boxscore/security
Monday, July 13, 2026 · all times UTC← 2026-07-12 · archive · 2026-07-14 →

337 CVEs published July 13, 2026: 49 critical, 147 high, 108 medium, 32 low; 1 in KEV; 8 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 312 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published27981511612952563
KEV catalog size1670

680 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux40152012186653012730.27.5.0013-56
google791343149604549387460.47.8.0023-512
microsoft54765585091774378283.77.8.0044-153
red hat39231149411112400.06.5.0026-5
apple0991236629377.16.5.0031-14
canonical1212685000.05.5.0011+1
suse61941140000.08.6.0036+6
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+20
cisco93241280961237.57.5.0066+6
palo alto networks1425021471428.04.7.0021+5
netgear01700161800.04.3.0024-17
checkpoint0915303111.17.5.0410-3
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-4
fortinet08132028337.57.3.0066-2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache65218428678114010.57.3.0048-2
mozilla46012183001300.06.9.0025-1
drupal465165355512.05.9.0018+46
gitlab74005276425.04.7.0024-4
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-3
adobe515113547927542.66.2.0021-119
ibm21263842460700.07.5.0025-9
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-3
veeam042200400.09.0.0046-1
zohocorp031110000.08.4.01700
servicenow111000200.09.5.2673+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link11405352617.16.0.0058-8
siemens4130760100.07.1.0019-3
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-5
schneider electric060420100.07.8.0024-1
moxa050320000.07.0.0029-1
dahua030111200.06.9.0036-3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester35106005551000.05.5.0026-1
dell3389441403211.17.0.0020+26
capgo2283242381000.07.1.0028+20
openclaw16830482510000.07.2.0021-18
spring073231391000.06.5.0024-68
edimax065039026100.07.4.00590
itsourcecode1164001945000.02.1.0020-11
themerex26055410000.08.1.0043+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-56291.760799.510.0
CVE-2026-48907.688399.310.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
Most disclosures (vendor)
VendorCVEs
google578
linux458
oracle240
red hat123
apache119
capgo81
microsoft68
ibm66
dell64
themerex60
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco12
apple7
google6
ivanti5
adobe4
solarwinds4
synacor4
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven61
PyPI5
npm5
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2025-67038Lantronix0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-45659Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171699
CVE-2021-27102Accellion2021-11-171699
CVE-2021-27101Accellion2021-11-171699
CVE-2021-27103Accellion2021-11-171699
CVE-2021-21017Adobe2021-11-171699
CVE-2021-28550Adobe2021-11-171699
CVE-2021-42013Apache2021-11-171699
CVE-2021-41773Apache2021-11-171699
CVE-2021-30858Apple2021-11-171699
CVE-2021-30860Apple2021-11-171699

Transactions

EXPLOIT PUBLISHEDCVE-2026-51536. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-51537. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-51538. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-51540. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-51541. Public exploit reference added.

Yesterday's Results

337 CVEs published. 25 box scores, 312 table rows — nothing truncated.

CVE-2008-4128AWAITING ENRICHMENT
Cisco IOS
  CVSS   EPSS    %ile   KEV
  —      .3295   98.2   YES
AFFECTED
  Product  Versions     Fixed
  IOS      unspecified  —
TIMELINE
  Jul 13  Added to CISA KEV, due Jul 16
  Jul 13  Published
0 references · KEV due July 16, 2026
ServiceNow ServiceNow AI Platform — Sandbox Escape in ServiceNow AI Platform
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.5   .2673   97.9     —
AFFECTED
  Product                 Versions     Fixed
  ServiceNow AI Platform  unspecified  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 13  Published (CNA: SN)
CWE-94 · CNA: SN · 1 reference · NVD status: Awaiting Analysis
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0409   89.9     —
AFFECTED
  Product   Versions  Fixed
  Flamingo  4.12.2 –  —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 3 references · NVD status: Analyzed
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0234   82.2     —
AFFECTED
  Product   Versions  Fixed
  Flamingo  4.12.2 –  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 3 references · NVD status: Analyzed
decolua 9Router — 9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0224   81.4     —
AFFECTED
  Product  Versions     Fixed
  9Router  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 2 references · NVD status: Deferred
Shibby Tomato start_jffs2 sub_2D568 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0105   61.4     —
AFFECTED
  Product  Versions  Fixed
  Tomato   1.0 –     —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Shibby Tomato CIFS Mount sub_2D048 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0105   61.4     —
AFFECTED
  Product  Versions  Fixed
  Tomato   1.0 –     —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
EVbee DC-80 — Command injection in diagnosis web endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0091   57.0     —
AFFECTED
  Product  Versions     Fixed
  DC-80    unspecified  —
TIMELINE
  Jan 6   Reserved by CNA
  Jul 13  Published (CNA: DIVD)
CWE-77 · CNA: DIVD · 1 reference · NVD status: Deferred
EVbee DC-80 — Command injection in NPC start web endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0091   57.0     —
AFFECTED
  Product  Versions     Fixed
  DC-80    unspecified  —
TIMELINE
  Jan 6   Reserved by CNA
  Jul 13  Published (CNA: DIVD)
CWE-77 · CNA: DIVD · 1 reference · NVD status: Deferred
EVbee DC-80 — Comnand injection in OCPP ReserveLogin message
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0081   53.9     —
AFFECTED
  Product  Versions     Fixed
  DC-80    unspecified  —
TIMELINE
  Jan 6   Reserved by CNA
  Jul 13  Published (CNA: DIVD)
CWE-78 · CNA: DIVD · 1 reference · NVD status: Deferred
plank laravel-mediable — Laravel-Mediable < 7.0.0 File Upload RCE via Extension Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    7.7   .0078   52.8     —
AFFECTED
  Product           Versions     Fixed
  laravel-mediable  unspecified  —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 3 references · NVD status: Deferred
plank laravel-mediable — Laravel-Mediable < 7.0.0 Path Traversal via File::sanitizePath()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0077   52.6     —
AFFECTED
  Product           Versions     Fixed
  laravel-mediable  unspecified  —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 3 references · NVD status: Deferred
Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0075   51.9     —
AFFECTED
  Product  Versions  Fixed
  hfs      3.0.0 –   —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-338 · CNA: VulnCheck · 2 references · NVD status: Deferred
n/a n/a — OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentSer…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0075   51.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Feb 16  Reserved by CNA
  Jul 13  Published (CNA: mitre)
CWE-22 · CNA: mitre · 1 reference · NVD status: Deferred
4real ThemisNETPanel — Unauthenticated Remote Code Execution in ThemisNETPanel
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0058   45.1     —
AFFECTED
  Product         Versions     Fixed
  ThemisNETPanel  unspecified  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 13  Published (CNA: CERT-PL)
CWE-306 · CNA: CERT-PL · 1 reference · NVD status: Awaiting Analysis
Shibby Tomato DNS List Rendering httpd sub_407220 stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0056   43.8     —
AFFECTED
  Product  Versions  Fixed
  Tomato   1.0 –     —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Deferred
n/a n/a — SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to ex…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 13  Published (CNA: mitre)
CWE-89 · CNA: mitre · 2 references · NVD status: Deferred
Centreon Infra Monitoring — A user with low privileges can inject SSTI templates that can lead to RCE in open-tickets
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  H    9.6   .0050   40.9     —
AFFECTED
  Product           Versions   Fixed
  Infra Monitoring  24.10.0 –  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 13  Published (CNA: Centreon)
CWE-94 · CNA: Centreon · 1 reference · NVD status: Awaiting Analysis
n/a n/a — In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, th…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0049   40.1     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 13  Public exploit reference published
  Jul 13  Published (CNA: mitre)
CWE-190 · CNA: mitre · 2 references · NVD status: Analyzed
n/a n/a — EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0048   39.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 13  Public exploit reference published
  Jul 13  Published (CNA: mitre)
CWE-125 · CNA: mitre · 2 references · NVD status: Analyzed
Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0048   39.2     —
AFFECTED
  Product                      Versions     Fixed
  Apache Airflow Git provider  unspecified  —
TIMELINE
  Jun 28  Reserved by CNA
  Jul 13  Published (CNA: apache)
CWE-322 · CNA: apache · 3 references · NVD status: Modified
Tenda CH22 CertListInfo formCertListInfo buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0048   39.1     —
AFFECTED
  Product  Versions   Fixed
  CH22     1.0.0.1 –  —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · 6 references · NVD status: Deferred
Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0047   39.0     —
AFFECTED
  Product           Versions  Fixed
  Apache Gravitino  1.0.0 –   —
TIMELINE
  Apr 16  Reserved by CNA
  Jul 13  Published (CNA: apache)
CWE-177 · CNA: apache · 2 references · NVD status: Analyzed
Thales CERT Suspicious — Remote Code Execution vulnerability in "Suspicious" application
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0047   38.7     —
AFFECTED
  Product     Versions  Fixed
  Suspicious  v1.2.0 –  patched v1.3.5
TIMELINE
  Jun 23  Reserved by CNA
  Jul 13  Published (CNA: THA-PSIRT)
CWE-22, CWE-73, CWE-94 · CNA: THA-PSIRT · 1 reference · NVD status: Awaiting Analysis
ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0046   37.8     —
AFFECTED
  Product  Versions   Fixed
  CRM      < 7.4.0 –  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 13  Published (CNA: GitHub_M)
CWE-434 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-615056.937.5rejettohfsCWE-22Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter
CVE-2026-47699.337.2WAGO0765-110x/0100-0000CWE-912Unauthenticated Access to Internal Diagnostic Interface
CVE-2026-621848.737.0openwrtluci-app-banipCWE-116luci-app-banip Log Monitor IP Extraction Bypass
CVE-2026-155447.436.5ShibbyTomatoCWE-119Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow
CVE-2026-132219.136.0SHAYperlCWE-190Perl versions through 5.43.9 produce silently incorrect regular expression ma…
CVE-2026-515409.835.1n/an/aCWE-191OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe m…
CVE-2026-515419.135.1n/an/aCWE-125OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message …
CVE-2026-525339.834.5n/an/aCWE-269An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escal…
CVE-2026-122579.334.2Mura SoftwareCMSCWE-94Remote code execution in Mura Software’s CMS
CVE-2026-390427.534.1n/an/aCWE-190An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4…
CVE-2026-577438.133.5stmcanRT-Theme 18 | ExtensionsCWE-98WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulne…
CVE-2026-155426.933.5will-mossIsaiahCWE-287will-moss Isaiah Websocket Connection Authentication main.go improper authent…
CVE-2026-498766.533.4Apache Software FoundationApache GravitinoCWE-918Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-si…
CVE-2026-155575.532.9waooAIwaoowaooCWE-287waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight impr…
CVE-2026-155457.432.8ShibbyTomatoCWE-119Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write
CVE-2026-156857.532.2OllamaOllamaCWE-129Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vuln…
CVE-2026-568776.332.3SkillableSCORM Lab Launch IntegrationCWE-472The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026…
CVE-2026-578568.732.1Cockpit HQCockpit CMSCWE-22Cockpit CMS Path Traversal via Bucket Name in Bucket File Storage API
CVE-2026-515389.132.0n/an/aCWE-284EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access …
CVE-2026-582285.131.3phoenixframeworkphoenix_live_viewCWE-79Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>
CVE-2026-614629.231.2zereightmcp-gitlabCWE-73mcp-gitlab Path Traversal via job_id Parameter
CVE-2026-577249.830.6ThemeumKirkiCWE-502WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability
CVE-2026-577389.830.6axiomthemes777CWE-502WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability
CVE-2026-574019.930.2Brainstorm ForceSureDashCWE-22WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability
CVE-2026-623279.330.2decolua9RouterCWE-3069Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats
CVE-2026-623288.730.2decolua9RouterCWE-3599Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
CVE-2026-573898.630.3Adrian TobeyGroundhoggCWE-22WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability
CVE-2026-577098.630.3WP SwingsMembership For WooCommerceCWE-22WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletio…
CVE-2026-577887.530.1Edge-ThemesAaltoCWE-98WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability
CVE-2026-577897.530.1jwsthemesAquaCWE-98WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability
CVE-2026-577907.530.1ThemeMoveBilleyCWE-98WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability
CVE-2026-577917.530.1ThemeMoveBrookCWE-98WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability
CVE-2026-577927.530.1Mikado-ThemesDørCWE-98WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability
CVE-2026-577937.530.1Elated-ThemesFlowCWE-98WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability
CVE-2026-577947.530.1uxperGolo FrameworkCWE-98WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability
CVE-2026-577957.530.1themelexusKitchorCWE-98WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability
CVE-2026-577967.530.1VLThemesLeedoCWE-98WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability
CVE-2026-577987.530.1SaurabhSharmaNewsPlus ShortcodesCWE-98WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerab…
CVE-2026-577997.530.1uxperNussCWE-98WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability
CVE-2026-578007.530.1Edge-ThemesOverworldCWE-98WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability
CVE-2026-578017.530.1Select-ThemesSetSailCWE-98WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability
CVE-2026-578027.530.1Select-ThemesStrukturCWE-98WordPress Struktur theme < 2.7 - Local File Inclusion vulnerability
CVE-2026-578037.530.1Select-ThemesStruktur CoreCWE-98WordPress Struktur Core plugin < 2.7 - Local File Inclusion vulnerability
CVE-2026-578047.530.1CodexThemesTheGem Theme Elements (for Elementor)CWE-98WordPress TheGem Theme Elements (for Elementor) plugin < 5.12.1.1 - Local Fil…
CVE-2026-614638.729.9go-shiorishioriCWE-269Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account
CVE-2026-592458.129.1Apache Software FoundationApache Airflow FAB providerCWE-269Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the…
CVE-2026-584875.128.9hedgedochedgedocCWE-79HedgeDoc: Stored HTML injection via email local-part
CVE-2026-574339.828.8HAARGStorableCWE-190Storable versions before 3.41 for Perl have a signed integer overflow when de…
CVE-2026-5771910.027.8CodeRevolutionAimogen ProCWE-434WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability
CVE-2026-584117.027.7ChurchCRMCRMCWE-79ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request pa…
CVE-2026-155962.127.8SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System subject.php cross site scrip…
CVE-2026-557718.827.5cedar-policycedar-javaCWE-94CedarJava has policy injection, type confusion, and incorrect equality compar…
CVE-2026-573718.827.4denishuaWPJAM BasicCWE-502WordPress WPJAM Basic plugin <= 7.0 - PHP Object Injection vulnerability
CVE-2026-515397.527.3n/an/aCWE-400A Denial of Service (DoS) vulnerability exists in the receive loop of libmodb…
CVE-2026-615036.927.3rejettohfsCWE-204Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences
CVE-2026-155975.525.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection
CVE-2026-578157.525.4WPMU DEV - Your All-in-One WordPress PlatformForminatorCWE-22WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability
CVE-2026-577109.924.7quantumcloudWoowBot Pro MaxCWE-434WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability
CVE-2026-576977.524.7MetagaussProfileGridCWE-288WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability
CVE-2026-155416.924.4will-mossIsaiahCWE-862will-moss Isaiah Master Websocket server.go Server.Handle authorization
CVE-2026-221029.324.1EVbeeDC-80CWE-20Arbitrary file overwrite through certificate update functionality
CVE-2026-622408.324.2crewAIInccrewAICWE-918CrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools
CVE-2026-155985.324.0antvlayoutCWE-94antv layout object.js setNestedValue prototype pollution
CVE-2026-220969.323.9EVbeeDC-80CWE-306Missing authentication for webserver endpoints
CVE-2026-5781110.023.8RealtynaRealtyna Organic IDX pluginCWE-94WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution…
CVE-2026-155305.523.8n/aWuzhiCMSCWE-200WuzhiCMS Attachment API index.php listimage information disclosure
CVE-2026-577138.823.4Marcus (aka @msykes)Events ManagerCWE-502WordPress Events Manager plugin <= 7.3.6 - PHP Object Injection vulnerability
CVE-2026-615015.323.5rejettohfsCWE-79Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer
CVE-2026-577449.823.0stmcanRT-Theme 18 | ExtensionsCWE-502WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulne…
CVE-2026-577709.823.0ThemeGoodsGrand PhotographyCWE-502WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability
CVE-2026-595189.823.0wpWaxDirectoristCWE-502WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability
CVE-2026-614588.723.0pglombardoPasswordPusherCWE-307PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint
CVE-2026-578308.822.9joomshaper.comHelix Ultimate extension for JoomlaCWE-862Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion i…
CVE-2026-578057.522.6Select-ThemesTondaCWE-98WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability
CVE-2026-155942.922.4waooAIwaoowaooCWE-266waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authoriza…
CVE-2026-621998.722.0OpenClawOpenClawCWE-184OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering
CVE-2026-622008.722.0OpenClawOpenClawCWE-184OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport
CVE-2026-584886.922.1hedgedochedgedocCWE-290HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
CVE-2026-557738.822.0cedar-policycedar-javaCWE-94CedarJava has a policy injection vulnerability
CVE-2026-577745.321.8vowelwebVW Food CornerCWE-862WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability
CVE-2026-577765.321.8vowelwebVW WeddingCWE-862WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability
CVE-2026-595217.221.6ShapedPlugin LLCReal TestimonialsCWE-502WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerabi…
CVE-2026-405535.121.5GNUgawkCWE-121Stack-based buffer overflow in gawk
CVE-2026-577277.521.2ThemeumKirkiCWE-862WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability
CVE-2026-621908.721.0OpenClawOpenClawCWE-706OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper
CVE-2026-621858.620.9argoprojargo-helmCWE-1188Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE
CVE-2026-577029.320.8Melograno Venture StudioAmeliaCWE-89WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability
CVE-2026-577079.320.8quantumcloudSimple Business Directory ProCWE-89WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vuln…
CVE-2026-577149.320.8LatePointLatePointCWE-89WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability
CVE-2026-577269.320.8ThemeumKirkiCWE-89WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability
CVE-2026-577399.320.8AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCWE-89WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulner…
CVE-2026-578558.720.8Cockpit HQCockpit CMSCWE-284Cockpit CMS Missing Authorization in Bucket File Storage API
CVE-2026-622427.720.8codecentricspring-boot-adminCWE-918Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration
CVE-2026-573868.820.2Kodezen LLCaBlocksCWE-266WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability
CVE-2026-574108.820.2MailerPress TeamMailerPressCWE-266WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability
CVE-2026-577297.520.3UX-themesFlatsomeCWE-862WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVE-2026-155952.120.3SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System forsubject.php cross site sc…
CVE-2026-585008.220.0appiumappium-mcpCWE-79MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGener…
CVE-2026-119649.119.9UnknownUser Registration & MembershipUser Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signa…
CVE-2026-155162.919.8n/aMacCMS ProCWE-285MacCMS Pro Installation Index.php step5 authorization
CVE-2026-557728.819.6cedar-policycedar-javaCWE-843CedarJava has a type confusion vulnerability
CVE-2026-47655.119.6RD Station ConversasTallos ChatCWE-79Stored Cross-Site Scripting (XSS) in Tallos Chat by RD Station Conversas
CVE-2026-577737.619.3ZoremAdvanced Shipment Tracking for WooCommerceCWE-89WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Inje…
CVE-2026-573936.519.2EDGARROJASWooCommerce PDF Invoice BuilderCWE-497WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Ex…
CVE-2026-155375.518.2SourceCodesterOnline Book Store SystemCWE-74SourceCodester Online Book Store System login.php sql injection
CVE-2026-125828.618.1UnknownLibrary Management SystemLibrary Management System < 3.5.8 - Unauthenticated SQL Injection via book_id
CVE-2026-578139.817.9properfractionMailOptinCWE-266WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability
CVE-2026-156807.517.8Lorex2K Indoor Wi-Fi Security CameraCWE-134Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Co…
CVE-2026-155747.517.7Red HatRed Hat OpenShift AI (RHOAI)CWE-538Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header an…
CVE-2026-155295.317.6yzhao062pyodCWE-20yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization
CVE-2026-155385.317.3primefacesprimereactCWE-94primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
CVE-2026-155175.517.1JinherOACWE-74Jinher OA PlanGiveOut.aspx sql injection
CVE-2026-156072.117.1tanstackdbCWE-94tanstack db Alias Path select.ts select prototype pollution
CVE-2026-220989.216.9EVbeeDC-80CWE-532Sensitive information is written to logs
CVE-2026-573858.516.9appsbdViteposCWE-89WordPress Vitepos plugin <= 3.4.2 - SQL Injection vulnerability
CVE-2026-577718.516.9Milan PetrovicGD Rating SystemCWE-89WordPress GD Rating System plugin <= 3.7 - SQL Injection vulnerability
CVE-2026-577728.516.9WP InventoryWP Inventory ManagerCWE-89WordPress WP Inventory Manager plugin <= 2.4.0 - SQL Injection vulnerability
CVE-2026-577878.516.9CreativeWSCWS SVGiconsCWE-89WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability
CVE-2026-621948.716.7OpenClawOpenClawCWE-732OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install
CVE-2026-155536.916.7RagicEnterprise Cloud DatabaseCWE-434Ragic|Enterprise Cloud Database - Arbitrary File Upload
CVE-2026-148464.516.7PrestaShopThe firmwareCWE-1236Incorrect neutralisation in the PrestaShop firmware
CVE-2026-573646.516.3WPDeveloperBetter Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; MoreCWE-1284WordPress Better Payment – Instant Payments, Donations, Fundraising with Subs…
CVE-2026-573956.516.3ThemeficTourficCWE-862WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
CVE-2026-574186.516.3BoldGridClient Invoicing by Sprout InvoicesCWE-862WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Acce…
CVE-2026-155182.016.4AREA 17Twill CMSCWE-284AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile un…
CVE-2026-155332.016.4n/aDedeCMSCWE-74DedeCMS Column Management search.php code injection
CVE-2026-155352.116.2AkariAsaiself-ragCWE-20AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserializa…
CVE-2026-621897.616.2OpenClawOpenClawCWE-59OpenClaw < 2026.6.9 Symlink Following via Mirror Sync
CVE-2026-141657.516.2Dassault SystèmesTuleap Enterprise EditionCWE-639Authorization Bypass Through User-Controlled Key vulnerability affecting Tule…
CVE-2026-155847.516.1Red HatPen Drive Powered by Red Hat LightspeedCWE-250Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot deb…
CVE-2026-576986.515.9VillaThemeAbandoned Cart Recovery for WooCommerceCWE-288WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken A…
CVE-2026-595159.315.7SergeyAIWUCWE-89WordPress AIWU plugin <= 1.5.4 - SQL Injection vulnerability
CVE-2026-573776.515.6WPXPOWowAddonsCWE-862WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability
CVE-2026-573906.515.6EDGARROJASExtra Product Options Builder for WooCommerceCWE-862WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - B…
CVE-2026-573926.515.6ThemeficTourficCWE-862WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
CVE-2026-574046.515.6magepeopleteamBooking and Rental ManagerCWE-862WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control …
CVE-2026-574086.515.6peachpaymentsPeach Payments GatewayCWE-862WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vuln…
CVE-2026-574126.515.6CodemenschenGift VouchersCWE-862WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability
CVE-2026-574246.515.6knitpayRazorpay Payment Links for WooCommerceCWE-862WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Acc…
CVE-2026-123854.315.7nextendwebSmart Slider 3CWE-200Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contribu…
CVE-2026-155402.115.6SourceCodesterOnline Book Store SystemCWE-73SourceCodester Online Book Store System Administrative index.php php file inc…
CVE-2026-499695.315.4planklaravel-mediableCWE-918Laravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL Handling
CVE-2026-68506.515.4MattermostMattermostCWE-1333Crafted message attachment causes client-side denial of service via markdown …
CVE-2026-577974.315.3ThemeMoveEduMallCWE-862WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability
CVE-2026-156182.115.3mosaxivclawletCWE-693mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection me…
CVE-2026-621438.315.2mispmisp-modulesCWE-918Server-Side Request Forgery protection bypass in misp-modules html_to_markdow…
CVE-2026-573787.515.1Phil KurthAdvanced FormsCWE-862WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability
CVE-2026-577057.515.1NexcessEvent TicketsCWE-862WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability
CVE-2026-155191.315.1usestrixstrixCWE-829usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted c…
CVE-2026-576946.515.0ThemeumTutor LMSCWE-639WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDO…
CVE-2026-584868.314.6hedgedochedgedocCWE-400HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter
CVE-2026-574006.514.7WP SwingsEvent Tickets Manager for WooCommerceCWE-862WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Acce…
CVE-2026-574066.514.7RoxnorFundEngineCWE-862WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability
CVE-2026-621927.214.4OpenClawOpenClawCWE-863OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass
CVE-2026-621958.714.0OpenClawOpenClawCWE-732OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback
CVE-2026-621968.714.0OpenClawOpenClawCWE-863OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs
CVE-2026-155392.013.6SourceCodesterOnline Book Store SystemCWE-284SourceCodester Online Book Store System Book Image Upload Feature index.php b…
CVE-2026-149349.413.6Google CloudBigQueryCWE-862Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dat…
CVE-2026-619557.613.5Hannanگرویتی فرم فارسیCWE-89WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability
CVE-2026-574057.113.5themehunkOpen ShopCWE-862WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability
CVE-2026-577407.113.5AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCWE-862WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Contro…
CVE-2026-577688.212.9favethemesHouzez Login RegisterCWE-266WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulner…
CVE-2026-584086.512.4ChurchCRMCRMCWE-862ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privilege…
CVE-2026-581029.112.0JONASBNCrypt::OpenSSL::X509CWE-125Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bound…
CVE-2026-155252.112.1kLOskadloopCWE-918kLOsk adloop write.py _validate_urls server-side request forgery
CVE-2026-621878.611.9openclawfeishuCWE-863OpenClaw < 2026.6.9 Feishu tools Authorization Bypass
CVE-2026-621888.611.9openclawfeishuCWE-863OpenClaw < 2026.6.9 Feishu Authorization Bypass
CVE-2026-404675.111.9GNUgawkCWE-416Use after free in gawk
CVE-2026-404695.111.9GNUgawkCWE-190Heap buffer overflow in gawk
CVE-2026-574196.511.8Fahad MahmoodStock Locations for WooCommerceCWE-862WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Con…
CVE-2026-574328.411.6SHAYperlCWE-125Perl versions through 5.43.10 have an integer overflow in S_measure_struct le…
CVE-2026-97084.911.5MattermostMattermostCWE-639Incoming webhook user attribution via unvalidated webhook owner
CVE-2026-155321.911.5SourceCodesterOnline Book Store SystemCWE-79SourceCodester Online Book Store System User Management cross site scripting
CVE-2026-621476.511.3Red HatRed Hat OpenShift distributed tracing 3CWE-863Tempo-operator: tempo operator: query rbac bypass
CVE-2026-220979.311.2EVbeeDC-80CWE-347Missing firmware validation allows remote code execution
CVE-2026-577785.311.2wpdevartBooking calendar, Appointment Booking SystemCWE-862WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Bro…
CVE-2026-577795.311.2themebeezFascinateCWE-862WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability
CVE-2026-577815.311.2SovlixMeetingHubCWE-862WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability
CVE-2026-577825.311.2PressTigersUniversal ClocksCWE-862WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability
CVE-2026-621917.111.1OpenClawOpenClawCWE-862OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations
CVE-2026-578108.510.8Saad IqbalAPIExperts Square for WooCommerceCWE-89WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection v…
CVE-2026-155525.310.8RagicEnterprise Cloud DatabaseCWE-79Ragic|Enterprise Cloud Database - Stored Cross-Site Scripting
CVE-2026-581017.510.7JONASBNCrypt::OpenSSL::X509CWE-476Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service v…
CVE-2026-499715.310.6planklaravel-mediableCWE-79Laravel-Mediable < 7.0.0 Stored XSS via SVG File Upload
CVE-2026-119638.110.3UnknownUser Registration & MembershipUser Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Memb…
CVE-2026-404682.110.3GNUgawkCWE-190Heap buffer overflow in gawk
CVE-2025-458697.310.1n/an/aCWE-918LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server…
CVE-2026-155232.110.2CodeAstroSimple Online Leave Management SystemCWE-74CodeAstro Simple Online Leave Management System dashboard.php sql injection
CVE-2026-155362.110.2itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patviewprescription.php sql injection
CVE-2026-155582.110.2CodeAstroSimple Online Leave Management SystemCWE-74CodeAstro Simple Online Leave Management System deletemp.php sql injection
CVE-2026-155592.110.2CodeAstroSimple Online Leave Management SystemCWE-74CodeAstro Simple Online Leave Management System POST accept.php sql injection
CVE-2026-621976.310.0OpenClawOpenClawCWE-918OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery
CVE-2026-619755.39.8CrocoblockJetReviewsCWE-497WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability
CVE-2026-619765.39.8CrocoblockJetBlocks For ElementorCWE-497WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure v…
CVE-2026-619775.39.8CrocoblockJetSearchCWE-497WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability
CVE-2026-573756.59.4FluxBuilderMStore APICWE-862WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability
CVE-2026-619524.99.3Jose VegaWooCommerce Bulk Edit Products – WP Sheet EditorCWE-862WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 -…
CVE-2026-621867.29.2OpenClawOpenClawCWE-862OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override
CVE-2026-619712.79.2CozmoslabsUser Profile PictureCWE-639WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object Refer…
CVE-2026-578126.59.0NSquaredSimply Schedule AppointmentsCWE-862WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Con…
CVE-2026-220998.78.7EVbeeDC-80CWE-287Missing authentication for Bluetooth communication
CVE-2026-573727.28.8denishuaWPJAM BasicCWE-918WordPress WPJAM Basic plugin <= 7.0 - Server Side Request Forgery (SSRF) vuln…
CVE-2026-574077.28.8WP SwingsPDF Generator for WordPressCWE-918WordPress PDF Generator for WordPress plugin <= 1.6.2 - Server Side Request F…
CVE-2026-621936.98.3OpenClawOpenClawCWE-863OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install
CVE-2026-122746.58.3UnknownTutor LMSTutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
CVE-2026-578298.78.1joomshaper.comHelix Ultimate extension for JoomlaCWE-79Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultim…
CVE-2026-615025.18.1rejettohfsCWE-352Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests
CVE-2026-573687.17.8NooThemeJobmonsterCWE-79WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vu…
CVE-2026-574217.17.8CRM PerksCRM Perks FormsCWE-79WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulner…
CVE-2026-577337.17.8tagDivtagDiv Cloud LibraryCWE-79WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) v…
CVE-2026-576957.17.7Dan RossiterDocument GalleryCWE-79WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulne…
CVE-2026-149065.37.5MozillaFirefox for iOSCWE-434Malicious webpage titles could allow overwriting of bundled PDF resources whe…
CVE-2026-619835.37.4andy_moyleChurch AdminCWE-862WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability
CVE-2026-619855.37.4magepeopleteamCar Rental ManagerCWE-862WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerab…
CVE-2026-573637.17.3QuantumCloudChatBotCWE-79WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573697.17.3themifymeThemify BuilderCWE-79WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulner…
CVE-2026-573767.17.3Element InvaderElementInvader Addons for ElementorCWE-79WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Sc…
CVE-2026-573797.17.3WPPOOLFormyChatCWE-79WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573807.17.3hupe13Extensions for Leaflet MapCWE-79WordPress Extensions for Leaflet Map plugin <= 5.1 - Cross Site Scripting (XS…
CVE-2026-573817.17.3Property HivePropertyHiveCWE-79WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-573827.17.3Mitchell BennisSimple File ListCWE-79WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (…
CVE-2026-573837.17.3eyecixJobSearchCWE-79WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573877.17.3picupicuCWE-79WordPress picu plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573887.17.3ThemeficHydra BookingCWE-79WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnera…
CVE-2026-573947.17.3Tribulant SoftwareNewslettersCWE-79WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573967.17.2FlintopFree Gifts for WooCommerceCWE-79WordPress Free Gifts for WooCommerce plugin <= 13.1.0 - Cross Site Scripting …
CVE-2026-573987.17.3WebCodingPlaceReal Estate Manager ProCWE-79WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XS…
CVE-2026-573997.17.3Proxy &amp; VPN BlockerProxy &amp; VPN BlockerCWE-79WordPress Proxy & VPN Blocker plugin <= 3.5.8 - Cross Site Scripting (XSS) vu…
CVE-2026-574037.17.3Milan PetrovicGD Security HeadersCWE-79WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vuln…
CVE-2026-574097.17.2RealMag777Active Products Tables for WooCommerceCWE-79WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site…
CVE-2026-574117.17.2AmanCF7 Views &#8211; Complete Entry Management for Contact Form 7CWE-79WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= …
CVE-2026-574157.17.3CodemenschenGift VouchersCWE-79WordPress Gift Vouchers plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-574167.17.3SiteGroundSiteGround Email MarketingCWE-79WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (…
CVE-2026-574177.17.3RexThemeCart LiftCWE-79WordPress Cart Lift plugin <= 3.1.57 - Cross Site Scripting (XSS) vulnerability
CVE-2026-574227.17.3VillaThemeBopo – WooCommerce Product Bundle BuilderCWE-79WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflect…
CVE-2026-574237.17.2Kofi MokomeMessage Filter for Contact Form 7CWE-79WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.8 - Reflected Cro…
CVE-2026-576687.17.2BasixNEX-FormsCWE-79WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577067.17.2Dokan, Inc.DokanCWE-79WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577087.17.2CRM PerksContact Form EntriesCWE-79WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) v…
CVE-2026-577127.17.2WPZOOMWPZOOM PortfolioCWE-79WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vuln…
CVE-2026-577157.17.2WPManageNinjaFluent CRMCWE-79WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577187.17.2Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-79WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-577257.17.2ThemeumKirkiCWE-79WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577287.17.2UX-themesFlatsomeCWE-79WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vul…
CVE-2026-577327.17.2tagDivtagDiv Opt-In BuilderCWE-79WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) …
CVE-2026-577347.17.2tagDivtagDiv ComposerCWE-79WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (X…
CVE-2026-577417.17.2AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCWE-79WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting…
CVE-2026-577457.17.2stmcanRT-Theme 18 | ExtensionsCWE-79WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scrip…
CVE-2026-101066.57.2MattermostMattermostCWE-863Unauthorized users can trigger interactive post actions in private channels v…
CVE-2026-584107.17.2ChurchCRMCRMCWE-639ChurchCRM: Improper object-level authorization allows low-privileged users to…
CVE-2026-95716.57.2MattermostMattermostCWE-305Deactivated user accounts can continue to obtain valid OAuth access tokens vi…
CVE-2026-615045.17.0rejettohfsCWE-79Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing
CVE-2026-122757.16.8UnknownTutor LMSTutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private C…
CVE-2026-100855.46.7MattermostMattermostCWE-862Ordinary group/direct message member can enable group_constrained and remove …
CVE-2026-122715.46.7UnknownTutor LMSTutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
CVE-2026-123965.46.7UnknownWP Job PortalWP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rej…
CVE-2026-619585.46.7Saad IqbalLicense Manager for WooCommerceCWE-862WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Conten…
CVE-2026-619685.46.7Saad IqbalmyCredCWE-862WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability
CVE-2026-122734.36.7UnknownTutor LMSTutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation
CVE-2026-125366.46.6themefusionAvada (Fusion) BuilderCWE-79Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-577868.86.1purethemesWorkScout-CoreCWE-352WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF)…
CVE-2026-573916.56.0TangibleLoops & LogicCWE-79WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-574136.46.0bdthemesInstant Image GeneratorCWE-918WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forge…
CVE-2026-98244.35.9MattermostMattermostCWE-862Remote cluster metadata enumeration via /share-channel autocomplete
CVE-2026-123974.35.9UnknownWP Job PortalWP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
CVE-2026-220939.55.7EVbeeEVbee ServiceCWE-295Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app
CVE-2026-621985.35.7OpenClawOpenClawCWE-863OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search
CVE-2026-483638.25.5AdobeColdFusionCWE-427ColdFusion | Uncontrolled Search Path Element (CWE-427)
CVE-2026-483648.25.5AdobeColdFusionCWE-427ColdFusion | Uncontrolled Search Path Element (CWE-427)
CVE-2026-573656.55.3Hitesh ChandwanireCAPTCHA (v2 &amp; v3) for Asgaros ForumCWE-79WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site …
CVE-2026-574026.55.3wpdeskFlexible Refund and Return Order for WooCommerceCWE-79WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 -…
CVE-2026-574146.55.3QuantumCloudChatBot for eCommerce &#8211; WoowBotCWE-79WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Script…
CVE-2026-574206.55.3NetrrAuthor Box WP LensCWE-79WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vul…
CVE-2026-576936.55.3SpacetimeAd InserterCWE-79WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-577116.55.3PSM PluginsSupportCandyCWE-79WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-577806.55.3Plugin EnvisionEnvision Page BuilderCWE-79WordPress Envision Page Builder plugin <= 0.22 - Cross Site Scripting (XSS) v…
CVE-2026-577836.55.3merkuloveSpeakerCWE-79WordPress Speaker plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability
CVE-2026-595236.55.1NSquaredSimply Schedule AppointmentsCWE-862WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Co…
CVE-2026-65414.34.9MattermostMattermostCWE-639Unscoped updates to other playbooks' metric configuration
CVE-2026-98203.84.9MattermostMattermostCWE-862Mattermost schemes teams endpoint exposes private team invite IDs
CVE-2026-156052.34.8n/awandbCWE-327wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.downloa…
CVE-2026-105516.14.6UnknownBreeze CacheBreeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library
CVE-2026-576915.84.5EliAnti-Malware Security and Brute-Force FirewallCWE-79WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.89 - …
CVE-2026-101034.34.2MattermostMattermostCWE-639Authenticated remote cluster can modify or delete posts it does not own in Ma…
CVE-2026-156847.34.0GlarysoftGlary UtilitiesCWE-59Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerabi…
CVE-2026-578147.14.0WPMU DEV - Your All-in-One WordPress PlatformForminatorCWE-79WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-578167.14.0FunnelKitFunnel Builder by FunnelKitCWE-79WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripti…
CVE-2026-595167.14.0Room 34 Creative Services, LLCICS CalendarCWE-79WordPress ICS Calendar plugin <= 12.1.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-95975.43.9MattermostMattermostCWE-305Deactivated guest accounts can authenticate via magic-link token in Mattermos…
CVE-2026-155271.93.8better-authbetter-iconsCWE-22better-auth better-icons scan_project_icons/sync_icon path traversal
CVE-2026-120815.03.8UnknownDatabase for Contact Form 7, WPforms, Elementor formsDatabase for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticat…
CVE-2026-155211.93.6makafelin8n-workflow-builderCWE-22makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
CVE-2026-155221.93.6tugcantopaloglugodot-mcpCWE-22tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
CVE-2026-155241.93.6alioshrmemory-bank-mcpCWE-22alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal
CVE-2026-155261.93.6augmntaugments-mcp-serverCWE-22augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProject…
CVE-2026-155201.93.5GNULibreDWGCWE-119GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section he…
CVE-2026-156825.53.2AnyDeskAnyDeskCWE-59AnyDesk Support Information Link Following Denial-of-Service Vulnerability
CVE-2026-622395.32.9Dao-AILabflash-attentionCWE-59FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py
CVE-2026-584896.82.7hedgedochedgedocCWE-352HedgeDoc: CSRF in GitHub Gist export callback
CVE-2026-155311.92.3yashbhalgatHashNeRF-pytorchCWE-20yashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deseriali…
CVE-2026-533655.52.2LinuxLinuxCWE-401vsock/virtio: fix zerocopy completion for multi-skb sends
CVE-2026-619704.92.1ThemeisleAuto Featured Image (Auto Post Thumbnail)CWE-918WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server …
CVE-2026-71627.82.0WinFspWinFspCWE-190Successful exploitation of the integer overflow vulnerability could allow an …
CVE-2026-601036.81.9blenderblenderCWE-125Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block
CVE-2026-155156.41.9TencentPC ManagerCWE-426Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path
CVE-2026-533645.51.7LinuxLinuxCWE-401Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()
CVE-2026-155281.91.6lamaalrajihkicad-mcpCWE-693lamaalrajih kicad-mcp path_validator.py protection mechanism
CVE-2026-94928.51.4GIGABYTEMBStorageCWE-782GIGABYTE|Gigabyte Control Center - Improper Access Control
CVE-2026-619567.11.3hamsalamووسلام &#8211; همگام سازی ووکامرس و باسلامCWE-352WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site R…
CVE-2026-156815.51.2AnyDeskAnyDeskCWE-59AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
CVE-2026-156837.50.8Lorex2K Indoor Wi-Fi Security CameraCWE-295Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certi…
CVE-2026-155515.50.2Samsung Open SourcerlottieCWE-190Samsung rlottie: Numeric truncation in gray_hline() leads to heap-based buffe…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-13 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.