boxscore/security
Monday, July 20, 2026 · all times UTC← 2026-07-19 · archive · 2026-07-21 →

266 CVEs published July 20, 2026: 48 critical, 99 high, 115 medium, 4 low; 0 in KEV; 23 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 241 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1712446113022563
KEV catalog size1670

78 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
microsoft6391342959232998378312.37.8.0039+420
linux31112291789755702730.27.8.0014+264
red hat32131972455400.07.3.0030-3
apple0771175119379.16.5.00370
google8173110073529.48.8.0033+6
android010100161100.08.4.0171-1
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco7194610961263.28.6.2459+5
fortinet1017248028529.46.3.0051+9
palo alto networks1015017514213.34.7.0028+7
vmware7716002100.08.7.0044+7
f51540007120.09.2.04020
ivanti051000335100.010.0.8152-1
broadcom2400204250.05.1.0877+2
ubiquiti0431004375.010.0.74550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache12441125804012.37.5.0066-3
mozilla2732201300.08.1.0038+2
docker030120100.05.7.0015-3
gitlab02000042100.0.44510
github110010000.04.7.0017+1
drupal01100051100.09.8.88320
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm31391611120700.08.8.0029+31
adobe16279104075414.88.6.0144+9
oracle15220040360.08.7.1331-1
solarwinds041100114100.08.7.7758-1
atlassian0000001300
progress000000900
sap0000001200
servicenow000000200
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link12001026150.05.5.4518+1
rockwell automation111000000.09.2.0030+1
hikvision01000021100.01.00000
siemens010100100.08.7.00320
dahua000000200
qnap000000800
schneider electric000000100
tp-link000000600
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb5757326253000.07.1.0025+57
grafana639213213000.06.5.0033+4
open ises037214210000.06.9.00210
watchguard172811890400.07.3.0026+17
netty32551901000.07.5.0062-11
erlang624010113100.06.6.0033-1
python software foundation12317132000.06.0.0044-3
axios01601150000.07.4.0072-7

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4435910.0.0100
CVE-2026-5288710.0.0059
Most disclosures (vendor)
VendorCVEs
microsoft639
linux505
surrealdb57
red hat52
ibm39
apple37
watchguard17
adobe16
apache13
openclaw13
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco12
apple7
fortinet5
google5
ivanti5
adobe4
solarwinds4
synacor4
langflow3
Most-affected ecosystems
EcosystemAdvisories
Maven9
npm1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2023-4346KNX Association0
CVE-2025-67038Lantronix0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-25089Fortinet0
CVE-2026-34908Ubiquiti0
CVE-2026-34909Ubiquiti0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171706
CVE-2021-27102Accellion2021-11-171706
CVE-2021-27101Accellion2021-11-171706
CVE-2021-27103Accellion2021-11-171706
CVE-2021-21017Adobe2021-11-171706
CVE-2021-28550Adobe2021-11-171706
CVE-2021-42013Apache2021-11-171706
CVE-2021-41773Apache2021-11-171706
CVE-2021-30858Apple2021-11-171706
CVE-2021-30860Apple2021-11-171706

Transactions

EXPLOIT PUBLISHEDCVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-26197 (HDFGroup hdf5). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-26199 (HDFGroup hdf5). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-28220 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-32286 (github.com/jackc/pgproto3/v2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45709 (axllent mailpit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45711 (axllent mailpit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45712 (axllent mailpit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45713 (axllent mailpit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46701 (Jovancoding Network-AI). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47774 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48824 (axllent mailpit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58413 (Jovancoding Network-AI). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58414 (Jovancoding Network-AI). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58481 (Jovancoding Network-AI). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58482 (Jovancoding Network-AI). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58484 (Jovancoding Network-AI). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64620 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64621 (FreeRDP). Public exploit reference added.

DUE DATE PASSEDCVE-2026-25089 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-39808 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-58644 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 19, 2026; still in catalog.

RESCOREDCVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). CVSS 6.2 → 7.5 (NVD).

RESCOREDCVE-2024-35260 (Microsoft Power Platform). CVSS 8 → 9.8 (NVD).

RESCOREDCVE-2026-16074 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16076 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16077 (AstrBotDevs AstrBot). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-16081 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16083 (Sipeed PicoClaw). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16085 (Sipeed PicoClaw). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-16088 (halo-dev halo). CVSS 5.1 → 2 (NVD).

RESCOREDCVE-2026-16120 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16121 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16122 (nextlevelbuilder GoClaw). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-16124 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16126 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16127 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16128 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16130 (nearai ironclaw). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-16133 (LiuMengxuan04 MiniCode). CVSS 2.3 → 1.3 (NVD).

RESCOREDCVE-2026-16154 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16194 (zhayujie CowAgent). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16195 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16197 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16199 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16200 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16201 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16203 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).

RESCOREDCVE-2026-16205 (Pluck CMS). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-16209 (Gerapy). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16211 (allegro). CVSS 2.1 → 1.2 (NVD).

RESCOREDCVE-2026-16212 (awesto django-shop). CVSS 2.3 → 1.3 (NVD).

RESCOREDCVE-2026-16215 (geex-arts django-jet). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16217 (guohongze adminset). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16219 (Croogo CMS). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16222 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16225 (davenardella snap7). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16228 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-33845 (gnutls). CVSS 7.5 → 9.1 (NVD).

RESCOREDCVE-2026-3602 (IBM App Connect Enterprise). CVSS 4.7 → 5.5 (NVD).

RESCOREDCVE-2026-49790 (Microsoft Windows 10 Version 1607). CVSS 7.3 → 7.8 (NVD).

RESCOREDCVE-2026-50374 (Microsoft Windows 10 Version 1809). CVSS 6.3 → 6.8 (NVD).

RESCOREDCVE-2026-54991 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD).

RESCOREDCVE-2026-54992 (Microsoft Windows 10 Version 1607). CVSS 8.4 → 7.8 (NVD).

RESCOREDCVE-2026-54995 (Microsoft Windows 10 Version 1607). CVSS 8.1 → 9.8 (NVD).

RESCOREDCVE-2026-57973 (Microsoft Windows Subsystem for Linux (WSL2)). CVSS 6.3 → 4.7 (NVD).

RESCOREDCVE-2026-7872 (IBM Langflow OSS). CVSS 7.5 → 8.1 (NVD).

Yesterday's Results

266 CVEs published. 25 box scores, 241 table rows — nothing truncated.

RooCodeInc Roo-Code — Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   H    7.7   .0192   78.2     —
AFFECTED
  Product   Versions     Fixed
  Roo-Code  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-184 · CNA: VulnCheck · 2 references · NVD status: Deferred
RVC-Boss GPT-SoVITS — GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0175   75.9     —
AFFECTED
  Product     Versions     Fixed
  GPT-SoVITS  unspecified  —
TIMELINE
  Jul 18  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Deferred
EGroupware egroupware — Remote Code Execution Vulnerability in EGroupware
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0103   60.8     —
AFFECTED
  Product     Versions            Fixed
  egroupware  <= 26.2.20260216 –  —
TIMELINE
  Feb 24  Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-285 · CNA: GitHub_M · 1 reference · NVD status: Deferred
EGroupware egroupware — Authenticated RCE via Malicious eTemplate Upload in EGroupware
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0093   57.8     —
AFFECTED
  Product     Versions   Fixed
  egroupware  <= 26.0 –  —
TIMELINE
  Apr 9   Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-78, CWE-95 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Unknown Kirki — Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0091   57.1     —
AFFECTED
  Product  Versions     Fixed
  Kirki    unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 20  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Deferred
FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0085   55.2     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.28.0
TIMELINE
  Jul 20  Public exploit reference published
  Jul 20  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-122 · CNA: VulnCheck · 3 references · NVD status: Analyzed
n/a n/a — Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive infor…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0085   55.1     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jul 20  Published (CNA: mitre)
CWE-23 · CNA: mitre · 2 references · NVD status: Deferred
NLNETLABS Net::DNS — Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0083   54.5     —
AFFECTED
  Product   Versions     Fixed
  Net::DNS  unspecified  —
TIMELINE
  Jul 19  Reserved by CNA
  Jul 20  Published (CNA: CPANSec)
CWE-95 · CNA: CPANSec · 4 references · NVD status: Deferred
Red Hat multicluster engine for Kubernetes 2.1 — Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  L    9.4   .0080   53.5     —
AFFECTED
  Product                                    Versions     Fixed
  multicluster engine for Kubernetes 2.1     unspecified  1784905766
  multicluster engine for Kubernetes 2.1     unspecified  1784905766
  multicluster engine for Kubernetes 2.11    unspecified  1784945966
  multicluster engine for Kubernetes 2.17    unspecified  1784856942
  multicluster engine for Kubernetes 2.6     unspecified  1784905804
  multicluster engine for Kubernetes 2.8     unspecified  1784905783
  multicluster engine for Kubernetes 2.9.0   unspecified  1784905769
  Red Hat OpenShift Container Platform 4.16  unspecified  1785534428
  Red Hat OpenShift Container Platform 4.17  unspecified  1784914869
  Red Hat OpenShift Container Platform 4.18  unspecified  1784912882
  + 32 more
TIMELINE
  Jul 20  Reserved by CNA
  Jul 20  Published (CNA: redhat)
CWE-306 · CNA: redhat · 17 references · NVD status: Awaiting Analysis
MB connect line mbCONNECT24 — Authenticated RCE in system_certificates view
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0076   52.4     —
AFFECTED
  Product            Versions  Fixed
  mbCONNECT24        1.0.0 –   —
  mymbCONNECT24      1.0.0 –   —
  mbCONNECT24        2.20.0 –  —
  mymbCONNECT24      2.20.0 –  —
  myREX24V2          1.0.0 –   —
  myREX24V2.virtual  1.0.0 –   —
  myREX24V2          2.20.0 –  —
  myREX24V2.virtual  2.20.0 –  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 20  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · 2 references · NVD status: Deferred
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 — Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  L  H  H    9.0   .0076   52.2     —
AFFECTED
  Product                                             Versions     Fixed
  Red Hat Ansible Automation Platform 2.5 for RHEL 8  unspecified  0:3.49.63-2.el8ap
  Red Hat Ansible Automation Platform 2.5 for RHEL 9  unspecified  0:3.49.63-2.el9ap
  Red Hat Ansible Automation Platform 2.6 for RHEL 9  unspecified  0:3.49.63-2.el9ap
  Red Hat Satellite 6.16 for RHEL 8                   unspecified  0:3.49.39-2.el8pc
  Red Hat Satellite 6.16 for RHEL 8                   unspecified  0:3.49.39-2.el8pc
  Red Hat Satellite 6.16 for RHEL 9                   unspecified  0:3.49.39-2.el9pc
  Red Hat Satellite 6.16 for RHEL 9                   unspecified  0:3.49.39-2.el9pc
  Red Hat Satellite 6.17 for RHEL 9                   unspecified  0:3.63.21-2.el9pc
  Red Hat Satellite 6.17 for RHEL 9                   unspecified  0:3.63.21-2.el9pc
  Red Hat Satellite 6.18 for RHEL 9                   unspecified  0:3.73.30-2.el9pc
  + 8 more
TIMELINE
  Jun 19  Reserved by CNA
  Jul 20  Published (CNA: redhat)
CWE-22 · CNA: redhat · 10 references · NVD status: Awaiting Analysis
kvcache-ai ktransformers — ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0074   51.7     —
AFFECTED
  Product        Versions     Fixed
  ktransformers  unspecified  def0f9313d6e063b5c5ccdfa1f6707f7a40dfdca
TIMELINE
  Jul 18  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 4 references · NVD status: Deferred
D-Link DNS-320 upload.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0073   51.2     —
AFFECTED
  Product  Versions  Fixed
  DNS-320  1.0.2 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 20  Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · 6 references · NVD status: Deferred
Apache Syncope: Remote Code Execution via Scripted Connector
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.3     —
AFFECTED
  Product         Versions    Fixed
  Apache Syncope  3.0.0-M0 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-653 · CNA: apache · 2 references · NVD status: Analyzed
neutrinolabs xrdp — xrdp: lib_palette_update Heap Buffer Overflow & RCE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0061   46.3     —
AFFECTED
  Product  Versions      Fixed
  xrdp     < 0.10.6.1 –  —
TIMELINE
  Apr 18  Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-122 · CNA: GitHub_M · 2 references · NVD status: Analyzed
datacycle-engine dataCycle-CORE — dataCycle Public Markdown Path Traversal Via /docs/*path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0060   46.0     —
AFFECTED
  Product         Versions      Fixed
  dataCycle-CORE  <= 25.07.3 –  —
TIMELINE
  Mar 16  Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 1 reference · NVD status: Deferred
Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  L  N    7.1   .0059   45.6     —
AFFECTED
  Product           Versions  Fixed
  Apache MINA SSHD  2.0.0 –   —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-22 · CNA: apache · 1 reference · NVD status: Analyzed
Apache MINA SSHD: Path traversal in SCP file reception
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0057   44.4     —
AFFECTED
  Product           Versions     Fixed
  Apache MINA SSHD  unspecified  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-22, CWE-73 · CNA: apache · 2 references · NVD status: Analyzed
neutrinolabs xrdp — xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0051   41.3     —
AFFECTED
  Product  Versions      Fixed
  xrdp     < 0.10.6.1 –  —
TIMELINE
  May 5   Reserved by CNA
  Jul 20  Published (CNA: GitHub_M)
CWE-122 · CNA: GitHub_M · 2 references · NVD status: Analyzed
n/a n/a — An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and befor…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 20  Published (CNA: mitre)
CWE-94 · CNA: mitre · 2 references · NVD status: Deferred
ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0050   40.7     —
AFFECTED
  Product  Versions     Fixed
  proftpd  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 20  Published (CNA: VulnCheck)
CWE-122 · CNA: VulnCheck · 6 references · NVD status: Analyzed
Apache Syncope: SQL injection vulnerability in Audit Events search
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0050   40.3     —
AFFECTED
  Product         Versions    Fixed
  Apache Syncope  3.0.0-M0 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-89 · CNA: apache · 2 references · NVD status: Analyzed
Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.4     —
AFFECTED
  Product  Versions                   Fixed
  AC10     16.03.10.09_multi_TDE01 –  —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 20  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 6 references · NVD status: Deferred
Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0044   37.0     —
AFFECTED
  Product         Versions    Fixed
  Apache Syncope  3.0.0-M0 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-653 · CNA: apache · 2 references · NVD status: Analyzed
Apache Syncope: RCE via Groovy Sandbox bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0044   36.6     —
AFFECTED
  Product         Versions    Fixed
  Apache Syncope  3.0.0-M0 –  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 20  Published (CNA: apache)
CWE-653 · CNA: apache · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-641947.536.1NLNETLABSNet::DNSCWE-674Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS …
CVE-2024-513119.835.6n/an/aCWE-121The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the…
CVE-2026-81708.735.5Extreme NetworksSwitch Engine (EXOS)CWE-59ExtremeXOS Privilege Escalation via Symlink Following in File Utilities
CVE-2026-4641210.035.4BeProductbeproduct-org-nestjs-authCWE-506Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-H…
CVE-2026-578526.335.4Trilby MediaGrav CMS scheduler-webhook pluginCWE-303Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook To…
CVE-2026-586245.435.4Apache Software FoundationApache MINA SSHDCWE-20Apache MINA SSHD: Remote execution of JGit commands can write files on the se…
CVE-2026-558317.535.3nettynettyCWE-400Netty SPDY SETTINGS frame count materializes unbounded settings map
CVE-2026-558337.535.3nettynettyCWE-400Netty SPDY zlib header block continues decoded expansion after maxHeaderSize …
CVE-2026-488245.335.1axllentmailpitCWE-770Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /a…
CVE-2024-513129.834.9n/an/aCWE-121The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the…
CVE-2024-513139.834.9n/an/aCWE-121The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the…
CVE-2024-513149.834.9n/an/aCWE-121The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the…
CVE-2024-513159.834.9n/an/aCWE-121The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the…
CVE-2026-422105.334.9webminwebminCWE-287Webmin 2FA requirement bypass
CVE-2026-260803.734.7HAProxyHAProxyCWE-252HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop o…
CVE-2026-621839.834.3Apache Software FoundationApache SyncopeCWE-269Apache Syncope: User self-service privilege escalation
CVE-2026-646229.334.0JovancodingNetwork-AICWE-862Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox
CVE-2026-457976.433.6heyformheyformCWE-79HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload
CVE-2026-513856.933.3n/an/aCWE-94An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a …
CVE-2026-163379.433.2dotCMSdotCMSCWE-269Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoin…
CVE-2026-282209.132.8wazuhwazuhCWE-502Wazuh cluster DAPI arbitrary callable deserialization and RBAC context inject…
CVE-2026-415219.132.3neutrinolabsxrdpCWE-190xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass
CVE-2026-457137.532.0axllentmailpitCWE-400Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA…
CVE-2026-159038.831.9GoogleChromeCWE-125Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 a…
CVE-2026-545387.531.6neutrinolabsxrdpCWE-835xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER
CVE-2026-535959.430.5freescout-help-deskfreescoutCWE-178FreeScout vulnerable to anonymous account takeover via /user-setup empty invi…
CVE-2026-573115.330.5JCDWindu CMSCWE-434Unrestricted Upload of File with Dangerous Type in Windu CMS
CVE-2026-540519.930.1JovancodingNetwork-AICWE-78Network-AI has an an OS Command Injection issue
CVE-2026-488127.529.9freescout-help-deskfreescoutCWE-287FreeScout Allows Unauthenticated Access to Legacy Attachment Files
CVE-2026-260814.829.4HAProxyHAProxyCWE-130HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check f…
CVE-2026-637478.729.0surrealdbsurrealdbCWE-248SurrealDB before 3.1.0 Denial of Service via malformed RPC use
CVE-2026-637608.729.0surrealdbsurrealdbCWE-674SurrealDB before 3.1.0 Denial of Service via JSON Parser
CVE-2026-162359.828.8DRSTEVECrypt::PasswordCWE-338Crypt::Password versions through 0.28 for Perl generate insecure random value…
CVE-2026-637398.328.7surrealdbsurrealdbCWE-22SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER
CVE-2026-637578.728.6surrealdbsurrealdbCWE-306SurrealDB before 3.1.0 Session Hijacking via /rpc sessions
CVE-2026-646259.328.2WWBNAVideoCWE-78AVideo before 29.0 OS Command Injection via execAsync
CVE-2026-535944.928.2freescout-help-deskfreescoutCWE-22FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path
CVE-2026-646127.528.0Red HatRed Hat Enterprise Linux 10CWE-248Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort…
CVE-2026-159028.827.9GoogleChromeCWE-416Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a rem…
CVE-2026-600278.727.6themexpert.comQuix Page Builder Pro extension for JoomlaCWE-22Joomla Extension - themexpert.com - Unauthenticated path traversal / file rea…
CVE-2026-637377.127.6surrealdbsurrealdbCWE-674SurrealDB before 3.1.5 Denial of Service via deep operator chains
CVE-2026-250398.827.5Scilleparsec-cloudCWE-40The application evaluate UNC path in workspace name
CVE-2024-513167.527.3n/an/aCWE-400The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in …
CVE-2026-510279.927.3n/an/aCWE-200An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive …
CVE-2026-592386.926.0maalferPentestifyCWE-79Stored XSS in Pentestify via unsanitized finding images and report client logo
CVE-2026-159019.626.0GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a …
CVE-2026-637346.925.7surrealdbsurrealdbCWE-20SurrealDB before 3.2.0 Denial of Service via malformed SurrealML import
CVE-2026-614259.425.6balbooa.comGridbox extension for JoomlaCWE-288Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0
CVE-2026-445835.325.4PaymenterPaymenterCWE-918Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module
CVE-2026-350489.825.0PiwigoPiwigoCWE-20Piwigo RCE via PHP Code Injection into Config File in Installer
CVE-2026-113498.624.9UnknownModern Event Calendar ProCWE-89Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection …
CVE-2026-66567.524.4DRSTEVECrypt::PasswordCWE-208Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks
CVE-2026-573099.324.1JCDWindu CMSCWE-89Blind SQL Injection in Windu CMS
CVE-2026-449785.324.2neutrinolabsxrdpCWE-20xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-…
CVE-2026-600268.923.8themexpert.comQuix Page Builder Pro extension for JoomlaCWE-94Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix …
CVE-2026-457118.223.8axllentmailpitCWE-22Mailpit: Path traversal & arbitrary file write in mailpit dump --http via att…
CVE-2026-128986.523.5UnknownAll-in-One WP Migration and BackupCWE-22All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Locati…
CVE-2026-549107.723.3gtsteffaniakfilebrowserCWE-22FileBrowser Quantum's path traversal issue in subtitle handler allows any aut…
CVE-2026-552385.323.1neutrinolabsxrdpCWE-126xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads
CVE-2026-646219.323.0FreeRDPFreeRDPCWE-415FreeRDP before 3.28.0 Double-Free via selectedmonitors
CVE-2026-624188.122.7Apache Software FoundationApache SyncopeCWE-918Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources…
CVE-2026-158999.622.3GoogleChromeCWE-416Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.1…
CVE-2026-159009.622.3GoogleChromeCWE-416Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 all…
CVE-2026-159048.822.3GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 all…
CVE-2026-634298.622.4heyformheyformCWE-306HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files…
CVE-2026-328247.322.1datacycle-enginedataCycle-CORECWE-601dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Cont…
CVE-2026-328257.322.1datacycle-enginedataCycle-CORECWE-307dataCycle No Brute-Force Protection On Web And API Login Endpoints
CVE-2026-630917.122.0proftpdproftpdCWE-126ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser
CVE-2026-100818.821.7UnknownUnlimited Elements For ElementorCWE-79Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Go…
CVE-2026-342397.521.7chamilochamilo-lmsCWE-285Chamilo Authenticated Remote Code Execution
CVE-2026-135778.221.4CROMEDOMEDancer2CWE-338Dancer2 versions through 2.1.0 for Perl generate insecure session ids when re…
CVE-2026-510317.521.2n/an/aCWE-918FlareSolverr before version 3.4.7 contains a server-side request forgery (SSR…
CVE-2026-471988.521.2PaymenterPaymenterCWE-20Paymenter: URL parameter injection bypasses paid plan limits at checkout
CVE-2026-328067.521.2datacycle-enginedataCycle-CORECWE-285dataCycle Authorization Bypass Via /remote_render
CVE-2026-328077.521.2datacycle-enginedataCycle-CORECWE-285dataCycle Public DataLink Text File Download Ignores Validity And Authorization
CVE-2026-637467.121.2surrealdbsurrealdbCWE-200SurrealDB before 3.1.0 Permission Bypass via Graph Traversal
CVE-2026-535938.820.8freescout-help-deskfreescoutCWE-434FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete up…
CVE-2026-556456.520.8neutrinolabsxrdpCWE-125xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_d…
CVE-2026-574958.220.6agenticmail@agenticmail/coreCWE-306AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume o…
CVE-2026-467155.320.4pallets-ecoFlask-Security-TooCWE-287Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OA…
CVE-2026-81698.720.3Extreme NetworksSwitch Engine (EXOS)CWE-338ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG
CVE-2026-637506.920.3surrealdbsurrealdbCWE-770SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket
CVE-2026-162776.520.3Red HatRed Hat Enterprise Linux 10CWE-121Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
CVE-2026-163245.520.3Metasoft 美特软件MetaCRMCWE-284Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload
CVE-2026-157885.619.8mobyBuildKitCWE-59WCOW cache mount source selector resolves NTFS junctions outside of cache root
CVE-2026-637637.519.7surrealdbsurrealdbCWE-639SurrealDB before 2.5.0 Privilege Escalation via Future Fields
CVE-2026-162544.319.6Red HatRed Hat Advanced Cluster Security 4CWE-125Claircore: claircore: denial of service via out-of-bounds slice in claircore'…
CVE-2026-637569.219.3surrealdbsurrealdbCWE-362SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition
CVE-2026-546855.319.2gtsteffaniakfilebrowserCWE-208FileBrowser Quantum has Username Enumeration via Authentication Timing Side-C…
CVE-2026-158136.519.1Red HatRed Hat Enterprise Linux 10CWE-787Kronosnet: kronosnet: memory corruption and out-of-bounds access via malforme…
CVE-2026-451396.518.9ci4-cms-erpci4msCWE-73CI4MS Fileeditor allows deletion and rename of critical application files due…
CVE-2026-261975.918.9HDFGrouphdf5CWE-125Array full size, element count, and element size are not checked to make sure…
CVE-2026-637416.918.6surrealdbsurrealdbCWE-862SurrealDB before 3.1.0 Authentication Bypass via USE statement
CVE-2026-457095.818.5axllentmailpitCWE-918Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to…
CVE-2026-6142410.018.2dj-extensions.comDJ-Classifieds extension for JoomlaCWE-434Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload …
CVE-2026-6190010.018.2dj-extensions.comjDownloads extension for JoomlaCWE-434Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload …
CVE-2026-464108.718.2gtsteffaniakfilebrowserCWE-200FileBrowser Quantum: unauthenticated user share share info
CVE-2026-637358.618.2surrealdbsurrealdbCWE-639SurrealDB before 3.2.0 Authentication Bypass via Custom API
CVE-2026-162525.518.2Beijing Shenzhou Shihan TechnologyMultimedia Integrated Business Display SystemCWE-74Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display Sys…
CVE-2026-642068.818.1LinuxLinuxBluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
CVE-2026-465164.817.9mwtcmifrogmanCWE-79Frogman vulnerable to stored XSS in chat console formatter (escalation vector…
CVE-2026-637407.117.6surrealdbsurrealdbCWE-863SurrealDB before 3.1.4 Array Element Permission Bypass
CVE-2026-261995.917.4HDFGrouphdf5CWE-124Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
CVE-2026-637547.117.1surrealdbsurrealdbCWE-754SurrealDB before 3.1.0 Denial of Service via LIVE Query
CVE-2026-637597.117.1surrealdbsurrealdbCWE-674SurrealDB before 3.1.0 Denial of Service nested type annotations
CVE-2026-637626.017.1surrealdbsurrealdbCWE-476SurrealDB before v2.6.1 Denial of Service via scripting
CVE-2026-556395.317.1neutrinolabsxrdpCWE-125xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY process…
CVE-2026-523497.816.9n/an/aCWE-22Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa4…
CVE-2026-600316.916.9themexpert.comQuix Page Builder Pro extension for JoomlaCWE-200Joomla Extension - themexpert.com - Information disclosure in Quix Page Build…
CVE-2026-422185.316.6neutrinolabsxrdpCWE-204XRDP is vulnerable to a server timing attack, leading to user enumeration
CVE-2026-442319.116.5bestpracticalrtCWE-200RT: Privilege escalation and information disclosure via REST 2.0 user collect…
CVE-2026-634285.816.5heyformheyformCWE-20HeyForm: completeSubmission persists submitter-supplied hidden fields verbati…
CVE-2026-600349.416.2themexpert.comJMedia extension for JoomlaCWE-79Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extens…
CVE-2026-600288.616.2themexpert.comQuix Page Builder Pro extension for JoomlaCWE-79Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Bui…
CVE-2026-457125.916.3axllentmailpitCWE-362Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth cr…
CVE-2026-600295.116.2themexpert.comQuix Page Builder Pro extension for JoomlaCWE-79Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Bui…
CVE-2026-631025.316.1rConfigrConfig v8 CoreCWE-915rConfig Core < 8.2.8 Privilege Escalation via Users API role field
CVE-2026-637716.015.7vranaadminerCWE-113Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
CVE-2026-600329.415.6themexpert.comJMedia extension for JoomlaCWE-434Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JM…
CVE-2026-600308.715.3themexpert.comQuix Page Builder Pro extension for JoomlaCWE-284Joomla Extension - themexpert.com - Broken Access Control for media managemen…
CVE-2026-507435.415.2ReviveAdserverCWE-352A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserv…
CVE-2026-637316.315.1hyperdxiohyperdxCWE-918HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint
CVE-2026-535965.315.0freescout-help-deskfreescoutCWE-400FreeScout has unrestricted file upload without rate limiting that leads to re…
CVE-2026-398789.314.8chamilochamilo-lmsCWE-79Chamilo stored XSS via user registration leads to admin account takeover
CVE-2026-218248.814.8HCLSoftwareCommerceCWE-266A privilege escalation vulnerability affects HCL Commerce
CVE-2026-133809.014.6VSeeClinicCWE-201VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTT…
CVE-2026-472766.514.6nanomqnanomqCWE-476NULL Pointer Dereference in REST API properties_parse via Malformed user_prop…
CVE-2026-351989.014.5heyformheyformCWE-79HeyForm vulnerable to stored XSS via form field titles
CVE-2026-88254.914.6UnknownElementor Website BuilderCWE-200Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API
CVE-2026-637305.314.4hyperdxiohyperdxCWE-918HyperDX < 2.31.0 SSRF via Webhook Test Endpoint
CVE-2026-637445.114.5surrealdbsurrealdbCWE-918SurrealDB before 3.1.5 SSRF via JWKS URL Redirect
CVE-2026-624149.114.3joomlack.frPage Builder CK extension for JoomlaCWE-284Joomla Extension - joomlack.fr - Improper access control in Page Builder CK <…
CVE-2026-637696.314.1huginnhuginnCWE-918Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method
CVE-2026-600335.113.9themexpert.comJMedia extension for JoomlaCWE-918Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extens…
CVE-2026-131428.113.6UnknownSocial Login, Passkeys, Magic Link & Email OTPCWE-269Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeove…
CVE-2026-637365.113.6surrealdbsurrealdbCWE-918SurrealDB before 3.2.0 SSRF via JWKS URL hostname resolution
CVE-2026-471298.113.1pdovhomiljanextcrm-appCWE-862NextCRM has Broken Access Control in Server Actions that allows any authentic…
CVE-2026-467017.613.2JovancodingNetwork-AICWE-346Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Defaul…
CVE-2026-393857.112.7frappelmsCWE-288Frappe LMS enrollment bypass in paid courses via unrelated batch
CVE-2026-574947.112.7agenticmail@agenticmail/apiCWE-639AgenticMail: Cross-agent task authorization bypass in AgenticMail API
CVE-2026-123419.812.3SailPoint TechnologiesIdentityIQCWE-287SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability
CVE-2026-535918.612.2freescout-help-deskfreescoutCWE-287FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMA…
CVE-2026-510256.112.0n/an/aCWE-79Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 al…
CVE-2026-328226.111.7datacycle-enginedataCycle-CORECWE-80dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages
CVE-2026-637425.311.6surrealdbsurrealdbCWE-863SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT
CVE-2026-637557.111.5surrealdbsurrealdbCWE-863SurrealDB before 3.1.0 Permission Bypass via WHERE Clause
CVE-2026-637495.311.5surrealdbsurrealdbCWE-863SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT
CVE-2026-133818.711.3VSeeClinicCWE-639VSee Clinic and API Insecure Direct Object Reference in File API Allows Unaut…
CVE-2026-631076.311.3LimeSurveyLimeSurveyCWE-918LimeSurvey SSRF via REST API Survey Template Host Header
CVE-2026-452708.711.1ci4-cms-erpci4msCWE-79CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
CVE-2026-584847.111.1JovancodingNetwork-AICWE-22Network-AI: Poisoned environment backup manifest allows arbitrary recursive d…
CVE-2026-125927.510.7UnknownSlimStat AnalyticsCWE-79SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header
CVE-2026-637385.310.7surrealdbsurrealdbCWE-863SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal
CVE-2026-637535.310.7surrealdbsurrealdbCWE-613SurrealDB before 3.1.0 Authentication Bypass via LIVE Query
CVE-2026-584816.510.5JovancodingNetwork-AICWE-22Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside…
CVE-2026-584136.110.5JovancodingNetwork-AICWE-22EnvironmentManager.restore() backup ID path traversal copies arbitrary direct…
CVE-2026-584145.510.5JovancodingNetwork-AICWE-22Network-AI: EnvironmentManager.backup() follows symlinked directories and cop…
CVE-2026-127235.310.6UnknownKirkiCWE-862Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderatio…
CVE-2026-646198.710.4vastsaFileCodeBoxCWE-348FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
CVE-2026-137244.310.4Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co.Corporate Training Management SystemCWE-602Business Logic Bypass in Gobito's Corporate Training Management System
CVE-2026-328218.110.3datacycle-enginedataCycle-CORECWE-285API Collection Impersonation Via user_email And Missing Object- Level Authori…
CVE-2026-637335.310.4surrealdbsurrealdbCWE-863SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause
CVE-2026-646238.810.1JovancodingNetwork-AICWE-347Network-AI before 5.13.4 Cryptographic Signature Verification Bypass
CVE-2026-452956.510.1freescout-help-deskfreescoutCWE-639FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and C…
CVE-2026-162442.110.2itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System prescriptionorderreport.php sql injec…
CVE-2026-637708.29.9glanceappglanceCWE-348Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
CVE-2026-328194.39.8datacycle-enginedataCycle-CORECWE-285dataCycle User Directory Enumeration Via /users/search
CVE-2026-637685.39.7calcomcal.diyCWE-601cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State
CVE-2026-555507.19.5pdovhomiljanextcrm-appCWE-269NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users…
CVE-2026-352176.59.4nanomqnanomqCWE-125NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an AS…
CVE-2026-637485.39.3surrealdbsurrealdbCWE-209SurrealDB before 3.1.0 Information Disclosure via Error Messages
CVE-2026-155885.39.2Red HatRed Hat Enterprise Linux 9CWE-770Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl lin…
CVE-2026-464289.19.1lettrelettreCWE-295lettre has TLS hostname verification disabled when using Boring TLS backend
CVE-2026-465557.18.7verygoodpluginswhatsapp-mcpCWE-22WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary…
CVE-2026-129006.48.6brainstormforceSpectra Legacy – Gutenberg BlocksCWE-79Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cro…
CVE-2026-483897.88.5AdobeDNG SDKCWE-121DNG SDK | Stack-based Buffer Overflow (CWE-121)
CVE-2026-646265.38.5WWBNAVideoCWE-918AVideo Encoder downloadURL SSRF via unpinned retry fallback
CVE-2026-118685.38.0UnknownWP TravelCWE-862WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
CVE-2026-637585.37.9surrealdbsurrealdbCWE-862SurrealDB before 3.1.0 Authorization Bypass via KILL Statement
CVE-2026-646248.57.9FreeRDPFreeRDPCWE-88FreeRDP RDP File Parser Remote Code Execution via CLI Options
CVE-2026-555447.67.9pdovhomiljanextcrm-appCWE-284NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign D…
CVE-2026-637435.37.8surrealdbsurrealdbCWE-918SurrealDB before 3.1.0 Port-Specific Deny Rule Bypass via HTTP Redirect
CVE-2026-637455.37.8surrealdbsurrealdbCWE-639SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id
CVE-2026-472558.27.6agenticmail@agenticmail/apiCWE-20AgenticMail API/storage and outbound relay hardening
CVE-2026-566247.37.6Apache Software FoundationApache MINA SSHDCWE-295Apache MINA SSHD: SSH certificate options lack validations
CVE-2026-445855.47.6PaymenterPaymenterCWE-639Paymenter: Broken object level authorization via service reference manipulati…
CVE-2026-129725.37.4UnknownPayPlus Payment GatewayCWE-284PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tamp…
CVE-2026-573106.37.2JCDWindu CMSCWE-916Weak password hashing in Windu CMS
CVE-2026-637515.37.1surrealdbsurrealdbCWE-863SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch
CVE-2026-398797.16.9syslog-ngsyslog-ngCWE-150SQL injection in syslog-ng SQL destionation driver
CVE-2026-134325.46.7UnknownThumbPressCWE-862ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation
CVE-2026-472752.66.6nanomqnanomqCWE-476nanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to R…
CVE-2026-107552.76.6UnknownAll in One SEOCWE-863All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration
CVE-2026-637525.36.3surrealdbsurrealdbCWE-285SurrealDB before 3.1.0 RELATE Statement Record Overwrite
CVE-2026-98337.16.0UnknownTag Groups is the Advanced Way to Display Your Taxonomy TermsCWE-79Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
CVE-2026-264836.16.0n/an/aCWE-79Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (X…
CVE-2026-637615.36.0surrealdbsurrealdbCWE-327SurrealDB before 3.1.0 Algorithm Downgrade via ES512
CVE-2026-471307.15.8pdovhomiljanextcrm-appCWE-639NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Ten…
CVE-2026-67935.45.9Bifra Engineering Consulting Ltd.Q-smart NexT PollCWE-79Stored XSS in Bifra Engineering's Q-smart NexT Poll
CVE-2026-464158.25.7JasonLovesDoggocaddy-defenderCWE-284Caddy Defender trusted proxy client IP bypass
CVE-2026-129736.55.7UnknownPayPlus Payment GatewayCWE-862PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Or…
CVE-2026-584825.95.6JovancodingNetwork-AICWE-352Network-AI: ApprovalInbox HTTP server has no authentication — anyone can appr…
CVE-2026-442276.15.1bestpracticalrtCWE-79RT: Reflected Cross-Site Scripting via URL parameters
CVE-2026-442306.15.1bestpracticalrtCWE-79RT: Reflected Cross-Site Scripting in search results chart
CVE-2026-442285.44.7bestpracticalrtCWE-79RT: Stored Cross-Site Scripting via insufficient template escaping
CVE-2026-24456.14.6WSO2WSO2 API ManagerCWE-79Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products En…
CVE-2026-129707.14.4UnknownLearnPressCWE-79LearnPress < 4.4.1 - Reflected XSS via c_search
CVE-2026-471445.54.4BKDDFSshamefileCWE-22Shamefile has an arbitrary file read via shamefile.yaml in shame next
CVE-2026-637288.14.3gitleaksgitleaksCWE-1336Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Rep…
CVE-2026-552195.34.2PaymenterPaymenterCWE-362Paymenter: Race condition in payWithCredit() enables credit double-spend
CVE-2026-466714.44.2msiemensonenote.rsCWE-22Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows r…
CVE-2026-619016.13.9hikashop.comHikashop extension for JoomlaCWE-601Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2
CVE-2026-120807.33.8Red HatRed Hat Enterprise Linux 10CWE-61Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in …
CVE-2026-442295.43.7bestpracticalrtCWE-79RT: Cross-Site Scripting via inline-served uploaded content
CVE-2026-333277.03.2libvipslibvipsCWE-190Possible integer overflow leading to potential heap-based buffer overflow
CVE-2026-355917.03.2libvipslibvipsCWE-122Possible heap-based buffer overflow when decoding TIFF image containing well-…
CVE-2026-131565.43.1UnknownMailerSendCWE-352MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin…
CVE-2026-641917.82.8LinuxLinuxCWE-125i2c: stub: Reject I2C block transfers with invalid length
CVE-2026-556267.32.7neutrinolabsxrdpCWE-287xrdp: No authentication required with Xvnc backend on RHEL 9
CVE-2026-642055.52.7LinuxLinuxi2c: i801: fix hardware state machine corruption in error path
CVE-2026-159057.82.2GoogleChromeCWE-416Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a loc…
CVE-2026-333286.82.1libvipslibvipsCWE-190Possible integer overflow on 32-bit systems when reading GIF images
CVE-2026-355906.82.1libvipslibvipsCWE-122Possible out-of-bounds read leading to crash when decoding well-crafted EXIF …
CVE-2026-535924.62.1freescout-help-deskfreescoutCWE-1321FreeScout vulnerable to prototype pollution in getQueryParam
CVE-2026-641925.52.0LinuxLinuxCWE-476bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
CVE-2026-641887.82.0LinuxLinuxCWE-416net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
CVE-2026-445844.31.8PaymenterPaymenterCWE-345Paymenter doesn't reset email verification status after email change
CVE-2026-641875.51.7LinuxLinuxCWE-476xfs: fail recovery on a committed log item with no regions
CVE-2026-162467.31.7Bizerba SE & Co. KGBRAIN2CWE-276Insecure permission assignment due to execution of LogPathConfig.exe during s…
CVE-2026-646506.31.6vercel@ai-sdk/harness-codexCWE-863AI SDK Codex Harness Tool Relay Authorization Bypass
CVE-2026-646516.31.6vercel@ai-sdk/harness-opencodeCWE-863AI SDK OpenCode Harness Tool Relay Authorization Bypass
CVE-2026-642075.51.6LinuxLinuxCWE-476net/sched: dualpi2: fix GSO backlog accounting
CVE-2026-328234.31.3datacycle-enginedataCycle-CORECWE-352dataCycle State-Changing GET Endpoints Enable CSRF
CVE-2026-471336.91.2craigjbassclearancekitCWE-294ClearanceKit's signed policy tables lack monotonic counter, allowing replay o…
CVE-2026-471346.91.2craigjbassclearancekitCWE-732ClearanceKit: Policy signing key in System Keychain has permissive ACL allowi…
CVE-2026-641905.51.2LinuxLinuxCWE-476net: team: fix NULL pointer dereference in team_xmit during mode change
CVE-2026-162477.31.1Bizerba SE & Co. KG_connect.BRAINCWE-276Insecure permission overwrite due to execution of LogPathConfig.exe while ins…
CVE-2026-127244.31.0UnknownKirkiCWE-345Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via k…
CVE-2026-641897.80.8LinuxLinuxCWE-362netfilter: ipset: fix race between dump and ip_set_list resize
CVE-2026-107244.80.6UnknownReviews FeedCWE-345Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution v…
CVE-2026-471286.10.5always-furthernonoCWE-863nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-20 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.