{"schema_version":1,"title":"Most vulnerable technologies: week of 29 June to 5 July 2026 (week 27)","summary":"In the week of 29 June to 5 July 2026, Junglewise Threat Intelligence recorded 1,993 new vulnerabilities: 125 critical, 544 high and 4 exploited in the wild. The most vulnerable technology was Google Chrome, with 427 vulnerabilities (0 critical), followed by Go Code.gitea.io/Gitea (38) and Gitea (39).","url":"https://junglewise.ai/threats/weekly/2026-06-29","json_url":"https://junglewise.ai/threats/weekly/2026-06-29.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/weekly/2026-06-29","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"week","period":{"end":"2026-07-05","start":"2026-06-29"},"totals":{"high":544,"critical":125,"exploited":4,"technologies":931,"vulnerabilities":1993},"notable":[{"cve":"CVE-2026-48282","cvss":10,"epss":0.0102,"slug":"cve-2026-48282-adobe-coldfusion-path-traversal-in-multiple-versions","title":"Adobe ColdFusion path traversal in multiple versions","severity":"critical","exploited":true,"published_at":"2026-06-30T16:16:54.533+00:00","url":"https://junglewise.ai/threats/cve-2026-48282-adobe-coldfusion-path-traversal-in-multiple-versions"},{"cve":"CVE-2026-56290","cvss":10,"epss":0.0036,"slug":"cve-2026-56290-joomlack-page-builder-ck-unauthenticated-arbitrary-file-upload","title":"Joomlack Page Builder CK unauthenticated arbitrary file upload","severity":"critical","exploited":true,"published_at":"2026-06-29T15:16:42.36+00:00","url":"https://junglewise.ai/threats/cve-2026-56290-joomlack-page-builder-ck-unauthenticated-arbitrary-file-upload"},{"cve":"CVE-2026-8452","cvss":8.8,"epss":0.0101,"slug":"cve-2026-8452-netscaler-adc-and-gateway-memory-overflow-in-gateway-or-aaa","title":"NetScaler ADC and Gateway memory overflow in Gateway or AAA virtual server","severity":"critical","exploited":true,"published_at":"2026-06-30T13:19:33.45+00:00","url":"https://junglewise.ai/threats/cve-2026-8452-netscaler-adc-and-gateway-memory-overflow-in-gateway-or-aaa"},{"cve":"CVE-2026-53362","cvss":6.2,"epss":0.0071,"slug":"cve-2026-53362-linux-kernel-buffer-overflow-in-ipv6-paged-allocation","title":"Linux Kernel buffer overflow in IPv6 paged allocation","severity":"critical","exploited":true,"published_at":"2026-07-04T12:17:02.113+00:00","url":"https://junglewise.ai/threats/cve-2026-53362-linux-kernel-buffer-overflow-in-ipv6-paged-allocation"},{"cve":"CVE-2026-13768","cvss":10,"slug":"cve-2026-13768-gardyn-iot-hub-hard-coded-privileged-key-exposure","title":"Gardyn IoT Hub hard-coded privileged key exposure","severity":"critical","exploited":false,"published_at":"2026-07-03T00:16:52.27+00:00","url":"https://junglewise.ai/threats/cve-2026-13768-gardyn-iot-hub-hard-coded-privileged-key-exposure"},{"cve":"CVE-2026-50746","cvss":10,"slug":"cve-2026-50746-ubiquiti-unifi-connect-command-injection-via-improper-access","title":"Ubiquiti UniFi Connect command injection via improper access control","severity":"critical","exploited":false,"published_at":"2026-07-02T15:17:02.723+00:00","url":"https://junglewise.ai/threats/cve-2026-50746-ubiquiti-unifi-connect-command-injection-via-improper-access"},{"cve":"CVE-2026-57624","cvss":10,"slug":"cve-2026-57624-creative-themes-blocksy-companion-pro-unauthenticated-rce","title":"Creative Themes Blocksy Companion Pro unauthenticated RCE","severity":"critical","exploited":false,"published_at":"2026-07-02T12:17:37.277+00:00","url":"https://junglewise.ai/threats/cve-2026-57624-creative-themes-blocksy-companion-pro-unauthenticated-rce"},{"cve":"CVE-2026-50160","cvss":10,"slug":"cve-2026-50160-hoppscotch-mass-assignment-in-onboarding-config-endpoint","title":"Hoppscotch mass assignment in onboarding config endpoint","severity":"critical","exploited":false,"published_at":"2026-07-01T19:16:53.173+00:00","url":"https://junglewise.ai/threats/cve-2026-50160-hoppscotch-mass-assignment-in-onboarding-config-endpoint"},{"cve":"CVE-2026-56415","cvss":10,"slug":"cve-2026-56415-stonefly-storage-concentrator-command-injection-in-debug-pl","title":"StoneFly Storage Concentrator command injection in debug.pl","severity":"critical","exploited":false,"published_at":"2026-06-30T23:17:32.157+00:00","url":"https://junglewise.ai/threats/cve-2026-56415-stonefly-storage-concentrator-command-injection-in-debug-pl"},{"cve":"CVE-2026-56413","cvss":10,"slug":"cve-2026-56413-stonefly-storage-concentrator-command-injection-in-ms-service-pl","title":"StoneFly Storage Concentrator command injection in ms_service.pl","severity":"critical","exploited":false,"published_at":"2026-06-30T23:17:32.027+00:00","url":"https://junglewise.ai/threats/cve-2026-56413-stonefly-storage-concentrator-command-injection-in-ms-service-pl"}],"vendors":[{"hub":true,"high":2,"name":"Google","rank":1,"slug":"google","critical":1,"exploited":0,"vulnerabilities":438,"url":"https://junglewise.ai/threats/vendors/google"},{"hub":true,"high":26,"name":"Go","rank":2,"slug":"go","critical":10,"exploited":0,"vulnerabilities":52,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":33,"name":"Microsoft","rank":3,"slug":"microsoft","critical":4,"exploited":0,"vulnerabilities":50,"url":"https://junglewise.ai/threats/vendors/microsoft"},{"hub":true,"high":22,"name":"Gitea","rank":4,"slug":"gitea","critical":9,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/vendors/gitea"},{"hub":true,"high":13,"name":"IBM","rank":5,"slug":"ibm","critical":10,"exploited":0,"vulnerabilities":42,"url":"https://junglewise.ai/threats/vendors/ibm"},{"hub":true,"high":15,"name":"Npm","rank":6,"slug":"npm","critical":2,"exploited":0,"vulnerabilities":44,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":24,"name":"Pip","rank":7,"slug":"pip","critical":1,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":21,"name":"SourceCodester","rank":8,"slug":"sourcecodester","critical":0,"exploited":0,"vulnerabilities":33,"url":"https://junglewise.ai/threats/vendors/sourcecodester"},{"hub":true,"high":16,"name":"Ubiquiti","rank":9,"slug":"ubiquiti","critical":4,"exploited":0,"vulnerabilities":20,"url":"https://junglewise.ai/threats/vendors/ubiquiti"},{"hub":true,"high":2,"name":"Adobe","rank":10,"slug":"adobe","critical":8,"exploited":1,"vulnerabilities":11,"url":"https://junglewise.ai/threats/vendors/adobe"}],"generated_at":"2026-09-26T10:07:00.179841+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-14417","cvss":10,"slug":"cve-2026-14417-google-chrome-use-after-free-in-dawn","title":"Google Chrome use after free in Dawn","severity":"info","exploited":false,"published_at":"2026-07-01T23:16:50.17+00:00","url":"https://junglewise.ai/threats/cve-2026-14417-google-chrome-use-after-free-in-dawn"},{"cve":"CVE-2026-13787","cvss":10,"slug":"cve-2026-13787-google-chrome-use-after-free-in-chromoting","title":"Google Chrome use after free in Chromoting","severity":"info","exploited":false,"published_at":"2026-06-30T23:16:53.53+00:00","url":"https://junglewise.ai/threats/cve-2026-13787-google-chrome-use-after-free-in-chromoting"},{"cve":"CVE-2026-13782","cvss":10,"slug":"cve-2026-13782-google-chrome-use-after-free-in-browser-sandbox-escape","title":"Google Chrome use after free in Browser sandbox escape","severity":"info","exploited":false,"published_at":"2026-06-30T23:16:53.063+00:00","url":"https://junglewise.ai/threats/cve-2026-13782-google-chrome-use-after-free-in-browser-sandbox-escape"}],"high":0,"name":"Google Chrome","rank":1,"slug":"chrome","score":427,"vendor":{"name":"Google","slug":"google"},"critical":0,"max_cvss":10,"max_epss":null,"exploited":0,"vulnerabilities":427,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2026-27780","cvss":9.8,"epss":0.0064,"slug":"cve-2026-27780-gitea-branch-protection-bypass-via-bufio-scanner-error-handling","title":"Gitea branch protection bypass via bufio.Scanner error handling in pre-receive hooks","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:59.347+00:00","url":"https://junglewise.ai/threats/cve-2026-27780-gitea-branch-protection-bypass-via-bufio-scanner-error-handling"},{"cve":"CVE-2026-26292","cvss":9.8,"epss":0.0065,"slug":"cve-2026-26292-gitea-migration-transport-bypass-in-lfs-mirror-operations","title":"Gitea migration transport bypass in LFS mirror operations","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:58.517+00:00","url":"https://junglewise.ai/threats/cve-2026-26292-gitea-migration-transport-bypass-in-lfs-mirror-operations"},{"cve":"CVE-2026-20896","cvss":9.8,"epss":0.0078,"slug":"cve-2026-20896-gitea-docker-image-authentication-bypass-via-trusted-proxy","title":"Gitea Docker image authentication bypass via trusted proxy misconfiguration","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:56.66+00:00","url":"https://junglewise.ai/threats/cve-2026-20896-gitea-docker-image-authentication-bypass-via-trusted-proxy"}],"high":21,"name":"Go Code.gitea.io/Gitea","rank":2,"slug":"code-gitea-io-gitea","score":125,"vendor":{"name":"Go","slug":"go"},"critical":9,"max_cvss":9.8,"max_epss":0.4074,"exploited":0,"vulnerabilities":38,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"hub":true,"top":[{"cve":"CVE-2026-27780","cvss":9.8,"epss":0.0064,"slug":"cve-2026-27780-gitea-branch-protection-bypass-via-bufio-scanner-error-handling","title":"Gitea branch protection bypass via bufio.Scanner error handling in pre-receive hooks","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:59.347+00:00","url":"https://junglewise.ai/threats/cve-2026-27780-gitea-branch-protection-bypass-via-bufio-scanner-error-handling"},{"cve":"CVE-2026-26292","cvss":9.8,"epss":0.0065,"slug":"cve-2026-26292-gitea-migration-transport-bypass-in-lfs-mirror-operations","title":"Gitea migration transport bypass in LFS mirror operations","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:58.517+00:00","url":"https://junglewise.ai/threats/cve-2026-26292-gitea-migration-transport-bypass-in-lfs-mirror-operations"},{"cve":"CVE-2026-58426","cvss":9.6,"epss":0.0018,"slug":"cve-2026-58426-gitea-actions-hmac-ambiguity-in-artifacts-v4-signed-urls","title":"Gitea Actions HMAC ambiguity in Artifacts V4 signed URLs","severity":"critical","exploited":false,"published_at":"2026-07-03T21:17:05.77+00:00","url":"https://junglewise.ai/threats/cve-2026-58426-gitea-actions-hmac-ambiguity-in-artifacts-v4-signed-urls"}],"high":22,"name":"Gitea","rank":3,"slug":"gitea","score":123,"vendor":{"name":"Gitea","slug":"gitea"},"critical":8,"max_cvss":9.8,"max_epss":0.4074,"exploited":0,"vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/gitea"},{"hub":true,"top":[{"cve":"CVE-2026-58289","cvss":9,"slug":"cve-2026-58289-microsoft-edge-type-confusion-remote-code-execution","title":"Microsoft Edge type confusion remote code execution","severity":"critical","exploited":false,"published_at":"2026-07-03T21:17:03.64+00:00","url":"https://junglewise.ai/threats/cve-2026-58289-microsoft-edge-type-confusion-remote-code-execution"},{"cve":"CVE-2026-57981","cvss":8.8,"slug":"cve-2026-57981-microsoft-edge-use-after-free-remote-code-execution","title":"Microsoft Edge use after free remote code execution","severity":"high","exploited":false,"published_at":"2026-07-03T21:17:01.313+00:00","url":"https://junglewise.ai/threats/cve-2026-57981-microsoft-edge-use-after-free-remote-code-execution"},{"cve":"CVE-2026-57974","cvss":8.8,"slug":"cve-2026-57974-microsoft-edge-integer-overflow-remote-code-execution","title":"Microsoft Edge integer overflow remote code execution","severity":"high","exploited":false,"published_at":"2026-07-03T21:17:00.957+00:00","url":"https://junglewise.ai/threats/cve-2026-57974-microsoft-edge-integer-overflow-remote-code-execution"}],"high":30,"name":"Microsoft Edge","rank":4,"slug":"edge-chromium-based","score":107,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":1,"max_cvss":9,"max_epss":null,"exploited":0,"vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"hub":true,"top":[{"cve":"CVE-2025-71375","cvss":8.1,"epss":0.0052,"slug":"cve-2025-71375-picklescan-detection-bypass-via-operator-methodcaller","title":"picklescan detection bypass via _operator.methodcaller","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:23.347+00:00","url":"https://junglewise.ai/threats/cve-2025-71375-picklescan-detection-bypass-via-operator-methodcaller"},{"cve":"CVE-2025-71373","cvss":8.1,"slug":"cve-2025-71373-picklescan-security-bypass-via-operator-methodcaller","title":"picklescan security bypass via operator.methodcaller","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:23.22+00:00","url":"https://junglewise.ai/threats/cve-2025-71373-picklescan-security-bypass-via-operator-methodcaller"},{"cve":"CVE-2025-71372","cvss":8.1,"slug":"cve-2025-71372-picklescan-detection-bypass-via-numpy-getlincoef-gadget","title":"Picklescan detection bypass via numpy getlincoef gadget","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:23.097+00:00","url":"https://junglewise.ai/threats/cve-2025-71372-picklescan-detection-bypass-via-numpy-getlincoef-gadget"}],"high":23,"name":"Pip Picklescan","rank":5,"slug":"picklescan","score":70,"vendor":{"name":"Pip","slug":"pip"},"critical":0,"max_cvss":8.1,"max_epss":0.0084,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"hub":true,"top":[{"cvss":9.3,"slug":"openclaw-qqbot-authorization-bypass-in-admin-commands-70474b74","title":"OpenClaw QQBot authorization bypass in admin commands","severity":"critical","exploited":false,"published_at":"2026-07-02T16:48:45+00:00","url":"https://junglewise.ai/threats/openclaw-qqbot-authorization-bypass-in-admin-commands-70474b74"},{"cvss":8.8,"slug":"openclaw-authorization-bypass-in-telegram-interactive-callbacks-7432a474","title":"OpenClaw authorization bypass in Telegram interactive callbacks","severity":"high","exploited":false,"published_at":"2026-07-02T17:18:51+00:00","url":"https://junglewise.ai/threats/openclaw-authorization-bypass-in-telegram-interactive-callbacks-7432a474"},{"cvss":8.8,"slug":"openclaw-privilege-escalation-in-control-ui-websocket-74ceeb42","title":"OpenClaw privilege escalation in Control UI WebSocket","severity":"high","exploited":false,"published_at":"2026-07-02T16:43:53+00:00","url":"https://junglewise.ai/threats/openclaw-privilege-escalation-in-control-ui-websocket-74ceeb42"}],"high":15,"name":"Openclaw","rank":6,"slug":"openclaw","score":64,"vendor":{"name":"Openclaw","slug":"openclaw"},"critical":1,"max_cvss":9.3,"max_epss":null,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/openclaw"},{"hub":true,"top":[{"cve":"CVE-2026-48282","cvss":10,"epss":0.0102,"slug":"cve-2026-48282-adobe-coldfusion-path-traversal-in-multiple-versions","title":"Adobe ColdFusion path traversal in multiple versions","severity":"critical","exploited":true,"published_at":"2026-06-30T16:16:54.533+00:00","url":"https://junglewise.ai/threats/cve-2026-48282-adobe-coldfusion-path-traversal-in-multiple-versions"},{"cve":"CVE-2026-48283","cvss":10,"slug":"cve-2026-48283-adobe-coldfusion-unrestricted-file-upload-in-web-server","title":"Adobe ColdFusion unrestricted file upload in web server","severity":"critical","exploited":false,"published_at":"2026-06-30T16:16:54.643+00:00","url":"https://junglewise.ai/threats/cve-2026-48283-adobe-coldfusion-unrestricted-file-upload-in-web-server"},{"cve":"CVE-2026-48281","cvss":10,"slug":"cve-2026-48281-adobe-coldfusion-arbitrary-code-execution-via-improper-input","title":"Adobe ColdFusion arbitrary code execution via improper input validation","severity":"critical","exploited":false,"published_at":"2026-06-30T16:16:54.427+00:00","url":"https://junglewise.ai/threats/cve-2026-48281-adobe-coldfusion-arbitrary-code-execution-via-improper-input"}],"high":2,"name":"Adobe ColdFusion","rank":7,"slug":"coldfusion","score":59,"vendor":{"name":"Adobe","slug":"adobe"},"critical":7,"max_cvss":10,"max_epss":0.0102,"exploited":1,"vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/coldfusion"},{"hub":true,"top":[{"cve":"CVE-2022-46295","cvss":7.8,"epss":0.0085,"slug":"cve-2022-46295-open-babel-out-of-bounds-write-in-msi-parser-translationvectors","title":"Open Babel out-of-bounds write in MSI parser translationVectors","severity":"high","exploited":false,"published_at":"2026-07-01T17:54:42+00:00","url":"https://junglewise.ai/threats/cve-2022-46295-open-babel-out-of-bounds-write-in-msi-parser-translationvectors"},{"cve":"CVE-2022-46294","cvss":7.8,"epss":0.0082,"slug":"cve-2022-46294-open-babel-out-of-bounds-write-in-mopac-input-parser","title":"Open Babel out-of-bounds write in MOPAC input parser","severity":"high","exploited":false,"published_at":"2026-07-01T17:54:07+00:00","url":"https://junglewise.ai/threats/cve-2022-46294-open-babel-out-of-bounds-write-in-mopac-input-parser"},{"cve":"CVE-2022-46293","cvss":7.8,"epss":0.0085,"slug":"cve-2022-46293-open-babel-out-of-bounds-write-in-mopac-output-parser","title":"Open Babel out-of-bounds write in MOPAC output parser","severity":"high","exploited":false,"published_at":"2026-07-01T17:53:28+00:00","url":"https://junglewise.ai/threats/cve-2022-46293-open-babel-out-of-bounds-write-in-mopac-output-parser"}],"high":17,"name":"Pip Openbabel","rank":8,"slug":"openbabel","score":56,"vendor":{"name":"Pip","slug":"pip"},"critical":0,"max_cvss":7.8,"max_epss":0.0085,"exploited":0,"vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"hub":true,"top":[{"cve":"CVE-2026-13125","cvss":8.8,"slug":"cve-2026-13125-geovision-geowebplayer-authentication-bypass-in-websocket-server","title":"GeoVision GeoWebPlayer authentication bypass in WebSocket server","severity":"high","exploited":false,"published_at":"2026-07-02T04:17:09.79+00:00","url":"https://junglewise.ai/threats/cve-2026-13125-geovision-geowebplayer-authentication-bypass-in-websocket-server"},{"cve":"CVE-2026-57278","cvss":8.3,"slug":"cve-2026-57278-geovision-geowebplayer-buffer-overflow-in-ip-field","title":"GeoVision GeoWebPlayer buffer overflow in ip field","severity":"high","exploited":false,"published_at":"2026-07-02T04:17:15.38+00:00","url":"https://junglewise.ai/threats/cve-2026-57278-geovision-geowebplayer-buffer-overflow-in-ip-field"},{"cve":"CVE-2026-57277","cvss":8.3,"slug":"cve-2026-57277-geovision-geowebplayer-stack-buffer-overflow-in-connectioninfo","title":"GeoVision GeoWebPlayer stack buffer overflow in connectionInfo handler","severity":"high","exploited":false,"published_at":"2026-07-02T04:17:15.157+00:00","url":"https://junglewise.ai/threats/cve-2026-57277-geovision-geowebplayer-stack-buffer-overflow-in-connectioninfo"}],"high":18,"name":"Geovision GeoWebPlayer","rank":9,"slug":"geowebplayer","score":54,"vendor":{"name":"Geovision","slug":"geovision"},"critical":0,"max_cvss":8.8,"max_epss":null,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/geowebplayer"},{"hub":true,"top":[{"cve":"CVE-2026-10134","cvss":10,"slug":"cve-2026-10134-ibm-langflow-oss-unauthenticated-rce-in-pythoncodestructuredtool","title":"IBM Langflow OSS unauthenticated RCE in PythonCodeStructuredTool","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:26.883+00:00","url":"https://junglewise.ai/threats/cve-2026-10134-ibm-langflow-oss-unauthenticated-rce-in-pythoncodestructuredtool"},{"cve":"CVE-2026-7873","cvss":9.9,"slug":"cve-2026-7873-ibm-langflow-oss-code-injection-in-code-validation-endpoint","title":"IBM Langflow OSS code injection in code validation endpoint","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:31.75+00:00","url":"https://junglewise.ai/threats/cve-2026-7873-ibm-langflow-oss-code-injection-in-code-validation-endpoint"},{"cve":"CVE-2026-7871","cvss":9.8,"slug":"cve-2026-7871-ibm-langflow-oss-insecure-deserialization-in-redis-cache-backend","title":"IBM Langflow OSS insecure deserialization in Redis cache backend","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:31.543+00:00","url":"https://junglewise.ai/threats/cve-2026-7871-ibm-langflow-oss-insecure-deserialization-in-redis-cache-backend"}],"high":4,"name":"IBM Langflow","rank":10,"slug":"langflow-oss","score":54,"vendor":{"name":"IBM","slug":"ibm"},"critical":7,"max_cvss":10,"max_epss":null,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"hub":true,"top":[{"cve":"CVE-2026-53362","cvss":6.2,"epss":0.0071,"slug":"cve-2026-53362-linux-kernel-buffer-overflow-in-ipv6-paged-allocation","title":"Linux Kernel buffer overflow in IPv6 paged allocation","severity":"critical","exploited":true,"published_at":"2026-07-04T12:17:02.113+00:00","url":"https://junglewise.ai/threats/cve-2026-53362-linux-kernel-buffer-overflow-in-ipv6-paged-allocation"},{"cve":"CVE-2026-53359","cvss":7.8,"slug":"cve-2026-53359-linux-kernel-kvm-shadow-paging-use-after-free-in-x86-mmu","title":"Linux Kernel KVM shadow paging use-after-free in x86 MMU","severity":"high","exploited":false,"published_at":"2026-07-04T12:17:01.76+00:00","url":"https://junglewise.ai/threats/cve-2026-53359-linux-kernel-kvm-shadow-paging-use-after-free-in-x86-mmu"},{"cve":"CVE-2026-53360","cvss":8.8,"slug":"cve-2026-53360-linux-kernel-kvm-sev-heap-overflow-in-ghcb-scratch-area","title":"Linux Kernel KVM SEV heap overflow in GHCB scratch area","severity":"info","exploited":false,"published_at":"2026-07-04T12:17:01.88+00:00","url":"https://junglewise.ai/threats/cve-2026-53360-linux-kernel-kvm-sev-heap-overflow-in-ghcb-scratch-area"}],"high":1,"name":"Linux Kernel","rank":11,"slug":"kernel","score":45,"vendor":{"name":"Linux","slug":"linux"},"critical":1,"max_cvss":8.8,"max_epss":0.0071,"exploited":1,"vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2022-46295","cvss":7.8,"epss":0.0085,"slug":"cve-2022-46295-open-babel-out-of-bounds-write-in-msi-parser-translationvectors","title":"Open Babel out-of-bounds write in MSI parser translationVectors","severity":"high","exploited":false,"published_at":"2026-07-01T17:54:42+00:00","url":"https://junglewise.ai/threats/cve-2022-46295-open-babel-out-of-bounds-write-in-msi-parser-translationvectors"},{"cve":"CVE-2022-46293","cvss":7.8,"epss":0.0085,"slug":"cve-2022-46293-open-babel-out-of-bounds-write-in-mopac-output-parser","title":"Open Babel out-of-bounds write in MOPAC output parser","severity":"high","exploited":false,"published_at":"2026-07-01T17:53:28+00:00","url":"https://junglewise.ai/threats/cve-2022-46293-open-babel-out-of-bounds-write-in-mopac-output-parser"},{"cve":"CVE-2022-46291","cvss":7.8,"epss":0.0082,"slug":"cve-2022-46291-open-babel-out-of-bounds-write-in-gaussian-translationvectors","title":"Open Babel out-of-bounds write in Gaussian translationVectors","severity":"high","exploited":false,"published_at":"2026-07-01T17:51:06+00:00","url":"https://junglewise.ai/threats/cve-2022-46291-open-babel-out-of-bounds-write-in-gaussian-translationvectors"}],"high":13,"name":"Openbabel Open Babel","rank":12,"slug":"open-babel","score":40,"vendor":{"name":"Openbabel","slug":"openbabel"},"critical":0,"max_cvss":7.8,"max_epss":0.0085,"exploited":0,"vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/open-babel"},{"hub":true,"top":[{"cve":"CVE-2026-14772","cvss":7.3,"slug":"cve-2026-14772-sourcecodester-class-and-exam-timetabling-system-sql-injection-in","title":"SourceCodester Class and Exam Timetabling System SQL injection in edit_course1.php","severity":"high","exploited":false,"published_at":"2026-07-05T22:16:53.063+00:00","url":"https://junglewise.ai/threats/cve-2026-14772-sourcecodester-class-and-exam-timetabling-system-sql-injection-in"},{"cve":"CVE-2026-14771","cvss":7.3,"slug":"cve-2026-14771-sourcecodester-class-and-exam-timetabling-system-sql-injection-in","title":"SourceCodester Class and Exam Timetabling System SQL injection in edit_exam1.php","severity":"high","exploited":false,"published_at":"2026-07-05T22:16:52.897+00:00","url":"https://junglewise.ai/threats/cve-2026-14771-sourcecodester-class-and-exam-timetabling-system-sql-injection-in"},{"cve":"CVE-2026-14770","cvss":7.3,"slug":"cve-2026-14770-sourcecodester-class-and-exam-timetabling-system-sql-injection-in","title":"SourceCodester Class and Exam Timetabling System SQL injection in edit_room.php","severity":"high","exploited":false,"published_at":"2026-07-05T21:16:54.31+00:00","url":"https://junglewise.ai/threats/cve-2026-14770-sourcecodester-class-and-exam-timetabling-system-sql-injection-in"}],"high":13,"name":"SourceCodester Class and Exam Timetabling System","rank":13,"slug":"class-and-exam-timetabling-system","score":39,"vendor":{"name":"SourceCodester","slug":"sourcecodester"},"critical":0,"max_cvss":7.3,"max_epss":null,"exploited":0,"vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/class-and-exam-timetabling-system"},{"hub":true,"top":[{"cve":"CVE-2026-43703","cvss":6.1,"slug":"cve-2026-43703-apple-ios-and-macos-denial-of-service-in-web-content-processing","title":"Apple iOS and macOS denial of service in web content processing","severity":"info","exploited":false,"published_at":"2026-06-29T20:17:35.27+00:00","url":"https://junglewise.ai/threats/cve-2026-43703-apple-ios-and-macos-denial-of-service-in-web-content-processing"},{"cve":"CVE-2026-43718","cvss":4.3,"slug":"cve-2026-43718-apple-safari-and-os-stack-overflow-via-web-content","title":"Apple Safari and OS stack overflow via web content","severity":"info","exploited":false,"published_at":"2026-06-29T20:17:36.457+00:00","url":"https://junglewise.ai/threats/cve-2026-43718-apple-safari-and-os-stack-overflow-via-web-content"},{"cve":"CVE-2026-43740","cvss":0,"slug":"cve-2026-43740-apple-safari-and-oss-memory-disclosure-via-web-content","title":"Apple Safari and OSs memory disclosure via web content","severity":"info","exploited":false,"published_at":"2026-06-29T20:17:37.6+00:00","url":"https://junglewise.ai/threats/cve-2026-43740-apple-safari-and-oss-memory-disclosure-via-web-content"}],"high":0,"name":"Apple iPadOS","rank":14,"slug":"ipados","score":37,"vendor":{"name":"Apple","slug":"apple"},"critical":0,"max_cvss":6.1,"max_epss":null,"exploited":0,"vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/ipados"},{"hub":true,"top":[{"cve":"CVE-2026-43703","cvss":6.1,"slug":"cve-2026-43703-apple-ios-and-macos-denial-of-service-in-web-content-processing","title":"Apple iOS and macOS denial of service in web content processing","severity":"info","exploited":false,"published_at":"2026-06-29T20:17:35.27+00:00","url":"https://junglewise.ai/threats/cve-2026-43703-apple-ios-and-macos-denial-of-service-in-web-content-processing"},{"cve":"CVE-2026-43718","cvss":4.3,"slug":"cve-2026-43718-apple-safari-and-os-stack-overflow-via-web-content","title":"Apple Safari and OS stack overflow via web content","severity":"info","exploited":false,"published_at":"2026-06-29T20:17:36.457+00:00","url":"https://junglewise.ai/threats/cve-2026-43718-apple-safari-and-os-stack-overflow-via-web-content"},{"cve":"CVE-2026-43740","cvss":0,"slug":"cve-2026-43740-apple-safari-and-oss-memory-disclosure-via-web-content","title":"Apple Safari and OSs memory disclosure via web content","severity":"info","exploited":false,"published_at":"2026-06-29T20:17:37.6+00:00","url":"https://junglewise.ai/threats/cve-2026-43740-apple-safari-and-oss-memory-disclosure-via-web-content"}],"high":0,"name":"Apple macOS","rank":15,"slug":"macos-tahoe","score":36,"vendor":{"name":"Apple","slug":"apple"},"critical":0,"max_cvss":6.1,"max_epss":null,"exploited":0,"vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"hub":true,"top":[{"cve":"CVE-2026-24251","cvss":7.8,"slug":"cve-2026-24251-nvidia-megatron-bridge-deserialization-in-code-resource","title":"NVIDIA Megatron Bridge deserialization in code resource management","severity":"high","exploited":false,"published_at":"2026-07-01T16:16:45.573+00:00","url":"https://junglewise.ai/threats/cve-2026-24251-nvidia-megatron-bridge-deserialization-in-code-resource"},{"cve":"CVE-2026-24250","cvss":7.8,"slug":"cve-2026-24250-nvidia-megatron-bridge-insecure-deserialization","title":"NVIDIA Megatron Bridge insecure deserialization","severity":"high","exploited":false,"published_at":"2026-07-01T16:16:45.467+00:00","url":"https://junglewise.ai/threats/cve-2026-24250-nvidia-megatron-bridge-insecure-deserialization"},{"cve":"CVE-2026-24249","cvss":7.8,"slug":"cve-2026-24249-nvidia-megatron-bridge-deserialization-of-untrusted-data","title":"NVIDIA Megatron Bridge deserialization of untrusted data","severity":"high","exploited":false,"published_at":"2026-07-01T16:16:45.357+00:00","url":"https://junglewise.ai/threats/cve-2026-24249-nvidia-megatron-bridge-deserialization-of-untrusted-data"}],"high":11,"name":"Nvidia Megatron-Bridge","rank":16,"slug":"megatron-bridge","score":33,"vendor":{"name":"Nvidia","slug":"nvidia"},"critical":0,"max_cvss":7.8,"max_epss":null,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/megatron-bridge"},{"hub":true,"top":[{"cve":"CVE-2026-14544","cvss":9.8,"slug":"cve-2026-14544-hp-hplip-integer-overflow-in-hpcups-processing-path","title":"HP HPLIP integer overflow in hpcups processing path","severity":"critical","exploited":false,"published_at":"2026-07-03T08:16:24.433+00:00","url":"https://junglewise.ai/threats/cve-2026-14544-hp-hplip-integer-overflow-in-hpcups-processing-path"},{"cve":"CVE-2026-58016","cvss":7.5,"slug":"cve-2026-58016-gnome-glib-out-of-bounds-read-in-d-bus-introspection-xml-parsing","title":"GNOME GLib out-of-bounds read in D-Bus introspection XML parsing","severity":"high","exploited":false,"published_at":"2026-06-30T13:19:17.84+00:00","url":"https://junglewise.ai/threats/cve-2026-58016-gnome-glib-out-of-bounds-read-in-d-bus-introspection-xml-parsing"},{"cve":"CVE-2026-58379","cvss":7.3,"slug":"cve-2026-58379-gimp-heap-buffer-overflow-in-paint-shop-pro-parser","title":"GIMP heap buffer overflow in Paint Shop Pro parser","severity":"high","exploited":false,"published_at":"2026-07-03T19:16:37.04+00:00","url":"https://junglewise.ai/threats/cve-2026-58379-gimp-heap-buffer-overflow-in-paint-shop-pro-parser"}],"high":4,"name":"Red Hat Enterprise Linux 9","rank":17,"slug":"enterprise-linux-9","score":32,"vendor":{"name":"Red Hat","slug":"red-hat"},"critical":1,"max_cvss":9.8,"max_epss":null,"exploited":0,"vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"hub":true,"top":[{"cve":"CVE-2026-56247","cvss":8.8,"slug":"cve-2026-56247-capgo-privilege-escalation-via-cross-scope-rbac-role-assignment","title":"Capgo privilege escalation via cross-scope RBAC role assignment","severity":"high","exploited":false,"published_at":"2026-06-30T23:17:29.107+00:00","url":"https://junglewise.ai/threats/cve-2026-56247-capgo-privilege-escalation-via-cross-scope-rbac-role-assignment"},{"cve":"CVE-2026-56230","cvss":8.8,"slug":"cve-2026-56230-capgo-bola-in-middlewarekey-via-x-limited-key-id-header","title":"Capgo BOLA in middlewareKey via x-limited-key-id header","severity":"high","exploited":false,"published_at":"2026-06-30T23:17:28.853+00:00","url":"https://junglewise.ai/threats/cve-2026-56230-capgo-bola-in-middlewarekey-via-x-limited-key-id-header"},{"cve":"CVE-2026-56233","cvss":8.3,"slug":"cve-2026-56233-capgo-path-traversal-in-builder-upload-proxy","title":"Capgo path traversal in builder upload proxy","severity":"high","exploited":false,"published_at":"2026-06-30T23:17:28.98+00:00","url":"https://junglewise.ai/threats/cve-2026-56233-capgo-path-traversal-in-builder-upload-proxy"}],"high":8,"name":"Capgo","rank":18,"slug":"capgo","score":31,"vendor":{"name":"Capgo","slug":"capgo"},"critical":0,"max_cvss":8.8,"max_epss":null,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/capgo"},{"hub":true,"top":[{"cve":"CVE-2026-54903","cvss":8.7,"slug":"cve-2026-54903-ohler55-oj-integer-overflow-in-oj-load-heap-corruption","title":"ohler55 Oj integer overflow in Oj.load heap corruption","severity":"high","exploited":false,"published_at":"2026-07-01T00:16:33.707+00:00","url":"https://junglewise.ai/threats/cve-2026-54903-ohler55-oj-integer-overflow-in-oj-load-heap-corruption"},{"cve":"CVE-2026-54902","cvss":8.7,"slug":"cve-2026-54902-ohler55-oj-use-after-free-in-oj-parser-saj-mode","title":"ohler55 Oj use-after-free in Oj::Parser SAJ mode","severity":"high","exploited":false,"published_at":"2026-07-01T00:16:33.587+00:00","url":"https://junglewise.ai/threats/cve-2026-54902-ohler55-oj-use-after-free-in-oj-parser-saj-mode"},{"cve":"CVE-2026-54901","cvss":8.7,"slug":"cve-2026-54901-ohler55-oj-use-after-free-in-oj-parser-gc-marking","title":"ohler55 Oj Use-After-Free in Oj::Parser GC marking","severity":"high","exploited":false,"published_at":"2026-07-01T00:16:33.467+00:00","url":"https://junglewise.ai/threats/cve-2026-54901-ohler55-oj-use-after-free-in-oj-parser-gc-marking"}],"high":10,"name":"Rubygems Oj","rank":19,"slug":"oj","score":31,"vendor":{"name":"Rubygems","slug":"rubygems"},"critical":0,"max_cvss":8.7,"max_epss":null,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/oj"},{"hub":true,"top":[{"cve":"CVE-2026-43718","cvss":4.3,"slug":"cve-2026-43718-apple-safari-and-os-stack-overflow-via-web-content","title":"Apple Safari and OS stack overflow via web content","severity":"info","exploited":false,"published_at":"2026-06-29T20:17:36.457+00:00","url":"https://junglewise.ai/threats/cve-2026-43718-apple-safari-and-os-stack-overflow-via-web-content"},{"cve":"CVE-2026-43740","cvss":0,"slug":"cve-2026-43740-apple-safari-and-oss-memory-disclosure-via-web-content","title":"Apple Safari and OSs memory disclosure via web content","severity":"info","exploited":false,"published_at":"2026-06-29T20:17:37.6+00:00","url":"https://junglewise.ai/threats/cve-2026-43740-apple-safari-and-oss-memory-disclosure-via-web-content"},{"cve":"CVE-2026-43735","cvss":0,"slug":"cve-2026-43735-apple-safari-and-os-cross-origin-data-exfiltration","title":"Apple Safari and OS cross-origin data exfiltration","severity":"info","exploited":false,"published_at":"2026-06-29T20:17:37.507+00:00","url":"https://junglewise.ai/threats/cve-2026-43735-apple-safari-and-os-cross-origin-data-exfiltration"}],"high":0,"name":"Apple Safari","rank":20,"slug":"safari","score":30,"vendor":{"name":"Apple","slug":"apple"},"critical":0,"max_cvss":4.3,"max_epss":null,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/safari"},{"hub":true,"top":[{"cve":"CVE-2026-14544","cvss":9.8,"slug":"cve-2026-14544-hp-hplip-integer-overflow-in-hpcups-processing-path","title":"HP HPLIP integer overflow in hpcups processing path","severity":"critical","exploited":false,"published_at":"2026-07-03T08:16:24.433+00:00","url":"https://junglewise.ai/threats/cve-2026-14544-hp-hplip-integer-overflow-in-hpcups-processing-path"},{"cve":"CVE-2026-58016","cvss":7.5,"slug":"cve-2026-58016-gnome-glib-out-of-bounds-read-in-d-bus-introspection-xml-parsing","title":"GNOME GLib out-of-bounds read in D-Bus introspection XML parsing","severity":"high","exploited":false,"published_at":"2026-06-30T13:19:17.84+00:00","url":"https://junglewise.ai/threats/cve-2026-58016-gnome-glib-out-of-bounds-read-in-d-bus-introspection-xml-parsing"},{"cve":"CVE-2026-58014","cvss":7.3,"slug":"cve-2026-58014-gnome-glib-off-by-one-error-in-g-key-file-get-locale-string-list","title":"GNOME GLib off-by-one error in g_key_file_get_locale_string_list","severity":"high","exploited":false,"published_at":"2026-06-30T13:19:17.58+00:00","url":"https://junglewise.ai/threats/cve-2026-58014-gnome-glib-off-by-one-error-in-g-key-file-get-locale-string-list"}],"high":3,"name":"Red Hat Enterprise Linux 8","rank":21,"slug":"enterprise-linux-8","score":29,"vendor":{"name":"Red Hat","slug":"red-hat"},"critical":1,"max_cvss":9.8,"max_epss":null,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"hub":true,"top":[{"cvss":8.8,"slug":"surrealdb-session-hijacking-via-http-rpc-session-leak-016308ef","title":"SurrealDB session hijacking via HTTP RPC session leak","severity":"high","exploited":false,"published_at":"2026-07-01T20:00:17+00:00","url":"https://junglewise.ai/threats/surrealdb-session-hijacking-via-http-rpc-session-leak-016308ef"},{"cvss":8.1,"slug":"surrealdb-privilege-escalation-via-http-rpc-session-race-condition-871af91c","title":"SurrealDB privilege escalation via HTTP RPC session race condition","severity":"high","exploited":false,"published_at":"2026-07-01T20:02:06+00:00","url":"https://junglewise.ai/threats/surrealdb-privilege-escalation-via-http-rpc-session-race-condition-871af91c"},{"cvss":7.5,"slug":"surrealdb-unauthenticated-remote-dos-in-rpc-use-handler-295d4555","title":"SurrealDB unauthenticated remote DoS in RPC use handler","severity":"high","exploited":false,"published_at":"2026-07-01T20:04:22+00:00","url":"https://junglewise.ai/threats/surrealdb-unauthenticated-remote-dos-in-rpc-use-handler-295d4555"}],"high":4,"name":"Rust Surrealdb","rank":22,"slug":"surrealdb","score":28,"vendor":{"name":"Rust","slug":"rust"},"critical":0,"max_cvss":8.8,"max_epss":null,"exploited":0,"vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/surrealdb"},{"hub":true,"top":[{"cve":"CVE-2026-14544","cvss":9.8,"slug":"cve-2026-14544-hp-hplip-integer-overflow-in-hpcups-processing-path","title":"HP HPLIP integer overflow in hpcups processing path","severity":"critical","exploited":false,"published_at":"2026-07-03T08:16:24.433+00:00","url":"https://junglewise.ai/threats/cve-2026-14544-hp-hplip-integer-overflow-in-hpcups-processing-path"},{"cve":"CVE-2026-58016","cvss":7.5,"slug":"cve-2026-58016-gnome-glib-out-of-bounds-read-in-d-bus-introspection-xml-parsing","title":"GNOME GLib out-of-bounds read in D-Bus introspection XML parsing","severity":"high","exploited":false,"published_at":"2026-06-30T13:19:17.84+00:00","url":"https://junglewise.ai/threats/cve-2026-58016-gnome-glib-out-of-bounds-read-in-d-bus-introspection-xml-parsing"},{"cve":"CVE-2026-58014","cvss":7.3,"slug":"cve-2026-58014-gnome-glib-off-by-one-error-in-g-key-file-get-locale-string-list","title":"GNOME GLib off-by-one error in g_key_file_get_locale_string_list","severity":"high","exploited":false,"published_at":"2026-06-30T13:19:17.58+00:00","url":"https://junglewise.ai/threats/cve-2026-58014-gnome-glib-off-by-one-error-in-g-key-file-get-locale-string-list"}],"high":3,"name":"Red Hat Enterprise Linux 10","rank":23,"slug":"enterprise-linux-10","score":28,"vendor":{"name":"Red Hat","slug":"red-hat"},"critical":1,"max_cvss":9.8,"max_epss":null,"exploited":0,"vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"hub":true,"top":[{"cve":"CVE-2026-54402","cvss":9.9,"slug":"cve-2026-54402-ubiquiti-unifi-os-command-injection-via-improper-input-validation","title":"Ubiquiti UniFi OS command injection via improper input validation","severity":"critical","exploited":false,"published_at":"2026-07-02T15:17:03.837+00:00","url":"https://junglewise.ai/threats/cve-2026-54402-ubiquiti-unifi-os-command-injection-via-improper-input-validation"},{"cve":"CVE-2026-55116","cvss":9,"slug":"cve-2026-55116-ubiquiti-unifi-os-improper-access-control-in-multiple-gateways","title":"Ubiquiti UniFi OS improper access control in multiple gateways","severity":"critical","exploited":false,"published_at":"2026-07-02T15:17:05.633+00:00","url":"https://junglewise.ai/threats/cve-2026-55116-ubiquiti-unifi-os-improper-access-control-in-multiple-gateways"},{"cve":"CVE-2026-54404","cvss":8.8,"slug":"cve-2026-54404-ubiquiti-unifi-os-sql-injection-privilege-escalation","title":"Ubiquiti UniFi OS SQL injection privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-02T15:17:04.06+00:00","url":"https://junglewise.ai/threats/cve-2026-54404-ubiquiti-unifi-os-sql-injection-privilege-escalation"}],"high":5,"name":"Ubiquiti Cloud Gateway","rank":24,"slug":"cloud-gateway","score":27,"vendor":{"name":"Ubiquiti","slug":"ubiquiti"},"critical":2,"max_cvss":9.9,"max_epss":null,"exploited":0,"vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/cloud-gateway"},{"hub":true,"top":[{"cve":"CVE-2026-54402","cvss":9.9,"slug":"cve-2026-54402-ubiquiti-unifi-os-command-injection-via-improper-input-validation","title":"Ubiquiti UniFi OS command injection via improper input validation","severity":"critical","exploited":false,"published_at":"2026-07-02T15:17:03.837+00:00","url":"https://junglewise.ai/threats/cve-2026-54402-ubiquiti-unifi-os-command-injection-via-improper-input-validation"},{"cve":"CVE-2026-55116","cvss":9,"slug":"cve-2026-55116-ubiquiti-unifi-os-improper-access-control-in-multiple-gateways","title":"Ubiquiti UniFi OS improper access control in multiple gateways","severity":"critical","exploited":false,"published_at":"2026-07-02T15:17:05.633+00:00","url":"https://junglewise.ai/threats/cve-2026-55116-ubiquiti-unifi-os-improper-access-control-in-multiple-gateways"},{"cve":"CVE-2026-54404","cvss":8.8,"slug":"cve-2026-54404-ubiquiti-unifi-os-sql-injection-privilege-escalation","title":"Ubiquiti UniFi OS SQL injection privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-02T15:17:04.06+00:00","url":"https://junglewise.ai/threats/cve-2026-54404-ubiquiti-unifi-os-sql-injection-privilege-escalation"}],"high":5,"name":"Ubiquiti Dream Machine","rank":25,"slug":"dream-machine","score":27,"vendor":{"name":"Ubiquiti","slug":"ubiquiti"},"critical":2,"max_cvss":9.9,"max_epss":null,"exploited":0,"vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/dream-machine"}],"previous":null,"next":{"key":"2026-07-06","top":"Apache Camel","period":{"end":"2026-07-12","start":"2026-07-06"},"totals":{"high":461,"critical":93,"exploited":2,"technologies":948,"vulnerabilities":1592},"url":"https://junglewise.ai/threats/weekly/2026-07-06"}}