CVE
Info.com
  • Browse CVEs
  • Trends
  • Email Alerts
  • About

📊 CVE Trends & Statistics

Discover trending vulnerabilities and security insights

Last 7 Days Last 30 Days Last 90 Days Last Year
54,776
Total CVEs
2,092
Critical
7,263
High
7,964
Medium
846
Low
6.9
Avg CVSS Score

Severity Distribution

2,092
Critical
4%
Click to view
7,263
High
13%
Click to view
7,964
Medium
15%
Click to view
846
Low
2%
Click to view

Monthly CVE Trends

4264
May 2025
3799
Jun 2025
3933
Jul 2025
3737
Aug 2025
4537
Sep 2025
4389
Oct 2025
3116
Nov 2025
5643
Dec 2025
5143
Jan 2026
4817
Feb 2026
6326
Mar 2026
4235
Apr 2026

Top Affected Vendors

Linux
Click to view all CVEs
628
Npm
Click to view all CVEs
404
🔥 57
Go
Click to view all CVEs
350
🔥 42
Google
Click to view all CVEs
317
🔥 22
Microsoft
Click to view all CVEs
315
🔥 9
OpenClaw
Click to view all CVEs
277
🔥 25
Pip
Click to view all CVEs
253
🔥 36
Adobe
Click to view all CVEs
212
🔥 7
Composer
Click to view all CVEs
206
🔥 17
Ibm
Click to view all CVEs
199
🔥 3

Top Affected Products

Linux
Linux
Click to view all CVEs
628
OpenClaw
OpenClaw
Click to view all CVEs
274
🔥 24
chrome
Google
Click to view all CVEs
204
🔥 10
windows_10_1607
Microsoft
Click to view all CVEs
130
🔥 1
firefox
Mozilla
Click to view all CVEs
124
🔥 71
android
Google
Click to view all CVEs
110
🔥 11
macos
Apple
Click to view all CVEs
83
🔥 1
discourse
Discourse
Click to view all CVEs
81
openemr
Openemr
Click to view all CVEs
73
🔥 6
gitlab
Gitlab
Click to view all CVEs
72
🔥 1

🔥 Recently Published CVEs

CVE-2026-22754 HIGH - 7.5

Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-22753 HIGH - 7.5

Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filte...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-22748 MEDIUM - 5.3

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately,...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-22747 MEDIUM - 6.8

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the us...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-22746 LOW - 3.7

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then�...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-40451 MEDIUM - 6.1

DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's browser, and inject mali...

Vendor: DeepL Product: Chrome browser extension Published: Apr 22, 2026
CVE-2026-6835 MEDIUM - 6.1

The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result i...

Published: Apr 22, 2026
CVE-2026-6834 MEDIUM - 6.5

The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method....

Published: Apr 22, 2026
CVE-2026-6833 MEDIUM - 6.5

The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents....

Published: Apr 22, 2026
CVE-2026-6416 LOW - 2.7

Tanium addressed an uncontrolled resource consumption vulnerability in Interact....

Published: Apr 22, 2026

💬 Most Discussed CVEs

CVE-2026-24422
MEDIUM 💬 1 comment

phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly expose sensitive user information due to insufficient access controls. The OpenQu...

CVE-2026-1302
MEDIUM 💬 1 comment

The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and out...

CVE-2026-1680
💬 1 comment

Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via...

Browse CVEs Trends Email Alerts About

© 2026 CVEInfo.com - Aggregating CVE Information from Multiple Sources

Data sources: NVD, MITRE, GitHub Security Advisories