boxscore/security
Wednesday, July 29, 2026 · all times UTC← 2026-07-28 · archive · 2026-07-30 →

274 CVEs published July 29, 2026: 47 critical, 116 high, 103 medium, 8 low; 1 in KEV; 4 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 249 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published5211796013882563
KEV catalog size1670

203 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux666158420711279802730.27.8.0016+425
microsoft65713601049293028378322.47.8.0039+438
apple167244566711229372.97.1.0027+130
red hat921919957611400.07.1.0027+47
google28377251173513.58.8.0028+25
canonical330210000.07.8.0013+3
android010100161100.08.4.0171-1
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco8204620961365.08.2.1853+5
fortinet1118249028633.36.1.0054+10
palo alto networks1015017514213.34.7.0028+7
vmware7716002100.08.7.0044+7
f51540007120.09.2.04020
ivanti051000335100.010.0.8152-1
checkpoint3431003250.09.2.4696+2
broadcom2400204250.05.1.0877+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache8912122702904010.87.5.0054+73
mozilla67724226401300.09.1.0031+67
gitlab1315021014213.34.9.0029+13
wordpress3311105266.78.6.7310+3
docker030120100.05.7.0015-3
github220110000.06.1.0029+2
kubernetes110001000.02.4.0024+1
drupal01100051100.09.8.88320
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091113212539304574030.37.6.0031+1107
ibm65732326240700.07.5.0026+64
adobe26379204075410.88.4.0040+19
progress232331550900.08.1.0032+23
solarwinds15191511011421.19.1.0044+14
atlassian3303001300.08.0.0026+3
zohocorp331110000.07.1.0048+3
veeam110100400.08.4.0013+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link78006126112.55.5.0073+7
hikvision5603202116.77.2.0024+5
schneider electric331200100.08.7.0020+3
bosch220200000.08.0.0018+2
honeywell110010000.06.9.0031+1
rockwell automation111000000.09.2.0030+1
siemens010100100.08.7.00320
dahua000000200
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb5757326253000.07.1.0025+57
netty194162771000.07.5.0046+5
grafana841214223000.06.5.0033+2
open ises037214210000.06.9.00210
erlang1432114143100.06.9.0033+7
regularlabs.com292961490000.07.5.0022+29
watchguard172811890400.07.3.0026+17
nlnet labs242704176000.05.9.0024+24

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1109
linux666
microsoft657
apple167
red hat102
apache89
ibm72
mozilla67
surrealdb57
regularlabs.com29
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven24
Go3
crates.io2
npm2
NuGet1
Packagist1
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-20316Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171715
CVE-2021-27102Accellion2021-11-171715
CVE-2021-27101Accellion2021-11-171715
CVE-2021-27103Accellion2021-11-171715
CVE-2021-21017Adobe2021-11-171715
CVE-2021-28550Adobe2021-11-171715
CVE-2021-42013Apache2021-11-171715
CVE-2021-41773Apache2021-11-171715
CVE-2021-30858Apple2021-11-171715
CVE-2021-30860Apple2021-11-171715

Transactions

EXPLOIT PUBLISHEDCVE-2021-29022. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-29023. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-29024. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-36271. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-38352 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-34632 (Adobe Photoshop Installer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45700 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50289 (sebhildebrandt systeminformation). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54497 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54498 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56821 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59733 (rclone). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59919 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-60113 (NASA-AMMOS AIT-DSN). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66746 (tomaka rouille). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66748 (owen2345 camaleon-cms). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66754 (tomaka rouille). Public exploit reference added.

DUE DATE PASSEDCVE-2026-56155 (Microsoft Windows 10 Version 1607). CISA remediation deadline was July 28, 2026; still in catalog.

RESCOREDCVE-2024-21537 (lilconfig). CVSS 9.3 → 8.9 (NVD).

RESCOREDCVE-2026-11541 (IBM CICS Transaction Gateway for Multiplatforms). CVSS 7.4 → 9.8 (NVD).

RESCOREDCVE-2026-49181 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 9.8 (NVD).

PATCH SHIPPEDCVE-2025-38352 (Linux). Fixed in Linux 5.4.295.

ENRICHEDCVE-2021-29022. Received CVSS 5.3 and CPE data from NVD.

ENRICHEDCVE-2021-29023. Received CVSS 5.3 and CPE data from NVD.

ENRICHEDCVE-2021-29024. Received CVSS 7.5 and CPE data from NVD.

ENRICHEDCVE-2026-53376 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2026-53377 (Linux). Received CVSS 5.5 and CPE data from NVD.

Yesterday's Results

274 CVEs published. 25 box scores, 249 table rows — nothing truncated.

Cisco Secure Firewall Management Center Software Static Credential Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0079   53.2   YES
AFFECTED
  Product                                        Versions  Fixed
  Cisco Secure Firewall Management Center (FMC)  7.0.0 –   —
TIMELINE
  Oct 8   Reserved by CNA
  Jul 29  Added to CISA KEV, due Aug 1
  Jul 29  Published (CNA: cisco)
CWE-259 · CNA: cisco · 2 references · NVD status: Analyzed · KEV due August 1, 2026
DriveLock Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0160   73.7     —
AFFECTED
  Product    Versions        Fixed
  DriveLock  25.2.2.61370 –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Deferred
DriveLock Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0154   72.8     —
AFFECTED
  Product    Versions        Fixed
  DriveLock  25.2.2.61370 –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Deferred
DriveLock Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0154   72.7     —
AFFECTED
  Product    Versions        Fixed
  DriveLock  25.2.2.61370 –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Deferred
DriveLock Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0127   67.3     —
AFFECTED
  Product    Versions        Fixed
  DriveLock  25.2.2.61370 –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-22 · CNA: zdi · 2 references · NVD status: Deferred
Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0109   62.6     —
AFFECTED
  Product         Versions       Fixed
  Database Proxy  25.03.01.21 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-93 · CNA: zdi · 1 reference · NVD status: Awaiting Analysis
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0100   59.8     —
AFFECTED
  Product   Versions                    Fixed
  OliveTin  >= 3000.2.0, < 3000.17.0 –  —
TIMELINE
  Jul 29  Reserved by CNA
  Jul 29  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 3 references · NVD status: Deferred
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0094   58.0     —
AFFECTED
  Product  Versions  Fixed
  7-Zip    26.01 –   —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-122 · CNA: zdi · 2 references · NVD status: Analyzed
TP-Link Systems Inc. TL-WR940N v6 — Unauthenticated Remote Code Execution in TP-Link TL-WR940N RTSP Conntrack Feature
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0081   53.8     —
AFFECTED
  Product       Versions     Fixed
  TL-WR940N v6  unspecified  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 29  Published (CNA: TPLink)
CWE-121 · CNA: TPLink · 4 references · NVD status: Deferred
Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0080   53.6     —
AFFECTED
  Product                  Versions   Fixed
  Care Everywhere Gateway  14.3.10 –  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 29  Published (CNA: VulnCheck)
CWE-1392 · CNA: VulnCheck · 3 references · NVD status: Deferred
StylemixThemes Cost Calculator Builder PRO — Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   49.8     —
AFFECTED
  Product                      Versions     Fixed
  Cost Calculator Builder PRO  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 29  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · 2 references · NVD status: Deferred
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.6     —
AFFECTED
  Product                      Versions     Fixed
  Apache Airflow FAB provider  unspecified  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-347 · CNA: apache · 3 references · NVD status: Analyzed
Apache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the server
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   L   H    8.3   .0065   48.3     —
AFFECTED
  Product                Versions  Fixed
  Apache Traffic Server  8.0.0 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-502 · CNA: apache · 1 reference · NVD status: Analyzed
Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0065   48.2     —
AFFECTED
  Product        Versions  Fixed
  Apache Kyuubi  1.8.0 –   —
TIMELINE
  Jan 19  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-923 · CNA: apache · 3 references · NVD status: Analyzed
Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0064   47.5     —
AFFECTED
  Product                Versions  Fixed
  Apache Traffic Server  8.0.0 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-476 · CNA: apache · 1 reference · NVD status: Analyzed
Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   L   L   H    8.3   .0064   47.5     —
AFFECTED
  Product                Versions  Fixed
  Apache Traffic Server  8.0.0 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-416 · CNA: apache · 1 reference · NVD status: Analyzed
Apache Traffic Server: HostDB SRV handling leaks memory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0064   47.5     —
AFFECTED
  Product                Versions  Fixed
  Apache Traffic Server  8.0.0 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-401 · CNA: apache · 1 reference · NVD status: Analyzed
Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0064   47.5     —
AFFECTED
  Product                Versions  Fixed
  Apache Traffic Server  8.0.0 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-674 · CNA: apache · 1 reference · NVD status: Analyzed
Apache Traffic Server: txn_box plugin overflows the stack from attacker input
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0064   47.5     —
AFFECTED
  Product                Versions  Fixed
  Apache Traffic Server  8.0.0 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-121 · CNA: apache · 1 reference · NVD status: Analyzed
smub Easy Digital Downloads – eCommerce Payments and Subscriptions made easy — Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0063   47.3     —
AFFECTED
  Product                                                                  Versions     Fixed
  Easy Digital Downloads – eCommerce Payments and Subscriptions made easy  unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 29  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 8 references · NVD status: Deferred
Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0062   46.6     —
AFFECTED
  Product            Versions     Fixed
  Xlight FTP Server  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 29  Published (CNA: VulnCheck)
CWE-121 · CNA: VulnCheck · 2 references · NVD status: Deferred
Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   L   H    8.4   .0060   45.8     —
AFFECTED
  Product                Versions  Fixed
  Apache Traffic Server  8.0.0 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-787 · CNA: apache · 1 reference · NVD status: Analyzed
nico23 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … — Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0059   45.3     —
AFFECTED
  Product                                                                        Versions  Fixed
  Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …  10.8.7 –  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 29  Published (CNA: Wordfence)
CWE-506 · CNA: Wordfence · 5 references · NVD status: Deferred
Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0058   44.9     —
AFFECTED
  Product            Versions     Fixed
  Xlight FTP Server  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 29  Published (CNA: VulnCheck)
CWE-122 · CNA: VulnCheck · 2 references · NVD status: Deferred
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0057   44.3     —
AFFECTED
  Product                    Versions   Fixed
  MaxiCharger AC Elite Home  1.39.51 –  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-191 · CNA: zdi · 1 reference · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-581588.243.9Apache Software FoundationApache Traffic ServerCWE-121Apache Traffic Server: PROXY protocol parsing has port truncation and a stack…
CVE-2026-6588310.043.8aimy-extensions.comAimy Captcha-Less Form Guard plugin for JoomlaCWE-502Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy…
CVE-2026-581799.243.7Apache Software FoundationApache Traffic ServerCWE-121Apache Traffic Server: regex_remap plugin overflows the stack from attacker i…
CVE-2026-581606.343.5Apache Software FoundationApache Traffic ServerCWE-125Apache Traffic Server: Out-of-bounds reads while parsing DNS responses
CVE-2026-142708.843.3ThemeCompleteExtra Checkout Options - addon for Extra Product Options pluginCWE-434Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooComm…
CVE-2026-581778.343.3Apache Software FoundationApache Traffic ServerCWE-787Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts …
CVE-2026-581868.243.2Apache Software FoundationApache Traffic ServerCWE-20Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels d…
CVE-2026-581828.243.0Apache Software FoundationApache Traffic ServerCWE-400Apache Traffic Server: ts_lua plugin has initialization and resource-handling…
CVE-2026-134239.842.7UnknownStreamitCWE-94Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Funct…
CVE-2026-581597.042.1Apache Software FoundationApache Traffic ServerCWE-863Apache Traffic Server: Listener and ACL handling allow access-control bypass
CVE-2026-581838.241.3Apache Software FoundationApache Traffic ServerCWE-20Apache Traffic Server: prefetch plugin can crash on attacker-influenced input
CVE-2026-6742910.040.2flytohubflyto-coreCWE-22Flyto2 Core: Arbitrary file write via image.download (and other file-writing …
CVE-2026-667237.040.2CERT.PLMWDB CoreCWE-862Missing authentication requirement in Remote Instances proxy API in MWDB Core
CVE-2025-106569.840.1holestSpreadsheet Price Changer for WooCommerce and WP E-commerce – LightCWE-863Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37…
CVE-2026-581818.240.1Apache Software FoundationApache Traffic ServerCWE-121Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack …
CVE-2026-119748.639.9Unknownwp-media-folder-addonCWE-22Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download
CVE-2026-581898.239.8Apache Software FoundationApache Traffic ServerCWE-918Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amp…
CVE-2026-50577.539.6ATENUnizonCWE-306ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability
CVE-2026-54908.839.4DriveLockDriveLockCWE-89DriveLock SQL Injection Privilege Escalation Vulnerability
CVE-2026-581518.739.0Apache Software FoundationApache Traffic ServerCWE-400Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash…
CVE-2026-653248.239.0Apache Software FoundationApache Traffic ServerCWE-400Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer…
CVE-2026-581536.338.8Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers t…
CVE-2026-581848.337.9Apache Software FoundationApache Traffic ServerCWE-787Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory
CVE-2026-581876.337.6Apache Software FoundationApache Traffic ServerCWE-787Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of s…
CVE-2026-581576.937.5Apache Software FoundationApache Traffic ServerCWE-200Apache Traffic Server: Improper server-session reuse can expose data across c…
CVE-2026-651006.337.3Apache Software FoundationApache Traffic ServerCWE-696Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a …
CVE-2026-581858.237.1Apache Software FoundationApache Traffic ServerCWE-416Apache Traffic Server: Use-after-free in the intercept plugin
CVE-2026-674327.536.3modelcontextprotocolruby-sdkCWE-770MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allo…
CVE-2026-506228.836.1Apache Software FoundationApache AtlasCWE-862Apache Atlas: Missing Authorization on Admin Endpoints
CVE-2026-546809.935.5kube-logginglogging-operatorCWE-74Logging operator has Fluentd configuration injection that allows remote code …
CVE-2026-50567.835.5GStreamerGStreamerCWE-121GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerabi…
CVE-2026-675959.235.2webreinventvaahcmsCWE-506VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blad…
CVE-2026-466785.934.9pydanticpydantic-aiCWE-918Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incom…
CVE-2026-601129.334.0NASA-AMMOSAIT-GUICWE-306AIT-GUI < 2.5.1 Missing Authentication via Sessions.create()
CVE-2026-601139.334.0NASA-AMMOSAIT-DSNCWE-306AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes
CVE-2026-159757.532.6GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-672017.732.2vlangvCWE-436V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
CVE-2026-581559.231.8Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: Header-name length truncation enables header aliasing …
CVE-2026-181919.331.5VacronVIN-DS783E-E6CWE-912Vacron|IP Camera - Hidden Functionality
CVE-2026-672158.731.1DaveGamblecJSONCWE-674cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
CVE-2026-181927.131.2VacronVIN-DS783E-E6CWE-23Vacron|IP Camera - Arbitrary File Read
CVE-2026-581549.230.4Apache Software FoundationApache Traffic ServerCWE-787Apache Traffic Server: Memory-safety errors in MIME and header parsing
CVE-2026-06679.329.9Schneider ElectricSCADAPack 47xCWE-754CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability t…
CVE-2026-121448.829.9saadiqbalWholesale for WooCommerceCWE-269Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escala…
CVE-2026-658869.229.5balbooa.comGridbox extension for JoomlaCWE-22Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridb…
CVE-2026-145299.829.1IBMWebSphere Application ServerCWE-306IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-153444.928.6opajaapWP Photo Album PlusCWE-89WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Inject…
CVE-2026-674377.528.5OliveTinOliveTinCWE-400OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded M…
CVE-2026-5473510.028.2prebidprebid-serverCWE-918prebid-server's request forgery vulnerability allows for possible host enviro…
CVE-2026-672168.228.1DaveGamblecJSONCWE-407cJSON cJSON_Compare Exponential Complexity Denial of Service
CVE-2026-507827.528.0n/an/aCWE-611Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in…
CVE-2026-220686.927.8Apache Software FoundationApache Traffic ServerCWE-777Apache Traffic Server: Regex mappings match with malicious domain names
CVE-2026-133465.627.8Python Packaging AuthoritypipCWE-36pip absolute path traversal during download from malicious package indexes
CVE-2026-133076.827.4AutelMaxiCharger AC Elite HomeCWE-122Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code…
CVE-2026-180228.827.3n/apgvectorCWE-190pgvector buffer overflow via integer wraparound in IVFFlat index build on 32-…
CVE-2026-546938.227.3zitadelzitadelCWE-863ZITADEL Users Can Self-Verify Email/Phone via API
CVE-2026-674278.626.9flytohubflyto-coreCWE-522Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get be…
CVE-2026-578347.026.8Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: Malformed chunked message body allows request smuggling
CVE-2026-674288.526.6flytohubflyto-coreCWE-918Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs withou…
CVE-2026-332677.726.5Apache Software FoundationApache Traffic ServerCWE-20Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata
CVE-2026-598996.926.4nettynettyCWE-770Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 …
CVE-2026-62675.326.2GitLabGitLabCWE-201Insertion of Sensitive Information Into Sent Data in GitLab
CVE-2026-581628.426.1Apache Software FoundationApache Traffic ServerCWE-295Apache Traffic Server: Certifier plugin trusts client SNI when generating cer…
CVE-2026-449436.925.9open-iscsiopen-iscsiCWE-22remote limited file-write as root via discovery in open-iscsi
CVE-2026-632279.925.7An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.Koollab LMSCWE-434Unrestricted SCORM file upload vulnerability
CVE-2026-240336.925.6Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: Request smuggling via chunked extension quoted-string …
CVE-2026-137236.525.6Develarapp-builderCWE-22Develar's electron-builder allows arbitrary file overwrite
CVE-2026-143414.925.5GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-136979.125.4undiciundiciCWE-200undici vulnerable to cross-user information disclosure and parse-time crash v…
CVE-2026-339308.225.1Apache Software FoundationApache Traffic ServerCWE-121Apache Traffic Server: Buffer overflow via Host field that has a long string …
CVE-2026-581526.925.1Apache Software FoundationApache Traffic ServerCWE-190Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrup…
CVE-2026-540788.724.7veraPDFveraPDF-validationCWE-611veraPDF Validation XXE via Rich Text
CVE-2026-540798.724.7veraPDFveraPDF-validationCWE-611veraPDF Validation XXE via XFA
CVE-2026-674258.624.7flytohubflyto-coreCWE-201Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
CVE-2026-672138.224.7nanoid_projectnanoidCWE-835nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customR…
CVE-2026-672148.224.7nanoid_projectnanoidCWE-835nanoid before 5.1.16 Infinite Loop via Negative Size in non-secure module
CVE-2026-581507.824.3Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejecte…
CVE-2026-124368.423.6GitLabGitLabCWE-915Improperly Controlled Modification of Dynamically-Determined Object Attribute…
CVE-2026-144889.123.3Meta BoxMeta Box AIOCWE-862Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Po…
CVE-2026-671947.123.1svarshavchikCourier IMAPCWE-674Courier IMAP < 6.0.1 Mail Server < 2.0.2 Stack Overflow DoS via Nested SEARCH…
CVE-2026-166557.223.0wpmanageninjaFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-79Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name …
CVE-2026-540806.922.7veraPDFveraPDF-parserCWE-1325veraPDF Parser DoS via PostScript CMap Streams
CVE-2026-540816.922.7veraPDFveraPDF-parserCWE-1325veraPDF Parser DoS via PostScript Type 1 Font Programs
CVE-2026-119734.922.7wp-labWP-Lister Lite for eBayCWE-89WP-Lister Lite for eBay <= 3.8.8 - Authenticated (Shop Manager+) SQL Injectio…
CVE-2026-83389.222.5Black DuckCoverity ConnectCWE-288Authentication and Authorization Bypass in Coverity Connect
CVE-2026-506424.822.5so-fancydiff-so-fancyCWE-116Terminal Escape Injection in diff‑so‑fancy
CVE-2026-1632610.022.5HashiCorpToolingCWE-488consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-H…
CVE-2026-632299.122.1Three LearningKoollab LMSCWE-89Pre-authentication blind SQL injection vulnerability
CVE-2026-632309.122.1Three LearningKoollab LMSCWE-89Pre-authentication error-based SQL injection vulnerability
CVE-2026-419207.022.2Apache Software FoundationApache Traffic ServerCWE-284Apache Traffic Server: SNI to Host header matching policy is not properly enf…
CVE-2026-167516.522.0EnteMuseum ServerEnte Museum Server Authorization Bypass Vulnerability
CVE-2026-632329.922.0Three LearningKoollab LMSCWE-89SQL injection and unsafe deserialisation vulnerability
CVE-2026-632339.922.0Three LearningKoollab LMSCWE-89SQL injection and unsafe deserialisation vulnerability
CVE-2026-632349.922.0Three LearningKoollab LMSCWE-89SQL injection and unsafe deserialisation vulnerability
CVE-2026-143514.322.0GitLabGitLabCWE-1230Exposure of Sensitive Information Through Metadata in GitLab
CVE-2026-182076.521.8Red HatRed Hat Build of KeycloakCWE-285Keycloak-services: keycloak-services: client policy source-group condition by…
CVE-2026-674269.321.6flytohubflyto-coreCWE-306Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and i…
CVE-2026-674305.321.6modelcontextprotocolruby-sdkCWE-401MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows m…
CVE-2026-91779.421.3AxwaySecureTransportCWE-1336Server-Side Template Injection in SecureTransport's Apache Velocity mail temp…
CVE-2026-658859.421.1balbooa.comGridbox extension for JoomlaCWE-434Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridb…
CVE-2026-546668.321.1acacodeswagger-typescript-apiCWE-74swagger-typescript-api vulnerable to code injection via unescaped OpenAPI pat…
CVE-2026-674356.021.1Linuxfabrikmonitoring-pluginsCWE-200linuxfabrik-lib: fetch() forwards credential headers across a cross-origin re…
CVE-2026-182015.521.0Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: generic identity-provider creation can …
CVE-2026-46724.321.0GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-6588410.020.9balbooa.comGridbox extension for JoomlaCWE-284Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2
CVE-2026-6588710.020.9balbooa.comGridbox extension for JoomlaCWE-284Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in …
CVE-2026-6588810.020.9balbooa.comGridbox extension for JoomlaCWE-284Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < …
CVE-2026-658899.220.9balbooa.comGridbox extension for JoomlaCWE-284Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion…
CVE-2026-60894.920.2blendmediaWP CTA – Call Now Button, Sticky Button & Call to Action BuilderCWE-918WP CTA <= 2.1.2 - Authenticated (Administrator+) Server-Side Request Forgery
CVE-2025-699439.820.0n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in ge…
CVE-2026-658909.220.0balbooa.comGridbox extension for JoomlaCWE-89Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2…
CVE-2026-674318.320.1modelcontextprotocolruby-sdkCWE-284MCP Ruby SDK: Ruby SSE Session Poisoning
CVE-2026-182557.219.6Red HatRed Hat Quay 3CWE-863Quay: quay: global read-only superuser can view robot account tokens
CVE-2026-546618.319.2acacodeswagger-typescript-apiCWE-74swagger-typescript-api vulnerable to code injection via unescaped `servers[0]…
CVE-2026-546628.319.2acacodeswagger-typescript-apiCWE-74swagger-typescript-api vulnerable to code injection via unescaped `servers[0]…
CVE-2026-546648.319.2acacodeswagger-typescript-apiCWE-74swagger-typescript-api vulnerable to code injection via unescaped enum string…
CVE-2026-181976.419.0Link LibraryCWE-79Improper neutralization of input during web page generation ('cross-site scri…
CVE-2026-667245.319.0CERT.PLMWDB CoreCWE-862Permission Bypass Via Undocumented HTTP Methods In MWDB Core
CVE-2026-671936.918.4XlightXlight FTP ServerCWE-203Xlight FTP Server < 3.9.5 Information Disclosure via USER Command
CVE-2026-599018.718.2nettynettyCWE-835Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Th…
CVE-2025-653409.817.9n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /…
CVE-2025-674039.817.9n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-674049.817.9n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-699429.817.9n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /…
CVE-2026-63365.317.2GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-136907.417.1UnknownUsersWPCWE-287UsersWP < 1.2.67 - Two-Factor Authentication Bypass
CVE-2026-165535.417.1GitLabGitLabCWE-522Insufficiently Protected Credentials in GitLab
CVE-2026-559958.716.8open-iscsiopen-iscsiCWE-415Double-free in the iSNS attribute decoder in open-iscsi
CVE-2026-632318.116.9Three LearningKoollab LMSCWE-89Post-authentication SQL injection vulnerability
CVE-2026-674394.316.9OliveTinOliveTinCWE-863OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Ac…
CVE-2026-672176.916.6DaveGamblecJSONCWE-696cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
CVE-2026-505585.916.6brightiopenelopeCWE-22Penelope unsafe tar extraction allows arbitrary local file write via crafted …
CVE-2026-150774.316.7GitLabGitLabCWE-74Improper Neutralization of Input Used for LLM Prompting in GitLab
CVE-2026-674368.316.5Linuxfabrikmonitoring-pluginsCWE-20Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidate…
CVE-2026-598986.316.5nettynettyCWE-444Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
CVE-2026-134257.216.4code4lifeDatabase for CF7CWE-79Database for CF7 <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting via A…
CVE-2026-151445.316.2@fastify/rate-limit@fastify/rate-limitCWE-307@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation
CVE-2026-546607.415.8acacodeswagger-typescript-apiCWE-200swagger-typescript-api vulnerable to authorization-token exfiltration via spe…
CVE-2026-182665.415.7LangGeniusDifyCWE-601Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability
CVE-2026-165977.215.5duracelltomiGTM4WP – A Google Tag Manager (GTM) plugin for WordPressCWE-79GTM4WP <= 1.22.3 - Unauthenticated Stored Cross-Site Scripting via WooCommerc…
CVE-2026-87916.415.5ameliabookingBooking System TrafftCWE-79Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Si…
CVE-2026-333855.115.4OpenSolutionQuick.CMSCWE-89Blind SQL Injection in Quick.CMS
CVE-2026-143008.115.2UnknownminiOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)CWE-287miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
CVE-2026-599206.515.2nettynettyCWE-93Netty: STOMP CONNECT Frame Header Injection
CVE-2026-30934.715.1GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-645578.814.8LinuxLinuxBluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
CVE-2026-674248.514.9flytohubflyto-coreCWE-918Flyto2 Core: Guarded HTTP modules follow redirects into internal space withou…
CVE-2026-136056.814.7UnknownPhotoSwipeCWE-79Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute
CVE-2026-46045.314.6klubraumKlubraum Membership RequestCWE-862Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticat…
CVE-2026-127038.014.6TeamViewerRemoteCWE-288Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS
CVE-2026-163288.614.3HashiCorpToolingCWE-918consul-mcp-server vulnerable to server side request forgery leading to token …
CVE-2025-609317.514.3n/an/aCWE-639An Insecure Direct Object Reference (IDOR) in the Employee Compensation View …
CVE-2026-659437.514.3rolandd.comRO CSVI extension for JoomlaCWE-284Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI <…
CVE-2026-599006.914.3nettynettyCWE-444Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Trans…
CVE-2026-171664.314.3magepeopleteamEvent Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event CalendarCWE-862Event Booking Manager for WooCommerce <= 5.3.7 - Missing Authorization to Aut…
CVE-2026-146437.514.1undiciundiciCWE-436undici vulnerable to cross-user information disclosure via whitespace around …
CVE-2026-540826.514.1veraPDFveraPDF-validationCWE-611veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When …
CVE-2026-133096.813.7AutelMaxiCharger AC Elite HomeCWE-121Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Cod…
CVE-2025-145623.113.3GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-581566.313.0Apache Software FoundationApache Traffic ServerCWE-863Apache Traffic Server: URL and port parsing errors allow access-control bypass
CVE-2026-158314.312.9GitLabGitLabCWE-1270Generation of Incorrect Security Tokens in GitLab
CVE-2026-50606.512.8stylemixMasterStudy LMS WordPress Plugin – for Online Courses and EducationCWE-639MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14…
CVE-2026-128957.112.3FrappeERPNextCWE-89SQL Injection in Frappe's ERPNext
CVE-2026-632386.512.3Three LearningKoollab LMSCWE-287Authentication bypass vulnerability
CVE-2026-129386.411.8contridNewslettersCWE-79Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-129396.411.8contridNewslettersCWE-79Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-547056.311.3arnogmathliveCWE-116mathlive's Lack of Escaping of HTML allows for XSS
CVE-2026-113515.311.0UnknownShinyStat AnalyticsCWE-200ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Informat…
CVE-2026-664895.310.8balbooa.comGridbox extension for JoomlaCWE-200Joomla Extension - balbooa.com - Various unauthenticated file system disclosu…
CVE-2026-664885.310.7balbooa.comGridbox extension for JoomlaCWE-285Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVE-2026-83398.710.6Black DuckCoverity ConnectCWE-89SQL Injection in Coverity Connect SOAP API
CVE-2025-674067.310.5n/an/aCWE-89https://www.sourcecodester.com Advocate office management system 1.0 is affec…
CVE-2026-182369.310.3GoogleGoogle-ADKCWE-863Google-ADK Continuation Forgery
CVE-2026-129278.410.3Schneider ElectricIGSS Definition (Def.exe)CWE-787CWE-787 Out-of-bounds write vulnerability exists that could cause loss of dat…
CVE-2026-131135.310.2GitLabGitLabCWE-367Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
CVE-2026-56264.310.1bpluginsSurvey Form Block – collect answers and insights from your audienceCWE-862Survey Form Block <= 1.0.1 - Missing Authorization to Authenticated (Subscrib…
CVE-2026-631186.99.9modelcontextprotocolruby-sdkCWE-346MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) pro…
CVE-2026-542496.89.8pydanticpydantic-aiCWE-918VercelAIAdapter trusts client-controlled `providerMetadata` to construct `Upl…
CVE-2026-659756.59.8pydanticpydantic-aiCWE-863Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute …
CVE-2026-646855.39.8ImageMagickImageMagickCWE-125ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file c…
CVE-2026-632353.79.6Three LearningKoollab LMSCWE-284Improper access control vulnerability
CVE-2026-658916.59.6joomlacontenteditor.netJoomla Content Editor (JCE) extension for JoomlaCWE-20Joomla Extension - joomlacontenteditor.net - Creation of hidden files and uni…
CVE-2026-74366.49.3wpcleverWPC Badge Management for WooCommerceCWE-79WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) …
CVE-2026-157356.49.3itpathsolutionsContact Form to Any APICWE-79Contact Form to Any API <= 3.0.6 - Authenticated (Contributor+) Stored Cross-…
CVE-2026-171616.49.3wpxpoWowStore – Store Builder & Product Blocks for WooCommerceCWE-79WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-171626.49.3wpxpoWowStore – Store Builder & Product Blocks for WooCommerceCWE-79WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-181745.39.3@fastify/forwarded@fastify/forwardedCWE-20@fastify/forwarded vulnerable to improper input validation via unstripped tab…
CVE-2026-164637.89.2AutodeskAutoCADCWE-122DXF File Parsing Heap-Based Overflow in Autodesk AutoCAD
CVE-2026-182207.88.5Red HatRed Hat Enterprise Linux 10CWE-787Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation pro…
CVE-2026-133064.38.1AutelMaxiCharger AC Elite HomeCWE-306Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability
CVE-2026-136925.38.0UnknownPayU CommercePro PluginCWE-862PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering
CVE-2026-164657.18.0AutodeskAutoCADCWE-125DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
CVE-2026-546636.18.0acacodeswagger-typescript-apiCWE-20swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVE-2026-175505.57.7AutodeskAutoCADCWE-125DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
CVE-2025-699497.37.4n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in c…
CVE-2026-167286.57.4undiciundiciCWE-444undici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-632404.37.4Three LearningKoollab LMSCWE-200Information disclosure vulnerability
CVE-2026-352267.16.9CODESYSCODESYS PROFINETCWE-787Out-of-bounds Write in CODESYS PROFINET Controller
CVE-2025-674057.36.6n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-674077.36.6n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-674087.36.6n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-699447.36.6n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in t…
CVE-2025-699457.36.6n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /…
CVE-2026-167296.56.4undiciundiciCWE-74undici vulnerable to cookie attribute injection via unsanitized domain and un…
CVE-2026-632363.76.4Three LearningKoollab LMSCWE-284Improper access control vulnerability
CVE-2026-653256.36.2Apache Software FoundationApache Traffic ServerCWE-295Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without …
CVE-2026-506417.15.7StreamsoftBusiness IntelligenceCWE-256Plaintext password storage in Streamsoft Business Intelligence
CVE-2025-653376.15.1n/an/aCWE-79Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (…
CVE-2026-664906.15.1balbooa.comGridbox extension for JoomlaCWE-79Joomla Extension - balbooa.com - Stored cross-site scripting via a comment av…
CVE-2026-563896.85.1GNUBisonCWE-78Arbitrary Command Execution in GNU Bison
CVE-2026-151575.45.1undiciundiciCWE-93undici vulnerable to CRLF Injection via blob-like body 'type' property
CVE-2026-664006.34.9getgravgravCWE-613Grav Login Plugin before 3.8.13 Insufficient Session Expiration
CVE-2026-632424.34.9Three LearningKoollab LMSCWE-639Business logic vulnerability
CVE-2026-132687.84.8G DATATotal SecurityCWE-59G DATA Total Security Backup Service Link Following Local Privilege Escalatio…
CVE-2026-659466.14.6rolandd.comRO CSVI extension for JoomlaCWE-79Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSV…
CVE-2026-142245.44.4UnknownEasy AppointmentsCWE-639Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modific…
CVE-2026-545748.24.3termuxproot-distroCWE-61`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via M…
CVE-2026-152287.13.9Kong/kubernetes-ingress-controllerCWE-400Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via…
CVE-2026-165437.13.9Kong/kong-operatorCWE-400Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-cert…
CVE-2026-632413.13.9Three LearningKoollab LMSCWE-639Insecure direct object reference vulnerability
CVE-2026-563904.63.3GNUBisonCWE-73Arbitrary Output Location Change in GNU Bison
CVE-2026-659448.83.1rolandd.comRO CSVI extension for JoomlaCWE-352Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CS…
CVE-2026-592477.63.0gleam-langgleamCWE-345Insufficient verification of Hex package metadata in Gleam
CVE-2026-631196.23.0modelcontextprotocolruby-sdkCWE-400MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhau…
CVE-2026-97204.32.9facturadorvirtualFacturación Electrónica Costa RicaCWE-352Facturación Electrónica Costa Rica <= 2.0.2 - Cross-Site Request Forgery to P…
CVE-2026-632282.62.9Three LearningKoollab LMSCWE-434Unrestricted image upload vulnerability
CVE-2026-659477.32.7balbooa.comGridbox extension for JoomlaCWE-352Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface …
CVE-2026-623434.72.5ImageMagickImageMagickCWE-190ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid k…
CVE-2026-632395.42.3Three LearningKoollab LMSCWE-798Hard-coded AWS IAM credentials vulnerability
CVE-2026-547278.22.3termuxproot-distroCWE-668proot-distro has a Container Isolation Bypass via Crafted Restore Archive
CVE-2026-133056.42.3AutelMaxiCharger AC Elite HomeCWE-347Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryp…
CVE-2026-645567.82.2LinuxLinuxperf/core: Detach event groups during remove_on_exec
CVE-2026-645587.82.1LinuxLinuxs390/pkey: Check length in pkey_pckmo handler implementation
CVE-2026-645597.82.1LinuxLinuxs390/pkey: Check length in PKEY_VERIFYPROTK ioctl
CVE-2026-645607.82.2LinuxLinuxposix-cpu-timers: Prevent UAF caused by non-leader exec() race
CVE-2026-143548.71.9Schneider ElectricEcoStruxure™ Cybersecurity Admin ExpertCWE-522CWE-522 Insufficiently Protected Credentials vulnerability exists that could …
CVE-2026-632374.81.9Three LearningKoollab LMSCWE-347TOTP two-factor authentication bypass vulnerability
CVE-2026-402727.01.6BlackBerry LtdQNX Software Development PlatformCWE-1284Vulnerability in the QNX libtraceparser Impacts QNX Software Development Plat…
CVE-2026-599195.51.6nettynettyCWE-93Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
CVE-2026-629952.31.3authlibjoserfcCWE-345joserfc accepts JWT with padding, leading to JWT malleability
CVE-2026-527912.01.1containersfuse-overlayfsCWE-266fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC)
CVE-2026-182575.61.0SysterelS2OPCCWE-295Improper Certificate Validation in S2OPC
CVE-2026-106843.01.0zephyrprojectzephyrCWE-125Out-of-bounds read in coredump shell when printing stored-dump target code
CVE-2026-142347.11.0UnknownWOLFCWE-79WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF
CVE-2026-24828.80.9IBMWebSphere Application Server - LibertyCWE-352IBM WebSphere Application Server Liberty is affected by a cross-site request …
CVE-2026-449448.50.6open-iscsiopen-iscsiCWE-863iscsiuio control-socket authentication bypass in open-iscsi
CVE-2026-61027.80.4MSIMSI CenterCWE-346MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vul…
CVE-2026-84977.40.3DevolutionsPassword ManagerCWE-295Improper certificate validation in the Devolutions Server connection handling…
CVE-2026-674335.80.2Linuxfabrikmonitoring-pluginsCWE-59Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database …

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-29 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.