boxscore/security
Tuesday, July 28, 2026 · all times UTC← 2026-07-27 · archive · 2026-07-29 →

243 CVEs published July 28, 2026: 21 critical, 117 high, 93 medium, 12 low; 0 in KEV; 20 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 218 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published4937768613872563
KEV catalog size1670

175 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux661157920711229802730.27.8.0016+421
microsoft65713601049293028378322.47.8.0039+438
apple167244566711229372.97.1.0027+167
red hat881879937411400.07.1.0027+46
google27366251173513.98.8.0029+24
canonical330210000.07.8.0013+3
android010100161100.08.4.0171-1
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco7194610961263.28.6.2459+4
fortinet1118249028633.36.1.0054+10
palo alto networks1015017514213.34.7.0028+7
vmware7716002100.08.7.0044+7
f51540007120.09.2.04020
ivanti051000335100.010.0.8152-1
checkpoint3431003250.09.2.4696+2
broadcom2400204250.05.1.0877+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache488017441904011.37.5.0061+32
mozilla67724226401300.09.1.0031+67
wordpress3311105266.78.6.7310+3
docker030120100.05.7.0015-3
github220110000.06.1.0029+2
gitlab02000042100.0.44510
kubernetes110001000.02.4.0024+1
drupal01100051100.09.8.88320
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091113212539304574030.37.6.0031+1107
ibm63712225240700.07.5.0026+62
adobe26379204075410.88.4.0040+19
progress232331550900.08.1.0032+23
solarwinds15191511011421.19.1.0044+14
atlassian3303001300.08.0.0026+3
zohocorp331110000.07.1.0048+3
veeam110100400.08.4.0013+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link78006126112.55.5.0073+7
hikvision5603202116.77.2.0024+5
bosch220200000.08.0.0018+2
honeywell110010000.06.9.0031+1
rockwell automation111000000.09.2.0030+1
siemens010100100.08.7.00320
dahua000000200
qnap000000800
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb5757326253000.07.1.0025+57
grafana841214223000.06.5.0033+2
open ises037214210000.06.9.00210
netty133562621000.07.5.0047-1
erlang1432114143100.06.9.0033+7
regularlabs.com292961490000.07.5.0022+29
watchguard172811890400.07.3.0026+17
nlnet labs242704176000.05.9.0024+24

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1109
linux662
microsoft657
apple204
red hat101
ibm70
mozilla67
surrealdb57
apache48
regularlabs.com29
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco12
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven22
Go3
crates.io2
npm2
NuGet1
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-25089Fortinet0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171714
CVE-2021-27102Accellion2021-11-171714
CVE-2021-27101Accellion2021-11-171714
CVE-2021-27103Accellion2021-11-171714
CVE-2021-21017Adobe2021-11-171714
CVE-2021-28550Adobe2021-11-171714
CVE-2021-42013Apache2021-11-171714
CVE-2021-41773Apache2021-11-171714
CVE-2021-30858Apple2021-11-171714
CVE-2021-30860Apple2021-11-171714

Transactions

EXPLOIT PUBLISHEDCVE-2026-17531 (unitedbyai droidclaw). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-31431 (Linux Kernel). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-39875 (Apple macOS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-4258 (sjcl). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-43760 (Apple macOS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-43910 (appium java-client). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45711 (axllent mailpit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47427 (github-mcp-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-49477 (facelessuser soupsieve). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53359 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54332 (gopacket). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54345 (gopacket). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54656 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54690 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55389 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55415 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55554 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55555 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56722 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59941 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59942 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59943 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-61511 (vBulletin). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64620 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64621 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65708 (nuxsmin sysPass). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65709 (nuxsmin sysPass). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65710 (nuxsmin sysPass). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65711 (nuxsmin sysPass). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65899 (cure53 DOMPurify). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65902 (cure53 DOMPurify). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65904 (cure53 DOMPurify). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65911 (cure53 DOMPurify). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65917 (usmannasir cyberpanel). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66028 (Creativeitem Ekushey Project Manager CRM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66029 (Creativeitem Ekushey Project Manager CRM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66030 (Creativeitem Ekushey Project Manager CRM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66031 (Creativeitem Ekushey Project Manager CRM). Public exploit reference added.

RESCOREDCVE-2024-21538 (cross-spawn). CVSS 8.7 → 7.7 (NVD).

RESCOREDCVE-2025-68686 (Fortinet FortiOS). CVSS 5.3 → 5.9 (NVD).

RESCOREDCVE-2026-15631 (@fastify/http-proxy). CVSS 8.7 → 10 (NVD).

RESCOREDCVE-2026-4258 (sjcl). CVSS 8.7 → 7.7 (NVD).

RESCOREDCVE-2026-45501 (Microsoft Exchange Server 2016 Cumulative Update 23). CVSS 6.5 → 6.1 (NVD).

RESCOREDCVE-2026-45503 (Microsoft Exchange Server 2016 Cumulative Update 23). CVSS 8.1 → 6.5 (NVD).

RESCOREDCVE-2026-45583 (Microsoft Exchange Server 2016 Cumulative Update 23). CVSS 7.5 → 8.1 (NVD).

RESCOREDCVE-2026-47631 (Microsoft Exchange Server 2016 Cumulative Update 23). CVSS 8.1 → 5.4 (NVD).

ENRICHEDCVE-2026-31431 (Linux Kernel). Received CVSS 7.8 and CPE data from NVD.

Yesterday's Results

243 CVEs published. 25 box scores, 218 table rows — nothing truncated.

Apache Axis2/Java: deserialization of untrusted Data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0183   77.0     —
AFFECTED
  Product            Versions     Fixed
  Apache Axis2/Java  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 28  Published (CNA: apache)
CWE-502 · CNA: apache · 3 references · NVD status: Analyzed
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebU…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0113   63.7     —
AFFECTED
  Product          Versions     Fixed
  WRC-X3000GS3-B   unspecified  —
  WRC-X3000GS3A-B  unspecified  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 28  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · 2 references · NVD status: Deferred
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Rest…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0113   63.7     —
AFFECTED
  Product       Versions     Fixed
  WAB-M1775-PS  unspecified  —
  WAB-S1775     unspecified  —
  WAB-M2133     unspecified  —
  WAB-I1750-PS  unspecified  —
  WAB-S1167-PS  unspecified  —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 28  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · 2 references · NVD status: Deferred
IBM Aspera Faspex 5 — OS Command Injection in IBM Aspera Faspex
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0104   61.1     —
AFFECTED
  Product          Versions  Fixed
  Aspera Faspex 5  5.0.0 –   —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: ibm)
CWE-78 · CNA: ibm · 1 reference · NVD status: Analyzed
Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0088   56.2     —
AFFECTED
  Product               Versions     Fixed
  Apache ActiveMQ AMQP  unspecified  —
  Apache ActiveMQ       unspecified  —
  Apache ActiveMQ All   unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: apache)
CWE-20 · CNA: apache · 2 references · NVD status: Analyzed
owen2345 camaleon-cms — Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0080   53.8     —
AFFECTED
  Product       Versions  Fixed
  camaleon-cms  2.1.1 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 28  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 7 references · NVD status: Deferred
n/a zip-lib — Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanis…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0078   53.1     —
AFFECTED
  Product  Versions     Fixed
  zip-lib  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 28  Published (CNA: snyk)
CWE-22 · CNA: snyk · 3 references · NVD status: Deferred
wordplus Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots — Better Messages <= 2.15.19 - Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal via 'file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0073   51.4     —
AFFECTED
  Product                                                                    Versions     Fixed
  Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots  unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 28  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 6 references · NVD status: Deferred
PHPOffice PhpSpreadsheet — PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0069   49.8     —
AFFECTED
  Product         Versions             Fixed
  PhpSpreadsheet  >= 4.0.0, < 5.8.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: GitHub_M)
CWE-400, CWE-409 · CNA: GitHub_M · 7 references · NVD status: Deferred
PHPOffice PhpSpreadsheet — PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0069   49.8     —
AFFECTED
  Product         Versions             Fixed
  PhpSpreadsheet  >= 4.0.0, < 5.8.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: GitHub_M)
CWE-400, CWE-835 · CNA: GitHub_M · 7 references · NVD status: Deferred
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0063   47.5     —
AFFECTED
  Product  Versions   Fixed
  dompdf   < 3.1.6 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Public exploit reference published
  Jul 28  Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · 3 references · NVD status: Analyzed
PHPOffice PhpSpreadsheet — PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0053   42.4     —
AFFECTED
  Product         Versions             Fixed
  PhpSpreadsheet  >= 4.0.0, < 5.8.1 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · 7 references · NVD status: Deferred
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0052   42.0     —
AFFECTED
  Product                       Versions  Fixed
  WebSphere Application Server  9.0 –     —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 28  Published (CNA: ibm)
CWE-502 · CNA: ibm · 1 reference · NVD status: Analyzed
IBM Aspera Faspex 5 — OS command injection in IBM Aspera Faspex
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0052   41.8     —
AFFECTED
  Product          Versions  Fixed
  Aspera Faspex 5  5.0.0 –   —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: ibm)
CWE-78 · CNA: ibm · 1 reference · NVD status: Analyzed
uncannyowl Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin — Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0051   41.4     —
AFFECTED
  Product                                                                               Versions     Fixed
  Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 28  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 14 references · NVD status: Deferred
deveasel Demi – One Click Demo Import, Backup & Site Migration — Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0051   41.1     —
AFFECTED
  Product                                                Versions     Fixed
  Demi – One Click Demo Import, Backup & Site Migration  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 28  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 10 references · NVD status: Deferred
Dompdf: File existence oracle via font-face stylesheet declaration
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   L   N   N    2.3   .0051   41.1     —
AFFECTED
  Product  Versions   Fixed
  dompdf   < 3.1.6 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 28  Public exploit reference published
  Jul 28  Published (CNA: GitHub_M)
CWE-203 · CNA: GitHub_M · 3 references · NVD status: Analyzed
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0050   40.2     —
AFFECTED
  Product  Versions   Fixed
  dompdf   < 3.1.6 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Public exploit reference published
  Jul 28  Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · 4 references · NVD status: Analyzed
misp misp — Open Redirect in MISP Installer-Generated Apache Configuration
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   N    7.8   .0049   40.1     —
AFFECTED
  Product  Versions     Fixed
  misp     unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 28  Published (CNA: CIRCL)
CWE-601 · CNA: CIRCL · 1 reference · NVD status: Deferred
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .0049   39.7     —
AFFECTED
  Product                 Versions     Fixed
  Apache ActiveMQ Broker  unspecified  —
  Apache ActiveMQ All     unspecified  —
  Apache ActiveMQ         unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 28  Published (CNA: apache)
CWE-285 · CNA: apache · 2 references · NVD status: Analyzed
Xen Xen — vIRQ event channel binding may break Xenstore
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0048   39.2     —
AFFECTED
  Product  Versions     Fixed
  Xen      unspecified  —
TIMELINE
  Apr 27  Reserved by CNA
  Jul 28  Published (CNA: XEN)
CWE-459 · CNA: XEN · 3 references · NVD status: Deferred
Xen Xen — x86 shadow paging is deprecated
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0047   38.9     —
AFFECTED
  Product  Versions     Fixed
  Xen      unspecified  —
TIMELINE
  Apr 27  Reserved by CNA
  Jul 28  Published (CNA: XEN)
CWE-400 · CNA: XEN · 3 references · NVD status: Deferred
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .0047   38.4     —
AFFECTED
  Product  Versions                          Fixed
  netty    >= 4.2.0.Final, < 4.2.16.Final –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: GitHub_M)
CWE-93 · CNA: GitHub_M · 1 reference · NVD status: Analyzed
delvedor find-my-way — find-my-way is Vulnerable to DDoS with HTTP2
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   38.1     —
AFFECTED
  Product      Versions   Fixed
  find-my-way  < 9.7.0 –  —
TIMELINE
  May 18  Reserved by CNA
  Jul 28  Published (CNA: GitHub_M)
CWE-20, CWE-248 · CNA: GitHub_M · 1 reference · NVD status: Deferred
cozyvision1 SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery — SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0046   38.0     —
AFFECTED
  Product                                                                               Versions     Fixed
  SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 28  Published (CNA: Wordfence)
CWE-288 · CNA: Wordfence · 7 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-118419.437.9SICK AGInspectorP61xCWE-552CVE-2026-11841
CVE-2026-6588010.037.8balbooa.comBalbooa Forms component for JoomlaCWE-94Joomla Extension - balbooa.com - Unauthenticated remote code execution in Bal…
CVE-2026-131617.537.6themetechmountTrueBooker – Appointment Booking and Scheduler SystemCWE-89TrueBooker <= 1.2.2 - Unauthenticated SQL Injection
CVE-2026-543456.937.6gopacketgopacketCWE-191GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads…
CVE-2026-671858.737.6GeneralSandmanTinyWebCWE-22TinyWeb 0.0.8 Path Traversal via URL Path Component
CVE-2026-1175610.037.5Dassault SystèmesStation Launcher App in 3DEXPERIENCE platformCWE-502Deserialization of Untrusted Data vulnerability affecting Station Launcher Ap…
CVE-2026-149739.337.5IBMAspera Desktop AppCWE-22Path Traversal in IBM Desktop App
CVE-2026-662997.537.4Apache Software FoundationApache TomcatCWE-400Apache Tomcat: DoS via WebSocket chat example
CVE-2026-567226.337.3dompdfdompdfCWE-20Dompdf: Local file read due to improper file path validation in SVG images en…
CVE-2026-546589.836.6hypequeryhypequeryCWE-89@hypequery/clickhouse has SQL Injection in parameter escaping that allows arb…
CVE-2026-671848.736.0GeneralSandmanTinyWebCWE-476TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
CVE-2026-543326.935.8gopacketgopacketCWE-770GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled a…
CVE-2026-546357.535.0nessshontonapiCWE-287pytonapi has a Webhook Custom Path Authentication Bypass
CVE-2026-164629.335.0Weidmueller InterfacePROCON-WEB SCADACWE-89SQL injection via unauthenticated GetGridData endpoint
CVE-2026-671826.934.6tomakarouilleCWE-444Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
CVE-2026-474277.534.2githubgithub-mcp-serverCWE-476GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler
CVE-2026-667548.233.3tomakarouilleCWE-617Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
CVE-2026-210478.332.8Samsung MobileSamsung Mobile DevicesCWE-787Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remo…
CVE-2026-616097.532.6pterodactylpanelCWE-770Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enable…
CVE-2026-633035.132.3OpenSolutionQuick.CMSCWE-23Path Traversal in Quick.CMS
CVE-2026-671749.231.7pivotickpivotickCWE-79DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pi…
CVE-2026-656246.931.5nineninescowboyCWE-770Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory …
CVE-2026-149749.830.9IBMWebSphere Application ServerCWE-502IBM WebSphere Application Server is affected by cross-site scripting and dese…
CVE-2026-143288.830.7eazypluginsEazy Plugin Manager – Powerful Plugin Management Solution for WordPressCWE-269Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalati…
CVE-2026-624317.530.6XenXenCWE-369Viridian STIMER division by zero
CVE-2026-553897.530.5koxudaxidatamodel-code-generatorCWE-22datamodel-code-generator vulnerable to arbitrary local file read via JSON-Sch…
CVE-2026-546538.830.0koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code injection in via attacker-contr…
CVE-2026-546596.929.9ddnexuspagyCWE-22Pagy I18n locale option is not validated before being used in a file path
CVE-2026-671838.729.8GeneralSandmanTinyWebCWE-401TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling
CVE-2026-546508.629.2bablilayoubopenholeCWE-22openhole-server vulnerable to path traversal via URL-decoded request path
CVE-2026-553907.529.2koxudaxidatamodel-code-generatorCWE-22Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`)…
CVE-2026-633017.029.2OpenSolutionQuick.CMSCWE-602Denial of Service in Quick.CMS
CVE-2026-80584.528.9IBMOPENBMCCWE-200This Power System update is being released to address a sensitive information…
CVE-2026-545938.128.8pterodactylpanelCWE-1259Pterodactyl's improper JWT scoping allows subuser to upload files when not ex…
CVE-2026-68792.028.6Python Software FoundationCPythonCWE-407Quadratic Behavior in xml.etree.ElementPath Index Predicates
CVE-2026-546387.527.6gotdtdCWE-770td has pre-auth denial of service via unbounded memory allocation in proto.Un…
CVE-2026-623259.127.4goshs-labsgoshsCWE-306goshs SFTP authentication bypass via empty password (incomplete fix of CVE-20…
CVE-2026-671735.127.1pivotickpivotickCWE-918Pivotick Unvalidated Node Image URLs Allow Unintended Client-Side Requests
CVE-2026-51144.927.0softaculousSpeedyCache – Cache, Optimization, PerformanceCWE-22SpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File Read
CVE-2026-575108.726.8superplanehqsuperplaneCWE-639SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC
CVE-2026-648639.126.6goshs-labsgoshsCWE-284goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVE-2026-152807.526.4IBMWebSphere Application Server - LibertyCWE-22IBM WebSphere Application Server Liberty is affected by a remote code executi…
CVE-2026-148937.326.3IBMObservability with Instana (Agent)CWE-1321IBM Instana Observability is affected by multiple Prototype Pollution within …
CVE-2026-1649810.025.9HashiCorpToolingCWE-488terraform-mcp-server vulnerable to cross-tenant credential reuse in streamabl…
CVE-2026-156734.425.6cozyvision1SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart RecoveryCWE-89SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checko…
CVE-2026-624345.325.5XenXenCWE-787PoD: Don't try to reclaim special pages
CVE-2026-161849.825.0IBMWebSphere Application ServerCWE-862IBM WebSphere Application Server is affected by an authentication bypass
CVE-2026-150125.324.5deveaselDemi – One Click Demo Import, Backup & Site MigrationCWE-200Demi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory Copy
CVE-2026-667457.524.4ArticaTechArtica ProxyCWE-94Artica Proxy 4.50 Session Fixation via fw.login.php
CVE-2026-667497.123.8sdelementslets-chatCWE-476Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup
CVE-2026-660645.323.5goshs-labsgoshsCWE-41goshs has ACL Bypass & Path Traversal
CVE-2026-474838.223.3NVIDIADCGMCWE-770NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug…
CVE-2026-633025.123.3OpenSolutionQuick.CMSCWE-98Local File Inclusion in Quick.CMS
CVE-2026-149769.823.1IBMWebSphere Application Server - LibertyCWE-306IBM WebSphere Application Server Liberty is affected by a remote code executi…
CVE-2026-102077.523.0pickpluginsPickPlugins Question AnswerCWE-89PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id…
CVE-2026-127417.523.0epsiloncoolWP Fast Total Search – The Power of Indexed SearchCWE-89WP Fast Total Search <= 1.80.280 - Unauthenticated SQL Injection
CVE-2026-128007.523.0codename065Premium Packages – Sell Digital Products SecurelyCWE-89Premium Packages <= 6.2.0 - Unauthenticated SQL Injection
CVE-2026-147857.523.0mihail-chepovskiyWeb Directory FreeCWE-89Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection
CVE-2026-507387.722.7EnterpriseDBpglogicalCWE-416A use-after-free condition exists in pglogical's worker signaling code, where…
CVE-2026-148698.621.8HashiCorpToolingCWE-918terraform-mcp-server vulnerable to server side request forgery leading to tok…
CVE-2026-144469.821.7IBMWebSphere Application ServerCWE-306IBM WebSphere Application Server is affected by a privilege escalation
CVE-2026-554157.521.7koxudaxidatamodel-code-generatorCWE-94datamodel-code-generator vulnerable to code injection via `x-python-import` /…
CVE-2026-671816.321.7tomakarouilleCWE-444Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
CVE-2026-592488.721.6nineninescowlibCWE-770Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhau…
CVE-2026-480256.921.7juevnebula-meshCWE-244nebula-mesh: Decrypted CA private key persists in heap after signing
CVE-2026-145167.521.5ladelaOnline Scheduling and Appointment Booking System – BooklyCWE-89Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQ…
CVE-2026-19184.921.4IBMSterling B2B IntegratorCWE-532IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive inf…
CVE-2026-141698.121.3ads-tec Industrial ITDVG-IRF1401CWE-696ads-tec Industrial IT: Account lockout via non-atomic user creation
CVE-2026-154444.921.3themeumTutor LMS – eLearning and online course solutionCWE-89Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon…
CVE-2026-156714.921.3cozyvision1SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart RecoveryCWE-89SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Pa…
CVE-2026-480608.120.9litestar-orglitestarCWE-79Litestar: HTML Injection Through CSRF Token
CVE-2026-669225.120.9pivotickpivotickCWE-1321Pivotick Prototype-Key Collision in Tree Layout and Cycle Detection Allows Gr…
CVE-2026-492588.820.8juevnebula-meshCWE-639Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to…
CVE-2026-547197.520.8goshs-labsgoshsCWE-862goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download …
CVE-2026-75215.520.8MattermostMattermostCWE-22SAML certificate deletion allows path traversal to delete arbitrary files out…
CVE-2026-493328.520.7Red HatRed Hat OpenShift Container Platform 4.14CWE-436Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling ena…
CVE-2026-180476.520.6Red HatRed Hat Certificate System 10CWE-288Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint aut…
CVE-2026-555542.320.3dompdfdompdfCWE-20Dompdf: Chroot Validation Bypass
CVE-2026-145459.820.1UnknownTrueBookerCWE-269TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via…
CVE-2026-141688.820.1ads-tec Industrial ITDVG-IRF1401CWE-862ads-tec Industrial IT: Vertical privilege escalation via configuration table …
CVE-2026-141678.720.1ads-tec Industrial ITDVG-IRF1401CWE-863ads-tec Industrial IT: Privilege escalation during configuration import
CVE-2026-669188.220.1pivotickpivotickCWE-79DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons
CVE-2026-669216.320.1pivotickpivotickCWE-79Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node …
CVE-2026-77698.120.0IBMSterling B2B IntegratorCWE-89SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM S…
CVE-2024-140418.219.9Legion of the Bouncy Castle Inc.BC-JAVACWE-208ML-KEM (Kyber) decapsulation leaks private key information through non-consta…
CVE-2026-159928.819.8teydeastudioWP Password PolicyCWE-269WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation
CVE-2026-164968.919.6HashiCorpToolingCWE-384terraform-mcp-server vulnerable to cross-user credential inheritance if an MC…
CVE-2026-167735.319.7quantumcloudWPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-200WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_sen…
CVE-2026-546038.619.0ruby-oauthoauth2CWE-200OAuth2::Client#request: Protocol-relative redirect Location overrides authori…
CVE-2026-156704.918.8cozyvision1SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart RecoveryCWE-89SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderb…
CVE-2026-168114.918.8devitemsllcShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-89ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'order…
CVE-2026-134407.218.5wedevsStoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerceCWE-79StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Chec…
CVE-2026-546098.618.2Quiet-Terminal-InteractiveQTINeonCWE-400QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNE…
CVE-2026-149817.518.2IBMWebSphere Application ServerCWE-400IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-150577.518.2IBMWebSphere Application Server - LibertyCWE-787IBM WebSphere Application Server Liberty is affected by a denial of service v…
CVE-2026-624337.318.2XenXenCWE-665correct buffer checks for DM_OP hypercalls
CVE-2026-161926.518.2IBMWebSphere Application Server - LibertyCWE-674IBM WebSphere Application Server Liberty is affected by a denial of service
CVE-2026-667505.318.3sdelementslets-chatCWE-862Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files…
CVE-2026-669196.918.1PivotickPivotickCWE-79Stored DOM-Based Cross-Site Scripting in Node Modal Headers
CVE-2026-152676.518.0taskbuilderTaskbuilder – Project Management & Task Management Tool With Kanban BoardCWE-89Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection
CVE-2026-637278.717.8AnchoreAnchore EnterpriseCWE-648Anchore Enterprise Privilege Escalation via User Management API
CVE-2026-154115.317.9wedevsStoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerceCWE-862StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Chec…
CVE-2026-145287.517.8IBMWebSphere Application ServerCWE-532IBM WebSphere Application Server is affected by an unsafe deserialization and…
CVE-2026-599436.317.7dompdfdompdfCWE-209Dompdf: Embedded SVG images can leak existence of files and directories withi…
CVE-2026-669208.216.9PivotickPivotickCWE-400Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data
CVE-2026-149247.517.0UnknownTablesome TableCWE-862Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
CVE-2026-669136.916.9lookyloolookylooCWE-400Zip Bomb in Lookyloo Capture Upload Allows Denial of Service
CVE-2026-624307.516.9XenXenCWE-362x86: Out-of-bounds read in vRTC emulation
CVE-2026-167718.816.6AT&TArris BGW210‑700CWE-306CVE-2026-16771
CVE-2026-153936.416.7cozythemesCozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & TemplatesCWE-79Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-624278.816.5XenXenCWE-284sysctl and platform-op locks open to abuse
CVE-2026-62516.516.5ChatyChaty ProCWE-89Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id…
CVE-2026-153046.516.5foomagooPlugin OrganizerCWE-89Plugin Organizer <= 10.2.4 - Authenticated (Subscriber+) SQL Injection
CVE-2026-163137.616.2Red HatRed Hat Enterprise Linux 10CWE-93Sg3_utils: sg3_utils: arbitrary command execution via udev property injection…
CVE-2026-658817.516.0joomdle.comJoomdle component for JoomlaCWE-1188Joomla Extension - joomdle.com - Insecure default configuration allows read/w…
CVE-2026-667465.315.5tomakarouilleCWE-113Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
CVE-2026-96805.815.4AlibabaAlibaba Cloud RDS OpenAPI MCP ServerCWE-1188MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-…
CVE-2026-49124.115.4tigroumeowMedia Cleaner: Clean your WordPress!CWE-918Media Cleaner: Clean your WordPress! <= 7.0.3 - Authenticated (Administrator+…
CVE-2026-439108.215.2appiumjava-clientCWE-441Appium java-client Allows Network Pivot via Unvalidated directConnect Redirec…
CVE-2026-477267.115.1juevnebula-meshCWE-285nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
CVE-2026-667526.315.0tiny-httptiny-httpCWE-444tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
CVE-2026-575116.314.7superplanehqsuperplaneCWE-93SuperPlane < 0.30.0 SMTP Header Injection via Webhook Event Title
CVE-2026-628285.414.6MicrosoftMicrosoft Edge for AndroidCWE-20Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
CVE-2026-131105.314.6wedevsStoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerceCWE-862StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Chec…
CVE-2026-167745.314.6quantumcloudWPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-862WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpc…
CVE-2026-163478.714.5MikroTikRouterOSCWE-307Improper restriction of excessive authentication attempts in MikroTik RouterO…
CVE-2026-624296.514.4XenXenCWE-362vNUMA domain cleanup may race other operations
CVE-2026-660636.514.4goshs-labsgoshsCWE-22goshs has a Path Traversal issue
CVE-2026-153288.114.1IBMWebSphere Application ServerCWE-444IBM WebSphere Application Server and WebSphere Application Server Liberty is …
CVE-2026-624268.813.8XenXenCWE-412sysctl and platform-op locks open to abuse
CVE-2026-149968.213.4IBMAspera Faspex 5CWE-613Multiple vulnerabilities in IBM Aspera Faspex
CVE-2026-165816.913.4igloohomeSmart Lock Mobile ApplicationCWE-540Inclusion of sensitive information in source code in igloohome Smart Lock Mob…
CVE-2026-134637.513.3IBMCloud Pak SystemCWE-798Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulner…
CVE-2026-494475.313.3azukaarCosmos-ServerCWE-287Cosmos-Server's constellation public-devices endpoint accepts arbitrary beare…
CVE-2026-165874.313.0nasirahmedAdvanced Form Integration — Connect Forms to 200+ AppsCWE-862Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (…
CVE-2026-180382.113.0nextlevelbuilderGoClawCWE-200nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute informati…
CVE-2026-150648.712.7IBMWebSphere Application ServerCWE-444IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-31574.312.7IBMSterling B2B IntegratorCWE-615Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File G…
CVE-2026-667536.312.5tiny-httptiny-httpCWE-113tiny-http 0.12.0 HTTP Response Splitting via Header Injection
CVE-2026-175285.312.5n/anice-select2CWE-79Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-sit…
CVE-2026-167974.312.5devitemsllcShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-639ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Cont…
CVE-2026-546908.212.3koxudaxidatamodel-code-generatorCWE-918datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP UR…
CVE-2026-157306.412.3rubengcGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-79GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-71878.812.2Universal Software Inc.UKBSCWE-306Improper Authentication in Universal Sotware's UKBS
CVE-2026-667515.311.9sdelementslets-chatCWE-862Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
CVE-2026-624327.311.8XenXenCWE-362evtchn: Race between FIFO expand and reset
CVE-2026-554033.711.7koxudaxidatamodel-code-generatorCWE-200datamodel-code-generator: Authorization / request headers leaked to cross-ori…
CVE-2026-115985.011.5lrnzShortcodifyCWE-79Shortcodify <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-546918.211.4koxudaxidatamodel-code-generatorCWE-918datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation,…
CVE-2026-121245.311.4wpeverestPDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice DesignerCWE-862PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Di…
CVE-2026-153258.711.2IBMWebSphere Application ServerCWE-444IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-180296.311.1pretix GmbHpretix-girosolutionCWE-841Insufficient validation of payment status in pretix-girosolution
CVE-2026-180282.311.1pretix GmbHpretixCWE-639Missing authorization check in event quick setup view
CVE-2026-424955.510.8XenXenCWE-191buffer overruns in libfsimage iso9660 handling
CVE-2026-624235.510.8XenXenCWE-130buffer overruns in libfsimage iso9660 handling
CVE-2026-624245.510.8XenXenCWE-130buffer overruns in libfsimage iso9660 handling
CVE-2026-624255.510.8XenXenCWE-20buffer overruns in libfsimage iso9660 handling
CVE-2026-68819.410.6EllucianAdvance WebCWE-89Authenticated SQL Injection Enables Unauthorized Access to Sensitive Informat…
CVE-2026-624356.59.6XenXenCWE-362grant-table: version change racing with other operations
CVE-2026-624366.59.6XenXenCWE-362grant-table: version change racing with other operations
CVE-2026-507369.09.5EnterpriseDBpglogicalCWE-89The pglogical queue mechanism, used to convey out-of-band commands such as re…
CVE-2026-507379.09.5EnterpriseDBpglogicalCWE-250When applying replicated changes for a row that is missing one or more column…
CVE-2026-507356.19.5EnterpriseDBpglogicalCWE-125pglogical's apply worker does not sufficiently validate the length of certain…
CVE-2026-553917.59.3koxudaxidatamodel-code-generatorCWE-350datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
CVE-2026-480584.69.3juevnebula-meshCWE-614nebula-mesh: Session and OIDC state cookies lack the Secure attribute
CVE-2026-483747.88.9AdobeAdobe BridgeCWE-22Bridge | Improper Limitation of a Pathname to a Restricted Directory ('Path T…
CVE-2026-483727.88.5AdobeFormat PluginsCWE-787Format Plugins | Heap-based Buffer Overflow (CWE-122)
CVE-2026-113916.38.5TaniumPatchCWE-89Tanium addressed a SQL injection vulnerability in Patch.
CVE-2026-452938.68.3WordPressWordPress-Coding-StandardsCWE-95WordPress Coding Standards (WordPressCS) contains an arbitrary code execution…
CVE-2026-141716.18.2ads-tec Industrial ITDVG-IRF1401CWE-601ads-tec Industrial IT: Post-login open redirect in the web interface
CVE-2026-31584.37.9IBMSterling B2B IntegratorCWE-615Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File G…
CVE-2026-73626.57.6IBMSterling B2B IntegratorCWE-284Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator…
CVE-2026-145156.17.6IBMWebSphere Application ServerCWE-79IBM WebSphere Application Server is affected by cross-site scripting and dese…
CVE-2026-134427.17.1IBMLangflow OSSCWE-520Langflow is affected by NET Misconfiguration: Use of Impersonation due to mul…
CVE-2026-78686.57.2IBMOPENBMCCWE-863This Power System update is being released to address incorrect authorization
CVE-2026-483888.67.0AdobeAdobe Photoshop InstallerCWE-427Photoshop Installer | CWE-427: Uncontrolled Search Path Element
CVE-2026-546567.86.8koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code execution on import via unescap…
CVE-2026-483958.66.7AdobeAdobe BridgeCWE-426Bridge | Untrusted Search Path (CWE-426)
CVE-2026-148212.76.6UnknownQuiz and Survey Master (QSM)CWE-862Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
CVE-2026-483968.65.7AdobeAdobe BridgeCWE-863Bridge | Incorrect Authorization (CWE-863)
CVE-2026-161075.95.5IBMTS4500 CLI toolCWE-295TS4500 CLI tool addresses security vulnerability
CVE-2026-180855.95.3BlackBerryUEMCWE-74Improper Input Validation Leads to Arbitrary File Download and Potential Deni…
CVE-2026-150166.45.3strangerstudiosPaid Memberships Pro – Content Restriction, User Registration, & Paid SubscriptionsCWE-79Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscri…
CVE-2026-483918.25.2AdobeAdobe BridgeCWE-426Bridge | Untrusted Search Path (CWE-426)
CVE-2026-477256.95.1juevnebula-meshCWE-352nebula-mesh: Web UI lacks CSRF tokens on /ui/* mutating endpoints
CVE-2026-443875.14.7ELECOM CO.,LTD.WAB-M1775-PSCWE-79ELECOM wireless LAN routers and access points devices contain a reflected cro…
CVE-2026-582464.34.7SAP_SESAP NetWeaver Application Server for ABAPCWE-497Information Disclosure vulnerability in SAP NetWeaver Application Server for …
CVE-2026-180848.64.6BlackBerryUEMCWE-79Cross-Site Scripting (XSS) in Management Console of BlackBerry UEM
CVE-2026-545457.14.6pionxzhwakaruCWE-22@wakaru/cli arbitrary file write during bundle unpack
CVE-2026-81676.14.6THEWP Digital SolutionsNews Theme V8CWE-79Reflected XSS in theWP's News Theme V8
CVE-2026-658826.14.6joomdle.comJoomdle component for JoomlaCWE-79Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1
CVE-2026-483927.84.5AdobeAdobe BridgeCWE-787Bridge | Out-of-bounds Write (CWE-787)
CVE-2026-483937.84.5AdobeAdobe BridgeCWE-787Bridge | Out-of-bounds Write (CWE-787)
CVE-2026-483947.84.5AdobeAdobe BridgeCWE-787Bridge | Out-of-bounds Write (CWE-787)
CVE-2026-148707.14.4UnknownDatabase for Contact Form 7, WPforms, Elementor formsCWE-79Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS…
CVE-2026-546557.84.3koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code execution on import via `x-pyth…
CVE-2026-483908.24.2AdobeAdobe BridgeCWE-863Bridge | Incorrect Authorization (CWE-863)
CVE-2026-149264.24.2UnknownFluentCart A New Era of eCommerceCWE-284FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR
CVE-2026-546217.84.0koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code injection via unescaped carriag…
CVE-2026-546547.84.0koxudaxidatamodel-code-generatorCWE-94`datamodel-code-generator` vulnerable to code injection via unescaped carriag…
CVE-2026-77754.84.0IBMSterling B2B IntegratorCWE-79Cross-site Scripting Security Vulnerability in IBM Sterling B2B Integrator an…
CVE-2026-148193.54.0UnknownEvent Tickets and RegistrationCWE-79Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move
CVE-2026-568217.43.6nettynettyCWE-299Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
CVE-2026-418746.83.2OpenSolutionQuick.CartCWE-256Hard-coded admin credentials in Quick.Cart
CVE-2026-546057.23.2ruby-oauthoauthCWE-200OAuth: Cross-origin token-request redirects can expose signed request metadata
CVE-2026-151364.33.0wplegalpagesWPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent ModeCWE-352Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Req…
CVE-2026-46486.82.0CasfID Servicios TecnológicosNFC WristbandsCWE-326Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands
CVE-2026-170723.31.9Red HatRed Hat Enterprise Linux 10CWE-125Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matro…
CVE-2026-424946.11.8XenXenCWE-125buffer overruns in libfsimage iso9660 handling
CVE-2026-181077.81.6Red HatRed Hat Enterprise Linux 10CWE-269Criu: criu: container escape via rseq critical section hijack during checkpoi…
CVE-2026-568227.41.6nettynettyCWE-367Netty: TOCTOU in OcspServerCertificateValidator
CVE-2026-477685.51.4juevnebula-meshCWE-598nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, …
CVE-2026-546192.01.3sparklemotionsqlite3-rubyCWE-416sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Differe…
CVE-2026-546202.01.3sparklemotionsqlite3-rubyCWE-416sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
CVE-2026-81647.31.3ArkSigner Software and Hardware Industry and Trade Inc.ArkSigner Desktop ClientCWE-427Search Order Hijacking in ArkSigner's ArkSigner Desktop Client
CVE-2026-624287.81.0XenXenCWE-367grant-table: type confusion in grant-copy
CVE-2026-559773.30.6EShareEShareProCWE-307Bypass of application rate-limiting mechanism
CVE-2026-49324.20.2IBMPowerVM HypervisorCWE-331This Power System update is being released to address Insufficient Entropy

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-28 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.