boxscore/security
Friday, July 31, 2026 · all times UTC← 2026-07-30 · archive · 2026-08-01 →

183 CVEs published July 31, 2026: 26 critical, 66 high, 76 medium, 15 low; 0 in KEV; 2 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 158 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published6056880513892563
KEV catalog size1670

303 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux667158520711279802730.27.8.0016+426
microsoft65813611059293028378322.47.8.0039+439
google40341264104226157351.26.5.0022+400
apple167244566711229372.97.1.0027+130
red hat12322291099212400.07.1.0027+68
canonical330210000.07.8.0013+3
android010100161100.08.4.0171-1
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco8204620961365.08.2.1853+5
fortinet1118249028633.36.1.0054+10
palo alto networks1015017514213.34.7.0028+7
vmware121247012100.08.7.0044+12
f51540007120.09.2.04020
ivanti051000335100.010.0.8152-1
checkpoint3431003250.09.2.4696+2
broadcom2400204250.05.1.0877+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache10513724743904010.77.5.0051+89
mozilla67724226401300.09.1.0031+67
gitlab1315021014213.34.9.0029+13
wordpress3311105266.78.6.7310+3
docker030120100.05.7.0015-3
github220110000.06.1.0029+2
kubernetes110001000.02.4.0024+1
drupal01100051100.09.8.88320
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091113212539304574030.37.6.0031+1107
ibm1001083143340700.07.5.0026+92
adobe294010224075410.08.4.0039+22
progress232331550900.08.1.0032+23
solarwinds16201611011420.09.1.0050+15
atlassian3303001300.08.0.0026+3
zohocorp331110000.07.1.0048+3
veeam220110400.06.8.0016+2
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link78006126112.55.5.0073+7
hikvision6704202114.37.2.0025+6
bosch330300000.08.1.0028+3
schneider electric331200100.08.7.0020+3
honeywell110010000.06.9.0031+1
mitsubishi electric110100000.07.1.0013+1
rockwell automation111000000.09.2.0030+1
siemens010100100.08.7.00320
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb5757326253000.07.1.0025+57
netty194162771000.07.5.0046+5
grafana841214223000.06.5.0033+2
open ises037214210000.06.9.00210
erlang1432114143100.06.9.0033+7
regularlabs.com292961490000.07.5.0022+29
watchguard172811890400.07.3.0026+17
nlnet labs242704176000.05.9.0024+24

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1109
linux661
microsoft656
google403
apple167
red hat120
apache105
ibm100
mozilla67
surrealdb57
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven29
Go3
crates.io2
npm2
NuGet1
Packagist1
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-20316Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171717
CVE-2021-27102Accellion2021-11-171717
CVE-2021-27101Accellion2021-11-171717
CVE-2021-27103Accellion2021-11-171717
CVE-2021-21017Adobe2021-11-171717
CVE-2021-28550Adobe2021-11-171717
CVE-2021-42013Apache2021-11-171717
CVE-2021-41773Apache2021-11-171717
CVE-2021-30858Apple2021-11-171717
CVE-2021-30860Apple2021-11-171717

Transactions

EXPLOIT PUBLISHEDCVE-2009-3960. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2017-12615 (Apache Software Foundation Apache Tomcat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-47966. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-47246. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10685 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10686 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56968 (GNU SASL). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66066 (rails). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67206 (wolfcms). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67207 (wolfcms). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67345 (dromara MaxKey). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67347 (vendurehq vendure). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67348 (julep-ai julep). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67349 (opencost). Public exploit reference added.

DUE DATE PASSEDCVE-2026-16812 (Arista Networks VeloCloud Orchestrator On-Prem). CISA remediation deadline was July 30, 2026; still in catalog.

RESCOREDCVE-2023-27997 (Fortinet FortiOS-6K7K). CVSS 9.2 → 9.8 (NVD).

RESCOREDCVE-2023-4966 (Citrix NetScaler ADC). CVSS 9.4 → 7.5 (NVD).

RESCOREDCVE-2023-6507 (Python Software Foundation CPython). CVSS 6.1 → 4.9 (NVD).

RESCOREDCVE-2025-4526 (Dígitro NGC Explorer). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2025-4527 (Dígitro NGC Explorer). CVSS 6.3 → 2.9 (NVD).

RESCOREDCVE-2025-4528 (Dígitro NGC Explorer). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-56968 (GNU SASL). CVSS 3.7 → 5.3 (NVD).

Yesterday's Results

183 CVEs published. 25 box scores, 158 table rows — nothing truncated.

n/a n/a — TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0262   84.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Received
n/a n/a — TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0262   84.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Received
n/a n/a — TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0262   84.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Received
n/a n/a — TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the syste…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0255   83.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-77 · CNA: mitre · 1 reference · NVD status: Received
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0219   80.9     —
AFFECTED
  Product                                        Versions     Fixed
  Realtyna Organic IDX plugin + WPL Real Estate  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 31  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 6 references · NVD status: Deferred
n/a n/a — An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0115   64.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-94 · CNA: mitre · 4 references · NVD status: Received
TP-Link Systems Inc. AXE75 V1 — Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   H   H   H    8.5   .0113   63.7     —
AFFECTED
  Product   Versions     Fixed
  AXE75 V1  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jul 31  Published (CNA: TPLink)
CWE-78 · CNA: TPLink · 3 references · NVD status: Analyzed
Hikvision DS-3WAP521-SI — Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient in…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0089   56.5     —
AFFECTED
  Product         Versions                             Fixed
  DS-3WAP521-SI   V1.1.6601 build251223 and earlier –  —
  DS-3WAP522-SI   V1.1.6601 build251223 and earlier –  —
  DS-3WAP621E-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WAP622E-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WAP623E-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WAP622G-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WG105G-SI   V1.1.6601 build251223 and earlier –  —
  DS-3WG105GP-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WG210GP-SI  V1.1.6601 build251223 and earlier –  —
  DS-3WG507G-SI   V1.1.6601 build251223 and earlier –  —
TIMELINE
  Jul 24  Reserved by CNA
  Jul 31  Published (CNA: hikvision)
CWE-78 · CNA: hikvision · 1 reference · NVD status: Received
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8 — 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0087   55.8     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Directory Server 11.7 E4S for RHEL 8                           unspecified  8080020260806114250.f969626e
  Red Hat Directory Server 11.9 for RHEL 8                               unspecified  8100020260803140625.37ed7c03
  Red Hat Directory Server 12.2 E4S for RHEL 9                           unspecified  9020020260730155601.1674d574
  Red Hat Directory Server 12.4 E4S for RHEL 9                           unspecified  9040020260810131422.1674d574
  Red Hat Enterprise Linux 10                                            unspecified  0:3.2.0-9.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.0.6-20.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.3.11.1-14.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  8100020260806150504.25e700aa
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  8040020260803141511.96015a92
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  8040020260803141511.96015a92
  + 11 more
TIMELINE
  Jul 14  Reserved by CNA
  Jul 31  Published (CNA: redhat)
CWE-121 · CNA: redhat · 17 references · NVD status: Modified
Apache Software Foundation Apache Zeppelin — Path traversal in NotebookRepo note and folder path composition
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0084   54.9     —
AFFECTED
  Product          Versions  Fixed
  Apache Zeppelin  0.9.0 –   —
TIMELINE
  May 7   Reserved by CNA
  Jul 31  Published (CNA: apache)
CWE-22 · CNA: apache · 4 references · NVD status: Analyzed
n/a n/a — An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0080   53.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 31  Published (CNA: mitre)
CWE-284 · CNA: mitre · 3 references · NVD status: Received
Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8 — 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0069   49.7     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Directory Server 11.7 E4S for RHEL 8                           unspecified  8080020260806114250.f969626e
  Red Hat Directory Server 11.9 for RHEL 8                               unspecified  8100020260803140625.37ed7c03
  Red Hat Directory Server 12.2 E4S for RHEL 9                           unspecified  9020020260730155601.1674d574
  Red Hat Directory Server 12.4 E4S for RHEL 9                           unspecified  9040020260810131422.1674d574
  Red Hat Enterprise Linux 10                                            unspecified  0:3.2.0-9.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.0.6-20.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.3.11.1-14.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  8100020260806150504.25e700aa
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  8040020260803141511.96015a92
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  8040020260803141511.96015a92
  + 11 more
TIMELINE
  Jun 9   Reserved by CNA
  Jul 31  Published (CNA: redhat)
CWE-90 · CNA: redhat · 18 references · NVD status: Modified
Comfy-Org ComfyUI — ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0066   48.7     —
AFFECTED
  Product  Versions    Fixed
  ComfyUI  < 0.28.0 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 31  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 3 references · NVD status: Received
Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Authenticated (Subscriber+) Arbitrary File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0063   47.3     —
AFFECTED
  Product                                        Versions     Fixed
  Realtyna Organic IDX plugin + WPL Real Estate  unspecified  —
TIMELINE
  Jul 19  Reserved by CNA
  Jul 31  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 5 references · NVD status: Deferred
Comfy-Org ComfyUI — ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0062   47.0     —
AFFECTED
  Product  Versions     Fixed
  ComfyUI  unspecified  —
TIMELINE
  Jul 31  Reserved by CNA
  Jul 31  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 4 references · NVD status: Received
WebPros cPanel — Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0056   44.0     —
AFFECTED
  Product     Versions     Fixed
  cPanel      unspecified  —
  WP Squared  unspecified  —
TIMELINE
  Jun 27  Reserved by CNA
  Jul 31  Published (CNA: hackerone)
CWE-89 · CNA: hackerone · 2 references · NVD status: Received
Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  N  H    6.5   .0053   42.4     —
AFFECTED
  Product    Versions    Fixed
  cloudreve  < 4.17.0 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 31  Published (CNA: GitHub_M)
CWE-400, CWE-409, CWE-770 · CNA: GitHub_M · 3 references · NVD status: Received
Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0052   41.9     —
AFFECTED
  Product        Versions  Fixed
  Apache Kyuubi  1.6.0 –   —
TIMELINE
  Jul 14  Reserved by CNA
  Jul 31  Published (CNA: apache)
CWE-22, CWE-27 · CNA: apache · 1 reference · NVD status: Analyzed
Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0052   41.9     —
AFFECTED
  Product                      Versions     Fixed
  gnome-remote-desktop         unspecified  —
  Red Hat Enterprise Linux 10  unspecified  0:49.3-4.el10_2
  Red Hat Enterprise Linux 8   unspecified  —
  Red Hat Enterprise Linux 9   unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Jul 31  Published (CNA: redhat)
CWE-400 · CNA: redhat · 3 references · NVD status: Awaiting Analysis
Hugging Face sentence-transformers — sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0052   41.8     —
AFFECTED
  Product                Versions     Fixed
  sentence-transformers  unspecified  —
TIMELINE
  Jul 31  Reserved by CNA
  Jul 31  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 5 references · NVD status: Received
WebPros cPanel — HTTP Smuggling in cPanel allows potential leak of credentials.
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   L   L   N    5.6   .0052   41.7     —
AFFECTED
  Product     Versions     Fixed
  cPanel      unspecified  —
  WP Squared  unspecified  —
TIMELINE
  Jun 27  Reserved by CNA
  Jul 31  Published (CNA: hackerone)
CWE-444 · CNA: hackerone · 2 references · NVD status: Received
Johnson Controls FM Systems Employee — FMS Employee Allows Upload of Unrestricted Files
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   L   L   N    4.8   .0050   40.8     —
AFFECTED
  Product              Versions     Fixed
  FM Systems Employee  unspecified  —
TIMELINE
  Jan 2   Reserved by CNA
  Jul 31  Published (CNA: jci)
CWE-434 · CNA: jci · 1 reference · NVD status: Analyzed
codeigniter4 CodeIgniter4 — CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0049   40.1     —
AFFECTED
  Product       Versions   Fixed
  CodeIgniter4  < 4.7.4 –  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 31  Published (CNA: GitHub_M)
CWE-434 · CNA: GitHub_M · 3 references · NVD status: Received
codeigniter4 CodeIgniter4 — CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0045   37.4     —
AFFECTED
  Product       Versions   Fixed
  CodeIgniter4  < 4.7.4 –  —
TIMELINE
  Jul 15  Reserved by CNA
  Jul 31  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 3 references · NVD status: Received
Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0043   36.0     —
AFFECTED
  Product            Versions     Fixed
  DMS+ (Non-Mobile)  unspecified  —
TIMELINE
  Jul 31  Reserved by CNA
  Jul 31  Published (CNA: twcert)
CWE-798 · CNA: twcert · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-566737.535.9Comfy-OrgComfyUICWE-22ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary fil…
CVE-2026-535516.935.8free5gcfree5gcCWE-20free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal serv…
CVE-2026-173468.735.4pgadmin.orgpgAdmin 4CWE-89pgAdmin 4: SQL injection via unescaped object names in index Statistics and p…
CVE-2026-535037.534.8thumborthumborCWE-20Thumbor convolution filter allows divide-by-zero in C extension leading to re…
CVE-2026-175669.434.0pgadmin.orgpgAdmin 4CWE-78pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guar…
CVE-2026-535108.132.8savonrbsavonCWE-94Savon::Model evaluates WSDL operation names as Ruby source
CVE-2026-629598.231.5coturncoturnCWE-125Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme…
CVE-2026-551008.731.4kyndryl-open-sourcehashi-vault-jsCWE-23hashi-vault-js has a path traversal and query parameter injection
CVE-2026-173519.431.3pgadmin.orgpgAdmin 4CWE-89pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL …
CVE-2026-632219.430.8codeigniter4CodeIgniter4CWE-89CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when u…
CVE-2026-175675.330.8wpmanageninjaFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-639Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via In…
CVE-2026-535734.830.8geonetworkcore-geonetworkCWE-601core-geonetwork has an Open Redirect Bypass
CVE-2026-554954.330.8cloudrevecloudreveCWE-22Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation…
CVE-2026-549095.330.2pionstunCWE-20Pion STUN vulnerable to remote denial of service via panic while parsing a ma…
CVE-2026-133927.230.1UnknownElementsKit Elementor AddonsCWE-94ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Cu…
CVE-2026-554964.329.2cloudrevecloudreveCWE-200Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search …
CVE-2026-646075.329.0Apache Software FoundationApache HttpComponents ClientCWE-772Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Erro…
CVE-2026-535028.728.8thumborthumborCWE-22Thumbor has path traversal via post-validation URL decoding bypass in file_lo…
CVE-2026-465945.127.8PHP JabbersPHP Poll ScriptCWE-79Reflected XSS in PHP Poll Script
CVE-2026-453765.527.2decidimdecidimCWE-89Decidim: Admin user search allows SQL injection through similarity-based sorting
CVE-2026-535057.526.8thumborthumborCWE-400Thumbor proportion filter allows unbounded post-transform resize leading to r…
CVE-2026-555027.126.8cloudrevecloudreveCWE-863Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials
CVE-2025-699469.826.6n/an/aCWE-89SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injecti…
CVE-2026-528567.526.4pterodactylwingsCWE-129Wings: Maliciously crafted packet during SFTP connection handshake causes den…
CVE-2026-535047.526.4thumborthumborCWE-400Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
CVE-2026-554994.326.0cloudrevecloudreveCWE-863Cloudreve: Broken access control in file event stream leaks activity events f…
CVE-2026-547259.624.8bank-vaultsvault-secrets-webhookCWE-918vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker UR…
CVE-2026-653107.524.6ANDRITZHIPASE-250CWE-306Missing authentication and permissive CORS policy
CVE-2026-143197.524.3UnknownGiveWPCWE-200GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure
CVE-2026-175619.824.1Innotim Software, Telecommunications and Consulting Trade Ltd. Co.Logsign SIEMCWE-94Unauthenticated RCE in Innotim Software's Logsign SIEM
CVE-2026-438309.824.1tbctbcCWE-77tbc
CVE-2026-535997.524.1redaxocoreCWE-434Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename t…
CVE-2026-181418.223.5Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9CWE-295Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via f…
CVE-2025-699489.823.3n/an/aCWE-89SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injecti…
CVE-2026-623236.323.2cloudrevecloudreveCWE-863Cloudreve: Unauthorized file write via WOPI view sessions whose access token …
CVE-2026-592325.323.1RoskusProspero Flow CRMCWE-79Stored Cross-site Scripting in Prospero Flow CRM lead name field
CVE-2026-127207.523.1UnknownKirkiCWE-502Kirki < 6.0.13 - Unauthenticated PHP Object Injection
CVE-2026-658415.322.6xdanjoditCWE-80Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses…
CVE-2026-465938.622.2PHP JabbersPHP Poll ScriptCWE-89Authenticated SQL Injection in PHP Poll Script
CVE-2026-184375.322.2mailerpressMailerPress – Newsletter, email marketing & AI automationCWE-862MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates
CVE-2026-173477.722.2pgadmin.orgpgAdmin 4CWE-78pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted usernam…
CVE-2026-143337.522.2UnknownDemiCWE-269Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticat…
CVE-2026-678229.822.0n/an/aCWE-121Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability …
CVE-2026-676078.222.0hfiref0xLightFTPCWE-367LightFTP 2.3.1 Race Condition DoS via worker_thread_cleanup
CVE-2026-106867.522.0zephyrprojectzephyrCWE-835Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet l…
CVE-2026-629997.522.0copier-orgcopierCWE-22Copier: Percent-encoded dot segments in template URLs can allow trusted-prefi…
CVE-2026-183946.921.9AWSStrands Agents ToolsCWE-863Incorrect authorization in Strands Agents Tools http_request proxy credential…
CVE-2026-547298.721.7HackingRepodssrf-jsCWE-918dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
CVE-2026-126958.121.7UnknownminiOrange 2FACWE-287miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret
CVE-2026-173499.321.3pgadmin.orgpgAdmin 4CWE-522pgAdmin 4: Adhoc server clone leaks another user's stored database credential…
CVE-2026-535008.221.2thumborthumborCWE-918Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing h…
CVE-2026-184816.220.7AWSAWS Ops WheelCWE-79Stored XSS in Participant URL Field leads to Account Takeover via Session Tok…
CVE-2025-676508.620.4PHP JabbersAppointment SchedulerCWE-89Authenticated SQL Injection in PHP Jabbers scripts
CVE-2026-453304.920.4decidimdecidimCWE-639Decidim: Verification admins can access supplied IDs from other organisations
CVE-2026-547686.920.2wp-graphqlwp-graphqlCWE-204WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that l…
CVE-2026-149199.820.1UnknownShopMonitor.ioCWE-287ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via P…
CVE-2026-519537.420.1n/an/aCWE-613An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via th…
CVE-2026-528559.919.8pterodactylwingsCWE-200Wings exposes node configuration secrets through egg configuration-file templ…
CVE-2025-676499.319.8PHP JabbersCar Rental ScriptCWE-89Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script
CVE-2026-453776.519.8decidimdecidimCWE-200Decidim: Private exports can be downloaded through reusable links
CVE-2026-653115.319.1ANDRITZHIPASE-250CWE-284Missing authentication for logging-configuration endpoint
CVE-2026-165049.819.0VPS.orgZulip templateCWE-321VPS.org one-click Zulip template deployment instance contains multiple vulner…
CVE-2026-127218.618.1UnknownKirkiCWE-89Kirki < 6.0.13 - Unauthenticated SQL Injection
CVE-2026-547377.318.1phun-kydefaults-deepCWE-1321@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive P…
CVE-2026-592315.317.7ccyl13PentestifyCWE-918Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs
CVE-2026-150487.517.4UnknownGeeky BotCWE-200GeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat Hi…
CVE-2026-659817.116.6coturncoturnCWE-639Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user…
CVE-2026-165039.116.2VPS.orgSupabase templateCWE-1188VPS.org one-click Supabase template deployment instance contains multiple vul…
CVE-2026-136098.816.1UnknownFrontend Admin by DynamiAppsCWE-79Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scr…
CVE-2026-438297.516.0tbctbcCWE-121tbc
CVE-2026-438317.516.0tbctbcCWE-121tbc
CVE-2026-438327.516.0tbctbcCWE-121tbc
CVE-2026-547064.815.8onionshareonionshareCWE-59OnionShare follows symlinks in shared directories, allowing unintended disclo…
CVE-2026-181577.815.4RedHatInsightsyggdrasil-worker-package-managerCWE-88Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote co…
CVE-2026-149307.515.3UnknownJS Help DeskCWE-862JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload
CVE-2026-173486.915.1pgadmin.orgpgAdmin 4CWE-306pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debu…
CVE-2026-566728.214.9Comfy-OrgComfyUICWE-79ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitiza…
CVE-2026-148336.814.7UnknownLightbox with PhotoSwipeCWE-79Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption …
CVE-2026-145418.014.5Googlemcp-toolboxCWE-287Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider
CVE-2026-344954.814.6Johnson ControlsFM Systems EmployeeCWE-79FMS Employee vulnerable to XSS
CVE-2026-344974.814.6Johnson ControlsFM Systems EmployeeCWE-80FMS Employee Vulnerable to HTML Injection
CVE-2026-145546.514.1UnknownCheck & Log EmailCWE-89Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters
CVE-2026-547075.414.1onionshareonionshareCWE-863OnionShare Receive mode writes uploaded files even when file uploads are disa…
CVE-2026-184365.313.7mailerpressMailerPress – Newsletter, email marketing & AI automationCWE-862MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Mod…
CVE-2026-122518.113.6UnknownUltimate MemberCWE-269Ultimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Sele…
CVE-2026-566708.213.3Comfy-OrgComfyUICWE-79ComfyUI: Stored XSS via SVG file upload on the /view endpoint
CVE-2026-523716.513.3n/an/aCWE-918A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger com…
CVE-2026-152588.112.9UnknownProduct Feed Manager For WooCommerceCWE-89Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via…
CVE-2026-184467.512.9fast-urifast-uriCWE-436fast-uri vulnerable to host confusion via backslash authority introducer
CVE-2026-143175.312.9UnknownGiveWPCWE-862GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass
CVE-2026-149286.512.6UnknownJS Help DeskCWE-200JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via check…
CVE-2026-149316.512.6UnknownJS Help DeskCWE-200JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure
CVE-2026-145378.112.3Googlemcp-toolboxCWE-863Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints
CVE-2026-173505.312.3pgadmin.orgpgAdmin 4CWE-862pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers
CVE-2026-145396.611.4Googlemcp-toolboxCWE-770Denial of Service via Unrestricted Payload Buffering in MCP Toolbox
CVE-2026-535018.211.2thumborthumborCWE-347Thumbor has HMAC validation bypass via multiple .replace() calls when removin…
CVE-2026-148307.511.2UnknownFlxWooCWE-287FlxWoo < 3.1.1 - Unauthenticated Payment Bypass
CVE-2026-558253.111.3contaocontaoCWE-22Contao: Possible path traversal in job download URIs
CVE-2026-152275.311.1Checkmk GmbHCheckmkCWE-862Missing Authorization Allows Editing of Foreign Reports
CVE-2026-673502.110.8s9ySerendipityCWE-601Serendipity < 2.6.1 Open Redirect via exit.php
CVE-2026-152096.510.3UnknownJS Help DeskCWE-639JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cr…
CVE-2026-182086.510.3Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: inactive out-of-audience token introspe…
CVE-2026-182063.710.3Red HatRed Hat Build of KeycloakCWE-20Keycloak-services: keycloak-services: client policy source-host wildcard doma…
CVE-2026-438335.39.8tbctbctbc
CVE-2026-565685.39.7HCL SoftwareHCL iControlCWE-209HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-182094.79.3Red HatRed Hat Build of KeycloakCWE-1288Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in ht…
CVE-2026-182174.79.3Red HatRed Hat Build of KeycloakCWE-20Keycloak-services: keycloak-services: saml http-redirect binding response pre…
CVE-2026-161054.99.2Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: missing per-role authorization on rolec…
CVE-2026-106857.69.1zephyrprojectzephyrCWE-416Use-after-free of GATT subscribe params in Bluetooth host CCC-write response …
CVE-2026-182148.18.8Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: google external access-token exchange b…
CVE-2026-182158.18.7Red HatRed Hat Build of KeycloakCWE-287Keycloak-services: keycloak-services: microsoft external access-token exchang…
CVE-2026-145385.78.5Googlemcp-toolboxCWE-285BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox
CVE-2025-623474.38.4HCLHCL iControlCWE-20HCL iControl was affected by Improper Input Validation vulnerability. It is v…
CVE-2026-182036.58.0Red HatRed Hat Build of KeycloakCWE-863Keycloak-services: keycloak-services: group policy extendchildren matches sib…
CVE-2026-148435.38.0UnknownEvents Made EasyCWE-639Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR
CVE-2026-572323.18.1contaocontaoCWE-918Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Fe…
CVE-2026-623245.47.8xdanjoditCWE-79Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement …
CVE-2026-182115.47.6Red HatRed Hat Build of KeycloakCWE-20Keycloak-services: keycloak-services: secure-client-uris policy bypass via lo…
CVE-2026-148493.77.6UnknownPaid Membership SubscriptionsCWE-552Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exp…
CVE-2026-153813.77.6UnknownWP Go MapsCWE-89WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter
CVE-2026-565705.37.6HCL SoftwareHCL iControlCWE-522HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-653138.17.4ANDRITZHIPASE-250CWE-798Use of hard-coded VNC credentials in the engineering-workstation provisioning
CVE-2026-281444.37.4Flipper CodeWP MapsCWE-201WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability
CVE-2026-580393.37.3nodejsnodeCWE-284A flaw in Node.js Permission Model enforcement allows process.report writes (…
CVE-2026-255526.37.0TryGhostGhost-CLICWE-348Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header
CVE-2026-565715.36.9HCL SoftwareHCL iControlCWE-209HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-450865.46.9decidimdecidimCWE-862Decidim: Forms admin question editor lacks authorization
CVE-2026-126975.46.7UnknownwpForo ForumCWE-639wpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR
CVE-2025-676516.96.3PHP JabbersAppointment SchedulerCWE-352CSRF in PHP Jabbers scripts
CVE-2026-148623.76.4UnknownSupport GenixCWE-862Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via …
CVE-2026-100798.56.2Red HatRed Hat Advanced Cluster Security 4CWE-345Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via …
CVE-2026-148346.56.1UnknownMailgun for WordPressCWE-284Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscr…
CVE-2026-148456.15.9UnknownNewStatPressCWE-79NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget
CVE-2026-123764.35.8UnknownAcademy LMSCWE-639Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_…
CVE-2026-148474.35.9UnknownPaid Membership SubscriptionsCWE-639Paid Member Subscriptions < 3.0.7 - Subscriber+ Payment Data Disclosure via IDOR
CVE-2026-149273.75.9UnknownFluentCart A New Era of eCommerceCWE-639FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes
CVE-2026-558242.65.1contaocontaoCWE-200Contao crawler leaks auth credentials to external hosts
CVE-2026-653097.54.9ANDRITZHIPASE-250CWE-257Storage of passwords in a reversible format
CVE-2026-149294.34.9UnknownJS Help DeskCWE-863JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR
CVE-2026-547856.24.8eLyiNgemini-bridgeCWE-22gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with…
CVE-2026-149216.14.6UnknownUltimate Addons for WPBakery Page BuilderCWE-79Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS …
CVE-2026-149226.14.6UnknownWP Photo Album PlusCWE-79WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment
CVE-2026-522326.14.6n/an/aCWE-79A reflected cross-site scripting (XSS) vulnerability in the /logo.asp compone…
CVE-2026-133933.54.0UnknownElementsKit Elementor AddonsCWE-79ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu M…
CVE-2026-656362.13.9ufirstgroupymlrCWE-93YAML injection via unescaped newlines in ymlr document comments
CVE-2026-346417.83.7AdobePremiereCWE-787Premiere Pro | Out-of-bounds Write (CWE-787)
CVE-2026-81555.43.6UnknownBuddyPressCWE-639BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR
CVE-2026-509868.83.4n/an/aCWE-352PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Sit…
CVE-2026-632204.83.5codeigniter4CodeIgniter4CWE-348CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
CVE-2026-182185.43.2Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: client not-before revocation ignored wh…
CVE-2026-145408.01.8Googlemcp-toolboxCWE-918Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox
CVE-2026-528575.51.6pterodactylwingsCWE-400Wings: Maliciously or erroneously created parsed config files can cause wings…
CVE-2026-281455.31.5StylemixThemesMasterStudy LMSCWE-345WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability
CVE-2026-344904.81.1Johnson ControlsXAAP ApplicationCWE-312XAAP Android Data Stored in Unencrypted Database
CVE-2026-565673.31.0HCL SoftwareHCL iControlCWE-15HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-565693.31.0HCL SoftwareHCL iControlCWE-497HCL iControl is affected by multiple security vulnerabilities.
CVE-2026-547873.10.5sigstoresigstore-goCWE-324sigstore-go fails to check signature timestamps against a signing key's valid…
CVE-2026-183214.70.3NTPsecntpsecCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-31 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.