242381000.07.1.0028+20
spring073231391000.06.5.0024-68
openclaw1680362210000.07.0.0021-33
edimax065039026100.07.4.00590
itsourcecode1063001944000.02.1.0020-12
themerex26055410000.08.1.0043+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-56291.760799.510.0
CVE-2026-48907.688399.310.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
Most disclosures (vendor)
VendorCVEs
google579
linux456
oracle240
red hat124
apache115
capgo81
microsoft68
ibm66
dell64
themerex60
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
adobe4
solarwinds4
synacor4
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven60
PyPI5
npm5
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-45659Microsoft0
CVE-2026-48282Adobe0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171698
CVE-2021-27102Accellion2021-11-171698
CVE-2021-27101Accellion2021-11-171698
CVE-2021-27103Accellion2021-11-171698
CVE-2021-21017Adobe2021-11-171698
CVE-2021-28550Adobe2021-11-171698
CVE-2021-42013Apache2021-11-171698
CVE-2021-41773Apache2021-11-171698
CVE-2021-30858Apple2021-11-171698
CVE-2021-30860Apple2021-11-171698

Transactions

EXPLOIT PUBLISHEDCVE-2026-10664 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10665 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10666 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10667 (zephyrproject zephyr). Public exploit reference added.

Yesterday's Results

63 CVEs published. 25 box scores, 38 table rows — nothing truncated.

Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0262   84.2     —
AFFECTED
  Product        Versions   Fixed
  CF-WR631AX V3  2.7.0.0 –  —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0156   73.2     —
AFFECTED
  Product     Versions   Fixed
  TEW-635BRM  1.00.03 –  —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0154   72.8     —
AFFECTED
  Product      Versions  Fixed
  sonic-agent  2.7.0 –   —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
SonicCloudOrg sonic-agent Groovy Script GroovyScriptImpl.java evalIsFailed os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.4     —
AFFECTED
  Product      Versions  Fixed
  sonic-agent  2.7.0 –   —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
TRENDnet TEW-821DAP DNS Lookup tools_nslookup sub_43F2C4 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0107   62.1     —
AFFECTED
  Product     Versions   Fixed
  TEW-821DAP  1.11B03 –  —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
TRENDnet TEW-821DAP Firmware Update tools_ddns sub_42026C os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0107   62.1     —
AFFECTED
  Product     Versions   Fixed
  TEW-821DAP  1.11B03 –  —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
TRENDnet TEW-821DAP Firmware Update system_ntp sub_41FBD0 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0107   62.1     —
AFFECTED
  Product     Versions   Fixed
  TEW-821DAP  1.11B03 –  —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0107   62.0     —
AFFECTED
  Product     Versions  Fixed
  WL-NU516U1  260515 –  —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
openwrt luci — LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   N   P   H   H   H    9.4   .0085   55.2     —
AFFECTED
  Product  Versions     Fixed
  luci     unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 12  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · 2 references · NVD status: Awaiting Analysis
OpenWrt luci-app-samba4 read ACL remote code execution via smbd
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0071   50.7     —
AFFECTED
  Product  Versions     Fixed
  luci     unspecified  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 12  Published (CNA: VulnCheck)
CWE-269 · CNA: VulnCheck · 2 references · NVD status: Deferred
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  H  H    8.3   .0048   39.3     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 12  Published (CNA: microsoft)
CWE-822 · CNA: microsoft · 1 reference · NVD status: Analyzed
TRENDnet TEW-821DAP ssi tools_nslookup sub_41EC14 buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0047   38.8     —
AFFECTED
  Product     Versions   Fixed
  TEW-821DAP  1.12B01 –  —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · 5 references · NVD status: Deferred
TRENDnet TEW-821DAP ssi tools_nslookup sub_41EC14 buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0047   38.8     —
AFFECTED
  Product     Versions   Fixed
  TEW-821DAP  1.12B01 –  —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · 5 references · NVD status: Deferred
Trendnet TEW-635BRM Web Service rc start_httpd stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.8     —
AFFECTED
  Product     Versions   Fixed
  TEW-635BRM  1.00.03 –  —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Deferred
zephyrproject zephyr — Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0045   37.6     —
AFFECTED
  Product  Versions  Fixed
  zephyr   1.9.0 –   —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 12  Public exploit reference published
  Jul 12  Published (CNA: zephyr)
CWE-121 · CNA: zephyr · 3 references · NVD status: Analyzed
zephyrproject zephyr — Heap buffer overflow on WireGuard receive path via unbounded incoming packet length
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  H  H    7.4   .0044   36.8     —
AFFECTED
  Product  Versions  Fixed
  zephyr   4.4.0 –   —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 12  Public exploit reference published
  Jul 12  Published (CNA: zephyr)
CWE-787 · CNA: zephyr · 2 references · NVD status: Analyzed
Crawl4AI - Arbitrary File Write via output_path Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   H   H    8.8   .0042   35.1     —
AFFECTED
  Product   Versions     Fixed
  Crawl4AI  unspecified  0.8.7
TIMELINE
  Jun 19  Reserved by CNA
  Jul 12  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 3 references · NVD status: Analyzed
SonicCloudOrg sonic-agent JWT Authentication Filter ExchangeController.java code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0039   32.5     —
AFFECTED
  Product      Versions  Fixed
  sonic-agent  2.7.0 –   —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-74, CWE-94 · CNA: VulDB · 5 references · NVD status: Deferred
RafyMrX TOKO-ONLINE-ROTI missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0038   31.5     —
AFFECTED
  Product           Versions                                    Fixed
  TOKO-ONLINE-ROTI  ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99 –  —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · 4 references · NVD status: Deferred
Flowise - Weak Default JWT Secrets in Authentication Middleware
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0038   30.7     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.1.0
TIMELINE
  Jun 20  Reserved by CNA
  Jul 12  Published (CNA: VulnCheck)
CWE-321 · CNA: VulnCheck · 2 references · NVD status: Analyzed
Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0037   29.8     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 19  Reserved by CNA
  Jul 12  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · 2 references · NVD status: Deferred
hcr707305003 shiroiAdmin FileController.php upload unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0031   24.1     —
AFFECTED
  Product      Versions  Fixed
  shiroiAdmin  1.1 –     1.4
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · 7 references · NVD status: Deferred
Crawl4AI - LLM Credential Exfiltration via base_url and Environment Variable Resolution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   N    8.8   .0031   23.4     —
AFFECTED
  Product   Versions     Fixed
  Crawl4AI  unspecified  0.8.8
TIMELINE
  Jun 19  Reserved by CNA
  Jul 12  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · 2 references · NVD status: Analyzed
openwrt luci — luci-app-upnp Stored XSS via UPnP Port Mapping Description
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   L    8.7   .0029   21.4     —
AFFECTED
  Product  Versions     Fixed
  luci     unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 12  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · 2 references · NVD status: Deferred
H3C NX15 Administrator Password Modification Endpoint modify change_passwd password recovery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0028   20.9     —
AFFECTED
  Product  Versions    Fixed
  NX15     V100R017 –  —
TIMELINE
  Jul 11  Reserved by CNA
  Jul 12  Published (CNA: VulDB)
CWE-640 · CNA: VulDB · 5 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-563137.220.1CapgoCapgoCWE-285Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint
CVE-2026-154825.519.8Aster TelecomAzcallCWE-74Aster Telecom Azcall HTTP sis.php sql injection
CVE-2026-154895.519.8RafyMrXTOKO-ONLINE-ROTICWE-74RafyMrX TOKO-ONLINE-ROTI login.php sql injection
CVE-2026-154905.519.0RafyMrXTOKO-ONLINE-ROTICWE-74RafyMrX TOKO-ONLINE-ROTI add.php sql injection
CVE-2026-154922.118.3igwezewizgradeCWE-79igweze wizgrade studentConductManager.php cross site scripting
CVE-2026-154986.917.1sergomanovSmartHomeAdatumCWE-74sergomanov SmartHomeAdatum Login users.php sql injection
CVE-2026-155145.517.1Metasoft 美特软件MetaCRMCWE-74Metasoft 美特软件 MetaCRM PHPRPC Remote Call rpc.jsp RPCService.query sql injection
CVE-2026-563088.415.9CapgoCapgoCWE-640Capgo - Insufficient Authentication in Email Change Endpoint
CVE-2026-106645.014.5zephyrprojectzephyrCWE-787Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded…
CVE-2026-155122.113.7pig-meshPigCWE-74pig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection
CVE-2026-562417.211.6CapgoCapgoCWE-285Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right
CVE-2026-155002.111.4AstrBotDevsAstrBotCWE-918AstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-…
CVE-2026-154712.111.1EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software pci_dss_status.jsp improper authorization
CVE-2026-154722.111.1EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software composeEmailAction.do improper authorization
CVE-2026-154742.111.1EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software audio.jsp improper authorization
CVE-2026-155012.110.9AstrBotDevsAstrBotCWE-918AstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection…
CVE-2026-155072.110.9coollabsioCoolifyCWE-862coollabsio Coolify Policy Policies authorization
CVE-2026-155082.110.9Heliconeai-gatewayCWE-918Helicone ai-gateway AWS Metadata Service service.rs build_target_url server-s…
CVE-2026-155092.110.9n/aLeantimeCWE-266Leantime JSON-RPC Endpoint addUser improper authorization
CVE-2026-155102.110.9n/aLeantimeCWE-266Leantime API saveSetting improper authorization
CVE-2026-563366.910.8CapgoCapgoCWE-200Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint
CVE-2026-154772.110.8BahmnibahmnicoreCWE-74Bahmni bahmnicore Search Endpoint sql additionalParams sql injection
CVE-2026-154942.010.4AMTTHotel Broadband Operation SystemCWE-74AMTT Hotel Broadband Operation System switch_status.php sql injection
CVE-2026-154732.110.4EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper a…
CVE-2026-154992.110.4AstrBotDevsAstrBotCWE-266AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper…
CVE-2026-618742.39.9filebrowserfilebrowserCWE-863filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete
CVE-2026-562815.19.8CapgoCapgoCWE-89Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint
CVE-2026-155025.39.7AojiaoZeroAntarisCWE-74AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
CVE-2026-154782.19.7n/aIceHRMCWE-74IceHRM UserReport Endpoint EmployeeAttendanceReport.php sql injection
CVE-2026-155052.09.5vnotexvnoteCWE-79vnotex vnote YAML Frontmatter markdownit.js cross site scripting
CVE-2026-154935.19.1Akpali9Attendance-Management-SystemCWE-79Akpali9 Attendance-Management-System absent.php cross site scripting
CVE-2026-562525.36.6CapgoCapgoCWE-863Capgo - Scope Isolation Failure in Webhook Test Endpoint
CVE-2026-106636.15.5zephyrprojectzephyrCWE-416Use-after-free / double-free of the root USB device in the experimental USB h…
CVE-2026-106684.65.5zephyrprojectzephyrCWE-400Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC d…
CVE-2026-106677.84.9zephyrprojectzephyrCWE-416SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object trackin…
CVE-2026-155067.13.9SecureAgeCatchPulseCWE-119SecureAge CatchPulse Driver saappctl.sys heap-based overflow
CVE-2026-154761.91.2QILINGDisk MasterCWE-266QILING Disk Master Kernel Driver diskbckp.sys access control
CVE-2026-154751.91.2MiniToolPartition WizardCWE-266MiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-12 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.