41 CVEs published May 23, 2026: 2 critical, 23 high, 3 medium, 13 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 16 in the results table.
Yesterday's Results
How to read these box scores · glossary
41 CVEs published. 25 box scores, 16 table rows — nothing truncated.
Linux Linux — net: skbuff: preserve shared-frag marker during coalescing
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0701 93.6 —
AFFECTED
Product Versions Fixed
Linux cef401de7be8c4e155c6746bfccf721a4fa5fab9 – —
Linux 3.9 – 5.10.257
TIMELINE
May 13 Reserved by CNA
May 23 Published (CNA: Linux)
Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .0170 75.4 —
AFFECTED
Product Versions Fixed
Dolibarr ERP CRM unspecified —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulnCheck)
Edimax EW-7438RPn webs formWpsStart os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0152 72.5 —
AFFECTED
Product Versions Fixed
EW-7438RPn 1.0 – —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulDB)
Edimax BR-6428NS POST Request formWlbasic command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0140 70.3 —
AFFECTED
Product Versions Fixed
BR-6428NS 1.10 – —
TIMELINE
May 22 Reserved by CNA
May 23 Published (CNA: VulDB)
Edimax BR-6428NS POST Request formWlanM system command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0116 64.6 —
AFFECTED
Product Versions Fixed
BR-6428NS 1.10 – —
TIMELINE
May 22 Reserved by CNA
May 23 Published (CNA: VulDB)
D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H N N 8.7 .0059 45.4 —
AFFECTED
Product Versions Fixed
DIR-601 unspecified —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulnCheck)
Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0054 43.2 —
AFFECTED
Product Versions Fixed
BR-6428NS 1.10 – —
TIMELINE
May 22 Reserved by CNA
May 23 Published (CNA: VulDB)
Edimax BR-6428NS POST Request formWirelessTbl buffer overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0054 43.2 —
AFFECTED
Product Versions Fixed
BR-6428NS 1.10 – —
TIMELINE
May 22 Reserved by CNA
May 23 Published (CNA: VulDB)
Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File Upload
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 8.7 .0045 37.7 —
AFFECTED
Product Versions Fixed
Redaxo CMS Mediapool unspecified —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulnCheck)
userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .0043 36.3 —
AFFECTED
Product Versions Fixed
userSpice 4.3.24 – —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulnCheck)
WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H L N 8.2 .0040 33.5 —
AFFECTED
Product Versions Fixed
WooCommerce PayPal Payments unspecified —
TIMELINE
May 22 Reserved by CNA
May 23 Published (CNA: Wordfence)
harmistechnology Ek Rishta — Joomla! Component Ek Rishta 2.10 SQL Injection via user_detail
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H L N 8.8 .0036 29.1 —
AFFECTED
Product Versions Fixed
Ek Rishta 2.10 – —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulnCheck)
harmistechnology EkRishta — Joomla! Component EkRishta 2.10 SQL Injection via username
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H L N 8.8 .0036 29.1 —
AFFECTED
Product Versions Fixed
EkRishta 2.10 – —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulnCheck)
Linux Linux — net: skbuff: propagate shared-frag marker through frag-transfer helpers
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N C H H H 8.8 .0034 26.7 —
AFFECTED
Product Versions Fixed
Linux cef401de7be8c4e155c6746bfccf721a4fa5fab9 – —
Linux 3.9 – 5.10.257
TIMELINE
May 1 Reserved by CNA
May 23 Published (CNA: Linux)
Behance Smartshop — Smartshop 1 SQL Injection via category.php
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H L N 8.8 .0033 26.4 —
AFFECTED
Product Versions Fixed
Smartshop 1.0 – —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulnCheck)
Behance Smartshop — Smartshop 1 SQL Injection via product.php id Parameter
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H L N 8.8 .0033 26.4 —
AFFECTED
Product Versions Fixed
Smartshop 1.0 – —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulnCheck)
Behance Smartshop — Smartshop 1 SQL Injection via search.php
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H L N 8.8 .0033 26.4 —
AFFECTED
Product Versions Fixed
Smartshop 1.0 – —
TIMELINE
May 23 Reserved by CNA
May 23 Published (CNA: VulnCheck)
QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H N N N L N N 2.9 .0029 21.7 —
AFFECTED
Product Versions Fixed
new-api 0.12.0 – —
TIMELINE
May 22 Reserved by CNA
May 23 Published (CNA: VulDB)
Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_get_screen' AJAX action
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0026 17.6 —
AFFECTED
Product Versions Fixed
Wishlist Member unspecified —
TIMELINE
Apr 16 Reserved by CNA
May 23 Published (CNA: Wordfence)
Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_export_settings' AJAX Action
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0025 16.4 —
AFFECTED
Product Versions Fixed
Wishlist Member unspecified —
TIMELINE
Apr 23 Reserved by CNA
May 23 Published (CNA: Wordfence)
Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0024 15.9 —
AFFECTED
Product Versions Fixed
Wishlist Member unspecified —
TIMELINE
Apr 23 Reserved by CNA
May 23 Published (CNA: Wordfence)
WishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX action
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0024 15.9 —
AFFECTED
Product Versions Fixed
Wishlist Member unspecified —
TIMELINE
Apr 23 Reserved by CNA
May 23 Published (CNA: Wordfence)
546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0024 15.0 —
AFFECTED
Product Versions Fixed
vps-inventory-monitoring 98c00b370668c96ae75e91c15548d9ea113652d9 – —
TIMELINE
May 22 Reserved by CNA
May 23 Published (CNA: VulDB)
omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0023 13.9 —
AFFECTED
Product Versions Fixed
amf 2.1.0 – —
TIMELINE
May 22 Reserved by CNA
May 23 Published (CNA: VulDB)
omec-project amf NGSetupRequest memory corruption
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0023 13.9 —
AFFECTED
Product Versions Fixed
amf 2.1.0 – —
TIMELINE
May 22 Reserved by CNA
May 23 Published (CNA: VulDB)
Methodology
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-05-23 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.