boxscore/security
Monday, July 27, 2026 · all times UTC← 2026-07-26 · archive · 2026-07-28 →

440 CVEs published July 27, 2026: 91 critical, 167 high, 162 medium, 14 low; 2 in KEV; 7 with a public exploit reference; 6 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 415 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published4694744313682563
KEV catalog size1670

167 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux661157920711229802730.27.8.0016+421
microsoft65613591049293018378322.47.8.0039+437
apple167244566711229372.97.1.0027+167
red hat831829907310400.07.1.0027+41
google27366251173513.98.8.0029+24
canonical330210000.07.8.0013+3
android010100161100.08.4.0171-1
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco7194610961263.28.6.2459+4
fortinet1118249028633.36.1.0054+10
palo alto networks1015017514213.34.7.0028+7
vmware7716002100.08.7.0044+7
f51540007120.09.2.04020
ivanti051000335100.010.0.8152-1
checkpoint3431003250.09.2.4696+2
broadcom2400204250.05.1.0877+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache447616421804011.37.5.0061+28
mozilla67724226401300.09.1.0031+67
docker030120100.05.7.0015-3
wordpress22101052100.07.9.8435+2
gitlab02000042100.0.44510
github110010000.04.7.0017+1
kubernetes110001000.02.4.0024+1
drupal01100051100.09.8.88320
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091113212539304574030.37.6.0031+1107
ibm32401611130700.08.4.0028+31
adobe16279104075414.88.6.0144+9
progress232331550900.08.1.0032+23
solarwinds15191511011421.19.1.0044+14
atlassian3303001300.08.0.0026+3
zohocorp331110000.07.1.0048+3
veeam110100400.08.4.0013+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link78006126112.55.5.0073+7
hikvision5603202116.77.2.0024+5
bosch220200000.08.0.0018+2
honeywell110010000.06.9.0031+1
rockwell automation111000000.09.2.0030+1
siemens010100100.08.7.00320
dahua000000200
qnap000000800
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb5757326253000.07.1.0025+57
grafana841214223000.06.5.0033+2
open ises037214210000.06.9.00210
erlang1432114143100.06.9.0033+7
netty103262411000.07.5.0051-4
regularlabs.com292961490000.07.5.0022+29
watchguard172811890400.07.3.0026+17
nlnet labs242704176000.05.9.0024+24

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1109
linux662
microsoft656
apple204
red hat96
mozilla67
surrealdb57
apache44
ibm39
regularlabs.com29
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco12
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven20
Go3
crates.io2
npm2
NuGet1
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-25089Fortinet0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171713
CVE-2021-27102Accellion2021-11-171713
CVE-2021-27101Accellion2021-11-171713
CVE-2021-27103Accellion2021-11-171713
CVE-2021-21017Adobe2021-11-171713
CVE-2021-28550Adobe2021-11-171713
CVE-2021-42013Apache2021-11-171713
CVE-2021-41773Apache2021-11-171713
CVE-2021-30858Apple2021-11-171713
CVE-2021-30860Apple2021-11-171713

Transactions

EXPLOIT PUBLISHEDCVE-2026-10682 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10683 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17432 (NousResearch hermes-agent). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17433 (nanocoai NanoClaw). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17434 (nanocoai NanoClaw). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17457 (mf-yang openclaw-cn). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17458 (mf-yang openclaw-cn). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17459 (perwendel spark). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17573 (The HDF Group HDF5). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-40033 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44421 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44422 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45623 (postcss). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47178 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47247 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47251 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47254 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47709 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63097 (matrix-org dendrite). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63107 (LimeSurvey). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63108 (RooCodeInc Roo-Code). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63720 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63731 (hyperdxio hyperdx). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63770 (glanceapp glance). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63771 (vrana adminer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64824 (home-assistant Home Assistant Core). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65708 (nuxsmin sysPass). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65709 (nuxsmin sysPass). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65710 (nuxsmin sysPass). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66757 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66758 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66759 (GNOME GIMP). Public exploit reference added.

RESCOREDCVE-2026-40033 (FreeRDP). CVSS 8.6 → 8.7 (NVD).

RESCOREDCVE-2026-44422 (FreeRDP). CVSS 7.5 → 8.8 (NVD).

Yesterday's Results

440 CVEs published. 25 box scores and 375 table rows below; the remaining 40 continue on page 2 — every CVE is listed, nothing truncated.

Fortinet FortiOS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  N  N    5.9   .0126   67.2   YES
AFFECTED
  Product  Versions  Fixed
  FortiOS  7.6.0 –   —
TIMELINE
  Dec 23  Reserved by CNA
  Jul 27  Added to CISA KEV, due Aug 10
  Jul 27  Published (CNA: fortinet)
CWE-200 · CNA: fortinet · 2 references · NVD status: Analyzed · KEV due August 10, 2026
Arista Networks VeloCloud Orchestrator On-Prem — VeloCloud Orchestrator OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0088   56.2   YES
AFFECTED
  Product                         Versions  Fixed
  VeloCloud Orchestrator On-Prem  5.2.0 –   —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 27  Added to CISA KEV, due Jul 30
  Jul 27  Published (CNA: Arista)
CWE-78 · CNA: Arista · 2 references · NVD status: Analyzed · KEV due July 30, 2026
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0515   91.7     —
AFFECTED
  Product   Versions             Fixed
  pheditor  >= 2.0.1, < 2.0.4 –  —
TIMELINE
  May 20  Reserved by CNA
  Jul 27  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 2 references · NVD status: Deferred
Arista Networks VeloCloud Orchestrator On-Prem — VeloCloud Orchestrator Flow Metrics API SQL Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   L   L    8.5   .0283   85.4     —
AFFECTED
  Product                         Versions  Fixed
  VeloCloud Orchestrator On-Prem  5.2.0 –   —
TIMELINE
  Jul 24  Reserved by CNA
  Jul 27  Published (CNA: Arista)
CWE-89 · CNA: Arista · 1 reference · NVD status: Awaiting Analysis
Arista Networks VeloCloud Orchestrator On-Prem — VeloCloud Orchestrator Missing Input Validation SSRF
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   N    6.3   .0234   82.2     —
AFFECTED
  Product                         Versions  Fixed
  VeloCloud Orchestrator On-Prem  5.2.0 –   —
TIMELINE
  Jul 24  Reserved by CNA
  Jul 27  Published (CNA: Arista)
CWE-918 · CNA: Arista · 1 reference · NVD status: Awaiting Analysis
Apache Thrift: Unbounded Read Leading to Denial of Service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0194   78.4     —
AFFECTED
  Product        Versions  Fixed
  Apache Thrift  0.19.0 –  —
TIMELINE
  May 8   Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-770 · CNA: apache · 3 references · NVD status: Analyzed
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0171   75.5     —
AFFECTED
  Product    Versions  Fixed
  vBulletin  5.0.0 –   6.2.2
TIMELINE
  Jul 10  Reserved by CNA
  Jul 27  Published (CNA: VulnCheck)
CWE-95 · CNA: VulnCheck · 6 references · NVD status: Deferred
Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0115   64.1     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-125, CWE-1284 · CNA: apache · 3 references · NVD status: Analyzed
Apache Thrift: Node.js quadratic-time DoS in server receive transports
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0110   62.8     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  Jun 17  Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-407, CWE-770 · CNA: apache · 3 references · NVD status: Analyzed
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0110   62.8     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
TIMELINE
  Jun 17  Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-190 · CNA: apache · 3 references · NVD status: Analyzed
Apache Thrift: Rust binary protocol non-strict path missing string size limit
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0110   62.8     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-770 · CNA: apache · 3 references · NVD status: Analyzed
Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0110   62.8     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  Apr 21  Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-409 · CNA: apache · 3 references · NVD status: Modified
Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0110   62.8     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  May 27  Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-409 · CNA: apache · 3 references · NVD status: Analyzed
Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   L    6.9   .0108   62.4     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  Jun 27  Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-125 · CNA: apache · 3 references · NVD status: Analyzed
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0107   62.2     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-835 · CNA: apache · 3 references · NVD status: Analyzed
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0107   62.2     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
  Apache Thrift  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-409 · CNA: apache · 3 references · NVD status: Analyzed
Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0104   61.2     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  Jun 17  Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-122 · CNA: apache · 3 references · NVD status: Analyzed
vercel next.js — Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   L   N    8.3   .0095   58.3     —
AFFECTED
  Product  Versions                Fixed
  next.js  >= 16.0.0, < 16.2.11 –  —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 27  Published (CNA: GitHub_M)
CWE-285 · CNA: GitHub_M · 4 references · NVD status: Analyzed
Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   L    6.9   .0083   54.4     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  Jun 17  Reserved by CNA
  Jul 27  Published (CNA: apache)
CWE-126 · CNA: apache · 3 references · NVD status: Analyzed
vercel next.js — Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   L   N    8.3   .0078   53.0     —
AFFECTED
  Product  Versions               Fixed
  next.js  >= 12.0.0 < 15.5.21 –  —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 27  Published (CNA: GitHub_M)
CWE-601, CWE-918 · CNA: GitHub_M · 5 references · NVD status: Analyzed
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   H   N  C  H  H  H    8.4   .0074   51.5     —
AFFECTED
  Product                          Versions                 Fixed
  LoadMaster                       All Previous Versions –  —
  ECS Connection Manager           7.2.60.0 –               —
  Object Scale Connection Manager  7.2.60.0 –               —
  MOVEit WAF                       7.2.60.0 –               —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 27  Published (CNA: ProgressSoftware)
CWE-78 · CNA: ProgressSoftware · 1 reference · NVD status: Analyzed
NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   H   N    8.7   .0074   51.5     —
AFFECTED
  Product             Versions     Fixed
  nitroshare-desktop  unspecified  —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 27  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 2 references · NVD status: Deferred
Erlang OTP — Megaco flex scanner buffer overflow via oversized property parm name
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   L   H    8.3   .0073   51.3     —
AFFECTED
  Product  Versions  Fixed
  OTP      3.17.1 –  4.9.1
  OTP      R13B03 –  29.0.4
TIMELINE
  Jul 4   Reserved by CNA
  Jul 27  Published (CNA: EEF)
CWE-120, CWE-787 · CNA: EEF · 5 references · NVD status: Undergoing Analysis
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   H   N  C  H  H  H    8.4   .0072   50.9     —
AFFECTED
  Product                          Versions    Fixed
  LoadMaster                       7.0.8 –     —
  ECS Connection Manager           7.2.60.0 –  —
  Object Scale Connection Manager  7.2.60.0 –  —
  MOVEit WAF                       7.2.60.0 –  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 27  Published (CNA: ProgressSoftware)
CWE-78 · CNA: ProgressSoftware · 1 reference · NVD status: Analyzed
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   H   N  C  H  H  H    8.4   .0072   50.9     —
AFFECTED
  Product                          Versions    Fixed
  LoadMaster                       7.2.40.0 –  —
  ECS Connection Manager           7.2.60.0 –  —
  Object Scale Connection Manager  7.2.60.0 –  —
  MOVEit WAF                       7.2.60.0 –  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 27  Published (CNA: ProgressSoftware)
CWE-78 · CNA: ProgressSoftware · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-545408.850.6pheditorpheditorCWE-78Authenticated terminal command whitelist bypass in Pheditor
CVE-2026-556858.750.1remix-runreact-routerCWE-400React Router: Unauthenticated Denial of Service via Inefficient Route Matching
CVE-2026-242527.849.7NVIDIANeMo FrameworkCWE-78NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS…
CVE-2026-646446.349.2vercelnext.jsCWE-407Next.js: Denial of Service in the Image Optimization API using SVGs
CVE-2026-515644.948.4n/an/aCWE-601An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attack…
CVE-2026-456239.146.3postcsspostcssCWE-22PostCSS: Arbitrary file read and information disclosure via attacker-controll…
CVE-2026-555799.846.0pheditorpheditorCWE-798Pheditor: Hardcoded default password 'admin' with no forced change enables fu…
CVE-2026-646418.245.9vercelnext.jsCWE-834Next.js: Denial of Service in App Router using Server Actions
CVE-2026-667298.745.7boazsegevfacil.ioCWE-125facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser
CVE-2026-667308.745.7boazsegevfacil.ioCWE-835facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser
CVE-2026-667318.745.7boazsegevfacil.ioCWE-125facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS
CVE-2026-438039.845.1AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-438109.845.1AppleiOS and iPadOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-567488.744.3CriblCribl StreamCWE-61Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import
CVE-2025-504559.143.6n/an/aCWE-89SQL injection vulnerability exists in the order_by parameter of the /customer…
CVE-2026-646498.342.7vercelnext.jsCWE-918Next.js: Server-Side Request Forgery in Server Actions on Custom Servers
CVE-2026-438079.842.7AppleiOS and iPadOSCWE-120A buffer overflow was addressed with improved bounds checking. This issue is …
CVE-2026-646466.342.4vercelnext.jsCWE-770Next.js: Unbounded Server Action payload in Edge runtime
CVE-2026-645419.841.8LinuxLinuxnet/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
CVE-2026-645519.141.8LinuxLinuxsctp: validate STALE_COOKIE cause length before reading staleness
CVE-2026-646959.841.7AppleiOS and iPadOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-646436.341.6vercelnext.jsCWE-201Next.js: Unauthenticated Disclosure of Internal Server Function endpoints
CVE-2026-436829.841.4ApplemacOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-646969.841.4ApplemacOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-437777.541.2ApplemacOSCWE-20This issue was addressed with improved input validation. This issue is fixed …
CVE-2026-645457.540.3LinuxLinuxnet, bpf: check master for NULL in xdp_master_redirect()
CVE-2026-437699.839.6AppleiOS and iPadOSCWE-190An integer overflow was addressed with improved input validation. This issue …
CVE-2026-647719.839.2AppleiOS and iPadOSCWE-119A buffer overflow was addressed with improved bounds checking. This issue is …
CVE-2026-645359.838.9LinuxLinuxnvmet-tcp: Fix potential UAF when ddgst mismatch
CVE-2026-437789.838.7AppleiOS and iPadOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-437999.838.7AppleiOS and iPadOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-438229.838.7AppleiOS and iPadOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-647009.838.7AppleiOS and iPadOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-647319.838.5ApplemacOSCWE-22A path handling issue was addressed with improved validation. This issue is f…
CVE-2026-647269.838.2AppleiOS and iPadOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-137149.838.2UnknownRealtyna Organic IDX plugin + WPL Real EstateCWE-434Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbit…
CVE-2026-647339.838.2AppleiOS and iPadOSCWE-200This issue was addressed with improved data protection. This issue is fixed i…
CVE-2026-438129.837.4AppleiOS and iPadOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-647679.837.0ApplemacOSCWE-120A buffer overflow was addressed with improved bounds checking. This issue is …
CVE-2026-647049.836.8ApplemacOSCWE-843A type confusion issue was addressed with improved memory handling. This issu…
CVE-2026-647699.836.8AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-647709.836.8AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-647749.836.8AppleiOS and iPadOSCWE-190An integer overflow was addressed with improved input validation. This issue …
CVE-2026-427926.336.7ErlangOTPCWE-755epmd permanent DoS via EMFILE on accept(2) in erts
CVE-2026-437509.836.4ApplemacOSCWE-120A buffer overflow was addressed with improved bounds checking. This issue is …
CVE-2026-481458.236.3Apache Software FoundationApache ThriftCWE-297Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
CVE-2026-647729.836.0AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved input validation. Th…
CVE-2026-438029.835.9AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-438099.835.9AppleiOS and iPadOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2026-289289.834.9AppleiOS and iPadOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-438149.834.9AppleiOS and iPadOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-647299.834.9AppleiOS and iPadOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-175006.934.9ggml-orgllama.cppCWE-404ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer der…
CVE-2026-175016.934.9ggml-orgllama.cppCWE-404ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp …
CVE-2026-481449.134.8Apache Software FoundationApache ThriftCWE-297Apache Thrift: c_glib TLS Client Missing Hostname Verification
CVE-2026-436949.834.7ApplemacOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-437649.834.7ApplemacOSCWE-190An integer overflow was addressed with improved input validation. This issue …
CVE-2026-437739.834.7ApplemacOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2026-437939.834.7ApplemacOSCWE-20An issue existed in the handling of environment variables. This issue was add…
CVE-2026-646949.834.7ApplemacOSCWE-190An integer overflow was addressed with improved input validation. This issue …
CVE-2026-646979.834.7ApplemacOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-646989.834.7ApplemacOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-536666.134.6remix-runreact-routerCWE-470React Router: Arbitrary Constructor Injection via deserializeErrors() in Reac…
CVE-2026-647039.833.7ApplemacOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-663916.533.6Apache Software FoundationApache WicketCWE-330Apache Wicket: leaked and missing CSP headers
CVE-2026-515656.133.5n/an/aCWE-79Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php i…
CVE-2026-647356.533.3AppleiOS and iPadOSCWE-451An inconsistent user interface issue was addressed with improved state manage…
CVE-2026-647389.833.0AppleiOS and iPadOSCWE-284A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-647469.833.0AppleiOS and iPadOSCWE-862An authorization issue was addressed with improved validation. This issue is …
CVE-2026-595287.533.0shiptimeShipTime: Discounted Shipping RatesCWE-497WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Dat…
CVE-2026-142899.032.8UnknownFacturaONE para WooCommerce con VeriFactuCWE-94WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution
CVE-2026-660157.232.3jfrogartifactoryCWE-269JFrog Platform contains an authorization flaw that may allow authenticated pr…
CVE-2026-438188.832.0AppleiOS and iPadOSCWE-190An integer overflow was addressed with improved input validation. This issue …
CVE-2026-437799.831.7ApplemacOSCWE-284A logic issue was addressed with improved restrictions. This issue is fixed i…
CVE-2026-647029.831.7ApplemacOSCWE-284An access issue was addressed with additional sandbox restrictions. This issu…
CVE-2026-548908.231.7ErlangOTPCWE-191BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
CVE-2026-645349.831.5LinuxLinuxnvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path
CVE-2026-592398.631.5RoskusProspero Flow CRMCWE-79Stored XSS in Prospero Flow CRM email body allows administrator account takeover
CVE-2026-658948.730.9CP-PlusEZ-P21 IP CameraCWE-307Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera
CVE-2026-175277.730.7Red HatRed Hat OpenShift Virtualization 4CWE-639Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregat…
CVE-2026-659218.830.6jfrogartifactoryCWE-22Potential path traversal leading to unauthorized file writes
CVE-2026-647398.830.4AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-582278.729.9ErlangOTPCWE-674TLS/DTLS denial of service via unbounded recursion on cross-signed peer certi…
CVE-2026-647759.829.8AppleiOS and iPadOSCWE-665A memory initialization issue was addressed with improved memory handling. Th…
CVE-2026-567478.729.5CriblCribl StreamCWE-94Code Injection in JSON Pointer Processing Component in Cribl Stream
CVE-2026-597302.129.5withastroastroCWE-601@astrojs/node: Backslash-prefixed paths not recognized as internal by trailin…
CVE-2026-555788.829.3pheditorpheditorCWE-78Pheditor: Incomplete command sanitization in terminal feature allows RCE via …
CVE-2026-595467.429.2John DarrelHide My WP GhostCWE-639WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability
CVE-2026-437489.828.9ApplemacOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-647279.828.9ApplemacOSCWE-843A type confusion issue was addressed with improved memory handling. This issu…
CVE-2026-175292.128.9AstrBotDevsAstrBotCWE-285AstrBotDevs AstrBot astr_main_agent.py authorization
CVE-2026-175302.128.9AstrBotDevsAstrBotCWE-285AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset a…
CVE-2026-663906.128.8Apache Software FoundationApache WicketCWE-79Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
CVE-2026-654346.528.6yoomoneyЮKassa для WooCommerceCWE-201WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure v…
CVE-2026-595606.528.3RoxnorFundEngineCWE-862WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability
CVE-2026-536676.128.1remix-runreact-routerCWE-79React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler…
CVE-2026-175529.128.0RRWOPlack::App::PrerenderCWE-918Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrar…
CVE-2026-657656.927.7phoca.czPhoca Commander extension for JoomlaCWE-22Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander…
CVE-2026-646919.827.3ApplemacOSCWE-120A buffer overflow was addressed with improved size validation. This issue is …
CVE-2026-654427.227.1Subtle Web IncFormCraftCWE-918WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vul…
CVE-2026-647306.527.0AppleSafariCWE-451The issue was addressed with improved UI. This issue is fixed in Safari 26.6,…
CVE-2026-646476.326.8vercelnext.jsCWE-116Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies
CVE-2026-437309.826.7AppleiOS and iPadOSCWE-200A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-437579.826.7AppleiOS and iPadOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2026-647629.826.7AppleiOS and iPadOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2026-536686.926.6remix-runreact-routerCWE-79React Router: Open redirect can lead to XSS
CVE-2026-646486.026.5vercelnext.jsCWE-524Next.js: Response Body Cache Confusion for Requests Containing Bodies
CVE-2026-647209.826.2AppleiOS and iPadOSCWE-362A race condition was addressed with improved state handling. This issue is fi…
CVE-2026-647519.825.7AppleiOS and iPadOSCWE-416A use after free issue was addressed with improved memory management. This is…
CVE-2026-647138.125.6AppleSafariCWE-203This issue was addressed with improved checks. This issue is fixed in Safari …
CVE-2021-320849.825.5n/an/aCWE-284An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0…
CVE-2026-398739.825.6ApplemacOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-437109.825.6ApplemacOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-663959.425.5siyuan-notesiyuanCWE-79SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol
CVE-2026-597295.125.6withastroastroCWE-79Astro: XSS via unescaped spread attribute names in renderHTMLElement (incompl…
CVE-2026-663978.625.3thorstenphpMyFAQCWE-22phpMyFAQ before 4.1.6 Path Traversal via category image deletion
CVE-2026-658788.325.3joomshaper.comSP Page Builder extension for JoomlaCWE-22Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP…
CVE-2026-654366.825.3ThemeumKirkiCWE-22WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerability
CVE-2026-664764.925.3Syed BalkhiEasy Digital DownloadsCWE-22WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vu…
CVE-2026-647688.125.3AppleiOS and iPadOSCWE-125An out-of-bounds read issue was addressed with improved input validation. Thi…
CVE-2026-595317.525.2Anh TranFalcon – WordPress Optimizations & TweaksCWE-1284WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknow…
CVE-2026-595397.525.1CozmoslabsPaid Member SubscriptionsCWE-639WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object …
CVE-2026-289829.824.9ApplemacOSCWE-362A race condition was addressed with improved locking. This issue is fixed in …
CVE-2026-660287.124.9CreativeitemEkushey Project Manager CRMCWE-303Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email
CVE-2026-660149.824.7jfrogartifactoryCWE-287Potential authentication bypass leading to privilege escalation in Artifactory
CVE-2026-657645.124.5phoca.czPhoca Commander extension for JoomlaCWE-79Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0…
CVE-2026-438216.524.5AppleSafariCWE-284An access issue was addressed with improved access restrictions. This issue i…
CVE-2026-510787.524.3n/an/aCWE-200An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive i…
CVE-2026-536695.124.2remix-runreact-routerCWE-601React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025…
CVE-2026-656178.823.9jfrogartifactoryCWE-502Potential remote code execution on an Artifactory package service container.
CVE-2026-510777.523.7n/an/aCWE-89SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to…
CVE-2026-647436.523.7AppleiOS and iPadOSCWE-285An authorization issue was addressed with improved state management. This iss…
CVE-2026-597272.123.6withastroastroCWE-79Astro: Cross-site scripting via unescaped transition:* directive values on hy…
CVE-2026-176126.923.4HoneywellS35 Series 3M/5M/8M/PinHole CamerasCWE-200Audit Log Exposure through Unauthorized Access
CVE-2026-660535.923.1Apache Software FoundationApache ThriftCWE-297Apache Thrift: Python TSSLSocket Hostname Matcher Import
CVE-2026-438046.523.0AppleSafariCWE-400This issue was addressed through improved state management. This issue is fix…
CVE-2026-595487.522.8ByteflowsByteflows Travel &amp; Hotel BookingCWE-497WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data E…
CVE-2026-663969.322.1siyuan-notesiyuanCWE-79SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL
CVE-2026-400001.822.2ZTEBlade A75 5GCWE-22Path Traversal Vulnerability in ZTE Blade A75 5G
CVE-2026-165545.122.0DaveGamblecJSONCWE-190Integer Overflow Leading to Heap Buffer Overflow in cJSON
CVE-2021-320858.821.8n/an/aCWE-798An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0…
CVE-2021-320878.821.8n/an/aCWE-798An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0…
CVE-2026-592518.721.8ErlangOTPCWE-770Denial of service via exponential certificate policy tree growth in path vali…
CVE-2026-557375.121.7ErlangOTPCWE-195Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decod…
CVE-2026-647198.121.7AppleSafariCWE-125An out-of-bounds access issue was addressed with improved bounds checking. Th…
CVE-2026-289119.821.5ApplemacOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-420178.821.4jfrogartifactoryCWE-200Privilege escalation via JFrog Worker event token exposure
CVE-2026-592406.921.3RoskusProspero Flow CRMCWE-639IDOR in Prospero Flow CRM allows deletion of other users' notifications
CVE-2021-320889.821.2n/an/aCWE-384An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0…
CVE-2026-595297.521.2motov.netEbook StoreCWE-862WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability
CVE-2026-658799.820.9joomshaper.comSP Page Builder extension for JoomlaCWE-798Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcode…
CVE-2026-289318.820.6AppleiOS and iPadOSCWE-120A buffer overflow was addressed with improved bounds checking. This issue is …
CVE-2026-595377.620.4SenderSender – Newsletter, SMS and Email Marketing Automation for WooCommerceCWE-89WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooComm…
CVE-2026-654336.520.4themewantRT Mega Menu – Mega Menu Builder for Elementor &amp; GutenbergCWE-862WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <…
CVE-2026-595518.520.2rtCamprtMedia for WordPress, BuddyPress and bbPressCWE-89WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQ…
CVE-2026-123949.820.1UnknownMemberGlutCWE-269MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-668249.220.1lookyloolookylooCWE-79Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding
CVE-2026-645408.120.2LinuxLinuxusbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
CVE-2026-645478.120.2LinuxLinuxnet: usb: net1080: validate packet_len before pad-byte access in rx_fixup
CVE-2026-668256.920.1pivotickpivotickCWE-79Cross-Site Scripting via Unsafe URL Schemes in Pivotick Property Links
CVE-2026-122558.119.9UnknownMainWP ChildCWE-287MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass vi…
CVE-2026-438059.819.2AppleiOS and iPadOSCWE-362A race condition was addressed with improved state handling. This issue is fi…
CVE-2026-597284.319.1withastroastroCWE-91@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
CVE-2026-159288.219.0XMLRPC-CXMLRPC-CCWE-79XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected …
CVE-2025-591814.818.9EricssonPacket Core Controller (PCC)CWE-35Path traversal Vulnerability
CVE-2026-663949.318.8siyuan-notesiyuanCWE-79SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass
CVE-2025-639137.518.2n/an/aCWE-400An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial o…
CVE-2026-647286.518.1AppleSafariCWE-693A permissions issue was addressed with improved validation. This issue is fix…
CVE-2026-135979.117.9Unknown微信二维码登陆CWE-287QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover
CVE-2025-156628.617.9UnknownPrintcart Web to Print Product Designer for WooCommerceCWE-918Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthentic…
CVE-2026-595327.517.7magepeopleteamBooking and Rental ManagerCWE-1284WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vul…
CVE-2026-645548.817.6LinuxLinuxnetfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
CVE-2026-542726.917.1beaugundersonip-addressCWE-20ip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass …
CVE-2026-645368.116.9LinuxLinuxstaging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop
CVE-2026-667587.816.7GNOMEGIMPCWE-190Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflo…
CVE-2026-120015.216.8TP-Link Systems Inc.TL-WR850N v3CWE-798Hardcoded Credential Vulnerability in Multiple TP-Link Router Models
CVE-2026-164818.416.4GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox)CWE-918Server-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/…
CVE-2026-437926.516.4AppleSafariCWE-285An authorization issue was addressed with improved state management. This iss…
CVE-2026-98308.216.3Unknownbookingpress-appointment-booking-proCWE-287BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Bookin…
CVE-2026-595307.516.0Payment PluginsStripe For WooCommerceCWE-862WordPress Stripe For WooCommerce plugin <= 4.0.7 - Broken Access Control vuln…
CVE-2026-595347.516.0Aurovrata VenetPost My CF7 FormCWE-862WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability
CVE-2026-595367.516.0CoCart HeadlessCoCart – Headless ecommerceCWE-862WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control…
CVE-2026-595576.515.6FrankyEvents Made EasyCWE-862WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability
CVE-2026-654356.515.6Thrive Themes CouponThrive Leads VersionCWE-862WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulne…
CVE-2026-663989.415.5thorstenphpMyFAQCWE-494phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API
CVE-2026-133329.115.3UnknownMasteriyo LMSCWE-287Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (D…
CVE-2026-437608.615.4ApplemacOSCWE-284An access issue was addressed with improved access restrictions. This issue i…
CVE-2026-108196.515.3MattermostMattermostCWE-409Mattermost Server Denial of Service via Animated GIF Emoji Upload
CVE-2026-664127.115.1LeantimeLeantimeCWE-639Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.ge…
CVE-2026-657669.214.9joomshaper.comSP Page Builder extension for JoomlaCWE-89Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page …
CVE-2026-595279.314.9RomanCodeMapSVGCWE-89WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability
CVE-2026-595339.314.9Christoph VielgraderRelevanssi LightCWE-89WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability
CVE-2026-595389.314.9Ruben GarciaGamiPressCWE-89WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability
CVE-2026-595499.314.9rtCamprtMedia for WordPress, BuddyPress and bbPressCWE-89WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQ…
CVE-2026-595509.314.9Strategy11 TeamAWP ClassifiedsCWE-89WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability
CVE-2026-148276.814.7UnknownCalendarCWE-79Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter
CVE-2026-175688.814.3DevolutionsServerCWE-863Improper access control in the role membership management endpoint in Devolut…
CVE-2026-142357.514.3UnknownDownload ManagerCWE-284WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download vi…
CVE-2026-660186.514.3jfrogartifactoryCWE-200JFrog Artifactory build environment properties exposure
CVE-2026-663998.514.1thorstenphpMyFAQCWE-269phpMyFAQ before 4.1.6 Privilege Escalation via Group Membership
CVE-2026-420168.814.0jfrogartifactoryCWE-863Incorrect authorization validation of user token in JFrog Artifactory allows …
CVE-2026-148566.314.1Media ManagerTastyIgniterCWE-79Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
CVE-2026-658769.213.8joomshaper.comSP Page Builder extension for JoomlaCWE-89Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page …
CVE-2026-647578.813.7AppleSafariCWE-119A memory corruption issue was addressed with improved state management. This …
CVE-2026-658778.213.6joomshaper.comSP Page Builder extension for JoomlaCWE-89Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Bu…
CVE-2026-131528.113.6UnknownCustom Fields Account Registration For WoocommerceCWE-269Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Pr…
CVE-2026-664277.613.5jgwhite33WP Google Review SliderCWE-89WordPress WP Google Review Slider plugin <= 18.4 - SQL Injection vulnerability
CVE-2026-148205.313.2UnknownQuiz and Survey Master (QSM)CWE-200Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Passwo…
CVE-2026-664425.413.2YayCommerceYayPricingCWE-862WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability
CVE-2026-595357.312.6Thrive Themes CouponThrive Product ManagerCWE-862WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vul…
CVE-2026-106004.312.4MattermostMattermostCWE-770Denial of service via unbounded document content extraction in Mattermost Server
CVE-2026-659246.512.2jfrogartifactoryCWE-918Server-Side Request Forgery (SSRF) via Terraform Remote repository
CVE-2026-667597.112.1GNOMEGIMPCWE-125Gimp: out-of-bounds read in file-icns plugin causes information disclosure or…
CVE-2026-559539.111.7ErlangOTPCWE-757TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing s…
CVE-2026-595596.511.7themewantRT Mega Menu – Mega Menu Builder for Elementor &amp; GutenbergCWE-79WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <…
CVE-2026-480525.411.7papra-hqpapraCWE-639Papra: Cross-organization tag deletion and modification via authenticated cro…
CVE-2026-656186.511.3jfrogartifactoryCWE-918Improper URL validation when handling specific URLs Pub, Terraform and Docker…
CVE-2026-659256.511.3jfrogartifactoryCWE-918Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository
CVE-2026-647838.811.2AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-124937.511.2UnknownClover Payment Gateway by Zaytech for WooCommerceCWE-287Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated P…
CVE-2026-480513.511.1papra-hqpapraCWE-918Papra: SSRF via HTTP redirect bypass in webhook delivery
CVE-2026-145686.510.5UnknownUser Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User RegistrationCWE-287WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion
CVE-2026-664737.510.4XenditXendit PaymentCWE-862WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability
CVE-2026-175311.310.1unitedbyaidroidclawCWE-285unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization
CVE-2026-667575.59.9GNOMEGIMPCWE-190Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to cras…
CVE-2026-655645.39.8chrisvrichardsonMapPress Maps for WordPressCWE-497WordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Expos…
CVE-2026-664385.39.8Tim StriflerExclusive Addons ElementorCWE-497WordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposur…
CVE-2026-647426.59.6AppleiOS and iPadOSCWE-319This issue was addressed by using HTTPS when sending information over the net…
CVE-2026-654456.59.7iSaumyaAd Invalid Click Protector (AICP)CWE-862WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access C…
CVE-2026-129898.79.6Ghost RoboticsVision 60CWE-306Multiple vulnerabilities in Ghost Robotics' Vision 60
CVE-2026-437287.59.5ApplemacOSCWE-362This issue was addressed through improved state management. This issue is fix…
CVE-2026-595527.29.4Shahadat Hossain3D Flipbook PDF Viewer &amp; EmbedderCWE-918WordPress 3D Flipbook PDF Viewer & Embedder plugin <= 1.4.2 - Server Side Req…
CVE-2021-320869.89.0n/an/aCWE-321An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0…
CVE-2026-659236.88.7jfrogartifactoryCWE-918Potential server-side request forgery in Artifactory Ansible repository handling
CVE-2026-656168.88.7jfrogartifactoryCWE-347Potential privilege escalation to JFrog administrator privileges
CVE-2026-133905.38.0UnknownThe Events CalendarCWE-862The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Stat…
CVE-2025-591728.57.9EricssonPacket Core Controller (PCC)CWE-78Improper Neutralization of Special Elements used in an OS Command Vulnerability
CVE-2026-595537.17.8RexThemeProduct Feed ManagerCWE-79WordPress Product Feed Manager plugin <= 7.6.1 - Cross Site Scripting (XSS) v…
CVE-2026-595567.17.8acowebsDynamic Pricing With Discount Rules for WooCommerceCWE-79WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.1…
CVE-2026-595587.17.8wpdevelopBooking CalendarCWE-79WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vuln…
CVE-2026-64549await7.9LinuxLinuxBluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
CVE-2026-659225.47.4jfrogartifactoryCWE-862Potential unauthorized modification of Artifactory internal metadata
CVE-2026-655675.37.4NexcessEvent TicketsCWE-862WordPress Event Tickets plugin <= 5.29.0.1 - Broken Access Control vulnerability
CVE-2026-664775.37.4ShufflehoundGillionCWE-862WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability
CVE-2026-64538await7.5LinuxLinuxipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
CVE-2026-64544await7.5LinuxLinuxcrypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
CVE-2026-64553await7.5LinuxLinuxnet: psample: fix info leak in PSAMPLE_ATTR_DATA
CVE-2026-596908.07.3Progress SoftwareLoadMasterCWE-862Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager,…
CVE-2026-64537await7.0LinuxLinuxbridge: cfm: reject invalid CCM interval at configuration time
CVE-2026-142364.76.8UnknownContact Form 7CWE-601Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect
CVE-2026-437534.66.8AppleiOS and iPadOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2026-596898.06.7Progress SoftwareLoadMasterCWE-863Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager,…
CVE-2026-64542await6.5LinuxLinuxipv6: ndisc: fix NULL deref in accept_untracked_na()
CVE-2026-398757.86.4ApplemacOSCWE-276A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-647409.36.2AppleiOS and iPadOSCWE-22A parsing issue in the handling of directory paths was addressed with improve…
CVE-2026-660295.16.2CreativeitemEkushey Project Manager CRMCWE-79Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field
CVE-2026-660305.16.2CreativeitemEkushey Project Manager CRMCWE-79Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field
CVE-2026-660315.16.2CreativeitemEkushey Project Manager CRMCWE-79Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field
CVE-2026-655685.06.2Visual ComposerVisual Composer Website BuilderCWE-862WordPress Visual Composer Website Builder plugin <= 45.15.0 - Broken Access C…
CVE-2026-137267.16.0UnknownMPGCWE-79Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode
CVE-2026-106834.66.1zephyrprojectzephyrCWE-835DesignWare I2C target driver can be wedged into a permanent stuck state by an…
CVE-2026-129826.15.9UnknownDocument GalleryCWE-79Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery
CVE-2026-141906.15.9UnknownSina Extension for ElementorCWE-79Sina Extension for Elementor < 3.10.2 - Reflected XSS
CVE-2026-124955.35.9MercusysMB115-4GCWE-121Stack-Based Buffer Overflow in the Mercusys MB115-4G
CVE-2026-175694.35.8DevolutionsServerCWE-522Improper access control in the NetBox synchronizer in Devolutions Server allo…
CVE-2026-175704.35.8DevolutionsServerCWE-639Improper access control in the PAM password history endpoints in Devolutions …
CVE-2026-437664.65.7ApplemacOSCWE-287An authorization issue was addressed with improved state management. This iss…
CVE-2026-619537.25.6QuantumCloudSimple Link Directory ProCWE-918WordPress Simple Link Directory Pro plugin <= 15.0.6 - Server Side Request Fo…
CVE-2026-658937.05.5CP-PlusEZ-P21 IP CameraCWE-489Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
CVE-2026-141893.85.5UnknownWPBotCWE-89WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_f…
CVE-2026-123837.55.3Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-345Eda-server: externaleventstreamviewset trusts subject header without validati…
CVE-2026-647324.65.3AppleiOS and iPadOSCWE-284This issue was addressed through improved state management. This issue is fix…
CVE-2026-565373.55.3HCLSoftwareConnectionsCWE-209HCL Connections is vulnerable to information disclosure
CVE-2026-565383.55.3HCLSoftwareConnectionsCWE-213HCL Connections is vulnerable to information disclosure
CVE-2026-289817.85.0ApplemacOSCWE-120A buffer overflow was addressed with improved bounds checking. This issue is …
CVE-2026-437767.84.9AppleiOS and iPadOSCWE-120A buffer overflow was addressed with improved bounds checking. This issue is …
CVE-2026-470784.84.8ErlangOTPCWE-23Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-co…
CVE-2026-437728.24.7ApplemacOSCWE-22A path traversal issue was addressed with improved input validation. This iss…
CVE-2026-436987.84.7ApplemacOSCWE-88An injection issue was addressed with improved validation. This issue is fixe…
CVE-2026-437497.84.7ApplemacOSCWE-22A parsing issue in the handling of directory paths was addressed with improve…
CVE-2026-437237.84.6AppleiOS and iPadOSCWE-22A path handling issue was addressed with improved validation. This issue is f…
CVE-2026-100826.14.6UnknownAdvanced AdsCWE-79Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via th…
CVE-2026-134006.14.6UnknownSimply Schedule AppointmentsCWE-79Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Book…
CVE-2026-619577.14.4miniOrangeminiorange otp verificationCWE-79WordPress miniorange otp verification plugin <= 5.5.1 - Cross Site Scripting …
CVE-2026-654377.14.4CleanTalk IncSpam protection, AntiSpam, FireWall by CleanTalkCWE-79WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.82 - C…
CVE-2026-654387.14.4Kofi MokomeMessage Filter for Contact Form 7CWE-79WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.9 - Cross Site Sc…
CVE-2026-654397.14.4ThemeficUltimate Addons for Contact Form 7CWE-79WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scr…
CVE-2026-654407.14.4RoxnorGetGenieCWE-79WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-654417.14.4NexcessGiveWPCWE-79WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-654437.14.4WP MediaBackWPupCWE-79WordPress BackWPup plugin <= 5.7.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-654467.14.4WP ChillKali FormsCWE-79WordPress Kali Forms plugin <= 2.4.18 - Cross Site Scripting (XSS) vulnerability
CVE-2026-654477.14.4Wasiliy Strecker / ContestGallery developerContest GalleryCWE-79WordPress Contest Gallery plugin <= 30.0.6 - Cross Site Scripting (XSS) vulne…
CVE-2025-591776.84.4EricssonEricsson Packet Core Controller (PCC)CWE-209Generation of Error Message Containing Sensitive Information Vulnerability
CVE-2025-591784.84.4EricssonPacket Core Controller (PCC)CWE-497Exposure of Sensitive System Information to an Unauthorized Control Sphere Vu…
CVE-2026-437717.14.2ApplemacOSCWE-121A stack overflow was addressed with improved input validation. This issue is …
CVE-2026-647225.54.3AppleiOS and iPadOSCWE-120A buffer overflow issue was addressed with improved memory handling. This iss…
CVE-2026-645488.44.2LinuxLinuxbpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
CVE-2026-645528.44.2LinuxLinuxvirtio-net: fix len check in receive_big()
CVE-2026-437655.54.2ApplemacOSCWE-59This issue was addressed with improved handling of symlinks. This issue is fi…
CVE-2026-129918.74.0Ghost RoboticsVision 60CWE-300Multiple vulnerabilities in Ghost Robotics' Vision 60
CVE-2026-647477.84.0AppleiOS and iPadOSCWE-120A buffer overflow was addressed with improved size validation. This issue is …
CVE-2026-142034.84.0UnknownSmart ManagerCWE-79Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title
CVE-2026-655575.93.8TychesoftwaresAbandoned Cart Lite for WooCommerceCWE-79WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Sc…
CVE-2026-655635.93.8ThemeisleOrbit Fox by ThemeIsleCWE-79WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS)…
CVE-2026-664755.93.8acowebsCheckout Field Editor for WooCommerce &#8211; Checkout ManagerCWE-79WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plug…
CVE-2026-289127.83.8ApplemacOSCWE-693A logic issue was addressed with improved restrictions. This issue is fixed i…
CVE-2026-646995.53.7ApplemacOSCWE-457A memory initialization issue was addressed with improved memory handling. Th…
CVE-2026-655585.43.7WPCenterAffiliateXCWE-918WordPress AffiliateX plugin <= 2.3.5 - Server Side Request Forgery (SSRF) vul…
CVE-2026-645337.83.6LinuxLinuxfs/ntfs3: validate lcns_follow in log_replay conversion
CVE-2026-175141.93.6ZJONSSONnode-unzipperCWE-22ZJONSSON node-unzipper extract.js Extract path traversal
CVE-2026-647452.43.5ApplemacOSCWE-287This issue was addressed with additional restrictions on the lock screen. Thi…
CVE-2026-398777.83.4AppleiOS and iPadOSCWE-119A memory corruption issue was addressed with improved memory handling. This i…
CVE-2026-647345.53.4AppleiOS and iPadOSCWE-200The issue was addressed with improved checks. This issue is fixed in iOS 18.7…
CVE-2026-579174.83.4AssecoproCertum SmartSignCWE-611Improper Restriction of XML External Entity Reference in proCertum SmartSign
CVE-2026-289738.63.3AppleiOS and iPadOSCWE-190An integer overflow was addressed with improved input validation. This issue …
CVE-2026-437297.83.3AppleiOS and iPadOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-437337.83.3AppleiOS and iPadOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-437807.83.3AppleiOS and iPadOSCWE-190An integer overflow was addressed with improved input validation. This issue …
CVE-2026-647167.83.3AppleiOS and iPadOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-437385.53.2AppleiOS and iPadOSCWE-125The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-129907.73.1Ghost RoboticsVision 60CWE-284Multiple vulnerabilities in Ghost Robotics' Vision 60
CVE-2026-438005.53.2AppleiOS and iPadOSCWE-200An information disclosure issue was addressed by removing the vulnerable code…
CVE-2026-645327.83.1LinuxLinuxfs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
CVE-2026-646927.13.0AppleiOS and iPadOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2026-647257.13.1AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-654486.53.1AcyMailing Newsletter TeamAnti Spam and list cleaner &#8211; AcyCheckerCWE-79WordPress Anti Spam and list cleaner – AcyChecker plugin <= 1.8.1 - Cross Sit…
CVE-2026-655616.53.1miniOrangeWordPress Social Login and RegisterCWE-79WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Sc…
CVE-2026-655626.53.1WPDeveloperBetterDocsCWE-79WordPress BetterDocs plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-664336.53.1ShapedPlugin LLCLocation WeatherCWE-79WordPress Location Weather plugin <= 3.0.6 - Cross Site Scripting (XSS) vulne…
CVE-2026-664346.53.1Sayontan SinhaPhotonic Gallery & Lightbox for Flickr, SmugMug & OthersCWE-79WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= …
CVE-2026-664456.53.1100pluginsOpen User MapCWE-79WordPress Open User Map plugin <= 1.4.46 - Cross Site Scripting (XSS) vulnera…
CVE-2026-664486.53.1WP ChillGallery PhotoBlocksCWE-79WordPress Gallery PhotoBlocks plugin <= 1.3.3 - Cross Site Scripting (XSS) vu…
CVE-2026-437745.53.1ApplemacOSCWE-787An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2026-437975.53.1AppleiOS and iPadOSCWE-200This issue was addressed with improved checks. This issue is fixed in iOS 18.…
CVE-2026-647105.53.1ApplemacOSCWE-200A privacy issue was addressed by removing sensitive data. This issue is fixed…
CVE-2026-645317.83.0LinuxLinuxnet: openvswitch: reject oversized nested action attrs
CVE-2026-647637.82.9AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed by removing the vulnerable code. T…
CVE-2026-647647.82.9AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-647657.83.0AppleiOS and iPadOSCWE-190An integer overflow was addressed with improved input validation. This issue …
CVE-2026-647667.82.9AppleiOS and iPadOSCWE-190An integer overflow was addressed with improved input validation. This issue …
CVE-2026-438137.12.9AppleiOS and iPadOSCWE-20A validation issue was addressed with improved input sanitization. This issue…
CVE-2026-437145.53.0AppleiOS and iPadOSCWE-20The issue was addressed with improved input sanitization. This issue is fixed…
CVE-2026-437545.53.0AppleiOS and iPadOSCWE-200This issue was addressed with improved redaction of sensitive information. Th…
CVE-2026-437585.53.0ApplemacOSCWE-200An authorization issue was addressed with improved state management. This iss…
CVE-2026-437965.53.0AppleiOS and iPadOSCWE-200This issue was addressed with improved data protection. This issue is fixed i…
CVE-2026-438015.53.0AppleiOS and iPadOSCWE-200This issue was addressed with improved checks. This issue is fixed in iOS 18.…
CVE-2026-647095.53.0AppleiOS and iPadOSCWE-200The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-647215.53.0AppleiOS and iPadOSCWE-664This issue was addressed through improved state management. This issue is fix…
CVE-2026-647415.53.0AppleiOS and iPadOSCWE-200A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-647445.53.0AppleiOS and iPadOSCWE-200An information leakage was addressed with additional validation. This issue i…
CVE-2026-645558.82.9LinuxLinuxKVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
CVE-2026-289325.52.8ApplemacOSCWE-400A logic issue existed resulting in memory corruption. This was addressed with…
CVE-2026-437595.52.9ApplemacOSCWE-200An authorization issue was addressed with improved state management. This iss…
CVE-2026-437685.52.8ApplemacOSCWE-400The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-647085.52.9ApplemacOSCWE-693A file quarantine bypass was addressed with additional checks. This issue is …
CVE-2026-288967.72.7ApplemacOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-645507.32.7LinuxLinuxnet: qualcomm: rmnet: validate MAP frame length before ingress parsing
CVE-2026-436817.12.7ApplemacOSCWE-120A buffer overflow was addressed with improved bounds checking. This issue is …
CVE-2026-645467.12.7LinuxLinuxdrm/edid: fix OOB read in drm_parse_tiled_block()
CVE-2026-437395.52.7AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-437445.52.7AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-438165.52.7AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-438175.52.7AppleiOS and iPadOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2026-646935.52.7AppleiOS and iPadOSCWE-843A type confusion issue was addressed with improved checks. This issue is fixe…
CVE-2026-647245.52.7AppleiOS and iPadOSCWE-400The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-645437.82.6LinuxLinuxtipc: fix use-after-free of the discoverer in tipc_disc_rcv()
CVE-2026-289457.12.6ApplemacOSCWE-284A permissions issue was addressed with additional sandbox restrictions. This …
CVE-2026-436737.82.5AppleiOS and iPadOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-437117.82.5AppleiOS and iPadOSCWE-119A memory corruption issue was addressed with improved memory handling. This i…
CVE-2026-647497.82.6AppleiOS and iPadOSCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-647587.82.6AppleiOS and iPadOSCWE-119The issue was addressed with improved bounds checks. This issue is fixed in i…
CVE-2026-437635.52.5ApplemacOSCWE-284A permissions issue was addressed by removing the vulnerable code. This issue…
CVE-2026-647555.52.5AppleiOS and iPadOSCWE-200An authorization issue was addressed with improved state management. This iss…
CVE-2026-438195.52.5ApplemacOSCWE-284An access issue was addressed with additional sandbox restrictions. This issu…
CVE-2026-645397.82.4LinuxLinuxBluetooth: eir: Fix stack OOB write when prepending the Flags AD

Results continue: ranks 401–440.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-27 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.