boxscore/security
Thursday, July 16, 2026 · all times UTC← 2026-07-15 · archive · 2026-07-17 →

248 CVEs published July 16, 2026: 38 critical, 96 high, 101 medium, 12 low; 2 in KEV; 23 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 223 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published43221664012982563
KEV catalog size1670

736 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux41152112186753012730.27.5.0013-56
google941358150612555387460.47.8.0024-536
microsoft64413559193030512378312.37.8.0039+436
red hat562481410511613400.06.7.0026-6
apple0991236629377.16.5.0031-14
canonical42436105000.05.5.0011+4
suse82141241000.08.5.0033+6
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco163961690961230.87.5.0050+12
ubiquiti2536142110438.38.8.0036+20
palo alto networks1425021471428.04.7.0021+5
netgear62300221800.04.6.0022-11
fortinet14223610028522.76.7.0036+12
f58175830715.98.6.0057+8
ivanti211232033545.58.8.3445-2
checkpoint0915303111.17.5.0410-3
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache76229478981114010.47.5.0048+9
mozilla66212183201300.06.5.0025-43
drupal465165355512.05.9.0018+46
gitlab74005276425.04.7.0024-4
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle12711321161844031.18.8.0040-242
adobe932392610110547541.77.5.0021-36
ibm21263842460700.07.5.0025-9
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-3
veeam042200400.09.0.0046-1
zohocorp031110000.08.4.01700
servicenow111000200.09.5.2673+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0025+10
synology02325133000.05.6.0025-5
siemens7161870100.07.6.00190
d-link11405352617.16.0.0058-8
abb060420000.07.2.0018-5
schneider electric060420100.07.8.0024-1
moxa050320000.07.0.0029-5
dahua030111200.06.9.0036-3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester37108005652000.05.5.0026+1
dell3793442433211.16.8.0019+24
capgo2283242381000.07.1.0028+20
openclaw16830482510000.07.2.0021-45
nvidia40791252150000.07.8.0019+34
imagemagick3273155512300.05.3.0017+4
spring073231391000.06.5.0024-71
itsourcecode1265001946000.02.1.0020-10

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
Most disclosures (vendor)
VendorCVEs
microsoft657
google554
linux458
apache130
red hat122
adobe106
capgo81
ibm66
dell62
picklescan50
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco12
apple7
google6
fortinet5
ivanti5
adobe4
solarwinds4
synacor4
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven61
PyPI5
npm5
NuGet3
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2023-4346KNX Association0
CVE-2025-67038Lantronix0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-25089Fortinet0
CVE-2026-34908Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171702
CVE-2021-27102Accellion2021-11-171702
CVE-2021-27101Accellion2021-11-171702
CVE-2021-27103Accellion2021-11-171702
CVE-2021-21017Adobe2021-11-171702
CVE-2021-28550Adobe2021-11-171702
CVE-2021-42013Apache2021-11-171702
CVE-2021-41773Apache2021-11-171702
CVE-2021-30858Apple2021-11-171702
CVE-2021-30860Apple2021-11-171702

Transactions

EXPLOIT PUBLISHEDCVE-2026-33434 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-33754 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-34150 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-39359 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-40106 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44180 (jupyter-server enterprise_gateway). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44181 (jupyter-server enterprise_gateway). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44182 (jupyter-server enterprise_gateway). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44595 (yamcs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44596 (yamcs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44632 (yamcs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44968 (dbt-labs dbt-mcp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44969 (dbt-labs dbt-mcp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44970 (dbt-labs dbt-mcp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46338 (facelessuser pymdown-extensions). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46562 (yamcs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46621 (yamcs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54526 (argoproj argo-workflows). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55548 (yamcs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-62290 (cert-manager). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-62299 (coredns). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-62309 (coredns). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-62994 (coredns). Public exploit reference added.

Yesterday's Results

248 CVEs published. 25 box scores, 223 table rows — nothing truncated.

CVE-2026-39808AWAITING ENRICHMENT
Fortinet FortiSandbox
  CVSS   EPSS    %ile   KEV
  —      .9121   99.8   YES
AFFECTED
  Product       Versions     Fixed
  FortiSandbox  unspecified  —
TIMELINE
  Jul 16  Added to CISA KEV, due Jul 19
  Jul 16  Published
0 references · KEV due July 19, 2026
Fortinet FortiSandbox
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .7360   99.4   YES
AFFECTED
  Product             Versions  Fixed
  FortiSandbox        5.0.0 –   —
  FortiSandbox Cloud  5.0.4 –   —
  FortiSandbox PaaS   5.0.4 –   —
TIMELINE
  Jan 29  Reserved by CNA
  Jul 16  Added to CISA KEV, due Jul 19
  Jul 16  Published (CNA: fortinet)
CWE-78 · CNA: fortinet · 2 references · NVD status: Analyzed · KEV due July 19, 2026
microsoft kiota — Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0319   87.0     —
AFFECTED
  Product  Versions               Fixed
  kiota    >= 1.30.0, < 1.31.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-94, CWE-829 · CNA: GitHub_M · 4 references · NVD status: Deferred
WWBN AVideo — AVideo incomplete fix for CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0216   80.7     —
AFFECTED
  Product  Versions   Fixed
  AVideo   <= 29.0 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 2 references · NVD status: Deferred
microsoft kiota — Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  L  N    7.1   .0192   78.2     —
AFFECTED
  Product  Versions               Fixed
  kiota    >= 1.30.0, < 1.31.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-22, CWE-829, CWE-918 · CNA: GitHub_M · 4 references · NVD status: Deferred
Yamcs: No Rate Limiting on Authentication Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0173   75.6     —
AFFECTED
  Product  Versions    Fixed
  yamcs    < 5.12.7 –  —
TIMELINE
  May 6   Reserved by CNA
  Jul 16  Public exploit reference published
  Jul 16  Published (CNA: GitHub_M)
CWE-307 · CNA: GitHub_M · 5 references · NVD status: Analyzed
squid-cache squid — Squid: Memory disclosure in FTP gateway
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0150   72.2     —
AFFECTED
  Product  Versions  Fixed
  squid    < 7.6 –   —
TIMELINE
  May 19  Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-125, CWE-1289 · CNA: GitHub_M · 5 references · NVD status: Analyzed
microsoft kiota — Kiota: Code Generation Literal Injection in Kiota Ruby Generator
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0147   71.6     —
AFFECTED
  Product  Versions               Fixed
  kiota    >= 1.30.0, < 1.31.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 4 references · NVD status: Deferred
WWBN AVideo — AVideo through 29.0 OS Command Injection via ffmpeg.json.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0138   69.9     —
AFFECTED
  Product  Versions     Fixed
  AVideo   unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Jul 16  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Deferred
squid-cache squid — Squid: Memory corruption in cache_digest reply handling
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  L  H    5.5   .0136   69.5     —
AFFECTED
  Product  Versions  Fixed
  squid    < 7.6 –   —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-20, CWE-122 · CNA: GitHub_M · 4 references · NVD status: Analyzed
microsoft kiota — Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product  Versions               Fixed
  kiota    >= 1.30.0, < 1.31.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-22, CWE-94 · CNA: GitHub_M · 4 references · NVD status: Deferred
WWBN AVideo — AVideo through 29.0 OS Command Injection via listFFmpegProcesses
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0135   69.3     —
AFFECTED
  Product  Versions     Fixed
  AVideo   unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Jul 16  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Deferred
microsoft kiota — Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0127   67.5     —
AFFECTED
  Product  Versions               Fixed
  kiota    >= 1.30.0, < 1.31.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-22, CWE-829 · CNA: GitHub_M · 4 references · NVD status: Deferred
Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0117   64.8     —
AFFECTED
  Product  Versions    Fixed
  yamcs    < 5.12.7 –  —
TIMELINE
  May 7   Reserved by CNA
  Jul 16  Public exploit reference published
  Jul 16  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 5 references · NVD status: Analyzed
microsoft kiota — Kiota: Workspace-config poisoning: out-of-repo file write + generation-time SSRF
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   L   H   L    7.0   .0112   63.5     —
AFFECTED
  Product  Versions               Fixed
  kiota    >= 1.30.0, < 1.31.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 4 references · NVD status: Deferred
microsoft prompty — Prompty: Arbitrary File Read via ${file:path} Reference Expansion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0106   61.7     —
AFFECTED
  Product  Versions          Fixed
  prompty  < 2.0.0-beta.2 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-22, CWE-200 · CNA: GitHub_M · 2 references · NVD status: Deferred
microsoft kiota — Kiota: Code Generation Literal Injection in the Python Generator
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0102   60.5     —
AFFECTED
  Product  Versions               Fixed
  kiota    >= 1.30.0, < 1.31.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 2 references · NVD status: Deferred
microsoft kiota — Kiota: Code Generation Literal Injection in the PHP Generator
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0102   60.4     —
AFFECTED
  Product  Versions               Fixed
  kiota    >= 1.30.0, < 1.31.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 4 references · NVD status: Deferred
microsoft kiota — Kiota: XML Doc-Comment Newline Breakout Code Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0102   60.4     —
AFFECTED
  Product  Versions               Fixed
  kiota    >= 1.30.0, < 1.31.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 4 references · NVD status: Deferred
Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0100   59.9     —
AFFECTED
  Product  Versions    Fixed
  yamcs    < 5.12.7 –  —
TIMELINE
  May 15  Reserved by CNA
  Jul 16  Public exploit reference published
  Jul 16  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 5 references · NVD status: Analyzed
Yamcs: Unauthorized user enumeration via IAM API endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  N    4.3   .0098   59.4     —
AFFECTED
  Product  Versions    Fixed
  yamcs    < 5.12.7 –  —
TIMELINE
  May 6   Reserved by CNA
  Jul 16  Public exploit reference published
  Jul 16  Published (CNA: GitHub_M)
CWE-862 · CNA: GitHub_M · 5 references · NVD status: Modified
microsoft prompty — Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0093   57.7     —
AFFECTED
  Product  Versions                            Fixed
  prompty  >= 2.0.0-alpha.1, < 2.0.0-beta.3 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 2 references · NVD status: Deferred
microsoft o365-moodle — moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0092   57.2     —
AFFECTED
  Product      Versions   Fixed
  o365-moodle  < 4.5.6 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-347 · CNA: GitHub_M · 7 references · NVD status: Awaiting Analysis
SGLang SGLang — CVE-2026-14890
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0091   57.0     —
AFFECTED
  Product  Versions     Fixed
  SGLang   unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 16  Published (CNA: certcc)
CWE-502 · CNA: certcc · 3 references · NVD status: Analyzed
microsoft simplechat — SimpleChat plugin validation endpoints missing authentication and authorization
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  H  L    8.6   .0089   56.4     —
AFFECTED
  Product     Versions       Fixed
  simplechat  < 0.241.206 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 16  Published (CNA: GitHub_M)
CWE-306, CWE-862 · CNA: GitHub_M · 3 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-465629.852.9yamcsyamcsCWE-94Yamcs: Remote Code Execution via Mission Database algorithm override
CVE-2026-143718.852.2LenovoXClarity Integrator for Microsoft Windows Admin CenterCWE-78The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 …
CVE-2026-235387.551.9FeastFeast Feature ServerCWE-770Feast: resource exhaustion via websocket endpoint
CVE-2026-4418110.050.2jupyter-serverenterprise_gatewayCWE-1336Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection re…
CVE-2026-554406.548.6microsoftUFOCWE-400Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing aut…
CVE-2026-534129.848.1Zoom CommunicationsZoom Workplace for WindowsCWE-20Zoom Workplace VDI Plugin for Windows - Improper Input Validation
CVE-2026-150088.145.6uncannyowlUncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder PluginCWE-502Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitr…
CVE-2026-535355.944.7activepiecesactivepiecesCWE-22Activepieces: Arbitrary file write in git-sync via path traversal and symlinks
CVE-2026-477515.344.0anthropicsclaude-code-actionCWE-78Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote …
CVE-2026-441809.843.6jupyter-serverenterprise_gatewayCWE-20Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can…
CVE-2023-499009.842.7X-RiteMA-T6CWE-78Origin Validation Error in X-Rite MA-T6
CVE-2026-545684.342.7microsoftUFOCWE-639Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE C…
CVE-2024-323867.341.9n/an/aCWE-22Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerO…
CVE-2026-154229.141.0illumosillumos-gateCWE-122SCTP needs to better-check INIT ACK chunk parameters
CVE-2026-572054.340.6microsoftsimplechatCWE-200SimpleChat: Authenticated users can access other users' profile metadata thro…
CVE-2026-4418210.040.5jupyter-serverenterprise_gatewayCWE-74Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Templ…
CVE-2026-16098.140.5KeycloakKeycloakCWE-284Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt a…
CVE-2026-453677.539.9hapifhirorg.hl7.fhir.coreCWE-1333HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HT…
CVE-2026-337546.539.6wazuhwazuhCWE-400Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory all…
CVE-2026-488637.538.6OpenSUSElibsolvCWE-121Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verificat…
CVE-2026-556298.737.8avwowhistleCWE-22Whistle: Path traversal
CVE-2026-441778.837.7getkirbykirbyCWE-22Kirby: Pre-authentication path traversal and PHP file inclusion during user l…
CVE-2026-150139.837.3cyberlord92SAML Single Sign On – SSO LoginCWE-347SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAM…
CVE-2026-227529.637.0Spring SecuritySpring Authorization ServerCWE-287Spring Security Authorization Server Dynamic Client Registration endpoints pe…
CVE-2026-591177.536.8MicrosoftWindows Terminal AppCWE-190Windows Terminal Remote Code Execution Vulnerability
CVE-2026-153528.235.8NASACore Flight System (cFS) Health & Safety (HS) ApplicationCWE-476NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer D…
CVE-2026-4533610.035.7StratonWebDesignersHireFlowCWE-798HireFlow: Use of Hard-coded Credentials
CVE-2026-630879.335.6grafana-cold-storageoncallCWE-306Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint
CVE-2026-554076.335.3anthropicsbuffaCWE-400Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unboun…
CVE-2026-570739.135.2CODECHILDHTML::BareCWE-125HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead
CVE-2026-364256.535.2n/an/aCWE-269An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier…
CVE-2026-570749.133.5CODECHILDXML::BareCWE-125XML::Bare versions through 0.53 for Perl have an unbounded character lookahead
CVE-2026-30319.833.4TOKUHIROMImage::EPEGCWE-1104Image::EPEG versions through 0.15 for Perl embeds an unsupported version of t…
CVE-2026-133977.532.5CODECHILDHTML::BareCWE-835HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when …
CVE-2026-134017.532.0CODECHILDXML::BareCWE-835XML::Bare versions through 0.53 for Perl will hang in an infinite loop when p…
CVE-2025-713778.731.5stoatchatstoatchatCWE-1025stoatchat before 20250210-1 Unrestricted Message History Fetch
CVE-2026-623097.530.8corednscorednsCWE-476CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — s…
CVE-2026-570759.130.5TODDRYAML::SyckCWE-125YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a si…
CVE-2026-630858.730.2axeloraxelor-open-platformCWE-863Axelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational R…
CVE-2026-630887.730.2stoatchatstoatchatCWE-918stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass
CVE-2026-592376.929.9RoskusProspero Flow CRMCWE-639IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification…
CVE-2026-545268.929.4argoprojargo-workflowsCWE-284Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch by…
CVE-2025-458706.529.3n/an/aCWE-22LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclus…
CVE-2026-455689.929.1openzitizrokCWE-22zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
CVE-2026-157274.928.6xylusWP Bulk DeleteCWE-89WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'd…
CVE-2026-465129.928.2mwtcmifrogmanCWE-94Frogman: Dialplan template parameters interpolated into extensions_custom.con…
CVE-2026-456959.827.8kopiakopiaCWE-78Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --w…
CVE-2026-381589.827.8n/an/aCWE-89A SQL injection vulnerability in the /ureport/datasource/previewData componen…
CVE-2026-113869.027.2Canonicalubuntu-pro-client (ubuntu-advantage-tools)CWE-20ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Dir…
CVE-2026-455768.327.1openzitizrokCWE-22zrok copy writes attacker-controlled WebDAV paths outside the destination root
CVE-2026-150226.527.1themeumTutor LMS – eLearning and online course solutionCWE-89Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Qui…
CVE-2026-453688.426.3getkirbykirbyCWE-79Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in…
CVE-2026-463367.126.1manyfold3dmanyfoldCWE-22Manyfold: Authenticated Path Traversal via File Rename
CVE-2026-628265.426.0MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-142548.325.8PerforceDelphix Continuous DataCWE-307Improper Restriction of Excessive Authentication Attempts in Delphix Continuo…
CVE-2026-465159.325.1mwtcmifrogmanCWE-862Frogman: Multiple read-tier tools expose admin-grade data and arbitrary Graph…
CVE-2026-466868.525.1emlogemlogCWE-79Emlog Reflected Cross-Site Scripting
CVE-2026-630866.925.1huggingfacetext-generation-inferenceCWE-918text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat compl…
CVE-2026-622995.323.8corednscorednsCWE-476CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) …
CVE-2026-151038.823.6getwpfunnelsWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click UpsellCWE-269WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation vi…
CVE-2026-463384.323.6facelessuserpymdown-extensionsCWE-22PyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-pref…
CVE-2026-617185.423.2bunkeritybunkerwebCWE-285bunkerweb: Read-only Web UI users can delete job cache files due to missing a…
CVE-2026-127537.523.0themehunkAdvance Product Search- Voice & Ajax Search for WooCommerceCWE-89Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauth…
CVE-2026-629638.722.7centrifugalcentrifugoCWE-409Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional W…
CVE-2026-592496.322.7elixir-mintmintCWE-444Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling aga…
CVE-2026-124929.822.5UnknownHappy Coders OTP Login for WooCommerceCWE-287Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeov…
CVE-2026-629943.722.0corednscorednsCWE-248CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that pa…
CVE-2026-449818.221.7crowdsecuritycrowdsecCWE-409CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
CVE-2026-466877.721.7emlogemlogCWE-24Emlog Local File Inclusion (LFI)
CVE-2026-393597.521.4wazuhwazuhCWE-22Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name
CVE-2026-156514.921.3jgwhite33WP TripAdvisor Review SliderCWE-89WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Inj…
CVE-2026-154074.321.3themifymeThemify BuilderCWE-862Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber…
CVE-2026-440238.621.1docling-projectdocling-coreCWE-22Docling Core has unsafe remote filename resolution
CVE-2025-458688.820.6n/an/aCWE-89LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injecti…
CVE-2026-441748.720.5getkirbykirbyCWE-470Kirby: Arbitrary Method Call via REST API search and collection query endpoints
CVE-2026-444537.520.4h2oh2oCWE-770h2o is vulnerable to musl libc stack overflow
CVE-2026-543407.520.4h2oh2oCWE-400h2o has HTTP/2 state amplification
CVE-2026-444337.520.3h2oquiclyCWE-400Quicly is vulnerable to memory exhaustion
CVE-2026-444357.520.3h2oquiclyCWE-400Quicly: Remote Denial of Service via assertion failure when CRYPTO stream han…
CVE-2026-444367.520.3h2oquiclyCWE-120Quicly is vulnerable to connection state corruption
CVE-2025-713887.619.9stoatchatstoatchatCWE-639stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions
CVE-2026-151065.319.7quantumcloudWPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-862WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Sess…
CVE-2026-154454.919.6cleverpluginsSEO BoosterCWE-89SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orde…
CVE-2026-154584.919.6cleverpluginsSEO BoosterCWE-89SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort…
CVE-2026-351478.218.9HCL SoftwareDFXServerCWE-639HCL DFXServer is affected by a Broken Authentication vulnerability via direct…
CVE-2026-453258.218.9tmlmobilidadegoCWE-1321Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath
CVE-2026-564557.518.9HCL SoftwareDFXAnalyticsCWE-121HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead…
CVE-2026-463538.118.6bigbluebuttonbigbluebuttonCWE-284BigBlueButton API checksum bypass via presentationUploadExternalUrl
CVE-2026-336927.518.6WWBNAVideoCWE-20AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Con…
CVE-2026-334347.118.6wazuhwazuhCWE-799Wazuh: Rate Limit Bypass via /events Endpoint
CVE-2026-217297.518.2GrafanaLokiCWE-770Loki detected_fields query limits results in unbounded memory allocation
CVE-2026-465137.418.0mwtcmifrogmanCWE-256Frogman: API tokens stored in plaintext
CVE-2026-465146.517.8mwtcmifrogmanCWE-532Frogman: Plaintext passwords and secrets persisted to audit log
CVE-2024-583606.917.7stoatchatstoatchatCWE-1173stoatchat before 0.7.8 Unrestricted Account Creation
CVE-2026-463518.117.7bigbluebuttonbigbluebuttonCWE-330BigBlueButton: Insecure Randomness allows to guess user's conference session …
CVE-2026-464046.817.4bigbluebuttonbigbluebuttonCWE-918BigBlueButton: Presentation URL Security Hardening
CVE-2026-341507.517.3wazuhwazuhCWE-122Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing
CVE-2026-441758.517.1getkirbykirbyCWE-79Kirby: Cross-site scripting (XSS) from list field content in the site frontend
CVE-2026-633977.117.1remorsesgenqlCWE-116remorses/genql code injection
CVE-2026-129416.517.1wcmpMultiVendorX – WooCommerce Multivendor Marketplace AI Powered SolutionsCWE-89MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order…
CVE-2026-444525.916.6h2oh2oCWE-125h2o is vulnerable to heap overrun
CVE-2026-153364.316.6catchpluginsCatch Themes Demo ImportCWE-862Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Sub…
CVE-2026-126846.516.5UnknownCustomer Reviews for WooCommerceCWE-434Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media …
CVE-2026-137546.516.5tickeraTickera – Sell Tickets & Manage EventsCWE-89Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter
CVE-2026-137676.516.5expresstechQuiz and Survey Master (QSM) – Quiz Maker & Survey MakerCWE-89Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injectio…
CVE-2026-351498.216.3HCL SoftwareDFXServerCWE-294HCL DFXServer is affected by an Authentication Bypass vulnerability via serve…
CVE-2026-130427.216.2yo35RPB ChessboardCWE-79RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Com…
CVE-2026-555484.316.3yamcsyamcsCWE-284Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivile…
CVE-2026-137418.816.1UnitedOverDigits: WordPress Mobile Number Signup and LoginCWE-269Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (…
CVE-2026-633069.215.5stoatchatstoatchatCWE-918stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints
CVE-2026-564565.315.4HCL SoftwareDFXAnalyticsCWE-200HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability.
CVE-2026-147824.915.3melogranoBooking for Appointments and Events Calendar – AmeliaCWE-89Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticate…
CVE-2026-124344.315.2fernandobtList category postsCWE-862List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contr…
CVE-2026-630899.015.0wg-easywg-easyCWE-338WireGuard Easy Weak Token Generation Information Disclosure via OTL Route
CVE-2026-580788.714.9themexpert.comQuix Page Builder Pro extension for JoomlaCWE-89Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Pag…
CVE-2026-547286.114.9bunkeritybunkerwebCWE-20bunkerweb: Improper Input Validation and Improper Neutralization of Special E…
CVE-2026-449704.314.8dbt-labsdbt-mcpCWE-201dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Tran…
CVE-2026-440198.114.7docling-projectdocling-coreCWE-73Docling Core has insufficient validation of image reference URIs
CVE-2026-586436.114.6MicrosoftWindows Admin CenterCWE-79Windows Admin Center Spoofing Vulnerability
CVE-2026-439777.514.3wger-projectwgerCWE-639wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data …
CVE-2026-156104.314.3quantumcloudWPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-862WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitra…
CVE-2026-125258.814.0UnknownRedux FrameworkCWE-269Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
CVE-2026-125858.113.6UnknownAbandoned Cart Lite for WooCommerceCWE-287Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeove…
CVE-2026-137556.413.3tickeraTickera – Sell Tickets & Manage EventsCWE-79Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-153504.313.0kevp75The Cache PurgerCWE-862The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscrib…
CVE-2026-123956.512.7UnknownWP Job PortalCWE-89WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Pa…
CVE-2026-449827.212.4crowdsecuritycrowdsecCWE-693CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests
CVE-2026-157375.712.3AWSbedrock-agentcoreCWE-532Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
CVE-2026-153066.112.2rexthemeProduct Feed Manager For WooCommerce – Sell on 200+ Online MarketplacesCWE-79Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scriptin…
CVE-2026-441766.012.2getkirbykirbyCWE-862Kirby: `pages.access` permission is not checked during rendering of page drafts
CVE-2026-453345.312.2getkirbykirbyCWE-862Kirby: Content locks disclose IDs and emails of inaccessible users from `user…
CVE-2026-470846.512.0cyrusimapCyrus IMAPCWE-863An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCA…
CVE-2026-439788.111.9wger-projectwgerCWE-269wger: Privilege escalation via trainer-login session chaining allows gym trai…
CVE-2026-150058.811.7timwhitlockLoco TranslateCWE-352Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution…
CVE-2026-159095.311.7RafyMrXTOKO-ONLINE-ROTICWE-285RafyMrX TOKO-ONLINE-ROTI add.php authorization
CVE-2023-498999.811.5X-RiteMA-T6CWE-346Origin Validation Error in X-Rite MA-T6
CVE-2024-323893.511.3n/an/aCWE-120Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.…
CVE-2026-153244.411.2phppoetSysBasics Customize My Account for WooCommerce – Live My Account CustomizerCWE-79SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Sho…
CVE-2024-323854.311.2n/an/aCWE-200An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 …
CVE-2026-130054.411.1mxchatMxChat – AI Chatbot & Content Generation for WordPressCWE-79MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'in…
CVE-2024-342687.110.9n/an/aCWE-306EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the l…
CVE-2026-149876.410.9stellarwpGiveWP – Donation Plugin and Fundraising PlatformCWE-79GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting v…
CVE-2026-150216.410.9tomdeverwpForo ForumCWE-79wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripti…
CVE-2024-323875.710.5n/an/aCWE-200An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 …
CVE-2026-470854.010.1cyrusimapCyrus IMAPCWE-340An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH …
CVE-2026-129795.59.9UnknownFunnelKitCWE-73FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in T…
CVE-2026-156526.49.8shapedpluginEasy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQCWE-79Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-470825.49.7cyrusimapCyrus IMAPCWE-863An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vaca…
CVE-2026-470834.39.4cyrusimapCyrus IMAPCWE-204An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is…
CVE-2026-150996.49.3wpdeliciousWP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)CWE-79WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scrip…
CVE-2026-118897.19.2SALTOProAccess SpaceCWE-639SALTO ProAccess Space Authorization Bypass Through User-Controlled Key
CVE-2026-351415.39.2HCL SoftwareDFXAnalyticsCWE-294HCL DFXAnalytics is affected by a Login Replay Attack vulnerability
CVE-2026-470873.59.2cyrusimapCyrus IMAPCWE-672An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH …
CVE-2026-463416.19.1apifyapify-mcp-serverCWE-20Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Pref…
CVE-2026-75437.29.0BreakdanceBreakdanceCWE-79Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook…
CVE-2026-585987.08.8MicrosoftWindows 10 Version 21H2CWE-362Windows Backup Service Elevation of Privilege Vulnerability
CVE-2026-564539.88.6HCL SoftwareDFXAnalyticsCWE-294HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation…
CVE-2026-535365.38.3activepiecesactivepiecesCWE-345Activepieces: Cross-tenant file download via missing JWT audience check on st…
CVE-2026-351428.28.2HCL SoftwareDFXAnalyticsCWE-200HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.
CVE-2026-470863.57.7cyrusimapCyrus IMAPCWE-863An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAU…
CVE-2026-129062.77.7UnknownRTMKitCWE-639RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure
CVE-2026-470894.37.6cyrusimapCyrus IMAPCWE-862An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGH…
CVE-2026-470883.17.6cyrusimapCyrus IMAPCWE-126An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is…
CVE-2026-159452.77.6Red HatRed Hat Build of KeycloakCWE-639Keycloak-services: keycloak-services: group hierarchy search discloses hidden…
CVE-2026-159259.27.5SnowflakeSnowflake Connector for PythonCWE-297Improper TLS Hostname Verification in Snowflake Connector for Python
CVE-2026-499988.27.5centrifugalcentrifugoCWE-347Centrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JW…
CVE-2026-351453.17.0HCL SoftwareDFXAnalyticsCWE-200HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Head…
CVE-2026-449686.36.9dbt-labsdbt-mcpCWE-88dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and r…
CVE-2026-533667.86.8LinuxLinuxipv4: account for fraggap on the paged allocation path
CVE-2026-129072.76.6UnknownRTMKitCWE-862RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Templat…
CVE-2026-351486.36.4HCL SoftwareDFXServerCWE-284HCL DFXServer is affected by a Missing Access Control vulnerability
CVE-2026-600735.26.4AutomationDirectProductivity SuiteCWE-125AutomationDirect Productivity Suite Out-of-bounds Read
CVE-2026-129787.16.0UnknownFunnelKitCWE-79FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form
CVE-2026-470813.16.0cyrusimapCyrus IMAPCWE-863An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is…
CVE-2026-113716.15.9UnknownBetterDocsCWE-79BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt …
CVE-2026-351407.25.8HCL SoftwareDFXAnalyticsCWE-200HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Sessi…
CVE-2026-457955.35.6JanssenProjectjansCWE-347Janssen Project: JWE Request Object Signature Verification Bypass in jans-aut…
CVE-2026-123915.05.5Canonicalubuntu-pro-client (ubuntu-advantage-tools)CWE-59ubuntu-pro-client Local Privilege Escalation and Information Disclosure via S…
CVE-2026-630825.35.2Ultimate FostersPerfect Support Ticketing & Document Management SystemCWE-862Perfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment
CVE-2026-534097.84.9Zoom CommunicationsZoom RoomsCWE-20Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 …
CVE-2026-128696.14.6UnknownHeader Footer Builder for ElementorCWE-79Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Tem…
CVE-2026-449693.34.5dbt-labsdbt-mcpCWE-532dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plain…
CVE-2026-444345.34.5h2oquiclyCWE-345Quicly is vulnerable to stateless reset injection
CVE-2026-64238.54.2ESET, spol. s.r.o.ESET Inspect ConnectorCWE-269Local privilege escalation via unauthenticated ALPC in ESET Inspect Connector
CVE-2026-125105.94.3UnknownAI EngineCWE-639AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via…
CVE-2026-337316.54.1WWBNAVideoCWE-345AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Bala…
CVE-2026-123796.84.0QtAxivionCWE-601URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dash…
CVE-2026-570777.74.0TODDRYAML::SyckCWE-125YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an u…
CVE-2026-630815.13.7Ultimate FostersPerfect Support Ticketing & Document Management SystemCWE-79Perfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field
CVE-2026-564547.53.6HCL SoftwareDFXAnalyticsCWE-327HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to th…
CVE-2026-137136.23.4TODDRYAML::SyckCWE-415YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-fr…
CVE-2026-131037.03.2LenovoApp StoreCWE-22A potential path traversal vulnerability was reported in Lenovo App Store, di…
CVE-2026-534117.03.2Zoom CommunicationsZoom Workplace VDI PluginCWE-20Zoom Workplace VDI Plugin for Windows - Improper Input Validation
CVE-2026-124094.33.0umarbajwaLanding Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing PagesCWE-352Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_da…
CVE-2026-401067.82.8wazuhwazuhCWE-122Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LP…
CVE-2026-463776.22.9TomWrightdaselCWE-129Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash…
CVE-2026-554065.92.9anthropicsbuffaCWE-200Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in …
CVE-2026-56748.82.8Red HatRed Hat Enterprise Linux 10CWE-427Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious…
CVE-2026-570767.82.6TODDRYAML::SyckCWE-416YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an a…
CVE-2026-456125.52.3rizinorgrz-libdemangleCWE-125rz-libdemangle: Out of bound read in rust demangler
CVE-2026-38427.82.3qemuCWE-787Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memor…
CVE-2026-351466.31.9HCLSoftwareDFXServerCWE-326HCL DFXServer is affected by an Unencrypted Communication vulnerability.
CVE-2026-613786.81.6AutomationDirectProductivity SuiteCWE-369AutomationDirect Productivity Suite Divide By Zero
CVE-2026-94945.51.7Canonicalubuntu-pro-client (ubuntu-advantage-tools)CWE-214ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure …
CVE-2026-131047.01.6LenovoApp StoreCWE-250A potential vulnerability was reported in Lenovo App Store, distributed exclu…
CVE-2026-64246.71.6ESET, spol. s.r.o.ESET Endpoint Antivirus for LinuxCWE-416Use-after-free vulnerability in ESET security products for Linux
CVE-2026-463786.21.6TomWrightdaselCWE-835Dasel: Denial of service in dasel selector lexer due to infinite loop on unte…
CVE-2026-105906.71.5LenovoYoga Pro 7 15IPH11 BIOSA potential missing authentication vulnerability could allow a local privileg…
CVE-2026-105896.81.4LenovoYoga Pro 7 15IPH11 BIOSCWE-787A potential out of bounds write vulnerability could allow a local privileged …
CVE-2026-351436.51.4HCL SoftwareDFXAnalyticsCWE-352HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.
CVE-2026-600637.31.3AutomationDirectProductivity SuiteCWE-787AutomationDirect Productivity Suite Out-of-bounds Write
CVE-2026-613897.31.3AutomationDirectProductivity SuiteCWE-787AutomationDirect Productivity Suite Out-of-bounds Write
CVE-2026-105886.71.4LenovoYoga Pro 7 15IPH11 BIOSCWE-497A potential vulnerability could allow a local privileged attacker to disclose…
CVE-2026-578966.91.3AutomationDirectProductivity SuiteCWE-125AutomationDirect Productivity Suite Out-of-bounds Read
CVE-2026-601406.91.3AutomationDirectProductivity SuiteCWE-125AutomationDirect Productivity Suite Out-of-bounds Read
CVE-2026-622907.31.2cert-managercert-managerCWE-863cert-manager: Direct ACME Challenge resources can bypass Issuer DNS01 solver …
CVE-2026-105876.81.0LenovoYoga Pro 7 15IPH11 BIOSCWE-787A potential out-of-bounds write vulnerability could allow a local privileged …
CVE-2026-159971.71.0Legion of the Bouncy Castle Inc.BC-LTSCWE-787Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow i…
CVE-2026-118665.40.8UnknownAppointment Booking PluginCWE-352LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF
CVE-2026-65116.80.7LenovoSmart ConnectCWE-306During an internal security assessment, a potential improper access control v…
CVE-2026-534107.00.7Zoom CommunicationsZoom ClientsCWE-367Zoom Clients for Windows - Race Condition
CVE-2026-90467.30.4LenovoLegion ZoneCWE-277A potential insecure permissions vulnerability was reported in Legion Zone an…
CVE-2026-154495.80.3illumosillumos-gateCWE-122TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-16 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.