AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H H 7.7 .0192 78.2 —
AFFECTED Product Versions Fixed Roo-Code unspecified —
TIMELINE Jul 15 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
266 CVEs published July 20, 2026: 48 critical, 99 high, 115 medium, 4 low; 0 in KEV; 23 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 241 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1712 | 4461 | 1302 | 2563 |
| KEV catalog size | 1670 | |||
78 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| microsoft | 639 | 1342 | 95 | 923 | 299 | 8 | 378 | 31 | 2.3 | 7.8 | .0039 | +420 |
| linux | 311 | 1229 | 178 | 975 | 57 | 0 | 27 | 3 | 0.2 | 7.8 | .0014 | +264 |
| red hat | 32 | 131 | 9 | 72 | 45 | 5 | 4 | 0 | 0.0 | 7.3 | .0030 | -3 |
| apple | 0 | 77 | 1 | 17 | 51 | 1 | 93 | 7 | 9.1 | 6.5 | .0037 | 0 |
| 8 | 17 | 3 | 11 | 0 | 0 | 73 | 5 | 29.4 | 8.8 | .0033 | +6 | |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | -1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 7 | 19 | 4 | 6 | 1 | 0 | 96 | 12 | 63.2 | 8.6 | .2459 | +5 |
| fortinet | 10 | 17 | 2 | 4 | 8 | 0 | 28 | 5 | 29.4 | 6.3 | .0051 | +9 |
| palo alto networks | 10 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | +7 |
| vmware | 7 | 7 | 1 | 6 | 0 | 0 | 21 | 0 | 0.0 | 8.7 | .0044 | +7 |
| f5 | 1 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | -1 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.1 | .0877 | +2 |
| ubiquiti | 0 | 4 | 3 | 1 | 0 | 0 | 4 | 3 | 75.0 | 10.0 | .7455 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 12 | 44 | 11 | 25 | 8 | 0 | 40 | 1 | 2.3 | 7.5 | .0066 | -3 |
| mozilla | 2 | 7 | 3 | 2 | 2 | 0 | 13 | 0 | 0.0 | 8.1 | .0038 | +2 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | -3 |
| gitlab | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .4451 | 0 |
| github | 1 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 4.7 | .0017 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ibm | 31 | 39 | 16 | 11 | 12 | 0 | 7 | 0 | 0.0 | 8.8 | .0029 | +31 |
| adobe | 16 | 27 | 9 | 10 | 4 | 0 | 75 | 4 | 14.8 | 8.6 | .0144 | +9 |
| oracle | 1 | 5 | 2 | 2 | 0 | 0 | 40 | 3 | 60.0 | 8.7 | .1331 | -1 |
| solarwinds | 0 | 4 | 1 | 1 | 0 | 0 | 11 | 4 | 100.0 | 8.7 | .7758 | -1 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| progress | 0 | 0 | 0 | 0 | 0 | 0 | 9 | 0 | — | — | — | 0 |
| sap | 0 | 0 | 0 | 0 | 0 | 0 | 12 | 0 | — | — | — | 0 |
| servicenow | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 1 | 2 | 0 | 0 | 1 | 0 | 26 | 1 | 50.0 | 5.5 | .4518 | +1 |
| rockwell automation | 1 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | +1 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| siemens | 0 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| tp-link | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 57 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | +57 |
| grafana | 6 | 39 | 2 | 13 | 21 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | +4 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| watchguard | 17 | 28 | 1 | 18 | 9 | 0 | 4 | 0 | 0.0 | 7.3 | .0026 | +17 |
| netty | 3 | 25 | 5 | 19 | 0 | 1 | 0 | 0 | 0.0 | 7.5 | .0062 | -11 |
| erlang | 6 | 24 | 0 | 10 | 11 | 3 | 1 | 0 | 0.0 | 6.6 | .0033 | -1 |
| python software foundation | 1 | 23 | 1 | 7 | 13 | 2 | 0 | 0 | 0.0 | 6.0 | .0044 | -3 |
| axios | 0 | 16 | 0 | 11 | 5 | 0 | 0 | 0 | 0.0 | 7.4 | .0072 | -7 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | — |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2026-52887 | 10.0 | .0059 |
| Vendor | CVEs |
|---|---|
| microsoft | 639 |
| linux | 505 |
| surrealdb | 57 |
| red hat | 52 |
| ibm | 39 |
| apple | 37 |
| watchguard | 17 |
| adobe | 16 |
| apache | 13 |
| openclaw | 13 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 12 |
| apple | 7 |
| fortinet | 5 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| solarwinds | 4 |
| synacor | 4 |
| langflow | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 9 |
| npm | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-34908 | Ubiquiti | 0 |
| CVE-2026-34909 | Ubiquiti | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1706 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1706 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1706 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1706 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1706 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1706 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1706 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1706 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1706 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1706 |
EXPLOIT PUBLISHED — CVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-26197 (HDFGroup hdf5). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-26199 (HDFGroup hdf5). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-28220 (wazuh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-32286 (github.com/jackc/pgproto3/v2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45709 (axllent mailpit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45711 (axllent mailpit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45712 (axllent mailpit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45713 (axllent mailpit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46701 (Jovancoding Network-AI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47774 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48824 (axllent mailpit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58413 (Jovancoding Network-AI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58414 (Jovancoding Network-AI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58481 (Jovancoding Network-AI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58482 (Jovancoding Network-AI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58484 (Jovancoding Network-AI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64620 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64621 (FreeRDP). Public exploit reference added.
DUE DATE PASSED — CVE-2026-25089 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-39808 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-58644 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 19, 2026; still in catalog.
RESCORED — CVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). CVSS 6.2 → 7.5 (NVD).
RESCORED — CVE-2024-35260 (Microsoft Power Platform). CVSS 8 → 9.8 (NVD).
RESCORED — CVE-2026-16074 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16076 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16077 (AstrBotDevs AstrBot). CVSS 4.8 → 1.9 (NVD).
RESCORED — CVE-2026-16081 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16083 (Sipeed PicoClaw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16085 (Sipeed PicoClaw). CVSS 4.8 → 1.9 (NVD).
RESCORED — CVE-2026-16088 (halo-dev halo). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-16120 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16121 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16122 (nextlevelbuilder GoClaw). CVSS 4.8 → 1.9 (NVD).
RESCORED — CVE-2026-16124 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16126 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16127 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16128 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16130 (nearai ironclaw). CVSS 4.8 → 1.9 (NVD).
RESCORED — CVE-2026-16133 (LiuMengxuan04 MiniCode). CVSS 2.3 → 1.3 (NVD).
RESCORED — CVE-2026-16154 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16194 (zhayujie CowAgent). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16195 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16197 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16199 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16200 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16201 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16203 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-16205 (Pluck CMS). CVSS 4.8 → 1.9 (NVD).
RESCORED — CVE-2026-16209 (Gerapy). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16211 (allegro). CVSS 2.1 → 1.2 (NVD).
RESCORED — CVE-2026-16212 (awesto django-shop). CVSS 2.3 → 1.3 (NVD).
RESCORED — CVE-2026-16215 (geex-arts django-jet). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-16217 (guohongze adminset). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16219 (Croogo CMS). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16222 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16225 (davenardella snap7). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-16228 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-33845 (gnutls). CVSS 7.5 → 9.1 (NVD).
RESCORED — CVE-2026-3602 (IBM App Connect Enterprise). CVSS 4.7 → 5.5 (NVD).
RESCORED — CVE-2026-49790 (Microsoft Windows 10 Version 1607). CVSS 7.3 → 7.8 (NVD).
RESCORED — CVE-2026-50374 (Microsoft Windows 10 Version 1809). CVSS 6.3 → 6.8 (NVD).
RESCORED — CVE-2026-54991 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2026-54992 (Microsoft Windows 10 Version 1607). CVSS 8.4 → 7.8 (NVD).
RESCORED — CVE-2026-54995 (Microsoft Windows 10 Version 1607). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2026-57973 (Microsoft Windows Subsystem for Linux (WSL2)). CVSS 6.3 → 4.7 (NVD).
RESCORED — CVE-2026-7872 (IBM Langflow OSS). CVSS 7.5 → 8.1 (NVD).
266 CVEs published. 25 box scores, 241 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H H 7.7 .0192 78.2 —
AFFECTED Product Versions Fixed Roo-Code unspecified —
TIMELINE Jul 15 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0175 75.9 —
AFFECTED Product Versions Fixed GPT-SoVITS unspecified —
TIMELINE Jul 18 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0103 60.8 —
AFFECTED Product Versions Fixed egroupware <= 26.2.20260216 – —
TIMELINE Feb 24 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0093 57.8 —
AFFECTED Product Versions Fixed egroupware <= 26.0 – —
TIMELINE Apr 9 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0091 57.1 —
AFFECTED Product Versions Fixed Kirki unspecified —
TIMELINE Jun 24 Reserved by CNA Jul 20 Published (CNA: WPScan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0085 55.2 —
AFFECTED Product Versions Fixed FreeRDP unspecified 3.28.0
TIMELINE Jul 20 Public exploit reference published Jul 20 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0085 55.1 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 7 Reserved by CNA Jul 20 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0083 54.5 —
AFFECTED Product Versions Fixed Net::DNS unspecified —
TIMELINE Jul 19 Reserved by CNA Jul 20 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H L 9.4 .0080 53.5 —
AFFECTED Product Versions Fixed multicluster engine for Kubernetes 2.1 unspecified 1784905766 multicluster engine for Kubernetes 2.1 unspecified 1784905766 multicluster engine for Kubernetes 2.11 unspecified 1784945966 multicluster engine for Kubernetes 2.17 unspecified 1784856942 multicluster engine for Kubernetes 2.6 unspecified 1784905804 multicluster engine for Kubernetes 2.8 unspecified 1784905783 multicluster engine for Kubernetes 2.9.0 unspecified 1784905769 Red Hat OpenShift Container Platform 4.16 unspecified 1785534428 Red Hat OpenShift Container Platform 4.17 unspecified 1784914869 Red Hat OpenShift Container Platform 4.18 unspecified 1784912882 + 32 more
TIMELINE Jul 20 Reserved by CNA Jul 20 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0076 52.4 —
AFFECTED Product Versions Fixed mbCONNECT24 1.0.0 – — mymbCONNECT24 1.0.0 – — mbCONNECT24 2.20.0 – — mymbCONNECT24 2.20.0 – — myREX24V2 1.0.0 – — myREX24V2.virtual 1.0.0 – — myREX24V2 2.20.0 – — myREX24V2.virtual 2.20.0 – —
TIMELINE Jul 2 Reserved by CNA Jul 20 Published (CNA: CERTVDE)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C L H H 9.0 .0076 52.2 —
AFFECTED Product Versions Fixed Red Hat Ansible Automation Platform 2.5 for RHEL 8 unspecified 0:3.49.63-2.el8ap Red Hat Ansible Automation Platform 2.5 for RHEL 9 unspecified 0:3.49.63-2.el9ap Red Hat Ansible Automation Platform 2.6 for RHEL 9 unspecified 0:3.49.63-2.el9ap Red Hat Satellite 6.16 for RHEL 8 unspecified 0:3.49.39-2.el8pc Red Hat Satellite 6.16 for RHEL 8 unspecified 0:3.49.39-2.el8pc Red Hat Satellite 6.16 for RHEL 9 unspecified 0:3.49.39-2.el9pc Red Hat Satellite 6.16 for RHEL 9 unspecified 0:3.49.39-2.el9pc Red Hat Satellite 6.17 for RHEL 9 unspecified 0:3.63.21-2.el9pc Red Hat Satellite 6.17 for RHEL 9 unspecified 0:3.63.21-2.el9pc Red Hat Satellite 6.18 for RHEL 9 unspecified 0:3.73.30-2.el9pc + 8 more
TIMELINE Jun 19 Reserved by CNA Jul 20 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0074 51.7 —
AFFECTED Product Versions Fixed ktransformers unspecified def0f9313d6e063b5c5ccdfa1f6707f7a40dfdca
TIMELINE Jul 18 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0073 51.2 —
AFFECTED Product Versions Fixed DNS-320 1.0.2 – —
TIMELINE Jul 20 Reserved by CNA Jul 20 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0068 49.3 —
AFFECTED Product Versions Fixed Apache Syncope 3.0.0-M0 – —
TIMELINE Jun 9 Reserved by CNA Jul 20 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0061 46.3 —
AFFECTED Product Versions Fixed xrdp < 0.10.6.1 – —
TIMELINE Apr 18 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0060 46.0 —
AFFECTED Product Versions Fixed dataCycle-CORE <= 25.07.3 – —
TIMELINE Mar 16 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H L N 7.1 .0059 45.6 —
AFFECTED Product Versions Fixed Apache MINA SSHD 2.0.0 – —
TIMELINE Jun 22 Reserved by CNA Jul 20 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0057 44.4 —
AFFECTED Product Versions Fixed Apache MINA SSHD unspecified —
TIMELINE Jun 22 Reserved by CNA Jul 20 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0051 41.3 —
AFFECTED Product Versions Fixed xrdp < 0.10.6.1 – —
TIMELINE May 5 Reserved by CNA Jul 20 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0051 41.2 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 8 Reserved by CNA Jul 20 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0050 40.7 —
AFFECTED Product Versions Fixed proftpd unspecified —
TIMELINE Jul 15 Reserved by CNA Jul 20 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0050 40.3 —
AFFECTED Product Versions Fixed Apache Syncope 3.0.0-M0 – —
TIMELINE Jun 24 Reserved by CNA Jul 20 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0047 38.4 —
AFFECTED Product Versions Fixed AC10 16.03.10.09_multi_TDE01 – —
TIMELINE Jul 20 Reserved by CNA Jul 20 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0044 37.0 —
AFFECTED Product Versions Fixed Apache Syncope 3.0.0-M0 – —
TIMELINE Jun 9 Reserved by CNA Jul 20 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0044 36.6 —
AFFECTED Product Versions Fixed Apache Syncope 3.0.0-M0 – —
TIMELINE Jul 15 Reserved by CNA Jul 20 Published (CNA: apache)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-64194 | 7.5 | 36.1 | NLNETLABS | Net::DNS | CWE-674 | Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS … |
| CVE-2024-51311 | 9.8 | 35.6 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the… |
| CVE-2026-8170 | 8.7 | 35.5 | Extreme Networks | Switch Engine (EXOS) | CWE-59 | ExtremeXOS Privilege Escalation via Symlink Following in File Utilities |
| CVE-2026-46412 | 10.0 | 35.4 | BeProduct | beproduct-org-nestjs-auth | CWE-506 | Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-H… |
| CVE-2026-57852 | 6.3 | 35.4 | Trilby Media | Grav CMS scheduler-webhook plugin | CWE-303 | Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook To… |
| CVE-2026-58624 | 5.4 | 35.4 | Apache Software Foundation | Apache MINA SSHD | CWE-20 | Apache MINA SSHD: Remote execution of JGit commands can write files on the se… |
| CVE-2026-55831 | 7.5 | 35.3 | netty | netty | CWE-400 | Netty SPDY SETTINGS frame count materializes unbounded settings map |
| CVE-2026-55833 | 7.5 | 35.3 | netty | netty | CWE-400 | Netty SPDY zlib header block continues decoded expansion after maxHeaderSize … |
| CVE-2026-48824 | 5.3 | 35.1 | axllent | mailpit | CWE-770 | Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /a… |
| CVE-2024-51312 | 9.8 | 34.9 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the… |
| CVE-2024-51313 | 9.8 | 34.9 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the… |
| CVE-2024-51314 | 9.8 | 34.9 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the… |
| CVE-2024-51315 | 9.8 | 34.9 | n/a | n/a | CWE-121 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the… |
| CVE-2026-42210 | 5.3 | 34.9 | webmin | webmin | CWE-287 | Webmin 2FA requirement bypass |
| CVE-2026-26080 | 3.7 | 34.7 | HAProxy | HAProxy | CWE-252 | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop o… |
| CVE-2026-62183 | 9.8 | 34.3 | Apache Software Foundation | Apache Syncope | CWE-269 | Apache Syncope: User self-service privilege escalation |
| CVE-2026-64622 | 9.3 | 34.0 | Jovancoding | Network-AI | CWE-862 | Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox |
| CVE-2026-45797 | 6.4 | 33.6 | heyform | heyform | CWE-79 | HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload |
| CVE-2026-51385 | 6.9 | 33.3 | n/a | n/a | CWE-94 | An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a … |
| CVE-2026-16337 | 9.4 | 33.2 | dotCMS | dotCMS | CWE-269 | Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoin… |
| CVE-2026-28220 | 9.1 | 32.8 | wazuh | wazuh | CWE-502 | Wazuh cluster DAPI arbitrary callable deserialization and RBAC context inject… |
| CVE-2026-41521 | 9.1 | 32.3 | neutrinolabs | xrdp | CWE-190 | xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass |
| CVE-2026-45713 | 7.5 | 32.0 | axllent | mailpit | CWE-400 | Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA… |
| CVE-2026-15903 | 8.8 | 31.9 | Chrome | CWE-125 | Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 a… | |
| CVE-2026-54538 | 7.5 | 31.6 | neutrinolabs | xrdp | CWE-835 | xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER |
| CVE-2026-53595 | 9.4 | 30.5 | freescout-help-desk | freescout | CWE-178 | FreeScout vulnerable to anonymous account takeover via /user-setup empty invi… |
| CVE-2026-57311 | 5.3 | 30.5 | JCD | Windu CMS | CWE-434 | Unrestricted Upload of File with Dangerous Type in Windu CMS |
| CVE-2026-54051 | 9.9 | 30.1 | Jovancoding | Network-AI | CWE-78 | Network-AI has an an OS Command Injection issue |
| CVE-2026-48812 | 7.5 | 29.9 | freescout-help-desk | freescout | CWE-287 | FreeScout Allows Unauthenticated Access to Legacy Attachment Files |
| CVE-2026-26081 | 4.8 | 29.4 | HAProxy | HAProxy | CWE-130 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check f… |
| CVE-2026-63747 | 8.7 | 29.0 | surrealdb | surrealdb | CWE-248 | SurrealDB before 3.1.0 Denial of Service via malformed RPC use |
| CVE-2026-63760 | 8.7 | 29.0 | surrealdb | surrealdb | CWE-674 | SurrealDB before 3.1.0 Denial of Service via JSON Parser |
| CVE-2026-16235 | 9.8 | 28.8 | DRSTEVE | Crypt::Password | CWE-338 | Crypt::Password versions through 0.28 for Perl generate insecure random value… |
| CVE-2026-63739 | 8.3 | 28.7 | surrealdb | surrealdb | CWE-22 | SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER |
| CVE-2026-63757 | 8.7 | 28.6 | surrealdb | surrealdb | CWE-306 | SurrealDB before 3.1.0 Session Hijacking via /rpc sessions |
| CVE-2026-64625 | 9.3 | 28.2 | WWBN | AVideo | CWE-78 | AVideo before 29.0 OS Command Injection via execAsync |
| CVE-2026-53594 | 4.9 | 28.2 | freescout-help-desk | freescout | CWE-22 | FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path |
| CVE-2026-64612 | 7.5 | 28.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-248 | Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort… |
| CVE-2026-15902 | 8.8 | 27.9 | Chrome | CWE-416 | Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a rem… | |
| CVE-2026-60027 | 8.7 | 27.6 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-22 | Joomla Extension - themexpert.com - Unauthenticated path traversal / file rea… |
| CVE-2026-63737 | 7.1 | 27.6 | surrealdb | surrealdb | CWE-674 | SurrealDB before 3.1.5 Denial of Service via deep operator chains |
| CVE-2026-25039 | 8.8 | 27.5 | Scille | parsec-cloud | CWE-40 | The application evaluate UNC path in workspace name |
| CVE-2024-51316 | 7.5 | 27.3 | n/a | n/a | CWE-400 | The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in … |
| CVE-2026-51027 | 9.9 | 27.3 | n/a | n/a | CWE-200 | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive … |
| CVE-2026-59238 | 6.9 | 26.0 | maalfer | Pentestify | CWE-79 | Stored XSS in Pentestify via unsanitized finding images and report client logo |
| CVE-2026-15901 | 9.6 | 26.0 | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a … | |
| CVE-2026-63734 | 6.9 | 25.7 | surrealdb | surrealdb | CWE-20 | SurrealDB before 3.2.0 Denial of Service via malformed SurrealML import |
| CVE-2026-61425 | 9.4 | 25.6 | balbooa.com | Gridbox extension for Joomla | CWE-288 | Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 |
| CVE-2026-44583 | 5.3 | 25.4 | Paymenter | Paymenter | CWE-918 | Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module |
| CVE-2026-35048 | 9.8 | 25.0 | Piwigo | Piwigo | CWE-20 | Piwigo RCE via PHP Code Injection into Config File in Installer |
| CVE-2026-11349 | 8.6 | 24.9 | Unknown | Modern Event Calendar Pro | CWE-89 | Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection … |
| CVE-2026-6656 | 7.5 | 24.4 | DRSTEVE | Crypt::Password | CWE-208 | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks |
| CVE-2026-57309 | 9.3 | 24.1 | JCD | Windu CMS | CWE-89 | Blind SQL Injection in Windu CMS |
| CVE-2026-44978 | 5.3 | 24.2 | neutrinolabs | xrdp | CWE-20 | xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-… |
| CVE-2026-60026 | 8.9 | 23.8 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-94 | Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix … |
| CVE-2026-45711 | 8.2 | 23.8 | axllent | mailpit | CWE-22 | Mailpit: Path traversal & arbitrary file write in mailpit dump --http via att… |
| CVE-2026-12898 | 6.5 | 23.5 | Unknown | All-in-One WP Migration and Backup | CWE-22 | All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Locati… |
| CVE-2026-54910 | 7.7 | 23.3 | gtsteffaniak | filebrowser | CWE-22 | FileBrowser Quantum's path traversal issue in subtitle handler allows any aut… |
| CVE-2026-55238 | 5.3 | 23.1 | neutrinolabs | xrdp | CWE-126 | xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads |
| CVE-2026-64621 | 9.3 | 23.0 | FreeRDP | FreeRDP | CWE-415 | FreeRDP before 3.28.0 Double-Free via selectedmonitors |
| CVE-2026-62418 | 8.1 | 22.7 | Apache Software Foundation | Apache Syncope | CWE-918 | Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources… |
| CVE-2026-15899 | 9.6 | 22.3 | Chrome | CWE-416 | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.1… | |
| CVE-2026-15900 | 9.6 | 22.3 | Chrome | CWE-416 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 all… | |
| CVE-2026-15904 | 8.8 | 22.3 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 all… | |
| CVE-2026-63429 | 8.6 | 22.4 | heyform | heyform | CWE-306 | HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files… |
| CVE-2026-32824 | 7.3 | 22.1 | datacycle-engine | dataCycle-CORE | CWE-601 | dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Cont… |
| CVE-2026-32825 | 7.3 | 22.1 | datacycle-engine | dataCycle-CORE | CWE-307 | dataCycle No Brute-Force Protection On Web And API Login Endpoints |
| CVE-2026-63091 | 7.1 | 22.0 | proftpd | proftpd | CWE-126 | ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser |
| CVE-2026-10081 | 8.8 | 21.7 | Unknown | Unlimited Elements For Elementor | CWE-79 | Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Go… |
| CVE-2026-34239 | 7.5 | 21.7 | chamilo | chamilo-lms | CWE-285 | Chamilo Authenticated Remote Code Execution |
| CVE-2026-13577 | 8.2 | 21.4 | CROMEDOME | Dancer2 | CWE-338 | Dancer2 versions through 2.1.0 for Perl generate insecure session ids when re… |
| CVE-2026-51031 | 7.5 | 21.2 | n/a | n/a | CWE-918 | FlareSolverr before version 3.4.7 contains a server-side request forgery (SSR… |
| CVE-2026-47198 | 8.5 | 21.2 | Paymenter | Paymenter | CWE-20 | Paymenter: URL parameter injection bypasses paid plan limits at checkout |
| CVE-2026-32806 | 7.5 | 21.2 | datacycle-engine | dataCycle-CORE | CWE-285 | dataCycle Authorization Bypass Via /remote_render |
| CVE-2026-32807 | 7.5 | 21.2 | datacycle-engine | dataCycle-CORE | CWE-285 | dataCycle Public DataLink Text File Download Ignores Validity And Authorization |
| CVE-2026-63746 | 7.1 | 21.2 | surrealdb | surrealdb | CWE-200 | SurrealDB before 3.1.0 Permission Bypass via Graph Traversal |
| CVE-2026-53593 | 8.8 | 20.8 | freescout-help-desk | freescout | CWE-434 | FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete up… |
| CVE-2026-55645 | 6.5 | 20.8 | neutrinolabs | xrdp | CWE-125 | xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_d… |
| CVE-2026-57495 | 8.2 | 20.6 | agenticmail | @agenticmail/core | CWE-306 | AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume o… |
| CVE-2026-46715 | 5.3 | 20.4 | pallets-eco | Flask-Security-Too | CWE-287 | Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OA… |
| CVE-2026-8169 | 8.7 | 20.3 | Extreme Networks | Switch Engine (EXOS) | CWE-338 | ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG |
| CVE-2026-63750 | 6.9 | 20.3 | surrealdb | surrealdb | CWE-770 | SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket |
| CVE-2026-16277 | 6.5 | 20.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() |
| CVE-2026-16324 | 5.5 | 20.3 | Metasoft 美特软件 | MetaCRM | CWE-284 | Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload |
| CVE-2026-15788 | 5.6 | 19.8 | moby | BuildKit | CWE-59 | WCOW cache mount source selector resolves NTFS junctions outside of cache root |
| CVE-2026-63763 | 7.5 | 19.7 | surrealdb | surrealdb | CWE-639 | SurrealDB before 2.5.0 Privilege Escalation via Future Fields |
| CVE-2026-16254 | 4.3 | 19.6 | Red Hat | Red Hat Advanced Cluster Security 4 | CWE-125 | Claircore: claircore: denial of service via out-of-bounds slice in claircore'… |
| CVE-2026-63756 | 9.2 | 19.3 | surrealdb | surrealdb | CWE-362 | SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition |
| CVE-2026-54685 | 5.3 | 19.2 | gtsteffaniak | filebrowser | CWE-208 | FileBrowser Quantum has Username Enumeration via Authentication Timing Side-C… |
| CVE-2026-15813 | 6.5 | 19.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Kronosnet: kronosnet: memory corruption and out-of-bounds access via malforme… |
| CVE-2026-45139 | 6.5 | 18.9 | ci4-cms-erp | ci4ms | CWE-73 | CI4MS Fileeditor allows deletion and rename of critical application files due… |
| CVE-2026-26197 | 5.9 | 18.9 | HDFGroup | hdf5 | CWE-125 | Array full size, element count, and element size are not checked to make sure… |
| CVE-2026-63741 | 6.9 | 18.6 | surrealdb | surrealdb | CWE-862 | SurrealDB before 3.1.0 Authentication Bypass via USE statement |
| CVE-2026-45709 | 5.8 | 18.5 | axllent | mailpit | CWE-918 | Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to… |
| CVE-2026-61424 | 10.0 | 18.2 | dj-extensions.com | DJ-Classifieds extension for Joomla | CWE-434 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload … |
| CVE-2026-61900 | 10.0 | 18.2 | dj-extensions.com | jDownloads extension for Joomla | CWE-434 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload … |
| CVE-2026-46410 | 8.7 | 18.2 | gtsteffaniak | filebrowser | CWE-200 | FileBrowser Quantum: unauthenticated user share share info |
| CVE-2026-63735 | 8.6 | 18.2 | surrealdb | surrealdb | CWE-639 | SurrealDB before 3.2.0 Authentication Bypass via Custom API |
| CVE-2026-16252 | 5.5 | 18.2 | Beijing Shenzhou Shihan Technology | Multimedia Integrated Business Display System | CWE-74 | Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display Sys… |
| CVE-2026-64206 | 8.8 | 18.1 | Linux | Linux | — | Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock |
| CVE-2026-46516 | 4.8 | 17.9 | mwtcmi | frogman | CWE-79 | Frogman vulnerable to stored XSS in chat console formatter (escalation vector… |
| CVE-2026-63740 | 7.1 | 17.6 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.4 Array Element Permission Bypass |
| CVE-2026-26199 | 5.9 | 17.4 | HDFGroup | hdf5 | CWE-124 | Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero |
| CVE-2026-63754 | 7.1 | 17.1 | surrealdb | surrealdb | CWE-754 | SurrealDB before 3.1.0 Denial of Service via LIVE Query |
| CVE-2026-63759 | 7.1 | 17.1 | surrealdb | surrealdb | CWE-674 | SurrealDB before 3.1.0 Denial of Service nested type annotations |
| CVE-2026-63762 | 6.0 | 17.1 | surrealdb | surrealdb | CWE-476 | SurrealDB before v2.6.1 Denial of Service via scripting |
| CVE-2026-55639 | 5.3 | 17.1 | neutrinolabs | xrdp | CWE-125 | xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY process… |
| CVE-2026-52349 | 7.8 | 16.9 | n/a | n/a | CWE-22 | Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa4… |
| CVE-2026-60031 | 6.9 | 16.9 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-200 | Joomla Extension - themexpert.com - Information disclosure in Quix Page Build… |
| CVE-2026-42218 | 5.3 | 16.6 | neutrinolabs | xrdp | CWE-204 | XRDP is vulnerable to a server timing attack, leading to user enumeration |
| CVE-2026-44231 | 9.1 | 16.5 | bestpractical | rt | CWE-200 | RT: Privilege escalation and information disclosure via REST 2.0 user collect… |
| CVE-2026-63428 | 5.8 | 16.5 | heyform | heyform | CWE-20 | HeyForm: completeSubmission persists submitter-supplied hidden fields verbati… |
| CVE-2026-60034 | 9.4 | 16.2 | themexpert.com | JMedia extension for Joomla | CWE-79 | Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extens… |
| CVE-2026-60028 | 8.6 | 16.2 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-79 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Bui… |
| CVE-2026-45712 | 5.9 | 16.3 | axllent | mailpit | CWE-362 | Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth cr… |
| CVE-2026-60029 | 5.1 | 16.2 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-79 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Bui… |
| CVE-2026-63102 | 5.3 | 16.1 | rConfig | rConfig v8 Core | CWE-915 | rConfig Core < 8.2.8 Privilege Escalation via Users API role field |
| CVE-2026-63771 | 6.0 | 15.7 | vrana | adminer | CWE-113 | Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header |
| CVE-2026-60032 | 9.4 | 15.6 | themexpert.com | JMedia extension for Joomla | CWE-434 | Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JM… |
| CVE-2026-60030 | 8.7 | 15.3 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-284 | Joomla Extension - themexpert.com - Broken Access Control for media managemen… |
| CVE-2026-50743 | 5.4 | 15.2 | Revive | Adserver | CWE-352 | A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserv… |
| CVE-2026-63731 | 6.3 | 15.1 | hyperdxio | hyperdx | CWE-918 | HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint |
| CVE-2026-53596 | 5.3 | 15.0 | freescout-help-desk | freescout | CWE-400 | FreeScout has unrestricted file upload without rate limiting that leads to re… |
| CVE-2026-39878 | 9.3 | 14.8 | chamilo | chamilo-lms | CWE-79 | Chamilo stored XSS via user registration leads to admin account takeover |
| CVE-2026-21824 | 8.8 | 14.8 | HCLSoftware | Commerce | CWE-266 | A privilege escalation vulnerability affects HCL Commerce |
| CVE-2026-13380 | 9.0 | 14.6 | VSee | Clinic | CWE-201 | VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTT… |
| CVE-2026-47276 | 6.5 | 14.6 | nanomq | nanomq | CWE-476 | NULL Pointer Dereference in REST API properties_parse via Malformed user_prop… |
| CVE-2026-35198 | 9.0 | 14.5 | heyform | heyform | CWE-79 | HeyForm vulnerable to stored XSS via form field titles |
| CVE-2026-8825 | 4.9 | 14.6 | Unknown | Elementor Website Builder | CWE-200 | Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API |
| CVE-2026-63730 | 5.3 | 14.4 | hyperdxio | hyperdx | CWE-918 | HyperDX < 2.31.0 SSRF via Webhook Test Endpoint |
| CVE-2026-63744 | 5.1 | 14.5 | surrealdb | surrealdb | CWE-918 | SurrealDB before 3.1.5 SSRF via JWKS URL Redirect |
| CVE-2026-62414 | 9.1 | 14.3 | joomlack.fr | Page Builder CK extension for Joomla | CWE-284 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK <… |
| CVE-2026-63769 | 6.3 | 14.1 | huginn | huginn | CWE-918 | Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method |
| CVE-2026-60033 | 5.1 | 13.9 | themexpert.com | JMedia extension for Joomla | CWE-918 | Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extens… |
| CVE-2026-13142 | 8.1 | 13.6 | Unknown | Social Login, Passkeys, Magic Link & Email OTP | CWE-269 | Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeove… |
| CVE-2026-63736 | 5.1 | 13.6 | surrealdb | surrealdb | CWE-918 | SurrealDB before 3.2.0 SSRF via JWKS URL hostname resolution |
| CVE-2026-47129 | 8.1 | 13.1 | pdovhomilja | nextcrm-app | CWE-862 | NextCRM has Broken Access Control in Server Actions that allows any authentic… |
| CVE-2026-46701 | 7.6 | 13.2 | Jovancoding | Network-AI | CWE-346 | Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Defaul… |
| CVE-2026-39385 | 7.1 | 12.7 | frappe | lms | CWE-288 | Frappe LMS enrollment bypass in paid courses via unrelated batch |
| CVE-2026-57494 | 7.1 | 12.7 | agenticmail | @agenticmail/api | CWE-639 | AgenticMail: Cross-agent task authorization bypass in AgenticMail API |
| CVE-2026-12341 | 9.8 | 12.3 | SailPoint Technologies | IdentityIQ | CWE-287 | SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability |
| CVE-2026-53591 | 8.6 | 12.2 | freescout-help-desk | freescout | CWE-287 | FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMA… |
| CVE-2026-51025 | 6.1 | 12.0 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 al… |
| CVE-2026-32822 | 6.1 | 11.7 | datacycle-engine | dataCycle-CORE | CWE-80 | dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages |
| CVE-2026-63742 | 5.3 | 11.6 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT |
| CVE-2026-63755 | 7.1 | 11.5 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.0 Permission Bypass via WHERE Clause |
| CVE-2026-63749 | 5.3 | 11.5 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT |
| CVE-2026-13381 | 8.7 | 11.3 | VSee | Clinic | CWE-639 | VSee Clinic and API Insecure Direct Object Reference in File API Allows Unaut… |
| CVE-2026-63107 | 6.3 | 11.3 | LimeSurvey | LimeSurvey | CWE-918 | LimeSurvey SSRF via REST API Survey Template Host Header |
| CVE-2026-45270 | 8.7 | 11.1 | ci4-cms-erp | ci4ms | CWE-79 | CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule |
| CVE-2026-58484 | 7.1 | 11.1 | Jovancoding | Network-AI | CWE-22 | Network-AI: Poisoned environment backup manifest allows arbitrary recursive d… |
| CVE-2026-12592 | 7.5 | 10.7 | Unknown | SlimStat Analytics | CWE-79 | SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header |
| CVE-2026-63738 | 5.3 | 10.7 | surrealdb | surrealdb | CWE-863 | SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal |
| CVE-2026-63753 | 5.3 | 10.7 | surrealdb | surrealdb | CWE-613 | SurrealDB before 3.1.0 Authentication Bypass via LIVE Query |
| CVE-2026-58481 | 6.5 | 10.5 | Jovancoding | Network-AI | CWE-22 | Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside… |
| CVE-2026-58413 | 6.1 | 10.5 | Jovancoding | Network-AI | CWE-22 | EnvironmentManager.restore() backup ID path traversal copies arbitrary direct… |
| CVE-2026-58414 | 5.5 | 10.5 | Jovancoding | Network-AI | CWE-22 | Network-AI: EnvironmentManager.backup() follows symlinked directories and cop… |
| CVE-2026-12723 | 5.3 | 10.6 | Unknown | Kirki | CWE-862 | Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderatio… |
| CVE-2026-64619 | 8.7 | 10.4 | vastsa | FileCodeBox | CWE-348 | FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers |
| CVE-2026-13724 | 4.3 | 10.4 | Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. | Corporate Training Management System | CWE-602 | Business Logic Bypass in Gobito's Corporate Training Management System |
| CVE-2026-32821 | 8.1 | 10.3 | datacycle-engine | dataCycle-CORE | CWE-285 | API Collection Impersonation Via user_email And Missing Object- Level Authori… |
| CVE-2026-63733 | 5.3 | 10.4 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause |
| CVE-2026-64623 | 8.8 | 10.1 | Jovancoding | Network-AI | CWE-347 | Network-AI before 5.13.4 Cryptographic Signature Verification Bypass |
| CVE-2026-45295 | 6.5 | 10.1 | freescout-help-desk | freescout | CWE-639 | FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and C… |
| CVE-2026-16244 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System prescriptionorderreport.php sql injec… |
| CVE-2026-63770 | 8.2 | 9.9 | glanceapp | glance | CWE-348 | Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass |
| CVE-2026-32819 | 4.3 | 9.8 | datacycle-engine | dataCycle-CORE | CWE-285 | dataCycle User Directory Enumeration Via /users/search |
| CVE-2026-63768 | 5.3 | 9.7 | calcom | cal.diy | CWE-601 | cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State |
| CVE-2026-55550 | 7.1 | 9.5 | pdovhomilja | nextcrm-app | CWE-269 | NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users… |
| CVE-2026-35217 | 6.5 | 9.4 | nanomq | nanomq | CWE-125 | NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an AS… |
| CVE-2026-63748 | 5.3 | 9.3 | surrealdb | surrealdb | CWE-209 | SurrealDB before 3.1.0 Information Disclosure via Error Messages |
| CVE-2026-15588 | 5.3 | 9.2 | Red Hat | Red Hat Enterprise Linux 9 | CWE-770 | Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl lin… |
| CVE-2026-46428 | 9.1 | 9.1 | lettre | lettre | CWE-295 | lettre has TLS hostname verification disabled when using Boring TLS backend |
| CVE-2026-46555 | 7.1 | 8.7 | verygoodplugins | whatsapp-mcp | CWE-22 | WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary… |
| CVE-2026-12900 | 6.4 | 8.6 | brainstormforce | Spectra Legacy – Gutenberg Blocks | CWE-79 | Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cro… |
| CVE-2026-48389 | 7.8 | 8.5 | Adobe | DNG SDK | CWE-121 | DNG SDK | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-64626 | 5.3 | 8.5 | WWBN | AVideo | CWE-918 | AVideo Encoder downloadURL SSRF via unpinned retry fallback |
| CVE-2026-11868 | 5.3 | 8.0 | Unknown | WP Travel | CWE-862 | WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation |
| CVE-2026-63758 | 5.3 | 7.9 | surrealdb | surrealdb | CWE-862 | SurrealDB before 3.1.0 Authorization Bypass via KILL Statement |
| CVE-2026-64624 | 8.5 | 7.9 | FreeRDP | FreeRDP | CWE-88 | FreeRDP RDP File Parser Remote Code Execution via CLI Options |
| CVE-2026-55544 | 7.6 | 7.9 | pdovhomilja | nextcrm-app | CWE-284 | NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign D… |
| CVE-2026-63743 | 5.3 | 7.8 | surrealdb | surrealdb | CWE-918 | SurrealDB before 3.1.0 Port-Specific Deny Rule Bypass via HTTP Redirect |
| CVE-2026-63745 | 5.3 | 7.8 | surrealdb | surrealdb | CWE-639 | SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id |
| CVE-2026-47255 | 8.2 | 7.6 | agenticmail | @agenticmail/api | CWE-20 | AgenticMail API/storage and outbound relay hardening |
| CVE-2026-56624 | 7.3 | 7.6 | Apache Software Foundation | Apache MINA SSHD | CWE-295 | Apache MINA SSHD: SSH certificate options lack validations |
| CVE-2026-44585 | 5.4 | 7.6 | Paymenter | Paymenter | CWE-639 | Paymenter: Broken object level authorization via service reference manipulati… |
| CVE-2026-12972 | 5.3 | 7.4 | Unknown | PayPlus Payment Gateway | CWE-284 | PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tamp… |
| CVE-2026-57310 | 6.3 | 7.2 | JCD | Windu CMS | CWE-916 | Weak password hashing in Windu CMS |
| CVE-2026-63751 | 5.3 | 7.1 | surrealdb | surrealdb | CWE-863 | SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch |
| CVE-2026-39879 | 7.1 | 6.9 | syslog-ng | syslog-ng | CWE-150 | SQL injection in syslog-ng SQL destionation driver |
| CVE-2026-13432 | 5.4 | 6.7 | Unknown | ThumbPress | CWE-862 | ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation |
| CVE-2026-47275 | 2.6 | 6.6 | nanomq | nanomq | CWE-476 | nanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to R… |
| CVE-2026-10755 | 2.7 | 6.6 | Unknown | All in One SEO | CWE-863 | All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration |
| CVE-2026-63752 | 5.3 | 6.3 | surrealdb | surrealdb | CWE-285 | SurrealDB before 3.1.0 RELATE Statement Record Overwrite |
| CVE-2026-9833 | 7.1 | 6.0 | Unknown | Tag Groups is the Advanced Way to Display Your Taxonomy Terms | CWE-79 | Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter |
| CVE-2026-26483 | 6.1 | 6.0 | n/a | n/a | CWE-79 | Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (X… |
| CVE-2026-63761 | 5.3 | 6.0 | surrealdb | surrealdb | CWE-327 | SurrealDB before 3.1.0 Algorithm Downgrade via ES512 |
| CVE-2026-47130 | 7.1 | 5.8 | pdovhomilja | nextcrm-app | CWE-639 | NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Ten… |
| CVE-2026-6793 | 5.4 | 5.9 | Bifra Engineering Consulting Ltd. | Q-smart NexT Poll | CWE-79 | Stored XSS in Bifra Engineering's Q-smart NexT Poll |
| CVE-2026-46415 | 8.2 | 5.7 | JasonLovesDoggo | caddy-defender | CWE-284 | Caddy Defender trusted proxy client IP bypass |
| CVE-2026-12973 | 6.5 | 5.7 | Unknown | PayPlus Payment Gateway | CWE-862 | PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Or… |
| CVE-2026-58482 | 5.9 | 5.6 | Jovancoding | Network-AI | CWE-352 | Network-AI: ApprovalInbox HTTP server has no authentication — anyone can appr… |
| CVE-2026-44227 | 6.1 | 5.1 | bestpractical | rt | CWE-79 | RT: Reflected Cross-Site Scripting via URL parameters |
| CVE-2026-44230 | 6.1 | 5.1 | bestpractical | rt | CWE-79 | RT: Reflected Cross-Site Scripting in search results chart |
| CVE-2026-44228 | 5.4 | 4.7 | bestpractical | rt | CWE-79 | RT: Stored Cross-Site Scripting via insufficient template escaping |
| CVE-2026-2445 | 6.1 | 4.6 | WSO2 | WSO2 API Manager | CWE-79 | Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products En… |
| CVE-2026-12970 | 7.1 | 4.4 | Unknown | LearnPress | CWE-79 | LearnPress < 4.4.1 - Reflected XSS via c_search |
| CVE-2026-47144 | 5.5 | 4.4 | BKDDFS | shamefile | CWE-22 | Shamefile has an arbitrary file read via shamefile.yaml in shame next |
| CVE-2026-63728 | 8.1 | 4.3 | gitleaks | gitleaks | CWE-1336 | Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Rep… |
| CVE-2026-55219 | 5.3 | 4.2 | Paymenter | Paymenter | CWE-362 | Paymenter: Race condition in payWithCredit() enables credit double-spend |
| CVE-2026-46671 | 4.4 | 4.2 | msiemens | onenote.rs | CWE-22 | Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows r… |
| CVE-2026-61901 | 6.1 | 3.9 | hikashop.com | Hikashop extension for Joomla | CWE-601 | Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 |
| CVE-2026-12080 | 7.3 | 3.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-61 | Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in … |
| CVE-2026-44229 | 5.4 | 3.7 | bestpractical | rt | CWE-79 | RT: Cross-Site Scripting via inline-served uploaded content |
| CVE-2026-33327 | 7.0 | 3.2 | libvips | libvips | CWE-190 | Possible integer overflow leading to potential heap-based buffer overflow |
| CVE-2026-35591 | 7.0 | 3.2 | libvips | libvips | CWE-122 | Possible heap-based buffer overflow when decoding TIFF image containing well-… |
| CVE-2026-13156 | 5.4 | 3.1 | Unknown | MailerSend | CWE-352 | MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin… |
| CVE-2026-64191 | 7.8 | 2.8 | Linux | Linux | CWE-125 | i2c: stub: Reject I2C block transfers with invalid length |
| CVE-2026-55626 | 7.3 | 2.7 | neutrinolabs | xrdp | CWE-287 | xrdp: No authentication required with Xvnc backend on RHEL 9 |
| CVE-2026-64205 | 5.5 | 2.7 | Linux | Linux | — | i2c: i801: fix hardware state machine corruption in error path |
| CVE-2026-15905 | 7.8 | 2.2 | Chrome | CWE-416 | Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a loc… | |
| CVE-2026-33328 | 6.8 | 2.1 | libvips | libvips | CWE-190 | Possible integer overflow on 32-bit systems when reading GIF images |
| CVE-2026-35590 | 6.8 | 2.1 | libvips | libvips | CWE-122 | Possible out-of-bounds read leading to crash when decoding well-crafted EXIF … |
| CVE-2026-53592 | 4.6 | 2.1 | freescout-help-desk | freescout | CWE-1321 | FreeScout vulnerable to prototype pollution in getQueryParam |
| CVE-2026-64192 | 5.5 | 2.0 | Linux | Linux | CWE-476 | bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized |
| CVE-2026-64188 | 7.8 | 2.0 | Linux | Linux | CWE-416 | net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() |
| CVE-2026-44584 | 4.3 | 1.8 | Paymenter | Paymenter | CWE-345 | Paymenter doesn't reset email verification status after email change |
| CVE-2026-64187 | 5.5 | 1.7 | Linux | Linux | CWE-476 | xfs: fail recovery on a committed log item with no regions |
| CVE-2026-16246 | 7.3 | 1.7 | Bizerba SE & Co. KG | BRAIN2 | CWE-276 | Insecure permission assignment due to execution of LogPathConfig.exe during s… |
| CVE-2026-64650 | 6.3 | 1.6 | vercel | @ai-sdk/harness-codex | CWE-863 | AI SDK Codex Harness Tool Relay Authorization Bypass |
| CVE-2026-64651 | 6.3 | 1.6 | vercel | @ai-sdk/harness-opencode | CWE-863 | AI SDK OpenCode Harness Tool Relay Authorization Bypass |
| CVE-2026-64207 | 5.5 | 1.6 | Linux | Linux | CWE-476 | net/sched: dualpi2: fix GSO backlog accounting |
| CVE-2026-32823 | 4.3 | 1.3 | datacycle-engine | dataCycle-CORE | CWE-352 | dataCycle State-Changing GET Endpoints Enable CSRF |
| CVE-2026-47133 | 6.9 | 1.2 | craigjbass | clearancekit | CWE-294 | ClearanceKit's signed policy tables lack monotonic counter, allowing replay o… |
| CVE-2026-47134 | 6.9 | 1.2 | craigjbass | clearancekit | CWE-732 | ClearanceKit: Policy signing key in System Keychain has permissive ACL allowi… |
| CVE-2026-64190 | 5.5 | 1.2 | Linux | Linux | CWE-476 | net: team: fix NULL pointer dereference in team_xmit during mode change |
| CVE-2026-16247 | 7.3 | 1.1 | Bizerba SE & Co. KG | _connect.BRAIN | CWE-276 | Insecure permission overwrite due to execution of LogPathConfig.exe while ins… |
| CVE-2026-12724 | 4.3 | 1.0 | Unknown | Kirki | CWE-345 | Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via k… |
| CVE-2026-64189 | 7.8 | 0.8 | Linux | Linux | CWE-362 | netfilter: ipset: fix race between dump and ip_set_list resize |
| CVE-2026-10724 | 4.8 | 0.6 | Unknown | Reviews Feed | CWE-345 | Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution v… |
| CVE-2026-47128 | 6.1 | 0.5 | always-further | nono | CWE-863 | nono: Sandbox escape on Linux via D-Bus: `systemd-run --user` |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-20 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.