AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H N N 5.9 .0126 67.2 YES
AFFECTED Product Versions Fixed FortiOS 7.6.0 – —
TIMELINE Dec 23 Reserved by CNA Jul 27 Added to CISA KEV, due Aug 10 Jul 27 Published (CNA: fortinet)
440 CVEs published July 27, 2026: 91 critical, 167 high, 162 medium, 14 low; 2 in KEV; 7 with a public exploit reference; 6 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 415 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4694 | 7443 | 1368 | 2563 |
| KEV catalog size | 1670 | |||
167 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 661 | 1579 | 207 | 1122 | 98 | 0 | 27 | 3 | 0.2 | 7.8 | .0016 | +421 |
| microsoft | 656 | 1359 | 104 | 929 | 301 | 8 | 378 | 32 | 2.4 | 7.8 | .0039 | +437 |
| apple | 167 | 244 | 56 | 67 | 112 | 2 | 93 | 7 | 2.9 | 7.1 | .0027 | +167 |
| red hat | 83 | 182 | 9 | 90 | 73 | 10 | 4 | 0 | 0.0 | 7.1 | .0027 | +41 |
| 27 | 36 | 6 | 25 | 1 | 1 | 73 | 5 | 13.9 | 8.8 | .0029 | +24 | |
| canonical | 3 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | +3 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | -1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 7 | 19 | 4 | 6 | 1 | 0 | 96 | 12 | 63.2 | 8.6 | .2459 | +4 |
| fortinet | 11 | 18 | 2 | 4 | 9 | 0 | 28 | 6 | 33.3 | 6.1 | .0054 | +10 |
| palo alto networks | 10 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | +7 |
| vmware | 7 | 7 | 1 | 6 | 0 | 0 | 21 | 0 | 0.0 | 8.7 | .0044 | +7 |
| f5 | 1 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | -1 |
| checkpoint | 3 | 4 | 3 | 1 | 0 | 0 | 3 | 2 | 50.0 | 9.2 | .4696 | +2 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.1 | .0877 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 44 | 76 | 16 | 42 | 18 | 0 | 40 | 1 | 1.3 | 7.5 | .0061 | +28 |
| mozilla | 67 | 72 | 42 | 26 | 4 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +67 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | -3 |
| wordpress | 2 | 2 | 1 | 0 | 1 | 0 | 5 | 2 | 100.0 | 7.9 | .8435 | +2 |
| gitlab | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .4451 | 0 |
| github | 1 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 4.7 | .0017 | +1 |
| kubernetes | 1 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1109 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | +1107 |
| ibm | 32 | 40 | 16 | 11 | 13 | 0 | 7 | 0 | 0.0 | 8.4 | .0028 | +31 |
| adobe | 16 | 27 | 9 | 10 | 4 | 0 | 75 | 4 | 14.8 | 8.6 | .0144 | +9 |
| progress | 23 | 23 | 3 | 15 | 5 | 0 | 9 | 0 | 0.0 | 8.1 | .0032 | +23 |
| solarwinds | 15 | 19 | 15 | 1 | 1 | 0 | 11 | 4 | 21.1 | 9.1 | .0044 | +14 |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 |
| zohocorp | 3 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0048 | +3 |
| veeam | 1 | 1 | 0 | 1 | 0 | 0 | 4 | 0 | 0.0 | 8.4 | .0013 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 7 | 8 | 0 | 0 | 6 | 1 | 26 | 1 | 12.5 | 5.5 | .0073 | +7 |
| hikvision | 5 | 6 | 0 | 3 | 2 | 0 | 2 | 1 | 16.7 | 7.2 | .0024 | +5 |
| bosch | 2 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.0 | .0018 | +2 |
| honeywell | 1 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 6.9 | .0031 | +1 |
| rockwell automation | 1 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | +1 |
| siemens | 0 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 57 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | +57 |
| grafana | 8 | 41 | 2 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | +2 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| erlang | 14 | 32 | 1 | 14 | 14 | 3 | 1 | 0 | 0.0 | 6.9 | .0033 | +7 |
| netty | 10 | 32 | 6 | 24 | 1 | 1 | 0 | 0 | 0.0 | 7.5 | .0051 | -4 |
| regularlabs.com | 29 | 29 | 6 | 14 | 9 | 0 | 0 | 0 | 0.0 | 7.5 | .0022 | +29 |
| watchguard | 17 | 28 | 1 | 18 | 9 | 0 | 4 | 0 | 0.0 | 7.3 | .0026 | +17 |
| nlnet labs | 24 | 27 | 0 | 4 | 17 | 6 | 0 | 0 | 0.0 | 5.9 | .0024 | +24 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | — |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE-2026-15409 | .7422 | 99.4 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 662 |
| microsoft | 656 |
| apple | 204 |
| red hat | 96 |
| mozilla | 67 |
| surrealdb | 57 |
| apache | 44 |
| ibm | 39 |
| regularlabs.com | 29 |
| Vendor | KEV |
|---|---|
| microsoft | 32 |
| cisco | 12 |
| apple | 7 |
| fortinet | 6 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 20 |
| Go | 3 |
| crates.io | 2 |
| npm | 2 |
| NuGet | 1 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1713 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1713 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1713 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1713 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1713 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1713 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1713 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1713 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1713 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1713 |
EXPLOIT PUBLISHED — CVE-2026-10682 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10683 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17432 (NousResearch hermes-agent). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17433 (nanocoai NanoClaw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17434 (nanocoai NanoClaw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17457 (mf-yang openclaw-cn). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17458 (mf-yang openclaw-cn). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17459 (perwendel spark). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17573 (The HDF Group HDF5). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-40033 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44421 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44422 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45623 (postcss). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47178 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47247 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47251 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47254 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47709 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63097 (matrix-org dendrite). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63107 (LimeSurvey). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63108 (RooCodeInc Roo-Code). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63720 (koxudaxi datamodel-code-generator). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63731 (hyperdxio hyperdx). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63770 (glanceapp glance). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63771 (vrana adminer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64824 (home-assistant Home Assistant Core). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65708 (nuxsmin sysPass). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65709 (nuxsmin sysPass). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65710 (nuxsmin sysPass). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66757 (GNOME GIMP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66758 (GNOME GIMP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66759 (GNOME GIMP). Public exploit reference added.
RESCORED — CVE-2026-40033 (FreeRDP). CVSS 8.6 → 8.7 (NVD).
RESCORED — CVE-2026-44422 (FreeRDP). CVSS 7.5 → 8.8 (NVD).
440 CVEs published. 25 box scores and 375 table rows below; the remaining 40 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H N N 5.9 .0126 67.2 YES
AFFECTED Product Versions Fixed FortiOS 7.6.0 – —
TIMELINE Dec 23 Reserved by CNA Jul 27 Added to CISA KEV, due Aug 10 Jul 27 Published (CNA: fortinet)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0088 56.2 YES
AFFECTED Product Versions Fixed VeloCloud Orchestrator On-Prem 5.2.0 – —
TIMELINE Jul 23 Reserved by CNA Jul 27 Added to CISA KEV, due Jul 30 Jul 27 Published (CNA: Arista)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0515 91.7 —
AFFECTED Product Versions Fixed pheditor >= 2.0.1, < 2.0.4 – —
TIMELINE May 20 Reserved by CNA Jul 27 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H L L 8.5 .0283 85.4 —
AFFECTED Product Versions Fixed VeloCloud Orchestrator On-Prem 5.2.0 – —
TIMELINE Jul 24 Reserved by CNA Jul 27 Published (CNA: Arista)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N N N 6.3 .0234 82.2 —
AFFECTED Product Versions Fixed VeloCloud Orchestrator On-Prem 5.2.0 – —
TIMELINE Jul 24 Reserved by CNA Jul 27 Published (CNA: Arista)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0194 78.4 —
AFFECTED Product Versions Fixed Apache Thrift 0.19.0 – —
TIMELINE May 8 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0171 75.5 —
AFFECTED Product Versions Fixed vBulletin 5.0.0 – 6.2.2
TIMELINE Jul 10 Reserved by CNA Jul 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0115 64.1 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE Jul 1 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0110 62.8 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE Jun 17 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0110 62.8 —
AFFECTED Product Versions Fixed Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified —
TIMELINE Jun 17 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0110 62.8 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0110 62.8 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE Apr 21 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0110 62.8 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE May 27 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N L 6.9 .0108 62.4 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE Jun 27 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0107 62.2 —
AFFECTED Product Versions Fixed Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified —
TIMELINE May 4 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0107 62.2 —
AFFECTED Product Versions Fixed Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified — Apache Thrift unspecified —
TIMELINE May 21 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0104 61.2 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE Jun 17 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H L N 8.3 .0095 58.3 —
AFFECTED Product Versions Fixed next.js >= 16.0.0, < 16.2.11 – —
TIMELINE Jul 20 Reserved by CNA Jul 27 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N L 6.9 .0083 54.4 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE Jun 17 Reserved by CNA Jul 27 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H L N 8.3 .0078 53.0 —
AFFECTED Product Versions Fixed next.js >= 12.0.0 < 15.5.21 – —
TIMELINE Jul 20 Reserved by CNA Jul 27 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV A L H N C H H H 8.4 .0074 51.5 —
AFFECTED Product Versions Fixed LoadMaster All Previous Versions – — ECS Connection Manager 7.2.60.0 – — Object Scale Connection Manager 7.2.60.0 – — MOVEit WAF 7.2.60.0 – —
TIMELINE Jul 6 Reserved by CNA Jul 27 Published (CNA: ProgressSoftware)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N H N 8.7 .0074 51.5 —
AFFECTED Product Versions Fixed nitroshare-desktop unspecified —
TIMELINE Jul 23 Reserved by CNA Jul 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N L H 8.3 .0073 51.3 —
AFFECTED Product Versions Fixed OTP 3.17.1 – 4.9.1 OTP R13B03 – 29.0.4
TIMELINE Jul 4 Reserved by CNA Jul 27 Published (CNA: EEF)
AV AC PR UI S C I A CVSS EPSS %ile KEV A L H N C H H H 8.4 .0072 50.9 —
AFFECTED Product Versions Fixed LoadMaster 7.0.8 – — ECS Connection Manager 7.2.60.0 – — Object Scale Connection Manager 7.2.60.0 – — MOVEit WAF 7.2.60.0 – —
TIMELINE Jul 6 Reserved by CNA Jul 27 Published (CNA: ProgressSoftware)
AV AC PR UI S C I A CVSS EPSS %ile KEV A L H N C H H H 8.4 .0072 50.9 —
AFFECTED Product Versions Fixed LoadMaster 7.2.40.0 – — ECS Connection Manager 7.2.60.0 – — Object Scale Connection Manager 7.2.60.0 – — MOVEit WAF 7.2.60.0 – —
TIMELINE Jul 6 Reserved by CNA Jul 27 Published (CNA: ProgressSoftware)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-54540 | 8.8 | 50.6 | pheditor | pheditor | CWE-78 | Authenticated terminal command whitelist bypass in Pheditor |
| CVE-2026-55685 | 8.7 | 50.1 | remix-run | react-router | CWE-400 | React Router: Unauthenticated Denial of Service via Inefficient Route Matching |
| CVE-2026-24252 | 7.8 | 49.7 | NVIDIA | NeMo Framework | CWE-78 | NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS… |
| CVE-2026-64644 | 6.3 | 49.2 | vercel | next.js | CWE-407 | Next.js: Denial of Service in the Image Optimization API using SVGs |
| CVE-2026-51564 | 4.9 | 48.4 | n/a | n/a | CWE-601 | An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attack… |
| CVE-2026-45623 | 9.1 | 46.3 | postcss | postcss | CWE-22 | PostCSS: Arbitrary file read and information disclosure via attacker-controll… |
| CVE-2026-55579 | 9.8 | 46.0 | pheditor | pheditor | CWE-798 | Pheditor: Hardcoded default password 'admin' with no forced change enables fu… |
| CVE-2026-64641 | 8.2 | 45.9 | vercel | next.js | CWE-834 | Next.js: Denial of Service in App Router using Server Actions |
| CVE-2026-66729 | 8.7 | 45.7 | boazsegev | facil.io | CWE-125 | facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser |
| CVE-2026-66730 | 8.7 | 45.7 | boazsegev | facil.io | CWE-835 | facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser |
| CVE-2026-66731 | 8.7 | 45.7 | boazsegev | facil.io | CWE-125 | facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS |
| CVE-2026-43803 | 9.8 | 45.1 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43810 | 9.8 | 45.1 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-56748 | 8.7 | 44.3 | Cribl | Cribl Stream | CWE-61 | Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import |
| CVE-2025-50455 | 9.1 | 43.6 | n/a | n/a | CWE-89 | SQL injection vulnerability exists in the order_by parameter of the /customer… |
| CVE-2026-64649 | 8.3 | 42.7 | vercel | next.js | CWE-918 | Next.js: Server-Side Request Forgery in Server Actions on Custom Servers |
| CVE-2026-43807 | 9.8 | 42.7 | Apple | iOS and iPadOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-64646 | 6.3 | 42.4 | vercel | next.js | CWE-770 | Next.js: Unbounded Server Action payload in Edge runtime |
| CVE-2026-64541 | 9.8 | 41.8 | Linux | Linux | — | net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket |
| CVE-2026-64551 | 9.1 | 41.8 | Linux | Linux | — | sctp: validate STALE_COOKIE cause length before reading staleness |
| CVE-2026-64695 | 9.8 | 41.7 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64643 | 6.3 | 41.6 | vercel | next.js | CWE-201 | Next.js: Unauthenticated Disclosure of Internal Server Function endpoints |
| CVE-2026-43682 | 9.8 | 41.4 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64696 | 9.8 | 41.4 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43777 | 7.5 | 41.2 | Apple | macOS | CWE-20 | This issue was addressed with improved input validation. This issue is fixed … |
| CVE-2026-64545 | 7.5 | 40.3 | Linux | Linux | — | net, bpf: check master for NULL in xdp_master_redirect() |
| CVE-2026-43769 | 9.8 | 39.6 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-64771 | 9.8 | 39.2 | Apple | iOS and iPadOS | CWE-119 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-64535 | 9.8 | 38.9 | Linux | Linux | — | nvmet-tcp: Fix potential UAF when ddgst mismatch |
| CVE-2026-43778 | 9.8 | 38.7 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-43799 | 9.8 | 38.7 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-43822 | 9.8 | 38.7 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-64700 | 9.8 | 38.7 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-64731 | 9.8 | 38.5 | Apple | macOS | CWE-22 | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-64726 | 9.8 | 38.2 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-13714 | 9.8 | 38.2 | Unknown | Realtyna Organic IDX plugin + WPL Real Estate | CWE-434 | Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbit… |
| CVE-2026-64733 | 9.8 | 38.2 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved data protection. This issue is fixed i… |
| CVE-2026-43812 | 9.8 | 37.4 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-64767 | 9.8 | 37.0 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-64704 | 9.8 | 36.8 | Apple | macOS | CWE-843 | A type confusion issue was addressed with improved memory handling. This issu… |
| CVE-2026-64769 | 9.8 | 36.8 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-64770 | 9.8 | 36.8 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-64774 | 9.8 | 36.8 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-42792 | 6.3 | 36.7 | Erlang | OTP | CWE-755 | epmd permanent DoS via EMFILE on accept(2) in erts |
| CVE-2026-43750 | 9.8 | 36.4 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-48145 | 8.2 | 36.3 | Apache Software Foundation | Apache Thrift | CWE-297 | Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass |
| CVE-2026-64772 | 9.8 | 36.0 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved input validation. Th… |
| CVE-2026-43802 | 9.8 | 35.9 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43809 | 9.8 | 35.9 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-28928 | 9.8 | 34.9 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-43814 | 9.8 | 34.9 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-64729 | 9.8 | 34.9 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-17500 | 6.9 | 34.9 | ggml-org | llama.cpp | CWE-404 | ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer der… |
| CVE-2026-17501 | 6.9 | 34.9 | ggml-org | llama.cpp | CWE-404 | ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp … |
| CVE-2026-48144 | 9.1 | 34.8 | Apache Software Foundation | Apache Thrift | CWE-297 | Apache Thrift: c_glib TLS Client Missing Hostname Verification |
| CVE-2026-43694 | 9.8 | 34.7 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43764 | 9.8 | 34.7 | Apple | macOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-43773 | 9.8 | 34.7 | Apple | macOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-43793 | 9.8 | 34.7 | Apple | macOS | CWE-20 | An issue existed in the handling of environment variables. This issue was add… |
| CVE-2026-64694 | 9.8 | 34.7 | Apple | macOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-64697 | 9.8 | 34.7 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64698 | 9.8 | 34.7 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-53666 | 6.1 | 34.6 | remix-run | react-router | CWE-470 | React Router: Arbitrary Constructor Injection via deserializeErrors() in Reac… |
| CVE-2026-64703 | 9.8 | 33.7 | Apple | macOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-66391 | 6.5 | 33.6 | Apache Software Foundation | Apache Wicket | CWE-330 | Apache Wicket: leaked and missing CSP headers |
| CVE-2026-51565 | 6.1 | 33.5 | n/a | n/a | CWE-79 | Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php i… |
| CVE-2026-64735 | 6.5 | 33.3 | Apple | iOS and iPadOS | CWE-451 | An inconsistent user interface issue was addressed with improved state manage… |
| CVE-2026-64738 | 9.8 | 33.0 | Apple | iOS and iPadOS | CWE-284 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-64746 | 9.8 | 33.0 | Apple | iOS and iPadOS | CWE-862 | An authorization issue was addressed with improved validation. This issue is … |
| CVE-2026-59528 | 7.5 | 33.0 | shiptime | ShipTime: Discounted Shipping Rates | CWE-497 | WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Dat… |
| CVE-2026-14289 | 9.0 | 32.8 | Unknown | FacturaONE para WooCommerce con VeriFactu | CWE-94 | WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution |
| CVE-2026-66015 | 7.2 | 32.3 | jfrog | artifactory | CWE-269 | JFrog Platform contains an authorization flaw that may allow authenticated pr… |
| CVE-2026-43818 | 8.8 | 32.0 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-43779 | 9.8 | 31.7 | Apple | macOS | CWE-284 | A logic issue was addressed with improved restrictions. This issue is fixed i… |
| CVE-2026-64702 | 9.8 | 31.7 | Apple | macOS | CWE-284 | An access issue was addressed with additional sandbox restrictions. This issu… |
| CVE-2026-54890 | 8.2 | 31.7 | Erlang | OTP | CWE-191 | BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding |
| CVE-2026-64534 | 9.8 | 31.5 | Linux | Linux | — | nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path |
| CVE-2026-59239 | 8.6 | 31.5 | Roskus | Prospero Flow CRM | CWE-79 | Stored XSS in Prospero Flow CRM email body allows administrator account takeover |
| CVE-2026-65894 | 8.7 | 30.9 | CP-Plus | EZ-P21 IP Camera | CWE-307 | Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera |
| CVE-2026-17527 | 7.7 | 30.7 | Red Hat | Red Hat OpenShift Virtualization 4 | CWE-639 | Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregat… |
| CVE-2026-65921 | 8.8 | 30.6 | jfrog | artifactory | CWE-22 | Potential path traversal leading to unauthorized file writes |
| CVE-2026-64739 | 8.8 | 30.4 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-58227 | 8.7 | 29.9 | Erlang | OTP | CWE-674 | TLS/DTLS denial of service via unbounded recursion on cross-signed peer certi… |
| CVE-2026-64775 | 9.8 | 29.8 | Apple | iOS and iPadOS | CWE-665 | A memory initialization issue was addressed with improved memory handling. Th… |
| CVE-2026-56747 | 8.7 | 29.5 | Cribl | Cribl Stream | CWE-94 | Code Injection in JSON Pointer Processing Component in Cribl Stream |
| CVE-2026-59730 | 2.1 | 29.5 | withastro | astro | CWE-601 | @astrojs/node: Backslash-prefixed paths not recognized as internal by trailin… |
| CVE-2026-55578 | 8.8 | 29.3 | pheditor | pheditor | CWE-78 | Pheditor: Incomplete command sanitization in terminal feature allows RCE via … |
| CVE-2026-59546 | 7.4 | 29.2 | John Darrel | Hide My WP Ghost | CWE-639 | WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability |
| CVE-2026-43748 | 9.8 | 28.9 | Apple | macOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-64727 | 9.8 | 28.9 | Apple | macOS | CWE-843 | A type confusion issue was addressed with improved memory handling. This issu… |
| CVE-2026-17529 | 2.1 | 28.9 | AstrBotDevs | AstrBot | CWE-285 | AstrBotDevs AstrBot astr_main_agent.py authorization |
| CVE-2026-17530 | 2.1 | 28.9 | AstrBotDevs | AstrBot | CWE-285 | AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset a… |
| CVE-2026-66390 | 6.1 | 28.8 | Apache Software Foundation | Apache Wicket | CWE-79 | Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence |
| CVE-2026-65434 | 6.5 | 28.6 | yoomoney | ЮKassa для WooCommerce | CWE-201 | WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure v… |
| CVE-2026-59560 | 6.5 | 28.3 | Roxnor | FundEngine | CWE-862 | WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability |
| CVE-2026-53667 | 6.1 | 28.1 | remix-run | react-router | CWE-79 | React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler… |
| CVE-2026-17552 | 9.1 | 28.0 | RRWO | Plack::App::Prerender | CWE-918 | Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrar… |
| CVE-2026-65765 | 6.9 | 27.7 | phoca.cz | Phoca Commander extension for Joomla | CWE-22 | Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander… |
| CVE-2026-64691 | 9.8 | 27.3 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved size validation. This issue is … |
| CVE-2026-65442 | 7.2 | 27.1 | Subtle Web Inc | FormCraft | CWE-918 | WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vul… |
| CVE-2026-64730 | 6.5 | 27.0 | Apple | Safari | CWE-451 | The issue was addressed with improved UI. This issue is fixed in Safari 26.6,… |
| CVE-2026-64647 | 6.3 | 26.8 | vercel | next.js | CWE-116 | Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies |
| CVE-2026-43730 | 9.8 | 26.7 | Apple | iOS and iPadOS | CWE-200 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-43757 | 9.8 | 26.7 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-64762 | 9.8 | 26.7 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-53668 | 6.9 | 26.6 | remix-run | react-router | CWE-79 | React Router: Open redirect can lead to XSS |
| CVE-2026-64648 | 6.0 | 26.5 | vercel | next.js | CWE-524 | Next.js: Response Body Cache Confusion for Requests Containing Bodies |
| CVE-2026-64720 | 9.8 | 26.2 | Apple | iOS and iPadOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-64751 | 9.8 | 25.7 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-64713 | 8.1 | 25.6 | Apple | Safari | CWE-203 | This issue was addressed with improved checks. This issue is fixed in Safari … |
| CVE-2021-32084 | 9.8 | 25.5 | n/a | n/a | CWE-284 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2026-39873 | 9.8 | 25.6 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43710 | 9.8 | 25.6 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-66395 | 9.4 | 25.5 | siyuan-note | siyuan | CWE-79 | SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol |
| CVE-2026-59729 | 5.1 | 25.6 | withastro | astro | CWE-79 | Astro: XSS via unescaped spread attribute names in renderHTMLElement (incompl… |
| CVE-2026-66397 | 8.6 | 25.3 | thorsten | phpMyFAQ | CWE-22 | phpMyFAQ before 4.1.6 Path Traversal via category image deletion |
| CVE-2026-65878 | 8.3 | 25.3 | joomshaper.com | SP Page Builder extension for Joomla | CWE-22 | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP… |
| CVE-2026-65436 | 6.8 | 25.3 | Themeum | Kirki | CWE-22 | WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerability |
| CVE-2026-66476 | 4.9 | 25.3 | Syed Balkhi | Easy Digital Downloads | CWE-22 | WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vu… |
| CVE-2026-64768 | 8.1 | 25.3 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read issue was addressed with improved input validation. Thi… |
| CVE-2026-59531 | 7.5 | 25.2 | Anh Tran | Falcon – WordPress Optimizations & Tweaks | CWE-1284 | WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknow… |
| CVE-2026-59539 | 7.5 | 25.1 | Cozmoslabs | Paid Member Subscriptions | CWE-639 | WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object … |
| CVE-2026-28982 | 9.8 | 24.9 | Apple | macOS | CWE-362 | A race condition was addressed with improved locking. This issue is fixed in … |
| CVE-2026-66028 | 7.1 | 24.9 | Creativeitem | Ekushey Project Manager CRM | CWE-303 | Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email |
| CVE-2026-66014 | 9.8 | 24.7 | jfrog | artifactory | CWE-287 | Potential authentication bypass leading to privilege escalation in Artifactory |
| CVE-2026-65764 | 5.1 | 24.5 | phoca.cz | Phoca Commander extension for Joomla | CWE-79 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0… |
| CVE-2026-43821 | 6.5 | 24.5 | Apple | Safari | CWE-284 | An access issue was addressed with improved access restrictions. This issue i… |
| CVE-2026-51078 | 7.5 | 24.3 | n/a | n/a | CWE-200 | An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive i… |
| CVE-2026-53669 | 5.1 | 24.2 | remix-run | react-router | CWE-601 | React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025… |
| CVE-2026-65617 | 8.8 | 23.9 | jfrog | artifactory | CWE-502 | Potential remote code execution on an Artifactory package service container. |
| CVE-2026-51077 | 7.5 | 23.7 | n/a | n/a | CWE-89 | SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to… |
| CVE-2026-64743 | 6.5 | 23.7 | Apple | iOS and iPadOS | CWE-285 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-59727 | 2.1 | 23.6 | withastro | astro | CWE-79 | Astro: Cross-site scripting via unescaped transition:* directive values on hy… |
| CVE-2026-17612 | 6.9 | 23.4 | Honeywell | S35 Series 3M/5M/8M/PinHole Cameras | CWE-200 | Audit Log Exposure through Unauthorized Access |
| CVE-2026-66053 | 5.9 | 23.1 | Apache Software Foundation | Apache Thrift | CWE-297 | Apache Thrift: Python TSSLSocket Hostname Matcher Import |
| CVE-2026-43804 | 6.5 | 23.0 | Apple | Safari | CWE-400 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-59548 | 7.5 | 22.8 | Byteflows | Byteflows Travel & Hotel Booking | CWE-497 | WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data E… |
| CVE-2026-66396 | 9.3 | 22.1 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL |
| CVE-2026-40000 | 1.8 | 22.2 | ZTE | Blade A75 5G | CWE-22 | Path Traversal Vulnerability in ZTE Blade A75 5G |
| CVE-2026-16554 | 5.1 | 22.0 | DaveGamble | cJSON | CWE-190 | Integer Overflow Leading to Heap Buffer Overflow in cJSON |
| CVE-2021-32085 | 8.8 | 21.8 | n/a | n/a | CWE-798 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2021-32087 | 8.8 | 21.8 | n/a | n/a | CWE-798 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2026-59251 | 8.7 | 21.8 | Erlang | OTP | CWE-770 | Denial of service via exponential certificate policy tree growth in path vali… |
| CVE-2026-55737 | 5.1 | 21.7 | Erlang | OTP | CWE-195 | Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decod… |
| CVE-2026-64719 | 8.1 | 21.7 | Apple | Safari | CWE-125 | An out-of-bounds access issue was addressed with improved bounds checking. Th… |
| CVE-2026-28911 | 9.8 | 21.5 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-42017 | 8.8 | 21.4 | jfrog | artifactory | CWE-200 | Privilege escalation via JFrog Worker event token exposure |
| CVE-2026-59240 | 6.9 | 21.3 | Roskus | Prospero Flow CRM | CWE-639 | IDOR in Prospero Flow CRM allows deletion of other users' notifications |
| CVE-2021-32088 | 9.8 | 21.2 | n/a | n/a | CWE-384 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2026-59529 | 7.5 | 21.2 | motov.net | Ebook Store | CWE-862 | WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability |
| CVE-2026-65879 | 9.8 | 20.9 | joomshaper.com | SP Page Builder extension for Joomla | CWE-798 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcode… |
| CVE-2026-28931 | 8.8 | 20.6 | Apple | iOS and iPadOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-59537 | 7.6 | 20.4 | Sender | Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | CWE-89 | WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooComm… |
| CVE-2026-65433 | 6.5 | 20.4 | themewant | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | CWE-862 | WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <… |
| CVE-2026-59551 | 8.5 | 20.2 | rtCamp | rtMedia for WordPress, BuddyPress and bbPress | CWE-89 | WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQ… |
| CVE-2026-12394 | 9.8 | 20.1 | Unknown | MemberGlut | CWE-269 | MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator |
| CVE-2026-66824 | 9.2 | 20.1 | lookyloo | lookyloo | CWE-79 | Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding |
| CVE-2026-64540 | 8.1 | 20.2 | Linux | Linux | — | usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() |
| CVE-2026-64547 | 8.1 | 20.2 | Linux | Linux | — | net: usb: net1080: validate packet_len before pad-byte access in rx_fixup |
| CVE-2026-66825 | 6.9 | 20.1 | pivotick | pivotick | CWE-79 | Cross-Site Scripting via Unsafe URL Schemes in Pivotick Property Links |
| CVE-2026-12255 | 8.1 | 19.9 | Unknown | MainWP Child | CWE-287 | MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass vi… |
| CVE-2026-43805 | 9.8 | 19.2 | Apple | iOS and iPadOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-59728 | 4.3 | 19.1 | withastro | astro | CWE-91 | @astrojs/rss: XML Injection via Unescaped RSS Feed Fields |
| CVE-2026-15928 | 8.2 | 19.0 | XMLRPC-C | XMLRPC-C | CWE-79 | XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected … |
| CVE-2025-59181 | 4.8 | 18.9 | Ericsson | Packet Core Controller (PCC) | CWE-35 | Path traversal Vulnerability |
| CVE-2026-66394 | 9.3 | 18.8 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass |
| CVE-2025-63913 | 7.5 | 18.2 | n/a | n/a | CWE-400 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial o… |
| CVE-2026-64728 | 6.5 | 18.1 | Apple | Safari | CWE-693 | A permissions issue was addressed with improved validation. This issue is fix… |
| CVE-2026-13597 | 9.1 | 17.9 | Unknown | 微信二维码登陆 | CWE-287 | QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover |
| CVE-2025-15662 | 8.6 | 17.9 | Unknown | Printcart Web to Print Product Designer for WooCommerce | CWE-918 | Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthentic… |
| CVE-2026-59532 | 7.5 | 17.7 | magepeopleteam | Booking and Rental Manager | CWE-1284 | WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vul… |
| CVE-2026-64554 | 8.8 | 17.6 | Linux | Linux | — | netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() |
| CVE-2026-54272 | 6.9 | 17.1 | beaugunderson | ip-address | CWE-20 | ip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass … |
| CVE-2026-64536 | 8.1 | 16.9 | Linux | Linux | — | staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop |
| CVE-2026-66758 | 7.8 | 16.7 | GNOME | GIMP | CWE-190 | Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflo… |
| CVE-2026-12001 | 5.2 | 16.8 | TP-Link Systems Inc. | TL-WR850N v3 | CWE-798 | Hardcoded Credential Vulnerability in Multiple TP-Link Router Models |
| CVE-2026-16481 | 8.4 | 16.4 | MCP Toolbox for Databases (googleapis/mcp-toolbox) | CWE-918 | Server-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/… | |
| CVE-2026-43792 | 6.5 | 16.4 | Apple | Safari | CWE-285 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-9830 | 8.2 | 16.3 | Unknown | bookingpress-appointment-booking-pro | CWE-287 | BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Bookin… |
| CVE-2026-59530 | 7.5 | 16.0 | Payment Plugins | Stripe For WooCommerce | CWE-862 | WordPress Stripe For WooCommerce plugin <= 4.0.7 - Broken Access Control vuln… |
| CVE-2026-59534 | 7.5 | 16.0 | Aurovrata Venet | Post My CF7 Form | CWE-862 | WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability |
| CVE-2026-59536 | 7.5 | 16.0 | CoCart Headless | CoCart – Headless ecommerce | CWE-862 | WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control… |
| CVE-2026-59557 | 6.5 | 15.6 | Franky | Events Made Easy | CWE-862 | WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability |
| CVE-2026-65435 | 6.5 | 15.6 | Thrive Themes Coupon | Thrive Leads Version | CWE-862 | WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulne… |
| CVE-2026-66398 | 9.4 | 15.5 | thorsten | phpMyFAQ | CWE-494 | phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API |
| CVE-2026-13332 | 9.1 | 15.3 | Unknown | Masteriyo LMS | CWE-287 | Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (D… |
| CVE-2026-43760 | 8.6 | 15.4 | Apple | macOS | CWE-284 | An access issue was addressed with improved access restrictions. This issue i… |
| CVE-2026-10819 | 6.5 | 15.3 | Mattermost | Mattermost | CWE-409 | Mattermost Server Denial of Service via Animated GIF Emoji Upload |
| CVE-2026-66412 | 7.1 | 15.1 | Leantime | Leantime | CWE-639 | Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.ge… |
| CVE-2026-65766 | 9.2 | 14.9 | joomshaper.com | SP Page Builder extension for Joomla | CWE-89 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page … |
| CVE-2026-59527 | 9.3 | 14.9 | RomanCode | MapSVG | CWE-89 | WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
| CVE-2026-59533 | 9.3 | 14.9 | Christoph Vielgrader | Relevanssi Light | CWE-89 | WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability |
| CVE-2026-59538 | 9.3 | 14.9 | Ruben Garcia | GamiPress | CWE-89 | WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability |
| CVE-2026-59549 | 9.3 | 14.9 | rtCamp | rtMedia for WordPress, BuddyPress and bbPress | CWE-89 | WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQ… |
| CVE-2026-59550 | 9.3 | 14.9 | Strategy11 Team | AWP Classifieds | CWE-89 | WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability |
| CVE-2026-14827 | 6.8 | 14.7 | Unknown | Calendar | CWE-79 | Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter |
| CVE-2026-17568 | 8.8 | 14.3 | Devolutions | Server | CWE-863 | Improper access control in the role membership management endpoint in Devolut… |
| CVE-2026-14235 | 7.5 | 14.3 | Unknown | Download Manager | CWE-284 | WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download vi… |
| CVE-2026-66018 | 6.5 | 14.3 | jfrog | artifactory | CWE-200 | JFrog Artifactory build environment properties exposure |
| CVE-2026-66399 | 8.5 | 14.1 | thorsten | phpMyFAQ | CWE-269 | phpMyFAQ before 4.1.6 Privilege Escalation via Group Membership |
| CVE-2026-42016 | 8.8 | 14.0 | jfrog | artifactory | CWE-863 | Incorrect authorization validation of user token in JFrog Artifactory allows … |
| CVE-2026-14856 | 6.3 | 14.1 | Media Manager | TastyIgniter | CWE-79 | Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager |
| CVE-2026-65876 | 9.2 | 13.8 | joomshaper.com | SP Page Builder extension for Joomla | CWE-89 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page … |
| CVE-2026-64757 | 8.8 | 13.7 | Apple | Safari | CWE-119 | A memory corruption issue was addressed with improved state management. This … |
| CVE-2026-65877 | 8.2 | 13.6 | joomshaper.com | SP Page Builder extension for Joomla | CWE-89 | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Bu… |
| CVE-2026-13152 | 8.1 | 13.6 | Unknown | Custom Fields Account Registration For Woocommerce | CWE-269 | Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Pr… |
| CVE-2026-66427 | 7.6 | 13.5 | jgwhite33 | WP Google Review Slider | CWE-89 | WordPress WP Google Review Slider plugin <= 18.4 - SQL Injection vulnerability |
| CVE-2026-14820 | 5.3 | 13.2 | Unknown | Quiz and Survey Master (QSM) | CWE-200 | Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Passwo… |
| CVE-2026-66442 | 5.4 | 13.2 | YayCommerce | YayPricing | CWE-862 | WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability |
| CVE-2026-59535 | 7.3 | 12.6 | Thrive Themes Coupon | Thrive Product Manager | CWE-862 | WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vul… |
| CVE-2026-10600 | 4.3 | 12.4 | Mattermost | Mattermost | CWE-770 | Denial of service via unbounded document content extraction in Mattermost Server |
| CVE-2026-65924 | 6.5 | 12.2 | jfrog | artifactory | CWE-918 | Server-Side Request Forgery (SSRF) via Terraform Remote repository |
| CVE-2026-66759 | 7.1 | 12.1 | GNOME | GIMP | CWE-125 | Gimp: out-of-bounds read in file-icns plugin causes information disclosure or… |
| CVE-2026-55953 | 9.1 | 11.7 | Erlang | OTP | CWE-757 | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing s… |
| CVE-2026-59559 | 6.5 | 11.7 | themewant | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | CWE-79 | WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <… |
| CVE-2026-48052 | 5.4 | 11.7 | papra-hq | papra | CWE-639 | Papra: Cross-organization tag deletion and modification via authenticated cro… |
| CVE-2026-65618 | 6.5 | 11.3 | jfrog | artifactory | CWE-918 | Improper URL validation when handling specific URLs Pub, Terraform and Docker… |
| CVE-2026-65925 | 6.5 | 11.3 | jfrog | artifactory | CWE-918 | Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository |
| CVE-2026-64783 | 8.8 | 11.2 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-12493 | 7.5 | 11.2 | Unknown | Clover Payment Gateway by Zaytech for WooCommerce | CWE-287 | Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated P… |
| CVE-2026-48051 | 3.5 | 11.1 | papra-hq | papra | CWE-918 | Papra: SSRF via HTTP redirect bypass in webhook delivery |
| CVE-2026-14568 | 6.5 | 10.5 | Unknown | User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration | CWE-287 | WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion |
| CVE-2026-66473 | 7.5 | 10.4 | Xendit | Xendit Payment | CWE-862 | WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability |
| CVE-2026-17531 | 1.3 | 10.1 | unitedbyai | droidclaw | CWE-285 | unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization |
| CVE-2026-66757 | 5.5 | 9.9 | GNOME | GIMP | CWE-190 | Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to cras… |
| CVE-2026-65564 | 5.3 | 9.8 | chrisvrichardson | MapPress Maps for WordPress | CWE-497 | WordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Expos… |
| CVE-2026-66438 | 5.3 | 9.8 | Tim Strifler | Exclusive Addons Elementor | CWE-497 | WordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposur… |
| CVE-2026-64742 | 6.5 | 9.6 | Apple | iOS and iPadOS | CWE-319 | This issue was addressed by using HTTPS when sending information over the net… |
| CVE-2026-65445 | 6.5 | 9.7 | iSaumya | Ad Invalid Click Protector (AICP) | CWE-862 | WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access C… |
| CVE-2026-12989 | 8.7 | 9.6 | Ghost Robotics | Vision 60 | CWE-306 | Multiple vulnerabilities in Ghost Robotics' Vision 60 |
| CVE-2026-43728 | 7.5 | 9.5 | Apple | macOS | CWE-362 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-59552 | 7.2 | 9.4 | Shahadat Hossain | 3D Flipbook PDF Viewer & Embedder | CWE-918 | WordPress 3D Flipbook PDF Viewer & Embedder plugin <= 1.4.2 - Server Side Req… |
| CVE-2021-32086 | 9.8 | 9.0 | n/a | n/a | CWE-321 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0… |
| CVE-2026-65923 | 6.8 | 8.7 | jfrog | artifactory | CWE-918 | Potential server-side request forgery in Artifactory Ansible repository handling |
| CVE-2026-65616 | 8.8 | 8.7 | jfrog | artifactory | CWE-347 | Potential privilege escalation to JFrog administrator privileges |
| CVE-2026-13390 | 5.3 | 8.0 | Unknown | The Events Calendar | CWE-862 | The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Stat… |
| CVE-2025-59172 | 8.5 | 7.9 | Ericsson | Packet Core Controller (PCC) | CWE-78 | Improper Neutralization of Special Elements used in an OS Command Vulnerability |
| CVE-2026-59553 | 7.1 | 7.8 | RexTheme | Product Feed Manager | CWE-79 | WordPress Product Feed Manager plugin <= 7.6.1 - Cross Site Scripting (XSS) v… |
| CVE-2026-59556 | 7.1 | 7.8 | acowebs | Dynamic Pricing With Discount Rules for WooCommerce | CWE-79 | WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.1… |
| CVE-2026-59558 | 7.1 | 7.8 | wpdevelop | Booking Calendar | CWE-79 | WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-64549 | await | 7.9 | Linux | Linux | — | Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() |
| CVE-2026-65922 | 5.4 | 7.4 | jfrog | artifactory | CWE-862 | Potential unauthorized modification of Artifactory internal metadata |
| CVE-2026-65567 | 5.3 | 7.4 | Nexcess | Event Tickets | CWE-862 | WordPress Event Tickets plugin <= 5.29.0.1 - Broken Access Control vulnerability |
| CVE-2026-66477 | 5.3 | 7.4 | Shufflehound | Gillion | CWE-862 | WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability |
| CVE-2026-64538 | await | 7.5 | Linux | Linux | — | ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). |
| CVE-2026-64544 | await | 7.5 | Linux | Linux | — | crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents |
| CVE-2026-64553 | await | 7.5 | Linux | Linux | — | net: psample: fix info leak in PSAMPLE_ATTR_DATA |
| CVE-2026-59690 | 8.0 | 7.3 | Progress Software | LoadMaster | CWE-862 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager,… |
| CVE-2026-64537 | await | 7.0 | Linux | Linux | — | bridge: cfm: reject invalid CCM interval at configuration time |
| CVE-2026-14236 | 4.7 | 6.8 | Unknown | Contact Form 7 | CWE-601 | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect |
| CVE-2026-43753 | 4.6 | 6.8 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-59689 | 8.0 | 6.7 | Progress Software | LoadMaster | CWE-863 | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager,… |
| CVE-2026-64542 | await | 6.5 | Linux | Linux | — | ipv6: ndisc: fix NULL deref in accept_untracked_na() |
| CVE-2026-39875 | 7.8 | 6.4 | Apple | macOS | CWE-276 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-64740 | 9.3 | 6.2 | Apple | iOS and iPadOS | CWE-22 | A parsing issue in the handling of directory paths was addressed with improve… |
| CVE-2026-66029 | 5.1 | 6.2 | Creativeitem | Ekushey Project Manager CRM | CWE-79 | Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field |
| CVE-2026-66030 | 5.1 | 6.2 | Creativeitem | Ekushey Project Manager CRM | CWE-79 | Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field |
| CVE-2026-66031 | 5.1 | 6.2 | Creativeitem | Ekushey Project Manager CRM | CWE-79 | Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field |
| CVE-2026-65568 | 5.0 | 6.2 | Visual Composer | Visual Composer Website Builder | CWE-862 | WordPress Visual Composer Website Builder plugin <= 45.15.0 - Broken Access C… |
| CVE-2026-13726 | 7.1 | 6.0 | Unknown | MPG | CWE-79 | Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode |
| CVE-2026-10683 | 4.6 | 6.1 | zephyrproject | zephyr | CWE-835 | DesignWare I2C target driver can be wedged into a permanent stuck state by an… |
| CVE-2026-12982 | 6.1 | 5.9 | Unknown | Document Gallery | CWE-79 | Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery |
| CVE-2026-14190 | 6.1 | 5.9 | Unknown | Sina Extension for Elementor | CWE-79 | Sina Extension for Elementor < 3.10.2 - Reflected XSS |
| CVE-2026-12495 | 5.3 | 5.9 | Mercusys | MB115-4G | CWE-121 | Stack-Based Buffer Overflow in the Mercusys MB115-4G |
| CVE-2026-17569 | 4.3 | 5.8 | Devolutions | Server | CWE-522 | Improper access control in the NetBox synchronizer in Devolutions Server allo… |
| CVE-2026-17570 | 4.3 | 5.8 | Devolutions | Server | CWE-639 | Improper access control in the PAM password history endpoints in Devolutions … |
| CVE-2026-43766 | 4.6 | 5.7 | Apple | macOS | CWE-287 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-61953 | 7.2 | 5.6 | QuantumCloud | Simple Link Directory Pro | CWE-918 | WordPress Simple Link Directory Pro plugin <= 15.0.6 - Server Side Request Fo… |
| CVE-2026-65893 | 7.0 | 5.5 | CP-Plus | EZ-P21 IP Camera | CWE-489 | Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera |
| CVE-2026-14189 | 3.8 | 5.5 | Unknown | WPBot | CWE-89 | WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_f… |
| CVE-2026-12383 | 7.5 | 5.3 | Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | CWE-345 | Eda-server: externaleventstreamviewset trusts subject header without validati… |
| CVE-2026-64732 | 4.6 | 5.3 | Apple | iOS and iPadOS | CWE-284 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-56537 | 3.5 | 5.3 | HCLSoftware | Connections | CWE-209 | HCL Connections is vulnerable to information disclosure |
| CVE-2026-56538 | 3.5 | 5.3 | HCLSoftware | Connections | CWE-213 | HCL Connections is vulnerable to information disclosure |
| CVE-2026-28981 | 7.8 | 5.0 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-43776 | 7.8 | 4.9 | Apple | iOS and iPadOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-47078 | 4.8 | 4.8 | Erlang | OTP | CWE-23 | Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-co… |
| CVE-2026-43772 | 8.2 | 4.7 | Apple | macOS | CWE-22 | A path traversal issue was addressed with improved input validation. This iss… |
| CVE-2026-43698 | 7.8 | 4.7 | Apple | macOS | CWE-88 | An injection issue was addressed with improved validation. This issue is fixe… |
| CVE-2026-43749 | 7.8 | 4.7 | Apple | macOS | CWE-22 | A parsing issue in the handling of directory paths was addressed with improve… |
| CVE-2026-43723 | 7.8 | 4.6 | Apple | iOS and iPadOS | CWE-22 | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-10082 | 6.1 | 4.6 | Unknown | Advanced Ads | CWE-79 | Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via th… |
| CVE-2026-13400 | 6.1 | 4.6 | Unknown | Simply Schedule Appointments | CWE-79 | Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Book… |
| CVE-2026-61957 | 7.1 | 4.4 | miniOrange | miniorange otp verification | CWE-79 | WordPress miniorange otp verification plugin <= 5.5.1 - Cross Site Scripting … |
| CVE-2026-65437 | 7.1 | 4.4 | CleanTalk Inc | Spam protection, AntiSpam, FireWall by CleanTalk | CWE-79 | WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.82 - C… |
| CVE-2026-65438 | 7.1 | 4.4 | Kofi Mokome | Message Filter for Contact Form 7 | CWE-79 | WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.9 - Cross Site Sc… |
| CVE-2026-65439 | 7.1 | 4.4 | Themefic | Ultimate Addons for Contact Form 7 | CWE-79 | WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scr… |
| CVE-2026-65440 | 7.1 | 4.4 | Roxnor | GetGenie | CWE-79 | WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65441 | 7.1 | 4.4 | Nexcess | GiveWP | CWE-79 | WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65443 | 7.1 | 4.4 | WP Media | BackWPup | CWE-79 | WordPress BackWPup plugin <= 5.7.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65446 | 7.1 | 4.4 | WP Chill | Kali Forms | CWE-79 | WordPress Kali Forms plugin <= 2.4.18 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65447 | 7.1 | 4.4 | Wasiliy Strecker / ContestGallery developer | Contest Gallery | CWE-79 | WordPress Contest Gallery plugin <= 30.0.6 - Cross Site Scripting (XSS) vulne… |
| CVE-2025-59177 | 6.8 | 4.4 | Ericsson | Ericsson Packet Core Controller (PCC) | CWE-209 | Generation of Error Message Containing Sensitive Information Vulnerability |
| CVE-2025-59178 | 4.8 | 4.4 | Ericsson | Packet Core Controller (PCC) | CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere Vu… |
| CVE-2026-43771 | 7.1 | 4.2 | Apple | macOS | CWE-121 | A stack overflow was addressed with improved input validation. This issue is … |
| CVE-2026-64722 | 5.5 | 4.3 | Apple | iOS and iPadOS | CWE-120 | A buffer overflow issue was addressed with improved memory handling. This iss… |
| CVE-2026-64548 | 8.4 | 4.2 | Linux | Linux | — | bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() |
| CVE-2026-64552 | 8.4 | 4.2 | Linux | Linux | — | virtio-net: fix len check in receive_big() |
| CVE-2026-43765 | 5.5 | 4.2 | Apple | macOS | CWE-59 | This issue was addressed with improved handling of symlinks. This issue is fi… |
| CVE-2026-12991 | 8.7 | 4.0 | Ghost Robotics | Vision 60 | CWE-300 | Multiple vulnerabilities in Ghost Robotics' Vision 60 |
| CVE-2026-64747 | 7.8 | 4.0 | Apple | iOS and iPadOS | CWE-120 | A buffer overflow was addressed with improved size validation. This issue is … |
| CVE-2026-14203 | 4.8 | 4.0 | Unknown | Smart Manager | CWE-79 | Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title |
| CVE-2026-65557 | 5.9 | 3.8 | Tychesoftwares | Abandoned Cart Lite for WooCommerce | CWE-79 | WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Sc… |
| CVE-2026-65563 | 5.9 | 3.8 | Themeisle | Orbit Fox by ThemeIsle | CWE-79 | WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS)… |
| CVE-2026-66475 | 5.9 | 3.8 | acowebs | Checkout Field Editor for WooCommerce – Checkout Manager | CWE-79 | WordPress Checkout Field Editor for WooCommerce – Checkout Manager plug… |
| CVE-2026-28912 | 7.8 | 3.8 | Apple | macOS | CWE-693 | A logic issue was addressed with improved restrictions. This issue is fixed i… |
| CVE-2026-64699 | 5.5 | 3.7 | Apple | macOS | CWE-457 | A memory initialization issue was addressed with improved memory handling. Th… |
| CVE-2026-65558 | 5.4 | 3.7 | WPCenter | AffiliateX | CWE-918 | WordPress AffiliateX plugin <= 2.3.5 - Server Side Request Forgery (SSRF) vul… |
| CVE-2026-64533 | 7.8 | 3.6 | Linux | Linux | — | fs/ntfs3: validate lcns_follow in log_replay conversion |
| CVE-2026-17514 | 1.9 | 3.6 | ZJONSSON | node-unzipper | CWE-22 | ZJONSSON node-unzipper extract.js Extract path traversal |
| CVE-2026-64745 | 2.4 | 3.5 | Apple | macOS | CWE-287 | This issue was addressed with additional restrictions on the lock screen. Thi… |
| CVE-2026-39877 | 7.8 | 3.4 | Apple | iOS and iPadOS | CWE-119 | A memory corruption issue was addressed with improved memory handling. This i… |
| CVE-2026-64734 | 5.5 | 3.4 | Apple | iOS and iPadOS | CWE-200 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7… |
| CVE-2026-57917 | 4.8 | 3.4 | Asseco | proCertum SmartSign | CWE-611 | Improper Restriction of XML External Entity Reference in proCertum SmartSign |
| CVE-2026-28973 | 8.6 | 3.3 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-43729 | 7.8 | 3.3 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43733 | 7.8 | 3.3 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43780 | 7.8 | 3.3 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-64716 | 7.8 | 3.3 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43738 | 5.5 | 3.2 | Apple | iOS and iPadOS | CWE-125 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-12990 | 7.7 | 3.1 | Ghost Robotics | Vision 60 | CWE-284 | Multiple vulnerabilities in Ghost Robotics' Vision 60 |
| CVE-2026-43800 | 5.5 | 3.2 | Apple | iOS and iPadOS | CWE-200 | An information disclosure issue was addressed by removing the vulnerable code… |
| CVE-2026-64532 | 7.8 | 3.1 | Linux | Linux | — | fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} |
| CVE-2026-64692 | 7.1 | 3.0 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-64725 | 7.1 | 3.1 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-65448 | 6.5 | 3.1 | AcyMailing Newsletter Team | Anti Spam and list cleaner – AcyChecker | CWE-79 | WordPress Anti Spam and list cleaner – AcyChecker plugin <= 1.8.1 - Cross Sit… |
| CVE-2026-65561 | 6.5 | 3.1 | miniOrange | WordPress Social Login and Register | CWE-79 | WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Sc… |
| CVE-2026-65562 | 6.5 | 3.1 | WPDeveloper | BetterDocs | CWE-79 | WordPress BetterDocs plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66433 | 6.5 | 3.1 | ShapedPlugin LLC | Location Weather | CWE-79 | WordPress Location Weather plugin <= 3.0.6 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-66434 | 6.5 | 3.1 | Sayontan Sinha | Photonic Gallery & Lightbox for Flickr, SmugMug & Others | CWE-79 | WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= … |
| CVE-2026-66445 | 6.5 | 3.1 | 100plugins | Open User Map | CWE-79 | WordPress Open User Map plugin <= 1.4.46 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-66448 | 6.5 | 3.1 | WP Chill | Gallery PhotoBlocks | CWE-79 | WordPress Gallery PhotoBlocks plugin <= 1.3.3 - Cross Site Scripting (XSS) vu… |
| CVE-2026-43774 | 5.5 | 3.1 | Apple | macOS | CWE-787 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-43797 | 5.5 | 3.1 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved checks. This issue is fixed in iOS 18.… |
| CVE-2026-64710 | 5.5 | 3.1 | Apple | macOS | CWE-200 | A privacy issue was addressed by removing sensitive data. This issue is fixed… |
| CVE-2026-64531 | 7.8 | 3.0 | Linux | Linux | — | net: openvswitch: reject oversized nested action attrs |
| CVE-2026-64763 | 7.8 | 2.9 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed by removing the vulnerable code. T… |
| CVE-2026-64764 | 7.8 | 2.9 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-64765 | 7.8 | 3.0 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-64766 | 7.8 | 2.9 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-43813 | 7.1 | 2.9 | Apple | iOS and iPadOS | CWE-20 | A validation issue was addressed with improved input sanitization. This issue… |
| CVE-2026-43714 | 5.5 | 3.0 | Apple | iOS and iPadOS | CWE-20 | The issue was addressed with improved input sanitization. This issue is fixed… |
| CVE-2026-43754 | 5.5 | 3.0 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved redaction of sensitive information. Th… |
| CVE-2026-43758 | 5.5 | 3.0 | Apple | macOS | CWE-200 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-43796 | 5.5 | 3.0 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved data protection. This issue is fixed i… |
| CVE-2026-43801 | 5.5 | 3.0 | Apple | iOS and iPadOS | CWE-200 | This issue was addressed with improved checks. This issue is fixed in iOS 18.… |
| CVE-2026-64709 | 5.5 | 3.0 | Apple | iOS and iPadOS | CWE-200 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64721 | 5.5 | 3.0 | Apple | iOS and iPadOS | CWE-664 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-64741 | 5.5 | 3.0 | Apple | iOS and iPadOS | CWE-200 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-64744 | 5.5 | 3.0 | Apple | iOS and iPadOS | CWE-200 | An information leakage was addressed with additional validation. This issue i… |
| CVE-2026-64555 | 8.8 | 2.9 | Linux | Linux | — | KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() |
| CVE-2026-28932 | 5.5 | 2.8 | Apple | macOS | CWE-400 | A logic issue existed resulting in memory corruption. This was addressed with… |
| CVE-2026-43759 | 5.5 | 2.9 | Apple | macOS | CWE-200 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-43768 | 5.5 | 2.8 | Apple | macOS | CWE-400 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64708 | 5.5 | 2.9 | Apple | macOS | CWE-693 | A file quarantine bypass was addressed with additional checks. This issue is … |
| CVE-2026-28896 | 7.7 | 2.7 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64550 | 7.3 | 2.7 | Linux | Linux | — | net: qualcomm: rmnet: validate MAP frame length before ingress parsing |
| CVE-2026-43681 | 7.1 | 2.7 | Apple | macOS | CWE-120 | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-64546 | 7.1 | 2.7 | Linux | Linux | — | drm/edid: fix OOB read in drm_parse_tiled_block() |
| CVE-2026-43739 | 5.5 | 2.7 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43744 | 5.5 | 2.7 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43816 | 5.5 | 2.7 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43817 | 5.5 | 2.7 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-64693 | 5.5 | 2.7 | Apple | iOS and iPadOS | CWE-843 | A type confusion issue was addressed with improved checks. This issue is fixe… |
| CVE-2026-64724 | 5.5 | 2.7 | Apple | iOS and iPadOS | CWE-400 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64543 | 7.8 | 2.6 | Linux | Linux | — | tipc: fix use-after-free of the discoverer in tipc_disc_rcv() |
| CVE-2026-28945 | 7.1 | 2.6 | Apple | macOS | CWE-284 | A permissions issue was addressed with additional sandbox restrictions. This … |
| CVE-2026-43673 | 7.8 | 2.5 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43711 | 7.8 | 2.5 | Apple | iOS and iPadOS | CWE-119 | A memory corruption issue was addressed with improved memory handling. This i… |
| CVE-2026-64749 | 7.8 | 2.6 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64758 | 7.8 | 2.6 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved bounds checks. This issue is fixed in i… |
| CVE-2026-43763 | 5.5 | 2.5 | Apple | macOS | CWE-284 | A permissions issue was addressed by removing the vulnerable code. This issue… |
| CVE-2026-64755 | 5.5 | 2.5 | Apple | iOS and iPadOS | CWE-200 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-43819 | 5.5 | 2.5 | Apple | macOS | CWE-284 | An access issue was addressed with additional sandbox restrictions. This issu… |
| CVE-2026-64539 | 7.8 | 2.4 | Linux | Linux | — | Bluetooth: eir: Fix stack OOB write when prepending the Flags AD |
Results continue: ranks 401–440.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-27 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.