boxscore/security
Friday, July 17, 2026 · all times UTC← 2026-07-16 · archive · 2026-07-18 →

288 CVEs published July 17, 2026: 38 critical, 99 high, 131 medium, 20 low; 1 in KEV; 17 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 263 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published46101692812982563
KEV catalog size1670

757 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux41152112186753012730.27.5.0013-56
google941358150612555387460.47.8.0024-586
microsoft64613579193130612378312.37.8.0039+438
red hat652571410612413400.06.5.00260
apple0991236629377.16.5.0031-14
canonical42436105000.05.5.0011+4
suse82141241000.08.5.0033+6
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco163961690961230.87.5.0050+7
ubiquiti2536142110438.38.8.0036+20
palo alto networks1425021471428.04.7.0021+5
netgear62300221800.04.6.0022-11
fortinet14223610028522.76.7.0036+12
f58175830715.98.6.0057+2
ivanti211232033545.58.8.3445-2
checkpoint0915303111.17.5.0410-3
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache77230478982114010.47.5.0048+3
mozilla66212183201300.06.5.0025-43
drupal465165355512.05.9.0018+46
gitlab74005276425.04.7.0024-4
github5111280000.06.0.0026+5
docker070520100.08.2.0016-2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle12711321161844031.18.8.0040-242
adobe942402610210547541.77.5.0021-35
ibm361605254540700.07.5.0026+25
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-3
veeam042200400.09.0.0046-1
zohocorp031110000.08.4.01700
servicenow111000200.09.5.2673+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0025+10
synology02325133000.05.6.0025-5
siemens7161870100.07.6.00190
d-link11405352617.16.0.0058-8
abb170430000.07.2.0018-4
schneider electric060420100.07.8.0024-1
moxa050320000.07.0.0029-5
dahua030111200.06.9.0036-3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
openclaw441110583914000.07.0.0022-17
sourcecodester37108005652000.05.5.00260
dell3793442433211.16.8.0019+11
capgo2283242381000.07.1.0028+20
nvidia40791252150000.07.8.0019+34
imagemagick3273155512300.05.3.0017+4
spring073231391000.06.5.0024-71
itsourcecode1366001947000.02.1.0020-9

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
Most disclosures (vendor)
VendorCVEs
microsoft659
google504
linux458
red hat128
apache124
adobe107
ibm100
capgo81
dell49
sourcecodester49
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco12
apple7
google6
fortinet5
ivanti5
adobe4
solarwinds4
synacor4
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven56
PyPI5
npm5
NuGet3
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2023-4346KNX Association0
CVE-2025-67038Lantronix0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-25089Fortinet0
CVE-2026-34908Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171703
CVE-2021-27102Accellion2021-11-171703
CVE-2021-27101Accellion2021-11-171703
CVE-2021-27103Accellion2021-11-171703
CVE-2021-21017Adobe2021-11-171703
CVE-2021-28550Adobe2021-11-171703
CVE-2021-42013Apache2021-11-171703
CVE-2021-41773Apache2021-11-171703
CVE-2021-30858Apple2021-11-171703
CVE-2021-30860Apple2021-11-171703

Transactions

EXPLOIT PUBLISHEDCVE-2025-60357. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16014 (code-projects Hospital Bed Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16073 (AstrBotDevs AstrBot). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16074 (AstrBotDevs AstrBot). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44251 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44891 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45309 (ronf asyncssh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45799 (square wire). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50185 (RustCrypto utils). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50289 (sebhildebrandt systeminformation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53727 (premailer css_parser). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54497 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54498 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56740 (jline3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56741 (jline3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-62238 (openremote). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-62241 (MohibShaikh clawvet). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63094 (signoz). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63100 (maybe-finance maybe). Public exploit reference added.

DUE DATE PASSEDCVE-2008-4128 (Cisco IOS). CISA remediation deadline was July 16, 2026; still in catalog.

Yesterday's Results

288 CVEs published. 25 box scores, 263 table rows — nothing truncated.

IBM Langflow OSS — Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1735   96.9   YES
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 21  Reserved by CNA
  Jul 17  Published (CNA: ibm)
  Aug 4   Added to CISA KEV, due Aug 7
CWE-94 · CNA: ibm · 2 references · NVD status: Analyzed · KEV due August 7, 2026
MohibShaikh clawvet — clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0655   93.2     —
AFFECTED
  Product  Versions     Fixed
  clawvet  unspecified  0.7.5
TIMELINE
  Jul 13  Reserved by CNA
  Jul 17  Public exploit reference published
  Jul 17  Published (CNA: VulnCheck)
CWE-306, CWE-321 · CNA: VulnCheck · 2 references · NVD status: Analyzed
sebhildebrandt systeminformation — systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0187   77.6     —
AFFECTED
  Product            Versions    Fixed
  systeminformation  < 5.31.7 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jul 17  Public exploit reference published
  Jul 17  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 3 references · NVD status: Analyzed
n/a n/a — django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0123   66.4     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 24  Reserved by CNA
  Jul 17  Published (CNA: mitre)
CWE-78 · CNA: mitre · 3 references · NVD status: Deferred
shivammathur setup-php — setup-php: Command Injection in Repository-Derived PHP Version Resolution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0115   64.2     —
AFFECTED
  Product    Versions               Fixed
  setup-php  >= 2.25.0, < 2.37.1 –  —
TIMELINE
  May 13  Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 3 references · NVD status: Analyzed
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0077   52.5     —
AFFECTED
  Product                                                      Versions     Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 17  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 10 references · NVD status: Deferred
n/a n/a — An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0060   45.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 17  Published (CNA: mitre)
CWE-77, CWE-94 · CNA: mitre · 1 reference · NVD status: Deferred
properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0057   44.7     —
AFFECTED
  Product                                                                                                                Versions     Fixed
  Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 17  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 8 references · NVD status: Deferred
Pimcore: Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  H  H  H    8.0   .0057   44.7     —
AFFECTED
  Product  Versions     Fixed
  pimcore  < 11.5.17 –  —
TIMELINE
  May 8   Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · 4 references · NVD status: Deferred
n/a n/a — An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 a…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0056   44.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 17  Published (CNA: mitre)
CWE-434 · CNA: mitre · 2 references · NVD status: Deferred
IBM Langflow OSS — Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0056   44.0     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 13  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-306 · CNA: ibm · 1 reference · NVD status: Modified
Anysphere, Inc. Cursor — Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0056   43.8     —
AFFECTED
  Product  Versions  Fixed
  Cursor   3.2.16 –  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 17  Published (CNA: VulnCheck)
CWE-426 · CNA: VulnCheck · 3 references · NVD status: Analyzed
square wire — Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0055   43.2     —
AFFECTED
  Product  Versions   Fixed
  wire     < 6.3.0 –  —
TIMELINE
  May 13  Reserved by CNA
  Jul 17  Public exploit reference published
  Jul 17  Published (CNA: GitHub_M)
CWE-129 · CNA: GitHub_M · 7 references · NVD status: Analyzed
JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0052   41.5     —
AFFECTED
  Product  Versions     Fixed
  jline3   < 3.30.14 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 17  Public exploit reference published
  Jul 17  Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · 7 references · NVD status: Analyzed
thimpress WP Hotel Booking — WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0051   41.3     —
AFFECTED
  Product           Versions     Fixed
  WP Hotel Booking  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 17  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 6 references · NVD status: Deferred
JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0050   40.8     —
AFFECTED
  Product  Versions     Fixed
  jline3   < 3.30.14 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 17  Public exploit reference published
  Jul 17  Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · 9 references · NVD status: Analyzed
IBM Langflow OSS — Disk Cache Deserialization Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0049   40.2     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 13  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-502 · CNA: ibm · 1 reference · NVD status: Analyzed
IBM Langflow OSS — Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0049   39.9     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 20  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-94 · CNA: ibm · 1 reference · NVD status: Analyzed
Datadog .NET Tracer: Improper parsing of W3C baggage headers may lead to DoS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0048   39.5     —
AFFECTED
  Product          Versions    Fixed
  dd-trace-dotnet  < 3.43.0 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jul 17  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · 4 references · NVD status: Awaiting Analysis
Microsoft Remote Desktop Web Client — Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0048   39.3     —
AFFECTED
  Product                    Versions   Fixed
  Remote Desktop Web Client  2.0.0.0 –  —
  Windows Admin Center       1809.0 –   —
TIMELINE
  Jun 19  Reserved by CNA
  Jul 17  Published (CNA: microsoft)
CWE-359 · CNA: microsoft · 1 reference · NVD status: Analyzed
Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   A   N   N   H    5.7   .0047   38.7     —
AFFECTED
  Product          Versions  Fixed
  Apache Accumulo  2.1.4 –   —
TIMELINE
  Jul 14  Reserved by CNA
  Jul 17  Published (CNA: apache)
CWE-274 · CNA: apache · 5 references · NVD status: Analyzed
IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0047   38.7     —
AFFECTED
  Product                 Versions   Fixed
  Storage Protect Client  8.1.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-122 · CNA: ibm · 1 reference · NVD status: Analyzed
SaturdayDrive Ninja Forms - Excel Export — Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0046   38.0     —
AFFECTED
  Product                     Versions     Fixed
  Ninja Forms - Excel Export  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 17  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 4 references · NVD status: Deferred
IBM Langflow OSS — Remote Code Execution via Code Validation Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0046   37.9     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  May 13  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-94 · CNA: ibm · 1 reference · NVD status: Analyzed
IBM Langflow OSS — Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0046   37.8     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 17  Published (CNA: ibm)
CWE-184 · CNA: ibm · 1 reference · NVD status: Modified
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-581958.837.8ruvnetagentic-flowCWE-78Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsan…
CVE-2026-144998.837.3IBMLangflow OSSCWE-78Langflow is affected by remote code execution, denial of service, path traver…
CVE-2026-498357.537.1sigstoretimestamp-authorityCWE-770Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality
CVE-2026-153438.637.1GitHubEnterprise ServerCWE-22Path traversal vulnerability in GitHub Enterprise Server allowed writing file…
CVE-2026-622297.737.1OpenClawOpenClawCWE-22OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching
CVE-2026-480495.337.1hapijsinertCWE-22@hapi/inert: Static-file confinement bypass via sibling-prefix path
CVE-2026-502717.536.7DataDogdd-trace-pyCWE-770dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-502727.536.7DataDogdd-trace-jsCWE-770dd-trace: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-502747.536.7DataDogdd-trace-goCWE-770dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-453098.236.6ronfasyncsshCWE-22AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected auth…
CVE-2026-480629.836.5codeigniter4CodeIgniter4CWE-434CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule
CVE-2025-516779.136.0n/an/aCWE-116An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch …
CVE-2025-516787.536.0n/an/aCWE-119An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the P…
CVE-2026-122836.136.0AWSaws-athena-query-federationCWE-89SQL injection in Amazon Athena Synapse connector
CVE-2026-501977.835.8zalandoskipperCWE-444Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-E…
CVE-2026-160135.535.7liftoff-srCIPsterCWE-119liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
CVE-2026-452608.135.6pimcorepimcoreCWE-862Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling
CVE-2026-448917.535.3nettynettyCWE-400Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVE-2026-77558.834.6IBMLangflow OSSCWE-20MCP Server Configuration Validator Bypass via File Upload API
CVE-2026-91039.834.2IBMLangflow OSSCWE-306Unauthenticated Superuser Token Issuance via Auto-Login Endpoint
CVE-2026-95869.334.2SangomaSwitchvox SMB EditionCWE-89Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
CVE-2026-5415910.033.8PrestaShopps_facetedsearchCWE-74ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthe…
CVE-2026-137657.532.0thimpressLearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-862LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Info…
CVE-2026-149797.531.8IBMEngineering Lifecycle ManagementCWE-776IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML E…
CVE-2026-160152.131.6poco-aipoco-clawCWE-287poco-ai poco-claw executor_manager API tasks.py create_task missing authentic…
CVE-2026-527467.531.0jsonata-jsjsonataCWE-1333JSONata: Malicious inputs to "$toMillis" function can cause resource exhaustion
CVE-2026-518337.530.8n/an/aCWE-918Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privil…
CVE-2026-494857.530.2hapifhirorg.hl7.fhir.coreCWE-400HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HT…
CVE-2026-88599.929.9IBMLangflow OSSCWE-22Path Traversal in APIRequest Component via Content-Disposition Header
CVE-2026-150075.729.7GitHubEnterprise ServerCWE-770Denial of service vulnerability in GitHub Enterprise Server allowed service d…
CVE-2026-501626.929.6oras-projectoras-goCWE-73oras-go: file store write outside workingDir via symlink traversal
CVE-2026-501517.529.6oras-projectoras-goCWE-918oras-go: credential forwarding via unvalidated Location header in blob upload
CVE-2026-78728.129.3IBMLangflow OSSCWE-22Path Traversal Vulnerability in File Component Leading to Arbitrary File Read…
CVE-2026-592528.229.3ZenHivemppCWE-1284Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
CVE-2026-442516.529.2wazuhwazuhCWE-122Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and po…
CVE-2026-76678.829.0IBMLangflow OSSCWE-22Path Traversal Vulnerability in API Request Component Content-Disposition Hea…
CVE-2026-147417.528.4OALDERSHTTP::DateCWE-1333HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial …
CVE-2026-149569.828.2BricksforgeBricksforgeCWE-269Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms f…
CVE-2026-126929.827.6Vimesoft Inc.Enterprise Video PlatformCWE-620Improper Authentication in Vimesoft's Enterprise Video Platform
CVE-2026-501637.127.5oras-projectoras-goCWE-22oras-go: Hardlink entry with relative Linkname escapes extract dir via proces…
CVE-2026-449747.727.4hapijscontentCWE-436Parameter smuggling in @hapi/content header parser allows upload-filter bypas…
CVE-2026-544636.927.4fayewebsocket-driver-rubyCWE-770websocket-driver: Memory exhaustion via abuse of protocol length headers
CVE-2026-544656.327.4fayewebsocket-driver-rubyCWE-770websocket-driver: Memory exhaustion in HTTP header parser
CVE-2026-159829.826.9CodeRevolutionAimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation ToolkitCWE-269Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Tool…
CVE-2026-622387.226.2openremoteopenremoteCWE-89OpenRemote < 1.26.0 SQL Injection via Crosstab Export
CVE-2026-555189.625.9avo-hqavoCWE-639Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthor…
CVE-2026-95858.625.6SangomaSwitchvox SMB EditionCWE-79Unauthenticated Reflected Cross-Site Scripting (XSS) in Switchvox SMB Web Portal
CVE-2026-221047.125.2hashtopolisserverCWE-639Improper access control in Hashtopolis server chunk activity component
CVE-2026-544646.325.2fayewebsocket-driver-rubyCWE-770websocket-driver: Resource limit bypass via message compression
CVE-2026-150919.324.8IBMEngineering AI HubCWE-79Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-581488.724.5chronoengine.comChronoForms extension for JoomlaCWE-79Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for…
CVE-2026-630986.924.4TheHive-ProjectTheHiveCWE-306TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
CVE-2026-145019.824.2IBMDb2 Genius HubCWE-676Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
CVE-2026-91717.524.1IBMPowerVM NovalinkCWE-400Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.
CVE-2026-457047.124.1pimcorepimcoreCWE-862Pimcore: CustomReports Share Bypass
CVE-2026-622106.024.1OpenClawOpenClawCWE-770OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs
CVE-2026-544988.723.9ViewComponentview_componentCWE-79view_component: around_render HTML-Safety Bypass
CVE-2026-148717.123.9osTicketosTicketCWE-863osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-d…
CVE-2026-492095.323.9symfonyuxCWE-770Symfony UX: Denial of service in symfony/ux-live-component via unbounded batc…
CVE-2026-622146.023.5openclawmsteamsCWE-522OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation
CVE-2026-492116.923.1symfonyuxCWE-200Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearch…
CVE-2026-541716.523.0exconexconCWE-201Excon: redact additional sensitive/risky headers when following redirects
CVE-2026-485045.323.0open-telemetryopentelemetry-rustCWE-770OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation
CVE-2026-98109.822.9UnknownAI CopilotCWE-269AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege …
CVE-2026-600249.822.9joomdonation.comEvents Booking extension for JoomlaCWE-1188Joomla Extension - joomdonation.com - Insecure default configuration Events B…
CVE-2026-153227.523.0IBMEngineering AI HubCWE-598Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-522037.523.0n/an/aCWE-200An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive informa…
CVE-2026-537278.922.8premailercss_parserCWE-918css_parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_…
CVE-2026-631018.722.8fossasiaopen-event-serverCWE-306Open Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export …
CVE-2026-86359.922.6IBMLangflow OSSCWE-94Arbitrary Code Execution in Python Interpreter Component
CVE-2026-596948.322.7ZenHivemppCWE-1284Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment
CVE-2026-596958.322.7ZenHivemppCWE-1284Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request walle…
CVE-2026-622077.722.7OpenClawOpenClawCWE-862OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools
CVE-2026-126917.522.5Vimesoft Inc.Enterprise Video PlatformCWE-306Authentication Bypass in Vimesoft's Enterprise Video Platform
CVE-2026-622027.722.4OpenClawOpenClawCWE-863OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron
CVE-2026-622348.422.2getgravgravCWE-918Grav < 2.0.4 SSRF via Unrestricted cURL Protocols
CVE-2026-80568.822.0IBMLangflow OSSCWE-94Parameter Injection Vulnerability in API Graph Execution Engine
CVE-2026-622206.321.8OpenClawOpenClawCWE-307OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
CVE-2026-622037.721.4OpenClawOpenClawCWE-184OpenClaw < 2026.6.6 Environment Variable Injection via rustup
CVE-2026-160165.521.3poco-aipoco-clawCWE-918poco-ai poco-claw task.py run_task server-side request forgery
CVE-2026-510809.821.2n/an/aCWE-611libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to c…
CVE-2026-145036.521.2ploudapppCloud WP BackupCWE-200pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX …
CVE-2026-447398.721.0pimcorepimcoreCWE-89Pimcore: SQL Injection in Custom Reports Column Configuration
CVE-2026-622308.720.7getgravgravCWE-178Grav < 2.0.4 File Access Bypass via Case Variation
CVE-2026-622329.120.5getgravgravCWE-862Grav < 2.0.4 2FA Bypass via Secret Regeneration
CVE-2025-603578.120.5n/an/aCWE-943AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injec…
CVE-2026-113246.120.5evertecWooCommerce Placetopay Gateway BeliceCWE-79WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via …
CVE-2026-92029.820.4IBMLangflow OSSCWE-306Unauthenticated User Registration Could Lead to Remote Code Execution
CVE-2026-480154.920.3shopwareshopwareCWE-79Shopware: Stored XSS via SVG file upload — no SVG sanitization
CVE-2026-633085.319.9helmhelmCWE-129Helm Files.Lines Denial of Service via Empty Chart Files
CVE-2026-157835.319.7GitHubEnterprise ServerCWE-862Missing Authorization vulnerability was identified in GitHub Enterprise Serve…
CVE-2026-480096.819.6shopwareshopwareCWE-200Shopware: Admin Account Takeover via User Recovery Hash Exposure
CVE-2026-153494.319.6wedevsERP: Complete HR, Accounting & CRM Suite Built for WooCommerceCWE-862ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Mi…
CVE-2026-623868.219.1getgravgravCWE-598Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter
CVE-2026-126939.418.3Vimesoft Inc.Enterprise Video PlatformCWE-639IDOR in Vimesoft's Enterprise Video Platform
CVE-2026-480086.518.4shopwareshopwareCWE-862Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
CVE-2026-480106.518.4shopwareshopwareCWE-269Shopware: Privilege escalation: non-admin user with user:create ACL can creat…
CVE-2026-117636.518.2Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.GisLab Laboratory Management SystemCWE-639IDOR in GIS Informatics' GisLab Laboratory Management System
CVE-2026-544906.318.2fayewebsocket-driver-nodeCWE-770websocket-driver: Resource limit bypass via message compression
CVE-2026-160145.518.2code-projectsHospital Bed Management SystemCWE-74code-projects Hospital Bed Management System Login Form sql injection
CVE-2026-160082.118.1sagoldjson-schema-libraryCWE-94sagold json-schema-library propertyDependencies.ts parsePropertyDependencies …
CVE-2026-82979.817.9Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.GisLab Laboratory Management SystemCWE-89SQLi in GIS Informatics' GisLab Laboratory Management System
CVE-2026-523489.817.9n/an/aCWE-89cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method…
CVE-2026-134108.217.9GARUDancer::Plugin::Auth::GoogleCWE-295Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verificat…
CVE-2026-83967.517.8Netcad Software Inc.NetGISCWE-611XXE in Netcad's NetGIS
CVE-2026-449796.317.9hapijswreckCWE-200@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-host…
CVE-2026-622014.917.8OpenClawOpenClawCWE-918OpenClaw < 2026.6.6 Network Policy Bypass via exec-server
CVE-2026-623877.117.7getgravgravCWE-942Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin
CVE-2026-73646.117.7IBMVerify Identity AccessCWE-601Security vulnerabilities have been found in IBM Verify Identity Access and IB…
CVE-2026-543353.717.7feathersjsfeathersCWE-1321Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parse…
CVE-2026-622086.017.6OpenClawOpenClawCWE-522OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE
CVE-2026-622136.017.6openclawmsteamsCWE-522OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests
CVE-2026-544976.816.5ViewComponentview_componentCWE-362view_component: Reused Component Instances Retain Stale Render Context
CVE-2026-622056.016.5OpenClawOpenClawCWE-862OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions
CVE-2026-622066.016.5OpenClawOpenClawCWE-862OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions
CVE-2026-622376.016.5getgravgravCWE-1333Grav < 2.0.4 ReDoS via regex_replace in Sandbox
CVE-2026-622188.716.3OpenClawOpenClawCWE-862OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve
CVE-2026-622237.716.3OpenClawOpenClawCWE-863OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
CVE-2026-622287.716.3OpenClawOpenClawCWE-863OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals
CVE-2026-484875.316.3python-zeroconfpython-zeroconfCWE-130Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cac…
CVE-2026-119618.116.3UnknownUser Registration & MembershipCWE-269User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation…
CVE-2026-49427.516.2IBMiCWE-757IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
CVE-2026-153957.216.2wpchillKali Forms — Contact Form & Drag-and-Drop BuilderCWE-79Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digit…
CVE-2026-154156.816.2AWSaws-healthomics-mcp-serverCWE-23Path traversal and arbitrary file write in the workflow linters of aws-health…
CVE-2026-622338.716.1getgravgravCWE-639grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey
CVE-2026-622177.716.1OpenClawOpenClawCWE-863OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals
CVE-2026-71897.516.0Proliz Software Ltd. Co.Proliz's OBSCWE-201Sensitive Data Exposure in Proliz's OBS
CVE-2026-74887.516.0IKAS Technology Inc.E-CommerceCWE-201Sensitive Data Exposure in IKAS Technologies' E-Commerce
CVE-2026-126949.115.7Vimesoft Inc.Enterprise Video PlatformCWE-862Missing Authorization in Vimesoft's Enterprise Video Platform
CVE-2026-622265.115.5OpenClawOpenClawCWE-918OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route
CVE-2026-492086.915.4symfonyuxCWE-20Symfony UX: Format-less date LiveProps parsed with the permissive DateTime co…
CVE-2026-80756.515.3MattermostMattermostCWE-754Posting a malicious markdown image crashes the Mattermost Desktop App
CVE-2026-96026.515.3MattermostMattermostCWE-400Mattermost Desktop App crashes when malformed arguments are provided to some …
CVE-2026-25946.415.3inc2734Smart Custom FieldsCWE-79Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scri…
CVE-2026-88615.315.4IBMVerify Identity AccessCWE-209Security vulnerabilities have been found in IBM Verify Identity Access and IB…
CVE-2026-95887.015.2SangomaSwitchvox SMB EditionCWE-79Authenticated Stored Cross-Site Scripting (XSS) in Switchvox SMB Web Portal
CVE-2026-471836.515.0python-zeroconfpython-zeroconfCWE-400Zeroconf: Unbounded exception-dedup state retains packet buffers via tracebac…
CVE-2026-471846.515.0python-zeroconfpython-zeroconfCWE-770Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via m…
CVE-2024-235655.315.0HCLSoftwareAftermarket EPCCWE-799HCL Aftermarket EPC is vulnerable to email flooding as the application does n…
CVE-2024-235685.315.0HCLSoftwareAftermarket EPCCWE-200HCL Aftermarket EPC is vulnerable to attacks since the server software versio…
CVE-2026-480164.315.1shopwareshopwareCWE-639Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/hand…
CVE-2026-480146.514.4shopwareshopwareCWE-862Shopware: Admin API ACL Bypass in Order State Transition Endpoints
CVE-2026-633077.114.1OtterMindChat2DBCWE-639Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/data…
CVE-2026-95877.113.9SangomaSwitchvox SMB EditionCWE-73Authenticated Local File Inclusion (LFI) in Switchvox SMB Web Portal
CVE-2026-622274.913.9OpenClawOpenClawCWE-918OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot
CVE-2026-115757.513.7UnknownPhonePe Payment SolutionsCWE-862PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged…
CVE-2026-86165.313.8devozonFense Proxy & VPN BlockerCWE-862Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated…
CVE-2026-95375.313.8JBERGERMojo::JWTCWE-208Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-con…
CVE-2026-134469.813.5IBMLangflow OSSCWE-798Langflow is affected by remote code execution, denial of service, path traver…
CVE-2026-471806.513.6python-zeroconfpython-zeroconfCWE-674Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-l…
CVE-2026-480456.513.6python-zeroconfpython-zeroconfCWE-770Zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via …
CVE-2026-134025.313.5UnknownRoyal Addons for ElementorCWE-200Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Templat…
CVE-2026-579805.413.1MicrosoftMicrosoft Edge (Chromium-based)CWE-288Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2026-544669.212.9fayewebsocket-driver-nodeCWE-130websocket-driver: Message corruption via abuse of protocol length headers
CVE-2026-622318.612.9getgravgravCWE-863Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator
CVE-2026-510827.212.9n/an/aCWE-362A race condition between the vncproxy and vncwebsocket API calls in Proxmox V…
CVE-2026-488194.812.9hey-apiopenapi-tsCWE-1321Hey API: `buildClientParams` template: prototype chain substitution via unkno…
CVE-2026-130825.312.3BURAKGD::SecurityImageCWE-338GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
CVE-2026-150934.312.1IBMEngineering AI HubCWE-601Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-630966.911.8matrix-orgdendriteCWE-918Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
CVE-2026-161046.511.7Red HatRed Hat Build of KeycloakCWE-522Keycloak-services: keycloak-services: authenticator config endpoint exposes r…
CVE-2026-622162.311.6OpenClawOpenClawCWE-918OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload
CVE-2026-489782.111.6oras-projectoras-goCWE-319oras-go: Malicious registry can hijack Bearer token realm to exfiltrate crede…
CVE-2026-544969.311.5ZcashFoundationzebraCWE-345Missing copy constraint in halo2_gadgets variable-base scalar multiplication …
CVE-2026-622097.611.5OpenClawOpenClawCWE-863OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode disp…
CVE-2026-630997.111.3TheHive-ProjectTheHiveCWE-639TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endp…
CVE-2026-631007.111.3maybe-financemaybeCWE-862Maybe 0.6.0 Missing Authorization via HostingsController show/update
CVE-2026-160172.111.4mosaxivclawletCWE-862mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
CVE-2026-127158.511.1Google CloudFirebase StudioCWE-862Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft
CVE-2026-581495.311.0joomdonation.comEvents Booking extension for JoomlaCWE-200Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0
CVE-2026-134458.110.8IBMLangflow OSSCWE-639Langflow is affected by remote code execution, denial of service, path traver…
CVE-2026-77546.510.3IBMLangflow OSSCWE-918SSRF Protection Configuration Vulnerability
CVE-2026-510836.510.3n/an/aCWE-284Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server…
CVE-2026-157596.410.3themeatelierChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat FormCWE-79ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-160724.910.3Red HatRed Hat Build of KeycloakCWE-284Keycloak-services: keycloak-services: organization invitation link exposure a…
CVE-2026-160742.110.4AstrBotDevsAstrBotCWE-918AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side re…
CVE-2026-499774.310.2AmauriCtarteaucitron.jsCWE-285tarteaucitron.js: data-cookie attribute can be used to delete arbitrary cookies
CVE-2026-160092.110.2itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System prescriptionorderdetail.php sql injec…
CVE-2026-159435.510.0Red HatRed Hat Build of KeycloakCWE-1288Keycloak-services: keycloak-services: oidc idp update reuses masked client se…
CVE-2026-119665.310.0UnknownUser Registration & MembershipCWE-639User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletio…
CVE-2026-161034.39.9Red HatRed Hat Build of KeycloakCWE-841Keycloak-services: keycloak-services: incomplete fix for ciba brute-force loc…
CVE-2024-235745.39.8HCLSoftwareAftermarket EPCCWE-204HCL Aftermarket EPC is vulnerable to attack since It was found that a malicio…
CVE-2024-235755.39.8HCLSoftwareAftermarket EPCCWE-209HCL Aftermarket EPC is vulnerable to attack since the application returns det…
CVE-2024-422145.39.8HCLSoftwareAftermarket EPCCWE-692HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enab…
CVE-2026-161086.59.4Red HatRed Hat Build of KeycloakCWE-200Keycloak-services: keycloak-services: realm default-group reads disclose hidd…
CVE-2026-492102.39.4symfonyuxCWE-79Symfony UX: XSS in symfony/ux-live-component via attacker-controlled child co…
CVE-2026-633095.39.3surrealdbsurrealdbCWE-863SurrealDB < 3.1.5 Information Disclosure via ORDER BY
CVE-2026-161064.99.2Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: incorrect authorization in admin role-c…
CVE-2026-542436.19.1statamiccmsCWE-1236Statamic: CSV formula injection in form submission exports
CVE-2026-160732.09.1AstrBotDevsAstrBotCWE-79AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross si…
CVE-2024-235649.18.8HCL SoftwareAftermarket EPCCWE-326HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a…
CVE-2026-457036.48.7pimcorepimcoreCWE-862Pimcore: WordExport Authorization Bypass for Unauthorized Document Export
CVE-2026-483737.88.5AdobeAcrobat ReaderCWE-122Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
CVE-2026-552546.58.5ncalcncalcCWE-190NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
CVE-2026-630957.18.1matrix-orgdendriteCWE-639Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint
CVE-2026-583175.18.0TeraTerm ProjectTTSSH2CWE-196Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 …
CVE-2026-600605.18.0TeraTerm ProjectTTSSH2CWE-130Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability e…
CVE-2026-160935.47.8Red HatRed Hat Build of KeycloakCWE-807Keycloak-services: keycloak-services: required signed-jwt assertion policy ca…
CVE-2024-235674.37.9HCLSoftwareAftermarket EPCCWE-804HCL Aftermarket EPC is affected by Sensitive Information in GET method & in U…
CVE-2026-151594.37.6SaturdayDriveNinja Forms - Excel ExportCWE-639Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Aut…
CVE-2026-150695.47.6IBMEngineering AI HubCWE-78Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-492165.17.4symfonyuxCWE-79Symfony UX: XSS in symfony/ux-autocomplete via unescaped AJAX response data
CVE-2024-235694.37.2HCLSoftwareAftermarket EPCCWE-692HCL Aftermarket EPC is vulnerable to attack since the server is not configure…
CVE-2024-235714.37.2HCLSoftwareAftermarket EPCCWE-525HCL Aftermarket EPC is vulnerable to attack since the application does not ha…
CVE-2024-235774.37.2HCLSoftwareAftermarket EPCCWE-20HCL Aftermarket EPC is vulnerable since the application does not have a valid…
CVE-2026-49386.57.2IBMVerify Identity AccessCWE-863Incorrect Authorization in IBM Verify Identity Access and IBM Security Verify…
CVE-2026-105256.17.1UnknownNEX-FormsCWE-79NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
CVE-2026-541634.77.2githubsecure_headersCWE-79secure_headers: CSP directive injection via sandbox, plugin_types, and report…
CVE-2026-542443.57.1statamiccmsCWE-863Statamic: Incorrect authorization lets view-only users submit Live Preview co…
CVE-2026-622196.07.1OpenClawOpenClawCWE-863OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs
CVE-2026-622155.17.0OpenClawOpenClawCWE-345OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas
CVE-2026-630947.66.9SigNozsignozCWE-345SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft
CVE-2026-217625.36.9HCLSoftwareDevOps LoopCWE-644Missing HTTP Security Headers in DevOps Loop
CVE-2026-622125.16.9OpenClawOpenClawCWE-367OpenClaw < 2026.5.28 Authentication Bypass via safeFetch
CVE-2026-123935.46.7UnknownWPS Bookings for WooCommerceCWE-639WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order C…
CVE-2026-622352.36.7getgravgravCWE-636Grav Flex-Objects < 1.4.3 Authorization Bypass via API
CVE-2026-537128.26.4ongresscramCWE-636SCRAM: Silent channel-binding authentication downgrade via unsupported certif…
CVE-2026-97627.86.2IBMDb2CWE-94IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execut…
CVE-2024-235704.36.1HCLSoftwareAftermarket EPCCWE-200HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scr…
CVE-2026-492126.95.8symfonyuxCWE-345Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding
CVE-2026-630975.35.7matrix-orgdendriteCWE-863Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure
CVE-2024-235666.55.6HCLSoftwareAftermarket EPCCWE-804HCL Aftermarket EPC is vulnerable to brute force attacks since application do…
CVE-2026-96564.35.5hubspotdevHubSpot All-In-One Marketing – Forms, Popups, Live ChatCWE-200HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensit…
CVE-2026-151616.45.3SaturdayDriveNinja Forms - Excel ExportCWE-79Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cros…
CVE-2024-235733.75.2HCLSoftwareAftermarket EPCCWE-425HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerab…
CVE-2026-622242.35.2openclawmsteamsCWE-290OpenClaw MS Teams < 2026.5.12 Authorization Bypass
CVE-2026-95927.55.0SEPPmailSEPPmail Secure Email Gateway & SEPPmail CloudCWE-598Sensitive Information Disclosure in HTTP header
CVE-2026-510816.14.6n/an/aCWE-79A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PV…
CVE-2026-492847.14.6simplesamlphpsimplesamlphpCWE-345SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Res…
CVE-2026-217604.64.6HCLSoftwareDevOps LoopCWE-425Unauthorized Access to Admin Functionality via Forced Browsing
CVE-2026-622252.34.5OpenClawOpenClawCWE-863OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch
CVE-2026-542424.94.4statamiccmsCWE-367Statamic: Server-Side Request Forgery via Glide (DNS rebinding)
CVE-2026-217615.44.4HCLSoftwareDevOps LoopCWE-942CORS Misconfiguration in DevOps Loop
CVE-2026-498528.74.1authlibjoserfcCWE-287joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language …
CVE-2026-622212.34.1OpenClawOpenClawCWE-863OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom
CVE-2026-160895.94.0Red HatRed Hat Build of KeycloakCWE-384Keycloak-services: keycloak-services: authorization codes can be retargeted t…
CVE-2026-578608.43.4tailcallhqforgecodeCWE-829ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Reposi…
CVE-2026-161187.13.4xdgxdgmimeCWE-122Xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in …
CVE-2026-457845.13.4rust-opensslrust-opensslCWE-131rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_i…
CVE-2026-217644.33.3HCLSoftwareDevOps LoopCWE-754Insufficient Input Validation in DevOps Loop
CVE-2026-600258.83.1joomdonation.comEvents Booking extension for JoomlaCWE-352Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0
CVE-2026-457856.23.0openmcdfopenmcdfCWE-835OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on …
CVE-2024-235784.22.4HCLSoftwareAftermarket EPCCWE-942HCL Aftermarket EPC is vulnerable to attack as the application implements an …
CVE-2026-480226.52.3hapijswreckCWE-319@hapi/wreck: Sensitive credential headers leak across cross-port and cross-sc…
CVE-2026-622227.12.0OpenClawOpenClawCWE-829OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode
CVE-2026-525847.11.9n/an/aCWE-121Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local at…
CVE-2026-153805.11.9BroadcomSymantec Management SuiteCWE-269Local privilege escalation in Symantec ITMS
CVE-2026-492152.12.0symfonyuxCWE-352Symfony UX: CSRF Protection Bypass in symfony/ux-live-component — Accept Head…
CVE-2026-498347.51.6sigstoresigstore-goCWE-347sigstore-go: Multi-log threshold bypass via single compromised log
CVE-2026-501852.01.6RustCryptoutilsCWE-758RustCrypto Cmov/CmovEq on aarch64 can produce wrong results if high-bits of r…
CVE-2026-217706.51.5HCLSoftwareHCL Traveler for Microsoft Outlook (HTMO)CWE-427HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking
CVE-2026-622114.11.5OpenClawOpenClawCWE-532OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export
CVE-2026-77715.51.2IBMDb2CWE-835IBM® Db2® is vulnerable to a trap when compiling specially crafted statements…
CVE-2026-419936.71.1TXOne NetworksSafePortAgentCWE-284Improper Access Control vulnerability in the Removable Media Validation funct…
CVE-2026-153795.11.1BroadcomSymantec IT Management SuiteCWE-269Arbitrary File Read as SYSTEM in Symantec ITMS
CVE-2026-149717.01.0IBMPowerVM NovalinkCWE-16This PowerVM Novalink update is being released to address
CVE-2026-159954.21.1IBMCognos AnalyticsCWE-362IBM Cognos Analytics 12.1.3 general availability package contains a data inte…
CVE-2026-622362.30.9getgravgravCWE-352grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret
CVE-2026-127055.90.9ABBKNX Update Tool (ABB)CWE-353Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool
CVE-2019-257647.30.5ASUSAURA SYNCCWE-782**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control …
CVE-2026-447226.20.4danifuspyzipperCWE-480pyzipper: Encryption bypass for small files encrypted with pyzipper
CVE-2024-235724.20.4HCLSoftwareAftermarket EPCCWE-614HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a se…
CVE-2025-598663.30.1HCLSoftwareDFMPro for CATIACWE-732The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecu…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-17 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.