AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1331 96.1 YES
AFFECTED Product Versions Fixed Oracle Payments 12.2.3 – —
TIMELINE May 18 Reserved by CNA Jul 15 Added to CISA KEV, due Jul 18 Jul 15 Published (CNA: oracle)
269 CVEs published July 15, 2026: 36 critical, 123 high, 92 medium, 17 low; 2 in KEV; 14 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 244 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4074 | 16392 | 1297 | 2563 |
| KEV catalog size | 1670 | |||
714 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 40 | 1520 | 121 | 866 | 530 | 1 | 27 | 3 | 0.2 | 7.5 | .0013 | -56 |
| 94 | 1358 | 150 | 612 | 555 | 38 | 74 | 6 | 0.4 | 7.8 | .0024 | -497 | |
| microsoft | 624 | 1335 | 87 | 919 | 300 | 12 | 378 | 30 | 2.2 | 7.8 | .0039 | +417 |
| red hat | 50 | 242 | 14 | 100 | 116 | 12 | 4 | 0 | 0.0 | 6.5 | .0026 | -3 |
| apple | 0 | 99 | 1 | 23 | 66 | 2 | 93 | 7 | 7.1 | 6.5 | .0031 | -14 |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0033 | +8 |
| canonical | 1 | 21 | 2 | 6 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +1 |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 16 | 39 | 6 | 16 | 9 | 0 | 96 | 12 | 30.8 | 7.5 | .0050 | +12 |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 4 | 3 | 8.3 | 8.8 | .0036 | +20 |
| palo alto networks | 14 | 25 | 0 | 2 | 14 | 7 | 14 | 2 | 8.0 | 4.7 | .0021 | +5 |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 8 | 0 | 0.0 | 4.6 | .0022 | -11 |
| fortinet | 12 | 20 | 2 | 6 | 10 | 0 | 28 | 3 | 15.0 | 6.7 | .0032 | +10 |
| f5 | 8 | 17 | 5 | 8 | 3 | 0 | 7 | 1 | 5.9 | 8.6 | .0057 | +8 |
| ivanti | 2 | 11 | 2 | 3 | 2 | 0 | 33 | 5 | 45.5 | 8.8 | .3445 | -2 |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 76 | 229 | 47 | 89 | 81 | 11 | 40 | 1 | 0.4 | 7.5 | .0048 | +9 |
| mozilla | 6 | 62 | 12 | 18 | 32 | 0 | 13 | 0 | 0.0 | 6.5 | .0025 | +1 |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 5 | 1 | 2.0 | 5.9 | .0018 | +46 |
| gitlab | 7 | 40 | 0 | 5 | 27 | 6 | 4 | 2 | 5.0 | 4.7 | .0024 | -4 |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0026 | +1 |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | -2 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1 | 271 | 132 | 116 | 18 | 4 | 40 | 3 | 1.1 | 8.8 | .0040 | -2 |
| adobe | 93 | 239 | 26 | 101 | 105 | 4 | 75 | 4 | 1.7 | 7.5 | .0021 | -31 |
| ibm | 2 | 126 | 38 | 42 | 46 | 0 | 7 | 0 | 0.0 | 7.5 | .0025 | -9 |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 9 | 0 | 0.0 | 7.5 | .0034 | +5 |
| solarwinds | 0 | 7 | 1 | 2 | 2 | 0 | 11 | 4 | 57.1 | 7.5 | .0835 | -3 |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | -1 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .2673 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0025 | +17 |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 1 | 0 | 0.0 | 7.6 | .0019 | 0 |
| d-link | 1 | 14 | 0 | 5 | 3 | 5 | 26 | 1 | 7.1 | 6.0 | .0058 | -8 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -5 |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | -1 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -1 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | -3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 37 | 108 | 0 | 0 | 56 | 52 | 0 | 0 | 0.0 | 5.5 | .0026 | +1 |
| dell | 37 | 93 | 4 | 42 | 43 | 3 | 2 | 1 | 1.1 | 6.8 | .0019 | +30 |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0028 | +20 |
| openclaw | 16 | 83 | 0 | 48 | 25 | 10 | 0 | 0 | 0.0 | 7.2 | .0021 | -18 |
| nvidia | 40 | 79 | 12 | 52 | 15 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | +36 |
| imagemagick | 32 | 73 | 1 | 5 | 55 | 12 | 3 | 0 | 0.0 | 5.3 | .0017 | +4 |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -71 |
| itsourcecode | 12 | 65 | 0 | 0 | 19 | 46 | 0 | 0 | 0.0 | 2.1 | .0020 | -10 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48282 | 10.0 | .9924 | KEV |
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| Vendor | CVEs |
|---|---|
| microsoft | 638 |
| 593 | |
| linux | 458 |
| oracle | 241 |
| apache | 130 |
| red hat | 125 |
| adobe | 111 |
| capgo | 81 |
| dell | 68 |
| ibm | 66 |
| Vendor | KEV |
|---|---|
| microsoft | 30 |
| cisco | 12 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| adobe | 4 |
| solarwinds | 4 |
| synacor | 4 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 62 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1701 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1701 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1701 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1701 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1701 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1701 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1701 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1701 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1701 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1701 |
EXPLOIT PUBLISHED — CVE-2026-10673 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41580 (Stirling-Tools Stirling-PDF). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45737 (argoproj argo-cd). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45738 (argoproj argo-cd). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45804 (huggingface diffusers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46709 (Eugeny tabby). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47703 (AdguardTeam AdGuardHome). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49987 (yamadashy repomix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49988 (yamadashy repomix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56398 (open-webui). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56400 (open-webui). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62947 (openwrt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62948 (openwrt). Public exploit reference added.
269 CVEs published. 25 box scores, 244 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1331 96.1 YES
AFFECTED Product Versions Fixed Oracle Payments 12.2.3 – —
TIMELINE May 18 Reserved by CNA Jul 15 Added to CISA KEV, due Jul 18 Jul 15 Published (CNA: oracle)
CVSS EPSS %ile KEV — .0091 56.9 YES
AFFECTED Product Versions Fixed KNX Protocol Connection Authorization Option 1 unspecified —
TIMELINE Jul 15 Added to CISA KEV, due Jul 29 Jul 15 Published
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0595 92.6 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 4 Reserved by CNA Jul 15 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H H H 9.2 .0351 88.2 —
AFFECTED Product Versions Fixed NGINX Plus 37.0.0.1 – — NGINX Open Source 1.31.2 – —
TIMELINE May 5 Reserved by CNA Jul 15 Published (CNA: f5)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0239 82.6 —
AFFECTED Product Versions Fixed 9router >= 0.4.30, < 0.4.37 – —
TIMELINE May 13 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0228 81.7 —
AFFECTED Product Versions Fixed Apache Fineract unspecified —
TIMELINE Apr 1 Reserved by CNA Jul 15 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0167 74.8 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 4 Reserved by CNA Jul 15 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0108 62.4 —
AFFECTED Product Versions Fixed grav unspecified 1.4.0
TIMELINE Jul 1 Reserved by CNA Jul 15 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N H 8.1 .0084 55.0 —
AFFECTED Product Versions Fixed Apache Fineract unspecified 1.15.0
TIMELINE Jun 25 Reserved by CNA Jul 15 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0080 53.5 —
AFFECTED Product Versions Fixed composer >= 1.0, < 1.10.28 – —
TIMELINE May 13 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0072 51.0 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Nov 18 Reserved by CNA Jul 15 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0072 50.8 —
AFFECTED Product Versions Fixed 9router < 0.5.2 – —
TIMELINE Jul 13 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N H 8.8 .0071 50.5 —
AFFECTED Product Versions Fixed NGINX Plus 37.0.0.1 – — NGINX Open Source 1.31.2 – —
TIMELINE Jul 8 Reserved by CNA Jul 15 Published (CNA: f5)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N A H H H 8.4 .0063 47.3 —
AFFECTED Product Versions Fixed jsii unspecified —
TIMELINE Jul 15 Reserved by CNA Jul 15 Published (CNA: AMZN)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0062 46.8 —
AFFECTED Product Versions Fixed Gravity Forms unspecified —
TIMELINE Jun 23 Reserved by CNA Jul 15 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0059 45.5 —
AFFECTED Product Versions Fixed nocobase < 2.0.61 – —
TIMELINE Jun 8 Reserved by CNA Jul 15 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L L N 5.4 .0051 41.0 —
AFFECTED Product Versions Fixed Apache Ivy 2.0.0 – —
TIMELINE Feb 9 Reserved by CNA Jul 15 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H N 8.6 .0050 40.5 —
AFFECTED Product Versions Fixed PraisonAI unspecified 1.6.78
TIMELINE Jul 9 Reserved by CNA Jul 15 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N A H H H 7.5 .0050 40.3 —
AFFECTED Product Versions Fixed repomix < 1.14.1 – —
TIMELINE Jun 2 Reserved by CNA Jul 15 Public exploit reference published Jul 15 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N N 8.6 .0049 40.1 —
AFFECTED Product Versions Fixed Grafana MCP Server 0.0.0 – —
TIMELINE Jul 13 Reserved by CNA Jul 15 Published (CNA: GRAFANA)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0048 39.4 —
AFFECTED Product Versions Fixed Splunk Enterprise 10.4 – — Splunk Cloud Platform 10.5.2605 – —
TIMELINE Oct 8 Reserved by CNA Jul 15 Published (CNA: cisco)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0048 39.2 —
AFFECTED Product Versions Fixed Tdelo64.sys 02-17-2025 – —
TIMELINE Jul 7 Reserved by CNA Jul 15 Published (CNA: certcc)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L N 6.9 .0047 38.6 —
AFFECTED Product Versions Fixed Prospero Flow CRM 1.0.0 – —
TIMELINE Jul 3 Reserved by CNA Jul 15 Published (CNA: Secur0)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0047 38.6 —
AFFECTED Product Versions Fixed Apache Fineract unspecified —
TIMELINE Jun 20 Reserved by CNA Jul 15 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L N 5.3 .0046 38.3 —
AFFECTED Product Versions Fixed grav unspecified 1.0.3
TIMELINE Jul 9 Reserved by CNA Jul 15 Published (CNA: VulnCheck)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-59762 | 8.7 | 38.0 | F5 | BIG-IP | CWE-770 | BIG-IP HTTP/2 vulnerability |
| CVE-2026-56434 | 8.3 | 37.4 | F5 | NGINX Plus | CWE-416 | NGINX ngx_http_ssi_module vulnerability |
| CVE-2026-40501 | 8.6 | 36.4 | CherryHQ | cherry-studio | CWE-829 | Cherry Studio RCE via SearchService nodeIntegration Misconfiguration |
| CVE-2026-49352 | 9.8 | 36.4 | decolua | 9router | CWE-798 | 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass |
| CVE-2026-50148 | 9.1 | 35.6 | metabase | metabase | CWE-73 | Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write |
| CVE-2026-43637 | 8.8 | 35.5 | PreferredAI | cornac | CWE-22 | Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py |
| CVE-2026-56398 | 8.5 | 34.7 | open-webui | open-webui | CWE-20 | Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI |
| CVE-2026-59235 | 8.7 | 34.4 | Roskus | Prospero Flow CRM | CWE-639 | Missing authorization in Prospero Flow CRM allows low-privileged users to rea… |
| CVE-2026-51380 | 9.8 | 34.2 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows… |
| CVE-2026-59954 | 7.5 | 34.1 | apolloconfig | apollo | CWE-20 | Apollo ConfigService access key authentication bypass via appId parsing and n… |
| CVE-2026-59955 | 7.5 | 34.1 | apolloconfig | apollo | CWE-20 | Apollo ConfigService access key authentication bypass via raw config file app… |
| CVE-2026-55445 | 9.3 | 33.6 | whyour | qinglong | CWE-287 | Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication |
| CVE-2026-52891 | 9.9 | 33.5 | wekan | wekan | CWE-78 | Wekan: Shell Injection via Avatar Upload |
| CVE-2026-61740 | 9.3 | 33.5 | HKUDS | LightRAG | CWE-287 | LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /a… |
| CVE-2026-62349 | 8.3 | 33.3 | taosdata | TDengine | CWE-121 | TDengine: Off-by-One Buffer Overflow |
| CVE-2026-36590 | 7.5 | 33.3 | n/a | n/a | CWE-400 | An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of… |
| CVE-2026-62947 | 4.9 | 33.3 | openwrt | openwrt | CWE-22 | OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download |
| CVE-2026-45534 | 9.0 | 32.8 | dataease | dataease | CWE-94 | DataEase: RCE Vulnerability |
| CVE-2026-10673 | 8.8 | 32.5 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly |
| CVE-2026-45738 | 8.7 | 32.4 | argoproj | argo-cd | CWE-79 | Argo CD: Stored XSS in application link annotations enables developer-to-admi… |
| CVE-2026-58658 | 8.8 | 32.1 | gpustack | gpustack | CWE-306 | GPUStack Unauthenticated Information Disclosure via Worker Endpoints |
| CVE-2026-61613 | 7.7 | 31.9 | cursor | cursor | CWE-306 | Cursor: Cloud Agent Browser Sandbox Escape |
| CVE-2026-46421 | 9.3 | 31.6 | cap-js | @cap-js/sqlite | CWE-506 | Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-… |
| CVE-2026-61435 | 8.8 | 31.5 | MervinPraison | PraisonAI | CWE-287 | PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing |
| CVE-2026-13230 | 5.3 | 31.3 | TP-Link Systems Inc. | Kasa EC71 v4 | CWE-200 | Information Disclosure Vulnerability in Local Discovery Response in TP-Link K… |
| CVE-2026-45804 | 7.5 | 30.8 | huggingface | diffusers | CWE-367 | Diffusers: TOCTOU Trust Remote Code Bypass |
| CVE-2026-62350 | 7.2 | 30.1 | taosdata | TDengine | CWE-94 | TDengine: UDF lead to RCE |
| CVE-2026-47159 | 6.9 | 30.1 | dani-garcia | vaultwarden | CWE-287 | Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allo… |
| CVE-2026-55410 | 6.7 | 30.1 | nocobase | nocobase | CWE-78 | NocoBase backup restore schema name allows command injection |
| CVE-2026-11851 | 5.9 | 29.9 | ASUS | Router | CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Inje… |
| CVE-2026-12382 | 8.2 | 29.7 | Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | CWE-290 | Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject he… |
| CVE-2026-9770 | 8.6 | 29.4 | TP-Link Systems Inc. | Kasa EC71 v4 | CWE-321 | Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link K… |
| CVE-2026-61371 | 7.5 | 29.1 | n/a | n/a | CWE-59 | Microsoft AVML before 0.17.0 could follow a symlink when opening a destinatio… |
| CVE-2026-45737 | 6.5 | 29.0 | argoproj | argo-cd | CWE-200 | Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive… |
| CVE-2026-62948 | 9.6 | 28.8 | openwrt | openwrt | CWE-79 | OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file line… |
| CVE-2026-26719 | 6.1 | 28.7 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote a… |
| CVE-2026-55652 | 9.8 | 28.6 | wekan | wekan | CWE-287 | Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan… |
| CVE-2026-58660 | 7.2 | 28.6 | kanboard | kanboard | CWE-639 | Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop |
| CVE-2026-56400 | 9.0 | 27.8 | open-webui | open-webui | CWE-613 | open-webui - Remote Code Execution via CORS Misconfiguration and Session Vali… |
| CVE-2026-56349 | 6.3 | 27.4 | n8n | n8n | CWE-20 | n8n - Guardrail Node Bypass via Crafted Input |
| CVE-2026-20146 | 5.5 | 27.0 | Cisco | Cisco Identity Services Engine Software | CWE-22 | Cisco Identity Services Engine Path Traversal Vulnerability |
| CVE-2026-61427 | 6.9 | 26.8 | MervinPraison | PraisonAI | CWE-20 | PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream |
| CVE-2026-62378 | 9.0 | 26.1 | rustfs | console | CWE-79 | RustFS Console: Critical Stored XSS in Preview Modal leading to Administrativ… |
| CVE-2026-49279 | 7.7 | 25.5 | WWBN | AVideo | CWE-79 | WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSoc… |
| CVE-2026-58659 | 8.4 | 25.4 | Lightning-AI | pytorch-lightning | CWE-470 | PyTorch Lightning Arbitrary Code Execution via _instantiator Hyperparameter |
| CVE-2026-45806 | 7.7 | 25.4 | penpot | penpot | CWE-918 | Penpot: Authenticated SSRF in remote image import via create-file-media-objec… |
| CVE-2026-52890 | 7.1 | 25.3 | wekan | wekan | CWE-22 | Wekan: Arbitrary file read and server DoS via attachment versions.original.path |
| CVE-2026-56679 | 8.7 | 25.2 | decolua | 9router | CWE-915 | 9Router: Mass assignment in PATCH /api/settings allows authenticated authoriz… |
| CVE-2026-62351 | 7.5 | 25.2 | taosdata | TDengine | CWE-125 | TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in … |
| CVE-2026-62685 | 8.1 | 25.1 | filebrowser | filebrowser | CWE-647 | File Browser: Colliding username normalization gives two users the same home … |
| CVE-2026-50124 | 7.1 | 25.0 | dataease | dataease | CWE-434 | DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper |
| CVE-2026-52869 | 7.1 | 24.7 | modelcontextprotocol | python-sdk | CWE-639 | MCP Python SDK: HTTP transports serve session requests without verifying the … |
| CVE-2026-58077 | 8.7 | 24.5 | weeblr.com | 4Analytics extension for Joomla | CWE-79 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 |
| CVE-2026-57833 | 8.6 | 24.5 | weeblr.com | 4Analytics extension for Joomla | CWE-79 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 |
| CVE-2026-59258 | 7.2 | 24.2 | immich-app | immich | CWE-863 | immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser |
| CVE-2026-59259 | 6.0 | 24.3 | n8n | n8n | CWE-639 | n8n - Permission Bypass via Expression Parser Mismatch in External Secrets |
| CVE-2026-45419 | 8.5 | 24.0 | dataease | dataease | CWE-22 | DataEase: Arbitrary File Write Vulnerability |
| CVE-2026-45533 | 8.3 | 24.0 | dataease | dataease | CWE-22 | DataEase: Path Traversal Vulnerability |
| CVE-2026-40957 | 6.1 | 24.0 | Absolute Security | Secure Access | CWE-1021 | Frameable content vulnerability in the Secure Access server login page |
| CVE-2026-15804 | 8.7 | 23.5 | MetaGuru | HCM | CWE-89 | MetaGuru|HCM - SQL Injection |
| CVE-2026-13585 | 8.2 | 23.3 | ASUS | System Control Interface v3 | CWE-226 | Allocation of Resources Without Limits and Throttling and Sensitive Informati… |
| CVE-2026-61736 | 9.3 | 23.1 | HKUDS | LightRAG | CWE-942 | LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests |
| CVE-2026-46485 | 8.2 | 23.0 | lissy93 | dashy | CWE-15 | Dash: Users can write to config despire permissions (OIDC tested) |
| CVE-2025-32781 | 6.5 | 23.0 | apolloconfig | apollo | CWE-639 | Apollo: Apollo Portal release endpoint allows cross-application configuration… |
| CVE-2026-54458 | 9.6 | 23.0 | WWBN | AVideo | CWE-79 | AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metada… |
| CVE-2026-52893 | 9.2 | 22.7 | wekan | wekan | CWE-287 | Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in o… |
| CVE-2026-48795 | 8.6 | 22.6 | adonisjs | core | CWE-1321 | Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser |
| CVE-2026-8919 | 7.2 | 22.6 | ASUS | GameSDK | CWE-942 | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSD… |
| CVE-2026-55576 | 8.8 | 22.3 | MaaAssistantArknights | MaaAssistantArknights | CWE-78 | MaaAssistantArknights: PR-title expression injection in release-preparation.yml |
| CVE-2026-61684 | 8.8 | 22.0 | labring | FastGPT | CWE-798 | FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke… |
| CVE-2026-63175 | 7.1 | 22.0 | Lookyloo | PlaywrightCapture | CWE-613 | Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo -… |
| CVE-2026-55723 | 8.7 | 21.8 | F5 | NGINX Ingress Controller | CWE-76 | NGINX Ingress Controller vulnerability |
| CVE-2026-61436 | 8.8 | 21.5 | MervinPraison | PraisonAI | CWE-287 | PraisonAI before 4.6.78 Missing Webhook Signature Verification |
| CVE-2026-46459 | 5.3 | 21.3 | ICU Scandinavia | Boomerang | CWE-862 | Missing Authorization in ICU Scandinavia Boomerang |
| CVE-2026-52865 | 7.1 | 21.1 | F5 | NGINX Ingress Controller | CWE-476 | NGINX Ingress Controller vulnerability |
| CVE-2026-53446 | 6.2 | 21.1 | wekan | wekan | CWE-918 | Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs |
| CVE-2026-44986 | 9.9 | 20.8 | penpot | penpot | CWE-287 | Penpot: Pre-authenticated account takeover via team-invitation token + prepar… |
| CVE-2026-56339 | 8.7 | 20.1 | Cap-go | capgo | CWE-203 | Capgo - Unauthenticated Organization Existence Enumeration via rescind_invita… |
| CVE-2026-61836 | 8.6 | 19.6 | directus | directus | CWE-524 | Directus: Authorization-dependent response served from unsegmented cache key |
| CVE-2026-47164 | 7.7 | 19.2 | dani-garcia | vaultwarden | CWE-284 | Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Att… |
| CVE-2026-62314 | 5.8 | 19.2 | TecharoHQ | anubis | CWE-284 | Anubis: Policy bypass via client controlled X-Original-URI header |
| CVE-2026-45320 | 8.7 | 19.1 | dataease | dataease | CWE-89 | DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection |
| CVE-2026-50030 | 7.1 | 19.1 | dataease | dataease | CWE-89 | DataEase: Arbitrary SQL execution in preview path (direct data disclosure) |
| CVE-2026-52888 | 6.8 | 19.1 | nocobase | nocobase | CWE-184 | NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass |
| CVE-2026-49867 | 6.3 | 19.1 | dataease | dataease | CWE-79 | DataEase: Authenticated Stored XSS in DataEase Template Static Resources |
| CVE-2026-12512 | 8.6 | 19.0 | Unknown | Quotes llama | CWE-89 | Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter |
| CVE-2026-20153 | 7.5 | 18.9 | Cisco | Cisco RoomOS Software | CWE-20 | Cisco RoomOS Security Hardening Release - Input Validation Vulnerabilities |
| CVE-2026-20158 | 7.5 | 18.9 | Cisco | Cisco RoomOS Software | CWE-664 | Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulner… |
| CVE-2026-20187 | 7.5 | 18.9 | Cisco | Cisco RoomOS Software | CWE-703 | Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vul… |
| CVE-2026-59254 | 6.3 | 18.5 | n8n | n8n | CWE-639 | n8n - External Secrets Disclosure via Workflow Node Expressions |
| CVE-2026-60065 | 6.3 | 18.5 | F5 | NGINX Plus | CWE-125 | NGINX Plus ngx_stream_mqtt_filter_module vulnerability |
| CVE-2026-62843 | 6.8 | 17.7 | filebrowser | filebrowser | CWE-22 | File Browser: Archive builder turns backslash filenames into path traversal (… |
| CVE-2026-52892 | 6.5 | 17.7 | wekan | wekan | CWE-862 | Wekan: Read-only board members can create/modify/delete Custom Fields (privil… |
| CVE-2026-33444 | 6.9 | 17.6 | Absolute Secutity | Secure Access | CWE-119 | Memory management vulnerability in Secure Access servers |
| CVE-2026-9007 | 5.5 | 17.6 | HCL Software | HCL Notes | CWE-79 | Reflected XSS in HCL Notes |
| CVE-2026-20156 | 9.8 | 17.3 | Cisco | Cisco RoomOS Software | CWE-119 | Cisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities |
| CVE-2026-61873 | 7.2 | 17.3 | getgrav | grav | CWE-73 | Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename |
| CVE-2026-15907 | 5.5 | 17.1 | H3C | SecPath F1000-C8300 | CWE-74 | H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection |
| CVE-2026-49997 | 5.4 | 17.2 | surrealdb | surrealdb | CWE-285 | SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted |
| CVE-2026-45150 | 6.3 | 16.9 | zen-browser | desktop | CWE-451 | Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing |
| CVE-2026-45535 | 8.7 | 16.4 | dataease | dataease | CWE-89 | DataEase: Stored SQL Injection Vulnerability |
| CVE-2026-61646 | 6.3 | 16.4 | labring | FastGPT | CWE-918 | FastGPT: Shared axios SSRF guard validates only the initial URL before follow… |
| CVE-2026-56352 | 5.3 | 16.4 | n8n | n8n | CWE-22 | n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter |
| CVE-2026-54560 | 7.6 | 16.2 | cloudreve | cloudreve | CWE-863 | Cloudreve: OAuth access tokens bypass scope enforcement due to missing client… |
| CVE-2026-61449 | 7.1 | 16.2 | getgrav | grav | CWE-409 | Grav before 2.0.2 Decompression Bomb via Forged ZIP Size |
| CVE-2026-62353 | 5.4 | 16.3 | taosdata | TDengine | CWE-125 | TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken |
| CVE-2026-57996 | 8.7 | 16.1 | phpMyFAQ | phpMyFAQ | CWE-269 | phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endp… |
| CVE-2026-59255 | 7.1 | 16.1 | SpecterOps | BloodHound | CWE-862 | BloodHound Missing Authorization on Custom Node Management API |
| CVE-2026-61451 | 9.4 | 15.8 | getgrav | grav | CWE-601 | Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url |
| CVE-2026-15746 | 6.9 | 15.8 | Amazon | strands-agents-tools | CWE-918 | Credential disclosure in Strands Agents Tools elasticsearch_memory tool |
| CVE-2026-54562 | 6.5 | 15.8 | cloudreve | cloudreve | CWE-918 | Cloudreve: Non-admin remote download users can SSRF loopback/internal service… |
| CVE-2026-55234 | 8.5 | 15.7 | wekan | wekan | CWE-284 | Wekan: Broken access control: any authenticated user can move their Cards/Lis… |
| CVE-2026-61644 | 7.7 | 15.8 | labring | FastGPT | CWE-863 | FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant d… |
| CVE-2026-46458 | 7.1 | 15.6 | ICU Scandinavia | Boomerang | CWE-522 | Credential exposure in ICU Scandinavia Boomerang |
| CVE-2026-60085 | 8.7 | 15.5 | MervinPraison | PraisonAI | CWE-273 | PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox |
| CVE-2026-53517 | 8.1 | 15.4 | better-auth | better-auth | CWE-362 | Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Conc… |
| CVE-2026-62361 | 5.5 | 15.2 | knadh | listmonk | CWE-89 | listmonk: SQL Injection in `/api/subscribers/export` bypasses table access co… |
| CVE-2026-53444 | 7.6 | 15.1 | wekan | wekan | CWE-269 | Wekan: Missing authorization on OIDC Meteor methods allows privilege escalati… |
| CVE-2026-53445 | 7.1 | 15.1 | wekan | wekan | CWE-862 | Wekan: Authorization bypass in copyBoard DDP method allows any user to copy p… |
| CVE-2026-53515 | 7.1 | 15.1 | better-auth | better-auth | CWE-269 | Better Auth: Privilege escalation via SSO provider registration: missing admi… |
| CVE-2026-57831 | 8.7 | 14.9 | digital-peak.com | DP Calendar extension for Joomla | CWE-89 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in … |
| CVE-2026-57832 | 8.7 | 14.9 | joomdonation.com | EDocman extension for Joomla | CWE-89 | Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in … |
| CVE-2026-11579 | 5.3 | 15.0 | Unknown | Kali Forms — Contact Form & Drag-and-Drop Builder | CWE-434 | Kali Forms < 2.4.17 - Unauthenticated Media Upload |
| CVE-2026-20150 | 8.8 | 14.8 | Cisco | Cisco RoomOS Software | CWE-284 | Cisco RoomOS Security Hardening Release - Access Control Vulnerabilities |
| CVE-2026-33445 | 8.7 | 14.8 | Absolute Security | Secure Access | CWE-400 | Memory management vulnerability in Secure Access servers |
| CVE-2026-52870 | 7.6 | 14.9 | modelcontextprotocol | python-sdk | CWE-862 | MCP Python SDK: Experimental task handlers allow any client to access and can… |
| CVE-2026-38754 | 5.1 | 14.7 | BusyBox | BusyBox | CWE-125 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0… |
| CVE-2026-61835 | 7.7 | 14.5 | directus | directus | CWE-918 | Directus: SSRF Protection Bypass via 0.0.0.0 in File Import |
| CVE-2026-61871 | 6.3 | 14.2 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in ICON decoder |
| CVE-2026-12281 | 8.1 | 14.2 | Unknown | Shibboleth | CWE-287 | Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Ident… |
| CVE-2026-49353 | 7.5 | 14.1 | decolua | 9router | CWE-290 | 9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING |
| CVE-2026-20298 | 6.5 | 14.2 | Splunk | Splunk Enterprise | CWE-200 | Sensitive Information Disclosure through the storage/passwords REST Endpoint … |
| CVE-2026-53447 | 6.5 | 14.1 | wekan | wekan | CWE-639 | Wekan: `cloneBoard` Meteor method has no authorization check — any user can c… |
| CVE-2026-56353 | 6.3 | 14.2 | n8n | n8n | CWE-287 | n8n - Authentication Bypass in Chat Trigger Node |
| CVE-2026-47160 | 5.8 | 14.2 | dani-garcia | vaultwarden | CWE-918 | Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex… |
| CVE-2026-45805 | 8.8 | 13.9 | penpot | penpot | CWE-749 | Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoi… |
| CVE-2026-20296 | 8.3 | 14.0 | Splunk | Splunk Enterprise | CWE-352 | SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in De… |
| CVE-2026-53518 | 7.6 | 13.9 | better-auth | better-auth | CWE-362 | Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Ena… |
| CVE-2026-56764 | 6.3 | 13.9 | Hono | Hono | CWE-208 | Hono - Timing Attack in basicAuth and bearerAuth Middleware |
| CVE-2026-54443 | 5.9 | 13.9 | lissy93 | dashy | CWE-80 | Dashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas… |
| CVE-2026-54052 | 9.9 | 13.8 | czlonkowski | n8n-mcp | CWE-639 | n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP… |
| CVE-2026-41580 | 6.1 | 13.8 | Stirling-Tools | Stirling-PDF | CWE-79 | Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Au… |
| CVE-2026-45417 | 8.7 | 13.7 | dataease | dataease | CWE-89 | DataEase: SQL injection vulnerability |
| CVE-2026-46709 | 7.8 | 13.6 | Eugeny | tabby | CWE-77 | Tabby: Drag-and-drop path injection still allows RCE via shell command substi… |
| CVE-2026-15921 | 2.1 | 13.4 | nvm-sh | nvm | CWE-22 | nvm path traversal via a malicious mirror's LTS codename writes outside the a… |
| CVE-2026-26718 | 9.1 | 13.2 | n/a | n/a | CWE-352 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin… |
| CVE-2026-14251 | 7.7 | 13.1 | Red Hat | Red Hat OpenShift GitOps | CWE-862 | Gitops-operator: gitops-operator: missing allowednamespace check in reconcile… |
| CVE-2026-40958 | 2.3 | 13.2 | Absolute Security | Secure Access | CWE-20 | Input validation error in Secure Access clients prior to 14.55 |
| CVE-2026-61860 | 6.3 | 13.0 | ImageMagick | ImageMagick | CWE-416 | ImageMagick before 7.1.2-26 Use-After-Free via freetype |
| CVE-2026-61868 | 6.3 | 13.0 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in YUV Decoder |
| CVE-2026-61446 | 8.6 | 12.9 | MervinPraison | PraisonAI | CWE-94 | PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery |
| CVE-2026-55399 | 5.1 | 12.4 | Absolute Security | Secure Access | CWE-400 | Resource exhaustion vulnerability in the Secure Access publisher |
| CVE-2026-53512 | 9.1 | 11.8 | better-auth | better-auth | CWE-287 | Better Auth: OAuth refresh-token replay via missing client authentication on … |
| CVE-2026-33443 | 7.1 | 11.9 | Absolute Security | Secure Access | CWE-400 | Memory management error in Secure Access servers prior to 14.55 |
| CVE-2026-61440 | 7.1 | 11.9 | MervinPraison | PraisonAI | CWE-862 | PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints |
| CVE-2026-55398 | 6.9 | 11.3 | Absolute Security | Secure Access | CWE-119 | Memory management vulnerability in Secure Access clients |
| CVE-2026-62348 | 5.4 | 11.4 | taosdata | TDengine | CWE-862 | TDengine: KILL SSMIGRATE missing authorization lets low-privilege users inter… |
| CVE-2026-33684 | 5.3 | 11.2 | WWBN | AVideo | CWE-862 | AVideo's Privilege AVideo: Escalation via Unguarded Permission Parameters in … |
| CVE-2026-38752 | 2.9 | 11.1 | BusyBox | BusyBox | CWE-674 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit… |
| CVE-2026-38755 | 2.9 | 11.1 | BusyBox | BusyBox | CWE-674 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.… |
| CVE-2026-61430 | 8.4 | 10.8 | MervinPraison | PraisonAI | CWE-918 | PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl |
| CVE-2026-61438 | 7.0 | 10.4 | MervinPraison | PraisonAI | CWE-78 | PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox |
| CVE-2026-60062 | 5.3 | 10.4 | F5 | NGINX Agent | CWE-22 | NGINX Agent Vulnerability |
| CVE-2026-40954 | 2.1 | 10.3 | Absolute Security | Secure Access | CWE-191 | Integer underflow in Secure Access clients prior to 14.55 |
| CVE-2026-40955 | 2.1 | 10.3 | Absolute Security | Secure Access | CWE-191 | Integer underflow vulnerability in Secure Access clients |
| CVE-2026-50147 | 7.6 | 10.1 | metabase | metabase | CWE-88 | Metabase: Arbitrary File Read via MySQL Connection Property Injection |
| CVE-2026-62683 | 3.1 | 9.9 | filebrowser | filebrowser | CWE-863 | File Browser: Trailing-slash delete leaves a stale public share behind |
| CVE-2026-38974 | 5.3 | 9.5 | n/a | n/a | CWE-295 | Dulwich through 1.1.0 was found to be missing SSH host key verification in co… |
| CVE-2026-61452 | 6.9 | 9.5 | getgrav | grav | CWE-613 | Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens |
| CVE-2026-46684 | 9.5 | 9.3 | dataease | dataease | CWE-347 | DataEase: Unauthorized Command Execution Vulnerability |
| CVE-2026-53513 | 9.6 | 8.8 | better-auth | better-auth | CWE-20 | Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @b… |
| CVE-2026-60087 | 6.9 | 8.9 | MervinPraison | PraisonAI | CWE-863 | PraisonAI before 1.6.78 Tool Approval Cache Bypass |
| CVE-2026-11580 | 5.5 | 8.9 | Unknown | Kali Forms — Contact Form & Drag-and-Drop Builder | CWE-639 | Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR |
| CVE-2026-61863 | 2.1 | 8.7 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder |
| CVE-2026-61866 | 2.1 | 8.7 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in JNG encoder |
| CVE-2026-54563 | 7.1 | 8.5 | cloudreve | cloudreve | CWE-863 | Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`… |
| CVE-2026-33213 | 6.1 | 7.6 | getredash | redash | CWE-601 | Redash: Open redirect vulnerability in post-login redirect handling |
| CVE-2026-50182 | 6.1 | 7.6 | WWBN | AVideo | CWE-79 | AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Ga… |
| CVE-2026-52843 | 9.3 | 7.1 | lightpanda-io | browser | CWE-346 | Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin… |
| CVE-2026-1563 | 4.8 | 7.1 | Pegasystems | Pega Infinity | CWE-79 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cros… |
| CVE-2026-1562 | 4.6 | 7.1 | Pegasystems | Pega Infinity | CWE-79 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-s… |
| CVE-2026-56742 | 8.9 | 6.9 | cilium | cilium | CWE-862 | Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces |
| CVE-2026-56678 | 6.4 | 6.9 | decolua | 9router | CWE-20 | 9Router: Kiro region injection allows authenticated SSRF with Authorization h… |
| CVE-2026-40956 | 2.1 | 6.8 | Absolute Security | Secure Access | CWE-200 | Memory disclosure in Secure Access Clients |
| CVE-2026-15809 | 7.8 | 6.0 | Red Hat | Confidential Compute Attestation | CWE-134 | Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection … |
| CVE-2026-48799 | 7.7 | 6.1 | gitroomhq | postiz-app | CWE-345 | Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook |
| CVE-2026-55608 | 5.4 | 6.0 | czlonkowski | n8n-mcp | CWE-200 | n8n-MCP: Incorrect authorization can expose default-scope workflow version ba… |
| CVE-2026-50183 | 4.7 | 5.9 | WWBN | AVideo | CWE-79 | WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI … |
| CVE-2026-52842 | 9.3 | 5.8 | lightpanda-io | browser | CWE-346 | Lightpanda:URL parser misidentifies page origin for URLs containing @ in the … |
| CVE-2026-47158 | 8.3 | 5.7 | dani-garcia | vaultwarden | CWE-352 | Vaultwarden: CSRF in SSO Authorization Flow |
| CVE-2026-56743 | 5.4 | 5.5 | cilium | cilium | CWE-863 | Cilium may unexpectedly allow ingress traffic from the local namespace when a… |
| CVE-2026-61453 | 5.1 | 5.1 | getgrav | grav | CWE-79 | Grav before 2.0.1 XSS via Twig String Concatenation |
| CVE-2026-61643 | 5.9 | 5.1 | labring | FastGPT | CWE-863 | FastGPT: workflow runtime can execute another user's private HTTP toolset |
| CVE-2026-53516 | 8.3 | 4.9 | better-auth | better-auth | CWE-287 | Better Auth: Account takeover via OAuth auto-link to unverified pre-registere… |
| CVE-2026-50562 | 9.3 | 4.8 | labring | FastGPT | CWE-266 | FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview… |
| CVE-2026-59950 | 7.6 | 4.6 | modelcontextprotocol | python-sdk | CWE-346 | MCP Python SDK: WebSocket server transport does not support Host/Origin valid… |
| CVE-2026-14961 | 6.2 | 4.6 | Pegatron Corp. | Tdelo64.sys | CWE-20 | CVE-2026-14961 |
| CVE-2026-56087 | 6.1 | 4.2 | Dell | ThinOS 10 | CWE-693 | Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism… |
| CVE-2026-38753 | 4.9 | 4.3 | BusyBox | BusyBox | CWE-416 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0… |
| CVE-2026-61433 | 8.5 | 4.2 | MervinPraison | PraisonAI | CWE-94 | PraisonAI before 4.6.78 Code Injection via API deployment generator |
| CVE-2026-59838 | 4.8 | 4.1 | Fortinet | FortiSIEM | CWE-80 | A improper neutralization of script-related html tags in a web page (basic xs… |
| CVE-2026-13385 | 9.5 | 4.1 | ASUS | Router | CWE-295 | An Improper Validation of Integrity Check Value and Improper Certificate Vali… |
| CVE-2026-42936 | 8.4 | 4.0 | SBI SECURITIES Co.,Ltd. | HYPER SBI 2 | CWE-427 | The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If ther… |
| CVE-2026-58559 | 6.5 | 4.0 | Huawei | Harmony OS | CWE-789 | DoS vulnerability in the vibration service. Impact: Successful exploitation o… |
| CVE-2026-45337 | 7.6 | 3.9 | better-auth | better-auth | CWE-285 | Better Auth: Device authorization approve and deny accept any authenticated s… |
| CVE-2026-53514 | 7.7 | 3.8 | better-auth | better-auth | CWE-287 | Better Auth: Unauthorized invitation acceptance via unverified email match in… |
| CVE-2026-49988 | 6.8 | 3.8 | yamadashy | repomix | CWE-200 | Repomix: attach_packed_output can bypass file-read secret scanning for suppor… |
| CVE-2026-62355 | 5.4 | 3.6 | taosdata | TDengine | CWE-269 | TDengine: Standard User permission unexpect |
| CVE-2026-55242 | 8.8 | 3.5 | frappe | erpnext | CWE-863 | ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock … |
| CVE-2026-15029 | 8.4 | 3.4 | ASUS | System Control Interface v3 | CWE-822 | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS Syste… |
| CVE-2026-49445 | 8.8 | 2.7 | cilium | cilium | CWE-732 | Cilium: Sensitive information disclosure and cluster disruption via local Env… |
| CVE-2026-61859 | 4.8 | 2.6 | ImageMagick | ImageMagick | CWE-59 | ImageMagick before 7.1.2-26 Policy Bypass via script operation |
| CVE-2026-47703 | 6.3 | 2.4 | AdguardTeam | AdGuardHome | CWE-330 | AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle |
| CVE-2026-15030 | 5.6 | 1.6 | ASUS | System Control Interface v3 | CWE-125 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control I… |
| CVE-2026-56375 | 4.8 | 1.5 | ImageMagick | ImageMagick | CWE-401 | ImageMagick - Memory Leak in ASHLAR Coder Action Failure |
| CVE-2026-40633 | 5.5 | 1.4 | Dell | PowerScale OneFS | CWE-532 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 th… |
| CVE-2026-45313 | 7.7 | 1.4 | sandboxie-plus | Sandboxie | CWE-284 | Sandboxie-Plus: Sandboxie APC Injection Sandbox Escape |
| CVE-2026-50144 | 7.1 | 1.4 | Tencent | ncnn | CWE-20 | ncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negativ… |
| CVE-2026-20157 | 9.8 | 1.3 | Cisco | Cisco RoomOS Software | CWE-311 | Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities |
| CVE-2026-61828 | 8.5 | 1.3 | NixOS | nixpkgs | CWE-276 | nixos/mysql : `services.mysql` is configured with insecure authentication by … |
| CVE-2026-49501 | 6.7 | 1.2 | Dell | PowerScale OneFS | CWE-269 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.… |
| CVE-2026-61862 | 2.1 | 1.2 | ImageMagick | ImageMagick | CWE-125 | ImageMagick before 7.1.2-26 Information Disclosure via identify |
| CVE-2026-56687 | 7.8 | 1.2 | Dell | ThinOS 10 | CWE-448 | Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature i… |
| CVE-2026-15779 | 6.1 | 1.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-732 | Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths with… |
| CVE-2026-61864 | 2.1 | 1.1 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in Log Colorspace |
| CVE-2026-61865 | 2.1 | 1.1 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in Hough Lines |
| CVE-2026-61867 | 2.1 | 1.1 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder |
| CVE-2026-61869 | 2.1 | 1.1 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak in MIFF Encoder |
| CVE-2026-62294 | 5.1 | 1.0 | flameshot-org | flameshot | CWE-362 | Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open … |
| CVE-2026-8920 | 8.5 | 1.0 | ASUS | Aura Wallpaper Service | CWE-73 | Improper Restriction of Communication Channel to Intended Endpoints and Exter… |
| CVE-2026-61872 | 2.0 | 0.8 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak via TIFF Encoder |
| CVE-2026-40952 | 8.5 | 0.7 | Absolute Security | Secure Access | CWE-276 | Privilge misconfiguration in Secure Access installers |
| CVE-2026-61464 | 1.0 | 0.6 | ImageMagick | ImageMagick | CWE-122 | ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11 |
| CVE-2026-58549 | 4.0 | 0.5 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58550 | 4.0 | 0.5 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58553 | 4.0 | 0.5 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58551 | 5.1 | 0.5 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58552 | 5.1 | 0.5 | Huawei | HarmonyOS | CWE-120 | Out-of-bounds read vulnerability in the image codec module. Impact: Successfu… |
| CVE-2026-58558 | 7.8 | 0.3 | Huawei | Harmony OS | CWE-840 | Permission control vulnerability in the file system. Impact: Successful explo… |
| CVE-2026-58555 | 6.6 | 0.2 | Huawei | HarmonyOS | CWE-264 | Permission bypass vulnerability in the card module. Impact: Successful exploi… |
| CVE-2026-58556 | 5.1 | 0.2 | Huawei | Harmony OS | CWE-264 | Permission control vulnerability in the Bluetooth module. Impact: Successful … |
| CVE-2026-58554 | 6.6 | 0.1 | Huawei | HarmonyOS | CWE-200 | Permission control vulnerability in the Settings module. Impact: Successful e… |
| CVE-2026-40953 | 6.7 | 0.1 | Absolute Security | Secure Access | CWE-787 | Heap overflow in Secure Access clients |
| CVE-2026-58557 | 4.8 | 0.0 | Huawei | HarmonyOS | CWE-701 | Design defect vulnerability in Expedition mode. Impact: Successful exploitati… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-15 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.