AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H L 10.0 .0473 91.1 —
AFFECTED Product Versions Fixed ManageEngine ADAudit Plus unspecified —
TIMELINE Apr 17 Reserved by CNA Jul 23 Published (CNA: Zohocorp)
376 CVEs published July 23, 2026: 63 critical, 137 high, 166 medium, 10 low; 0 in KEV; 15 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 351 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 3763 | 6512 | 1324 | 2563 |
| KEV catalog size | 1670 | |||
126 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| microsoft | 643 | 1346 | 97 | 925 | 299 | 8 | 378 | 32 | 2.4 | 7.8 | .0039 | +424 |
| linux | 312 | 1230 | 178 | 976 | 57 | 0 | 27 | 3 | 0.2 | 7.8 | .0014 | +264 |
| red hat | 66 | 165 | 9 | 84 | 63 | 9 | 4 | 0 | 0.0 | 7.1 | .0029 | +26 |
| apple | 3 | 80 | 1 | 19 | 52 | 1 | 93 | 7 | 8.8 | 6.5 | .0036 | +3 |
| 26 | 35 | 6 | 24 | 1 | 1 | 73 | 5 | 14.3 | 8.8 | .0030 | +24 | |
| canonical | 3 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | +3 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | -1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 7 | 19 | 4 | 6 | 1 | 0 | 96 | 12 | 63.2 | 8.6 | .2459 | +5 |
| fortinet | 10 | 17 | 2 | 4 | 8 | 0 | 28 | 5 | 29.4 | 6.3 | .0051 | +9 |
| palo alto networks | 10 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | +7 |
| vmware | 7 | 7 | 1 | 6 | 0 | 0 | 21 | 0 | 0.0 | 8.7 | .0044 | +7 |
| f5 | 1 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | -1 |
| checkpoint | 3 | 4 | 3 | 1 | 0 | 0 | 3 | 2 | 50.0 | 9.2 | .4696 | +2 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.1 | .0877 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mozilla | 67 | 72 | 42 | 26 | 4 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +67 |
| apache | 16 | 48 | 14 | 26 | 8 | 0 | 40 | 1 | 2.1 | 7.5 | .0063 | +1 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | -3 |
| wordpress | 2 | 2 | 1 | 0 | 1 | 0 | 5 | 2 | 100.0 | 7.9 | .8435 | +2 |
| gitlab | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .4451 | 0 |
| github | 1 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 4.7 | .0017 | +1 |
| kubernetes | 1 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1109 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | +1107 |
| ibm | 32 | 40 | 16 | 11 | 13 | 0 | 7 | 0 | 0.0 | 8.4 | .0028 | +31 |
| adobe | 16 | 27 | 9 | 10 | 4 | 0 | 75 | 4 | 14.8 | 8.6 | .0144 | +9 |
| solarwinds | 15 | 19 | 15 | 1 | 1 | 0 | 11 | 4 | 21.1 | 9.1 | .0044 | +14 |
| progress | 18 | 18 | 3 | 10 | 5 | 0 | 9 | 0 | 0.0 | 7.8 | .0031 | +18 |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 |
| zohocorp | 3 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0048 | +3 |
| veeam | 1 | 1 | 0 | 1 | 0 | 0 | 4 | 0 | 0.0 | 8.4 | .0013 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 7 | 8 | 0 | 0 | 6 | 1 | 26 | 1 | 12.5 | 5.5 | .0073 | +7 |
| hikvision | 5 | 6 | 0 | 3 | 2 | 0 | 2 | 1 | 16.7 | 7.2 | .0024 | +5 |
| bosch | 2 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.0 | .0018 | +2 |
| rockwell automation | 1 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | +1 |
| siemens | 0 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 57 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | +57 |
| grafana | 7 | 40 | 2 | 13 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | +1 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| netty | 10 | 32 | 6 | 24 | 1 | 1 | 0 | 0 | 0.0 | 7.5 | .0051 | -4 |
| regularlabs.com | 29 | 29 | 6 | 14 | 9 | 0 | 0 | 0 | 0.0 | 7.5 | .0022 | +29 |
| watchguard | 17 | 28 | 1 | 18 | 9 | 0 | 4 | 0 | 0.0 | 7.3 | .0026 | +17 |
| nlnet labs | 24 | 27 | 0 | 4 | 17 | 6 | 0 | 0 | 0.0 | 5.9 | .0024 | +24 |
| mongodb | 26 | 26 | 1 | 17 | 7 | 1 | 2 | 0 | 0.0 | 7.1 | .0023 | +26 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | — |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| microsoft | 643 |
| linux | 505 |
| red hat | 81 |
| mozilla | 67 |
| surrealdb | 57 |
| apple | 40 |
| ibm | 39 |
| regularlabs.com | 29 |
| 27 |
| Vendor | KEV |
|---|---|
| microsoft | 32 |
| cisco | 12 |
| apple | 7 |
| fortinet | 5 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 11 |
| npm | 2 |
| crates.io | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1709 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1709 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1709 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1709 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1709 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1709 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1709 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1709 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1709 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1709 |
EXPLOIT PUBLISHED — CVE-2026-16489 (jsforce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16628 (oclif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16630 (syncfusion ej2-javascript-ui-controls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-20253 (Splunk Enterprise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-26740. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-34908 (Ubiquiti UniFi OS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-34909 (Ubiquiti UniFi OS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-34910 (Ubiquiti UniFi OS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42999 (OpenStack Keystone). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43000 (OpenStack Keystone). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44210 (kata-containers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44891 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55831 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56292 (acymailing.com AcyMailing extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-57827 (rsjoomla.com RSFiles extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-57828 (phoca.cz Phoca Download extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64600 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65012 (invoke-ai InvokeAI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65013 (onlook repo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65898 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65899 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65900 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65901 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65902 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65903 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65904 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65911 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65914 (cure53 DOMPurify). Public exploit reference added.
RESCORED — CVE-2026-10732 (decompress). CVSS 6.1 → 5.6 (NVD).
RESCORED — CVE-2026-13448 (IBM Langflow OSS). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2026-16631 (publint). CVSS 4.8 → 1.9 (NVD).
RESCORED — CVE-2026-16632 (boazsegev facil.io). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-42010 (Red Hat Enterprise Linux 10). CVSS 7.1 → 9.8 (NVD).
RESCORED — CVE-2026-42975 (Microsoft Windows 10 Version 1607). CVSS 8 → 8.8 (NVD).
RESCORED — CVE-2026-42999 (OpenStack Keystone). CVSS 6 → 8.8 (NVD).
RESCORED — CVE-2026-43000 (OpenStack Keystone). CVSS 6 → 8.8 (NVD).
RESCORED — CVE-2026-44930 (Apache Software Foundation Apache CXF). CVSS 4.3 → 9.8 (NVD).
RESCORED — CVE-2026-50317 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2026-50406 (Microsoft Windows 10 Version 21H2). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2026-50440 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2026-50491 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2026-54989 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2026-56187 (Microsoft Windows 11 Version 24H2). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2026-57089 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 9.8 (NVD).
ENRICHED — CVE-2026-10520 (Ivanti Sentry). Received CVSS 10.0 and CPE data from NVD.
ENRICHED — CVE-2026-11645 (Google Chromium V8). Received CVSS 8.8 and CPE data from NVD.
ENRICHED — CVE-2026-20253 (Splunk Enterprise). Received CVSS 9.8 and CPE data from NVD.
ENRICHED — CVE-2026-25089 (Fortinet FortiSandbox). Received CVSS 9.8 and CPE data from NVD.
ENRICHED — CVE-2026-34908 (Ubiquiti UniFi OS). Received CVSS 10.0 and CPE data from NVD.
ENRICHED — CVE-2026-34909 (Ubiquiti UniFi OS). Received CVSS 10.0 and CPE data from NVD.
ENRICHED — CVE-2026-34910 (Ubiquiti UniFi OS). Received CVSS 10.0 and CPE data from NVD.
ENRICHED — CVE-2026-34926 (Trend Micro Apex One). Received CVSS 6.7 and CPE data from NVD.
ENRICHED — CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools). Received CVSS 9.8 and CPE data from NVD.
ENRICHED — CVE-2026-45498 (Microsoft Defender). Received CVSS 7.5 and CPE data from NVD.
ENRICHED — CVE-2026-45659 (Microsoft SharePoint Server). Received CVSS 8.8 and CPE data from NVD.
ENRICHED — CVE-2026-48172 (LiteSpeed cPanel Plugin). Received CVSS 10.0 and CPE data from NVD.
ENRICHED — CVE-2026-48907 (Widget Factory Joomla Content Editor ). Received CVSS 10.0 and CPE data from NVD.
ENRICHED — CVE-2026-54420 (LiteSpeed cPanel Plugin). Received CVSS 8.5 and CPE data from NVD.
ENRICHED — CVE-2026-9082 (Drupal Core). Received CVSS 9.8 and CPE data from NVD.
376 CVEs published. 25 box scores, 351 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H L 10.0 .0473 91.1 —
AFFECTED Product Versions Fixed ManageEngine ADAudit Plus unspecified —
TIMELINE Apr 17 Reserved by CNA Jul 23 Published (CNA: Zohocorp)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0434 90.4 —
AFFECTED Product Versions Fixed dbgate < 7.1.9 – —
TIMELINE May 19 Reserved by CNA Jul 23 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0246 83.1 —
AFFECTED Product Versions Fixed microweber unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0184 77.1 —
AFFECTED Product Versions Fixed meshery unspecified —
TIMELINE Jul 23 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0171 75.5 —
AFFECTED Product Versions Fixed dbgate < 7.1.9 – —
TIMELINE May 19 Reserved by CNA Jul 23 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0127 67.3 —
AFFECTED Product Versions Fixed h2ogpt unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0093 57.6 —
AFFECTED Product Versions Fixed cal.diy unspecified 5.9.9
TIMELINE Jul 16 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0085 55.1 —
AFFECTED Product Versions Fixed grav 1.7.0 – 2.0.9
TIMELINE Jul 22 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0074 51.7 —
AFFECTED Product Versions Fixed 9router unspecified 0.4.60
TIMELINE Jul 18 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0072 50.9 —
AFFECTED Product Versions Fixed Microsoft Account - – —
TIMELINE Jun 19 Reserved by CNA Jul 23 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0071 50.5 —
AFFECTED Product Versions Fixed Surface Management Services - – —
TIMELINE Jun 11 Reserved by CNA Jul 23 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0070 50.3 —
AFFECTED Product Versions Fixed serverless-localstack 1.0 – —
TIMELINE Jul 23 Reserved by CNA Jul 23 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.0 —
AFFECTED Product Versions Fixed GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more unspecified —
TIMELINE Jul 1 Reserved by CNA Jul 23 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0062 46.9 —
AFFECTED Product Versions Fixed conventional-changelog 11.0.0 – —
TIMELINE Jul 23 Reserved by CNA Jul 23 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0061 46.5 —
AFFECTED Product Versions Fixed WCPOS – Point of Sale (POS) plugin for WooCommerce unspecified —
TIMELINE Jul 17 Reserved by CNA Jul 23 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0061 46.4 —
AFFECTED Product Versions Fixed find-cypress-specs 1.54.0 – —
TIMELINE Jul 23 Reserved by CNA Jul 23 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0060 45.9 —
AFFECTED Product Versions Fixed Standalone Report Designer 6.3 – 14.1.12
TIMELINE Jul 22 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0060 45.7 —
AFFECTED Product Versions Fixed Advanced Views n/a – 3.9.0
TIMELINE Jul 5 Reserved by CNA Jul 23 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0059 45.6 —
AFFECTED Product Versions Fixed Standalone Report Designer 6.3 – 14.1.12
TIMELINE Jul 22 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0058 45.2 —
AFFECTED Product Versions Fixed Azure Red Hat OpenShift (ARO) - – —
TIMELINE Jun 19 Reserved by CNA Jul 23 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H N 9.3 .0058 45.1 —
AFFECTED Product Versions Fixed so-vits-svc unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0058 45.0 —
AFFECTED Product Versions Fixed Standalone Report Designer 6.3 – 14.1.12
TIMELINE Jul 22 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0058 45.0 —
AFFECTED Product Versions Fixed Standalone Report Designer 6.3 – 14.1.12
TIMELINE Jul 22 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0055 43.3 —
AFFECTED Product Versions Fixed SAML Single Sign On – SSO Login unspecified —
TIMELINE Jul 16 Reserved by CNA Jul 23 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P H H H 9.4 .0052 41.5 —
AFFECTED Product Versions Fixed siyuan unspecified 3.7.2
TIMELINE Jul 22 Reserved by CNA Jul 23 Published (CNA: VulnCheck)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-65606 | 9.4 | 41.5 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.2 Cross-Site Scripting to RCE |
| CVE-2026-52439 | 9.8 | 41.5 | n/a | n/a | CWE-917 | An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitra… |
| CVE-2026-44909 | 7.5 | 41.5 | proxygen | — | Proxygen lacked a generalized slow-consumer detection mechanism in its core H… | |
| CVE-2026-64600 | 7.8 | 41.0 | Linux | Linux | CWE-362 | xfs: resample the data fork mapping after cycling ILOCK |
| CVE-2026-15011 | 9.8 | 40.2 | emarket-design | Customer Support Ticket System & Helpdesk | CWE-94 | Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Inj… |
| CVE-2026-64800 | 5.7 | 40.0 | JetBrains | GoLand | CWE-532 | In JetBrains GoLand before 2026.2 sensitive configuration values written to l… |
| CVE-2026-65702 | 8.8 | 39.8 | vanna-ai | vanna | CWE-22 | Vanna 2.0.2 Path Traversal via FileSystemConversationStore |
| CVE-2026-16653 | 5.5 | 39.4 | boazsegev | facil.io | CWE-22 | boazsegev facil.io Public Folder http.c http_sendfile2 path traversal |
| CVE-2026-16767 | 5.5 | 39.3 | Ne-Lexa | php-zip | CWE-22 | Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal |
| CVE-2026-16287 | 7.8 | 38.9 | TUBITAK BILGEM Software Technologies Research Institute | pardus-update | CWE-78 | Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update |
| CVE-2026-59542 | 7.7 | 37.4 | WP Chill | Kali Forms | CWE-22 | WordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerability |
| CVE-2026-15074 | 7.5 | 37.2 | @fastify/static | @fastify/static | CWE-22 | @fastify/static vulnerable to route guard bypass via path traversal |
| CVE-2026-44210 | 5.8 | 37.3 | kata-containers | kata-containers | CWE-88 | Kata Containers have VM Escape via virtiofsd Argument Injection through Defau… |
| CVE-2026-65907 | 9.1 | 35.1 | JetBrains | TeamCity | CWE-94 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS ro… |
| CVE-2026-63359 | 9.3 | 34.9 | Appriss Insights | Victim Information Notification Exchange (VINE) | CWE-89 | Appriss Insights VINE SQLI |
| CVE-2026-65906 | 10.0 | 34.7 | JetBrains | TeamCity | CWE-94 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DS… |
| CVE-2026-16756 | 8.7 | 34.8 | AWS | aws-smithy-http-server | CWE-770 | Allocation of resources without limits in the default aws-smithy-http-server … |
| CVE-2026-16723 | 9.0 | 34.5 | Alibaba | Fastjson | CWE-20 | Remote Code Execution in fastjson 1.2.68–1.2.83 |
| CVE-2026-15786 | 4.4 | 34.1 | gowebsmarty | WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security | CWE-22 | WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Writ… |
| CVE-2026-56167 | 8.8 | 33.8 | Microsoft | Azure AI Search | CWE-918 | Azure AI Search Elevation of Privilege Vulnerability |
| CVE-2026-65607 | 7.1 | 33.1 | siyuan-note | siyuan | CWE-22 | SiYuan before v3.7.2 Path Traversal via /export/temp/ |
| CVE-2026-16806 | 8.8 | 33.0 | Chrome | CWE-416 | Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a r… | |
| CVE-2026-64813 | 10.0 | 32.5 | JetBrains | IntelliJ IDEA | CWE-602 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification w… |
| CVE-2026-47752 | 9.9 | 32.3 | Quenary | tugtainer | CWE-1336 | Tugtainer has Server-Side Template Injection in notification templates that l… |
| CVE-2024-58354 | 8.5 | 31.7 | calcom | cal.diy | CWE-77 | cal.com Repository Takeover via pull_request_target Workflow |
| CVE-2026-15015 | 9.8 | 31.2 | cascadiawebservices | MountDev AI MCP Connector for WordPress | CWE-862 | MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege … |
| CVE-2026-63765 | 8.8 | 31.2 | chatwoot | chatwoot | CWE-306 | Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob … |
| CVE-2026-59555 | 10.0 | 31.2 | Roland Barker | Participants Database | CWE-22 | WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion v… |
| CVE-2026-65431 | 9.8 | 31.2 | regularlabs.com | GeoIP extension for Joomla | CWE-22 | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension |
| CVE-2026-65493 | 7.5 | 30.4 | Dokan | Dokan Pro | CWE-502 | WordPress Dokan Pro plugin <= 5.0.2 - PHP Object Injection vulnerability |
| CVE-2026-65497 | 7.2 | 30.1 | Complianz | Complianz | CWE-502 | WordPress Complianz plugin <= 7.5.0 - PHP Object Injection vulnerability |
| CVE-2026-49035 | 9.2 | 30.0 | MZ Automation | libIEC61850 | CWE-122 | Stack-based Buffer Overflow in MZ Automation libIEC61850 |
| CVE-2026-65455 | 9.1 | 29.8 | MapSVG | MapSVG | CWE-434 | WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability |
| CVE-2026-65461 | 9.1 | 29.8 | Webの相談所 | Really Simple CSV Importer | CWE-434 | WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vu… |
| CVE-2026-64812 | 10.0 | 29.4 | JetBrains | IntelliJ IDEA | CWE-306 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was pos… |
| CVE-2026-15017 | 8.8 | 29.3 | mdjm | MDJM Event Management | CWE-269 | MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Esca… |
| CVE-2026-65897 | 8.7 | 29.2 | getgrav | grav | CWE-269 | Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups |
| CVE-2026-47769 | 5.3 | 29.2 | Work90210 | APIFold | CWE-306 | APIFold Vulnerable to Unauthenticated Webhook Event Injection |
| CVE-2026-65917 | 8.7 | 28.7 | usmannasir | cyberpanel | CWE-639 | CyberPanel IncBackups IDOR via Sequential Backup ID |
| CVE-2026-47743 | 8.7 | 28.4 | shopperlabs | shopper | CWE-79 | Shopper: Multiple data integrity and disclosure issues in admin Livewire comp… |
| CVE-2026-47724 | 9.9 | 28.1 | juev | nebula-mesh | CWE-862 | nebula-mesh: API endpoints lack ownership checks, enabling cross-operator pri… |
| CVE-2026-65698 | 6.0 | 27.8 | voideditor | void | CWE-22 | Void 1.3.4 Path Traversal via AI Agent File-Reading Tools |
| CVE-2026-47669 | 9.3 | 27.4 | dbgate | dbgate | CWE-22 | DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE |
| CVE-2026-14257 | 7.5 | 26.8 | juliangruber | brace-expansion | CWE-400 | brace-expansion DoS via unbounded expansion length causing an out-of-memory p… |
| CVE-2026-25800 | 7.5 | 26.8 | quinn-rs | quinn | CWE-770 | quinn-proto has remote memory exhaustion from unbounded out-of-order stream r… |
| CVE-2026-64611 | 7.5 | 26.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-835 | Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loo… |
| CVE-2026-65762 | 5.1 | 26.8 | phoca.cz | Phoca Guestbook extension for Joomla | CWE-79 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook … |
| CVE-2026-65763 | 5.1 | 26.8 | phoca.cz | Phoca Maps extension for Joomla | CWE-79 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0… |
| CVE-2026-63313 | 8.3 | 26.5 | decolua | 9router | CWE-918 | 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch |
| CVE-2026-65916 | 7.2 | 26.6 | usmannasir | cyberpanel | CWE-862 | CyberPanel Missing Authorization in cancelBackupCreation Handler |
| CVE-2026-65754 | 7.5 | 26.4 | regularlabs.com | ReReplacer PRo extension for Joomla | CWE-22 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro… |
| CVE-2026-64815 | 9.8 | 25.9 | JetBrains | IntelliJ IDEA | CWE-94 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possibl… |
| CVE-2026-15616 | 9.1 | 25.7 | Logto | Logto | CWE-308 | Local MFA not enforced during SSO sign-in |
| CVE-2026-16796 | 8.4 | 25.5 | AWS | bedrock-agentcore 1.18.1 | CWE-88 | Improper neutralization of argument delimiters in AWS Bedrock AgentCore Pytho… |
| CVE-2026-14291 | 7.5 | 25.5 | Unknown | security-ninja-premium | CWE-287 | Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secni… |
| CVE-2026-65920 | 5.3 | 25.4 | huggingface | diffusers | CWE-22 | Diffusers Path Traversal via weight_map Arbitrary File Read |
| CVE-2026-61951 | 9.8 | 24.9 | themetechmount | TrueBooker | CWE-266 | WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability |
| CVE-2026-65695 | 7.6 | 24.9 | GongRzhe | Office-Word-MCP-Server | CWE-22 | Office-Word-MCP-Server 1.1.11 Path Traversal via document tools |
| CVE-2026-65477 | 7.5 | 24.7 | Select-Themes | Tonda Core | CWE-98 | WordPress Tonda Core plugin <= 2.1.2 - Local File Inclusion vulnerability |
| CVE-2026-65481 | 7.5 | 24.7 | Elated-Themes | Vino | CWE-98 | WordPress Vino theme <= 1.9 - Local File Inclusion vulnerability |
| CVE-2026-15348 | 6.3 | 24.8 | codename065 | Premium Packages – Sell Digital Products Securely | CWE-287 | Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl'… |
| CVE-2026-59522 | 6.5 | 24.4 | weDevs | WP ERP | CWE-862 | WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability |
| CVE-2026-59541 | 8.8 | 24.3 | Hakan Ozevin | WP BASE Booking | CWE-266 | WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability |
| CVE-2026-64814 | 8.6 | 24.2 | JetBrains | IntelliJ IDEA | CWE-862 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possibl… |
| CVE-2026-57367 | 7.1 | 24.3 | WP Booking System . | WP Booking System | CWE-862 | WordPress WP Booking System plugin < 5.12.8.1 - Broken Access Control vulnera… |
| CVE-2026-16805 | 8.8 | 24.2 | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a re… | |
| CVE-2026-59544 | 9.8 | 24.1 | Thrive Themes Coupon | Thrive Quiz Builder | CWE-502 | WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulne… |
| CVE-2026-64799 | 7.5 | 24.0 | regularlabs.com | Articles Anywhere Pro extension for Joomla | CWE-918 | Joomla Extension - regularlabs.com - SSRF via remote image downloads in Artic… |
| CVE-2026-65918 | 7.1 | 24.0 | pytorch | vision | CWE-125 | PyTorch torchvision GIF Decoder Out-of-bounds Heap Read |
| CVE-2026-15827 | 5.3 | 23.7 | ataurr | GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor | CWE-862 | GutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Infor… |
| CVE-2026-57696 | 7.1 | 23.3 | videowhisper | Picture Gallery | CWE-22 | WordPress Picture Gallery plugin <= 1.6.5 - Arbitrary File Deletion vulnerabi… |
| CVE-2026-14481 | 6.4 | 23.3 | equalizedigital | Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance | CWE-79 | Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor… |
| CVE-2026-47723 | 7.1 | 22.9 | juev | nebula-mesh | CWE-1021 | nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Opt… |
| CVE-2026-65495 | 7.5 | 22.5 | Dokan Multivendor Plugin | Dokan Pro | CWE-862 | WordPress Dokan Pro plugin <= 5.0.3 - Broken Access Control vulnerability |
| CVE-2026-57808 | 6.5 | 22.5 | Saad Iqbal | WP EasyPay | CWE-862 | WordPress WP EasyPay plugin <= 4.5.0 - Arbitrary Content Deletion vulnerability |
| CVE-2024-58353 | 9.3 | 22.3 | calcom | cal.diy | CWE-80 | Cal.com through 4.7.15 Cross-Site Scripting via booking questions |
| CVE-2026-59524 | 6.5 | 22.1 | Sandhills Development, LLC | Easy Digital Downloads | CWE-288 | WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vuln… |
| CVE-2026-59554 | 7.5 | 21.9 | Ziina | Ziina | CWE-1390 | WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability |
| CVE-2026-10697 | 9.8 | 21.7 | Progress | MOVEit Transfer | CWE-287 | MFA Bypass in MOVEit Transfer |
| CVE-2024-58355 | 9.3 | 21.6 | calcom | cal.diy | CWE-80 | Cal.com through 4.7.15 Cross-Site Scripting via booking questions |
| CVE-2024-58330 | 7.5 | 21.6 | Bosch | Camera Firmware | CWE-284 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP1… |
| CVE-2026-64874 | 9.8 | 21.5 | regularlabs.com | Cache Cleaner Pro extension for Joomla | CWE-200 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro… |
| CVE-2026-65604 | 8.8 | 21.5 | zalando | skipper | CWE-20 | Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass |
| CVE-2026-65500 | 7.5 | 21.2 | pixelacehq | Manual - Documentation, Knowledge Base & Education WordPress Theme | CWE-862 | WordPress Manual - Documentation, Knowledge Base & Education WordPress theme … |
| CVE-2026-65463 | 5.4 | 21.2 | masteriyo | Masteriyo - LMS | CWE-639 | WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References… |
| CVE-2026-42933 | 10.0 | 21.0 | Pronetiqs | Panduit Intravue | CWE-441 | Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs |
| CVE-2026-61948 | 9.3 | 20.8 | Shahjada | WPDM – Premium Packages | CWE-89 | WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability |
| CVE-2026-61949 | 9.3 | 20.8 | Bookly | Bookly | CWE-89 | WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability |
| CVE-2026-61950 | 9.3 | 20.8 | themetechmount | TrueBooker | CWE-89 | WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability |
| CVE-2026-15906 | 6.5 | 20.6 | codename065 | Premium Packages – Sell Digital Products Securely | CWE-89 | Premium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby… |
| CVE-2026-15617 | 9.1 | 20.3 | Logto | Logto | CWE-178 | Principal/domain lookup without case normalization |
| CVE-2026-65462 | 7.6 | 20.4 | Uncanny Owl | Uncanny Automator | CWE-89 | WordPress Uncanny Automator plugin <= 7.3.2 - SQL Injection vulnerability |
| CVE-2026-27064 | 9.1 | 20.2 | EverPress | Mailster | CWE-434 | WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability |
| CVE-2026-61943 | 7.5 | 20.3 | Shahjada | WPDM – Premium Packages | CWE-862 | WordPress WPDM – Premium Packages plugin <= 6.2.0 - Broken Access Control vul… |
| CVE-2026-57716 | 5.3 | 20.3 | videowhisper | Broadcast Live Video | CWE-22 | WordPress Broadcast Live Video plugin <= 7.2.4 - Arbitrary File Deletion vuln… |
| CVE-2026-27355 | 5.3 | 20.2 | metaphorcreations | Ditty | CWE-862 | WordPress Ditty plugin <= 3.1.66 - Broken Access Control vulnerability |
| CVE-2026-25427 | 5.4 | 19.9 | DigitalME | eRoom | CWE-862 | WordPress eRoom plugin <= 1.7.1 - Broken Access Control vulnerability |
| CVE-2026-27391 | 5.4 | 19.9 | Stylemix | uListing | CWE-862 | WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability |
| CVE-2026-65479 | 5.4 | 19.9 | MVP Themes | Reviewer | CWE-862 | WordPress Reviewer plugin <= 3.14.2 - Broken Access Control vulnerability |
| CVE-2026-15611 | 9.1 | 19.8 | Logto | Logto | CWE-287 | Unverified email-based SSO account linking |
| CVE-2026-65494 | 7.1 | 19.7 | Dokan | Dokan Pro | CWE-89 | WordPress Dokan Pro plugin <= 5.0.2 - SQL Injection vulnerability |
| CVE-2026-47755 | 6.5 | 19.8 | itflow-org | itflow | CWE-639 | ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unp… |
| CVE-2026-9713 | 7.5 | 19.7 | King-Theme | Product Designer for WooCommerce WordPress | Lumise | CWE-89 | Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticate… |
| CVE-2026-27377 | 6.7 | 19.2 | axiomthemes | QuickCal - Appointment Booking Calendar for WordPress | CWE-862 | WordPress QuickCal - Appointment Booking Calendar for WordPress plugin <= 1.0… |
| CVE-2026-16745 | 8.8 | 19.1 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-346 | Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-tok… |
| CVE-2026-47722 | 8.7 | 19.1 | juev | nebula-mesh | CWE-94 | nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml |
| CVE-2026-13009 | 6.5 | 19.1 | wupsales | AI Copilot – Content Generator | CWE-89 | AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0]… |
| CVE-2026-15761 | 6.5 | 19.1 | tickera | Tickera – Sell Tickets & Manage Events | CWE-89 | Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filte… |
| CVE-2026-59540 | 9.8 | 19.0 | Cozy Vision Technologies Pvt. Ltd. | SMS Alert Order Notifications | CWE-266 | WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalatio… |
| CVE-2026-64873 | 9.8 | 19.0 | regularlabs.com | Cache Cleaner Pro extension for Joomla | CWE-918 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension |
| CVE-2026-59545 | 8.1 | 18.9 | miniOrange | miniOrange Discord Integration | CWE-288 | WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authenticat… |
| CVE-2026-27372 | 6.5 | 19.0 | Pepro Dev. Group | PeproDev Ultimate Invoice | CWE-201 | WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Sensitive Data Exposure… |
| CVE-2026-50039 | 8.7 | 18.9 | MZ Automation | libIEC61850 | CWE-121 | Stack-based Buffer Overflow in MZ Automation libIEC61850 |
| CVE-2026-65896 | 7.1 | 18.9 | getgrav | grav | CWE-73 | Grav API Plugin before 1.0.10 Path Traversal via move |
| CVE-2026-16807 | 8.8 | 18.2 | Chrome | CWE-787 | Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowe… | |
| CVE-2026-6924 | 8.7 | 18.2 | Silicon Labs | Silicon Labs Matter Github | CWE-336 | Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path |
| CVE-2026-50032 | 8.7 | 18.2 | MZ Automation | libIEC61850 | CWE-476 | NULL Pointer Dereference in MZ Automation libIEC61850 |
| CVE-2026-16765 | 5.5 | 18.2 | CodeAstro | Online Classroom | CWE-74 | CodeAstro Online Classroom loginlinkadmin.php sql injection |
| CVE-2026-15037 | 2.9 | 18.1 | Qt | Qt | CWE-91 | XML injection vulnerability in QDom comment, CDATA and processing-instruction… |
| CVE-2026-65450 | 8.5 | 17.9 | RomanCode | MapSVG | CWE-89 | WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
| CVE-2026-65451 | 8.5 | 17.9 | RomanCode | MapSVG | CWE-89 | WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
| CVE-2026-65454 | 8.5 | 17.9 | ExpressTech Systems | Quiz And Survey Master | CWE-89 | WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerability |
| CVE-2026-65526 | 8.5 | 17.9 | Themeisle | Visualizer | CWE-89 | WordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerability |
| CVE-2026-28698 | 9.2 | 17.7 | Pronetiqs | Panduit Intravue | CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in… |
| CVE-2026-65491 | 4.3 | 17.7 | Jonathan Daggerhart | Query Wrangler | CWE-862 | WordPress Query Wrangler plugin <= 1.5.57 - Broken Access Control vulnerability |
| CVE-2026-12353 | 5.3 | 17.6 | Red Hat | Red Hat Certificate System 9 | CWE-772 | Rhcs: memory leak during https connection leads to denial of service |
| CVE-2026-16002 | 8.8 | 17.6 | MZ Automation | lib60870 | CWE-125 | Out-of-bounds Read in MZ Automation lib60870 |
| CVE-2026-65759 | 8.7 | 17.5 | joomshaper.com | Easy Store extension for Joomla | CWE-284 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in … |
| CVE-2026-43823 | 7.5 | 17.3 | Apple | swift-crypto | CWE-415 | When initializing an RSA public key from DER or PEM bytes throws an error, th… |
| CVE-2026-65490 | 5.3 | 16.7 | mischiefmarmot | Create by Mediavine | CWE-497 | WordPress Create by Mediavine plugin <= 2.5.3 - Sensitive Data Exposure vulne… |
| CVE-2026-16804 | 8.3 | 16.6 | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a re… | |
| CVE-2026-65760 | 9.2 | 16.5 | joomshaper.com | Easy Store extension for Joomla | CWE-284 | Joomla Extension - joomshaper.com - cross-customer order and personal informa… |
| CVE-2026-13119 | 6.5 | 16.5 | roundupwp | Registrations for the Events Calendar – Event Registration Plugin | CWE-89 | Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) S… |
| CVE-2026-15448 | 6.5 | 16.5 | tickera | Tickera – Sell Tickets & Manage Events | CWE-89 | Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_statu… |
| CVE-2026-57703 | 6.3 | 16.5 | sunshinephotocart | Sunshine Photo Cart | CWE-862 | WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vuln… |
| CVE-2026-15630 | 9.9 | 16.1 | Casdoor | Casdoor | CWE-269 | CVE-2026-15630 |
| CVE-2026-59547 | 7.5 | 16.0 | Easy Payment | Payment Gateway for PayPal on WooCommerce | CWE-862 | WordPress Payment Gateway for PayPal on WooCommerce plugin <= 9.1.4 - Broken … |
| CVE-2026-61954 | 7.5 | 16.0 | PayU India | PayU India | CWE-862 | WordPress PayU India plugin <= 3.8.9 - Broken Access Control vulnerability |
| CVE-2026-65430 | 7.5 | 16.0 | regularlabs.com | GeoIP extension for Joomla | CWE-200 | Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP exte… |
| CVE-2026-65755 | 7.5 | 16.0 | regularlabs.com | Articles Anywhere extension for Joomla | CWE-524 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Ar… |
| CVE-2026-15404 | 6.4 | 15.7 | niklaslindemann | Bulk Page Generator – LPagery | CWE-79 | Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site… |
| CVE-2026-15646 | 6.4 | 15.7 | berocket | Brands for WooCommerce | CWE-79 | Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-S… |
| CVE-2026-27423 | 4.3 | 15.8 | Roland Barker | Participants Database | CWE-862 | WordPress Participants Database plugin <= 2.7.8.4 - Broken Access Control vul… |
| CVE-2026-61973 | 4.3 | 15.8 | WooLentor | ShopLentor Pro | CWE-862 | WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability |
| CVE-2026-65457 | 4.3 | 15.8 | yoomoney | ЮKassa для WooCommerce | CWE-862 | WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Broken Access Control vul… |
| CVE-2026-57717 | 6.5 | 15.6 | knitpay | Knit Pay | CWE-862 | WordPress Knit Pay plugin <= 9.6.0.0 - Broken Access Control vulnerability |
| CVE-2026-12082 | 7.5 | 15.3 | Unknown | Praison AI SEO | CWE-862 | Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post… |
| CVE-2026-65474 | 5.3 | 15.4 | WPManageNinja | Ninja Tables | CWE-497 | WordPress Ninja Tables plugin <= 5.2.10 - Sensitive Data Exposure vulnerability |
| CVE-2026-65498 | 5.3 | 15.4 | Complianz | Complianz | CWE-497 | WordPress Complianz plugin <= 7.5.0 - Sensitive Data Exposure vulnerability |
| CVE-2026-65505 | 5.3 | 15.4 | bdthemes | Ultimate Store Kit Elementor Addons | CWE-497 | WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Sensitive Dat… |
| CVE-2026-65521 | 5.3 | 15.4 | Mahmudul Hasan Arif | WP Social Ninja | CWE-497 | WordPress WP Social Ninja plugin <= 4.3.0 - Sensitive Data Exposure vulnerabi… |
| CVE-2026-65761 | 9.3 | 14.9 | joomshaper.com | Easy Store extension for Joomla | CWE-89 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Sto… |
| CVE-2026-57699 | 7.1 | 14.9 | bqworks | Slider Pro | CWE-79 | WordPress Slider Pro plugin <= 4.8.13 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-59525 | 9.3 | 14.9 | Roland Barker | Participants Database | CWE-89 | WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability |
| CVE-2026-59526 | 9.3 | 14.9 | RomanCode | MapSVG | CWE-89 | WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
| CVE-2026-16768 | 5.3 | 14.9 | GNOME | gdk-pixbuf | CWE-125 | Gdk-pixbuf: out-of-bounds read in ico parser |
| CVE-2026-57425 | 6.5 | 14.7 | wpdesk | Autopay dla WooCommerce | CWE-862 | WordPress Autopay dla WooCommerce plugin <= 2.2.27 - Broken Access Control vu… |
| CVE-2026-61946 | 6.5 | 14.7 | Easy Appointments | Easy Appointments | CWE-639 | WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object Refere… |
| CVE-2026-15687 | 2.4 | 14.6 | Kubernetes | kubernetes-client/java | CWE-22 | Path traversal via non-tar copyDirectoryFromPod |
| CVE-2026-65895 | 8.2 | 14.6 | getgrav | grav | CWE-862 | Grav API Plugin before 1.0.10 Broken Access Control |
| CVE-2026-16764 | 2.1 | 14.4 | OWASP | DefectDojo | CWE-266 | OWASP DefectDojo API/Web serializers.py UserSerializer privileges management |
| CVE-2026-40430 | 8.7 | 14.3 | Pronetiqs | Panduit Intravue | CWE-256 | Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs |
| CVE-2026-65899 | 5.1 | 14.1 | cure53 | DOMPurify | CWE-693 | DOMPurify before 3.4.9 Trusted Types Policy State Contamination |
| CVE-2026-15614 | 7.5 | 14.0 | Logto | Logto | CWE-294 | IdP-initiated SAML sessions not reliably invalidated (replay) |
| CVE-2026-59514 | 9.3 | 14.0 | MightyNetworks vs BuddyBoss | Buddyboss Platform | CWE-89 | WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability |
| CVE-2026-21653 | 7.2 | 13.9 | Johnson Controls | CCure 9000 and victor application server | CWE-918 | CCure and Victor Application Server - Server Side Request Forgery |
| CVE-2026-25466 | 5.3 | 13.7 | WPGMaps | WP Go Maps | CWE-862 | WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability |
| CVE-2026-65452 | 5.3 | 13.7 | motov.net | Ebook Store | CWE-862 | WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability |
| CVE-2026-65485 | 5.3 | 13.7 | Daniel Iser | Content Control | CWE-862 | WordPress Content Control plugin <= 2.6.5 - Broken Access Control vulnerability |
| CVE-2026-65486 | 5.3 | 13.7 | Bastien Ho | Event post | CWE-862 | WordPress Event post plugin <= 6.0.1 - Broken Access Control vulnerability |
| CVE-2026-65489 | 5.3 | 13.7 | LA-Studio | LA-Studio Element Kit for Elementor | CWE-862 | WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access… |
| CVE-2026-65501 | 5.3 | 13.7 | vendidero | Shiptastic for WooCommerce | CWE-639 | WordPress Shiptastic for WooCommerce plugin <= 5.1.0 - Insecure Direct Object… |
| CVE-2026-65532 | 7.6 | 13.5 | PersianScript | Persian Woocommerce SMS | CWE-89 | WordPress Persian Woocommerce SMS plugin <= 7.2.2 - SQL Injection vulnerability |
| CVE-2026-64872 | 6.5 | 13.2 | regularlabs.com | Cache Cleaner Pro extension for Joomla | CWE-22 | Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro exte… |
| CVE-2026-65713 | 6.5 | 13.2 | regularlabs.com | Modals Pro extension for Joomla | CWE-22 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro ext… |
| CVE-2026-63226 | 6.9 | 13.2 | Ricoh Company | Ricoh printers and Multifunction Printers (MFPs) | CWE-923 | Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do… |
| CVE-2026-65530 | 4.3 | 13.0 | Templatespare | TemplateSpare | CWE-862 | WordPress TemplateSpare plugin <= 4.2.2 - Broken Access Control vulnerability |
| CVE-2026-65699 | 2.3 | 13.0 | reworkd | AgentGPT | CWE-639 | AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation |
| CVE-2026-7120 | 5.3 | 12.9 | @fastify/static | @fastify/static | CWE-180 | @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths |
| CVE-2026-65478 | 5.4 | 12.8 | CridioStudio | ListingPro | CWE-862 | WordPress ListingPro plugin <= 2.9.10 - Broken Access Control vulnerability |
| CVE-2026-65458 | 4.3 | 12.1 | Chouby | Polylang | CWE-497 | WordPress Polylang and Polylang Pro plugins <= 3.8.5 - Sensitive Data Exposur… |
| CVE-2026-64875 | 6.5 | 12.1 | regularlabs.com | GeoIP extension for Joomla | CWE-290 | Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP exten… |
| CVE-2026-27399 | 5.3 | 12.0 | WebWizards | MarketKing | CWE-862 | WordPress MarketKing plugin <= 2.1.40 - Broken Access Control vulnerability |
| CVE-2026-27418 | 5.3 | 12.0 | Epsiloncool | WP Fast Total Search | CWE-862 | WordPress WP Fast Total Search plugin <= 1.81.282 - Broken Access Control vul… |
| CVE-2026-27422 | 5.3 | 12.0 | bPlugins | YT Player | CWE-862 | WordPress YT Player plugin <= 2.0.9 - Broken Access Control vulnerability |
| CVE-2026-61972 | 5.3 | 12.0 | WooLentor | ShopLentor Pro | CWE-862 | WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability |
| CVE-2026-65453 | 5.3 | 12.0 | motov.net | Ebook Store | CWE-862 | WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability |
| CVE-2026-65468 | 5.3 | 12.0 | Crocoblock. Jetimpex Inc. | JetBooking | CWE-862 | WordPress JetBooking plugin <= 4.1.2 - Broken Access Control vulnerability |
| CVE-2026-65469 | 5.3 | 12.0 | Strategy11 Team | AWP Classifieds | CWE-862 | WordPress AWP Classifieds plugin <= 4.4.7 - Broken Access Control vulnerability |
| CVE-2026-65472 | 5.3 | 12.0 | Kit | Kit (formerly ConvertKit) | CWE-862 | WordPress Kit (formerly ConvertKit) plugin <= 3.3.5 - Broken Access Control v… |
| CVE-2026-65476 | 5.3 | 12.0 | uxper | Civi | CWE-862 | WordPress Civi theme <= 2.2.4 - Broken Access Control vulnerability |
| CVE-2026-65487 | 5.3 | 12.0 | ThemeGoods | Photography | CWE-862 | WordPress Photography theme <= 7.7.6 - Broken Access Control vulnerability |
| CVE-2026-65506 | 5.3 | 12.0 | sonaar | MP3 Audio Player for Music, Radio & Podcast by Sonaar | CWE-862 | WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.1… |
| CVE-2026-48013 | 4.1 | 11.9 | shopware | shopware | CWE-918 | Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation |
| CVE-2026-61945 | 6.5 | 11.8 | MultiVendorX | WooCommerce Product Stock Alert | CWE-497 | WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Ex… |
| CVE-2026-8287 | 4.3 | 11.8 | BizimHesap Information Systems Industry and Trade Inc. | Online Pre-Accounting Software | CWE-770 | Unrestricted File Upload in BizimHesap Information Systems' Online Pre-Accoun… |
| CVE-2026-24552 | 8.5 | 11.6 | John-Michael L'Allier | Create | CWE-89 | WordPress Create plugin <= 2.5.3 - SQL Injection vulnerability |
| CVE-2026-25405 | 8.5 | 11.6 | DigitalME | eRoom | CWE-89 | WordPress eRoom plugin <= 1.7.1 - SQL Injection vulnerability |
| CVE-2026-59513 | 6.5 | 11.7 | masteriyo | Masteriyo - LMS | CWE-79 | WordPress Masteriyo - LMS plugin <= 2.3.0 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-65902 | 5.3 | 11.4 | cure53 | DOMPurify | CWE-501 | DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags |
| CVE-2026-65537 | 4.3 | 11.3 | Themeisle | Cyr to Lat reloaded – transliteration of links and file names | CWE-862 | WordPress Cyr to Lat reloaded – transliteration of links and file names plugi… |
| CVE-2026-7232 | 7.2 | 11.0 | FormCraft | FormCraft | CWE-79 | FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix … |
| CVE-2026-44955 | 6.9 | 11.0 | Pronetiqs | Panduit Intravue | CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in… |
| CVE-2026-34496 | 7.1 | 10.8 | Johnson Controls | victor Web | CWE-269 | victor Web - Priviledge Escalation |
| CVE-2026-57384 | 6.5 | 10.8 | Membership Software | WishList Member X | CWE-79 | WordPress WishList Member X plugin <= 3.32.0 - Cross Site Scripting (XSS) vul… |
| CVE-2026-15966 | 9.8 | 10.7 | Progress | MOVEit Transfer | CWE-942 | Improper CORS handling in MOVEit Transfer |
| CVE-2026-15967 | 9.8 | 10.7 | Progress | MOVEit Transfer | CWE-613 | MOVEit Transfer refresh-token processing does not enforce updated account res… |
| CVE-2026-65903 | 5.1 | 10.2 | cure53 | DOMPurify | CWE-697 | DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS |
| CVE-2026-65484 | 6.3 | 9.9 | AnalogWP | Style Kits | CWE-862 | WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability |
| CVE-2026-21723 | 5.3 | 10.0 | Grafana | Grafana OSS | CWE-400 | CVE-2026-21723 Record |
| CVE-2026-65703 | 8.5 | 9.8 | FFmpeg | FFmpeg | CWE-787 | FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder |
| CVE-2026-65758 | 8.2 | 9.7 | tassos.gr | Convert Forms extension for Joomla | CWE-284 | Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms exten… |
| CVE-2026-65456 | 4.3 | 9.8 | PickPlugins | Product Slider for WooCommerce | CWE-639 | WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct … |
| CVE-2026-65529 | 5.3 | 9.6 | Iqonic Design | Graphina | CWE-862 | WordPress Graphina plugin <= 3.1.12 - Broken Access Control vulnerability |
| CVE-2026-15647 | 4.4 | 9.6 | berocket | Brands for WooCommerce | CWE-79 | Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-… |
| CVE-2026-65516 | 7.2 | 9.4 | Pepro Dev. Group | PeproDev Ultimate Invoice | CWE-918 | WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Server Side Request For… |
| CVE-2026-65499 | 6.5 | 9.4 | Pepro Dev. Group | PeproDev Ultimate Invoice | CWE-862 | WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Broken Access Control v… |
| CVE-2026-9729 | 6.4 | 9.3 | webpushr | Web Push Notifications – Webpushr | CWE-79 | Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-… |
| CVE-2026-15394 | 6.4 | 9.3 | mahethekiller | Header Footer Script Adder | CWE-79 | Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site… |
| CVE-2026-15794 | 6.4 | 9.3 | berocket | Grid/List View for WooCommerce | CWE-79 | Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored… |
| CVE-2026-59512 | 7.1 | 9.1 | PI Web Solution | Product Enquiry for WooCommerce | CWE-79 | WordPress Product Enquiry for WooCommerce plugin <= 2.2.34.43 - Cross Site Sc… |
| CVE-2026-65911 | 5.1 | 9.0 | cure53 | DOMPurify | CWE-79 | DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage |
| CVE-2026-7534 | 7.2 | 9.0 | FantasticPlugins | SUMO Reward Points for WooCommerce | CWE-79 | SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-S… |
| CVE-2026-12421 | 7.2 | 9.0 | n/a | ARforms | CWE-79 | ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password'… |
| CVE-2026-9635 | 6.4 | 8.6 | mythemeshop | WP Shortcode by MyThemeShop | CWE-79 | WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored C… |
| CVE-2026-61944 | 7.1 | 8.5 | Bookly | Bookly | CWE-79 | WordPress Bookly plugin <= 27.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-38764 | 7.8 | 8.4 | n/a | n/a | CWE-269 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local at… |
| CVE-2026-65913 | 5.1 | 8.4 | cure53 | DOMPurify | CWE-1321 | DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES |
| CVE-2026-25424 | 4.3 | 8.4 | mediavine | Mediavine Control Panel | CWE-862 | WordPress Mediavine Control Panel plugin <= 2.10.10 - Broken Access Control v… |
| CVE-2026-27392 | 4.3 | 8.4 | Stylemix | uListing | CWE-862 | WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability |
| CVE-2026-65535 | 4.3 | 8.3 | Takayuki Miyauchi | TinyMCE Templates | CWE-497 | WordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnera… |
| CVE-2026-15612 | 9.1 | 8.1 | Logto | Logto | CWE-345 | LOIDC nonce validation bypass |
| CVE-2026-15615 | 7.5 | 8.1 | Logto | Logto | CWE-345 | SAML <Conditions> element not validated |
| CVE-2026-15968 | 5.4 | 8.0 | Progress | MOVEit Transfer | CWE-79 | Stored XSS vulnerability in MOVEit Transfer |
| CVE-2026-64785 | 5.3 | 7.9 | Apple | swift-nio-http2 | CWE-444 | SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR,… |
| CVE-2026-57370 | 7.1 | 7.8 | CODEPRESS IT Solutions LLC | Visitor Traffic Real Time Statistics Pro | CWE-79 | WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.9.1 - Reflect… |
| CVE-2026-57701 | 7.1 | 7.8 | WebCodingPlace | Real Estate Manager Pro | CWE-79 | WordPress Real Estate Manager Pro plugin <= 12.8.5 - Reflected Cross Site Scr… |
| CVE-2026-57704 | 7.1 | 7.8 | StoreApps | Smart Manager | CWE-79 | WordPress Smart Manager plugin <= 8.90.0 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57769 | 7.1 | 7.8 | ThemeGoods | Grand Photography | CWE-79 | WordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (… |
| CVE-2026-57809 | 7.1 | 7.8 | AffiliateWP | AffiliateWP | CWE-79 | WordPress AffiliateWP plugin <= 2.34.0 - Reflected Cross Site Scripting (XSS)… |
| CVE-2026-59517 | 7.1 | 7.8 | hassantafreshi | Easy Form Builder | CWE-79 | WordPress Easy Form Builder plugin <= 4.0.12 - Cross Site Scripting (XSS) vul… |
| CVE-2026-65492 | 7.1 | 7.8 | Dokan WordPress Plugin | Dokan Pro | CWE-79 | WordPress Dokan Pro plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65510 | 7.1 | 7.8 | Pepro Dev. Group | PeproDev Ultimate Invoice | CWE-79 | WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Cross Site Scripting (X… |
| CVE-2026-65511 | 7.1 | 7.8 | pixelacehq | Manual - Documentation, Knowledge Base & Education WordPress Theme | CWE-79 | WordPress Manual - Documentation, Knowledge Base & Education WordPress Theme … |
| CVE-2026-65900 | 5.1 | 7.9 | cure53 | DOMPurify | CWE-79 | DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM |
| CVE-2026-65525 | 5.3 | 7.4 | uxper | Civi Framework | CWE-862 | WordPress Civi Framework plugin <= 2.2.0 - Broken Access Control vulnerability |
| CVE-2026-57374 | 7.1 | 7.2 | Wisetr INC. | Funnel Kit Funnel Builder PRO | CWE-79 | WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.7 - Cross Site Scrip… |
| CVE-2026-57397 | 7.1 | 7.3 | ThimPress. | Coaching | CWE-79 | WordPress Coaching theme <= 3.9.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57427 | 7.1 | 7.2 | Download Monitor | Download Monitor - WPForms Lock | CWE-79 | WordPress Download Monitor - WPForms Lock plugin <= 1.0.4 - Cross Site Script… |
| CVE-2026-57428 | 7.1 | 7.2 | BoldGrid | Sprout Clients | CWE-79 | WordPress Sprout Clients plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57735 | 7.1 | 7.2 | Soflyy | Breakdance | CWE-79 | WordPress Breakdance plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57767 | 7.1 | 7.2 | CodeCabin.io | WP Google Maps Pro | CWE-79 | WordPress WP Google Maps Pro plugin <= 10.1.02 - Cross Site Scripting (XSS) v… |
| CVE-2026-61947 | 7.1 | 7.2 | WPVibes | Form Vibes – Database Manager for Forms | CWE-79 | WordPress Form Vibes – Database Manager for Forms plugin <= 1.5.2 - Cross Sit… |
| CVE-2026-65912 | 5.1 | 7.2 | cure53 | DOMPurify | CWE-79 | DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR |
| CVE-2026-60122 | 8.5 | 7.2 | gpsd | gpsd | CWE-94 | gpsd gpsprof Code Injection via SKY.satellites used Field |
| CVE-2025-68081 | 5.9 | 6.9 | Lester Chan | WP-Polls | CWE-79 | WordPress WP-Polls plugin <= 2.77.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-24628 | 5.9 | 6.9 | Supsystic | Photo Gallery by Supsystic | CWE-79 | WordPress Photo Gallery by Supsystic plugin <= 1.16.3 - Cross Site Scripting … |
| CVE-2026-65483 | 5.9 | 6.9 | hashthemes | HashThemes Demo Importer | CWE-79 | WordPress HashThemes Demo Importer plugin <= 1.4.2 - Cross Site Scripting (XS… |
| CVE-2026-65473 | 6.5 | 6.8 | Nexcess | Virtue/Ascend/Pinnacle Toolkit | CWE-79 | WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12 - Cross Site Script… |
| CVE-2026-65898 | 5.1 | 6.4 | cure53 | DOMPurify | CWE-79 | DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig |
| CVE-2026-65914 | 5.3 | 6.3 | cure53 | DOMPurify | CWE-79 | DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization |
| CVE-2026-65901 | 5.1 | 6.3 | cure53 | DOMPurify | CWE-79 | DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName |
| CVE-2026-21655 | 8.7 | 6.2 | Johnson Control | victor | CWE-502 | C-CURE 9000 and Victor application server - Deserialization of Untrusted Data |
| CVE-2026-50103 | 7.1 | 6.2 | MZ Automation | libIEC61850 | CWE-228 | Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC6… |
| CVE-2026-65904 | 2.3 | 6.2 | cure53 | DOMPurify | CWE-754 | DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode |
| CVE-2026-65696 | 5.3 | 6.1 | sct | overseerr | CWE-639 | Overseerr 1.35.0 Authorization Bypass via pushSubscriptions API |
| CVE-2026-48012 | 4.3 | 5.9 | shopware | shopware | CWE-601 | Shopware SSO referer trust leading to an arbitrary redirect target |
| CVE-2026-65524 | 4.3 | 5.9 | ThemeFusion | Avada Custom Branding | CWE-862 | WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnera… |
| CVE-2026-27403 | 6.5 | 5.7 | NerdPress | Hubbub Lite | CWE-79 | WordPress Hubbub Lite plugin <= 1.36.3 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-65449 | 6.5 | 5.7 | RomanCode | MapSVG | CWE-79 | WordPress MapSVG plugin <= 8.14.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65465 | 6.5 | 5.8 | Crocoblock. Jetimpex Inc. | JetElements For Elementor | CWE-79 | WordPress JetElements For Elementor plugin <= 2.9.1.1 - Cross Site Scripting … |
| CVE-2026-65470 | 6.5 | 5.7 | WPManageNinja | Fluent Support | CWE-79 | WordPress Fluent Support plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-65480 | 6.5 | 5.7 | CodexThemes | TheGem | CWE-79 | WordPress TheGem theme < 5.12.1.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65482 | 6.5 | 5.8 | LA-Studio | LA-Studio Element Kit for Elementor | CWE-79 | WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Sc… |
| CVE-2026-65503 | 6.5 | 5.8 | bdthemes | Ultimate Store Kit Elementor Addons | CWE-79 | WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Cross Site Sc… |
| CVE-2026-65514 | 6.5 | 5.7 | codepeople | Appointment Hour Booking | CWE-79 | WordPress Appointment Hour Booking plugin <= 1.5.86 - Cross Site Scripting (X… |
| CVE-2026-65518 | 6.5 | 5.8 | Scott Paterson | Accept Donations with PayPal & Stripe | CWE-79 | WordPress Accept Donations with PayPal & Stripe plugin <= 1.5.5 - Cross Site … |
| CVE-2026-65519 | 6.5 | 5.8 | gt3themes | Photo Gallery | CWE-79 | WordPress Photo Gallery plugin <= 2.7.7.29 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-65522 | 6.5 | 5.8 | pixelacehq | Manual - Documentation, Knowledge Base & Education WordPress Theme | CWE-79 | WordPress Manual - Documentation, Knowledge Base & Education WordPress theme … |
| CVE-2026-24639 | 4.4 | 5.7 | Ronald Huereca | Photo Block | CWE-918 | WordPress Photo Block plugin <= 1.7.1 - Server Side Request Forgery (SSRF) vu… |
| CVE-2026-65496 | 4.4 | 5.7 | Complianz | Complianz | CWE-918 | WordPress Complianz plugin <= 7.5.0 - Server Side Request Forgery (SSRF) vuln… |
| CVE-2026-65697 | 5.1 | 5.7 | usefathom | fathom | CWE-79 | Fathom Lite 1.3.1 Stored XSS via /collect Endpoint |
| CVE-2026-16584 | 7.3 | 5.5 | AWS | aws-api-mcp-server | CWE-455 | AWS API MCP Server Security Policy Bypass via Startup Failure |
| CVE-2026-15212 | 8.8 | 5.4 | wpo365 | WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) | CWE-352 | WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 … |
| CVE-2026-57373 | 6.5 | 5.3 | Wisetr INC. | Funnel Kit Funnel Builder PRO | CWE-79 | WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.4 - Cross Site Scrip… |
| CVE-2026-65466 | 4.9 | 4.8 | Crocoblock. Jetimpex Inc. | JetBooking | CWE-918 | WordPress JetBooking plugin <= 4.1.2 - Server Side Request Forgery (SSRF) vul… |
| CVE-2026-39155 | 6.5 | 4.7 | n/a | n/a | CWE-345 | Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod… |
| CVE-2026-11804 | 5.2 | 4.7 | Tridium | Niagara Framework | CWE-280 | Program Module Vulnerability |
| CVE-2026-9066 | 6.1 | 4.6 | Unknown | WP Compress | CWE-79 | WP Compress < 7.10.04 - Reflected XSS via test_zone |
| CVE-2026-64810 | 6.1 | 4.6 | JetBrains | IntelliJ IDEA | CWE-79 | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an ID… |
| CVE-2026-65756 | 6.1 | 4.6 | regularlabs.com | Keyboard Shortcuts extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension |
| CVE-2026-65534 | 5.9 | 4.6 | Charlie Etienne | Custom links in Elementor Image Carousel | CWE-79 | WordPress Custom links in Elementor Image Carousel plugin <= 1.1.1 - Cross Si… |
| CVE-2026-65538 | 5.9 | 4.6 | Nilo Velez | Machete | CWE-79 | WordPress Machete plugin <= 5.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65550 | 5.9 | 4.6 | wpshopmart | Tabs | CWE-79 | WordPress Tabs plugin <= 2.5 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65712 | 6.2 | 4.3 | regularlabs.com | CDN for Joomla Pro extension for Joomla | CWE-22 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla… |
| CVE-2026-65467 | 4.9 | 4.3 | Crocoblock. Jetimpex Inc. | JetEngine | CWE-918 | WordPress JetEngine plugin <= 3.8.11 - Server Side Request Forgery (SSRF) vul… |
| CVE-2026-65531 | 4.8 | 4.2 | Themeum | Qubely | CWE-862 | WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerability |
| CVE-2026-65471 | 9.6 | 4.1 | Avada Studio | Avada Core | CWE-352 | WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vul… |
| CVE-2026-64802 | 7.8 | 4.1 | JetBrains | GoLand | CWE-94 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible befor… |
| CVE-2026-64803 | 7.8 | 4.1 | JetBrains | GoLand | CWE-94 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible befor… |
| CVE-2026-52684 | 3.7 | 4.1 | PowerDNS | Recursor | — | Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack |
| CVE-2026-57785 | 8.8 | 4.0 | ApusTheme | ApusListing | CWE-352 | WordPress ApusListing theme <= 1.2.63 - Cross Site Request Forgery (CSRF) vul… |
| CVE-2026-9577 | 4.8 | 4.0 | Unknown | Post Status Notifier Lite | CWE-79 | Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter |
| CVE-2026-64804 | 8.4 | 3.8 | JetBrains | WebStorm | CWE-829 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible bef… |
| CVE-2026-64805 | 8.4 | 3.8 | JetBrains | WebStorm | CWE-829 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible bef… |
| CVE-2026-64806 | 8.4 | 3.8 | JetBrains | WebStorm | CWE-829 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible bef… |
| CVE-2026-64808 | 8.4 | 3.8 | JetBrains | PhpStorm | CWE-829 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible bef… |
| CVE-2026-64809 | 8.4 | 3.8 | JetBrains | PhpStorm | CWE-829 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible bef… |
| CVE-2026-65528 | 6.5 | 3.7 | bannersky | BSK PDF Manager | CWE-79 | WordPress BSK PDF Manager plugin <= 3.8 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-65533 | 6.5 | 3.7 | wbolt.com | Smart SEO Tool | CWE-79 | WordPress Smart SEO Tool plugin <= 4.1.2 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-48530 | 5.1 | 3.7 | GFI Software | GFI Archiver | CWE-79 | GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx |
| CVE-2026-48531 | 5.1 | 3.7 | GFI Software | GFI Archiver | CWE-79 | GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx |
| CVE-2026-48532 | 5.1 | 3.7 | GFI Software | GFI Archiver | CWE-79 | GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx |
| CVE-2026-48534 | 5.1 | 3.7 | GFI Software | GFI Archiver | CWE-79 | GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx |
| CVE-2026-48535 | 5.1 | 3.7 | GFI Software | GFI Archiver | CWE-79 | GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx |
| CVE-2026-48536 | 5.1 | 3.7 | GFI Software | GFI Archiver | CWE-79 | GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx |
| CVE-2026-48537 | 5.1 | 3.7 | GFI Software | GFI Archiver | CWE-79 | GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx |
| CVE-2026-48538 | 5.1 | 3.7 | GFI Software | GFI Archiver | CWE-79 | GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx |
| CVE-2026-48539 | 5.1 | 3.7 | GFI Software | GFI Archiver | CWE-79 | GFI Archiver < 15.13 Stored XSS via MailInsights.aspx |
| CVE-2026-65010 | 4.4 | 3.3 | huggingface | datasets | CWE-61 | Datasets Symlink-following Arbitrary File Write via Extractor.extract() |
| CVE-2026-57784 | 9.6 | 3.1 | Ninja Forms | Ninja Forms File Uploads Extension | CWE-352 | WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Re… |
| CVE-2026-65757 | 8.1 | 3.1 | regularlabs.com | Modules Anywhere extension for Joomla | CWE-352 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile… |
| CVE-2026-65475 | 6.5 | 3.1 | WP Chill | Modula Image Gallery | CWE-79 | WordPress Modula Image Gallery plugin 2.14.25-2.14.30 - Cross Site Scripting … |
| CVE-2026-65527 | 6.5 | 3.1 | lqd | LIQUID SPEECH BALLOON | CWE-79 | WordPress LIQUID SPEECH BALLOON plugin <= 1.2.5 - Cross Site Scripting (XSS) … |
| CVE-2026-64876 | 8.8 | 2.8 | regularlabs.com | GeoIP extension for Joomla | CWE-352 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile… |
| CVE-2026-65706 | 8.5 | 2.7 | FFmpeg | FFmpeg | CWE-131 | FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing |
| CVE-2026-52688 | 7.5 | 2.8 | PowerDNS | Recursor | CWE-295 | RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation |
| CVE-2026-65705 | 7.3 | 2.7 | FFmpeg | FFmpeg | CWE-131 | FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame() |
| CVE-2026-65908 | 8.6 | 2.7 | JetBrains | PyCharm | CWE-829 | In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via mal… |
| CVE-2026-64807 | 7.8 | 2.7 | JetBrains | WebStorm | CWE-829 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via… |
| CVE-2026-64811 | 7.8 | 2.7 | JetBrains | IntelliJ IDEA | CWE-829 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possibl… |
| CVE-2026-65536 | 6.5 | 2.5 | Mahdi Yousefi | افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) | CWE-352 | WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <… |
| CVE-2026-65704 | 7.3 | 2.2 | FFmpeg | FFmpeg | CWE-191 | FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder |
| CVE-2026-59678 | 7.1 | 1.9 | Linux-Gaming | PortProtonQt | CWE-863 | portprotonqt allows any users to mount and unmount arbitrary file systems and… |
| CVE-2026-52686 | 3.7 | 1.6 | PowerDNS | Recursor | CWE-347 | Wildcard CNAME proof validation bypass |
| CVE-2026-65512 | 5.4 | 1.4 | Melapress | WP Activity Log | CWE-352 | WordPress WP Activity Log and WP Activity Log Premium plugins <= 5.6.4 - Cros… |
| CVE-2026-6390 | 6.8 | 1.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-134 | Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of… |
| CVE-2026-59677 | 6.8 | 1.3 | SELinuxProject | selinux | CWE-862 | Process Kill Attack Vector in killall() in seunshare |
| CVE-2026-24537 | 4.3 | 1.3 | Alex Volkov | WP Accessibility Helper (WAH) | CWE-352 | WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request … |
| CVE-2026-65460 | 4.3 | 1.3 | zarinpal | Zarinpal Gateway | CWE-352 | WordPress Zarinpal Gateway plugin <= 5.1.0 - Cross Site Request Forgery (CSRF… |
| CVE-2026-61981 | 5.4 | 1.2 | QuantumCloud | Simple Link Directory Pro | CWE-352 | WordPress Simple Link Directory Pro plugin <= 15.0.8 - Cross Site Request For… |
| CVE-2026-65464 | 5.4 | 1.2 | Nexcess | GiveWP | CWE-352 | WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnera… |
| CVE-2026-65488 | 7.1 | 0.9 | LA-Studio | LA-Studio Element Kit for Elementor | CWE-352 | WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Re… |
| CVE-2026-65539 | 7.1 | 0.7 | Bimal Rekhadiya | Kwayy HTML Sitemap | CWE-352 | WordPress Kwayy HTML Sitemap plugin <= 4.0 - CSRF to Stored XSS vulnerability |
| CVE-2026-65540 | 7.1 | 0.7 | Metin Saraç | Popup for CF7 with Sweet Alert | CWE-352 | WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request… |
| CVE-2026-64871 | 5.4 | 0.7 | regularlabs.com | Cache Cleaner extension for Joomla | CWE-352 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privile… |
| CVE-2026-57626 | 7.1 | 0.5 | MailPoet | MailPoet | CWE-352 | WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) v… |
| CVE-2026-59676 | 5.8 | 0.4 | SELinuxProject | selinux | CWE-367 | Local File Deletion Attack Vector in rm_rf() in seunshare |
| CVE-2026-50044 | 7.6 | 0.3 | Pronetiqs | Panduit Intravue | CWE-326 | Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs |
| CVE-2024-58023 | 8.4 | 0.2 | Bosch | Bosch Configuration Manager | CWE-312 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 al… |
| CVE-2026-43820 | 7.7 | 0.2 | Apple | swift-nio-ssl | CWE-125 | NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes f… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-23 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.