AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0423 90.2 —
AFFECTED Product Versions Fixed Juggle unspecified —
TIMELINE Jul 28 Reserved by CNA Jul 30 Published (CNA: VulnCheck)
662 CVEs published July 30, 2026: 110 critical, 199 high, 329 medium, 23 low; 0 in KEV; 6 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 637 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 5873 | 8622 | 1389 | 2563 |
| KEV catalog size | 1670 | |||
256 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 667 | 1585 | 207 | 1127 | 98 | 0 | 27 | 3 | 0.2 | 7.8 | .0016 | +426 |
| microsoft | 658 | 1361 | 105 | 929 | 302 | 8 | 378 | 32 | 2.4 | 7.8 | .0039 | +439 |
| 398 | 407 | 64 | 101 | 224 | 15 | 73 | 5 | 1.2 | 6.5 | .0022 | +395 | |
| apple | 167 | 244 | 56 | 67 | 112 | 2 | 93 | 7 | 2.9 | 7.1 | .0027 | +130 |
| red hat | 107 | 206 | 9 | 101 | 85 | 11 | 4 | 0 | 0.0 | 7.1 | .0027 | +52 |
| canonical | 3 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | +3 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | -1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 8 | 20 | 4 | 6 | 2 | 0 | 96 | 13 | 65.0 | 8.2 | .1853 | +5 |
| fortinet | 11 | 18 | 2 | 4 | 9 | 0 | 28 | 6 | 33.3 | 6.1 | .0054 | +10 |
| palo alto networks | 10 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | +7 |
| vmware | 12 | 12 | 4 | 7 | 0 | 1 | 21 | 0 | 0.0 | 8.7 | .0044 | +12 |
| f5 | 1 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | -1 |
| checkpoint | 3 | 4 | 3 | 1 | 0 | 0 | 3 | 2 | 50.0 | 9.2 | .4696 | +2 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.1 | .0877 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 102 | 134 | 24 | 73 | 37 | 0 | 40 | 1 | 0.7 | 7.5 | .0051 | +86 |
| mozilla | 67 | 72 | 42 | 26 | 4 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +67 |
| gitlab | 13 | 15 | 0 | 2 | 10 | 1 | 4 | 2 | 13.3 | 4.9 | .0029 | +13 |
| wordpress | 3 | 3 | 1 | 1 | 1 | 0 | 5 | 2 | 66.7 | 8.6 | .7310 | +3 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | -3 |
| github | 2 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 6.1 | .0029 | +2 |
| kubernetes | 1 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1109 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | +1107 |
| ibm | 100 | 108 | 31 | 43 | 34 | 0 | 7 | 0 | 0.0 | 7.5 | .0026 | +92 |
| adobe | 28 | 39 | 10 | 21 | 4 | 0 | 75 | 4 | 10.3 | 8.5 | .0040 | +21 |
| progress | 23 | 23 | 3 | 15 | 5 | 0 | 9 | 0 | 0.0 | 8.1 | .0032 | +23 |
| solarwinds | 16 | 20 | 16 | 1 | 1 | 0 | 11 | 4 | 20.0 | 9.1 | .0050 | +15 |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 |
| zohocorp | 3 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0048 | +3 |
| veeam | 2 | 2 | 0 | 1 | 1 | 0 | 4 | 0 | 0.0 | 6.8 | .0016 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 7 | 8 | 0 | 0 | 6 | 1 | 26 | 1 | 12.5 | 5.5 | .0073 | +7 |
| hikvision | 5 | 6 | 0 | 3 | 2 | 0 | 2 | 1 | 16.7 | 7.2 | .0024 | +5 |
| bosch | 3 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0028 | +3 |
| schneider electric | 3 | 3 | 1 | 2 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0020 | +3 |
| honeywell | 1 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 6.9 | .0031 | +1 |
| mitsubishi electric | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.1 | .0013 | +1 |
| rockwell automation | 1 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | +1 |
| siemens | 0 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 57 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | +57 |
| netty | 19 | 41 | 6 | 27 | 7 | 1 | 0 | 0 | 0.0 | 7.5 | .0046 | +5 |
| grafana | 8 | 41 | 2 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | +2 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| erlang | 14 | 32 | 1 | 14 | 14 | 3 | 1 | 0 | 0.0 | 6.9 | .0033 | +7 |
| regularlabs.com | 29 | 29 | 6 | 14 | 9 | 0 | 0 | 0 | 0.0 | 7.5 | .0022 | +29 |
| watchguard | 17 | 28 | 1 | 18 | 9 | 0 | 4 | 0 | 0.0 | 7.3 | .0026 | +17 |
| nlnet labs | 24 | 27 | 0 | 4 | 17 | 6 | 0 | 0 | 0.0 | 5.9 | .0024 | +24 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | — |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE-2026-15409 | .7422 | 99.4 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 667 |
| microsoft | 658 |
| 398 | |
| apple | 167 |
| red hat | 107 |
| apache | 102 |
| ibm | 100 |
| mozilla | 67 |
| surrealdb | 57 |
| Vendor | KEV |
|---|---|
| microsoft | 32 |
| cisco | 13 |
| apple | 7 |
| fortinet | 6 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 27 |
| Go | 3 |
| crates.io | 2 |
| npm | 2 |
| NuGet | 1 |
| Packagist | 1 |
| PyPI | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1716 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1716 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1716 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1716 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1716 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1716 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1716 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1716 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1716 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1716 |
EXPLOIT PUBLISHED — CVE-2025-37899 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-38002 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-38089 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-12436 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14234 (Unknown WOLF). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14300 (Unknown miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41939 (Care Everywhere LLC Care Everywhere Gateway). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45309 (ronf asyncssh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47143 (capstone-engine capstone). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54522 (msgpack-ruby). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56819 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56820 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-6267 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66729 (boazsegev facil.io). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66730 (boazsegev facil.io). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66731 (boazsegev facil.io). Public exploit reference added.
DUE DATE PASSED — CVE-2023-4346 (KNX Association KNX Protocol Connection Authorization Option 1). CISA remediation deadline was July 29, 2026; still in catalog.
RESCORED — CVE-2023-4244 (Linux Kernel). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2025-21629 (Linux). CVSS 8.2 → 5.5 (NVD).
RESCORED — CVE-2025-21637 (Linux). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2025-21638 (Linux). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2025-21640 (Linux). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2025-21646 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2025-21647 (Linux). CVSS 7.3 → 7.1 (NVD).
RESCORED — CVE-2025-21650 (Linux). CVSS 7.1 → 7.8 (NVD).
RESCORED — CVE-2025-21655 (Linux). CVSS 7.8 → 4.7 (NVD).
RESCORED — CVE-2025-21659 (Linux). CVSS 8.1 → 5.5 (NVD).
RESCORED — CVE-2025-21661 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21663 (Linux). CVSS 10 → 5.5 (NVD).
RESCORED — CVE-2025-21664 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21669 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21673 (Linux). CVSS 9.8 → 5.5 (NVD).
RESCORED — CVE-2025-21676 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2025-21677 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21678 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21682 (Linux). CVSS 7.3 → 5.5 (NVD).
RESCORED — CVE-2025-21697 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21699 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21701 (Linux). CVSS 7.8 → 4.7 (NVD).
RESCORED — CVE-2025-21707 (Linux). CVSS 9.8 → 5.5 (NVD).
RESCORED — CVE-2025-21709 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21710 (Linux). CVSS 8.2 → 5.5 (NVD).
RESCORED — CVE-2025-21712 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21717 (Linux). CVSS 7.8 → 7.1 (NVD).
RESCORED — CVE-2025-21718 (Linux). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2025-21720 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2025-21725 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2025-21730 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21735 (Linux). CVSS 8.8 → 7.8 (NVD).
RESCORED — CVE-2025-21738 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21748 (Linux). CVSS 9.8 → 5.5 (NVD).
RESCORED — CVE-2025-21758 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21765 (Linux). CVSS 8.1 → 5.5 (NVD).
RESCORED — CVE-2025-21766 (Linux). CVSS 8.1 → 5.5 (NVD).
RESCORED — CVE-2025-21778 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21788 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2025-21789 (Linux). CVSS 7.3 → 7.1 (NVD).
RESCORED — CVE-2025-21792 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21795 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2025-21801 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21804 (Linux). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2025-21805 (Linux). CVSS 9.8 → 5.5 (NVD).
RESCORED — CVE-2025-21808 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21809 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2025-21810 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21823 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2025-21825 (Linux). CVSS 7.8 → 4.7 (NVD).
ENRICHED — CVE-2021-20322 (kernel). Received CVSS 7.4 and CPE data from NVD.
ENRICHED — CVE-2026-53167 (Linux). Received CVSS 5.5 and CPE data from NVD.
+ 527 more transactions — continued on page 2. Every change is listed; nothing truncated.
662 CVEs published. 25 box scores and 375 table rows below; the remaining 262 continue on page 2 — every CVE is listed, nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0423 90.2 —
AFFECTED Product Versions Fixed Juggle unspecified —
TIMELINE Jul 28 Reserved by CNA Jul 30 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0267 84.5 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jul 30 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 .0177 76.2 —
AFFECTED Product Versions Fixed rails < 7.2.3.2 – —
TIMELINE Jul 23 Reserved by CNA Jul 30 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N N N H 8.2 .0153 72.6 —
AFFECTED Product Versions Fixed open62541 1.3.0 – —
TIMELINE Jul 27 Reserved by CNA Jul 30 Published (CNA: icscert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L H 8.8 .0137 69.5 —
AFFECTED Product Versions Fixed CHARX SEC-3150 1.0.0 – — CHARX SEC-3100 1.0.0 – — CHARX SEC-3050 1.0.0 – — CHARX SEC-3000 1.0.0 – —
TIMELINE May 5 Reserved by CNA Jul 30 Published (CNA: CERTVDE)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0114 63.9 —
AFFECTED Product Versions Fixed Cloud Foundation 9.1.x.x – — vSphere Foundation 9.1.x.x – — vCenter 9.1.x.x – — Telco Cloud Infrastructure 3.0 – — Telco Cloud Platform 5.1.x – —
TIMELINE Jul 4 Reserved by CNA Jul 30 Published (CNA: vmware)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N L 5.3 .0110 62.9 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 10 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified — Red Hat Enterprise Linux 8 unspecified — Red Hat Enterprise Linux 9 unspecified — Red Hat OpenShift Container Platform 4 unspecified —
TIMELINE Jun 29 Reserved by CNA Jul 30 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0102 60.4 —
AFFECTED Product Versions Fixed App Connect Enterprise 13.0.1.0 – —
TIMELINE Jul 2 Reserved by CNA Jul 30 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0098 59.3 —
AFFECTED Product Versions Fixed SGLang unspecified —
TIMELINE Jul 16 Reserved by CNA Jul 30 Published (CNA: certcc)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0092 57.3 —
AFFECTED Product Versions Fixed HMC V10.3.1050.0 10.3.1050.0 – — HMC V11.1.1110.0 11.1.1110.0 – —
TIMELINE Jun 22 Reserved by CNA Jul 30 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0084 54.8 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 10 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified — Red Hat Enterprise Linux 8 unspecified — Red Hat Enterprise Linux 9 unspecified — Red Hat OpenShift Container Platform 4 unspecified —
TIMELINE Jun 29 Reserved by CNA Jul 30 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L N 6.5 .0084 54.8 —
AFFECTED Product Versions Fixed Apache Zeppelin 0.11.1 – —
TIMELINE May 7 Reserved by CNA Jul 30 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0075 51.9 —
AFFECTED Product Versions Fixed Apache Kyuubi 1.7.0 – —
TIMELINE Jun 8 Reserved by CNA Jul 30 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0074 51.7 —
AFFECTED Product Versions Fixed Cloud Foundation 9.1.x.x – — vSphere Foundation 9.1.x.x – — vCenter 9.1.x.x – — Telco Cloud Infrastructure 3.0 – — Telco Cloud Platform 5.1.x – —
TIMELINE Jul 4 Reserved by CNA Jul 30 Published (CNA: vmware)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.4 —
AFFECTED Product Versions Fixed App Connect Enterprise 13.0.1.0 – —
TIMELINE Jul 10 Reserved by CNA Jul 30 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U H H H 7.8 .0065 48.3 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 10 unspecified 0:7.0.3-5.el10_2 Red Hat Enterprise Linux 8 unspecified 0:5.3.7-22.el8_10.5 Red Hat Enterprise Linux 9 unspecified 0:6.3.7-8.el9_8.4 Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified — Red Hat OpenShift Container Platform 4 unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 30 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0062 47.0 —
AFFECTED Product Versions Fixed App Connect Enterprise 13.0.1.0 – —
TIMELINE Jul 2 Reserved by CNA Jul 30 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0061 46.2 —
AFFECTED Product Versions Fixed Web Help Desk 2026.1 and all previous versions – —
TIMELINE Feb 26 Reserved by CNA Jul 30 Published (CNA: SolarWinds)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0060 46.1 —
AFFECTED Product Versions Fixed open62541 1.3.0 – —
TIMELINE Jul 27 Reserved by CNA Jul 30 Published (CNA: icscert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H L 8.3 .0058 45.1 —
AFFECTED Product Versions Fixed PADM unspecified —
TIMELINE Jan 8 Reserved by CNA Jul 30 Published (CNA: Eaton)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0058 44.8 —
AFFECTED Product Versions Fixed Admin and Site Enhancements (ASE) Pro unspecified —
TIMELINE Jul 22 Reserved by CNA Jul 30 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H H 7.2 .0057 44.6 —
AFFECTED Product Versions Fixed open62541 1.3.0 – —
TIMELINE Jul 27 Reserved by CNA Jul 30 Published (CNA: icscert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0057 44.4 —
AFFECTED Product Versions Fixed BuddyPress unspecified —
TIMELINE Jan 22 Reserved by CNA Jul 30 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H N L 7.6 .0056 43.7 —
AFFECTED Product Versions Fixed Cloud Foundation 9.1.x.x – — vSphere Foundation 9.1.x.x – — ESX 9.1.x.x – — Workstation 25H2 – — Fusion 25H2 – — Telco Cloud Platform 5.1.x – —
TIMELINE Apr 22 Reserved by CNA Jul 30 Published (CNA: vmware)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0055 43.4 —
AFFECTED Product Versions Fixed Enterprise Build of Quarkus 3.27.1 – —
TIMELINE Jul 20 Reserved by CNA Jul 30 Published (CNA: ibm)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-48449 | 9.8 | 43.0 | Adobe | Adobe Campaign Classic | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-18245 | 6.4 | 42.6 | AWS | Amplify Codegen UI | CWE-94 | Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codege… |
| CVE-2026-68502 | 9.8 | 42.2 | grisuno | LazyOwn | CWE-306 | LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Disp… |
| CVE-2026-12940 | 9.8 | 42.1 | IBM | Langflow OSS | CWE-78 | Langflow is affected by remote code execution due to multiple unauthenticated… |
| CVE-2026-14602 | 9.0 | 42.1 | Unknown | Remote API | CWE-94 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query… |
| CVE-2026-59952 | 6.9 | 42.1 | open-circle | valibot | CWE-755 | Valibot: record() issue paths can make flatten() throw for inherited Object p… |
| CVE-2026-17544 | 8.1 | 41.9 | PHP Group | PHP | CWE-787 | Out-of-bounds write in bccomp() via crafted operand and scale |
| CVE-2026-58216 | 5.3 | 41.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might ca… |
| CVE-2026-12118 | 9.8 | 40.5 | IBM | webMethods Integration (on prem) | CWE-502 | IBM webMethods Integration could allow an unauthenticated remote attacker to … |
| CVE-2026-16527 | 7.3 | 40.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-306 | Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing … |
| CVE-2026-66803 | 10.0 | 39.6 | Microsoft | Azure Cosmos DB | CWE-284 | Azure Cosmos DB Remote Code Execution Vulnerability |
| CVE-2026-28811 | 7.5 | 39.2 | Apache Software Foundation | Apache JSPWiki | CWE-1295 | Apache JSPWiki: Error Handling - Reveals Error Details |
| CVE-2026-17543 | 8.1 | 38.6 | PHP Group | PHP | CWE-89 | SQL injection in ext-pgsql via E'...' backslash breakout |
| CVE-2026-44108 | 9.3 | 38.2 | Phoenix Contact | CHARX SEC-3150 | CWE-696 | Firewall bypass during shutdown |
| CVE-2026-12996 | 6.0 | 38.1 | OpenVPN | OpenVPN | CWE-125 | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4… |
| CVE-2026-67594 | 9.3 | 37.7 | yolanmees | Spikster | CWE-306 | Spikster Missing Authentication via API Route Group |
| CVE-2026-16526 | 8.8 | 37.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-403 | Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability |
| CVE-2026-44616 | 6.5 | 37.3 | Apache Software Foundation | Apache Zeppelin | CWE-90 | Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction |
| CVE-2026-66756 | 6.9 | 37.0 | Apache Software Foundation | Apache Tika | CWE-424 | Apache Tika: unpack endpoint in tika-server allows configuration with unsecur… |
| CVE-2026-66755 | 5.9 | 36.8 | Apache Software Foundation | Apache Tika | CWE-22 | Apache Tika: Arbitrary Local File Read in ISArchiveParser |
| CVE-2026-17658 | 8.8 | 36.8 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… | |
| CVE-2026-17661 | 8.8 | 36.8 | Chrome | CWE-416 | Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a re… | |
| CVE-2026-17665 | 8.8 | 36.8 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… | |
| CVE-2026-17685 | 8.8 | 36.8 | Chrome | CWE-416 | Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-17694 | 8.8 | 36.8 | Chrome | CWE-416 | Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remot… | |
| CVE-2026-17705 | 8.8 | 36.8 | Chrome | CWE-190 | Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-67206 | 8.7 | 36.4 | wolfcms | wolfcms | CWE-434 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload |
| CVE-2026-18140 | 8.7 | 36.3 | AWS | aws-smithy-json | CWE-674 | Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows un… |
| CVE-2026-63559 | 8.7 | 36.1 | o6 Automation | open62541 | CWE-190 | o6 Automation open62541 Integer Overflow or Wraparound |
| CVE-2026-17664 | 6.5 | 35.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Loader in Google Chrome prior t… | |
| CVE-2026-17681 | 9.6 | 35.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Web Authentication in Google Ch… | |
| CVE-2026-7849 | 9.3 | 35.0 | Phoenix Contact | CHARX SEC-3150 | CWE-77 | Command Injection in SCM (idledisconnect parameter) |
| CVE-2026-17881 | 8.8 | 34.8 | Chrome | CWE-416 | Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a r… | |
| CVE-2026-12932 | 7.1 | 34.7 | OpenVPN | OpenVPN | CWE-401 | A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 thro… |
| CVE-2026-12942 | 7.5 | 34.7 | IBM | Langflow OSS | CWE-22 | Langflow is affected by path traversal due to multiple unauthenticated and in… |
| CVE-2026-53431 | 9.1 | 34.4 | malach-it | boruta | CWE-294 | Boruta accepts expired JWT client assertions due to missing exp claim validation |
| CVE-2026-17725 | 8.8 | 34.4 | Chrome | CWE-843 | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… | |
| CVE-2026-23985 | 5.3 | 34.4 | Apache Software Foundation | Apache Superset | CWE-1333 | Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser |
| CVE-2026-28814 | 7.5 | 34.2 | Apache Software Foundation | Apache JSPWiki | CWE-306 | Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering |
| CVE-2026-15971 | 9.8 | 33.6 | SGLang | SGLang | CWE-95 | CVE-2026-15971 |
| CVE-2026-28812 | 9.8 | 33.5 | Apache Software Foundation | Apache JSPWiki | CWE-290 | Apache JSPWiki: UserManager does not sanity-check user database at startup |
| CVE-2026-17687 | 9.6 | 33.5 | Chrome | CWE-843 | Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-17697 | 9.6 | 33.5 | Chrome | CWE-843 | Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-44090 | 9.3 | 33.3 | Phoenix Contact | CHARX SEC-3150 | CWE-306 | Missing authentication for MQTT Broker |
| CVE-2026-44101 | 9.3 | 33.3 | Phoenix Contact | CHARX SEC-3150 | CWE-306 | OCPP reconfiguration vulnerability |
| CVE-2026-17680 | 9.6 | 33.2 | Chrome | CWE-122 | Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.792… | |
| CVE-2026-17922 | 8.8 | 33.1 | Chrome | CWE-94 | Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.79… | |
| CVE-2026-57859 | 7.7 | 33.0 | e107inc | e107 | CWE-502 | e107 Second-Order Code Execution via eval()-Based Deserialization in e_array:… |
| CVE-2026-13117 | 6.0 | 32.9 | OpenVPN | OpenVPN | CWE-416 | An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.… |
| CVE-2026-17651 | 9.6 | 32.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on Androi… | |
| CVE-2026-17652 | 9.6 | 32.9 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-17655 | 9.6 | 32.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-17656 | 9.6 | 32.8 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-68503 | 9.8 | 32.7 | grisuno | LazyOwn | CWE-1392 | LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 D… |
| CVE-2026-12947 | 7.5 | 32.7 | IBM | App Connect Enterprise | CWE-532 | IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Dis… |
| CVE-2026-54363 | 9.3 | 32.5 | Gladinet | CentreStack | CWE-321 | CentreStack < 17.5 Hardcoded Key Token Forgery RCE |
| CVE-2026-54368 | 8.7 | 32.4 | Gladinet | CentreStack | CWE-89 | CentreStack < 17.4 SQL Injection via x-glad-filter Header |
| CVE-2026-10700 | 6.5 | 32.2 | IBM | Langflow OSS | CWE-639 | Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling… |
| CVE-2026-60074 | 7.5 | 31.9 | SBECK | Date::Manip | CWE-1289 | Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASC… |
| CVE-2026-60075 | 7.5 | 31.9 | SBECK | Date::Manip | CWE-1333 | Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic… |
| CVE-2026-44613 | 6.1 | 31.9 | Apache Software Foundation | Apache Zeppelin | CWE-352 | Apache Zeppelin: Cross-site request forgery in REST and WebSocket request han… |
| CVE-2026-68500 | 7.5 | 31.3 | Sylius | MolliePlugin | CWE-639 | Sylius Mollie Plugin: Payment status forgery via the payment webhook |
| CVE-2026-41709 | 2.7 | 31.3 | VMware | Cloud Foundation | CWE-778 | ESX insufficient logging vulnerability |
| CVE-2026-17667 | 6.5 | 31.3 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-17668 | 6.5 | 31.3 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-17707 | 6.5 | 31.3 | Chrome | CWE-457 | Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72… | |
| CVE-2026-17714 | 6.5 | 31.3 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-44092 | 8.8 | 31.1 | Phoenix Contact | CHARX SEC-3150 | CWE-93 | Missing input validation / stripping of CRLF characters in SystemConfigManager |
| CVE-2026-17719 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-11771 | 7.0 | 30.6 | OpenVPN | OpenVPN | CWE-121 | OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows atta… |
| CVE-2026-54885 | 6.9 | 30.4 | malach-it | boruta | CWE-918 | Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri f… |
| CVE-2026-67351 | 8.7 | 30.1 | s9y | Serendipity | CWE-304 | Serendipity < 2.6.1 Authentication Bypass via Username Collision |
| CVE-2026-48448 | 8.6 | 30.1 | Adobe | Adobe Campaign Classic | CWE-89 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-17669 | 9.6 | 30.0 | Chrome | CWE-693 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-17670 | 9.6 | 30.0 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-17671 | 9.6 | 30.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-17672 | 9.6 | 30.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromecast in Google Chrome pri… | |
| CVE-2026-17673 | 9.6 | 30.0 | Chrome | CWE-190 | Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a re… | |
| CVE-2026-17676 | 9.6 | 30.0 | Chrome | CWE-693 | Inappropriate implementation in ANGLE in Google Chrome on Android prior to 15… | |
| CVE-2026-17682 | 9.6 | 30.0 | Chrome | CWE-190 | Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a r… | |
| CVE-2026-17684 | 9.6 | 30.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-17688 | 9.6 | 30.0 | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-17691 | 9.6 | 30.0 | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.… | |
| CVE-2026-17692 | 9.6 | 30.0 | Chrome | CWE-416 | Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.792… | |
| CVE-2026-17695 | 9.6 | 30.0 | Chrome | CWE-693 | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.… | |
| CVE-2026-17704 | 9.6 | 30.0 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-17708 | 9.6 | 30.0 | Chrome | CWE-416 | Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-17710 | 9.6 | 30.0 | Chrome | CWE-693 | Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.… | |
| CVE-2026-17713 | 9.6 | 30.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Accessibility in Google Chrome … | |
| CVE-2026-17717 | 9.6 | 30.0 | Chrome | CWE-190 | Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a r… | |
| CVE-2026-17677 | 8.8 | 30.0 | Chrome | CWE-693 | Inappropriate implementation in ANGLE in Google Chrome on Android prior to 15… | |
| CVE-2026-17678 | 8.8 | 30.0 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a… | |
| CVE-2026-35847 | 9.8 | 29.8 | n/a | n/a | CWE-77 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbit… |
| CVE-2026-6540 | 7.9 | 29.8 | Tigera | Calico | CWE-22 | L7 policy bypass via unnormalized HTTP path matching |
| CVE-2026-16529 | 7.5 | 29.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Pcp: pcp: denial of service due to signed integer overflow |
| CVE-2026-17751 | 8.8 | 29.6 | Chrome | CWE-269 | Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922… | |
| CVE-2026-23981 | 5.3 | 29.5 | Apache Software Foundation | Apache Superset | CWE-285 | Apache Superset: Improper Authorization in Chart Update allowing Dashboard Mo… |
| CVE-2026-66421 | 8.8 | 29.4 | tugcantopaloglu | openclaw-dashboard | CWE-79 | OpenClaw Dashboard Stored XSS via lastMessage Session Field |
| CVE-2026-22620 | 8.6 | 29.3 | Eaton | PADM | CWE-89 | Improper input validation in the authentication component of Eaton's Tripp Li… |
| CVE-2026-17896 | 7.5 | 29.3 | Chrome | CWE-416 | Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-18362 | 5.9 | 28.8 | dfir-iris | iris-web | CWE-770 | DFIR-IRIS Missing Brute Force Protection in User Authentication |
| CVE-2026-16531 | 5.3 | 28.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-22 | Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet |
| CVE-2026-17701 | 9.6 | 28.4 | Chrome | CWE-125 | Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac p… | |
| CVE-2026-17712 | 8.8 | 28.4 | Chrome | CWE-362 | Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote … | |
| CVE-2026-17686 | 8.1 | 28.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Passwords in Google Chrome prio… | |
| CVE-2026-12946 | 9.9 | 28.2 | IBM | Langflow OSS | CWE-94 | Remote Code Execution in CUGA Component CodeAgent |
| CVE-2026-17778 | 8.8 | 28.0 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed … | |
| CVE-2026-17679 | 6.5 | 28.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Print Preview in Google Chrome … | |
| CVE-2026-17683 | 6.5 | 28.0 | Chrome | CWE-200 | Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72… | |
| CVE-2026-17650 | 8.3 | 28.0 | Chrome | CWE-416 | Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed… | |
| CVE-2026-17653 | 8.3 | 28.0 | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remo… | |
| CVE-2026-48910 | 6.5 | 27.9 | Apache Software Foundation | Apache JSPWiki | CWE-80 | Apache JSPWiki: Markdown parser allows XSS injection in Markdown error proces… |
| CVE-2026-17660 | 8.3 | 27.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … | |
| CVE-2026-17663 | 8.3 | 27.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in GPU in Google Chrome on Android… | |
| CVE-2026-11536 | 8.5 | 27.4 | IBM | WebSphere Application Server | CWE-502 | IBM WebSphere Application Server is affected by a remote code execution vulne… |
| CVE-2026-58046 | 9.9 | 27.3 | WebPros | Plesk | CWE-89 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticate… |
| CVE-2026-41186 | 6.0 | 27.3 | Tigera | Calico | CWE-200 | Unauthenticated Go pprof exposure in Calico debug server |
| CVE-2026-17758 | 9.6 | 27.2 | Chrome | CWE-122 | Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed … | |
| CVE-2026-68501 | 6.5 | 27.1 | Sylius | MolliePlugin | CWE-639 | Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII |
| CVE-2026-17729 | 8.8 | 27.0 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… | |
| CVE-2026-17935 | 8.8 | 26.8 | Chrome | CWE-122 | Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowe… | |
| CVE-2026-13395 | 8.6 | 26.8 | Unknown | Online Scheduling and Appointment Booking System | CWE-89 | Bookly < 27.8 - Unauthenticated SQL Injection via staff_id |
| CVE-2026-18064 | 8.2 | 26.8 | NASA | Core Flight System (cFS) Health & Safety (HS) Application | CWE-476 | NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer D… |
| CVE-2026-66418 | 9.3 | 26.7 | tugcantopaloglu | openclaw-dashboard | CWE-79 | OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field |
| CVE-2026-13379 | 5.1 | 26.7 | OpenVPN | OpenVPN | CWE-125 | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows re… |
| CVE-2026-62663 | 7.5 | 26.4 | masci | banks | CWE-22 | Banks: Arbitrary File Read via Path Traversal in Media Filters (image/audio/v… |
| CVE-2026-15976 | 9.8 | 26.1 | SGLang | SGLang | CWE-502 | CVE-2026-15976 |
| CVE-2026-17868 | 8.8 | 26.1 | Chrome | CWE-269 | Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.7… | |
| CVE-2026-54722 | 8.7 | 25.7 | HackingRepo | dssrf-js | CWE-76 | dssrf: there a critical security bug with remove_at_symbol_in_string |
| CVE-2026-44091 | 8.8 | 25.6 | Phoenix Contact | CHARX SEC-3150 | CWE-501 | Creation of a new configuration by posting a malicious ID to MQTT |
| CVE-2026-17759 | 6.5 | 25.5 | Chrome | CWE-457 | Uninitialized Use in Codecs in Google Chrome prior to 151.0.7922.72 allowed a… | |
| CVE-2026-17657 | 8.3 | 25.3 | Chrome | CWE-416 | Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed … | |
| CVE-2025-65336 | 9.8 | 24.9 | n/a | n/a | CWE-89 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL I… |
| CVE-2026-17674 | 6.5 | 24.6 | Chrome | CWE-693 | Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 … | |
| CVE-2026-17703 | 6.5 | 24.6 | Chrome | CWE-602 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… | |
| CVE-2026-16971 | 5.9 | 24.6 | dfir-iris | iris-web | CWE-770 | DFIR-IRIS Missing Brute Force Protection in OTP Validation |
| CVE-2026-17989 | 8.8 | 24.4 | Chrome | CWE-843 | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… | |
| CVE-2026-14318 | 6.8 | 24.4 | Unknown | GiveWP | CWE-79 | GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings |
| CVE-2026-17675 | 9.6 | 24.3 | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed … | |
| CVE-2026-17718 | 9.6 | 24.3 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-17721 | 9.6 | 24.3 | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed … | |
| CVE-2026-17726 | 9.6 | 24.3 | Chrome | CWE-190 | Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 … | |
| CVE-2026-17727 | 9.6 | 24.3 | Chrome | CWE-787 | Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.… | |
| CVE-2026-17738 | 9.6 | 24.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Payments in Google Chrome prior… | |
| CVE-2026-17768 | 9.6 | 24.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebSockets in Google Chrome pri… | |
| CVE-2026-17801 | 9.6 | 24.3 | Chrome | CWE-125 | Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72… | |
| CVE-2026-17804 | 9.6 | 24.3 | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-17752 | 8.8 | 24.3 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowe… | |
| CVE-2026-17784 | 8.8 | 24.3 | Chrome | CWE-416 | Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowe… | |
| CVE-2026-17967 | 8.8 | 24.3 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.… | |
| CVE-2026-15397 | 7.2 | 24.1 | wpswings | Subscriptions for WooCommerce | CWE-862 | Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticat… |
| CVE-2026-12733 | 7.5 | 24.1 | IBM | DataPower Gateway 10.6CD | CWE-770 | IBM DataPower Gateway affected by denial of service |
| CVE-2026-67345 | 8.5 | 23.7 | dromara | MaxKey | CWE-183 | MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft |
| CVE-2026-10842 | 7.5 | 23.7 | IBM | WebSphere Application Server | CWE-289 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-17689 | 4.3 | 23.7 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-44107 | 8.7 | 23.6 | Phoenix Contact | CHARX SEC-3150 | CWE-749 | Exposed Reboot via Modbus |
| CVE-2026-67246 | 6.9 | 23.3 | ASUSTOR Inc. | ADM | CWE-22 | A path traversal vulnerability was found in the Wallpaper component of ADM |
| CVE-2026-17875 | 8.8 | 23.1 | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a re… | |
| CVE-2026-22622 | 8.8 | 23.1 | Eaton | PADM | CWE-78 | Improper input validation in one of the session management interface of Eaton… |
| CVE-2026-9322 | 7.5 | 23.1 | IBM | WebSphere Application Server | CWE-400 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-11897 | 7.5 | 23.0 | IBM | WebSphere Application Server - Liberty | CWE-770 | IBM WebSphere Application Server Liberty is affected by a denial of service v… |
| CVE-2026-17887 | 7.5 | 23.0 | Chrome | CWE-416 | Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-52539 | 9.1 | 22.9 | n/a | n/a | CWE-798 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_… |
| CVE-2026-17807 | 8.8 | 22.9 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… | |
| CVE-2026-17836 | 8.8 | 22.9 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote… | |
| CVE-2026-17918 | 8.8 | 22.9 | Chrome | CWE-416 | Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remo… | |
| CVE-2026-17698 | 7.5 | 22.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in UI in Google Chrome on Android … | |
| CVE-2026-67247 | 7.1 | 22.8 | ASUSTOR Inc. | ADM | CWE-22 | A path traversal vulnerability was found in the IHM Log handling of ADM |
| CVE-2026-59881 | 6.9 | 22.7 | aio-libs | aiohttp | CWE-20 | AIOHTTP: WebSocket client accepts compressed frames without negotiated permes… |
| CVE-2026-65635 | 8.3 | 22.7 | malach-it | boruta | CWE-653 | Boruta dynamic client registration allows creation of over-privileged OAuth c… |
| CVE-2026-67207 | 8.7 | 22.5 | wolfcms | wolfcms | CWE-697 | Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController |
| CVE-2026-61536 | 7.5 | 22.5 | masci | banks | CWE-94 | Banks: Unsafe importlib.import_module of attacker-controlled Tool.import_path… |
| CVE-2026-16530 | 6.5 | 22.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Pcp: pcp: remote denial of service and information leakage |
| CVE-2026-17796 | 6.5 | 22.5 | Chrome | CWE-1300 | Side-channel information leakage in WebXR in Google Chrome prior to 151.0.792… | |
| CVE-2026-17800 | 6.5 | 22.5 | Chrome | CWE-1300 | Inappropriate implementation in MediaRecording in Google Chrome prior to 151.… | |
| CVE-2026-18363 | 9.1 | 22.4 | Enhancesoft LLC | osTicket | CWE-640 | Weak password recovery mechanism in osTicket by Enhancesoft LLC |
| CVE-2026-15153 | 6.8 | 22.3 | Unknown | WP Hotel Booking | CWE-89 | WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search |
| CVE-2026-12687 | 7.5 | 22.2 | Unknown | ProfileGrid | CWE-269 | ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted… |
| CVE-2026-17709 | 9.6 | 22.0 | Chrome | CWE-362 | Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a re… | |
| CVE-2026-17711 | 9.6 | 22.0 | Chrome | CWE-362 | Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a re… | |
| CVE-2026-13435 | 9.9 | 22.0 | IBM | Langflow OSS | CWE-94 | Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure |
| CVE-2026-15978 | 7.5 | 21.9 | SGLang | SGLang | CWE-306 | CVE-2026-15978 |
| CVE-2026-57862 | 8.4 | 21.8 | Kanboard | Kanboard | CWE-918 | Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation |
| CVE-2026-11904 | 5.3 | 21.8 | IBM | Verify Identity Access | CWE-209 | Security vulnerabilities have been found in IBM Verify Identity Access and IB… |
| CVE-2026-17803 | 9.6 | 21.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in Save to Drive in Google Chrome … | |
| CVE-2026-17956 | 8.8 | 21.6 | Chrome | CWE-269 | Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.79… | |
| CVE-2026-17969 | 8.8 | 21.6 | Chrome | CWE-269 | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.792… | |
| CVE-2026-17735 | 8.7 | 21.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in BFCache in Google Chrome prior … | |
| CVE-2026-67346 | 7.7 | 21.5 | kyegomez | swarms | CWE-918 | Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass |
| CVE-2026-54366 | 8.7 | 21.2 | Gladinet | CentreStack | CWE-611 | CentreStack < 17.4 XXE via SharePoint Storage Configuration |
| CVE-2026-67349 | 8.7 | 21.1 | opencost | opencost | CWE-306 | OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass |
| CVE-2026-17696 | 4.3 | 21.0 | Chrome | CWE-1300 | Side-channel information leakage in Media in Google Chrome prior to 151.0.792… | |
| CVE-2026-17700 | 4.3 | 21.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Actor in Google Chrome prior to… | |
| CVE-2026-17706 | 4.3 | 21.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome on Windo… | |
| CVE-2026-66415 | 8.4 | 20.9 | Leantime | Leantime | CWE-918 | Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::… |
| CVE-2026-56428 | 8.1 | 20.9 | Bosch | BSH ELP (Electronic Platform) Modules | CWE-286 | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-… |
| CVE-2026-47876 | 9.3 | 20.6 | VMware | Cloud Foundation | CWE-787 | VMXNET3 out-of-bounds write vulnerability |
| CVE-2026-17951 | 8.8 | 20.4 | Chrome | CWE-122 | Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowe… | |
| CVE-2026-55768 | 8.7 | 20.3 | allinurl | goaccess | CWE-681 | GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame lengt… |
| CVE-2026-12562 | 8.7 | 20.3 | Toptech Systems | RCU II+ | CWE-306 | Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical… |
| CVE-2026-66360 | 8.7 | 20.3 | MZ Automation GmbH | libiec61850 | CWE-125 | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-67244 | 8.6 | 20.2 | ASUSTOR Inc. | ADM | CWE-134 | A format string vulnerability was found in the Notification OAuth settings of… |
| CVE-2026-17722 | 8.3 | 20.3 | Chrome | CWE-416 | Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.… | |
| CVE-2026-17723 | 8.3 | 20.3 | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 al… | |
| CVE-2026-44100 | 8.8 | 20.2 | Phoenix Contact | CHARX SEC-3150 | CWE-306 | JupiCore charging point reconfiguration without auth |
| CVE-2026-67248 | 8.7 | 20.1 | ASUSTOR Inc. | ADM | CWE-121 | A stack-based buffer overflow vulnerability was found in the File Explorer on… |
| CVE-2026-67347 | 6.1 | 20.1 | vendurehq | vendure | CWE-863 | Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset … |
| CVE-2026-17847 | 9.6 | 20.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-17856 | 9.6 | 20.0 | Chrome | CWE-693 | Inappropriate implementation in Network in Google Chrome on Mac prior to 151.… | |
| CVE-2026-17865 | 9.6 | 20.0 | Chrome | CWE-693 | Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0… | |
| CVE-2026-17884 | 8.8 | 20.0 | Chrome | CWE-416 | Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allo… | |
| CVE-2026-17886 | 8.8 | 20.0 | Chrome | CWE-416 | Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed … | |
| CVE-2026-17894 | 8.8 | 20.0 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allo… | |
| CVE-2026-17690 | 6.5 | 19.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in PDF in Google Chrome on Android… | |
| CVE-2026-17756 | 6.5 | 19.6 | Chrome | CWE-602 | Insufficient policy enforcement in Presentation in Google Chrome prior to 151… | |
| CVE-2026-17764 | 6.5 | 19.6 | Chrome | CWE-693 | Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72… | |
| CVE-2026-17814 | 6.5 | 19.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-58040 | 6.3 | 19.6 | nodejs | node | CWE-297 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reu… |
| CVE-2026-17971 | 8.8 | 19.4 | Chrome | CWE-125 | Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72… | |
| CVE-2026-17946 | 6.5 | 19.2 | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a r… | |
| CVE-2026-17968 | 6.5 | 19.2 | Chrome | CWE-457 | Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72… | |
| CVE-2026-14356 | 8.8 | 19.1 | fleekdash | FleekDash V2 | CWE-862 | FleekDash V2 <= 2.6.2.2 - Missing Authorization to Authenticated (Subscriber+… |
| CVE-2026-17950 | 8.8 | 19.1 | Chrome | CWE-269 | Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to… | |
| CVE-2026-62246 | 8.5 | 19.1 | clastix | kamaji | CWE-284 | Kamaji: TenantControlPlane namespace/name collision binds two tenants to the … |
| CVE-2026-18360 | 7.6 | 19.0 | dfir-iris | iris-web | CWE-79 | DFIR-IRIS Stored XSS in Custom Attributes |
| CVE-2026-18361 | 7.6 | 19.0 | dfir-iris | iris-web | CWE-79 | DFIR-IRIS Stored XSS in Datastore Upload |
| CVE-2026-17816 | 7.5 | 19.0 | Chrome | CWE-269 | Insufficient policy enforcement in Speech in Google Chrome on Android prior t… | |
| CVE-2026-18382 | 6.8 | 19.0 | Red Hat | Cost Management Metrics Operator | CWE-918 | Project-koku/koku-metrics-operator: koku-metrics-operator: service-account cl… |
| CVE-2026-64816 | 7.1 | 18.8 | CyberTimon | RapidRAW | CWE-73 | RapidRAW < 1.6.0 NTLMv2 Credential Leak via UNC Path in lutPath |
| CVE-2026-65834 | 6.8 | 18.8 | projectcapsule | capsule | CWE-20 | Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validati… |
| CVE-2026-17740 | 4.3 | 18.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-17757 | 4.3 | 18.6 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a r… | |
| CVE-2026-17771 | 4.3 | 18.6 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a r… | |
| CVE-2026-17785 | 4.3 | 18.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-17790 | 4.3 | 18.5 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72… | |
| CVE-2026-17808 | 4.3 | 18.5 | Chrome | CWE-457 | Uninitialized Use in WebGL in Google Chrome on Android prior to 151.0.7922.72… | |
| CVE-2026-17810 | 4.3 | 18.6 | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a r… | |
| CVE-2026-18186 | 7.1 | 18.5 | ASUSTOR Inc. | ADM | CWE-134 | A stored format string vulnerability was found in the FTP Backup on the ADM |
| CVE-2026-18187 | 7.1 | 18.5 | ASUSTOR Inc. | ADM | CWE-134 | A format string vulnerability was found in the Internal Backup on the ADM |
| CVE-2026-18188 | 7.1 | 18.5 | ASUSTOR Inc. | ADM | CWE-134 | A format string vulnerability was found in the Rsync Backup on the ADM |
| CVE-2026-61893 | 6.9 | 18.3 | MZ Automation | lib60870 | CWE-125 | MZ Automation lib60870 Out-of-bounds Read |
| CVE-2026-63033 | 6.9 | 18.3 | MZ Automation | lib60870 | CWE-125 | MZ Automation lib60870 Out-of-bounds Read |
| CVE-2026-17791 | 6.5 | 18.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Payments in Google Chrome prior… | |
| CVE-2026-17792 | 6.5 | 18.4 | Chrome | CWE-451 | Inappropriate implementation in Credential Management in Google Chrome prior … | |
| CVE-2026-17793 | 6.5 | 18.4 | Chrome | CWE-451 | Inappropriate implementation in Messages in Google Chrome on Android prior to… | |
| CVE-2026-17831 | 6.5 | 18.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Passwords in Google Chrome prio… | |
| CVE-2024-25039 | 7.5 | 18.2 | IBM | Engineering Requirements Management DOORS and DOORS Web Access | CWE-400 | IBM Engineering Requirements Management DOORS and DOORS Web Access is affecte… |
| CVE-2026-54715 | 7.1 | 18.2 | allinurl | goaccess | CWE-122 | GoAccess: Heap Out-of-Bounds Write in parse_browser() |
| CVE-2026-17892 | 6.5 | 18.2 | Chrome | CWE-200 | Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72… | |
| CVE-2026-55777 | 5.3 | 18.2 | allinurl | goaccess | CWE-125 | GoAccess: Out-of-bounds heap read in parse_ios() via crafted User-Agent leads… |
| CVE-2026-17830 | 6.5 | 18.1 | Chrome | CWE-284 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-17869 | 8.1 | 18.0 | Chrome | CWE-125 | Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a… | |
| CVE-2025-69930 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69931 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69933 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69934 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69935 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in t… |
| CVE-2025-69936 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69937 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69938 | 9.8 | 17.9 | n/a | n/a | CWE-89 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in … |
| CVE-2025-69941 | 9.8 | 17.9 | n/a | n/a | CWE-89 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in… |
| CVE-2025-69947 | 9.8 | 17.9 | n/a | n/a | CWE-89 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in… |
| CVE-2026-4978 | 9.8 | 17.9 | UMAI Vision | Traffic Analysis System | CWE-89 | SQLi in UMAI Vision's Traffic Analysis System |
| CVE-2026-14923 | 6.5 | 17.7 | Unknown | Sync Post With Other Site | CWE-863 | Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modi… |
| CVE-2026-17992 | 6.5 | 17.7 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 … | |
| CVE-2026-17851 | 4.3 | 17.7 | Chrome | CWE-1300 | Side-channel information leakage in Autofill in Google Chrome prior to 151.0.… | |
| CVE-2026-17859 | 4.3 | 17.7 | Chrome | CWE-1300 | Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922… | |
| CVE-2026-44094 | 8.3 | 17.7 | Phoenix Contact | CHARX SEC-3150 | CWE-636 | Fallback to second RAUC slot with default credentials |
| CVE-2026-12722 | 8.2 | 17.2 | FTC Software IT Services | FTC E-Commerce Management Panel | CWE-306 | Authentication Bypass in FTC Software's E-Commerce Management Panel |
| CVE-2026-17848 | 9.6 | 17.2 | Chrome | CWE-20 | Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-17832 | 9.6 | 16.9 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-17834 | 9.6 | 16.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Passwords in Google Chrome prio… | |
| CVE-2026-17837 | 9.6 | 16.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-17924 | 9.6 | 16.9 | Chrome | CWE-416 | Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remot… | |
| CVE-2026-17940 | 9.6 | 16.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Picture-in-Picture in Google Ch… | |
| CVE-2026-17947 | 9.6 | 16.9 | Chrome | CWE-416 | Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed … | |
| CVE-2026-67348 | 8.6 | 17.0 | julep-ai | julep | CWE-639 | Julep Insecure Direct Object Reference via GET /executions/{execution_id} |
| CVE-2026-12500 | 7.5 | 17.0 | Unknown | WP Travel Engine | CWE-862 | WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update |
| CVE-2026-13178 | 7.5 | 17.0 | Unknown | Eventin | CWE-639 | Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation |
| CVE-2026-54364 | 6.9 | 16.8 | Gladinet | CentreStack | CWE-116 | CentreStack < 17.4 Session Injection via SelectProvider.aspx |
| CVE-2026-63550 | 7.1 | 16.5 | MZ Automation GmbH | libiec61850 | CWE-125 | MZ Automation libiec61850 Out-of-bounds Read |
| CVE-2026-16092 | 6.5 | 16.5 | labelblanc | Improved Save Button | CWE-89 | Improved Save Button <= 1.2.1 - Authenticated (Author+) Second-Order SQL Inje… |
| CVE-2026-13345 | 5.3 | 16.0 | Unknown | Essential Addons for Elementor | CWE-639 | Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Privat… |
| CVE-2026-58066 | 9.8 | 15.9 | Rocket.Chat | Rocket.Chat | CWE-287 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2… |
| CVE-2026-44097 | 5.3 | 15.8 | Phoenix Contact | CHARX SEC-3150 | CWE-434 | File Upload vulnerability |
| CVE-2026-17730 | 4.3 | 15.8 | Chrome | CWE-1300 | Side-channel information leakage in Autofill in Google Chrome prior to 151.0.… | |
| CVE-2026-17760 | 4.3 | 15.8 | Chrome | CWE-1300 | Side-channel information leakage in NoStatePrefetch in Google Chrome prior to… | |
| CVE-2026-17767 | 4.3 | 15.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebView in Google Chrome on And… | |
| CVE-2026-17769 | 4.3 | 15.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in Cast in Google Chrome prior to … | |
| CVE-2026-17772 | 4.3 | 15.8 | Chrome | CWE-125 | Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a… | |
| CVE-2026-17773 | 4.3 | 15.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in Cast in Google Chrome prior to … | |
| CVE-2026-17795 | 4.3 | 15.8 | Chrome | CWE-20 | Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.… | |
| CVE-2026-17991 | 9.6 | 15.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in AI in Google Chrome prior to 15… | |
| CVE-2026-18017 | 8.8 | 15.6 | Chrome | CWE-416 | Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remo… | |
| CVE-2026-67527 | 7.6 | 15.6 | opf | openproject | CWE-862 | OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via… |
| CVE-2026-17779 | 5.4 | 15.6 | Chrome | CWE-693 | Inappropriate implementation in Site Isolation in Google Chrome prior to 151.… | |
| CVE-2026-14222 | 3.8 | 15.6 | Unknown | Easy Appointments | CWE-284 | Easy Appointments < 3.12.28 - Contributor+ Connection Deletion via Missing Au… |
| CVE-2026-17749 | 9.6 | 15.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-44104 | 9.3 | 15.5 | Phoenix Contact | CHARX SEC-3150 | CWE-347 | ControllerAgent does not perform validation of firmware |
| CVE-2026-17786 | 8.8 | 15.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-15977 | 7.5 | 15.5 | SGLang | SGLang | CWE-522 | CVE-2026-15977 |
| CVE-2025-36374 | 5.5 | 15.5 | IBM | DataPower Gateway 10.6CD | CWE-611 | IBM DataPower Gateway affected by XML external entity injection |
| CVE-2026-17913 | 5.4 | 15.3 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-14188 | 2.7 | 15.4 | Unknown | Easy Appointments | CWE-200 | Easy Appointments < 3.12.28 - Contributor+ Customer Data Disclosure |
| CVE-2026-18353 | 8.8 | 15.3 | Eclipse Foundation | Eclipse CSI - PIA | CWE-918 | Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass |
| CVE-2026-48499 | 9.3 | 15.1 | activepieces | activepieces | CWE-200 | Activepieces: Cross-tenant data exposure and code injection via the Code piec… |
| CVE-2026-17840 | 6.5 | 15.1 | Chrome | CWE-451 | Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 al… | |
| CVE-2026-17850 | 6.5 | 15.0 | Chrome | CWE-346 | Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7… | |
| CVE-2026-17852 | 6.5 | 15.0 | Chrome | CWE-346 | Inappropriate implementation in Media Router in Google Chrome prior to 151.0.… | |
| CVE-2026-17662 | 4.3 | 15.1 | Chrome | CWE-346 | Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7… | |
| CVE-2026-17693 | 4.3 | 15.1 | Chrome | CWE-346 | Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0… | |
| CVE-2026-17934 | 4.3 | 15.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-17930 | 7.5 | 14.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-17824 | 6.5 | 14.9 | Chrome | CWE-284 | Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 15… | |
| CVE-2026-17873 | 6.5 | 14.9 | Chrome | CWE-284 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… | |
| CVE-2026-17975 | 6.5 | 15.0 | Chrome | CWE-200 | Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.79… | |
| CVE-2026-67529 | 4.3 | 14.9 | opf | openproject | CWE-200 | OpenProject: Private work package subject/identity disclosure through the glo… |
| CVE-2026-17995 | 8.1 | 14.8 | Chrome | CWE-125 | Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-44103 | 6.9 | 14.8 | Phoenix Contact | CHARX SEC-3150 | CWE-434 | JupiCore does not perform validation of firmware |
| CVE-2026-14980 | 8.8 | 14.7 | IBM | WebSphere Application Server - Liberty | CWE-269 | IBM WebSphere Application Server Liberty is affected by a cross-site request … |
| CVE-2026-17858 | 4.3 | 14.4 | Chrome | CWE-457 | Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72… | |
| CVE-2026-17889 | 4.3 | 14.4 | Chrome | CWE-457 | Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a … | |
| CVE-2026-44093 | 8.5 | 14.2 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via… |
| CVE-2026-44095 | 8.5 | 14.2 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | Local Privilege Escalation via Network scripts |
| CVE-2026-44096 | 8.5 | 14.2 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | udhcpc Privilege Escalation |
| CVE-2026-44099 | 8.5 | 14.2 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | Local Privilege Escalation via pppd password injection |
| CVE-2026-44106 | 8.5 | 14.2 | Phoenix Contact | CHARX SEC-3150 | CWE-78 | Local Privilege Escalation vulnerability in /etc/init.d/user-applications via… |
| CVE-2026-14305 | 5.3 | 14.1 | Unknown | WP Delicious | CWE-287 | WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe… |
| CVE-2026-17782 | 4.3 | 14.1 | Chrome | CWE-451 | Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.… | |
| CVE-2026-17794 | 4.3 | 14.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Mobile in Google Chrome on Andr… | |
| CVE-2026-17938 | 4.3 | 14.1 | Chrome | CWE-451 | Inappropriate implementation in FullScreen in Google Chrome on Android prior … | |
| CVE-2026-17941 | 4.3 | 14.1 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-18378 | 6.8 | 13.9 | Red Hat | Cost Management Metrics Operator | CWE-918 | Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secre… |
| CVE-2026-15382 | 6.5 | 13.5 | Unknown | Ultimate Addons for WPBakery Page Builder | CWE-73 | Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom I… |
| CVE-2026-17849 | 4.3 | 13.5 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-17805 | 6.5 | 13.4 | Chrome | CWE-602 | Insufficient policy enforcement in Glic in Google Chrome on Android prior to … | |
| CVE-2026-17813 | 6.5 | 13.4 | Chrome | CWE-602 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… | |
| CVE-2026-17921 | 6.5 | 13.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Navigation in Google Chrome pri… | |
| CVE-2026-17926 | 6.5 | 13.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-17931 | 6.5 | 13.4 | Chrome | CWE-693 | Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922… | |
| CVE-2026-17953 | 6.5 | 13.4 | Chrome | CWE-602 | Insufficient policy enforcement in WebView in Google Chrome on Android prior … | |
| CVE-2026-17659 | 4.2 | 13.4 | Chrome | CWE-693 | Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0… | |
| CVE-2026-17987 | 9.6 | 13.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Notifications in Google Chrome … | |
| CVE-2026-17990 | 9.6 | 13.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAuthn in Google Chrome prior… | |
| CVE-2026-14226 | 4.3 | 13.3 | Unknown | Easy Appointments | CWE-200 | Easy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure vi… |
| CVE-2026-14231 | 4.3 | 13.3 | Unknown | LifterLMS | CWE-200 | LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select… |
| CVE-2026-15235 | 4.3 | 13.3 | Unknown | MotoPress Hotel Booking | CWE-200 | Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin … |
| CVE-2026-18012 | 8.8 | 13.2 | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a re… | |
| CVE-2026-17920 | 8.8 | 13.0 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attac… | |
| CVE-2026-14227 | 6.9 | 13.0 | MikroTik | RouterOS | CWE-613 | Insufficient session expiration in MikroTik RouterOS |
| CVE-2026-10545 | 7.5 | 12.9 | IBM | Planning Analytics Local | CWE-601 | IBM Planning Analytics Local is affected by Open Redirect |
| CVE-2026-11782 | 5.9 | 12.8 | Unknown | Points and Rewards for WooCommerce | CWE-284 | Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User … |
| CVE-2026-13143 | 5.3 | 12.9 | Unknown | WP Travel | CWE-290 | WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN |
| CVE-2026-17855 | 9.6 | 12.8 | Chrome | CWE-362 | Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a rem… | |
| CVE-2026-41187 | 6.2 | 12.8 | Tigera | Calico | CWE-285 | Calico Tier Authorization Bypass via DeleteCollection |
| CVE-2026-17914 | 5.3 | 12.7 | Chrome | CWE-1300 | Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922… | |
| CVE-2026-17949 | 4.3 | 12.7 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.72 a… | |
| CVE-2026-68562 | 6.2 | 12.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-610 | Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information… |
| CVE-2026-17743 | 6.5 | 12.5 | Chrome | CWE-346 | Insufficient policy enforcement in ControlledFrame in Google Chrome prior to … | |
| CVE-2026-17748 | 6.5 | 12.5 | Chrome | CWE-346 | Inappropriate implementation in Extensions in Google Chrome prior to 151.0.79… | |
| CVE-2026-17754 | 6.5 | 12.5 | Chrome | CWE-346 | Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72… | |
| CVE-2026-17787 | 6.5 | 12.5 | Chrome | CWE-346 | Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922… | |
| CVE-2026-17819 | 6.5 | 12.6 | Chrome | CWE-451 | Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.… | |
| CVE-2026-17828 | 6.5 | 12.6 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-17835 | 6.5 | 12.6 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-17838 | 6.5 | 12.6 | Chrome | CWE-451 | Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.… | |
| CVE-2026-17839 | 6.5 | 12.6 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-11707 | 9.3 | 12.4 | IBM | Tivoli System Automation Application Manager | CWE-79 | Multiple vulnerabilities have been identified in IBM WebSphere Application Se… |
| CVE-2026-17825 | 6.5 | 12.4 | Chrome | CWE-284 | Insufficient policy enforcement in Passwords in Google Chrome on Android prio… | |
| CVE-2026-17917 | 6.5 | 12.4 | Chrome | CWE-284 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… | |
| CVE-2025-51684 | 6.1 | 12.4 | n/a | n/a | CWE-79 | CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The ap… |
| CVE-2026-54365 | 8.7 | 12.3 | Gladinet | CentreStack | CWE-306 | CentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNam… |
| CVE-2026-17985 | 6.5 | 12.3 | Chrome | CWE-602 | Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.792… | |
| CVE-2026-17988 | 6.5 | 12.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Navigation in Google Chrome pri… | |
| CVE-2026-17747 | 4.2 | 12.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Payments in Google Chrome on An… |
Results continue: ranks 401–662.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-30 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.