boxscore/security
Wednesday, July 15, 2026 · all times UTC← 2026-07-14 · archive · 2026-07-16 →

269 CVEs published July 15, 2026: 36 critical, 123 high, 92 medium, 17 low; 2 in KEV; 14 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 244 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published40741639212972563
KEV catalog size1670

714 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux40152012186653012730.27.5.0013-56
google941358150612555387460.47.8.0024-497
microsoft62413358791930012378302.27.8.0039+417
red hat502421410011612400.06.5.0026-3
apple0991236629377.16.5.0031-14
suse82141241000.08.5.0033+8
canonical1212685000.05.5.0011+1
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco163961690961230.87.5.0050+12
ubiquiti2536142110438.38.8.0036+20
palo alto networks1425021471428.04.7.0021+5
netgear62300221800.04.6.0022-11
fortinet12202610028315.06.7.0032+10
f58175830715.98.6.0057+8
ivanti211232033545.58.8.3445-2
checkpoint0915303111.17.5.0410-3
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache76229478981114010.47.5.0048+9
mozilla66212183201300.06.5.0025+1
drupal465165355512.05.9.0018+46
gitlab74005276425.04.7.0024-4
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle12711321161844031.18.8.0040-2
adobe932392610110547541.77.5.0021-31
ibm21263842460700.07.5.0025-9
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-3
veeam042200400.09.0.0046-1
zohocorp031110000.08.4.01700
servicenow111000200.09.5.2673+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0025+17
synology02325133000.05.6.0025-5
siemens7161870100.07.6.00190
d-link11405352617.16.0.0058-8
abb060420000.07.2.0018-5
schneider electric060420100.07.8.0024-1
moxa050320000.07.0.0029-1
dahua030111200.06.9.0036-3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester37108005652000.05.5.0026+1
dell3793442433211.16.8.0019+30
capgo2283242381000.07.1.0028+20
openclaw16830482510000.07.2.0021-18
nvidia40791252150000.07.8.0019+36
imagemagick3273155512300.05.3.0017+4
spring073231391000.06.5.0024-71
itsourcecode1265001946000.02.1.0020-10

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
Most disclosures (vendor)
VendorCVEs
microsoft638
google593
linux458
oracle241
apache130
red hat125
adobe111
capgo81
dell68
ibm66
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco12
apple7
google6
ivanti5
adobe4
solarwinds4
synacor4
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven62
PyPI5
npm5
NuGet3
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2023-4346KNX Association0
CVE-2025-67038Lantronix0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171701
CVE-2021-27102Accellion2021-11-171701
CVE-2021-27101Accellion2021-11-171701
CVE-2021-27103Accellion2021-11-171701
CVE-2021-21017Adobe2021-11-171701
CVE-2021-28550Adobe2021-11-171701
CVE-2021-42013Apache2021-11-171701
CVE-2021-41773Apache2021-11-171701
CVE-2021-30858Apple2021-11-171701
CVE-2021-30860Apple2021-11-171701

Transactions

EXPLOIT PUBLISHEDCVE-2026-10673 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-41580 (Stirling-Tools Stirling-PDF). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45737 (argoproj argo-cd). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45738 (argoproj argo-cd). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45804 (huggingface diffusers). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46709 (Eugeny tabby). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47703 (AdguardTeam AdGuardHome). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49987 (yamadashy repomix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49988 (yamadashy repomix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56398 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56400 (open-webui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-62947 (openwrt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-62948 (openwrt). Public exploit reference added.

Yesterday's Results

269 CVEs published. 25 box scores, 244 table rows — nothing truncated.

Oracle E-Business Suite
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1331   96.1   YES
AFFECTED
  Product          Versions  Fixed
  Oracle Payments  12.2.3 –  —
TIMELINE
  May 18  Reserved by CNA
  Jul 15  Added to CISA KEV, due Jul 18
  Jul 15  Published (CNA: oracle)
CWE-269, CWE-287, CWE-306 · CNA: oracle · 2 references · NVD status: Analyzed · KEV due July 18, 2026
CVE-2023-4346AWAITING ENRICHMENT
KNX Association KNX Protocol Connection Authorization Option 1
  CVSS   EPSS    %ile   KEV
  —      .0091   56.9   YES
AFFECTED
  Product                                         Versions     Fixed
  KNX Protocol Connection Authorization Option 1  unspecified  —
TIMELINE
  Jul 15  Added to CISA KEV, due Jul 29
  Jul 15  Published
0 references · KEV due July 29, 2026
n/a n/a — LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. Th…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0595   92.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jul 15  Published (CNA: mitre)
CWE-77 · CNA: mitre · 3 references · NVD status: Awaiting Analysis
F5 NGINX Plus — NGINX Map directive and Regex matching vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.2   .0351   88.2     —
AFFECTED
  Product            Versions    Fixed
  NGINX Plus         37.0.0.1 –  —
  NGINX Open Source  1.31.2 –    —
TIMELINE
  May 5   Reserved by CNA
  Jul 15  Published (CNA: f5)
CWE-122 · CNA: f5 · 1 reference · NVD status: Analyzed
decolua 9router — 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0239   82.6     —
AFFECTED
  Product  Versions               Fixed
  9router  >= 0.4.30, < 0.4.37 –  —
TIMELINE
  May 13  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-78, CWE-306 · CNA: GitHub_M · 2 references · NVD status: Deferred
Apache Fineract: SQL injection in runreports endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0228   81.7     —
AFFECTED
  Product          Versions     Fixed
  Apache Fineract  unspecified  —
TIMELINE
  Apr 1   Reserved by CNA
  Jul 15  Published (CNA: apache)
CWE-89 · CNA: apache · 4 references · NVD status: Analyzed
n/a n/a — xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and comm…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0167   74.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jul 15  Published (CNA: mitre)
CWE-94 · CNA: mitre · 2 references · NVD status: Deferred
getgrav grav — Grav Flex Objects - Server-Side Template Injection via Dynamic Titles
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0108   62.4     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  1.4.0
TIMELINE
  Jul 1   Reserved by CNA
  Jul 15  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 2 references · NVD status: Deferred
Apache Fineract: Office list: SQL Injection via Subquery in orderBy
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  H    8.1   .0084   55.0     —
AFFECTED
  Product          Versions     Fixed
  Apache Fineract  unspecified  1.15.0
TIMELINE
  Jun 25  Reserved by CNA
  Jul 15  Published (CNA: apache)
CWE-89 · CNA: apache · 3 references · NVD status: Analyzed
Composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0080   53.5     —
AFFECTED
  Product   Versions             Fixed
  composer  >= 1.0, < 1.10.28 –  —
TIMELINE
  May 13  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-200 · CNA: GitHub_M · 9 references · NVD status: Awaiting Analysis
n/a n/a — An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim sy…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0072   51.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Nov 18  Reserved by CNA
  Jul 15  Published (CNA: mitre)
CWE-77 · CNA: mitre · 3 references · NVD status: Awaiting Analysis
decolua 9router — 9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0072   50.8     —
AFFECTED
  Product  Versions   Fixed
  9router  < 0.5.2 –  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 3 references · NVD status: Deferred
F5 NGINX Plus — NGINX ngx_http_slice_module vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   H    8.8   .0071   50.5     —
AFFECTED
  Product            Versions    Fixed
  NGINX Plus         37.0.0.1 –  —
  NGINX Open Source  1.31.2 –    —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 15  Published (CNA: f5)
CWE-908 · CNA: f5 · 1 reference · NVD status: Analyzed
AWS jsii — OS command injection in jsii-diff in AWS jsii
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   A   H   H   H    8.4   .0063   47.3     —
AFFECTED
  Product  Versions     Fixed
  jsii     unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 15  Published (CNA: AMZN)
CWE-78 · CNA: AMZN · 2 references · NVD status: Awaiting Analysis
Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0062   46.8     —
AFFECTED
  Product        Versions     Fixed
  Gravity Forms  unspecified  —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 15  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 2 references · NVD status: Deferred
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0059   45.5     —
AFFECTED
  Product   Versions    Fixed
  nocobase  < 2.0.61 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 15  Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · 3 references · NVD status: Deferred
Apache Ivy: PackagerResolver path traversal vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  L  N    5.4   .0051   41.0     —
AFFECTED
  Product     Versions  Fixed
  Apache Ivy  2.0.0 –   —
TIMELINE
  Feb 9   Reserved by CNA
  Jul 15  Published (CNA: apache)
CWE-22 · CNA: apache · 2 references · NVD status: Analyzed
MervinPraison PraisonAI — PraisonAI before 1.6.78 Remote Code Execution via SkillTools
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   N    8.6   .0050   40.5     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  1.6.78
TIMELINE
  Jul 9   Reserved by CNA
  Jul 15  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 2 references · NVD status: Deferred
yamadashy repomix — Repomix: Command Injection (RCE) via `--remote-branch` Argument Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   A   H   H   H    7.5   .0050   40.3     —
AFFECTED
  Product  Versions    Fixed
  repomix  < 1.14.1 –  —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 15  Public exploit reference published
  Jul 15  Published (CNA: GitHub_M)
CWE-88 · CNA: GitHub_M · 3 references · NVD status: Analyzed
Grafana Grafana MCP Server — SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0049   40.1     —
AFFECTED
  Product             Versions  Fixed
  Grafana MCP Server  0.0.0 –   —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 15  Published (CNA: GRAFANA)
CWE-610 · CNA: GRAFANA · 1 reference · NVD status: Awaiting Analysis
Splunk Splunk Enterprise — Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0048   39.4     —
AFFECTED
  Product                Versions     Fixed
  Splunk Enterprise      10.4 –       —
  Splunk Cloud Platform  10.5.2605 –  —
TIMELINE
  Oct 8   Reserved by CNA
  Jul 15  Published (CNA: cisco)
CWE-22 · CNA: cisco · 1 reference · NVD status: Analyzed
Pegatron Corp. Tdelo64.sys — CVE-2026-14960
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0048   39.2     —
AFFECTED
  Product      Versions      Fixed
  Tdelo64.sys  02-17-2025 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 15  Published (CNA: certcc)
CWE-269, CWE-284, CWE-668 · CNA: certcc · 1 reference · NVD status: Deferred
Roskus Prospero Flow CRM — Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   N    6.9   .0047   38.6     —
AFFECTED
  Product            Versions  Fixed
  Prospero Flow CRM  1.0.0 –   —
TIMELINE
  Jul 3   Reserved by CNA
  Jul 15  Published (CNA: Secur0)
CWE-639 · CNA: Secur0 · 3 references · NVD status: Deferred
Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0047   38.6     —
AFFECTED
  Product          Versions     Fixed
  Apache Fineract  unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jul 15  Published (CNA: apache)
CWE-89 · CNA: apache · 3 references · NVD status: Analyzed
getgrav grav — Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   N    5.3   .0046   38.3     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  1.0.3
TIMELINE
  Jul 9   Reserved by CNA
  Jul 15  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-597628.738.0F5BIG-IPCWE-770BIG-IP HTTP/2 vulnerability
CVE-2026-564348.337.4F5NGINX PlusCWE-416NGINX ngx_http_ssi_module vulnerability
CVE-2026-405018.636.4CherryHQcherry-studioCWE-829Cherry Studio RCE via SearchService nodeIntegration Misconfiguration
CVE-2026-493529.836.4decolua9routerCWE-7989Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
CVE-2026-501489.135.6metabasemetabaseCWE-73Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
CVE-2026-436378.835.5PreferredAIcornacCWE-22Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
CVE-2026-563988.534.7open-webuiopen-webuiCWE-20Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI
CVE-2026-592358.734.4RoskusProspero Flow CRMCWE-639Missing authorization in Prospero Flow CRM allows low-privileged users to rea…
CVE-2026-513809.834.2n/an/aCWE-120Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows…
CVE-2026-599547.534.1apolloconfigapolloCWE-20Apollo ConfigService access key authentication bypass via appId parsing and n…
CVE-2026-599557.534.1apolloconfigapolloCWE-20Apollo ConfigService access key authentication bypass via raw config file app…
CVE-2026-554459.333.6whyourqinglongCWE-287Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication
CVE-2026-528919.933.5wekanwekanCWE-78Wekan: Shell Injection via Avatar Upload
CVE-2026-617409.333.5HKUDSLightRAGCWE-287LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /a…
CVE-2026-623498.333.3taosdataTDengineCWE-121TDengine: Off-by-One Buffer Overflow
CVE-2026-365907.533.3n/an/aCWE-400An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of…
CVE-2026-629474.933.3openwrtopenwrtCWE-22OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
CVE-2026-455349.032.8dataeasedataeaseCWE-94DataEase: RCE Vulnerability
CVE-2026-106738.832.5zephyrprojectzephyrCWE-787Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly
CVE-2026-457388.732.4argoprojargo-cdCWE-79Argo CD: Stored XSS in application link annotations enables developer-to-admi…
CVE-2026-586588.832.1gpustackgpustackCWE-306GPUStack Unauthenticated Information Disclosure via Worker Endpoints
CVE-2026-616137.731.9cursorcursorCWE-306Cursor: Cloud Agent Browser Sandbox Escape
CVE-2026-464219.331.6cap-js@cap-js/sqliteCWE-506Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-…
CVE-2026-614358.831.5MervinPraisonPraisonAICWE-287PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing
CVE-2026-132305.331.3TP-Link Systems Inc.Kasa EC71 v4CWE-200Information Disclosure Vulnerability in Local Discovery Response in TP-Link K…
CVE-2026-458047.530.8huggingfacediffusersCWE-367Diffusers: TOCTOU Trust Remote Code Bypass
CVE-2026-623507.230.1taosdataTDengineCWE-94TDengine: UDF lead to RCE
CVE-2026-471596.930.1dani-garciavaultwardenCWE-287Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allo…
CVE-2026-554106.730.1nocobasenocobaseCWE-78NocoBase backup restore schema name allows command injection
CVE-2026-118515.929.9ASUSRouterCWE-89Improper Neutralization of Special Elements used in an SQL Command ("SQL Inje…
CVE-2026-123828.229.7Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-290Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject he…
CVE-2026-97708.629.4TP-Link Systems Inc.Kasa EC71 v4CWE-321Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link K…
CVE-2026-613717.529.1n/an/aCWE-59Microsoft AVML before 0.17.0 could follow a symlink when opening a destinatio…
CVE-2026-457376.529.0argoprojargo-cdCWE-200Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive…
CVE-2026-629489.628.8openwrtopenwrtCWE-79OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file line…
CVE-2026-267196.128.7n/an/aCWE-79Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote a…
CVE-2026-556529.828.6wekanwekanCWE-287Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan…
CVE-2026-586607.228.6kanboardkanboardCWE-639Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop
CVE-2026-564009.027.8open-webuiopen-webuiCWE-613open-webui - Remote Code Execution via CORS Misconfiguration and Session Vali…
CVE-2026-563496.327.4n8nn8nCWE-20n8n - Guardrail Node Bypass via Crafted Input
CVE-2026-201465.527.0CiscoCisco Identity Services Engine SoftwareCWE-22Cisco Identity Services Engine Path Traversal Vulnerability
CVE-2026-614276.926.8MervinPraisonPraisonAICWE-20PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream
CVE-2026-623789.026.1rustfsconsoleCWE-79RustFS Console: Critical Stored XSS in Preview Modal leading to Administrativ…
CVE-2026-492797.725.5WWBNAVideoCWE-79WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSoc…
CVE-2026-586598.425.4Lightning-AIpytorch-lightningCWE-470PyTorch Lightning Arbitrary Code Execution via _instantiator Hyperparameter
CVE-2026-458067.725.4penpotpenpotCWE-918Penpot: Authenticated SSRF in remote image import via create-file-media-objec…
CVE-2026-528907.125.3wekanwekanCWE-22Wekan: Arbitrary file read and server DoS via attachment versions.original.path
CVE-2026-566798.725.2decolua9routerCWE-9159Router: Mass assignment in PATCH /api/settings allows authenticated authoriz…
CVE-2026-623517.525.2taosdataTDengineCWE-125TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in …
CVE-2026-626858.125.1filebrowserfilebrowserCWE-647File Browser: Colliding username normalization gives two users the same home …
CVE-2026-501247.125.0dataeasedataeaseCWE-434DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper
CVE-2026-528697.124.7modelcontextprotocolpython-sdkCWE-639MCP Python SDK: HTTP transports serve session requests without verifying the …
CVE-2026-580778.724.5weeblr.com4Analytics extension for JoomlaCWE-79Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
CVE-2026-578338.624.5weeblr.com4Analytics extension for JoomlaCWE-79Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
CVE-2026-592587.224.2immich-appimmichCWE-863immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser
CVE-2026-592596.024.3n8nn8nCWE-639n8n - Permission Bypass via Expression Parser Mismatch in External Secrets
CVE-2026-454198.524.0dataeasedataeaseCWE-22DataEase: Arbitrary File Write Vulnerability
CVE-2026-455338.324.0dataeasedataeaseCWE-22DataEase: Path Traversal Vulnerability
CVE-2026-409576.124.0Absolute SecuritySecure AccessCWE-1021Frameable content vulnerability in the Secure Access server login page
CVE-2026-158048.723.5MetaGuruHCMCWE-89MetaGuru|HCM - SQL Injection
CVE-2026-135858.223.3ASUSSystem Control Interface v3CWE-226Allocation of Resources Without Limits and Throttling and Sensitive Informati…
CVE-2026-617369.323.1HKUDSLightRAGCWE-942LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2026-464858.223.0lissy93dashyCWE-15Dash: Users can write to config despire permissions (OIDC tested)
CVE-2025-327816.523.0apolloconfigapolloCWE-639Apollo: Apollo Portal release endpoint allows cross-application configuration…
CVE-2026-544589.623.0WWBNAVideoCWE-79AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metada…
CVE-2026-528939.222.7wekanwekanCWE-287Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in o…
CVE-2026-487958.622.6adonisjscoreCWE-1321Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser
CVE-2026-89197.222.6ASUSGameSDKCWE-942Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSD…
CVE-2026-555768.822.3MaaAssistantArknightsMaaAssistantArknightsCWE-78MaaAssistantArknights: PR-title expression injection in release-preparation.yml
CVE-2026-616848.822.0labringFastGPTCWE-798FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke…
CVE-2026-631757.122.0LookylooPlaywrightCaptureCWE-613Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo -…
CVE-2026-557238.721.8F5NGINX Ingress ControllerCWE-76NGINX Ingress Controller vulnerability
CVE-2026-614368.821.5MervinPraisonPraisonAICWE-287PraisonAI before 4.6.78 Missing Webhook Signature Verification
CVE-2026-464595.321.3ICU ScandinaviaBoomerangCWE-862Missing Authorization in ICU Scandinavia Boomerang
CVE-2026-528657.121.1F5NGINX Ingress ControllerCWE-476NGINX Ingress Controller vulnerability
CVE-2026-534466.221.1wekanwekanCWE-918Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs
CVE-2026-449869.920.8penpotpenpotCWE-287Penpot: Pre-authenticated account takeover via team-invitation token + prepar…
CVE-2026-563398.720.1Cap-gocapgoCWE-203Capgo - Unauthenticated Organization Existence Enumeration via rescind_invita…
CVE-2026-618368.619.6directusdirectusCWE-524Directus: Authorization-dependent response served from unsegmented cache key
CVE-2026-471647.719.2dani-garciavaultwardenCWE-284Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Att…
CVE-2026-623145.819.2TecharoHQanubisCWE-284Anubis: Policy bypass via client controlled X-Original-URI header
CVE-2026-453208.719.1dataeasedataeaseCWE-89DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection
CVE-2026-500307.119.1dataeasedataeaseCWE-89DataEase: Arbitrary SQL execution in preview path (direct data disclosure)
CVE-2026-528886.819.1nocobasenocobaseCWE-184NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
CVE-2026-498676.319.1dataeasedataeaseCWE-79DataEase: Authenticated Stored XSS in DataEase Template Static Resources
CVE-2026-125128.619.0UnknownQuotes llamaCWE-89Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter
CVE-2026-201537.518.9CiscoCisco RoomOS SoftwareCWE-20Cisco RoomOS Security Hardening Release - Input Validation Vulnerabilities
CVE-2026-201587.518.9CiscoCisco RoomOS SoftwareCWE-664Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulner…
CVE-2026-201877.518.9CiscoCisco RoomOS SoftwareCWE-703Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vul…
CVE-2026-592546.318.5n8nn8nCWE-639n8n - External Secrets Disclosure via Workflow Node Expressions
CVE-2026-600656.318.5F5NGINX PlusCWE-125NGINX Plus ngx_stream_mqtt_filter_module vulnerability
CVE-2026-628436.817.7filebrowserfilebrowserCWE-22File Browser: Archive builder turns backslash filenames into path traversal (…
CVE-2026-528926.517.7wekanwekanCWE-862Wekan: Read-only board members can create/modify/delete Custom Fields (privil…
CVE-2026-334446.917.6Absolute SecutitySecure AccessCWE-119Memory management vulnerability in Secure Access servers
CVE-2026-90075.517.6HCL SoftwareHCL NotesCWE-79Reflected XSS in HCL Notes
CVE-2026-201569.817.3CiscoCisco RoomOS SoftwareCWE-119Cisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities
CVE-2026-618737.217.3getgravgravCWE-73Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename
CVE-2026-159075.517.1H3CSecPath F1000-C8300CWE-74H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
CVE-2026-499975.417.2surrealdbsurrealdbCWE-285SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
CVE-2026-451506.316.9zen-browserdesktopCWE-451Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing
CVE-2026-455358.716.4dataeasedataeaseCWE-89DataEase: Stored SQL Injection Vulnerability
CVE-2026-616466.316.4labringFastGPTCWE-918FastGPT: Shared axios SSRF guard validates only the initial URL before follow…
CVE-2026-563525.316.4n8nn8nCWE-22n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter
CVE-2026-545607.616.2cloudrevecloudreveCWE-863Cloudreve: OAuth access tokens bypass scope enforcement due to missing client…
CVE-2026-614497.116.2getgravgravCWE-409Grav before 2.0.2 Decompression Bomb via Forged ZIP Size
CVE-2026-623535.416.3taosdataTDengineCWE-125TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken
CVE-2026-579968.716.1phpMyFAQphpMyFAQCWE-269phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endp…
CVE-2026-592557.116.1SpecterOpsBloodHoundCWE-862BloodHound Missing Authorization on Custom Node Management API
CVE-2026-614519.415.8getgravgravCWE-601Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url
CVE-2026-157466.915.8Amazonstrands-agents-toolsCWE-918Credential disclosure in Strands Agents Tools elasticsearch_memory tool
CVE-2026-545626.515.8cloudrevecloudreveCWE-918Cloudreve: Non-admin remote download users can SSRF loopback/internal service…
CVE-2026-552348.515.7wekanwekanCWE-284Wekan: Broken access control: any authenticated user can move their Cards/Lis…
CVE-2026-616447.715.8labringFastGPTCWE-863FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant d…
CVE-2026-464587.115.6ICU ScandinaviaBoomerangCWE-522Credential exposure in ICU Scandinavia Boomerang
CVE-2026-600858.715.5MervinPraisonPraisonAICWE-273PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
CVE-2026-535178.115.4better-authbetter-authCWE-362Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Conc…
CVE-2026-623615.515.2knadhlistmonkCWE-89listmonk: SQL Injection in `/api/subscribers/export` bypasses table access co…
CVE-2026-534447.615.1wekanwekanCWE-269Wekan: Missing authorization on OIDC Meteor methods allows privilege escalati…
CVE-2026-534457.115.1wekanwekanCWE-862Wekan: Authorization bypass in copyBoard DDP method allows any user to copy p…
CVE-2026-535157.115.1better-authbetter-authCWE-269Better Auth: Privilege escalation via SSO provider registration: missing admi…
CVE-2026-578318.714.9digital-peak.comDP Calendar extension for JoomlaCWE-89Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in …
CVE-2026-578328.714.9joomdonation.comEDocman extension for JoomlaCWE-89Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in …
CVE-2026-115795.315.0UnknownKali Forms — Contact Form & Drag-and-Drop BuilderCWE-434Kali Forms < 2.4.17 - Unauthenticated Media Upload
CVE-2026-201508.814.8CiscoCisco RoomOS SoftwareCWE-284Cisco RoomOS Security Hardening Release - Access Control Vulnerabilities
CVE-2026-334458.714.8Absolute SecuritySecure AccessCWE-400Memory management vulnerability in Secure Access servers
CVE-2026-528707.614.9modelcontextprotocolpython-sdkCWE-862MCP Python SDK: Experimental task handlers allow any client to access and can…
CVE-2026-387545.114.7BusyBoxBusyBoxCWE-125A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0…
CVE-2026-618357.714.5directusdirectusCWE-918Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
CVE-2026-618716.314.2ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in ICON decoder
CVE-2026-122818.114.2UnknownShibbolethCWE-287Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Ident…
CVE-2026-493537.514.1decolua9routerCWE-2909Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
CVE-2026-202986.514.2SplunkSplunk EnterpriseCWE-200Sensitive Information Disclosure through the storage/passwords REST Endpoint …
CVE-2026-534476.514.1wekanwekanCWE-639Wekan: `cloneBoard` Meteor method has no authorization check — any user can c…
CVE-2026-563536.314.2n8nn8nCWE-287n8n - Authentication Bypass in Chat Trigger Node
CVE-2026-471605.814.2dani-garciavaultwardenCWE-918Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex…
CVE-2026-458058.813.9penpotpenpotCWE-749Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoi…
CVE-2026-202968.314.0SplunkSplunk EnterpriseCWE-352SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in De…
CVE-2026-535187.613.9better-authbetter-authCWE-362Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Ena…
CVE-2026-567646.313.9HonoHonoCWE-208Hono - Timing Attack in basicAuth and bearerAuth Middleware
CVE-2026-544435.913.9lissy93dashyCWE-80Dashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas…
CVE-2026-540529.913.8czlonkowskin8n-mcpCWE-639n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP…
CVE-2026-415806.113.8Stirling-ToolsStirling-PDFCWE-79Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Au…
CVE-2026-454178.713.7dataeasedataeaseCWE-89DataEase: SQL injection vulnerability
CVE-2026-467097.813.6EugenytabbyCWE-77Tabby: Drag-and-drop path injection still allows RCE via shell command substi…
CVE-2026-159212.113.4nvm-shnvmCWE-22nvm path traversal via a malicious mirror's LTS codename writes outside the a…
CVE-2026-267189.113.2n/an/aCWE-352A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin…
CVE-2026-142517.713.1Red HatRed Hat OpenShift GitOpsCWE-862Gitops-operator: gitops-operator: missing allowednamespace check in reconcile…
CVE-2026-409582.313.2Absolute SecuritySecure AccessCWE-20Input validation error in Secure Access clients prior to 14.55
CVE-2026-618606.313.0ImageMagickImageMagickCWE-416ImageMagick before 7.1.2-26 Use-After-Free via freetype
CVE-2026-618686.313.0ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in YUV Decoder
CVE-2026-614468.612.9MervinPraisonPraisonAICWE-94PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery
CVE-2026-553995.112.4Absolute SecuritySecure AccessCWE-400Resource exhaustion vulnerability in the Secure Access publisher
CVE-2026-535129.111.8better-authbetter-authCWE-287Better Auth: OAuth refresh-token replay via missing client authentication on …
CVE-2026-334437.111.9Absolute SecuritySecure AccessCWE-400Memory management error in Secure Access servers prior to 14.55
CVE-2026-614407.111.9MervinPraisonPraisonAICWE-862PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints
CVE-2026-553986.911.3Absolute SecuritySecure AccessCWE-119Memory management vulnerability in Secure Access clients
CVE-2026-623485.411.4taosdataTDengineCWE-862TDengine: KILL SSMIGRATE missing authorization lets low-privilege users inter…
CVE-2026-336845.311.2WWBNAVideoCWE-862AVideo's Privilege AVideo: Escalation via Unguarded Permission Parameters in …
CVE-2026-387522.911.1BusyBoxBusyBoxCWE-674A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit…
CVE-2026-387552.911.1BusyBoxBusyBoxCWE-674A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.…
CVE-2026-614308.410.8MervinPraisonPraisonAICWE-918PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl
CVE-2026-614387.010.4MervinPraisonPraisonAICWE-78PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox
CVE-2026-600625.310.4F5NGINX AgentCWE-22NGINX Agent Vulnerability
CVE-2026-409542.110.3Absolute SecuritySecure AccessCWE-191Integer underflow in Secure Access clients prior to 14.55
CVE-2026-409552.110.3Absolute SecuritySecure AccessCWE-191Integer underflow vulnerability in Secure Access clients
CVE-2026-501477.610.1metabasemetabaseCWE-88Metabase: Arbitrary File Read via MySQL Connection Property Injection
CVE-2026-626833.19.9filebrowserfilebrowserCWE-863File Browser: Trailing-slash delete leaves a stale public share behind
CVE-2026-389745.39.5n/an/aCWE-295Dulwich through 1.1.0 was found to be missing SSH host key verification in co…
CVE-2026-614526.99.5getgravgravCWE-613Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens
CVE-2026-466849.59.3dataeasedataeaseCWE-347DataEase: Unauthorized Command Execution Vulnerability
CVE-2026-535139.68.8better-authbetter-authCWE-20Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @b…
CVE-2026-600876.98.9MervinPraisonPraisonAICWE-863PraisonAI before 1.6.78 Tool Approval Cache Bypass
CVE-2026-115805.58.9UnknownKali Forms — Contact Form & Drag-and-Drop BuilderCWE-639Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
CVE-2026-618632.18.7ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder
CVE-2026-618662.18.7ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in JNG encoder
CVE-2026-545637.18.5cloudrevecloudreveCWE-863Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`…
CVE-2026-332136.17.6getredashredashCWE-601Redash: Open redirect vulnerability in post-login redirect handling
CVE-2026-501826.17.6WWBNAVideoCWE-79AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Ga…
CVE-2026-528439.37.1lightpanda-iobrowserCWE-346Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin…
CVE-2026-15634.87.1PegasystemsPega InfinityCWE-79Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cros…
CVE-2026-15624.67.1PegasystemsPega InfinityCWE-79Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-s…
CVE-2026-567428.96.9ciliumciliumCWE-862Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
CVE-2026-566786.46.9decolua9routerCWE-209Router: Kiro region injection allows authenticated SSRF with Authorization h…
CVE-2026-409562.16.8Absolute SecuritySecure AccessCWE-200Memory disclosure in Secure Access Clients
CVE-2026-158097.86.0Red HatConfidential Compute AttestationCWE-134Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection …
CVE-2026-487997.76.1gitroomhqpostiz-appCWE-345Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook
CVE-2026-556085.46.0czlonkowskin8n-mcpCWE-200n8n-MCP: Incorrect authorization can expose default-scope workflow version ba…
CVE-2026-501834.75.9WWBNAVideoCWE-79WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI …
CVE-2026-528429.35.8lightpanda-iobrowserCWE-346Lightpanda:URL parser misidentifies page origin for URLs containing @ in the …
CVE-2026-471588.35.7dani-garciavaultwardenCWE-352Vaultwarden: CSRF in SSO Authorization Flow
CVE-2026-567435.45.5ciliumciliumCWE-863Cilium may unexpectedly allow ingress traffic from the local namespace when a…
CVE-2026-614535.15.1getgravgravCWE-79Grav before 2.0.1 XSS via Twig String Concatenation
CVE-2026-616435.95.1labringFastGPTCWE-863FastGPT: workflow runtime can execute another user's private HTTP toolset
CVE-2026-535168.34.9better-authbetter-authCWE-287Better Auth: Account takeover via OAuth auto-link to unverified pre-registere…
CVE-2026-505629.34.8labringFastGPTCWE-266FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview…
CVE-2026-599507.64.6modelcontextprotocolpython-sdkCWE-346MCP Python SDK: WebSocket server transport does not support Host/Origin valid…
CVE-2026-149616.24.6Pegatron Corp.Tdelo64.sysCWE-20CVE-2026-14961
CVE-2026-560876.14.2DellThinOS 10CWE-693Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism…
CVE-2026-387534.94.3BusyBoxBusyBoxCWE-416A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0…
CVE-2026-614338.54.2MervinPraisonPraisonAICWE-94PraisonAI before 4.6.78 Code Injection via API deployment generator
CVE-2026-598384.84.1FortinetFortiSIEMCWE-80A improper neutralization of script-related html tags in a web page (basic xs…
CVE-2026-133859.54.1ASUSRouterCWE-295An Improper Validation of Integrity Check Value and Improper Certificate Vali…
CVE-2026-429368.44.0SBI SECURITIES Co.,Ltd.HYPER SBI 2CWE-427The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If ther…
CVE-2026-585596.54.0HuaweiHarmony OSCWE-789DoS vulnerability in the vibration service. Impact: Successful exploitation o…
CVE-2026-453377.63.9better-authbetter-authCWE-285Better Auth: Device authorization approve and deny accept any authenticated s…
CVE-2026-535147.73.8better-authbetter-authCWE-287Better Auth: Unauthorized invitation acceptance via unverified email match in…
CVE-2026-499886.83.8yamadashyrepomixCWE-200Repomix: attach_packed_output can bypass file-read secret scanning for suppor…
CVE-2026-623555.43.6taosdataTDengineCWE-269TDengine: Standard User permission unexpect
CVE-2026-552428.83.5frappeerpnextCWE-863ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock …
CVE-2026-150298.43.4ASUSSystem Control Interface v3CWE-822Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS Syste…
CVE-2026-494458.82.7ciliumciliumCWE-732Cilium: Sensitive information disclosure and cluster disruption via local Env…
CVE-2026-618594.82.6ImageMagickImageMagickCWE-59ImageMagick before 7.1.2-26 Policy Bypass via script operation
CVE-2026-477036.32.4AdguardTeamAdGuardHomeCWE-330AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
CVE-2026-150305.61.6ASUSSystem Control Interface v3CWE-125Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control I…
CVE-2026-563754.81.5ImageMagickImageMagickCWE-401ImageMagick - Memory Leak in ASHLAR Coder Action Failure
CVE-2026-406335.51.4DellPowerScale OneFSCWE-532Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 th…
CVE-2026-453137.71.4sandboxie-plusSandboxieCWE-284Sandboxie-Plus: Sandboxie APC Injection Sandbox Escape
CVE-2026-501447.11.4TencentncnnCWE-20ncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negativ…
CVE-2026-201579.81.3CiscoCisco RoomOS SoftwareCWE-311Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
CVE-2026-618288.51.3NixOSnixpkgsCWE-276nixos/mysql : `services.mysql` is configured with insecure authentication by …
CVE-2026-495016.71.2DellPowerScale OneFSCWE-269Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.…
CVE-2026-618622.11.2ImageMagickImageMagickCWE-125ImageMagick before 7.1.2-26 Information Disclosure via identify
CVE-2026-566877.81.2DellThinOS 10CWE-448Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature i…
CVE-2026-157796.11.2Red HatRed Hat Enterprise Linux 10CWE-732Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths with…
CVE-2026-618642.11.1ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in Log Colorspace
CVE-2026-618652.11.1ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in Hough Lines
CVE-2026-618672.11.1ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder
CVE-2026-618692.11.1ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak in MIFF Encoder
CVE-2026-622945.11.0flameshot-orgflameshotCWE-362Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open …
CVE-2026-89208.51.0ASUSAura Wallpaper ServiceCWE-73Improper Restriction of Communication Channel to Intended Endpoints and Exter…
CVE-2026-618722.00.8ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak via TIFF Encoder
CVE-2026-409528.50.7Absolute SecuritySecure AccessCWE-276Privilge misconfiguration in Secure Access installers
CVE-2026-614641.00.6ImageMagickImageMagickCWE-122ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11
CVE-2026-585494.00.5HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585504.00.5HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585534.00.5HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585515.10.5HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585525.10.5HuaweiHarmonyOSCWE-120Out-of-bounds read vulnerability in the image codec module. Impact: Successfu…
CVE-2026-585587.80.3HuaweiHarmony OSCWE-840Permission control vulnerability in the file system. Impact: Successful explo…
CVE-2026-585556.60.2HuaweiHarmonyOSCWE-264Permission bypass vulnerability in the card module. Impact: Successful exploi…
CVE-2026-585565.10.2HuaweiHarmony OSCWE-264Permission control vulnerability in the Bluetooth module. Impact: Successful …
CVE-2026-585546.60.1HuaweiHarmonyOSCWE-200Permission control vulnerability in the Settings module. Impact: Successful e…
CVE-2026-409536.70.1Absolute SecuritySecure AccessCWE-787Heap overflow in Secure Access clients
CVE-2026-585574.80.0HuaweiHarmonyOSCWE-701Design defect vulnerability in Expedition mode. Impact: Successful exploitati…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-15 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.