boxscore/security
Thursday, July 30, 2026 · all times UTC← 2026-07-29 · archive · 2026-07-31 →

662 CVEs published July 30, 2026: 110 critical, 199 high, 329 medium, 23 low; 0 in KEV; 6 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 637 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published5873862213892563
KEV catalog size1670

256 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux667158520711279802730.27.8.0016+426
microsoft65813611059293028378322.47.8.0039+439
google39840764101224157351.26.5.0022+395
apple167244566711229372.97.1.0027+130
red hat10720691018511400.07.1.0027+52
canonical330210000.07.8.0013+3
android010100161100.08.4.0171-1
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco8204620961365.08.2.1853+5
fortinet1118249028633.36.1.0054+10
palo alto networks1015017514213.34.7.0028+7
vmware121247012100.08.7.0044+12
f51540007120.09.2.04020
ivanti051000335100.010.0.8152-1
checkpoint3431003250.09.2.4696+2
broadcom2400204250.05.1.0877+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache10213424733704010.77.5.0051+86
mozilla67724226401300.09.1.0031+67
gitlab1315021014213.34.9.0029+13
wordpress3311105266.78.6.7310+3
docker030120100.05.7.0015-3
github220110000.06.1.0029+2
kubernetes110001000.02.4.0024+1
drupal01100051100.09.8.88320
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091113212539304574030.37.6.0031+1107
ibm1001083143340700.07.5.0026+92
adobe283910214075410.38.5.0040+21
progress232331550900.08.1.0032+23
solarwinds16201611011420.09.1.0050+15
atlassian3303001300.08.0.0026+3
zohocorp331110000.07.1.0048+3
veeam220110400.06.8.0016+2
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link78006126112.55.5.0073+7
hikvision5603202116.77.2.0024+5
bosch330300000.08.1.0028+3
schneider electric331200100.08.7.0020+3
honeywell110010000.06.9.0031+1
mitsubishi electric110100000.07.1.0013+1
rockwell automation111000000.09.2.0030+1
siemens010100100.08.7.00320
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb5757326253000.07.1.0025+57
netty194162771000.07.5.0046+5
grafana841214223000.06.5.0033+2
open ises037214210000.06.9.00210
erlang1432114143100.06.9.0033+7
regularlabs.com292961490000.07.5.0022+29
watchguard172811890400.07.3.0026+17
nlnet labs242704176000.05.9.0024+24

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1109
linux667
microsoft658
google398
apple167
red hat107
apache102
ibm100
mozilla67
surrealdb57
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven27
Go3
crates.io2
npm2
NuGet1
Packagist1
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-20316Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171716
CVE-2021-27102Accellion2021-11-171716
CVE-2021-27101Accellion2021-11-171716
CVE-2021-27103Accellion2021-11-171716
CVE-2021-21017Adobe2021-11-171716
CVE-2021-28550Adobe2021-11-171716
CVE-2021-42013Apache2021-11-171716
CVE-2021-41773Apache2021-11-171716
CVE-2021-30858Apple2021-11-171716
CVE-2021-30860Apple2021-11-171716

Transactions

EXPLOIT PUBLISHEDCVE-2025-37899 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-38002 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-38089 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-12436 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14234 (Unknown WOLF). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14300 (Unknown miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-41939 (Care Everywhere LLC Care Everywhere Gateway). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45309 (ronf asyncssh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47143 (capstone-engine capstone). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47671 (nhost cli). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54522 (msgpack-ruby). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56819 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56820 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-6267 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66729 (boazsegev facil.io). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66730 (boazsegev facil.io). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66731 (boazsegev facil.io). Public exploit reference added.

DUE DATE PASSEDCVE-2023-4346 (KNX Association KNX Protocol Connection Authorization Option 1). CISA remediation deadline was July 29, 2026; still in catalog.

RESCOREDCVE-2023-4244 (Linux Kernel). CVSS 7.8 → 7 (NVD).

RESCOREDCVE-2025-21629 (Linux). CVSS 8.2 → 5.5 (NVD).

RESCOREDCVE-2025-21637 (Linux). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2025-21638 (Linux). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2025-21640 (Linux). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2025-21646 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2025-21647 (Linux). CVSS 7.3 → 7.1 (NVD).

RESCOREDCVE-2025-21650 (Linux). CVSS 7.1 → 7.8 (NVD).

RESCOREDCVE-2025-21655 (Linux). CVSS 7.8 → 4.7 (NVD).

RESCOREDCVE-2025-21659 (Linux). CVSS 8.1 → 5.5 (NVD).

RESCOREDCVE-2025-21661 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21663 (Linux). CVSS 10 → 5.5 (NVD).

RESCOREDCVE-2025-21664 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21669 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21673 (Linux). CVSS 9.8 → 5.5 (NVD).

RESCOREDCVE-2025-21676 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2025-21677 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21678 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21682 (Linux). CVSS 7.3 → 5.5 (NVD).

RESCOREDCVE-2025-21697 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21699 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21701 (Linux). CVSS 7.8 → 4.7 (NVD).

RESCOREDCVE-2025-21707 (Linux). CVSS 9.8 → 5.5 (NVD).

RESCOREDCVE-2025-21709 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21710 (Linux). CVSS 8.2 → 5.5 (NVD).

RESCOREDCVE-2025-21712 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21717 (Linux). CVSS 7.8 → 7.1 (NVD).

RESCOREDCVE-2025-21718 (Linux). CVSS 7.8 → 7 (NVD).

RESCOREDCVE-2025-21720 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2025-21725 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2025-21730 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21735 (Linux). CVSS 8.8 → 7.8 (NVD).

RESCOREDCVE-2025-21738 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21748 (Linux). CVSS 9.8 → 5.5 (NVD).

RESCOREDCVE-2025-21758 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21765 (Linux). CVSS 8.1 → 5.5 (NVD).

RESCOREDCVE-2025-21766 (Linux). CVSS 8.1 → 5.5 (NVD).

RESCOREDCVE-2025-21778 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21788 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2025-21789 (Linux). CVSS 7.3 → 7.1 (NVD).

RESCOREDCVE-2025-21792 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21795 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2025-21801 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21804 (Linux). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2025-21805 (Linux). CVSS 9.8 → 5.5 (NVD).

RESCOREDCVE-2025-21808 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21809 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2025-21810 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21823 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2025-21825 (Linux). CVSS 7.8 → 4.7 (NVD).

ENRICHEDCVE-2021-20322 (kernel). Received CVSS 7.4 and CPE data from NVD.

ENRICHEDCVE-2026-53167 (Linux). Received CVSS 5.5 and CPE data from NVD.

+ 527 more transactions — continued on page 2. Every change is listed; nothing truncated.

Yesterday's Results

662 CVEs published. 25 box scores and 375 table rows below; the remaining 262 continue on page 2 — every CVE is listed, nothing truncated.

somta Juggle — Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0423   90.2     —
AFFECTED
  Product  Versions     Fixed
  Juggle   unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 30  Published (CNA: VulnCheck)
CWE-306, CWE-1188 · CNA: VulnCheck · 2 references · NVD status: Deferred
n/a n/a — TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0267   84.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 30  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Received
rails rails — Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0177   76.2     —
AFFECTED
  Product  Versions     Fixed
  rails    < 7.2.3.2 –  —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 30  Published (CNA: GitHub_M)
CWE-1188 · CNA: GitHub_M · 13 references · NVD status: Received
o6 Automation open62541 Integer Underflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   N   N   H    8.2   .0153   72.6     —
AFFECTED
  Product    Versions  Fixed
  open62541  1.3.0 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 30  Published (CNA: icscert)
CWE-191 · CNA: icscert · 7 references · NVD status: Received
Phoenix Contact CHARX SEC-3150 — OS Command Injection in OCPP Agent via charge_box_id
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   H    8.8   .0137   69.5     —
AFFECTED
  Product         Versions  Fixed
  CHARX SEC-3150  1.0.0 –   —
  CHARX SEC-3100  1.0.0 –   —
  CHARX SEC-3050  1.0.0 –   —
  CHARX SEC-3000  1.0.0 –   —
TIMELINE
  May 5   Reserved by CNA
  Jul 30  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · 1 reference · NVD status: Deferred
VMware Cloud Foundation — vCenter directory-traversal vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0114   63.9     —
AFFECTED
  Product                     Versions   Fixed
  Cloud Foundation            9.1.x.x –  —
  vSphere Foundation          9.1.x.x –  —
  vCenter                     9.1.x.x –  —
  Telco Cloud Infrastructure  3.0 –      —
  Telco Cloud Platform        5.1.x –    —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 30  Published (CNA: vmware)
CWE-22 · CNA: vmware · 4 references · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Samba: dns signing dos via tkey name cache exhaustion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0110   62.9     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat Enterprise Linux 10             unspecified  —
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 7              unspecified  —
  Red Hat Enterprise Linux 8              unspecified  —
  Red Hat Enterprise Linux 9              unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 30  Published (CNA: redhat)
CWE-410 · CNA: redhat · 4 references · NVD status: Awaiting Analysis
IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0102   60.4     —
AFFECTED
  Product                 Versions    Fixed
  App Connect Enterprise  13.0.1.0 –  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 30  Published (CNA: ibm)
CWE-78 · CNA: ibm · 1 reference · NVD status: Analyzed
SGLang SGLang — CVE-2026-15969
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0098   59.3     —
AFFECTED
  Product  Versions     Fixed
  SGLang   unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Jul 30  Published (CNA: certcc)
CWE-502 · CNA: certcc · 2 references · NVD status: Analyzed
IBM HMC V10.3.1050.0 — This Power Hardware Management Console update is being released to address
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0092   57.3     —
AFFECTED
  Product           Versions       Fixed
  HMC V10.3.1050.0  10.3.1050.0 –  —
  HMC V11.1.1110.0  11.1.1110.0 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 30  Published (CNA: ibm)
CWE-78 · CNA: ibm · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0084   54.8     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat Enterprise Linux 10             unspecified  —
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 7              unspecified  —
  Red Hat Enterprise Linux 8              unspecified  —
  Red Hat Enterprise Linux 9              unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 30  Published (CNA: redhat)
CWE-90 · CNA: redhat · 4 references · NVD status: Awaiting Analysis
Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0084   54.8     —
AFFECTED
  Product          Versions  Fixed
  Apache Zeppelin  0.11.1 –  —
TIMELINE
  May 7   Reserved by CNA
  Jul 30  Published (CNA: apache)
CWE-90 · CNA: apache · 3 references · NVD status: Analyzed
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0075   51.9     —
AFFECTED
  Product        Versions  Fixed
  Apache Kyuubi  1.7.0 –   —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 30  Published (CNA: apache)
CWE-22, CWE-73 · CNA: apache · 2 references · NVD status: Analyzed
VMware Cloud Foundation — vCenter authentication-bypass vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0074   51.7     —
AFFECTED
  Product                     Versions   Fixed
  Cloud Foundation            9.1.x.x –  —
  vSphere Foundation          9.1.x.x –  —
  vCenter                     9.1.x.x –  —
  Telco Cloud Infrastructure  3.0 –      —
  Telco Cloud Platform        5.1.x –    —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 30  Published (CNA: vmware)
CWE-303 · CNA: vmware · 1 reference · NVD status: Awaiting Analysis
IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.4     —
AFFECTED
  Product                 Versions    Fixed
  App Connect Enterprise  13.0.1.0 –  —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 30  Published (CNA: ibm)
CWE-22 · CNA: ibm · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0065   48.3     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat Enterprise Linux 10             unspecified  0:7.0.3-5.el10_2
  Red Hat Enterprise Linux 8              unspecified  0:5.3.7-22.el8_10.5
  Red Hat Enterprise Linux 9              unspecified  0:6.3.7-8.el9_8.4
  Red Hat Enterprise Linux 6              unspecified  —
  Red Hat Enterprise Linux 7              unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 30  Published (CNA: redhat)
CWE-78 · CNA: redhat · 5 references · NVD status: Awaiting Analysis
IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0062   47.0     —
AFFECTED
  Product                 Versions    Fixed
  App Connect Enterprise  13.0.1.0 –  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 30  Published (CNA: ibm)
CWE-22 · CNA: ibm · 1 reference · NVD status: Analyzed
SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0061   46.2     —
AFFECTED
  Product        Versions                            Fixed
  Web Help Desk  2026.1 and all previous versions –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jul 30  Published (CNA: SolarWinds)
CWE-287 · CNA: SolarWinds · 3 references · NVD status: Analyzed
o6 Automation open62541 Integer Overflow or Wraparound
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0060   46.1     —
AFFECTED
  Product    Versions  Fixed
  open62541  1.3.0 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 30  Published (CNA: icscert)
CWE-190 · CNA: icscert · 7 references · NVD status: Received
Eaton PADM — Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firm…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  L    8.3   .0058   45.1     —
AFFECTED
  Product  Versions     Fixed
  PADM     unspecified  —
TIMELINE
  Jan 8   Reserved by CNA
  Jul 30  Published (CNA: Eaton)
CWE-78 · CNA: Eaton · 2 references · NVD status: Awaiting Analysis
ASE Admin and Site Enhancements (ASE) Pro — Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0058   44.8     —
AFFECTED
  Product                                Versions     Fixed
  Admin and Site Enhancements (ASE) Pro  unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Jul 30  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 2 references · NVD status: Deferred
o6 Automation open62541 Use After Free
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0057   44.6     —
AFFECTED
  Product    Versions  Fixed
  open62541  1.3.0 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Jul 30  Published (CNA: icscert)
CWE-416 · CNA: icscert · 7 references · NVD status: Received
BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0057   44.4     —
AFFECTED
  Product     Versions     Fixed
  BuddyPress  unspecified  —
TIMELINE
  Jan 22  Reserved by CNA
  Jul 30  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · 8 references · NVD status: Deferred
VMware Cloud Foundation — Out-of-bounds read vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  N  L    7.6   .0056   43.7     —
AFFECTED
  Product               Versions   Fixed
  Cloud Foundation      9.1.x.x –  —
  vSphere Foundation    9.1.x.x –  —
  ESX                   9.1.x.x –  —
  Workstation           25H2 –     —
  Fusion                25H2 –     —
  Telco Cloud Platform  5.1.x –    —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 30  Published (CNA: vmware)
CWE-125 · CNA: vmware · 1 reference · NVD status: Awaiting Analysis
IBM Enterprise Build of Quarkus is affected by a DoS vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0055   43.4     —
AFFECTED
  Product                      Versions  Fixed
  Enterprise Build of Quarkus  3.27.1 –  —
TIMELINE
  Jul 20  Reserved by CNA
  Jul 30  Published (CNA: ibm)
CWE-770 · CNA: ibm · 1 reference · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-484499.843.0AdobeAdobe Campaign ClassicCWE-863Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CVE-2026-182456.442.6AWSAmplify Codegen UICWE-94Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codege…
CVE-2026-685029.842.2grisunoLazyOwnCWE-306LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Disp…
CVE-2026-129409.842.1IBMLangflow OSSCWE-78Langflow is affected by remote code execution due to multiple unauthenticated…
CVE-2026-146029.042.1UnknownRemote APICWE-94Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query…
CVE-2026-599526.942.1open-circlevalibotCWE-755Valibot: record() issue paths can make flatten() throw for inherited Object p…
CVE-2026-175448.141.9PHP GroupPHPCWE-787Out-of-bounds write in bccomp() via crafted operand and scale
CVE-2026-582165.341.5Red HatRed Hat Enterprise Linux 10CWE-125Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might ca…
CVE-2026-121189.840.5IBMwebMethods Integration (on prem)CWE-502IBM webMethods Integration could allow an unauthenticated remote attacker to …
CVE-2026-165277.340.4Red HatRed Hat Enterprise Linux 10CWE-306Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing …
CVE-2026-6680310.039.6MicrosoftAzure Cosmos DBCWE-284Azure Cosmos DB Remote Code Execution Vulnerability
CVE-2026-288117.539.2Apache Software FoundationApache JSPWikiCWE-1295Apache JSPWiki: Error Handling - Reveals Error Details
CVE-2026-175438.138.6PHP GroupPHPCWE-89SQL injection in ext-pgsql via E'...' backslash breakout
CVE-2026-441089.338.2Phoenix ContactCHARX SEC-3150CWE-696Firewall bypass during shutdown
CVE-2026-129966.038.1OpenVPNOpenVPNCWE-125A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4…
CVE-2026-675949.337.7yolanmeesSpiksterCWE-306Spikster Missing Authentication via API Route Group
CVE-2026-165268.837.6Red HatRed Hat Enterprise Linux 10CWE-403Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability
CVE-2026-446166.537.3Apache Software FoundationApache ZeppelinCWE-90Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
CVE-2026-667566.937.0Apache Software FoundationApache TikaCWE-424Apache Tika: unpack endpoint in tika-server allows configuration with unsecur…
CVE-2026-667555.936.8Apache Software FoundationApache TikaCWE-22Apache Tika: Arbitrary Local File Read in ISArchiveParser
CVE-2026-176588.836.8GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-176618.836.8GoogleChromeCWE-416Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a re…
CVE-2026-176658.836.8GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-176858.836.8GoogleChromeCWE-416Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-176948.836.8GoogleChromeCWE-416Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remot…
CVE-2026-177058.836.8GoogleChromeCWE-190Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-672068.736.4wolfcmswolfcmsCWE-434Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
CVE-2026-181408.736.3AWSaws-smithy-jsonCWE-674Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows un…
CVE-2026-635598.736.1o6 Automationopen62541CWE-190o6 Automation open62541 Integer Overflow or Wraparound
CVE-2026-176646.535.9GoogleChromeCWE-20Insufficient validation of untrusted input in Loader in Google Chrome prior t…
CVE-2026-176819.635.1GoogleChromeCWE-20Insufficient validation of untrusted input in Web Authentication in Google Ch…
CVE-2026-78499.335.0Phoenix ContactCHARX SEC-3150CWE-77Command Injection in SCM (idledisconnect parameter)
CVE-2026-178818.834.8GoogleChromeCWE-416Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-129327.134.7OpenVPNOpenVPNCWE-401A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 thro…
CVE-2026-129427.534.7IBMLangflow OSSCWE-22Langflow is affected by path traversal due to multiple unauthenticated and in…
CVE-2026-534319.134.4malach-itborutaCWE-294Boruta accepts expired JWT client assertions due to missing exp claim validation
CVE-2026-177258.834.4GoogleChromeCWE-843Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-239855.334.4Apache Software FoundationApache SupersetCWE-1333Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
CVE-2026-288147.534.2Apache Software FoundationApache JSPWikiCWE-306Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering
CVE-2026-159719.833.6SGLangSGLangCWE-95CVE-2026-15971
CVE-2026-288129.833.5Apache Software FoundationApache JSPWikiCWE-290Apache JSPWiki: UserManager does not sanity-check user database at startup
CVE-2026-176879.633.5GoogleChromeCWE-843Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176979.633.5GoogleChromeCWE-843Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-440909.333.3Phoenix ContactCHARX SEC-3150CWE-306Missing authentication for MQTT Broker
CVE-2026-441019.333.3Phoenix ContactCHARX SEC-3150CWE-306OCPP reconfiguration vulnerability
CVE-2026-176809.633.2GoogleChromeCWE-122Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.792…
CVE-2026-179228.833.1GoogleChromeCWE-94Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.79…
CVE-2026-578597.733.0e107ince107CWE-502e107 Second-Order Code Execution via eval()-Based Deserialization in e_array:…
CVE-2026-131176.032.9OpenVPNOpenVPNCWE-416An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.…
CVE-2026-176519.632.9GoogleChromeCWE-20Insufficient validation of untrusted input in Dawn in Google Chrome on Androi…
CVE-2026-176529.632.9GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176559.632.8GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-176569.632.8GoogleChromeCWE-416Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-685039.832.7grisunoLazyOwnCWE-1392LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 D…
CVE-2026-129477.532.7IBMApp Connect EnterpriseCWE-532IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Dis…
CVE-2026-543639.332.5GladinetCentreStackCWE-321CentreStack < 17.5 Hardcoded Key Token Forgery RCE
CVE-2026-543688.732.4GladinetCentreStackCWE-89CentreStack < 17.4 SQL Injection via x-glad-filter Header
CVE-2026-107006.532.2IBMLangflow OSSCWE-639Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling…
CVE-2026-600747.531.9SBECKDate::ManipCWE-1289Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASC…
CVE-2026-600757.531.9SBECKDate::ManipCWE-1333Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic…
CVE-2026-446136.131.9Apache Software FoundationApache ZeppelinCWE-352Apache Zeppelin: Cross-site request forgery in REST and WebSocket request han…
CVE-2026-685007.531.3SyliusMolliePluginCWE-639Sylius Mollie Plugin: Payment status forgery via the payment webhook
CVE-2026-417092.731.3VMwareCloud FoundationCWE-778ESX insufficient logging vulnerability
CVE-2026-176676.531.3GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-176686.531.3GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-177076.531.3GoogleChromeCWE-457Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72…
CVE-2026-177146.531.3GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-440928.831.1Phoenix ContactCHARX SEC-3150CWE-93Missing input validation / stripping of CRLF characters in SystemConfigManager
CVE-2026-177198.831.0GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-117717.030.6OpenVPNOpenVPNCWE-121OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows atta…
CVE-2026-548856.930.4malach-itborutaCWE-918Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri f…
CVE-2026-673518.730.1s9ySerendipityCWE-304Serendipity < 2.6.1 Authentication Bypass via Username Collision
CVE-2026-484488.630.1AdobeAdobe Campaign ClassicCWE-89Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us…
CVE-2026-176699.630.0GoogleChromeCWE-693Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-176709.630.0GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176719.630.0GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-176729.630.0GoogleChromeCWE-20Insufficient validation of untrusted input in Chromecast in Google Chrome pri…
CVE-2026-176739.630.0GoogleChromeCWE-190Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a re…
CVE-2026-176769.630.0GoogleChromeCWE-693Inappropriate implementation in ANGLE in Google Chrome on Android prior to 15…
CVE-2026-176829.630.0GoogleChromeCWE-190Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-176849.630.0GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-176889.630.0GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-176919.630.0GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.…
CVE-2026-176929.630.0GoogleChromeCWE-416Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.792…
CVE-2026-176959.630.0GoogleChromeCWE-693Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.…
CVE-2026-177049.630.0GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-177089.630.0GoogleChromeCWE-416Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-177109.630.0GoogleChromeCWE-693Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.…
CVE-2026-177139.630.0GoogleChromeCWE-20Insufficient validation of untrusted input in Accessibility in Google Chrome …
CVE-2026-177179.630.0GoogleChromeCWE-190Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-176778.830.0GoogleChromeCWE-693Inappropriate implementation in ANGLE in Google Chrome on Android prior to 15…
CVE-2026-176788.830.0GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a…
CVE-2026-358479.829.8n/an/aCWE-77An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbit…
CVE-2026-65407.929.8TigeraCalicoCWE-22L7 policy bypass via unnormalized HTTP path matching
CVE-2026-165297.529.7Red HatRed Hat Enterprise Linux 10CWE-190Pcp: pcp: denial of service due to signed integer overflow
CVE-2026-177518.829.6GoogleChromeCWE-269Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922…
CVE-2026-239815.329.5Apache Software FoundationApache SupersetCWE-285Apache Superset: Improper Authorization in Chart Update allowing Dashboard Mo…
CVE-2026-664218.829.4tugcantopalogluopenclaw-dashboardCWE-79OpenClaw Dashboard Stored XSS via lastMessage Session Field
CVE-2026-226208.629.3EatonPADMCWE-89Improper input validation in the authentication component of Eaton's Tripp Li…
CVE-2026-178967.529.3GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-183625.928.8dfir-irisiris-webCWE-770DFIR-IRIS Missing Brute Force Protection in User Authentication
CVE-2026-165315.328.8Red HatRed Hat Enterprise Linux 10CWE-22Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet
CVE-2026-177019.628.4GoogleChromeCWE-125Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac p…
CVE-2026-177128.828.4GoogleChromeCWE-362Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote …
CVE-2026-176868.128.3GoogleChromeCWE-20Insufficient validation of untrusted input in Passwords in Google Chrome prio…
CVE-2026-129469.928.2IBMLangflow OSSCWE-94Remote Code Execution in CUGA Component CodeAgent
CVE-2026-177788.828.0GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-176796.528.0GoogleChromeCWE-20Insufficient validation of untrusted input in Print Preview in Google Chrome …
CVE-2026-176836.528.0GoogleChromeCWE-200Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72…
CVE-2026-176508.328.0GoogleChromeCWE-416Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed…
CVE-2026-176538.328.0GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remo…
CVE-2026-489106.527.9Apache Software FoundationApache JSPWikiCWE-80Apache JSPWiki: Markdown parser allows XSS injection in Markdown error proces…
CVE-2026-176608.327.7GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-176638.327.7GoogleChromeCWE-20Insufficient validation of untrusted input in GPU in Google Chrome on Android…
CVE-2026-115368.527.4IBMWebSphere Application ServerCWE-502IBM WebSphere Application Server is affected by a remote code execution vulne…
CVE-2026-580469.927.3WebProsPleskCWE-89Improper neutralization in the Plesk XML-RPC API allows a remote authenticate…
CVE-2026-411866.027.3TigeraCalicoCWE-200Unauthenticated Go pprof exposure in Calico debug server
CVE-2026-177589.627.2GoogleChromeCWE-122Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-685016.527.1SyliusMolliePluginCWE-639Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII
CVE-2026-177298.827.0GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-179358.826.8GoogleChromeCWE-122Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowe…
CVE-2026-133958.626.8UnknownOnline Scheduling and Appointment Booking SystemCWE-89Bookly < 27.8 - Unauthenticated SQL Injection via staff_id
CVE-2026-180648.226.8NASACore Flight System (cFS) Health & Safety (HS) ApplicationCWE-476NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer D…
CVE-2026-664189.326.7tugcantopalogluopenclaw-dashboardCWE-79OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field
CVE-2026-133795.126.7OpenVPNOpenVPNCWE-125The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows re…
CVE-2026-626637.526.4mascibanksCWE-22Banks: Arbitrary File Read via Path Traversal in Media Filters (image/audio/v…
CVE-2026-159769.826.1SGLangSGLangCWE-502CVE-2026-15976
CVE-2026-178688.826.1GoogleChromeCWE-269Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.7…
CVE-2026-547228.725.7HackingRepodssrf-jsCWE-76dssrf: there a critical security bug with remove_at_symbol_in_string
CVE-2026-440918.825.6Phoenix ContactCHARX SEC-3150CWE-501Creation of a new configuration by posting a malicious ID to MQTT
CVE-2026-177596.525.5GoogleChromeCWE-457Uninitialized Use in Codecs in Google Chrome prior to 151.0.7922.72 allowed a…
CVE-2026-176578.325.3GoogleChromeCWE-416Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2025-653369.824.9n/an/aCWE-89Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL I…
CVE-2026-176746.524.6GoogleChromeCWE-693Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 …
CVE-2026-177036.524.6GoogleChromeCWE-602Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2026-169715.924.6dfir-irisiris-webCWE-770DFIR-IRIS Missing Brute Force Protection in OTP Validation
CVE-2026-179898.824.4GoogleChromeCWE-843Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-143186.824.4UnknownGiveWPCWE-79GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
CVE-2026-176759.624.3GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-177189.624.3GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-177219.624.3GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-177269.624.3GoogleChromeCWE-190Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 …
CVE-2026-177279.624.3GoogleChromeCWE-787Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.…
CVE-2026-177389.624.3GoogleChromeCWE-20Insufficient validation of untrusted input in Payments in Google Chrome prior…
CVE-2026-177689.624.3GoogleChromeCWE-20Insufficient validation of untrusted input in WebSockets in Google Chrome pri…
CVE-2026-178019.624.3GoogleChromeCWE-125Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72…
CVE-2026-178049.624.3GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-177528.824.3GoogleChromeCWE-416Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowe…
CVE-2026-177848.824.3GoogleChromeCWE-416Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowe…
CVE-2026-179678.824.3GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…
CVE-2026-153977.224.1wpswingsSubscriptions for WooCommerceCWE-862Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticat…
CVE-2026-127337.524.1IBMDataPower Gateway 10.6CDCWE-770IBM DataPower Gateway affected by denial of service
CVE-2026-673458.523.7dromaraMaxKeyCWE-183MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
CVE-2026-108427.523.7IBMWebSphere Application ServerCWE-289IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-176894.323.7GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-441078.723.6Phoenix ContactCHARX SEC-3150CWE-749Exposed Reboot via Modbus
CVE-2026-672466.923.3ASUSTOR Inc.ADMCWE-22A path traversal vulnerability was found in the Wallpaper component of ADM
CVE-2026-178758.823.1GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a re…
CVE-2026-226228.823.1EatonPADMCWE-78Improper input validation in one of the session management interface of Eaton…
CVE-2026-93227.523.1IBMWebSphere Application ServerCWE-400IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-118977.523.0IBMWebSphere Application Server - LibertyCWE-770IBM WebSphere Application Server Liberty is affected by a denial of service v…
CVE-2026-178877.523.0GoogleChromeCWE-416Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-525399.122.9n/an/aCWE-798Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_…
CVE-2026-178078.822.9GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-178368.822.9GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote…
CVE-2026-179188.822.9GoogleChromeCWE-416Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remo…
CVE-2026-176987.522.7GoogleChromeCWE-20Insufficient validation of untrusted input in UI in Google Chrome on Android …
CVE-2026-672477.122.8ASUSTOR Inc.ADMCWE-22A path traversal vulnerability was found in the IHM Log handling of ADM
CVE-2026-598816.922.7aio-libsaiohttpCWE-20AIOHTTP: WebSocket client accepts compressed frames without negotiated permes…
CVE-2026-656358.322.7malach-itborutaCWE-653Boruta dynamic client registration allows creation of over-privileged OAuth c…
CVE-2026-672078.722.5wolfcmswolfcmsCWE-697Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
CVE-2026-615367.522.5mascibanksCWE-94Banks: Unsafe importlib.import_module of attacker-controlled Tool.import_path…
CVE-2026-165306.522.5Red HatRed Hat Enterprise Linux 10CWE-125Pcp: pcp: remote denial of service and information leakage
CVE-2026-177966.522.5GoogleChromeCWE-1300Side-channel information leakage in WebXR in Google Chrome prior to 151.0.792…
CVE-2026-178006.522.5GoogleChromeCWE-1300Inappropriate implementation in MediaRecording in Google Chrome prior to 151.…
CVE-2026-183639.122.4Enhancesoft LLCosTicketCWE-640Weak password recovery mechanism in osTicket by Enhancesoft LLC
CVE-2026-151536.822.3UnknownWP Hotel BookingCWE-89WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search
CVE-2026-126877.522.2UnknownProfileGridCWE-269ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted…
CVE-2026-177099.622.0GoogleChromeCWE-362Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a re…
CVE-2026-177119.622.0GoogleChromeCWE-362Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a re…
CVE-2026-134359.922.0IBMLangflow OSSCWE-94Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure
CVE-2026-159787.521.9SGLangSGLangCWE-306CVE-2026-15978
CVE-2026-578628.421.8KanboardKanboardCWE-918Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation
CVE-2026-119045.321.8IBMVerify Identity AccessCWE-209Security vulnerabilities have been found in IBM Verify Identity Access and IB…
CVE-2026-178039.621.7GoogleChromeCWE-20Insufficient validation of untrusted input in Save to Drive in Google Chrome …
CVE-2026-179568.821.6GoogleChromeCWE-269Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.79…
CVE-2026-179698.821.6GoogleChromeCWE-269Inappropriate implementation in Passwords in Google Chrome prior to 151.0.792…
CVE-2026-177358.721.6GoogleChromeCWE-20Insufficient validation of untrusted input in BFCache in Google Chrome prior …
CVE-2026-673467.721.5kyegomezswarmsCWE-918Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass
CVE-2026-543668.721.2GladinetCentreStackCWE-611CentreStack < 17.4 XXE via SharePoint Storage Configuration
CVE-2026-673498.721.1opencostopencostCWE-306OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
CVE-2026-176964.321.0GoogleChromeCWE-1300Side-channel information leakage in Media in Google Chrome prior to 151.0.792…
CVE-2026-177004.321.0GoogleChromeCWE-20Insufficient validation of untrusted input in Actor in Google Chrome prior to…
CVE-2026-177064.321.0GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome on Windo…
CVE-2026-664158.420.9LeantimeLeantimeCWE-918Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::…
CVE-2026-564288.120.9BoschBSH ELP (Electronic Platform) ModulesCWE-286The SSH service on BSH ELP (Electronic Platform) modules contains a platform-…
CVE-2026-478769.320.6VMwareCloud FoundationCWE-787VMXNET3 out-of-bounds write vulnerability
CVE-2026-179518.820.4GoogleChromeCWE-122Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowe…
CVE-2026-557688.720.3allinurlgoaccessCWE-681GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame lengt…
CVE-2026-125628.720.3Toptech SystemsRCU II+CWE-306Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical…
CVE-2026-663608.720.3MZ Automation GmbHlibiec61850CWE-125MZ Automation libiec61850 Out-of-bounds Read
CVE-2026-672448.620.2ASUSTOR Inc.ADMCWE-134A format string vulnerability was found in the Notification OAuth settings of…
CVE-2026-177228.320.3GoogleChromeCWE-416Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.…
CVE-2026-177238.320.3GoogleChromeCWE-416Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 al…
CVE-2026-441008.820.2Phoenix ContactCHARX SEC-3150CWE-306JupiCore charging point reconfiguration without auth
CVE-2026-672488.720.1ASUSTOR Inc.ADMCWE-121A stack-based buffer overflow vulnerability was found in the File Explorer on…
CVE-2026-673476.120.1vendurehqvendureCWE-863Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset …
CVE-2026-178479.620.0GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-178569.620.0GoogleChromeCWE-693Inappropriate implementation in Network in Google Chrome on Mac prior to 151.…
CVE-2026-178659.620.0GoogleChromeCWE-693Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0…
CVE-2026-178848.820.0GoogleChromeCWE-416Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allo…
CVE-2026-178868.820.0GoogleChromeCWE-416Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-178948.820.0GoogleChromeCWE-416Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allo…
CVE-2026-176906.519.6GoogleChromeCWE-20Insufficient validation of untrusted input in PDF in Google Chrome on Android…
CVE-2026-177566.519.6GoogleChromeCWE-602Insufficient policy enforcement in Presentation in Google Chrome prior to 151…
CVE-2026-177646.519.6GoogleChromeCWE-693Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72…
CVE-2026-178146.519.6GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-580406.319.6nodejsnodeCWE-297An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reu…
CVE-2026-179718.819.4GoogleChromeCWE-125Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72…
CVE-2026-179466.519.2GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-179686.519.2GoogleChromeCWE-457Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72…
CVE-2026-143568.819.1fleekdashFleekDash V2CWE-862FleekDash V2 <= 2.6.2.2 - Missing Authorization to Authenticated (Subscriber+…
CVE-2026-179508.819.1GoogleChromeCWE-269Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to…
CVE-2026-622468.519.1clastixkamajiCWE-284Kamaji: TenantControlPlane namespace/name collision binds two tenants to the …
CVE-2026-183607.619.0dfir-irisiris-webCWE-79DFIR-IRIS Stored XSS in Custom Attributes
CVE-2026-183617.619.0dfir-irisiris-webCWE-79DFIR-IRIS Stored XSS in Datastore Upload
CVE-2026-178167.519.0GoogleChromeCWE-269Insufficient policy enforcement in Speech in Google Chrome on Android prior t…
CVE-2026-183826.819.0Red HatCost Management Metrics OperatorCWE-918Project-koku/koku-metrics-operator: koku-metrics-operator: service-account cl…
CVE-2026-648167.118.8CyberTimonRapidRAWCWE-73RapidRAW < 1.6.0 NTLMv2 Credential Leak via UNC Path in lutPath
CVE-2026-658346.818.8projectcapsulecapsuleCWE-20Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validati…
CVE-2026-177404.318.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-177574.318.6GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-177714.318.6GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-177854.318.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-177904.318.5GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72…
CVE-2026-178084.318.5GoogleChromeCWE-457Uninitialized Use in WebGL in Google Chrome on Android prior to 151.0.7922.72…
CVE-2026-178104.318.6GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a r…
CVE-2026-181867.118.5ASUSTOR Inc.ADMCWE-134A stored format string vulnerability was found in the FTP Backup on the ADM
CVE-2026-181877.118.5ASUSTOR Inc.ADMCWE-134A format string vulnerability was found in the Internal Backup on the ADM
CVE-2026-181887.118.5ASUSTOR Inc.ADMCWE-134A format string vulnerability was found in the Rsync Backup on the ADM
CVE-2026-618936.918.3MZ Automationlib60870CWE-125MZ Automation lib60870 Out-of-bounds Read
CVE-2026-630336.918.3MZ Automationlib60870CWE-125MZ Automation lib60870 Out-of-bounds Read
CVE-2026-177916.518.4GoogleChromeCWE-20Insufficient validation of untrusted input in Payments in Google Chrome prior…
CVE-2026-177926.518.4GoogleChromeCWE-451Inappropriate implementation in Credential Management in Google Chrome prior …
CVE-2026-177936.518.4GoogleChromeCWE-451Inappropriate implementation in Messages in Google Chrome on Android prior to…
CVE-2026-178316.518.4GoogleChromeCWE-20Insufficient validation of untrusted input in Passwords in Google Chrome prio…
CVE-2024-250397.518.2IBMEngineering Requirements Management DOORS and DOORS Web AccessCWE-400IBM Engineering Requirements Management DOORS and DOORS Web Access is affecte…
CVE-2026-547157.118.2allinurlgoaccessCWE-122GoAccess: Heap Out-of-Bounds Write in parse_browser()
CVE-2026-178926.518.2GoogleChromeCWE-200Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72…
CVE-2026-557775.318.2allinurlgoaccessCWE-125GoAccess: Out-of-bounds heap read in parse_ios() via crafted User-Agent leads…
CVE-2026-178306.518.1GoogleChromeCWE-284Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-178698.118.0GoogleChromeCWE-125Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a…
CVE-2025-699309.817.9n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699319.817.9n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699339.817.9n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699349.817.9n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699359.817.9n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in t…
CVE-2025-699369.817.9n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699379.817.9n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699389.817.9n/an/aCWE-89CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in …
CVE-2025-699419.817.9n/an/aCWE-89SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in…
CVE-2025-699479.817.9n/an/aCWE-89SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in…
CVE-2026-49789.817.9UMAI VisionTraffic Analysis SystemCWE-89SQLi in UMAI Vision's Traffic Analysis System
CVE-2026-149236.517.7UnknownSync Post With Other SiteCWE-863Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modi…
CVE-2026-179926.517.7GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 …
CVE-2026-178514.317.7GoogleChromeCWE-1300Side-channel information leakage in Autofill in Google Chrome prior to 151.0.…
CVE-2026-178594.317.7GoogleChromeCWE-1300Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922…
CVE-2026-440948.317.7Phoenix ContactCHARX SEC-3150CWE-636Fallback to second RAUC slot with default credentials
CVE-2026-127228.217.2FTC Software IT ServicesFTC E-Commerce Management PanelCWE-306Authentication Bypass in FTC Software's E-Commerce Management Panel
CVE-2026-178489.617.2GoogleChromeCWE-20Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-178329.616.9GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem…
CVE-2026-178349.616.9GoogleChromeCWE-20Insufficient validation of untrusted input in Passwords in Google Chrome prio…
CVE-2026-178379.616.9GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-179249.616.9GoogleChromeCWE-416Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remot…
CVE-2026-179409.616.9GoogleChromeCWE-20Insufficient validation of untrusted input in Picture-in-Picture in Google Ch…
CVE-2026-179479.616.9GoogleChromeCWE-416Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed …
CVE-2026-673488.617.0julep-aijulepCWE-639Julep Insecure Direct Object Reference via GET /executions/{execution_id}
CVE-2026-125007.517.0UnknownWP Travel EngineCWE-862WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update
CVE-2026-131787.517.0UnknownEventinCWE-639Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
CVE-2026-543646.916.8GladinetCentreStackCWE-116CentreStack < 17.4 Session Injection via SelectProvider.aspx
CVE-2026-635507.116.5MZ Automation GmbHlibiec61850CWE-125MZ Automation libiec61850 Out-of-bounds Read
CVE-2026-160926.516.5labelblancImproved Save ButtonCWE-89Improved Save Button <= 1.2.1 - Authenticated (Author+) Second-Order SQL Inje…
CVE-2026-133455.316.0UnknownEssential Addons for ElementorCWE-639Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Privat…
CVE-2026-580669.815.9Rocket.ChatRocket.ChatCWE-287Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2…
CVE-2026-440975.315.8Phoenix ContactCHARX SEC-3150CWE-434File Upload vulnerability
CVE-2026-177304.315.8GoogleChromeCWE-1300Side-channel information leakage in Autofill in Google Chrome prior to 151.0.…
CVE-2026-177604.315.8GoogleChromeCWE-1300Side-channel information leakage in NoStatePrefetch in Google Chrome prior to…
CVE-2026-177674.315.8GoogleChromeCWE-20Insufficient validation of untrusted input in WebView in Google Chrome on And…
CVE-2026-177694.315.8GoogleChromeCWE-20Insufficient validation of untrusted input in Cast in Google Chrome prior to …
CVE-2026-177724.315.8GoogleChromeCWE-125Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a…
CVE-2026-177734.315.8GoogleChromeCWE-20Insufficient validation of untrusted input in Cast in Google Chrome prior to …
CVE-2026-177954.315.8GoogleChromeCWE-20Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.…
CVE-2026-179919.615.7GoogleChromeCWE-20Insufficient validation of untrusted input in AI in Google Chrome prior to 15…
CVE-2026-180178.815.6GoogleChromeCWE-416Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remo…
CVE-2026-675277.615.6opfopenprojectCWE-862OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via…
CVE-2026-177795.415.6GoogleChromeCWE-693Inappropriate implementation in Site Isolation in Google Chrome prior to 151.…
CVE-2026-142223.815.6UnknownEasy AppointmentsCWE-284Easy Appointments < 3.12.28 - Contributor+ Connection Deletion via Missing Au…
CVE-2026-177499.615.5GoogleChromeCWE-20Insufficient validation of untrusted input in Extensions in Google Chrome pri…
CVE-2026-441049.315.5Phoenix ContactCHARX SEC-3150CWE-347ControllerAgent does not perform validation of firmware
CVE-2026-177868.815.5GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-159777.515.5SGLangSGLangCWE-522CVE-2026-15977
CVE-2025-363745.515.5IBMDataPower Gateway 10.6CDCWE-611IBM DataPower Gateway affected by XML external entity injection
CVE-2026-179135.415.3GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-141882.715.4UnknownEasy AppointmentsCWE-200Easy Appointments < 3.12.28 - Contributor+ Customer Data Disclosure
CVE-2026-183538.815.3Eclipse FoundationEclipse CSI - PIACWE-918Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass
CVE-2026-484999.315.1activepiecesactivepiecesCWE-200Activepieces: Cross-tenant data exposure and code injection via the Code piec…
CVE-2026-178406.515.1GoogleChromeCWE-451Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 al…
CVE-2026-178506.515.0GoogleChromeCWE-346Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7…
CVE-2026-178526.515.0GoogleChromeCWE-346Inappropriate implementation in Media Router in Google Chrome prior to 151.0.…
CVE-2026-176624.315.1GoogleChromeCWE-346Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7…
CVE-2026-176934.315.1GoogleChromeCWE-346Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0…
CVE-2026-179344.315.0GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-179307.514.9GoogleChromeCWE-20Insufficient validation of untrusted input in Extensions in Google Chrome pri…
CVE-2026-178246.514.9GoogleChromeCWE-284Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 15…
CVE-2026-178736.514.9GoogleChromeCWE-284Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2026-179756.515.0GoogleChromeCWE-200Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.79…
CVE-2026-675294.314.9opfopenprojectCWE-200OpenProject: Private work package subject/identity disclosure through the glo…
CVE-2026-179958.114.8GoogleChromeCWE-125Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-441036.914.8Phoenix ContactCHARX SEC-3150CWE-434JupiCore does not perform validation of firmware
CVE-2026-149808.814.7IBMWebSphere Application Server - LibertyCWE-269IBM WebSphere Application Server Liberty is affected by a cross-site request …
CVE-2026-178584.314.4GoogleChromeCWE-457Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72…
CVE-2026-178894.314.4GoogleChromeCWE-457Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a …
CVE-2026-440938.514.2Phoenix ContactCHARX SEC-3150CWE-78Local Privilege Escalation vulnerability in /etc/init.d/user-applications via…
CVE-2026-440958.514.2Phoenix ContactCHARX SEC-3150CWE-78Local Privilege Escalation via Network scripts
CVE-2026-440968.514.2Phoenix ContactCHARX SEC-3150CWE-78udhcpc Privilege Escalation
CVE-2026-440998.514.2Phoenix ContactCHARX SEC-3150CWE-78Local Privilege Escalation via pppd password injection
CVE-2026-441068.514.2Phoenix ContactCHARX SEC-3150CWE-78Local Privilege Escalation vulnerability in /etc/init.d/user-applications via…
CVE-2026-143055.314.1UnknownWP DeliciousCWE-287WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe…
CVE-2026-177824.314.1GoogleChromeCWE-451Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.…
CVE-2026-177944.314.1GoogleChromeCWE-20Insufficient validation of untrusted input in Mobile in Google Chrome on Andr…
CVE-2026-179384.314.1GoogleChromeCWE-451Inappropriate implementation in FullScreen in Google Chrome on Android prior …
CVE-2026-179414.314.1GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-183786.813.9Red HatCost Management Metrics OperatorCWE-918Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secre…
CVE-2026-153826.513.5UnknownUltimate Addons for WPBakery Page BuilderCWE-73Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom I…
CVE-2026-178494.313.5GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-178056.513.4GoogleChromeCWE-602Insufficient policy enforcement in Glic in Google Chrome on Android prior to …
CVE-2026-178136.513.4GoogleChromeCWE-602Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2026-179216.513.4GoogleChromeCWE-20Insufficient validation of untrusted input in Navigation in Google Chrome pri…
CVE-2026-179266.513.4GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-179316.513.4GoogleChromeCWE-693Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922…
CVE-2026-179536.513.4GoogleChromeCWE-602Insufficient policy enforcement in WebView in Google Chrome on Android prior …
CVE-2026-176594.213.4GoogleChromeCWE-693Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0…
CVE-2026-179879.613.3GoogleChromeCWE-20Insufficient validation of untrusted input in Notifications in Google Chrome …
CVE-2026-179909.613.3GoogleChromeCWE-20Insufficient validation of untrusted input in WebAuthn in Google Chrome prior…
CVE-2026-142264.313.3UnknownEasy AppointmentsCWE-200Easy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure vi…
CVE-2026-142314.313.3UnknownLifterLMSCWE-200LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select…
CVE-2026-152354.313.3UnknownMotoPress Hotel BookingCWE-200Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin …
CVE-2026-180128.813.2GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a re…
CVE-2026-179208.813.0GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attac…
CVE-2026-142276.913.0MikroTikRouterOSCWE-613Insufficient session expiration in MikroTik RouterOS
CVE-2026-105457.512.9IBMPlanning Analytics LocalCWE-601IBM Planning Analytics Local is affected by Open Redirect
CVE-2026-117825.912.8UnknownPoints and Rewards for WooCommerceCWE-284Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User …
CVE-2026-131435.312.9UnknownWP TravelCWE-290WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
CVE-2026-178559.612.8GoogleChromeCWE-362Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a rem…
CVE-2026-411876.212.8TigeraCalicoCWE-285Calico Tier Authorization Bypass via DeleteCollection
CVE-2026-179145.312.7GoogleChromeCWE-1300Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922…
CVE-2026-179494.312.7GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.72 a…
CVE-2026-685626.212.7Red HatRed Hat Enterprise Linux 10CWE-610Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information…
CVE-2026-177436.512.5GoogleChromeCWE-346Insufficient policy enforcement in ControlledFrame in Google Chrome prior to …
CVE-2026-177486.512.5GoogleChromeCWE-346Inappropriate implementation in Extensions in Google Chrome prior to 151.0.79…
CVE-2026-177546.512.5GoogleChromeCWE-346Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72…
CVE-2026-177876.512.5GoogleChromeCWE-346Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922…
CVE-2026-178196.512.6GoogleChromeCWE-451Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.…
CVE-2026-178286.512.6GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-178356.512.6GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-178386.512.6GoogleChromeCWE-451Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.…
CVE-2026-178396.512.6GoogleChromeCWE-451Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-117079.312.4IBMTivoli System Automation Application ManagerCWE-79Multiple vulnerabilities have been identified in IBM WebSphere Application Se…
CVE-2026-178256.512.4GoogleChromeCWE-284Insufficient policy enforcement in Passwords in Google Chrome on Android prio…
CVE-2026-179176.512.4GoogleChromeCWE-284Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2025-516846.112.4n/an/aCWE-79CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The ap…
CVE-2026-543658.712.3GladinetCentreStackCWE-306CentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNam…
CVE-2026-179856.512.3GoogleChromeCWE-602Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.792…
CVE-2026-179886.512.3GoogleChromeCWE-20Insufficient validation of untrusted input in Navigation in Google Chrome pri…
CVE-2026-177474.212.3GoogleChromeCWE-20Insufficient validation of untrusted input in Payments in Google Chrome on An…

Results continue: ranks 401–662.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-30 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.