boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, May 23, 2026 · all times UTC← 2026-05-22 · archive · 2026-05-24 →

Security Box Score — May 23, 2026

41 CVEs published, led by Edimax (5).

41 CVEs published May 23, 2026: 2 critical, 23 high, 3 medium, 13 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 16 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published11172329——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

40 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux227553674483801120.47.8.0014+130 ▲
microsoft160530463711112286193.67.8.0047-22 ▼
red hat1062526247200.06.8.0041-9 ▼
apple154511528188715.66.2.0028+15 ▲
google16230176077417.48.8.0034+15 ▲
freebsd770520000.07.8.0020+7 ▲
suse220200000.08.2.0020+2 ▲
ubuntu010001100.02.7.02180
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco512534056866.77.8.1576+5 ▲
fortinet17430028342.99.1.8584-2 ▼
ivanti25230025480.08.8.8056+2 ▲
ubiquiti231200300.08.8.0068+2 ▲
f52220004150.09.2.3901+2 ▲
palo alto networks22110013150.08.6.6281+2 ▲
vmware01010071100.08.1.17420
check point00000010———0
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache922412603314.57.5.0080+6 ▲
mozilla553200900.09.6.0045+5 ▲
docker330300000.08.8.0022+3 ▲
drupal3310204133.35.1.0021+3 ▲
gitlab00000042———0
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
progress440400600.07.5.0036+4 ▲
oracle0312002700.07.5.00880
solarwinds032100103100.09.8.83620
adobe020200192100.08.6.0368-2 ▼
zohocorp110100000.08.4.0170+1 ▲
atlassian000000130———0
ibm00000060———0
sap00000060———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link110100300.08.7.0059+1 ▲
siemens110100000.08.7.0032+1 ▲
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44 ▲
open ises3737214210000.06.9.0021+37 ▲
netatalk3333113910000.06.4.0030+33 ▲
grafana102727162200.06.5.0033+7 ▲
dell121816110215.66.7.0019+7 ▲
nvidia16167900000.08.4.0060+16 ▲
trend micro1616213101216.37.8.0030+16 ▲
givanz11152760000.08.3.0028+7 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2026-41940.985399.99.3
CVE-2026-0257.939199.87.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-42208.894299.89.3
CVE-2026-9082.883299.89.8
CVE-2024-1708.875699.78.4
CVE-2026-42271.835499.78.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4659510.0.0050
CVE-2026-4282210.0.0049
CVE-2026-3371210.0.0035
CVE-2026-915210.0.0034
Most disclosures (vendor)
VendorCVEs
linux295
microsoft162
concrete cms44
open ises37
netatalk33
google16
nvidia16
trend micro16
apache15
apple15
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google4
ivanti4
fortinet3
smartertools3
solarwinds3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven4
PyPI1
npm1
Fastest to KEV
CVEVendorDays
CVE-2024-1708ConnectWise0
CVE-2024-57726n/a0
CVE-2024-57728n/a0
CVE-2026-31431Linux0
CVE-2026-32202Microsoft0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-41940WebPros0
CVE-2026-42208BerriAI0
CVE-2026-42897Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171648
CVE-2021-27102n/a2021-11-171648
CVE-2021-27101n/a2021-11-171648
CVE-2021-27103n/a2021-11-171648
CVE-2021-21017Adobe2021-11-171648
CVE-2021-28550Adobe2021-11-171648
CVE-2021-42013Apache Software Foundation2021-11-171648
CVE-2021-41773Apache Software Foundation2021-11-171648
CVE-2021-30858Apple2021-11-171648
CVE-2021-30860Apple2021-11-171648

Transactions

No status changes recorded.

Yesterday's Results

How to read these box scores · glossary

41 CVEs published. 25 box scores, 16 table rows — nothing truncated.

Linux Linux — net: skbuff: preserve shared-frag marker during coalescing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0948   95.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    cef401de7be8c4e155c6746bfccf721a4fa5fab9 –  —
  Linux    3.9 –                                       5.10.257
TIMELINE
  May 13  Reserved by CNA
  May 23  Published (CNA: Linux)
CWE-123 · CNA: Linux · CVSS v3.1 · 50 references · NVD status: Modified
Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0170   75.4     —
AFFECTED
  Product           Versions     Fixed
  Dolibarr ERP CRM  unspecified  —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Analyzed
Edimax EW-7438RPn webs formWpsStart os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0152   72.6     —
AFFECTED
  Product     Versions  Fixed
  EW-7438RPn  1.0 –     —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax BR-6428NS POST Request formWlbasic command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0140   70.3     —
AFFECTED
  Product    Versions  Fixed
  BR-6428NS  1.10 –    —
TIMELINE
  May 22  Reserved by CNA
  May 23  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax BR-6428NS POST Request formWlanM system command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product    Versions  Fixed
  BR-6428NS  1.10 –    —
TIMELINE
  May 22  Reserved by CNA
  May 23  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0059   45.4     —
AFFECTED
  Product  Versions     Fixed
  DIR-601  unspecified  —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulnCheck)
CWE-497 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Awaiting Analysis
Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0054   43.1     —
AFFECTED
  Product    Versions  Fixed
  BR-6428NS  1.10 –    —
TIMELINE
  May 22  Reserved by CNA
  May 23  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax BR-6428NS POST Request formWirelessTbl buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0054   43.1     —
AFFECTED
  Product    Versions  Fixed
  BR-6428NS  1.10 –    —
TIMELINE
  May 22  Reserved by CNA
  May 23  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0045   37.4     —
AFFECTED
  Product               Versions     Fixed
  Redaxo CMS Mediapool  unspecified  —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0043   35.9     —
AFFECTED
  Product    Versions  Fixed
  userSpice  4.3.24 –  —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulnCheck)
CWE-204 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  L  N    8.2   .0040   32.9     —
AFFECTED
  Product                      Versions     Fixed
  WooCommerce PayPal Payments  unspecified  —
TIMELINE
  May 22  Reserved by CNA
  May 23  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
harmistechnology Ek Rishta — Joomla! Component Ek Rishta 2.10 SQL Injection via user_detail
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   N    8.8   .0036   28.5     —
AFFECTED
  Product    Versions  Fixed
  Ek Rishta  2.10 –    —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
harmistechnology EkRishta — Joomla! Component EkRishta 2.10 SQL Injection via username
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   N    8.8   .0036   28.5     —
AFFECTED
  Product   Versions  Fixed
  EkRishta  2.10 –    —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Linux Linux — net: skbuff: propagate shared-frag marker through frag-transfer helpers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  C  H  H  H    8.8   .0034   26.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    cef401de7be8c4e155c6746bfccf721a4fa5fab9 –  —
  Linux    3.9 –                                       5.10.257
TIMELINE
  May 1   Reserved by CNA
  May 23  Published (CNA: Linux)
CWE-664 · CNA: Linux · CVSS v3.1 · 41 references · NVD status: Modified
Behance Smartshop — Smartshop 1 SQL Injection via category.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   N    8.8   .0033   25.8     —
AFFECTED
  Product    Versions  Fixed
  Smartshop  1.0 –     —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Behance Smartshop — Smartshop 1 SQL Injection via product.php id Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   N    8.8   .0033   25.8     —
AFFECTED
  Product    Versions  Fixed
  Smartshop  1.0 –     —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Behance Smartshop — Smartshop 1 SQL Injection via search.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   N    8.8   .0033   25.8     —
AFFECTED
  Product    Versions  Fixed
  Smartshop  1.0 –     —
TIMELINE
  May 23  Reserved by CNA
  May 23  Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   L   N   N    2.9   .0029   21.1     —
AFFECTED
  Product  Versions  Fixed
  new-api  0.12.0 –  —
TIMELINE
  May 22  Reserved by CNA
  May 23  Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_get_screen' AJAX action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0026   17.1     —
AFFECTED
  Product          Versions     Fixed
  Wishlist Member  unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 23  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_export_settings' AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0025   15.8     —
AFFECTED
  Product          Versions     Fixed
  Wishlist Member  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  May 23  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0024   15.3     —
AFFECTED
  Product          Versions     Fixed
  Wishlist Member  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  May 23  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
WishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0024   15.3     —
AFFECTED
  Product          Versions     Fixed
  Wishlist Member  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  May 23  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0024   14.4     —
AFFECTED
  Product                   Versions                                    Fixed
  vps-inventory-monitoring  98c00b370668c96ae75e91c15548d9ea113652d9 –  —
TIMELINE
  May 22  Reserved by CNA
  May 23  Published (CNA: VulDB)
CWE-74, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0023   13.4     —
AFFECTED
  Product  Versions  Fixed
  amf      2.1.0 –   —
TIMELINE
  May 22  Reserved by CNA
  May 23  Published (CNA: VulDB)
CWE-119 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
omec-project amf NGSetupRequest memory corruption
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0023   13.4     —
AFFECTED
  Product  Versions  Fixed
  amf      2.1.0 –   —
TIMELINE
  May 22  Reserved by CNA
  May 23  Published (CNA: VulDB)
CWE-119 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-93012.113.4omec-projectamfCWE-119omec-project amf NGReset Message memory corruption
CVE-2026-92982.113.4omec-projectamfCWE-119omec-project amf PathSwitchRequest memory corruption
CVE-2018-253477.111.5web-doradoContact Form MakerCWE-89WordPress Contact Form Maker Plugin 1.12.20 SQL Injection
CVE-2018-253527.111.5ultimate-form-builder-liteUltimate Form Builder LiteCWE-89WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_id
CVE-2026-93041.39.6calcomcal.diyCWE-918calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery
CVE-2018-253467.19.410WebForm MakerCWE-89WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php
CVE-2026-93032.19.0calcomcal.diyCWE-352calcom cal.diy cross-site request forgery
CVE-2026-93052.18.9QuantumNousnew-apiCWE-74QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection
CVE-2026-93422.18.9SourceCodesterHospitals Patient Records Management SystemCWE-74SourceCodester Hospitals Patient Records Management System view_history.php s…
CVE-2018-253458.66.010-StrikeNetwork ScannerCWE-12010-Strike Network Scanner 3.0 Local Buffer Overflow SEH
CVE-2018-253448.65.610-StrikeNetwork Inventory ExplorerCWE-12110-Strike Network Inventory Explorer 8.54 Buffer Overflow SEH
CVE-2018-253558.65.6AudiograbberAudiograbberCWE-120Audiograbber 1.83 Local Buffer Overflow via SEH
CVE-2018-253568.65.6SippSIPpCWE-120SIPp 3.6 Local Buffer Overflow via Command-line Arguments
CVE-2018-253495.14.8UserSpiceuserSpiceCWE-79userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header
CVE-2018-253435.33.0BehanceSmartshopCWE-352Smartshop 1 Cross-Site Request Forgery via editprofile.php
CVE-2018-253545.33.0JomresJomresCWE-352Joomla Component jomres 9.11.2 Cross-Site Request Forgery

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-23 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.