AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0241 82.7 —
AFFECTED Product Versions Fixed sysPass unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 24 Published (CNA: VulnCheck)
192 CVEs published July 24, 2026: 18 critical, 91 high, 79 medium, 4 low; 0 in KEV; 10 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 167 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 3955 | 6704 | 1324 | 2563 |
| KEV catalog size | 1670 | |||
133 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| microsoft | 653 | 1356 | 104 | 927 | 300 | 8 | 378 | 32 | 2.4 | 7.8 | .0039 | +434 |
| linux | 360 | 1278 | 180 | 999 | 80 | 0 | 27 | 3 | 0.2 | 7.8 | .0014 | +208 |
| red hat | 76 | 175 | 9 | 85 | 71 | 10 | 4 | 0 | 0.0 | 7.1 | .0028 | +35 |
| apple | 3 | 80 | 1 | 19 | 52 | 1 | 93 | 7 | 8.8 | 6.5 | .0036 | +3 |
| 26 | 35 | 6 | 24 | 1 | 1 | 73 | 5 | 14.3 | 8.8 | .0030 | +23 | |
| canonical | 3 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | +3 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | -1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 7 | 19 | 4 | 6 | 1 | 0 | 96 | 12 | 63.2 | 8.6 | .2459 | +5 |
| fortinet | 10 | 17 | 2 | 4 | 8 | 0 | 28 | 5 | 29.4 | 6.3 | .0051 | +9 |
| palo alto networks | 10 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | +7 |
| vmware | 7 | 7 | 1 | 6 | 0 | 0 | 21 | 0 | 0.0 | 8.7 | .0044 | +7 |
| f5 | 1 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | -1 |
| checkpoint | 3 | 4 | 3 | 1 | 0 | 0 | 3 | 2 | 50.0 | 9.2 | .4696 | +2 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.1 | .0877 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mozilla | 67 | 72 | 42 | 26 | 4 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +67 |
| apache | 27 | 59 | 14 | 33 | 12 | 0 | 40 | 1 | 1.7 | 7.5 | .0058 | +12 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | -3 |
| wordpress | 2 | 2 | 1 | 0 | 1 | 0 | 5 | 2 | 100.0 | 7.9 | .8435 | +2 |
| gitlab | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .4451 | 0 |
| github | 1 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 4.7 | .0017 | +1 |
| kubernetes | 1 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1109 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | +1107 |
| ibm | 32 | 40 | 16 | 11 | 13 | 0 | 7 | 0 | 0.0 | 8.4 | .0028 | +31 |
| adobe | 16 | 27 | 9 | 10 | 4 | 0 | 75 | 4 | 14.8 | 8.6 | .0144 | +9 |
| solarwinds | 15 | 19 | 15 | 1 | 1 | 0 | 11 | 4 | 21.1 | 9.1 | .0044 | +14 |
| progress | 18 | 18 | 3 | 10 | 5 | 0 | 9 | 0 | 0.0 | 7.8 | .0031 | +18 |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 |
| zohocorp | 3 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0048 | +3 |
| veeam | 1 | 1 | 0 | 1 | 0 | 0 | 4 | 0 | 0.0 | 8.4 | .0013 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 7 | 8 | 0 | 0 | 6 | 1 | 26 | 1 | 12.5 | 5.5 | .0073 | +7 |
| hikvision | 5 | 6 | 0 | 3 | 2 | 0 | 2 | 1 | 16.7 | 7.2 | .0024 | +5 |
| bosch | 2 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.0 | .0018 | +2 |
| rockwell automation | 1 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | +1 |
| siemens | 0 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 57 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | +57 |
| grafana | 8 | 41 | 2 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | +2 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| netty | 10 | 32 | 6 | 24 | 1 | 1 | 0 | 0 | 0.0 | 7.5 | .0051 | -4 |
| regularlabs.com | 29 | 29 | 6 | 14 | 9 | 0 | 0 | 0 | 0.0 | 7.5 | .0022 | +29 |
| watchguard | 17 | 28 | 1 | 18 | 9 | 0 | 4 | 0 | 0.0 | 7.3 | .0026 | +17 |
| nlnet labs | 24 | 27 | 0 | 4 | 17 | 6 | 0 | 0 | 0.0 | 5.9 | .0024 | +24 |
| mongodb | 26 | 26 | 1 | 17 | 7 | 1 | 2 | 0 | 0.0 | 7.1 | .0023 | +26 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | — |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| microsoft | 653 |
| linux | 449 |
| red hat | 90 |
| mozilla | 67 |
| surrealdb | 57 |
| apple | 40 |
| ibm | 39 |
| regularlabs.com | 29 |
| apache | 28 |
| Vendor | KEV |
|---|---|
| microsoft | 32 |
| cisco | 12 |
| apple | 7 |
| fortinet | 5 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 16 |
| crates.io | 1 |
| npm | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1710 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1710 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1710 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1710 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1710 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1710 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1710 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1710 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1710 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1710 |
EXPLOIT PUBLISHED — CVE-2026-16372 (Mozilla Firefox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16763 (localstack serverless-localstack). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16765 (CodeAstro Online Classroom). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16767 (Ne-Lexa php-zip). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-25244 (webdriverio). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-35397 (jupyter-server jupyter_server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-38764. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47075 (benoitc hackney). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56291 (balbooa.com Balbooa Forms extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63765 (chatwoot). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65010 (huggingface datasets). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65012 (invoke-ai InvokeAI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65013 (onlook repo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65694 (microweber). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65698 (voideditor void). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65916 (usmannasir cyberpanel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65917 (usmannasir cyberpanel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65918 (pytorch vision). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65920 (huggingface diffusers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66010 (cure53 DOMPurify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66041 (FFmpeg). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-7007 (zephyrproject zephyr). Public exploit reference added.
RESCORED — CVE-2024-37129 (Dell Inventory Collector). CVSS 6.7 → 7.8 (NVD).
RESCORED — CVE-2026-47304 (Microsoft .NET 10.0). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2026-54120 (Microsoft Surface Management Services). CVSS 9.9 → 8.8 (NVD).
RESCORED — CVE-2026-56160 (Microsoft Azure Red Hat OpenShift (ARO)). CVSS 9.1 → 9.9 (NVD).
RESCORED — CVE-2026-56167 (Microsoft Azure AI Search). CVSS 8.5 → 8.8 (NVD).
ENRICHED — CVE-2022-49662 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2023-52494 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2024-27390 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2025-39729 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2025-39936 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-20262 (Cisco Catalyst SD-WAN Manager). Received CVSS 6.5 and CPE data from NVD.
ENRICHED — CVE-2026-31610 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-33825 (Microsoft Defender). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-35616 (Fortinet FortiClient EMS). Received CVSS 9.8 and CPE data from NVD.
ENRICHED — CVE-2026-41091 (Microsoft Defender). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-43119 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-43216 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-45247 (Mirasvit Full Page Cache Warmer). Received CVSS 9.3 and CPE data from NVD.
ENRICHED — CVE-2026-5281 (Google Dawn). Received CVSS 8.8 and CPE data from NVD.
ENRICHED — CVE-2026-53027 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-53163 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-53332 (Linux). Received CVSS 5.5 and CPE data from NVD.
192 CVEs published. 25 box scores, 167 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0241 82.7 —
AFFECTED Product Versions Fixed sysPass unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 24 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0125 67.0 —
AFFECTED Product Versions Fixed Microsoft 365 Copilot - – —
TIMELINE Jun 4 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0097 59.1 —
AFFECTED Product Versions Fixed Azure Portal - – —
TIMELINE Jul 14 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0090 56.7 —
AFFECTED Product Versions Fixed Azure Kubernetes Service - – —
TIMELINE Jun 19 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0090 56.7 —
AFFECTED Product Versions Fixed Microsoft Purview Data Governance - – —
TIMELINE Jun 23 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0086 55.7 —
AFFECTED Product Versions Fixed Azure App Service for Linux - – —
TIMELINE Jul 1 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0077 52.6 —
AFFECTED Product Versions Fixed TOML::XS unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 24 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0071 50.5 —
AFFECTED Product Versions Fixed Azure Key Vault - – —
TIMELINE Jul 14 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0068 49.6 —
AFFECTED Product Versions Fixed Azure DNS - – —
TIMELINE Jun 29 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 9.3 .0067 49.0 —
AFFECTED Product Versions Fixed Corporate Training Management System unspecified —
TIMELINE Jan 26 Reserved by CNA Jul 24 Published (CNA: ZUSO ART)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0067 48.9 —
AFFECTED Product Versions Fixed Microsoft Exchange Online - – —
TIMELINE Jun 19 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0066 48.8 —
AFFECTED Product Versions Fixed TPDIN-Monitor-WEB2 2.3.9 – —
TIMELINE Jul 13 Reserved by CNA Jul 24 Published (CNA: icscert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0062 46.6 —
AFFECTED Product Versions Fixed Apache NimBLE unspecified —
TIMELINE May 13 Reserved by CNA Jul 24 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0060 46.0 —
AFFECTED Product Versions Fixed Apache NimBLE unspecified —
TIMELINE May 13 Reserved by CNA Jul 24 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0059 45.3 —
AFFECTED Product Versions Fixed Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder unspecified —
TIMELINE Jul 10 Reserved by CNA Jul 24 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N L 5.3 .0056 44.0 —
AFFECTED Product Versions Fixed Apache NimBLE unspecified —
TIMELINE May 14 Reserved by CNA Jul 24 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0055 43.6 —
AFFECTED Product Versions Fixed Microsoft Graph - – —
TIMELINE May 27 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0053 42.3 —
AFFECTED Product Versions Fixed Azure API Management (APIM) - – —
TIMELINE Apr 2 Reserved by CNA Jul 24 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A H N N 6.9 .0052 42.0 —
AFFECTED Product Versions Fixed datasets unspecified f989ef9b4cc6c0039a7a82458eebca49e2b58b4b
TIMELINE Jul 23 Reserved by CNA Jul 24 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P H H H 8.7 .0052 41.8 —
AFFECTED Product Versions Fixed FFmpeg unspecified b506fafec9a19fcbc2be5271875fd4a63d6615bc
TIMELINE Jul 23 Reserved by CNA Jul 24 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0051 41.3 —
AFFECTED Product Versions Fixed Apache Neethi unspecified —
TIMELINE Jul 24 Reserved by CNA Jul 24 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U L L L 5.6 .0051 41.3 —
AFFECTED Product Versions Fixed Apache OpenNLP 3.0.0-M1 – —
TIMELINE Jul 16 Reserved by CNA Jul 24 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0048 39.6 —
AFFECTED Product Versions Fixed microweber unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 24 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0048 39.2 —
AFFECTED Product Versions Fixed Apache Neethi unspecified —
TIMELINE Jul 24 Reserved by CNA Jul 24 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0048 39.2 —
AFFECTED Product Versions Fixed Apache Neethi unspecified —
TIMELINE Jul 24 Reserved by CNA Jul 24 Published (CNA: apache)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-64232 | 9.8 | 38.2 | Linux | Linux | — | block: recompute nr_integrity_segments in blk_insert_cloned_request |
| CVE-2026-64216 | 9.8 | 37.2 | Linux | Linux | CWE-416 | netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() |
| CVE-2026-64208 | 7.5 | 36.0 | Linux | Linux | — | crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks |
| CVE-2026-66138 | 7.2 | 35.3 | OpenStack | Ironic Python Agent | CWE-78 | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with t… |
| CVE-2026-45812 | 6.5 | 35.0 | Apache Software Foundation | Apache NimBLE | CWE-131 | Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler |
| CVE-2026-58586 | 9.8 | 34.0 | ZAPAD | Image::WebP | CWE-1395 | Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of lib… |
| CVE-2026-65623 | 8.7 | 32.3 | mtrudel | bandit | CWE-407 | Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit |
| CVE-2026-66033 | 8.7 | 30.1 | libssh2 | libssh2 | CWE-125 | libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation |
| CVE-2026-16870 | 8.8 | 29.3 | Snowflake | Snowflake libsnowflakeclient | CWE-121 | Multiple Security Vulnerabilities in Snowflake libsnowflakeclient |
| CVE-2026-12496 | 8.7 | 28.9 | Loytec | LIP-ME20xC | CWE-79 | Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server |
| CVE-2026-55730 | 8.7 | 28.9 | Loytec | LWEB-802 | CWE-79 | Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802 |
| CVE-2026-15704 | 9.8 | 28.4 | Eclipse Foundation | Eclipse BaSyx Go Components | CWE-180 | CWE-863: ABAC authorization bypass via trailing slash route normalization in … |
| CVE-2026-12654 | 5.3 | 28.2 | paymentplugins | Payment Plugins for Stripe WooCommerce | CWE-862 | Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Un… |
| CVE-2026-45813 | 8.8 | 28.2 | Apache Software Foundation | Apache NimBLE | CWE-191 | Apache NimBLE: Incorrect data validation in BASS add/modify source operation |
| CVE-2026-17107 | 8.5 | 27.7 | Red Hat | multicluster engine for Kubernetes 2.1 | CWE-441 | Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy… |
| CVE-2026-66041 | 7.7 | 27.5 | FFmpeg | FFmpeg | CWE-787 | FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter |
| CVE-2026-64210 | 7.5 | 27.3 | Linux | Linux | — | net/mlx5e: xsk: Fix unlocked writing to ICOSQ |
| CVE-2026-13464 | 5.3 | 27.3 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-639 | Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensiti… |
| CVE-2026-45811 | 7.5 | 27.2 | Apache Software Foundation | Apache NimBLE | CWE-120 | Apache NimBLE: Buffer overflow in socket HCI transport |
| CVE-2026-15401 | 7.2 | 27.2 | e4jvikwp | VikBooking Hotel Booking Engine & PMS | CWE-79 | VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cros… |
| CVE-2026-12736 | 8.0 | 26.7 | wpify | WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce | CWE-269 | WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via … |
| CVE-2026-64235 | 8.1 | 26.0 | Linux | Linux | — | x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines |
| CVE-2026-55732 | 8.7 | 24.9 | Loytec | LIP-ME20xC | CWE-125 | Loytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_date… |
| CVE-2026-55729 | 7.7 | 24.9 | Loytec | LWEB-802 | CWE-200 | Loytec LWEB802: Exposure of Sensitive Information in browser localStorage |
| CVE-2026-55731 | 6.6 | 24.9 | Loytec | LIP-ME20xC | CWE-606 | Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent |
| CVE-2026-66008 | 6.3 | 24.7 | parse-community | parse-server | CWE-209 | Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages |
| CVE-2026-66035 | 7.7 | 24.5 | libssh2 | libssh2 | CWE-122 | libssh2 Heap Buffer Overflow via ETM Cipher Negotiation |
| CVE-2026-60134 | 8.7 | 24.2 | Weintek | cMT3092X firmware | CWE-784 | Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checkin… |
| CVE-2026-66006 | 6.9 | 24.3 | treeverse | lakeFS | CWE-306 | lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs |
| CVE-2026-49326 | 6.5 | 23.8 | Apache Software Foundation | Apache HBase | CWE-862 | Apache HBase: Missing scanner instance owner check in thrift delegation service |
| CVE-2026-66039 | 8.7 | 23.8 | FFmpeg | FFmpeg | CWE-122 | FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File |
| CVE-2026-48032 | 8.3 | 23.6 | kerberosmansour | hulumi | CWE-697 | Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC pr… |
| CVE-2026-12981 | 7.5 | 23.1 | Unknown | CAFEHAUS API | CWE-269 | CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset |
| CVE-2026-15663 | 4.9 | 22.8 | kstover | Ninja Forms – The Contact Form Builder That Grows With You | CWE-89 | Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Impo… |
| CVE-2026-16280 | 9.8 | 22.0 | Imagination Technologies | Graphics DDK | CWE-190 | GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset |
| CVE-2026-66004 | 6.0 | 22.1 | ahujasid | blender-mcp | CWE-22 | BlenderMCP Path Traversal via download_polyhaven_asset API |
| CVE-2026-16800 | 8.8 | 22.0 | Devolutions | PowerShell Universal | CWE-94 | Improper control of generation of code ('Code Injection') in the schedule fea… |
| CVE-2026-16801 | 8.8 | 22.0 | Devolutions | PowerShell Universal | CWE-94 | Improper control of generation of code ('Code Injection') in the variables fe… |
| CVE-2026-48036 | 8.4 | 21.9 | kerberosmansour | hulumi | CWE-755 | Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed… |
| CVE-2026-66139 | 4.8 | 21.9 | OpenStack | Zaqar | CWE-306 | OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC… |
| CVE-2026-9765 | 7.1 | 21.2 | Grafana | Grafana IRM | CWE-284 | CVE-2026-9765 CVE Record |
| CVE-2026-66032 | 8.7 | 20.0 | libssh2 | libssh2 | CWE-415 | libssh2 Double-Free Heap Corruption via sftp_open() |
| CVE-2026-66036 | 7.7 | 20.0 | FFmpeg | FFmpeg | CWE-122 | FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter |
| CVE-2026-48033 | 8.4 | 19.9 | kerberosmansour | hulumi | CWE-693 | Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name |
| CVE-2026-61892 | 8.7 | 19.8 | Weintek | cMT3092X firmware | CWE-732 | Weintek cMT3092X Incorrect Permission Assignment for Critical Resource |
| CVE-2026-15810 | 8.7 | 19.0 | Google Cloud | Looker | CWE-79 | Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover |
| CVE-2026-65707 | 8.5 | 18.6 | likeadmin-likeshop | likeshop | CWE-89 | Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint |
| CVE-2026-66009 | 6.3 | 18.2 | parse-community | parse-server | CWE-209 | Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages |
| CVE-2026-15346 | 6.1 | 17.9 | e4jvikwp | VikBooking Hotel Booking Engine & PMS | CWE-79 | VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Script… |
| CVE-2026-48035 | 7.1 | 17.8 | kerberosmansour | hulumi | CWE-1059 | Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened |
| CVE-2026-48037 | 6.3 | 17.8 | kerberosmansour | hulumi | CWE-693 | Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security… |
| CVE-2026-48034 | 8.5 | 17.6 | kerberosmansour | hulumi | CWE-284 | HULUMI-H5 bypass via decoy sibling resources targeting a different bucket |
| CVE-2026-64223 | 8.1 | 17.4 | Linux | Linux | CWE-125 | wifi: mac80211: consume only present negotiated TTLM maps |
| CVE-2026-66027 | 8.7 | 17.3 | kortix-ai | suna | CWE-862 | Suna < 0.9.102 Broken Access Control via Message Queue API |
| CVE-2026-66140 | 7.8 | 17.2 | Exim | Exim | CWE-24 | Exim before 4.99.5 allows directory traversal to access files outside of the … |
| CVE-2026-66034 | 7.7 | 16.9 | libssh2 | libssh2 | CWE-125 | libssh2 Heap Out-of-Bounds Read via publickey subsystem |
| CVE-2026-15333 | 6.4 | 16.7 | cozythemes | Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates | CWE-79 | Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Script… |
| CVE-2026-15334 | 6.4 | 16.7 | cozythemes | Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates | CWE-79 | Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Script… |
| CVE-2026-57531 | 5.1 | 16.5 | Milkdown | milkdown | CWE-79 | Milkdown < 7.21.3 DOM XSS via innerHTML Assignment |
| CVE-2026-66038 | 7.1 | 16.0 | FFmpeg | FFmpeg | CWE-908 | FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c |
| CVE-2026-15739 | 6.4 | 15.5 | widgetpack | Rich Showcase for Google Reviews | CWE-79 | Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stor… |
| CVE-2026-15755 | 6.4 | 15.5 | 100plugins | Open User Map – Interactive Leaflet Maps | CWE-79 | Open User Map <= 1.4.45 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-14603 | 7.5 | 15.3 | Unknown | WowOptin: Next-Gen Popup Maker | CWE-284 | WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Inje… |
| CVE-2026-11354 | 5.3 | 15.3 | xnau | Participants Database | CWE-862 | Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated A… |
| CVE-2026-12877 | 9.1 | 15.1 | Unknown | Project Management, Bug and Issue Tracking Plugin | CWE-287 | Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Par… |
| CVE-2026-12497 | 7.5 | 14.3 | Unknown | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content | CWE-269 | ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registratio… |
| CVE-2026-61886 | 7.1 | 14.1 | Weintek | cMT3092X firmware | CWE-256 | Weintek cMT3092X Plaintext Storage of a Password |
| CVE-2026-66337 | 6.5 | 13.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_… |
| CVE-2026-66339 | 6.5 | 13.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-201 | Libsoup: libsoup: proxy credentials leak to destination server via proxy-auth… |
| CVE-2026-64255 | 8.8 | 13.5 | Linux | Linux | CWE-125 | wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers |
| CVE-2026-16798 | 6.5 | 13.2 | Devolutions | PowerShell Universal | CWE-201 | Insertion of sensitive information into sent data in the automation jobs API … |
| CVE-2026-65709 | 8.7 | 13.2 | nuxsmin | sysPass | CWE-639 | sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API |
| CVE-2026-8789 | 8.1 | 13.1 | easyappointments | Easy Appointments | CWE-863 | Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contri… |
| CVE-2026-65708 | 8.6 | 12.9 | nuxsmin | sysPass | CWE-639 | sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController |
| CVE-2026-60135 | 7.1 | 11.9 | Weintek | cMT3092X firmware | CWE-286 | Weintek cMT3092X Incorrect User Management |
| CVE-2026-66037 | 7.1 | 11.9 | FFmpeg | FFmpeg | CWE-770 | FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu() |
| CVE-2026-16910 | 5.5 | 11.9 | Red Hat | Red Hat OpenShift Update Service | CWE-918 | Quay: ssrf in red hat quay notification webhooks (slack/generic) |
| CVE-2026-17039 | 3.1 | 11.6 | Red Hat | Red Hat Certificate System 10 | CWE-863 | Pki-core: dogtag-pki: redhat-pki: pki-core: ca renewal request processing omi… |
| CVE-2026-6454 | 6.4 | 10.9 | firelightwp | Firelight Lightbox | CWE-79 | Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-… |
| CVE-2026-10033 | 7.3 | 10.5 | EventON | EventON Action User | CWE-862 | EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Priv… |
| CVE-2026-15821 | 6.4 | 10.3 | brainstormforce | SureDash – Community, Courses & Member Dashboard | CWE-79 | SureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-17059 | 6.5 | 10.1 | Red Hat | Red Hat Build of Keycloak | CWE-639 | Keycloak-services: keycloak-services: information disclosure via role-users e… |
| CVE-2026-17048 | 4.9 | 10.0 | Red Hat | Red Hat build of Keycloak 26.6 | CWE-200 | Keycloak-services: keycloak-services: vault-resolved rotated client secrets l… |
| CVE-2026-15665 | 6.4 | 9.9 | wpmanageninja | Fluent Support – Helpdesk & Customer Support Ticket System | CWE-79 | Fluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-7484 | 5.3 | 9.8 | ABIS Technology Ltd. Co. | AVESİS | CWE-472 | Improper Access Control in Abis Technology's AVESİS |
| CVE-2026-15100 | 6.4 | 9.3 | wpxpo | Post Grid Gutenberg Blocks – PostX | CWE-79 | Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cr… |
| CVE-2026-15464 | 6.4 | 9.3 | thimpress | WP Hotel Booking | CWE-79 | WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Sc… |
| CVE-2026-15648 | 6.4 | 9.3 | berocket | Brands for WooCommerce | CWE-79 | Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-S… |
| CVE-2026-15653 | 6.4 | 9.3 | themeisle | Visualizer – Tables & Charts Manager with Built-in AI Generator | CWE-79 | Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-12702 | 5.1 | 9.3 | Octopus Deploy | Octopus Server | CWE-284 | In affected versions of Octopus Deploy Insufficient checks on the project tri… |
| CVE-2025-9205 | 6.4 | 8.6 | oyatek | MapSVG – Vector maps, Image maps, Google Maps | CWE-79 | MapSVG Lite <= 8.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
| CVE-2026-66005 | 5.3 | 8.6 | janhq | jan | CWE-183 | Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding |
| CVE-2025-71408 | 8.5 | 8.2 | ntlk | ntlk | CWE-95 | NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments |
| CVE-2026-11922 | 6.5 | 7.7 | zenml-io | zenml-io/zenml | CWE-290 | Rate-limit Bypass in zenml-io/zenml |
| CVE-2026-65710 | 7.1 | 7.6 | nuxsmin | sysPass | CWE-639 | sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption |
| CVE-2026-57530 | 5.1 | 7.6 | Milkdown | milkdown | CWE-79 | Milkdown < 7.21.3 Stored XSS via javascript: URL in link href |
| CVE-2026-66338 | 5.4 | 7.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-444 | Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in… |
| CVE-2026-15243 | 7.4 | 6.7 | Apereo | Java Apereo CAS Client | CWE-297 | Improper Validation of Certificate in CAS Client |
| CVE-2026-66010 | 5.1 | 6.1 | cure53 | DOMPurify | CWE-79 | DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING |
| CVE-2026-12688 | 6.5 | 6.1 | Unknown | ProfileGrid | CWE-284 | ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membe… |
| CVE-2026-7007 | 4.6 | 6.1 | zephyrproject | zephyr | CWE-369 | Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted fil… |
| CVE-2026-16799 | 5.0 | 4.9 | Devolutions | PowerShell Universal | CWE-862 | Improper access control in the automation tests and workflows features in Dev… |
| CVE-2026-12690 | 3.8 | 4.9 | Unknown | ProfileGrid | CWE-862 | ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Aut… |
| CVE-2026-8308 | 6.1 | 4.6 | Polen Media Software and Information Services | Website Template | CWE-79 | Reflected XSS Polen Media's Website Template |
| CVE-2026-55985 | 5.3 | 4.7 | Tycon Systems | TPDIN-Monitor-WEB2 | CWE-312 | Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information |
| CVE-2026-56392 | 1.8 | 4.6 | GNU | coreutils | CWE-122 | Heap-based Buffer Overflow in GNU coreutils |
| CVE-2026-10610 | 8.5 | 4.1 | ESET spol. s.r.o. | ESET Endpoint Security for macOS | CWE-269 | Local privilege escalation in ESET security applications for macOS |
| CVE-2026-12689 | 5.4 | 3.6 | Unknown | ProfileGrid | CWE-862 | ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletio… |
| CVE-2026-12503 | 9.2 | 3.5 | Loytec | LIP-ME20xC | CWE-59 | Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter |
| CVE-2026-64219 | 7.0 | 3.4 | Linux | Linux | CWE-674 | drm/amd/display: Validate payload length and link_index in dc_process_dmub_au… |
| CVE-2026-56391 | 4.6 | 3.4 | GNU | coreutils | CWE-125 | Out‑of‑bounds Read in GNU coreutils |
| CVE-2026-12504 | 8.4 | 3.0 | Loytec | LIP-ME20xC | CWE-287 | Loytec LINX firmware: Improper Authentication in PAM configuration |
| CVE-2026-64217 | 7.8 | 3.0 | Linux | Linux | CWE-787 | netfs: Fix overrun check in netfs_extract_user_iter() |
| CVE-2026-64218 | 7.8 | 3.0 | Linux | Linux | — | batman-adv: bla: fix report_work leak on backbone_gw purge |
| CVE-2026-64225 | 7.8 | 3.0 | Linux | Linux | CWE-129 | octeontx2-af: CGX: add bounds check to cgx_speed_mbps index |
| CVE-2026-64226 | 7.8 | 3.0 | Linux | Linux | CWE-416 | sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path |
| CVE-2026-64224 | 7.8 | 2.8 | Linux | Linux | CWE-415 | octeontx2-pf: fix double free in rvu_rep_rsrc_init() |
| CVE-2026-64221 | 7.8 | 2.7 | Linux | Linux | CWE-416 | spi: ti-qspi: fix use-after-free after DMA setup failure |
| CVE-2026-7483 | 8.5 | 2.6 | ESET spol. s.r.o. | ESET Endpoint Security for macOS | CWE-269 | Local privilege escalation in ESET security applications for macOS |
| CVE-2026-54342 | 8.1 | 2.6 | med-united | epa4all | CWE-295 | TLS Certificate Verification Disabled on CXF Transport Clients in epa4all |
| CVE-2026-48021 | 9.1 | 2.6 | med-united | epa4all | CWE-295 | epa4all Security Incident: Implement keystore based on Telematik TSL, impleme… |
| CVE-2026-54422 | 5.5 | 2.5 | OpenStack | Ironic Python Agent | CWE-522 | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container,… |
| CVE-2026-64214 | 5.5 | 2.5 | Linux | Linux | CWE-476 | powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_w… |
| CVE-2026-64220 | 5.5 | 2.5 | Linux | Linux | CWE-908 | device property: set fwnode->secondary to NULL in fwnode_init() |
| CVE-2026-64231 | 5.5 | 2.5 | Linux | Linux | — | drm/msm/dsi: don't dump registers past the mapped region |
| CVE-2026-64222 | 7.0 | 2.3 | Linux | Linux | CWE-415 | octeontx2-pf: avoid double free of pool->stack on AQ init failure |
| CVE-2026-64227 | 5.5 | 2.4 | Linux | Linux | CWE-476 | ACPI: driver: Check ACPI_COMPANION() against NULL during probe |
| CVE-2026-64242 | 7.8 | 2.2 | Linux | Linux | CWE-415 | usb: gadget: net2280: Fix double free in probe error path |
| CVE-2026-64213 | 5.5 | 2.2 | Linux | Linux | — | hwmon: (lm90) Add lock protection to lm90_alert |
| CVE-2026-64228 | 5.5 | 2.2 | Linux | Linux | CWE-476 | net: ethtool: phy: avoid NULL deref when PHY driver is unbound |
| CVE-2026-64229 | 5.5 | 2.3 | Linux | Linux | CWE-476 | x86/mm: Disable broadcast TLB flush when PCID is disabled |
| CVE-2026-64230 | 5.5 | 2.3 | Linux | Linux | CWE-476 | regulator: tps65219: fix irq_data.rdev not being assigned |
| CVE-2026-64245 | 7.8 | 2.1 | Linux | Linux | CWE-416 | fbdev: modedb: fix a possible UAF in fb_find_mode() |
| CVE-2026-16519 | 7.3 | 2.0 | GeoVision Inc. | GV-IP Device Utility | CWE-427 | GeoVision GV-IP Device Utility DLL Search Order Hijacking Vulnerability |
| CVE-2026-64246 | 7.8 | 2.0 | Linux | Linux | CWE-416 | power: reset: linkstation-poweroff: fix use-after-free in the linkstation_pow… |
| CVE-2026-64249 | 7.8 | 2.0 | Linux | Linux | CWE-416 | fpga: region: fix use-after-free in child_regions_with_firmware() |
| CVE-2026-64251 | 7.8 | 1.9 | Linux | Linux | CWE-416 | pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() |
| CVE-2026-64209 | 7.1 | 1.9 | Linux | Linux | CWE-125 | phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config |
| CVE-2026-64237 | 7.1 | 2.0 | Linux | Linux | CWE-125 | Input: elan_i2c - validate firmware size before use |
| CVE-2026-64243 | 7.1 | 2.0 | Linux | Linux | CWE-129 | ASoC: codecs: simple-mux: Fix enum control bounds check |
| CVE-2026-64212 | 5.5 | 2.0 | Linux | Linux | CWE-476 | wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it |
| CVE-2026-64239 | 7.8 | 1.9 | Linux | Linux | CWE-416 | mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() |
| CVE-2026-64247 | 8.4 | 1.7 | Linux | Linux | CWE-125 | KVM: x86: hyper-v: Bound the bank index when querying sparse banks |
| CVE-2026-64233 | 5.5 | 1.7 | Linux | Linux | — | usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind |
| CVE-2026-64234 | 5.5 | 1.8 | Linux | Linux | CWE-476 | tty: serial: pch_uart: add check for dma_alloc_coherent() |
| CVE-2026-64240 | 5.5 | 1.8 | Linux | Linux | — | media: rc: igorplugusb: fix control request setup packet |
| CVE-2026-64241 | 5.5 | 1.7 | Linux | Linux | CWE-401 | gpio: rockchip: teardown bugs and resource leaks |
| CVE-2026-64244 | 5.5 | 1.8 | Linux | Linux | — | drivers/base/memory: set mem->altmap after successful device registration |
| CVE-2026-64252 | 5.5 | 1.8 | Linux | Linux | — | MIPS: DEC: Prevent initial console buffer from landing in XKPHYS |
| CVE-2026-64253 | 5.5 | 1.7 | Linux | Linux | CWE-476 | kernel/fork: clear PF_BLOCK_TS in copy_process() |
| CVE-2026-64254 | 5.5 | 1.7 | Linux | Linux | CWE-617 | NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR |
| CVE-2026-64236 | 5.5 | 1.6 | Linux | Linux | CWE-369 | i2c: davinci: fix division by zero on missing clock-frequency |
| CVE-2026-55728 | 3.8 | 1.7 | Loytec | LIP-ME20xC | CWE-121 | Loytec LINX firmware: Stack-based Buffer Overflow in cmd_ipaddr_conflict |
| CVE-2026-64248 | 5.5 | 1.5 | Linux | Linux | — | MIPS: smp: report dying CPU to RCU in stop_this_cpu() |
| CVE-2026-64250 | 5.5 | 1.5 | Linux | Linux | — | LoongArch: Report dying CPU to RCU in stop_this_cpu() |
| CVE-2026-49743 | 7.8 | 1.5 | Imagination Technologies | Graphics DDK | CWE-416 | GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fenc… |
| CVE-2026-49744 | 7.8 | 1.5 | Imagination Technologies | Graphics DDK | CWE-823 | GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex() |
| CVE-2026-49745 | 7.8 | 1.5 | Imagination Technologies | Graphics DDK | CWE-823 | GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via… |
| CVE-2026-64215 | 5.5 | 1.4 | Linux | Linux | CWE-476 | drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table |
| CVE-2026-14172 | 7.8 | 1.3 | Rapid7 | InsightVM | CWE-250 | Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via U… |
| CVE-2026-16730 | 5.5 | 1.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-755 | Dbus-broker: dbus-broker: session bus denial of service via emfile during pee… |
| CVE-2026-64211 | 5.5 | 1.3 | Linux | Linux | — | srcu: Don't queue workqueue handlers to never-online CPUs |
| CVE-2026-12502 | 8.4 | 1.2 | Loytec | LIP-ME20xC | CWE-269 | Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo |
| CVE-2026-16743 | 5.5 | 0.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-269 | Accountsservice: accountsservice: arbitrary file read via seticonfile for sys… |
| CVE-2026-66141 | 7.8 | 0.8 | Exim | Exim | CWE-829 | Exim before 4.99.5 allows .forward privilege escalation because force_command… |
| CVE-2026-64238 | 5.5 | 0.2 | Linux | Linux | CWE-667 | gpio: shared: fix deadlock on shared proxy's parent removal |
| CVE-2026-16802 | 6.5 | 0.1 | Devolutions | PowerShell Universal | CWE-312 | Cleartext storage of sensitive information in the variables feature in Devolu… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-24 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.