boxscore/security
Wednesday, July 22, 2026 · all times UTC← 2026-07-21 · archive · 2026-07-23 →

198 CVEs published July 22, 2026: 17 critical, 103 high, 65 medium, 13 low; 1 in KEV; 3 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 173 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published3387613613222563
KEV catalog size1670

118 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
microsoft6391342959232998378322.47.8.0039+420
linux31112291789755702730.27.8.0014+263
red hat61160982609400.07.1.0029+24
apple0771175119379.16.5.00370
google22316201173516.18.8.0030+20
canonical330210000.07.8.0013+3
android010100161100.08.4.0171-1
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco7194610961263.28.6.2459+5
fortinet1017248028529.46.3.0051+9
palo alto networks1015017514213.34.7.0028+7
vmware7716002100.08.7.0044+7
f51540007120.09.2.04020
ivanti051000335100.010.0.8152-1
checkpoint3431003250.09.2.4696+2
broadcom2400204250.05.1.0877+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
mozilla67724226401300.09.1.0031+67
apache16481426804012.17.5.0063+1
docker030120100.05.7.0015-3
wordpress22101052100.07.9.8435+2
gitlab02000042100.0.44510
github110010000.04.7.0017+1
drupal01100051100.09.8.88320
jenkins000000600
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091113212539304574030.37.6.0031+1107
ibm32401611130700.08.4.0028+31
adobe16279104075414.88.6.0144+9
solarwinds15191511011421.19.1.0044+14
progress141401040900.07.5.0033+14
atlassian3303001300.08.0.0026+3
zohocorp220110000.05.7.0038+2
veeam110100400.08.4.0013+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link78006126112.55.5.0073+7
hikvision5603202116.77.2.0024+5
rockwell automation111000000.09.2.0030+1
siemens010100100.08.7.00320
dahua000000200
qnap000000800
schneider electric000000100
tp-link000000600
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb5757326253000.07.1.0025+57
grafana639213213000.06.5.00330
open ises037214210000.06.9.00210
netty103262411000.07.5.0051-4
watchguard172811890400.07.3.0026+17
nlnet labs242704176000.05.9.0024+24
mongodb262611771200.07.1.0023+26
mervinpraison252581340000.08.3.0028+25

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-898510.0.0660
CVE-2026-4435910.0.0100
Most disclosures (vendor)
VendorCVEs
oracle1109
microsoft639
linux504
red hat79
mozilla67
surrealdb57
ibm39
apple37
mongodb26
mervinpraison25
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco12
apple7
fortinet5
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven11
crates.io1
npm1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-67038Lantronix0
CVE-2026-0770Langflow0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-20230Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171708
CVE-2021-27102Accellion2021-11-171708
CVE-2021-27101Accellion2021-11-171708
CVE-2021-27103Accellion2021-11-171708
CVE-2021-21017Adobe2021-11-171708
CVE-2021-28550Adobe2021-11-171708
CVE-2021-42013Apache2021-11-171708
CVE-2021-41773Apache2021-11-171708
CVE-2021-30858Apple2021-11-171708
CVE-2021-30860Apple2021-11-171708

Transactions

EXPLOIT PUBLISHEDCVE-2016-20096 (Kunshi Network Technology Co., Ltd. Linknat VOS3000). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-27137 (DD-WRT). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-60689. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16329 (D-Link DNS-320). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16331 (D-Link DNS-320). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16332 (D-Link DNS-320). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16334 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16447 (D-Link DNS-320). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16449 (zsadmin2025 ZS-Admin). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16450 (zsadmin2025 ZS-Admin). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16451 (zsadmin2025 ZS-Admin). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16484 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16485 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16486 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-20230 (Cisco Unified Communications Manager). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48029 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50475 (Microsoft Windows 10 Version 1607). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5497 (vllm-project/vllm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58613 (Microsoft Windows 10 Version 1809). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63080 (aptabase). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63107 (LimeSurvey). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64821 (thiagopena djangoSIGE). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64822 (thiagopena djangoSIGE). Public exploit reference added.

RESCOREDCVE-2022-2712 (The Eclipse Foundation Eclipse GlassFish). CVSS 6.5 → 7.5 (NVD).

RESCOREDCVE-2026-16073 (AstrBotDevs AstrBot). CVSS 5.1 → 2 (NVD).

RESCOREDCVE-2026-16082 (Sipeed PicoClaw). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-16123 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16129 (princezuda SafestClaw). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-16152 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16196 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16202 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD).

RESCOREDCVE-2026-16214 (geex-arts django-jet). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16220 (code-projects Online Examination System). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-16227 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-16488 (QUSETIONS MiniCode-Python). CVSS 2.3 → 1.3 (NVD).

RESCOREDCVE-2026-16489 (jsforce). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-28369 (Red Hat JBoss Enterprise Application Platform 8.1). CVSS 8.7 → 9.1 (NVD).

RESCOREDCVE-2026-3833 (gnutls). CVSS 6.5 → 7.4 (NVD).

RESCOREDCVE-2026-44806 (Microsoft Windows 10 Version 1607). CVSS 5.3 → 7.5 (NVD).

RESCOREDCVE-2026-49164 (Microsoft Windows 10 Version 1607). CVSS 8.1 → 9.8 (NVD).

RESCOREDCVE-2026-49167 (Microsoft Windows 10 Version 1809). CVSS 4.7 → 7.8 (NVD).

RESCOREDCVE-2026-49171 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 7.8 (NVD).

RESCOREDCVE-2026-49184 (Microsoft Windows 10 Version 1607). CVSS 8.4 → 7.8 (NVD).

RESCOREDCVE-2026-49789 (Microsoft Windows 10 Version 1607). CVSS 7.3 → 7.8 (NVD).

RESCOREDCVE-2026-49791 (Microsoft Windows 10 Version 1607). CVSS 7.1 → 7.8 (NVD).

RESCOREDCVE-2026-50302 (Microsoft Windows 10 Version 21H2). CVSS 4.2 → 6.5 (NVD).

RESCOREDCVE-2026-50307 (Microsoft Windows 10 Version 1809). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2026-50312 (Microsoft Windows 10 Version 1607). CVSS 4.7 → 7.8 (NVD).

RESCOREDCVE-2026-50321 (Microsoft Windows 10 Version 1607). CVSS 7.8 → 7 (NVD).

RESCOREDCVE-2026-50330 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 9.8 (NVD).

RESCOREDCVE-2026-50340 (Microsoft Windows 11 Version 24H2). CVSS 8.5 → 8.8 (NVD).

RESCOREDCVE-2026-50348 (Microsoft Windows 10 Version 1809). CVSS 7 → 8.1 (NVD).

RESCOREDCVE-2026-50358 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2026-50359 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2026-50375 (Microsoft Windows 10 Version 1809). CVSS 6.3 → 7.8 (NVD).

RESCOREDCVE-2026-50378 (Microsoft Windows 10 Version 1809). CVSS 7.8 → 7 (NVD).

RESCOREDCVE-2026-50383 (Microsoft Windows 10 Version 1809). CVSS 6.1 → 5.5 (NVD).

RESCOREDCVE-2026-50390 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2026-50393 (Microsoft Windows 11 Version 24H2). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2026-50396 (Microsoft Windows 11 Version 24H2). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2026-50398 (Microsoft Windows 11 Version 24H2). CVSS 8.8 → 7.5 (NVD).

RESCOREDCVE-2026-50413 (Microsoft Windows 11 Version 24H2). CVSS 8.8 → 7.8 (NVD).

RESCOREDCVE-2026-50414 (Microsoft Windows 11 Version 24H2). CVSS 7.5 → 8.8 (NVD).

RESCOREDCVE-2026-50415 (Microsoft Windows 10 Version 1809). CVSS 5.3 → 7.5 (NVD).

RESCOREDCVE-2026-50418 (Microsoft Windows 11 Version 24H2). CVSS 5.1 → 6.1 (NVD).

RESCOREDCVE-2026-50420 (Microsoft Windows 11 Version 24H2). CVSS 6.2 → 5.5 (NVD).

RESCOREDCVE-2026-50428 (Microsoft Windows 11 version 26H1). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2026-50432 (Microsoft Windows 10 Version 1607). CVSS 5.3 → 6.5 (NVD).

RESCOREDCVE-2026-50439 (Microsoft Windows 10 Version 1607). CVSS 8.1 → 9.8 (NVD).

RESCOREDCVE-2026-50445 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD).

RESCOREDCVE-2026-50450 (Microsoft Windows 10 Version 1809). CVSS 7.8 → 7 (NVD).

RESCOREDCVE-2026-50451 (Microsoft Windows 10 Version 1607). CVSS 7.1 → 7.8 (NVD).

RESCOREDCVE-2026-50452 (Microsoft Windows 10 Version 1809). CVSS 7 → 8.1 (NVD).

ENRICHEDCVE-2025-48595 (Android Framework). Received CVSS 8.4 and CPE data from NVD.

ENRICHEDCVE-2026-20230 (Cisco Unified Communications Manager). Received CVSS 8.6 and CPE data from NVD.

ENRICHEDCVE-2026-28318 (SolarWinds Serv-U). Received CVSS 7.5 and CPE data from NVD.

+ 50 more transactions — continued on page 2. Every change is listed; nothing truncated.

Yesterday's Results

198 CVEs published. 25 box scores, 173 table rows — nothing truncated.

checkpoint Quantum Security Management — Authentication Bypass in the SmartConsole Login Process Using an Application Token
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .7330   99.4   YES
AFFECTED
  Product                           Versions                                     Fixed
  Quantum Security Management       R82.10 with Jumbo Hotfix Take 36 or below –  —
  Multi-Domain Security Management  R82.10 with Jumbo Hotfix Take 36 or below –  —
TIMELINE
  Jul 19  Reserved by CNA
  Jul 22  Added to CISA KEV, due Jul 25
  Jul 22  Published (CNA: checkpoint)
CWE-287 · CNA: checkpoint · 2 references · NVD status: Analyzed · KEV due July 25, 2026
checkpoint Quantum Security Management — Management Authentication Bypass and Privilege Escalation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .2062   97.3     —
AFFECTED
  Product                           Versions                                     Fixed
  Quantum Security Management       R82.10 with Jumbo Hotfix Take 36 or below –  —
  Multi-Domain Security Management  R82.10 with Jumbo Hotfix Take 36 or below –  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 22  Published (CNA: checkpoint)
CWE-287 · CNA: checkpoint · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — Local Privilege Escalation in Gaia Portal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0754   94.0     —
AFFECTED
  Product                      Versions                                     Fixed
  Quantum Security Gateway     R82.10 with Jumbo Hotfix Take 36 or below –  —
  Quantum Security Management  R82.10 with Jumbo Hotfix Take 36 or below –  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 22  Published (CNA: checkpoint)
CWE-269 · CNA: checkpoint · 1 reference · NVD status: Awaiting Analysis
umijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   L   N   L   L   L    2.0   .0166   74.7     —
AFFECTED
  Product  Versions  Fixed
  umi      4.6.0 –   4.6.64
TIMELINE
  Jul 21  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 9 references · NVD status: Deferred
Fujitsu Linux openFT — Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0065   48.3     —
AFFECTED
  Product                Versions     Fixed
  Linux openFT           unspecified  12.1D00
  Oracle Solaris openFT  unspecified  12.1D00
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: FTI)
CWE-94 · CNA: FTI · 3 references · NVD status: Deferred
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0063   47.5     —
AFFECTED
  Product                     Versions  Fixed
  ej2-javascript-ui-controls  33.2.0 –  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
n/a publint — publint package-manager pack.js child_process.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0063   47.5     —
AFFECTED
  Product  Versions  Fixed
  publint  0.1.0 –   —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 8 references · NVD status: Deferred
danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    4.8   .0062   46.9     —
AFFECTED
  Product    Versions  Fixed
  danger-js  13.0.0 –  13.0.8
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 8 references · NVD status: Deferred
n/a oclif — oclif JIT Plugin Entry child_process.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0062   46.9     —
AFFECTED
  Product  Versions  Fixed
  oclif    4.23.0 –  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 8 references · NVD status: Deferred
n/a n/a — An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privil…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0057   44.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 22  Published (CNA: mitre)
CWE-693 · CNA: mitre · 3 references · NVD status: Deferred
Red Hat Red Hat Ansible Automation Platform 2 — Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filename
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0054   42.7     —
AFFECTED
  Product                                Versions     Fixed
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
TIMELINE
  May 5   Reserved by CNA
  Jul 22  Published (CNA: redhat)
CWE-88 · CNA: redhat · 2 references · NVD status: Awaiting Analysis
Progress Software Telerik UI for ASP.NET AJAX — AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0053   42.5     —
AFFECTED
  Product                      Versions      Fixed
  Telerik UI for ASP.NET AJAX  2013.1.220 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: ProgressSoftware)
CWE-22 · CNA: ProgressSoftware · 1 reference · NVD status: Analyzed
ISC BIND 9 — Unnecessary validation of DNSSEC signed records
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0052   42.1     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.20.0 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 22  Published (CNA: isc)
CWE-408 · CNA: isc · 3 references · NVD status: Undergoing Analysis
Chimpstudio WP Foodbakery — WP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0052   41.6     —
AFFECTED
  Product        Versions     Fixed
  WP Foodbakery  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 22  Published (CNA: Wordfence)
CWE-23 · CNA: Wordfence · 2 references · NVD status: Deferred
ISC BIND 9 — Potential memory usage beyond configured limits
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0051   41.1     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.11.0 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 22  Published (CNA: isc)
CWE-770 · CNA: isc · 3 references · NVD status: Undergoing Analysis
ISC BIND 9 — Unexpected exit in certain situations with NSEC and NSEC3 both present
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0051   41.1     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.11.0 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: isc)
CWE-617 · CNA: isc · 3 references · NVD status: Undergoing Analysis
FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0050   40.7     —
AFFECTED
  Product  Versions  Fixed
  FFmpeg   0.6.3 –   —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 22  Published (CNA: VulnCheck)
CWE-835 · CNA: VulnCheck · 3 references · NVD status: Analyzed
ISC BIND 9 — Record ordering based unexpected exit with CNAME or DNAME
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0049   39.9     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.18.0 –  —
TIMELINE
  Jun 18  Reserved by CNA
  Jul 22  Published (CNA: isc)
CWE-617 · CNA: isc · 2 references · NVD status: Undergoing Analysis
Progress Software Telerik UI for ASP.NET AJAX — PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0049   39.7     —
AFFECTED
  Product                      Versions      Fixed
  Telerik UI for ASP.NET AJAX  2013.1.220 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: ProgressSoftware)
CWE-502 · CNA: ProgressSoftware · 1 reference · NVD status: Analyzed
Progress Software Telerik UI for ASP.NET AJAX — RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0049   39.7     —
AFFECTED
  Product                      Versions      Fixed
  Telerik UI for ASP.NET AJAX  2010.1.309 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: ProgressSoftware)
CWE-470 · CNA: ProgressSoftware · 1 reference · NVD status: Analyzed
Progress Software Telerik UI for ASP.NET AJAX — PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0049   39.7     —
AFFECTED
  Product                      Versions      Fixed
  Telerik UI for ASP.NET AJAX  2011.2.712 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 22  Published (CNA: ProgressSoftware)
CWE-502 · CNA: ProgressSoftware · 1 reference · NVD status: Analyzed
Red Hat Red Hat Ansible Automation Platform 2 — Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0047   38.9     —
AFFECTED
  Product                                Versions     Fixed
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
  Red Hat Ansible Automation Platform 2  unspecified  —
TIMELINE
  May 5   Reserved by CNA
  Jul 22  Published (CNA: redhat)
CWE-78 · CNA: redhat · 2 references · NVD status: Awaiting Analysis
n8n-io n8n — n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    8.9   .0047   38.7     —
AFFECTED
  Product  Versions     Fixed
  n8n      unspecified  1.123.64
  n8n      unspecified  2.30.1
  n8n      unspecified  2.29.8
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulnCheck)
CWE-917 · CNA: VulnCheck · 2 references · NVD status: Analyzed
n8n-io n8n — n8n before 2.29.8 and 2.30.1 Privilege Escalation via Token Exchange
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    8.9   .0047   38.7     —
AFFECTED
  Product  Versions     Fixed
  n8n      unspecified  2.30.1
  n8n      unspecified  2.29.8
TIMELINE
  Jul 22  Reserved by CNA
  Jul 22  Published (CNA: VulnCheck)
CWE-269 · CNA: VulnCheck · 2 references · NVD status: Analyzed
FFmpeg 8.0 - 8.1.2 Stack Buffer Overflow in Vulkan HEVC Decoder
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0046   37.9     —
AFFECTED
  Product  Versions  Fixed
  FFmpeg   8.0 –     —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 22  Published (CNA: VulnCheck)
CWE-121 · CNA: VulnCheck · 3 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-441907.836.0Red HatRed Hat Ansible Automation Platform 2CWE-78Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrar…
CVE-2026-113317.534.7ISCBIND 9CWE-790Potential wildcard CNAME RPZ policy bypass
CVE-2026-656007.834.2traefiktraefikCWE-22Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex
CVE-2026-656504.332.2ElggElggCWE-770Elgg before 7.0.0 does not check image dimensions to prevent denial of servic…
CVE-2025-503278.831.7n/an/aCWE-693An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attac…
CVE-2026-117217.531.6ISCBIND 9CWE-1284Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
CVE-2026-108226.530.2ISCBIND 9CWE-617Key Record using PRIVATEDNS algorithm may lead to unexpected exit
CVE-2026-655895.130.3n8n-ion8nCWE-532n8n before 1.123.64 Credential Exposure via LLM Node Execution Data
CVE-2025-503248.829.4n/an/aCWE-693An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker …
CVE-2025-503308.829.4n/an/aCWE-693An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote …
CVE-2026-131897.529.1Progress SoftwareTelerik UI for ASP.NET AJAXCWE-36SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI fo…
CVE-2026-38218.828.6SMCIX14DBG-DAP,X14DBICWE-78Supermicro SMASH service contain an Arbitrary code execution issue
CVE-2026-23959.828.5Xpoda Türkiye Informatics Technology Inc.No Code PlatformCWE-89SQLi in Xpoda Türkiye Informatics Technology's No Code Platform
CVE-2026-407127.228.0DellPowerProtect Data ManagerCWE-20Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp…
CVE-2026-467387.228.0DellPowerProtect Data ManagerCWE-20Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp…
CVE-2026-467377.227.9DellPowerProtect Data ManagerCWE-20Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp…
CVE-2026-165446.527.7Red HatRed Hat Ansible Automation Platform 2CWE-862Awx: websocket eventconsumer missing authorization for inventory_update_event…
CVE-2026-648308.727.3FFmpegFFmpegCWE-122FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer
CVE-2026-131878.127.1Progress SoftwareTelerik UI for ASP.NET AJAXCWE-470DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET…
CVE-2026-648328.726.4FFmpegFFmpegCWE-415FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c
CVE-2026-650146.326.3n8n-ion8nCWE-306n8n before 2.28.0 Authentication Bypass via test-webhook
CVE-2026-648358.725.6FFmpegFFmpegCWE-787FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder
CVE-2026-650157.225.2n8n-ion8nCWE-863n8n before 2.30.1 Privilege Escalation via run_node_tool
CVE-2026-648299.125.0q2aquestion2answerCWE-613Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow
CVE-2026-655905.524.9n8n-ion8nCWE-78n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows
CVE-2026-131827.524.8Progress SoftwareTelerik UI for ASP.NET AJAXCWE-209RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik …
CVE-2026-131837.524.8Progress SoftwareTelerik UI for ASP.NET AJAXCWE-208RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for …
CVE-2026-47738.124.7Magarsus Consulting Ltd. Co.IDM-MFACWE-1287OTP Bypass in Magarsus' IDM-MFA
CVE-2026-603679.824.4Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-130729.224.2MongoDBMongoDB ServerCWE-122MongoDB Improper Input Validation in Compute Mode External Data Processing Le…
CVE-2026-6036610.023.7Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-603729.823.7Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-603688.823.6Oracle CorporationOracle Platform Security for JavaCWE-1104Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-166325.523.7boazsegevfacil.ioCWE-20boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_e…
CVE-2026-650167.723.4n8n-ion8nCWE-639n8n before 1.123.64, 2.29.8, and 2.30.1 Privilege Escalation via SSO Instance…
CVE-2026-613917.223.0HikvisionDS-2CD SeriesCWE-121There is a stack-based buffer overflow vulnerability in some Hikvision camera…
CVE-2026-480297.123.0strukturaglibheifCWE-125libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced t…
CVE-2026-656038.722.9getgravgravCWE-269Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update
CVE-2026-650138.722.5onlookrepoCWE-639Onlook tRPC Insecure Direct Object Reference via multiple procedures
CVE-2026-130657.122.2MongoDBMongoDB ServerCWE-476MongoDB $linearFill Window Function Improper Input Validation Leading to Proc…
CVE-2025-440908.821.8n/an/aCWE-693An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary c…
CVE-2026-406917.521.8NLnet LabsUnboundCWE-122Packet of death for DNSCrypt over TCP
CVE-2026-129688.821.7UnknownProduct Addons and Product Options With Custom FieldsCWE-79Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrar…
CVE-2026-559737.521.6NLnet LabsUnboundCWE-20'dns-error-reporting: yes' leads to stack buffer overflow
CVE-2026-24066.521.6Universe Software Computer Marketing Trade and Industry Inc.Online Registration and Workflow Management SystemCWE-639IDOR in Universe Software's Online Registration and Workflow Management System
CVE-2025-440898.821.3n/an/aCWE-693An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitr…
CVE-2026-494998.821.1DellPowerProtect Data ManagerCWE-1270Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Gene…
CVE-2026-220498.721.1NETAPPONTAP 9CWE-288ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (M…
CVE-2025-503255.421.1n/an/aCWE-693BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vu…
CVE-2026-647969.821.0regularlabs.comSourcerer extension for JoomlaCWE-284Joomla Extension - regularlabs.com - various code injection vectors in Source…
CVE-2026-326657.521.0NLnet LabsUnboundCWE-1284Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
CVE-2026-130557.120.8MongoDBMongoDB ServerCWE-617Server crash via aggregation pipeline expression with compound wildcard index…
CVE-2026-130567.120.8MongoDBMongoDB ServerCWE-1325A user with read access can cause a DoS by executing a specifically crafted q…
CVE-2026-166249.620.6Cal.comCal.diyCWE-639CVE-2026-16624
CVE-2026-603699.920.4Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-603738.820.4Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-407147.220.2DellPowerProtect Data ManagerCWE-20Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Imp…
CVE-2026-162706.920.2Open MercatoOpen MercatoCWE-1333ReDoS in Open Mercato
CVE-2026-500455.320.2NLnet LabsUnboundCWE-406'max-global-quota' reset by DNSSEC validation restarts
CVE-2025-131466.519.9sevensparkContact Form 7 – Dynamic Text ExtensionCWE-94Contact Form 7 – Dynamic Text Extension <= 5.0.6 - Unauthenticated Arbitrary …
CVE-2026-148997.519.8MozillaThunderbirdCWE-193Off-by-one out of bounds read in MIME header parser for forwarding
CVE-2026-656015.319.8traefiktraefikCWE-863Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef
CVE-2026-130598.619.6MongoDBMongoDB ServerCWE-807Improper Validation of Client-Supplied Command Parameters Allowing Role-Based…
CVE-2026-604398.819.2Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-145865.919.0NLnet LabsUnboundCWE-617Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC …
CVE-2026-655945.119.0n8n-ion8nCWE-863n8n before 2.30.1 Missing OAuth Authorization Check
CVE-2026-129877.518.9UnknownEvents ManagerCWE-89Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injecti…
CVE-2026-107236.818.5ISCBIND 9CWE-347Incorrect acceptance of NSEC3 records
CVE-2026-416373.718.5NLnet LabsUnboundCWE-772Degradation of resolution service from improperly accounted client-terminated…
CVE-2026-612468.818.4Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-130746.917.8MongoDBMongoDB ServerCWE-770Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to …
CVE-2026-34825.317.8IBMSterling B2B IntegratorCWE-639IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass
CVE-2026-632645.317.6joomshopping.comJoomShopping extension for JoomlaCWE-79Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3
CVE-2026-650126.317.4invoke-aiInvokeAICWE-306InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder
CVE-2026-559905.917.5NLnet LabsUnboundCWE-457Packet of death for a DNSCrypt misconfigured Unbound
CVE-2026-458206.617.2101arrowzfflateCWE-400fflate through 0.8.2 is vulnerable to denial of service via an infinite loop …
CVE-2026-148655.317.3Progress SoftwareTelerik UI for ASP.NET AJAXCWE-776XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP…
CVE-2026-166156.817.1GNOMElibrestCWE-338Librest: weak random number generation in pkce implementation
CVE-2026-502515.317.1NLnet LabsUnboundCWE-184Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
CVE-2026-165516.916.9Thinkst Applied ResearchOpenCanaryCWE-20Denial-of-Service in OpenCanary's MongoDB module
CVE-2026-130576.016.9MongoDBMongoDB ServerCWE-20Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauth…
CVE-2026-647927.516.5regularlabs.comArticles Anywhere extension for JoomlaCWE-524Joomla Extension - regularlabs.com - disclosure of restricted content via sea…
CVE-2026-576007.516.4HikvisionDS-2CD SeriesCWE-20Insufficient validation of input parameters in the firmware of some Hikvision…
CVE-2026-446215.916.3NLnet LabsUnboundCWE-754Libunbound applications configured with 'unwanted-reply-threshold' could even…
CVE-2026-647939.116.2regularlabs.comArticles Anywhere extension for JoomlaCWE-284Joomla Extension - regularlabs.com - Content access and publication bypass in…
CVE-2026-647989.116.0regularlabs.comIP Login extension for JoomlaCWE-338Joomla Extension - regularlabs.com - Insecure login URL keys in IP login exte…
CVE-2026-130717.116.0MongoDBMongoDB ServerCWE-416Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to …
CVE-2026-164734.315.9Red HatRed Hat Enterprise Linux 10CWE-125Sbc: sbc: heap out-of-bounds read via crafted sbc audio frame
CVE-2026-81529.315.9Unblu inc.Unblu SparkCWE-79Unblu Spark Open Redirect leading to DOM-Based XSS
CVE-2026-604558.815.9Oracle CorporationOracle Platform Security for JavaCWE-269Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-131926.515.8Progress SoftwareTelerik UI for ASP.NET AJAXCWE-918RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX
CVE-2026-647946.515.8regularlabs.comArticles Anywhere extension for JoomlaCWE-284Joomla Extension - regularlabs.com - restricted user-data exposure in Users A…
CVE-2026-165605.315.9Red HatRed Hat Directory Server 11CWE-1220389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multi…
CVE-2026-655988.915.5n8n-ion8nCWE-367n8n before 1.123.64 Remote Code Execution via Git Clone
CVE-2026-130777.115.5MongoDBMongoDB ServerCWE-125Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSON…
CVE-2026-157876.415.5brainstormforceUltimate Addons for ElementorCWE-79Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored …
CVE-2026-130897.515.4RITOUOIDC::LiteCWE-347OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verifica…
CVE-2026-500465.915.0NLnet LabsUnboundCWE-416Possible heap use-after-free in an error path when a DoT forwarded query is j…
CVE-2026-528635.915.0NLnet LabsUnboundCWE-416Memory corruption could lead to crash and denial of service
CVE-2026-557175.915.0NLnet LabsUnboundCWE-476'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to…
CVE-2026-559915.915.0NLnet LabsUnboundCWE-195Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
CVE-2026-564445.915.0NLnet LabsUnboundCWE-772Degradation of resolution service when 'discard-timeout' and 'serve-expired-c…
CVE-2026-130607.114.8MongoDBMongoDB ServerCWE-863$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Una…
CVE-2026-97377.114.6MongoDBMongoDB ServerCWE-617Find command with $meta sort can lead to crash
CVE-2026-130757.114.7MongoDBMongoDB ServerCWE-770$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggest…
CVE-2026-130767.114.6MongoDBMongoDB ServerCWE-770Aggregation Framework Memory Exhaustion Leading to Process Termination
CVE-2026-630477.514.3joomdonation.comEvents Booking extension for JoomlaCWE-284Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect…
CVE-2026-130587.114.0MongoDBMongoDB ServerCWE-617Transaction Command Insufficient Input Validation Leading to Process Termination
CVE-2026-130647.114.0MongoDBMongoDB ServerCWE-407MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denia…
CVE-2026-130635.314.0MongoDBMongoDB ServerCWE-190libmongocrypt Improper Input Validation Leading to Process Termination
CVE-2026-636858.813.9regularlabs.comDB Replacer extension for JoomlaCWE-284Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer exte…
CVE-2026-613907.713.7HikvisionDS-2CD SeriesCWE-122There is a heap buffer overflow vulnerability in some Hikvision cameras, whic…
CVE-2026-130667.113.7MongoDBMongoDB ServerCWE-843Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure
CVE-2026-630489.413.5joomlack.frPage Builder CK extension for JoomlaCWE-434Joomla Extension - joomlack.fr - Improper access control in Page Builder CK <…
CVE-2026-636837.513.5regularlabs.comAdvanced Module Manager extension for JoomlaCWE-290Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regu…
CVE-2026-650115.312.5Graylog2graylog2-serverCWE-862Graylog2 Server Missing Permission Check on Event Definition Duplicate
CVE-2026-446873.712.5NLnet LabsUnboundCWE-193Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward z…
CVE-2026-133218.612.4ISCBIND 9CWE-346DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVE-2026-655978.212.0n8n-ion8nCWE-79n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe
CVE-2026-648337.112.0FFmpegFFmpegCWE-125FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c
CVE-2026-130735.311.8MongoDBMongoDB ServerCWE-617MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Te…
CVE-2026-575996.611.6HikvisionDS-2CD SeriesCWE-269There is a privilege escalation vulnerability in some Hikvision cameras. Due …
CVE-2026-648285.311.6FroidenTableTrackCWE-79Froiden TableTrack 1.3.10 Stored XSS via Order Notes Field
CVE-2026-130786.311.4MongoDBMongoDB ServerCWE-862Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader
CVE-2026-149326.511.3Progress SoftwareTelerik UI for ASP.NET AJAXCWE-321Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart
CVE-2026-655965.111.3n8n-ion8nCWE-863n8n before 1.123.64 Credential Exfiltration via GraphQL Node
CVE-2026-613925.311.0HikvisionDS-2CD SeriesCWE-200There is a information disclosure vulnerability in some Hikvision cameras, al…
CVE-2026-429553.710.6NLnet LabsUnboundCWE-672Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallow…
CVE-2026-131847.510.4Progress SoftwareTelerik UI for ASP.NET AJAXCWE-321RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.…
CVE-2026-647977.510.4regularlabs.comIP Login extension for JoomlaCWE-290Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login ex…
CVE-2026-603707.510.3Oracle CorporationOracle Platform Security for JavaCWE-1021Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-164902.110.2itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System prescription.php sql injection
CVE-2026-656025.38.4traefiktraefikCWE-863Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass
CVE-2026-143225.38.0UnknownTimeticsCWE-284Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payme…
CVE-2026-465823.78.0NLnet LabsUnboundCWE-358A wildcard replay, as another piece of data, triggers poisoning in the serve …
CVE-2026-544783.77.6NLnet LabsUnboundCWE-290DNS Cookie bypass when combined with proxy-protocol use
CVE-2026-387635.57.4n/an/aCWE-400An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at…
CVE-2026-149857.87.1Analog WayPicturall Quad Compact Mark IICWE-22CVE-2026-14985
CVE-2026-130697.17.0MongoDBMongoDB ServerCWE-770Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Re…
CVE-2026-655928.46.9n8n-ion8nCWE-79n8n before 1.123.64 Stored DOM XSS via cachedResultUrl
CVE-2026-387657.86.9n/an/aCWE-269An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at…
CVE-2026-387667.86.9n/an/aCWE-269An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at…
CVE-2026-603718.06.8Oracle CorporationOracle Platform Security for JavaCWE-200Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-130615.36.3MongoDBMongoDB ServerCWE-863Improper Access Control Allowing Cross-User Session Metadata Disclosure in $l…
CVE-2026-655995.15.0n8n-ion8nCWE-312n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header
CVE-2026-148818.44.9MongoDBMongoDB CompassCWE-78Compass connection import allows to override OIDC browser open command (usual…
CVE-2026-557083.14.7NLnet LabsUnboundCWE-1188Privacy/configuration issue when adding local data in views through 'unbound-…
CVE-2026-441926.64.6Red HatRed Hat Ansible Automation Platform 2CWE-22Ansible-lightspeed: ansible lightspeed mcp server: remote code execution and …
CVE-2025-608357.84.5n/an/aCWE-35An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute…
CVE-2026-130682.34.6MongoDBMongoDB ServerCWE-863MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cr…
CVE-2026-446907.54.3NLnet LabsUnboundCWE-345Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
CVE-2026-655936.34.1n8n-ion8nCWE-918n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters
CVE-2026-632814.84.0regularlabs.comAdvanced Module Manager extension for JoomlaCWE-79Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs condit…
CVE-2026-502525.73.9NLnet LabsUnboundCWE-349Possible cache poisoning attack by mapping source port population per thread
CVE-2026-647955.43.3regularlabs.comModals extension for JoomlaCWE-79Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in va…
CVE-2026-145518.83.2servereye GmbHservereye Windows Agent (Sensorhub)CWE-73Local Privilege Escalation in servereye client (sensorhub)
CVE-2026-568448.43.0VeeamBackup and ReplicationCWE-22A vulnerability in the Veeam Updater component of the Veeam Software Applianc…
CVE-2026-502486.52.9NLnet LabsUnboundCWE-345BOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVE-2026-632808.82.8regularlabs.comAdvanced Module Manager extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-636848.82.8regularlabs.comContent Templater extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-647918.82.8regularlabs.comRegular Labs Extension Manager extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-161577.82.0DuplicatiDuplicatiCWE-732Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission a…
CVE-2026-564164.82.0NLnet LabsUnboundCWE-354Possible heap buffer overflow when validator canonicalizes RDATA that contain…
CVE-2026-632658.01.8regularlabs.comAdvanced Module Manager extension for JoomlaCWE-352Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile…
CVE-2026-130627.11.7MongoDBMongoDB ServerCWE-441MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption …
CVE-2026-131885.91.5Progress SoftwareTelerik UI for ASP.NET AJAXCWE-345DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX
CVE-2026-442764.41.4DellPowerProtect Data ManagerCWE-200Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exp…
CVE-2026-502436.31.3NLnet LabsUnboundCWE-348'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
CVE-2026-166078.51.0FujitsuLinux openFTCWE-269Authenticated local root privilege escalation vulnerability in openFT for Lin…
CVE-2026-73286.80.6CaliptraCore Runtime FirmwareCWE-862Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service
CVE-2026-130706.00.5MongoDBMongoDB ServerCWE-476Improper Validation of OCSP Response During Outbound TLS Handshake Leading to…
CVE-2026-441873.30.5Red HatRed Hat Ansible Automation Platform 2CWE-256Ansible-lightspeed: ansible lightspeed extension for visual studio code: info…
CVE-2026-130677.20.0MongoDBMongoDB ServerCWE-863tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domai…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-22 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.