CVSS EPSS %ile KEV — .9121 99.8 YES
AFFECTED Product Versions Fixed FortiSandbox unspecified —
TIMELINE Jul 16 Added to CISA KEV, due Jul 19 Jul 16 Published
248 CVEs published July 16, 2026: 38 critical, 96 high, 101 medium, 12 low; 2 in KEV; 23 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 223 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4322 | 16640 | 1298 | 2563 |
| KEV catalog size | 1670 | |||
736 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 41 | 1521 | 121 | 867 | 530 | 1 | 27 | 3 | 0.2 | 7.5 | .0013 | -56 |
| 94 | 1358 | 150 | 612 | 555 | 38 | 74 | 6 | 0.4 | 7.8 | .0024 | -536 | |
| microsoft | 644 | 1355 | 91 | 930 | 305 | 12 | 378 | 31 | 2.3 | 7.8 | .0039 | +436 |
| red hat | 56 | 248 | 14 | 105 | 116 | 13 | 4 | 0 | 0.0 | 6.7 | .0026 | -6 |
| apple | 0 | 99 | 1 | 23 | 66 | 2 | 93 | 7 | 7.1 | 6.5 | .0031 | -14 |
| canonical | 4 | 24 | 3 | 6 | 10 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +4 |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0033 | +6 |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 16 | 39 | 6 | 16 | 9 | 0 | 96 | 12 | 30.8 | 7.5 | .0050 | +12 |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 4 | 3 | 8.3 | 8.8 | .0036 | +20 |
| palo alto networks | 14 | 25 | 0 | 2 | 14 | 7 | 14 | 2 | 8.0 | 4.7 | .0021 | +5 |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 8 | 0 | 0.0 | 4.6 | .0022 | -11 |
| fortinet | 14 | 22 | 3 | 6 | 10 | 0 | 28 | 5 | 22.7 | 6.7 | .0036 | +12 |
| f5 | 8 | 17 | 5 | 8 | 3 | 0 | 7 | 1 | 5.9 | 8.6 | .0057 | +8 |
| ivanti | 2 | 11 | 2 | 3 | 2 | 0 | 33 | 5 | 45.5 | 8.8 | .3445 | -2 |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 76 | 229 | 47 | 89 | 81 | 11 | 40 | 1 | 0.4 | 7.5 | .0048 | +9 |
| mozilla | 6 | 62 | 12 | 18 | 32 | 0 | 13 | 0 | 0.0 | 6.5 | .0025 | -43 |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 5 | 1 | 2.0 | 5.9 | .0018 | +46 |
| gitlab | 7 | 40 | 0 | 5 | 27 | 6 | 4 | 2 | 5.0 | 4.7 | .0024 | -4 |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0026 | +1 |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | -2 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1 | 271 | 132 | 116 | 18 | 4 | 40 | 3 | 1.1 | 8.8 | .0040 | -242 |
| adobe | 93 | 239 | 26 | 101 | 105 | 4 | 75 | 4 | 1.7 | 7.5 | .0021 | -36 |
| ibm | 2 | 126 | 38 | 42 | 46 | 0 | 7 | 0 | 0.0 | 7.5 | .0025 | -9 |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 9 | 0 | 0.0 | 7.5 | .0034 | +5 |
| solarwinds | 0 | 7 | 1 | 2 | 2 | 0 | 11 | 4 | 57.1 | 7.5 | .0835 | -3 |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | -1 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .2673 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0025 | +10 |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 1 | 0 | 0.0 | 7.6 | .0019 | 0 |
| d-link | 1 | 14 | 0 | 5 | 3 | 5 | 26 | 1 | 7.1 | 6.0 | .0058 | -8 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -5 |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | -1 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -5 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | -3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 37 | 108 | 0 | 0 | 56 | 52 | 0 | 0 | 0.0 | 5.5 | .0026 | +1 |
| dell | 37 | 93 | 4 | 42 | 43 | 3 | 2 | 1 | 1.1 | 6.8 | .0019 | +24 |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0028 | +20 |
| openclaw | 16 | 83 | 0 | 48 | 25 | 10 | 0 | 0 | 0.0 | 7.2 | .0021 | -45 |
| nvidia | 40 | 79 | 12 | 52 | 15 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | +34 |
| imagemagick | 32 | 73 | 1 | 5 | 55 | 12 | 3 | 0 | 0.0 | 5.3 | .0017 | +4 |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -71 |
| itsourcecode | 12 | 65 | 0 | 0 | 19 | 46 | 0 | 0 | 0.0 | 2.1 | .0020 | -10 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48282 | 10.0 | .9924 | KEV |
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-50160 | 10.0 | .1775 |
| Vendor | CVEs |
|---|---|
| microsoft | 657 |
| 554 | |
| linux | 458 |
| apache | 130 |
| red hat | 122 |
| adobe | 106 |
| capgo | 81 |
| ibm | 66 |
| dell | 62 |
| picklescan | 50 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 12 |
| apple | 7 |
| 6 | |
| fortinet | 5 |
| ivanti | 5 |
| adobe | 4 |
| solarwinds | 4 |
| synacor | 4 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 61 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1702 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1702 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1702 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1702 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1702 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1702 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1702 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1702 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1702 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1702 |
EXPLOIT PUBLISHED — CVE-2026-33434 (wazuh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33754 (wazuh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-34150 (wazuh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39359 (wazuh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-40106 (wazuh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44180 (jupyter-server enterprise_gateway). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44181 (jupyter-server enterprise_gateway). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44182 (jupyter-server enterprise_gateway). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44595 (yamcs). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44596 (yamcs). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44632 (yamcs). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44968 (dbt-labs dbt-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44969 (dbt-labs dbt-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44970 (dbt-labs dbt-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46338 (facelessuser pymdown-extensions). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46562 (yamcs). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46621 (yamcs). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54526 (argoproj argo-workflows). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55548 (yamcs). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62290 (cert-manager). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62299 (coredns). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62309 (coredns). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62994 (coredns). Public exploit reference added.
248 CVEs published. 25 box scores, 223 table rows — nothing truncated.
CVSS EPSS %ile KEV — .9121 99.8 YES
AFFECTED Product Versions Fixed FortiSandbox unspecified —
TIMELINE Jul 16 Added to CISA KEV, due Jul 19 Jul 16 Published
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .7360 99.4 YES
AFFECTED Product Versions Fixed FortiSandbox 5.0.0 – — FortiSandbox Cloud 5.0.4 – — FortiSandbox PaaS 5.0.4 – —
TIMELINE Jan 29 Reserved by CNA Jul 16 Added to CISA KEV, due Jul 19 Jul 16 Published (CNA: fortinet)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0319 87.0 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.31.1 – —
TIMELINE Jul 7 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0216 80.7 —
AFFECTED Product Versions Fixed AVideo <= 29.0 – —
TIMELINE Jun 16 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H L N 7.1 .0192 78.2 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.31.1 – —
TIMELINE Jul 7 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0173 75.6 —
AFFECTED Product Versions Fixed yamcs < 5.12.7 – —
TIMELINE May 6 Reserved by CNA Jul 16 Public exploit reference published Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0150 72.2 —
AFFECTED Product Versions Fixed squid < 7.6 – —
TIMELINE May 19 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0147 71.6 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.31.1 – —
TIMELINE Jul 7 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N H H H 9.2 .0138 69.9 —
AFFECTED Product Versions Fixed AVideo unspecified —
TIMELINE Jul 16 Reserved by CNA Jul 16 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U N L H 5.5 .0136 69.5 —
AFFECTED Product Versions Fixed squid < 7.6 – —
TIMELINE Jun 2 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0135 69.3 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.31.1 – —
TIMELINE Jul 7 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N H H H 9.2 .0135 69.3 —
AFFECTED Product Versions Fixed AVideo unspecified —
TIMELINE Jul 16 Reserved by CNA Jul 16 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0127 67.5 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.31.1 – —
TIMELINE Jul 7 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0117 64.8 —
AFFECTED Product Versions Fixed yamcs < 5.12.7 – —
TIMELINE May 7 Reserved by CNA Jul 16 Public exploit reference published Jul 16 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A L H L 7.0 .0112 63.5 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.31.1 – —
TIMELINE Jul 7 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0106 61.7 —
AFFECTED Product Versions Fixed prompty < 2.0.0-beta.2 – —
TIMELINE Jun 9 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0102 60.5 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.31.1 – —
TIMELINE Jul 7 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P H H H 8.7 .0102 60.4 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.31.1 – —
TIMELINE Jul 7 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P H H H 8.7 .0102 60.4 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.31.1 – —
TIMELINE Jul 7 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0100 59.9 —
AFFECTED Product Versions Fixed yamcs < 5.12.7 – —
TIMELINE May 15 Reserved by CNA Jul 16 Public exploit reference published Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L N N 4.3 .0098 59.4 —
AFFECTED Product Versions Fixed yamcs < 5.12.7 – —
TIMELINE May 6 Reserved by CNA Jul 16 Public exploit reference published Jul 16 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P H H H 8.7 .0093 57.7 —
AFFECTED Product Versions Fixed prompty >= 2.0.0-alpha.1, < 2.0.0-beta.3 – —
TIMELINE Jun 9 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0092 57.2 —
AFFECTED Product Versions Fixed o365-moodle < 4.5.6 – —
TIMELINE Jun 15 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0091 57.0 —
AFFECTED Product Versions Fixed SGLang unspecified —
TIMELINE Jul 6 Reserved by CNA Jul 16 Published (CNA: certcc)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L H L 8.6 .0089 56.4 —
AFFECTED Product Versions Fixed simplechat < 0.241.206 – —
TIMELINE Jun 24 Reserved by CNA Jul 16 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-46562 | 9.8 | 52.9 | yamcs | yamcs | CWE-94 | Yamcs: Remote Code Execution via Mission Database algorithm override |
| CVE-2026-14371 | 8.8 | 52.2 | Lenovo | XClarity Integrator for Microsoft Windows Admin Center | CWE-78 | The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 … |
| CVE-2026-23538 | 7.5 | 51.9 | Feast | Feast Feature Server | CWE-770 | Feast: resource exhaustion via websocket endpoint |
| CVE-2026-44181 | 10.0 | 50.2 | jupyter-server | enterprise_gateway | CWE-1336 | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection re… |
| CVE-2026-55440 | 6.5 | 48.6 | microsoft | UFO | CWE-400 | Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing aut… |
| CVE-2026-53412 | 9.8 | 48.1 | Zoom Communications | Zoom Workplace for Windows | CWE-20 | Zoom Workplace VDI Plugin for Windows - Improper Input Validation |
| CVE-2026-15008 | 8.1 | 45.6 | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | CWE-502 | Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitr… |
| CVE-2026-53535 | 5.9 | 44.7 | activepieces | activepieces | CWE-22 | Activepieces: Arbitrary file write in git-sync via path traversal and symlinks |
| CVE-2026-47751 | 5.3 | 44.0 | anthropics | claude-code-action | CWE-78 | Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote … |
| CVE-2026-44180 | 9.8 | 43.6 | jupyter-server | enterprise_gateway | CWE-20 | Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can… |
| CVE-2023-49900 | 9.8 | 42.7 | X-Rite | MA-T6 | CWE-78 | Origin Validation Error in X-Rite MA-T6 |
| CVE-2026-54568 | 4.3 | 42.7 | microsoft | UFO | CWE-639 | Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE C… |
| CVE-2024-32386 | 7.3 | 41.9 | n/a | n/a | CWE-22 | Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerO… |
| CVE-2026-15422 | 9.1 | 41.0 | illumos | illumos-gate | CWE-122 | SCTP needs to better-check INIT ACK chunk parameters |
| CVE-2026-57205 | 4.3 | 40.6 | microsoft | simplechat | CWE-200 | SimpleChat: Authenticated users can access other users' profile metadata thro… |
| CVE-2026-44182 | 10.0 | 40.5 | jupyter-server | enterprise_gateway | CWE-74 | Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Templ… |
| CVE-2026-1609 | 8.1 | 40.5 | Keycloak | Keycloak | CWE-284 | Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt a… |
| CVE-2026-45367 | 7.5 | 39.9 | hapifhir | org.hl7.fhir.core | CWE-1333 | HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HT… |
| CVE-2026-33754 | 6.5 | 39.6 | wazuh | wazuh | CWE-400 | Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory all… |
| CVE-2026-48863 | 7.5 | 38.6 | OpenSUSE | libsolv | CWE-121 | Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verificat… |
| CVE-2026-55629 | 8.7 | 37.8 | avwo | whistle | CWE-22 | Whistle: Path traversal |
| CVE-2026-44177 | 8.8 | 37.7 | getkirby | kirby | CWE-22 | Kirby: Pre-authentication path traversal and PHP file inclusion during user l… |
| CVE-2026-15013 | 9.8 | 37.3 | cyberlord92 | SAML Single Sign On – SSO Login | CWE-347 | SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAM… |
| CVE-2026-22752 | 9.6 | 37.0 | Spring Security | Spring Authorization Server | CWE-287 | Spring Security Authorization Server Dynamic Client Registration endpoints pe… |
| CVE-2026-59117 | 7.5 | 36.8 | Microsoft | Windows Terminal App | CWE-190 | Windows Terminal Remote Code Execution Vulnerability |
| CVE-2026-15352 | 8.2 | 35.8 | NASA | Core Flight System (cFS) Health & Safety (HS) Application | CWE-476 | NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer D… |
| CVE-2026-45336 | 10.0 | 35.7 | StratonWebDesigners | HireFlow | CWE-798 | HireFlow: Use of Hard-coded Credentials |
| CVE-2026-63087 | 9.3 | 35.6 | grafana-cold-storage | oncall | CWE-306 | Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint |
| CVE-2026-55407 | 6.3 | 35.3 | anthropics | buffa | CWE-400 | Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unboun… |
| CVE-2026-57073 | 9.1 | 35.2 | CODECHILD | HTML::Bare | CWE-125 | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead |
| CVE-2026-36425 | 6.5 | 35.2 | n/a | n/a | CWE-269 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier… |
| CVE-2026-57074 | 9.1 | 33.5 | CODECHILD | XML::Bare | CWE-125 | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead |
| CVE-2026-3031 | 9.8 | 33.4 | TOKUHIROM | Image::EPEG | CWE-1104 | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of t… |
| CVE-2026-13397 | 7.5 | 32.5 | CODECHILD | HTML::Bare | CWE-835 | HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when … |
| CVE-2026-13401 | 7.5 | 32.0 | CODECHILD | XML::Bare | CWE-835 | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when p… |
| CVE-2025-71377 | 8.7 | 31.5 | stoatchat | stoatchat | CWE-1025 | stoatchat before 20250210-1 Unrestricted Message History Fetch |
| CVE-2026-62309 | 7.5 | 30.8 | coredns | coredns | CWE-476 | CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — s… |
| CVE-2026-57075 | 9.1 | 30.5 | TODDR | YAML::Syck | CWE-125 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a si… |
| CVE-2026-63085 | 8.7 | 30.2 | axelor | axelor-open-platform | CWE-863 | Axelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational R… |
| CVE-2026-63088 | 7.7 | 30.2 | stoatchat | stoatchat | CWE-918 | stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass |
| CVE-2026-59237 | 6.9 | 29.9 | Roskus | Prospero Flow CRM | CWE-639 | IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification… |
| CVE-2026-54526 | 8.9 | 29.4 | argoproj | argo-workflows | CWE-284 | Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch by… |
| CVE-2025-45870 | 6.5 | 29.3 | n/a | n/a | CWE-22 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclus… |
| CVE-2026-45568 | 9.9 | 29.1 | openziti | zrok | CWE-22 | zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths |
| CVE-2026-15727 | 4.9 | 28.6 | xylus | WP Bulk Delete | CWE-89 | WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'd… |
| CVE-2026-46512 | 9.9 | 28.2 | mwtcmi | frogman | CWE-94 | Frogman: Dialplan template parameters interpolated into extensions_custom.con… |
| CVE-2026-45695 | 9.8 | 27.8 | kopia | kopia | CWE-78 | Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --w… |
| CVE-2026-38158 | 9.8 | 27.8 | n/a | n/a | CWE-89 | A SQL injection vulnerability in the /ureport/datasource/previewData componen… |
| CVE-2026-11386 | 9.0 | 27.2 | Canonical | ubuntu-pro-client (ubuntu-advantage-tools) | CWE-20 | ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Dir… |
| CVE-2026-45576 | 8.3 | 27.1 | openziti | zrok | CWE-22 | zrok copy writes attacker-controlled WebDAV paths outside the destination root |
| CVE-2026-15022 | 6.5 | 27.1 | themeum | Tutor LMS – eLearning and online course solution | CWE-89 | Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Qui… |
| CVE-2026-45368 | 8.4 | 26.3 | getkirby | kirby | CWE-79 | Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in… |
| CVE-2026-46336 | 7.1 | 26.1 | manyfold3d | manyfold | CWE-22 | Manyfold: Authenticated Path Traversal via File Rename |
| CVE-2026-62826 | 5.4 | 26.0 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-14254 | 8.3 | 25.8 | Perforce | Delphix Continuous Data | CWE-307 | Improper Restriction of Excessive Authentication Attempts in Delphix Continuo… |
| CVE-2026-46515 | 9.3 | 25.1 | mwtcmi | frogman | CWE-862 | Frogman: Multiple read-tier tools expose admin-grade data and arbitrary Graph… |
| CVE-2026-46686 | 8.5 | 25.1 | emlog | emlog | CWE-79 | Emlog Reflected Cross-Site Scripting |
| CVE-2026-63086 | 6.9 | 25.1 | huggingface | text-generation-inference | CWE-918 | text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat compl… |
| CVE-2026-62299 | 5.3 | 23.8 | coredns | coredns | CWE-476 | CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) … |
| CVE-2026-15103 | 8.8 | 23.6 | getwpfunnels | WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell | CWE-269 | WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation vi… |
| CVE-2026-46338 | 4.3 | 23.6 | facelessuser | pymdown-extensions | CWE-22 | PyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-pref… |
| CVE-2026-61718 | 5.4 | 23.2 | bunkerity | bunkerweb | CWE-285 | bunkerweb: Read-only Web UI users can delete job cache files due to missing a… |
| CVE-2026-12753 | 7.5 | 23.0 | themehunk | Advance Product Search- Voice & Ajax Search for WooCommerce | CWE-89 | Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauth… |
| CVE-2026-62963 | 8.7 | 22.7 | centrifugal | centrifugo | CWE-409 | Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional W… |
| CVE-2026-59249 | 6.3 | 22.7 | elixir-mint | mint | CWE-444 | Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling aga… |
| CVE-2026-12492 | 9.8 | 22.5 | Unknown | Happy Coders OTP Login for WooCommerce | CWE-287 | Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeov… |
| CVE-2026-62994 | 3.7 | 22.0 | coredns | coredns | CWE-248 | CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that pa… |
| CVE-2026-44981 | 8.2 | 21.7 | crowdsecurity | crowdsec | CWE-409 | CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression |
| CVE-2026-46687 | 7.7 | 21.7 | emlog | emlog | CWE-24 | Emlog Local File Inclusion (LFI) |
| CVE-2026-39359 | 7.5 | 21.4 | wazuh | wazuh | CWE-22 | Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name |
| CVE-2026-15651 | 4.9 | 21.3 | jgwhite33 | WP TripAdvisor Review Slider | CWE-89 | WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Inj… |
| CVE-2026-15407 | 4.3 | 21.3 | themifyme | Themify Builder | CWE-862 | Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber… |
| CVE-2026-44023 | 8.6 | 21.1 | docling-project | docling-core | CWE-22 | Docling Core has unsafe remote filename resolution |
| CVE-2025-45868 | 8.8 | 20.6 | n/a | n/a | CWE-89 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injecti… |
| CVE-2026-44174 | 8.7 | 20.5 | getkirby | kirby | CWE-470 | Kirby: Arbitrary Method Call via REST API search and collection query endpoints |
| CVE-2026-44453 | 7.5 | 20.4 | h2o | h2o | CWE-770 | h2o is vulnerable to musl libc stack overflow |
| CVE-2026-54340 | 7.5 | 20.4 | h2o | h2o | CWE-400 | h2o has HTTP/2 state amplification |
| CVE-2026-44433 | 7.5 | 20.3 | h2o | quicly | CWE-400 | Quicly is vulnerable to memory exhaustion |
| CVE-2026-44435 | 7.5 | 20.3 | h2o | quicly | CWE-400 | Quicly: Remote Denial of Service via assertion failure when CRYPTO stream han… |
| CVE-2026-44436 | 7.5 | 20.3 | h2o | quicly | CWE-120 | Quicly is vulnerable to connection state corruption |
| CVE-2025-71388 | 7.6 | 19.9 | stoatchat | stoatchat | CWE-639 | stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions |
| CVE-2026-15106 | 5.3 | 19.7 | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | CWE-862 | WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Sess… |
| CVE-2026-15445 | 4.9 | 19.6 | cleverplugins | SEO Booster | CWE-89 | SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orde… |
| CVE-2026-15458 | 4.9 | 19.6 | cleverplugins | SEO Booster | CWE-89 | SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort… |
| CVE-2026-35147 | 8.2 | 18.9 | HCL Software | DFXServer | CWE-639 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct… |
| CVE-2026-45325 | 8.2 | 18.9 | tmlmobilidade | go | CWE-1321 | Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath |
| CVE-2026-56455 | 7.5 | 18.9 | HCL Software | DFXAnalytics | CWE-121 | HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead… |
| CVE-2026-46353 | 8.1 | 18.6 | bigbluebutton | bigbluebutton | CWE-284 | BigBlueButton API checksum bypass via presentationUploadExternalUrl |
| CVE-2026-33692 | 7.5 | 18.6 | WWBN | AVideo | CWE-20 | AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Con… |
| CVE-2026-33434 | 7.1 | 18.6 | wazuh | wazuh | CWE-799 | Wazuh: Rate Limit Bypass via /events Endpoint |
| CVE-2026-21729 | 7.5 | 18.2 | Grafana | Loki | CWE-770 | Loki detected_fields query limits results in unbounded memory allocation |
| CVE-2026-46513 | 7.4 | 18.0 | mwtcmi | frogman | CWE-256 | Frogman: API tokens stored in plaintext |
| CVE-2026-46514 | 6.5 | 17.8 | mwtcmi | frogman | CWE-532 | Frogman: Plaintext passwords and secrets persisted to audit log |
| CVE-2024-58360 | 6.9 | 17.7 | stoatchat | stoatchat | CWE-1173 | stoatchat before 0.7.8 Unrestricted Account Creation |
| CVE-2026-46351 | 8.1 | 17.7 | bigbluebutton | bigbluebutton | CWE-330 | BigBlueButton: Insecure Randomness allows to guess user's conference session … |
| CVE-2026-46404 | 6.8 | 17.4 | bigbluebutton | bigbluebutton | CWE-918 | BigBlueButton: Presentation URL Security Hardening |
| CVE-2026-34150 | 7.5 | 17.3 | wazuh | wazuh | CWE-122 | Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing |
| CVE-2026-44175 | 8.5 | 17.1 | getkirby | kirby | CWE-79 | Kirby: Cross-site scripting (XSS) from list field content in the site frontend |
| CVE-2026-63397 | 7.1 | 17.1 | remorses | genql | CWE-116 | remorses/genql code injection |
| CVE-2026-12941 | 6.5 | 17.1 | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions | CWE-89 | MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order… |
| CVE-2026-44452 | 5.9 | 16.6 | h2o | h2o | CWE-125 | h2o is vulnerable to heap overrun |
| CVE-2026-15336 | 4.3 | 16.6 | catchplugins | Catch Themes Demo Import | CWE-862 | Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Sub… |
| CVE-2026-12684 | 6.5 | 16.5 | Unknown | Customer Reviews for WooCommerce | CWE-434 | Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media … |
| CVE-2026-13754 | 6.5 | 16.5 | tickera | Tickera – Sell Tickets & Manage Events | CWE-89 | Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter |
| CVE-2026-13767 | 6.5 | 16.5 | expresstech | Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker | CWE-89 | Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injectio… |
| CVE-2026-35149 | 8.2 | 16.3 | HCL Software | DFXServer | CWE-294 | HCL DFXServer is affected by an Authentication Bypass vulnerability via serve… |
| CVE-2026-13042 | 7.2 | 16.2 | yo35 | RPB Chessboard | CWE-79 | RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Com… |
| CVE-2026-55548 | 4.3 | 16.3 | yamcs | yamcs | CWE-284 | Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivile… |
| CVE-2026-13741 | 8.8 | 16.1 | UnitedOver | Digits: WordPress Mobile Number Signup and Login | CWE-269 | Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (… |
| CVE-2026-63306 | 9.2 | 15.5 | stoatchat | stoatchat | CWE-918 | stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints |
| CVE-2026-56456 | 5.3 | 15.4 | HCL Software | DFXAnalytics | CWE-200 | HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. |
| CVE-2026-14782 | 4.9 | 15.3 | melograno | Booking for Appointments and Events Calendar – Amelia | CWE-89 | Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticate… |
| CVE-2026-12434 | 4.3 | 15.2 | fernandobt | List category posts | CWE-862 | List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contr… |
| CVE-2026-63089 | 9.0 | 15.0 | wg-easy | wg-easy | CWE-338 | WireGuard Easy Weak Token Generation Information Disclosure via OTL Route |
| CVE-2026-58078 | 8.7 | 14.9 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-89 | Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Pag… |
| CVE-2026-54728 | 6.1 | 14.9 | bunkerity | bunkerweb | CWE-20 | bunkerweb: Improper Input Validation and Improper Neutralization of Special E… |
| CVE-2026-44970 | 4.3 | 14.8 | dbt-labs | dbt-mcp | CWE-201 | dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Tran… |
| CVE-2026-44019 | 8.1 | 14.7 | docling-project | docling-core | CWE-73 | Docling Core has insufficient validation of image reference URIs |
| CVE-2026-58643 | 6.1 | 14.6 | Microsoft | Windows Admin Center | CWE-79 | Windows Admin Center Spoofing Vulnerability |
| CVE-2026-43977 | 7.5 | 14.3 | wger-project | wger | CWE-639 | wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data … |
| CVE-2026-15610 | 4.3 | 14.3 | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | CWE-862 | WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitra… |
| CVE-2026-12525 | 8.8 | 14.0 | Unknown | Redux Framework | CWE-269 | Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator |
| CVE-2026-12585 | 8.1 | 13.6 | Unknown | Abandoned Cart Lite for WooCommerce | CWE-287 | Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeove… |
| CVE-2026-13755 | 6.4 | 13.3 | tickera | Tickera – Sell Tickets & Manage Events | CWE-79 | Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-15350 | 4.3 | 13.0 | kevp75 | The Cache Purger | CWE-862 | The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscrib… |
| CVE-2026-12395 | 6.5 | 12.7 | Unknown | WP Job Portal | CWE-89 | WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Pa… |
| CVE-2026-44982 | 7.2 | 12.4 | crowdsecurity | crowdsec | CWE-693 | CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests |
| CVE-2026-15737 | 5.7 | 12.3 | AWS | bedrock-agentcore | CWE-532 | Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK |
| CVE-2026-15306 | 6.1 | 12.2 | rextheme | Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces | CWE-79 | Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scriptin… |
| CVE-2026-44176 | 6.0 | 12.2 | getkirby | kirby | CWE-862 | Kirby: `pages.access` permission is not checked during rendering of page drafts |
| CVE-2026-45334 | 5.3 | 12.2 | getkirby | kirby | CWE-862 | Kirby: Content locks disclose IDs and emails of inaccessible users from `user… |
| CVE-2026-47084 | 6.5 | 12.0 | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCA… |
| CVE-2026-43978 | 8.1 | 11.9 | wger-project | wger | CWE-269 | wger: Privilege escalation via trainer-login session chaining allows gym trai… |
| CVE-2026-15005 | 8.8 | 11.7 | timwhitlock | Loco Translate | CWE-352 | Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution… |
| CVE-2026-15909 | 5.3 | 11.7 | RafyMrX | TOKO-ONLINE-ROTI | CWE-285 | RafyMrX TOKO-ONLINE-ROTI add.php authorization |
| CVE-2023-49899 | 9.8 | 11.5 | X-Rite | MA-T6 | CWE-346 | Origin Validation Error in X-Rite MA-T6 |
| CVE-2024-32389 | 3.5 | 11.3 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.… |
| CVE-2026-15324 | 4.4 | 11.2 | phppoet | SysBasics Customize My Account for WooCommerce – Live My Account Customizer | CWE-79 | SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Sho… |
| CVE-2024-32385 | 4.3 | 11.2 | n/a | n/a | CWE-200 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 … |
| CVE-2026-13005 | 4.4 | 11.1 | mxchat | MxChat – AI Chatbot & Content Generation for WordPress | CWE-79 | MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'in… |
| CVE-2024-34268 | 7.1 | 10.9 | n/a | n/a | CWE-306 | EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the l… |
| CVE-2026-14987 | 6.4 | 10.9 | stellarwp | GiveWP – Donation Plugin and Fundraising Platform | CWE-79 | GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting v… |
| CVE-2026-15021 | 6.4 | 10.9 | tomdever | wpForo Forum | CWE-79 | wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripti… |
| CVE-2024-32387 | 5.7 | 10.5 | n/a | n/a | CWE-200 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 … |
| CVE-2026-47085 | 4.0 | 10.1 | cyrusimap | Cyrus IMAP | CWE-340 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH … |
| CVE-2026-12979 | 5.5 | 9.9 | Unknown | FunnelKit | CWE-73 | FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in T… |
| CVE-2026-15652 | 6.4 | 9.8 | shapedplugin | Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ | CWE-79 | Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-47082 | 5.4 | 9.7 | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vaca… |
| CVE-2026-47083 | 4.3 | 9.4 | cyrusimap | Cyrus IMAP | CWE-204 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is… |
| CVE-2026-15099 | 6.4 | 9.3 | wpdelicious | WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) | CWE-79 | WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scrip… |
| CVE-2026-11889 | 7.1 | 9.2 | SALTO | ProAccess Space | CWE-639 | SALTO ProAccess Space Authorization Bypass Through User-Controlled Key |
| CVE-2026-35141 | 5.3 | 9.2 | HCL Software | DFXAnalytics | CWE-294 | HCL DFXAnalytics is affected by a Login Replay Attack vulnerability |
| CVE-2026-47087 | 3.5 | 9.2 | cyrusimap | Cyrus IMAP | CWE-672 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH … |
| CVE-2026-46341 | 6.1 | 9.1 | apify | apify-mcp-server | CWE-20 | Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Pref… |
| CVE-2026-7543 | 7.2 | 9.0 | Breakdance | Breakdance | CWE-79 | Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook… |
| CVE-2026-58598 | 7.0 | 8.8 | Microsoft | Windows 10 Version 21H2 | CWE-362 | Windows Backup Service Elevation of Privilege Vulnerability |
| CVE-2026-56453 | 9.8 | 8.6 | HCL Software | DFXAnalytics | CWE-294 | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation… |
| CVE-2026-53536 | 5.3 | 8.3 | activepieces | activepieces | CWE-345 | Activepieces: Cross-tenant file download via missing JWT audience check on st… |
| CVE-2026-35142 | 8.2 | 8.2 | HCL Software | DFXAnalytics | CWE-200 | HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. |
| CVE-2026-47086 | 3.5 | 7.7 | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAU… |
| CVE-2026-12906 | 2.7 | 7.7 | Unknown | RTMKit | CWE-639 | RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure |
| CVE-2026-47089 | 4.3 | 7.6 | cyrusimap | Cyrus IMAP | CWE-862 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGH… |
| CVE-2026-47088 | 3.1 | 7.6 | cyrusimap | Cyrus IMAP | CWE-126 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is… |
| CVE-2026-15945 | 2.7 | 7.6 | Red Hat | Red Hat Build of Keycloak | CWE-639 | Keycloak-services: keycloak-services: group hierarchy search discloses hidden… |
| CVE-2026-15925 | 9.2 | 7.5 | Snowflake | Snowflake Connector for Python | CWE-297 | Improper TLS Hostname Verification in Snowflake Connector for Python |
| CVE-2026-49998 | 8.2 | 7.5 | centrifugal | centrifugo | CWE-347 | Centrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JW… |
| CVE-2026-35145 | 3.1 | 7.0 | HCL Software | DFXAnalytics | CWE-200 | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Head… |
| CVE-2026-44968 | 6.3 | 6.9 | dbt-labs | dbt-mcp | CWE-88 | dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and r… |
| CVE-2026-53366 | 7.8 | 6.8 | Linux | Linux | — | ipv4: account for fraggap on the paged allocation path |
| CVE-2026-12907 | 2.7 | 6.6 | Unknown | RTMKit | CWE-862 | RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Templat… |
| CVE-2026-35148 | 6.3 | 6.4 | HCL Software | DFXServer | CWE-284 | HCL DFXServer is affected by a Missing Access Control vulnerability |
| CVE-2026-60073 | 5.2 | 6.4 | AutomationDirect | Productivity Suite | CWE-125 | AutomationDirect Productivity Suite Out-of-bounds Read |
| CVE-2026-12978 | 7.1 | 6.0 | Unknown | FunnelKit | CWE-79 | FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form |
| CVE-2026-47081 | 3.1 | 6.0 | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is… |
| CVE-2026-11371 | 6.1 | 5.9 | Unknown | BetterDocs | CWE-79 | BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt … |
| CVE-2026-35140 | 7.2 | 5.8 | HCL Software | DFXAnalytics | CWE-200 | HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Sessi… |
| CVE-2026-45795 | 5.3 | 5.6 | JanssenProject | jans | CWE-347 | Janssen Project: JWE Request Object Signature Verification Bypass in jans-aut… |
| CVE-2026-12391 | 5.0 | 5.5 | Canonical | ubuntu-pro-client (ubuntu-advantage-tools) | CWE-59 | ubuntu-pro-client Local Privilege Escalation and Information Disclosure via S… |
| CVE-2026-63082 | 5.3 | 5.2 | Ultimate Fosters | Perfect Support Ticketing & Document Management System | CWE-862 | Perfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment |
| CVE-2026-53409 | 7.8 | 4.9 | Zoom Communications | Zoom Rooms | CWE-20 | Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 … |
| CVE-2026-12869 | 6.1 | 4.6 | Unknown | Header Footer Builder for Elementor | CWE-79 | Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Tem… |
| CVE-2026-44969 | 3.3 | 4.5 | dbt-labs | dbt-mcp | CWE-532 | dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plain… |
| CVE-2026-44434 | 5.3 | 4.5 | h2o | quicly | CWE-345 | Quicly is vulnerable to stateless reset injection |
| CVE-2026-6423 | 8.5 | 4.2 | ESET, spol. s.r.o. | ESET Inspect Connector | CWE-269 | Local privilege escalation via unauthenticated ALPC in ESET Inspect Connector |
| CVE-2026-12510 | 5.9 | 4.3 | Unknown | AI Engine | CWE-639 | AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via… |
| CVE-2026-33731 | 6.5 | 4.1 | WWBN | AVideo | CWE-345 | AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Bala… |
| CVE-2026-12379 | 6.8 | 4.0 | Qt | Axivion | CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dash… |
| CVE-2026-57077 | 7.7 | 4.0 | TODDR | YAML::Syck | CWE-125 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an u… |
| CVE-2026-63081 | 5.1 | 3.7 | Ultimate Fosters | Perfect Support Ticketing & Document Management System | CWE-79 | Perfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field |
| CVE-2026-56454 | 7.5 | 3.6 | HCL Software | DFXAnalytics | CWE-327 | HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to th… |
| CVE-2026-13713 | 6.2 | 3.4 | TODDR | YAML::Syck | CWE-415 | YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-fr… |
| CVE-2026-13103 | 7.0 | 3.2 | Lenovo | App Store | CWE-22 | A potential path traversal vulnerability was reported in Lenovo App Store, di… |
| CVE-2026-53411 | 7.0 | 3.2 | Zoom Communications | Zoom Workplace VDI Plugin | CWE-20 | Zoom Workplace VDI Plugin for Windows - Improper Input Validation |
| CVE-2026-12409 | 4.3 | 3.0 | umarbajwa | Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages | CWE-352 | Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_da… |
| CVE-2026-40106 | 7.8 | 2.8 | wazuh | wazuh | CWE-122 | Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LP… |
| CVE-2026-46377 | 6.2 | 2.9 | TomWright | dasel | CWE-129 | Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash… |
| CVE-2026-55406 | 5.9 | 2.9 | anthropics | buffa | CWE-200 | Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in … |
| CVE-2026-5674 | 8.8 | 2.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-427 | Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious… |
| CVE-2026-57076 | 7.8 | 2.6 | TODDR | YAML::Syck | CWE-416 | YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an a… |
| CVE-2026-45612 | 5.5 | 2.3 | rizinorg | rz-libdemangle | CWE-125 | rz-libdemangle: Out of bound read in rust demangler |
| CVE-2026-3842 | 7.8 | 2.3 | — | qemu | CWE-787 | Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memor… |
| CVE-2026-35146 | 6.3 | 1.9 | HCLSoftware | DFXServer | CWE-326 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. |
| CVE-2026-61378 | 6.8 | 1.6 | AutomationDirect | Productivity Suite | CWE-369 | AutomationDirect Productivity Suite Divide By Zero |
| CVE-2026-9494 | 5.5 | 1.7 | Canonical | ubuntu-pro-client (ubuntu-advantage-tools) | CWE-214 | ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure … |
| CVE-2026-13104 | 7.0 | 1.6 | Lenovo | App Store | CWE-250 | A potential vulnerability was reported in Lenovo App Store, distributed exclu… |
| CVE-2026-6424 | 6.7 | 1.6 | ESET, spol. s.r.o. | ESET Endpoint Antivirus for Linux | CWE-416 | Use-after-free vulnerability in ESET security products for Linux |
| CVE-2026-46378 | 6.2 | 1.6 | TomWright | dasel | CWE-835 | Dasel: Denial of service in dasel selector lexer due to infinite loop on unte… |
| CVE-2026-10590 | 6.7 | 1.5 | Lenovo | Yoga Pro 7 15IPH11 BIOS | — | A potential missing authentication vulnerability could allow a local privileg… |
| CVE-2026-10589 | 6.8 | 1.4 | Lenovo | Yoga Pro 7 15IPH11 BIOS | CWE-787 | A potential out of bounds write vulnerability could allow a local privileged … |
| CVE-2026-35143 | 6.5 | 1.4 | HCL Software | DFXAnalytics | CWE-352 | HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. |
| CVE-2026-60063 | 7.3 | 1.3 | AutomationDirect | Productivity Suite | CWE-787 | AutomationDirect Productivity Suite Out-of-bounds Write |
| CVE-2026-61389 | 7.3 | 1.3 | AutomationDirect | Productivity Suite | CWE-787 | AutomationDirect Productivity Suite Out-of-bounds Write |
| CVE-2026-10588 | 6.7 | 1.4 | Lenovo | Yoga Pro 7 15IPH11 BIOS | CWE-497 | A potential vulnerability could allow a local privileged attacker to disclose… |
| CVE-2026-57896 | 6.9 | 1.3 | AutomationDirect | Productivity Suite | CWE-125 | AutomationDirect Productivity Suite Out-of-bounds Read |
| CVE-2026-60140 | 6.9 | 1.3 | AutomationDirect | Productivity Suite | CWE-125 | AutomationDirect Productivity Suite Out-of-bounds Read |
| CVE-2026-62290 | 7.3 | 1.2 | cert-manager | cert-manager | CWE-863 | cert-manager: Direct ACME Challenge resources can bypass Issuer DNS01 solver … |
| CVE-2026-10587 | 6.8 | 1.0 | Lenovo | Yoga Pro 7 15IPH11 BIOS | CWE-787 | A potential out-of-bounds write vulnerability could allow a local privileged … |
| CVE-2026-15997 | 1.7 | 1.0 | Legion of the Bouncy Castle Inc. | BC-LTS | CWE-787 | Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow i… |
| CVE-2026-11866 | 5.4 | 0.8 | Unknown | Appointment Booking Plugin | CWE-352 | LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF |
| CVE-2026-6511 | 6.8 | 0.7 | Lenovo | Smart Connect | CWE-306 | During an internal security assessment, a potential improper access control v… |
| CVE-2026-53410 | 7.0 | 0.7 | Zoom Communications | Zoom Clients | CWE-367 | Zoom Clients for Windows - Race Condition |
| CVE-2026-9046 | 7.3 | 0.4 | Lenovo | Legion Zone | CWE-277 | A potential insecure permissions vulnerability was reported in Legion Zone an… |
| CVE-2026-15449 | 5.8 | 0.3 | illumos | illumos-gate | CWE-122 | TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-16 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.