AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0262 84.2 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jul 31 Published (CNA: mitre)
183 CVEs published July 31, 2026: 26 critical, 66 high, 76 medium, 15 low; 0 in KEV; 2 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 158 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 6056 | 8805 | 1389 | 2563 |
| KEV catalog size | 1670 | |||
303 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 667 | 1585 | 207 | 1127 | 98 | 0 | 27 | 3 | 0.2 | 7.8 | .0016 | +426 |
| microsoft | 658 | 1361 | 105 | 929 | 302 | 8 | 378 | 32 | 2.4 | 7.8 | .0039 | +439 |
| 403 | 412 | 64 | 104 | 226 | 15 | 73 | 5 | 1.2 | 6.5 | .0022 | +400 | |
| apple | 167 | 244 | 56 | 67 | 112 | 2 | 93 | 7 | 2.9 | 7.1 | .0027 | +130 |
| red hat | 123 | 222 | 9 | 109 | 92 | 12 | 4 | 0 | 0.0 | 7.1 | .0027 | +68 |
| canonical | 3 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | +3 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | -1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 8 | 20 | 4 | 6 | 2 | 0 | 96 | 13 | 65.0 | 8.2 | .1853 | +5 |
| fortinet | 11 | 18 | 2 | 4 | 9 | 0 | 28 | 6 | 33.3 | 6.1 | .0054 | +10 |
| palo alto networks | 10 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | +7 |
| vmware | 12 | 12 | 4 | 7 | 0 | 1 | 21 | 0 | 0.0 | 8.7 | .0044 | +12 |
| f5 | 1 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | -1 |
| checkpoint | 3 | 4 | 3 | 1 | 0 | 0 | 3 | 2 | 50.0 | 9.2 | .4696 | +2 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.1 | .0877 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 105 | 137 | 24 | 74 | 39 | 0 | 40 | 1 | 0.7 | 7.5 | .0051 | +89 |
| mozilla | 67 | 72 | 42 | 26 | 4 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +67 |
| gitlab | 13 | 15 | 0 | 2 | 10 | 1 | 4 | 2 | 13.3 | 4.9 | .0029 | +13 |
| wordpress | 3 | 3 | 1 | 1 | 1 | 0 | 5 | 2 | 66.7 | 8.6 | .7310 | +3 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | -3 |
| github | 2 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 6.1 | .0029 | +2 |
| kubernetes | 1 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1109 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | +1107 |
| ibm | 100 | 108 | 31 | 43 | 34 | 0 | 7 | 0 | 0.0 | 7.5 | .0026 | +92 |
| adobe | 29 | 40 | 10 | 22 | 4 | 0 | 75 | 4 | 10.0 | 8.4 | .0039 | +22 |
| progress | 23 | 23 | 3 | 15 | 5 | 0 | 9 | 0 | 0.0 | 8.1 | .0032 | +23 |
| solarwinds | 16 | 20 | 16 | 1 | 1 | 0 | 11 | 4 | 20.0 | 9.1 | .0050 | +15 |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 |
| zohocorp | 3 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0048 | +3 |
| veeam | 2 | 2 | 0 | 1 | 1 | 0 | 4 | 0 | 0.0 | 6.8 | .0016 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 7 | 8 | 0 | 0 | 6 | 1 | 26 | 1 | 12.5 | 5.5 | .0073 | +7 |
| hikvision | 6 | 7 | 0 | 4 | 2 | 0 | 2 | 1 | 14.3 | 7.2 | .0025 | +6 |
| bosch | 3 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0028 | +3 |
| schneider electric | 3 | 3 | 1 | 2 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0020 | +3 |
| honeywell | 1 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 6.9 | .0031 | +1 |
| mitsubishi electric | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.1 | .0013 | +1 |
| rockwell automation | 1 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | +1 |
| siemens | 0 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 57 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | +57 |
| netty | 19 | 41 | 6 | 27 | 7 | 1 | 0 | 0 | 0.0 | 7.5 | .0046 | +5 |
| grafana | 8 | 41 | 2 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | +2 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| erlang | 14 | 32 | 1 | 14 | 14 | 3 | 1 | 0 | 0.0 | 6.9 | .0033 | +7 |
| regularlabs.com | 29 | 29 | 6 | 14 | 9 | 0 | 0 | 0 | 0.0 | 7.5 | .0022 | +29 |
| watchguard | 17 | 28 | 1 | 18 | 9 | 0 | 4 | 0 | 0.0 | 7.3 | .0026 | +17 |
| nlnet labs | 24 | 27 | 0 | 4 | 17 | 6 | 0 | 0 | 0.0 | 5.9 | .0024 | +24 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | — |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE-2026-15409 | .7422 | 99.4 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 661 |
| microsoft | 656 |
| 403 | |
| apple | 167 |
| red hat | 120 |
| apache | 105 |
| ibm | 100 |
| mozilla | 67 |
| surrealdb | 57 |
| Vendor | KEV |
|---|---|
| microsoft | 32 |
| cisco | 13 |
| apple | 7 |
| fortinet | 6 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 29 |
| Go | 3 |
| crates.io | 2 |
| npm | 2 |
| NuGet | 1 |
| Packagist | 1 |
| PyPI | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1717 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1717 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1717 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1717 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1717 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1717 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1717 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1717 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1717 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1717 |
EXPLOIT PUBLISHED — CVE-2009-3960. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-12615 (Apache Software Foundation Apache Tomcat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-47966. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-47246. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10685 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10686 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56968 (GNU SASL). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66066 (rails). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67206 (wolfcms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67207 (wolfcms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67345 (dromara MaxKey). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67347 (vendurehq vendure). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67348 (julep-ai julep). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67349 (opencost). Public exploit reference added.
DUE DATE PASSED — CVE-2026-16812 (Arista Networks VeloCloud Orchestrator On-Prem). CISA remediation deadline was July 30, 2026; still in catalog.
RESCORED — CVE-2023-27997 (Fortinet FortiOS-6K7K). CVSS 9.2 → 9.8 (NVD).
RESCORED — CVE-2023-4966 (Citrix NetScaler ADC). CVSS 9.4 → 7.5 (NVD).
RESCORED — CVE-2023-6507 (Python Software Foundation CPython). CVSS 6.1 → 4.9 (NVD).
RESCORED — CVE-2025-4526 (Dígitro NGC Explorer). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2025-4527 (Dígitro NGC Explorer). CVSS 6.3 → 2.9 (NVD).
RESCORED — CVE-2025-4528 (Dígitro NGC Explorer). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-56968 (GNU SASL). CVSS 3.7 → 5.3 (NVD).
183 CVEs published. 25 box scores, 158 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0262 84.2 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jul 31 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0262 84.2 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jul 31 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0262 84.2 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jul 31 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0255 83.7 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jul 31 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0219 80.9 —
AFFECTED Product Versions Fixed Realtyna Organic IDX plugin + WPL Real Estate unspecified —
TIMELINE Jul 2 Reserved by CNA Jul 31 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0115 64.2 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 8 Reserved by CNA Jul 31 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N H N H H H 8.5 .0113 63.7 —
AFFECTED Product Versions Fixed AXE75 V1 unspecified —
TIMELINE May 19 Reserved by CNA Jul 31 Published (CNA: TPLink)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0089 56.5 —
AFFECTED Product Versions Fixed DS-3WAP521-SI V1.1.6601 build251223 and earlier – — DS-3WAP522-SI V1.1.6601 build251223 and earlier – — DS-3WAP621E-SI V1.1.6601 build251223 and earlier – — DS-3WAP622E-SI V1.1.6601 build251223 and earlier – — DS-3WAP623E-SI V1.1.6601 build251223 and earlier – — DS-3WAP622G-SI V1.1.6601 build251223 and earlier – — DS-3WG105G-SI V1.1.6601 build251223 and earlier – — DS-3WG105GP-SI V1.1.6601 build251223 and earlier – — DS-3WG210GP-SI V1.1.6601 build251223 and earlier – — DS-3WG507G-SI V1.1.6601 build251223 and earlier – —
TIMELINE Jul 24 Reserved by CNA Jul 31 Published (CNA: hikvision)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0087 55.8 —
AFFECTED Product Versions Fixed Red Hat Directory Server 11.7 E4S for RHEL 8 unspecified 8080020260806114250.f969626e Red Hat Directory Server 11.9 for RHEL 8 unspecified 8100020260803140625.37ed7c03 Red Hat Directory Server 12.2 E4S for RHEL 9 unspecified 9020020260730155601.1674d574 Red Hat Directory Server 12.4 E4S for RHEL 9 unspecified 9040020260810131422.1674d574 Red Hat Enterprise Linux 10 unspecified 0:3.2.0-9.el10_2 Red Hat Enterprise Linux 10.0 Extended Update Support unspecified 0:3.0.6-20.el10_0 Red Hat Enterprise Linux 7 Extended Lifecycle Support unspecified 0:1.3.11.1-14.el7_9 Red Hat Enterprise Linux 8 unspecified 8100020260806150504.25e700aa Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support unspecified 8040020260803141511.96015a92 Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On unspecified 8040020260803141511.96015a92 + 11 more
TIMELINE Jul 14 Reserved by CNA Jul 31 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0084 54.9 —
AFFECTED Product Versions Fixed Apache Zeppelin 0.9.0 – —
TIMELINE May 7 Reserved by CNA Jul 31 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0080 53.6 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 8 Reserved by CNA Jul 31 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0069 49.7 —
AFFECTED Product Versions Fixed Red Hat Directory Server 11.7 E4S for RHEL 8 unspecified 8080020260806114250.f969626e Red Hat Directory Server 11.9 for RHEL 8 unspecified 8100020260803140625.37ed7c03 Red Hat Directory Server 12.2 E4S for RHEL 9 unspecified 9020020260730155601.1674d574 Red Hat Directory Server 12.4 E4S for RHEL 9 unspecified 9040020260810131422.1674d574 Red Hat Enterprise Linux 10 unspecified 0:3.2.0-9.el10_2 Red Hat Enterprise Linux 10.0 Extended Update Support unspecified 0:3.0.6-20.el10_0 Red Hat Enterprise Linux 7 Extended Lifecycle Support unspecified 0:1.3.11.1-14.el7_9 Red Hat Enterprise Linux 8 unspecified 8100020260806150504.25e700aa Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support unspecified 8040020260803141511.96015a92 Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On unspecified 8040020260803141511.96015a92 + 11 more
TIMELINE Jun 9 Reserved by CNA Jul 31 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0066 48.7 —
AFFECTED Product Versions Fixed ComfyUI < 0.28.0 – —
TIMELINE Jun 22 Reserved by CNA Jul 31 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0063 47.3 —
AFFECTED Product Versions Fixed Realtyna Organic IDX plugin + WPL Real Estate unspecified —
TIMELINE Jul 19 Reserved by CNA Jul 31 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0062 47.0 —
AFFECTED Product Versions Fixed ComfyUI unspecified —
TIMELINE Jul 31 Reserved by CNA Jul 31 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0056 44.0 —
AFFECTED Product Versions Fixed cPanel unspecified — WP Squared unspecified —
TIMELINE Jun 27 Reserved by CNA Jul 31 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N N H 6.5 .0053 42.4 —
AFFECTED Product Versions Fixed cloudreve < 4.17.0 – —
TIMELINE Jun 16 Reserved by CNA Jul 31 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0052 41.9 —
AFFECTED Product Versions Fixed Apache Kyuubi 1.6.0 – —
TIMELINE Jul 14 Reserved by CNA Jul 31 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0052 41.9 —
AFFECTED Product Versions Fixed gnome-remote-desktop unspecified — Red Hat Enterprise Linux 10 unspecified 0:49.3-4.el10_2 Red Hat Enterprise Linux 8 unspecified — Red Hat Enterprise Linux 9 unspecified —
TIMELINE Jul 30 Reserved by CNA Jul 31 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0052 41.8 —
AFFECTED Product Versions Fixed sentence-transformers unspecified —
TIMELINE Jul 31 Reserved by CNA Jul 31 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P L L N 5.6 .0052 41.7 —
AFFECTED Product Versions Fixed cPanel unspecified — WP Squared unspecified —
TIMELINE Jun 27 Reserved by CNA Jul 31 Published (CNA: hackerone)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H P L L N 4.8 .0050 40.8 —
AFFECTED Product Versions Fixed FM Systems Employee unspecified —
TIMELINE Jan 2 Reserved by CNA Jul 31 Published (CNA: jci)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0049 40.1 —
AFFECTED Product Versions Fixed CodeIgniter4 < 4.7.4 – —
TIMELINE Jul 15 Reserved by CNA Jul 31 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0045 37.4 —
AFFECTED Product Versions Fixed CodeIgniter4 < 4.7.4 – —
TIMELINE Jul 15 Reserved by CNA Jul 31 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0043 36.0 —
AFFECTED Product Versions Fixed DMS+ (Non-Mobile) unspecified —
TIMELINE Jul 31 Reserved by CNA Jul 31 Published (CNA: twcert)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-56673 | 7.5 | 35.9 | Comfy-Org | ComfyUI | CWE-22 | ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary fil… |
| CVE-2026-53551 | 6.9 | 35.8 | free5gc | free5gc | CWE-20 | free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal serv… |
| CVE-2026-17346 | 8.7 | 35.4 | pgadmin.org | pgAdmin 4 | CWE-89 | pgAdmin 4: SQL injection via unescaped object names in index Statistics and p… |
| CVE-2026-53503 | 7.5 | 34.8 | thumbor | thumbor | CWE-20 | Thumbor convolution filter allows divide-by-zero in C extension leading to re… |
| CVE-2026-17566 | 9.4 | 34.0 | pgadmin.org | pgAdmin 4 | CWE-78 | pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guar… |
| CVE-2026-53510 | 8.1 | 32.8 | savonrb | savon | CWE-94 | Savon::Model evaluates WSDL operation names as Ruby source |
| CVE-2026-62959 | 8.2 | 31.5 | coturn | coturn | CWE-125 | Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme… |
| CVE-2026-55100 | 8.7 | 31.4 | kyndryl-open-source | hashi-vault-js | CWE-23 | hashi-vault-js has a path traversal and query parameter injection |
| CVE-2026-17351 | 9.4 | 31.3 | pgadmin.org | pgAdmin 4 | CWE-89 | pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL … |
| CVE-2026-63221 | 9.4 | 30.8 | codeigniter4 | CodeIgniter4 | CWE-89 | CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when u… |
| CVE-2026-17567 | 5.3 | 30.8 | wpmanageninja | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | CWE-639 | Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via In… |
| CVE-2026-53573 | 4.8 | 30.8 | geonetwork | core-geonetwork | CWE-601 | core-geonetwork has an Open Redirect Bypass |
| CVE-2026-55495 | 4.3 | 30.8 | cloudreve | cloudreve | CWE-22 | Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation… |
| CVE-2026-54909 | 5.3 | 30.2 | pion | stun | CWE-20 | Pion STUN vulnerable to remote denial of service via panic while parsing a ma… |
| CVE-2026-13392 | 7.2 | 30.1 | Unknown | ElementsKit Elementor Addons | CWE-94 | ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Cu… |
| CVE-2026-55496 | 4.3 | 29.2 | cloudreve | cloudreve | CWE-200 | Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search … |
| CVE-2026-64607 | 5.3 | 29.0 | Apache Software Foundation | Apache HttpComponents Client | CWE-772 | Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Erro… |
| CVE-2026-53502 | 8.7 | 28.8 | thumbor | thumbor | CWE-22 | Thumbor has path traversal via post-validation URL decoding bypass in file_lo… |
| CVE-2026-46594 | 5.1 | 27.8 | PHP Jabbers | PHP Poll Script | CWE-79 | Reflected XSS in PHP Poll Script |
| CVE-2026-45376 | 5.5 | 27.2 | decidim | decidim | CWE-89 | Decidim: Admin user search allows SQL injection through similarity-based sorting |
| CVE-2026-53505 | 7.5 | 26.8 | thumbor | thumbor | CWE-400 | Thumbor proportion filter allows unbounded post-transform resize leading to r… |
| CVE-2026-55502 | 7.1 | 26.8 | cloudreve | cloudreve | CWE-863 | Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials |
| CVE-2025-69946 | 9.8 | 26.6 | n/a | n/a | CWE-89 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injecti… |
| CVE-2026-52856 | 7.5 | 26.4 | pterodactyl | wings | CWE-129 | Wings: Maliciously crafted packet during SFTP connection handshake causes den… |
| CVE-2026-53504 | 7.5 | 26.4 | thumbor | thumbor | CWE-400 | Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter |
| CVE-2026-55499 | 4.3 | 26.0 | cloudreve | cloudreve | CWE-863 | Cloudreve: Broken access control in file event stream leaks activity events f… |
| CVE-2026-54725 | 9.6 | 24.8 | bank-vaults | vault-secrets-webhook | CWE-918 | vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker UR… |
| CVE-2026-65310 | 7.5 | 24.6 | ANDRITZ | HIPASE-250 | CWE-306 | Missing authentication and permissive CORS policy |
| CVE-2026-14319 | 7.5 | 24.3 | Unknown | GiveWP | CWE-200 | GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure |
| CVE-2026-17561 | 9.8 | 24.1 | Innotim Software, Telecommunications and Consulting Trade Ltd. Co. | Logsign SIEM | CWE-94 | Unauthenticated RCE in Innotim Software's Logsign SIEM |
| CVE-2026-43830 | 9.8 | 24.1 | tbc | tbc | CWE-77 | tbc |
| CVE-2026-53599 | 7.5 | 24.1 | redaxo | core | CWE-434 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename t… |
| CVE-2026-18141 | 8.2 | 23.5 | Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | CWE-295 | Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via f… |
| CVE-2025-69948 | 9.8 | 23.3 | n/a | n/a | CWE-89 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injecti… |
| CVE-2026-62323 | 6.3 | 23.2 | cloudreve | cloudreve | CWE-863 | Cloudreve: Unauthorized file write via WOPI view sessions whose access token … |
| CVE-2026-59232 | 5.3 | 23.1 | Roskus | Prospero Flow CRM | CWE-79 | Stored Cross-site Scripting in Prospero Flow CRM lead name field |
| CVE-2026-12720 | 7.5 | 23.1 | Unknown | Kirki | CWE-502 | Kirki < 6.0.13 - Unauthenticated PHP Object Injection |
| CVE-2026-65841 | 5.3 | 22.6 | xdan | jodit | CWE-80 | Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses… |
| CVE-2026-46593 | 8.6 | 22.2 | PHP Jabbers | PHP Poll Script | CWE-89 | Authenticated SQL Injection in PHP Poll Script |
| CVE-2026-18437 | 5.3 | 22.2 | mailerpress | MailerPress – Newsletter, email marketing & AI automation | CWE-862 | MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates |
| CVE-2026-17347 | 7.7 | 22.2 | pgadmin.org | pgAdmin 4 | CWE-78 | pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted usernam… |
| CVE-2026-14333 | 7.5 | 22.2 | Unknown | Demi | CWE-269 | Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticat… |
| CVE-2026-67822 | 9.8 | 22.0 | n/a | n/a | CWE-121 | Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability … |
| CVE-2026-67607 | 8.2 | 22.0 | hfiref0x | LightFTP | CWE-367 | LightFTP 2.3.1 Race Condition DoS via worker_thread_cleanup |
| CVE-2026-10686 | 7.5 | 22.0 | zephyrproject | zephyr | CWE-835 | Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet l… |
| CVE-2026-62999 | 7.5 | 22.0 | copier-org | copier | CWE-22 | Copier: Percent-encoded dot segments in template URLs can allow trusted-prefi… |
| CVE-2026-18394 | 6.9 | 21.9 | AWS | Strands Agents Tools | CWE-863 | Incorrect authorization in Strands Agents Tools http_request proxy credential… |
| CVE-2026-54729 | 8.7 | 21.7 | HackingRepo | dssrf-js | CWE-918 | dssrf: any users using 1.1.1.1 DNS is impacted by SSRF |
| CVE-2026-12695 | 8.1 | 21.7 | Unknown | miniOrange 2FA | CWE-287 | miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret |
| CVE-2026-17349 | 9.3 | 21.3 | pgadmin.org | pgAdmin 4 | CWE-522 | pgAdmin 4: Adhoc server clone leaks another user's stored database credential… |
| CVE-2026-53500 | 8.2 | 21.2 | thumbor | thumbor | CWE-918 | Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing h… |
| CVE-2026-18481 | 6.2 | 20.7 | AWS | AWS Ops Wheel | CWE-79 | Stored XSS in Participant URL Field leads to Account Takeover via Session Tok… |
| CVE-2025-67650 | 8.6 | 20.4 | PHP Jabbers | Appointment Scheduler | CWE-89 | Authenticated SQL Injection in PHP Jabbers scripts |
| CVE-2026-45330 | 4.9 | 20.4 | decidim | decidim | CWE-639 | Decidim: Verification admins can access supplied IDs from other organisations |
| CVE-2026-54768 | 6.9 | 20.2 | wp-graphql | wp-graphql | CWE-204 | WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that l… |
| CVE-2026-14919 | 9.8 | 20.1 | Unknown | ShopMonitor.io | CWE-287 | ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via P… |
| CVE-2026-51953 | 7.4 | 20.1 | n/a | n/a | CWE-613 | An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via th… |
| CVE-2026-52855 | 9.9 | 19.8 | pterodactyl | wings | CWE-200 | Wings exposes node configuration secrets through egg configuration-file templ… |
| CVE-2025-67649 | 9.3 | 19.8 | PHP Jabbers | Car Rental Script | CWE-89 | Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script |
| CVE-2026-45377 | 6.5 | 19.8 | decidim | decidim | CWE-200 | Decidim: Private exports can be downloaded through reusable links |
| CVE-2026-65311 | 5.3 | 19.1 | ANDRITZ | HIPASE-250 | CWE-284 | Missing authentication for logging-configuration endpoint |
| CVE-2026-16504 | 9.8 | 19.0 | VPS.org | Zulip template | CWE-321 | VPS.org one-click Zulip template deployment instance contains multiple vulner… |
| CVE-2026-12721 | 8.6 | 18.1 | Unknown | Kirki | CWE-89 | Kirki < 6.0.13 - Unauthenticated SQL Injection |
| CVE-2026-54737 | 7.3 | 18.1 | phun-ky | defaults-deep | CWE-1321 | @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive P… |
| CVE-2026-59231 | 5.3 | 17.7 | ccyl13 | Pentestify | CWE-918 | Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs |
| CVE-2026-15048 | 7.5 | 17.4 | Unknown | Geeky Bot | CWE-200 | GeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat Hi… |
| CVE-2026-65981 | 7.1 | 16.6 | coturn | coturn | CWE-639 | Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user… |
| CVE-2026-16503 | 9.1 | 16.2 | VPS.org | Supabase template | CWE-1188 | VPS.org one-click Supabase template deployment instance contains multiple vul… |
| CVE-2026-13609 | 8.8 | 16.1 | Unknown | Frontend Admin by DynamiApps | CWE-79 | Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scr… |
| CVE-2026-43829 | 7.5 | 16.0 | tbc | tbc | CWE-121 | tbc |
| CVE-2026-43831 | 7.5 | 16.0 | tbc | tbc | CWE-121 | tbc |
| CVE-2026-43832 | 7.5 | 16.0 | tbc | tbc | CWE-121 | tbc |
| CVE-2026-54706 | 4.8 | 15.8 | onionshare | onionshare | CWE-59 | OnionShare follows symlinks in shared directories, allowing unintended disclo… |
| CVE-2026-18157 | 7.8 | 15.4 | RedHatInsights | yggdrasil-worker-package-manager | CWE-88 | Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote co… |
| CVE-2026-14930 | 7.5 | 15.3 | Unknown | JS Help Desk | CWE-862 | JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload |
| CVE-2026-17348 | 6.9 | 15.1 | pgadmin.org | pgAdmin 4 | CWE-306 | pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debu… |
| CVE-2026-56672 | 8.2 | 14.9 | Comfy-Org | ComfyUI | CWE-79 | ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitiza… |
| CVE-2026-14833 | 6.8 | 14.7 | Unknown | Lightbox with PhotoSwipe | CWE-79 | Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption … |
| CVE-2026-14541 | 8.0 | 14.5 | mcp-toolbox | CWE-287 | Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider | |
| CVE-2026-34495 | 4.8 | 14.6 | Johnson Controls | FM Systems Employee | CWE-79 | FMS Employee vulnerable to XSS |
| CVE-2026-34497 | 4.8 | 14.6 | Johnson Controls | FM Systems Employee | CWE-80 | FMS Employee Vulnerable to HTML Injection |
| CVE-2026-14554 | 6.5 | 14.1 | Unknown | Check & Log Email | CWE-89 | Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters |
| CVE-2026-54707 | 5.4 | 14.1 | onionshare | onionshare | CWE-863 | OnionShare Receive mode writes uploaded files even when file uploads are disa… |
| CVE-2026-18436 | 5.3 | 13.7 | mailerpress | MailerPress – Newsletter, email marketing & AI automation | CWE-862 | MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Mod… |
| CVE-2026-12251 | 8.1 | 13.6 | Unknown | Ultimate Member | CWE-269 | Ultimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Sele… |
| CVE-2026-56670 | 8.2 | 13.3 | Comfy-Org | ComfyUI | CWE-79 | ComfyUI: Stored XSS via SVG file upload on the /view endpoint |
| CVE-2026-52371 | 6.5 | 13.3 | n/a | n/a | CWE-918 | A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger com… |
| CVE-2026-15258 | 8.1 | 12.9 | Unknown | Product Feed Manager For WooCommerce | CWE-89 | Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via… |
| CVE-2026-18446 | 7.5 | 12.9 | fast-uri | fast-uri | CWE-436 | fast-uri vulnerable to host confusion via backslash authority introducer |
| CVE-2026-14317 | 5.3 | 12.9 | Unknown | GiveWP | CWE-862 | GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass |
| CVE-2026-14928 | 6.5 | 12.6 | Unknown | JS Help Desk | CWE-200 | JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via check… |
| CVE-2026-14931 | 6.5 | 12.6 | Unknown | JS Help Desk | CWE-200 | JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure |
| CVE-2026-14537 | 8.1 | 12.3 | mcp-toolbox | CWE-863 | Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints | |
| CVE-2026-17350 | 5.3 | 12.3 | pgadmin.org | pgAdmin 4 | CWE-862 | pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers |
| CVE-2026-14539 | 6.6 | 11.4 | mcp-toolbox | CWE-770 | Denial of Service via Unrestricted Payload Buffering in MCP Toolbox | |
| CVE-2026-53501 | 8.2 | 11.2 | thumbor | thumbor | CWE-347 | Thumbor has HMAC validation bypass via multiple .replace() calls when removin… |
| CVE-2026-14830 | 7.5 | 11.2 | Unknown | FlxWoo | CWE-287 | FlxWoo < 3.1.1 - Unauthenticated Payment Bypass |
| CVE-2026-55825 | 3.1 | 11.3 | contao | contao | CWE-22 | Contao: Possible path traversal in job download URIs |
| CVE-2026-15227 | 5.3 | 11.1 | Checkmk GmbH | Checkmk | CWE-862 | Missing Authorization Allows Editing of Foreign Reports |
| CVE-2026-67350 | 2.1 | 10.8 | s9y | Serendipity | CWE-601 | Serendipity < 2.6.1 Open Redirect via exit.php |
| CVE-2026-15209 | 6.5 | 10.3 | Unknown | JS Help Desk | CWE-639 | JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cr… |
| CVE-2026-18208 | 6.5 | 10.3 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: inactive out-of-audience token introspe… |
| CVE-2026-18206 | 3.7 | 10.3 | Red Hat | Red Hat Build of Keycloak | CWE-20 | Keycloak-services: keycloak-services: client policy source-host wildcard doma… |
| CVE-2026-43833 | 5.3 | 9.8 | tbc | tbc | — | tbc |
| CVE-2026-56568 | 5.3 | 9.7 | HCL Software | HCL iControl | CWE-209 | HCL iControl is affected by multiple security vulnerabilities. |
| CVE-2026-18209 | 4.7 | 9.3 | Red Hat | Red Hat Build of Keycloak | CWE-1288 | Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in ht… |
| CVE-2026-18217 | 4.7 | 9.3 | Red Hat | Red Hat Build of Keycloak | CWE-20 | Keycloak-services: keycloak-services: saml http-redirect binding response pre… |
| CVE-2026-16105 | 4.9 | 9.2 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: missing per-role authorization on rolec… |
| CVE-2026-10685 | 7.6 | 9.1 | zephyrproject | zephyr | CWE-416 | Use-after-free of GATT subscribe params in Bluetooth host CCC-write response … |
| CVE-2026-18214 | 8.1 | 8.8 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: google external access-token exchange b… |
| CVE-2026-18215 | 8.1 | 8.7 | Red Hat | Red Hat Build of Keycloak | CWE-287 | Keycloak-services: keycloak-services: microsoft external access-token exchang… |
| CVE-2026-14538 | 5.7 | 8.5 | mcp-toolbox | CWE-285 | BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox | |
| CVE-2025-62347 | 4.3 | 8.4 | HCL | HCL iControl | CWE-20 | HCL iControl was affected by Improper Input Validation vulnerability. It is v… |
| CVE-2026-18203 | 6.5 | 8.0 | Red Hat | Red Hat Build of Keycloak | CWE-863 | Keycloak-services: keycloak-services: group policy extendchildren matches sib… |
| CVE-2026-14843 | 5.3 | 8.0 | Unknown | Events Made Easy | CWE-639 | Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR |
| CVE-2026-57232 | 3.1 | 8.1 | contao | contao | CWE-918 | Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Fe… |
| CVE-2026-62324 | 5.4 | 7.8 | xdan | jodit | CWE-79 | Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement … |
| CVE-2026-18211 | 5.4 | 7.6 | Red Hat | Red Hat Build of Keycloak | CWE-20 | Keycloak-services: keycloak-services: secure-client-uris policy bypass via lo… |
| CVE-2026-14849 | 3.7 | 7.6 | Unknown | Paid Membership Subscriptions | CWE-552 | Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exp… |
| CVE-2026-15381 | 3.7 | 7.6 | Unknown | WP Go Maps | CWE-89 | WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter |
| CVE-2026-56570 | 5.3 | 7.6 | HCL Software | HCL iControl | CWE-522 | HCL iControl is affected by multiple security vulnerabilities. |
| CVE-2026-65313 | 8.1 | 7.4 | ANDRITZ | HIPASE-250 | CWE-798 | Use of hard-coded VNC credentials in the engineering-workstation provisioning |
| CVE-2026-28144 | 4.3 | 7.4 | Flipper Code | WP Maps | CWE-201 | WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability |
| CVE-2026-58039 | 3.3 | 7.3 | nodejs | node | CWE-284 | A flaw in Node.js Permission Model enforcement allows process.report writes (… |
| CVE-2026-25552 | 6.3 | 7.0 | TryGhost | Ghost-CLI | CWE-348 | Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header |
| CVE-2026-56571 | 5.3 | 6.9 | HCL Software | HCL iControl | CWE-209 | HCL iControl is affected by multiple security vulnerabilities. |
| CVE-2026-45086 | 5.4 | 6.9 | decidim | decidim | CWE-862 | Decidim: Forms admin question editor lacks authorization |
| CVE-2026-12697 | 5.4 | 6.7 | Unknown | wpForo Forum | CWE-639 | wpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR |
| CVE-2025-67651 | 6.9 | 6.3 | PHP Jabbers | Appointment Scheduler | CWE-352 | CSRF in PHP Jabbers scripts |
| CVE-2026-14862 | 3.7 | 6.4 | Unknown | Support Genix | CWE-862 | Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via … |
| CVE-2026-10079 | 8.5 | 6.2 | Red Hat | Red Hat Advanced Cluster Security 4 | CWE-345 | Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via … |
| CVE-2026-14834 | 6.5 | 6.1 | Unknown | Mailgun for WordPress | CWE-284 | Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscr… |
| CVE-2026-14845 | 6.1 | 5.9 | Unknown | NewStatPress | CWE-79 | NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget |
| CVE-2026-12376 | 4.3 | 5.8 | Unknown | Academy LMS | CWE-639 | Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_… |
| CVE-2026-14847 | 4.3 | 5.9 | Unknown | Paid Membership Subscriptions | CWE-639 | Paid Member Subscriptions < 3.0.7 - Subscriber+ Payment Data Disclosure via IDOR |
| CVE-2026-14927 | 3.7 | 5.9 | Unknown | FluentCart A New Era of eCommerce | CWE-639 | FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes |
| CVE-2026-55824 | 2.6 | 5.1 | contao | contao | CWE-200 | Contao crawler leaks auth credentials to external hosts |
| CVE-2026-65309 | 7.5 | 4.9 | ANDRITZ | HIPASE-250 | CWE-257 | Storage of passwords in a reversible format |
| CVE-2026-14929 | 4.3 | 4.9 | Unknown | JS Help Desk | CWE-863 | JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR |
| CVE-2026-54785 | 6.2 | 4.8 | eLyiN | gemini-bridge | CWE-22 | gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with… |
| CVE-2026-14921 | 6.1 | 4.6 | Unknown | Ultimate Addons for WPBakery Page Builder | CWE-79 | Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS … |
| CVE-2026-14922 | 6.1 | 4.6 | Unknown | WP Photo Album Plus | CWE-79 | WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment |
| CVE-2026-52232 | 6.1 | 4.6 | n/a | n/a | CWE-79 | A reflected cross-site scripting (XSS) vulnerability in the /logo.asp compone… |
| CVE-2026-13393 | 3.5 | 4.0 | Unknown | ElementsKit Elementor Addons | CWE-79 | ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu M… |
| CVE-2026-65636 | 2.1 | 3.9 | ufirstgroup | ymlr | CWE-93 | YAML injection via unescaped newlines in ymlr document comments |
| CVE-2026-34641 | 7.8 | 3.7 | Adobe | Premiere | CWE-787 | Premiere Pro | Out-of-bounds Write (CWE-787) |
| CVE-2026-8155 | 5.4 | 3.6 | Unknown | BuddyPress | CWE-639 | BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR |
| CVE-2026-50986 | 8.8 | 3.4 | n/a | n/a | CWE-352 | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Sit… |
| CVE-2026-63220 | 4.8 | 3.5 | codeigniter4 | CodeIgniter4 | CWE-348 | CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() |
| CVE-2026-18218 | 5.4 | 3.2 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: client not-before revocation ignored wh… |
| CVE-2026-14540 | 8.0 | 1.8 | mcp-toolbox | CWE-918 | Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox | |
| CVE-2026-52857 | 5.5 | 1.6 | pterodactyl | wings | CWE-400 | Wings: Maliciously or erroneously created parsed config files can cause wings… |
| CVE-2026-28145 | 5.3 | 1.5 | StylemixThemes | MasterStudy LMS | CWE-345 | WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability |
| CVE-2026-34490 | 4.8 | 1.1 | Johnson Controls | XAAP Application | CWE-312 | XAAP Android Data Stored in Unencrypted Database |
| CVE-2026-56567 | 3.3 | 1.0 | HCL Software | HCL iControl | CWE-15 | HCL iControl is affected by multiple security vulnerabilities. |
| CVE-2026-56569 | 3.3 | 1.0 | HCL Software | HCL iControl | CWE-497 | HCL iControl is affected by multiple security vulnerabilities. |
| CVE-2026-54787 | 3.1 | 0.5 | sigstore | sigstore-go | CWE-324 | sigstore-go fails to check signature timestamps against a signing key's valid… |
| CVE-2026-18321 | 4.7 | 0.3 | NTPsec | ntpsec | CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-31 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.