boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, June 6, 2026 · all times UTC← 2026-06-05 · archive · 2026-06-07 →

Security Box Score — June 6, 2026

39 CVEs published, led by theonedev (4).

39 CVEs published June 6, 2026: 0 critical, 7 high, 26 medium, 6 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 14 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published15826043——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

259 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux3310008163028811120.27.8.0013-113 ▼
google48866358335255157750.87.8.0023+488 ▲
microsoft7543473791152286193.57.8.0047+7 ▲
red hat191138494610200.07.0.0033+16 ▲
apple05211733188713.56.2.00230
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco214536056857.17.3.0566+2 ▲
fortinet07430028342.99.1.85840
ivanti16240025466.78.8.5751+1 ▲
checkpoint060330300.06.5.03380
zyxel230030900.06.5.0017+2 ▲
ubiquiti031200300.08.8.00680
f50220004150.09.2.39010
palo alto networks021100132100.08.6.6281-1 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache32668262923311.57.2.0052+28 ▲
mozilla4103340900.07.4.0035+4 ▲
gitlab0701604228.64.3.00240
docker250500000.08.8.0021+2 ▲
drupal0511304120.05.1.00260
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm5541326150600.07.5.0031+5 ▲
oracle028915402713.68.1.00270
progress591710600.07.5.0036+5 ▲
solarwinds25230010480.08.1.8162+2 ▲
veeam031200100.08.6.00510
adobe020200192100.08.6.03680
zohocorp020110000.07.1.01040
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link570313300.06.0.0069+5 ▲
abb440400000.07.3.0024+4 ▲
siemens120110000.07.3.0026+1 ▲
hitachi energy020020000.05.7.00140
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax051032019100.07.4.00590
concrete cms1451101321000.06.0.0015+1 ▲
open ises044221210000.07.1.00210
sourcecodester2143001429000.02.1.0025+21 ▲
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
acer2636111960000.08.7.0024+26 ▲
nvidia23582070000.07.8.0029+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-0257.939199.87.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-42208.894299.89.3
CVE-2026-9082.883299.89.8
CVE-2026-42271.835499.78.7
CVE-2026-41089.796299.69.8
CVE-2026-42897.712099.48.1
CVE-2026-42945.680599.39.2
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4399710.0.0098
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
Most disclosures (vendor)
VendorCVEs
google656
linux528
microsoft161
red hat56
ibm54
edimax51
apache49
concrete cms45
open ises44
sourcecodester43
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google5
ivanti4
solarwinds4
fortinet3
smartertools3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven24
PyPI10
Packagist7
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-28318SolarWinds0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-42208BerriAI0
CVE-2026-42897Microsoft0
CVE-2026-45247Mirasvit0
CVE-2026-45321@tanstack0
CVE-2026-45498Microsoft0
CVE-2026-48027nrwl0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171662
CVE-2021-27102n/a2021-11-171662
CVE-2021-27101n/a2021-11-171662
CVE-2021-27103n/a2021-11-171662
CVE-2021-21017Adobe2021-11-171662
CVE-2021-28550Adobe2021-11-171662
CVE-2021-42013Apache Software Foundation2021-11-171662
CVE-2021-41773Apache Software Foundation2021-11-171662
CVE-2021-30858Apple2021-11-171662
CVE-2021-30860Apple2021-11-171662

Transactions

DUE DATE PASSED — CVE-2022-0492 (Linux Kernel). CISA remediation deadline was June 5, 2026; still in catalog.

DUE DATE PASSED — CVE-2025-48595 (Google Android). CISA remediation deadline was June 5, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

39 CVEs published. 25 box scores, 14 table rows — nothing truncated.

wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets — Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0724   93.8     —
AFFECTED
  Product                                                                 Versions     Fixed
  Essential Addons for Elementor – Popular Elementor Templates & Widgets  unspecified  —
TIMELINE
  May 1   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0123   66.6     —
AFFECTED
  Product  Versions  Fixed
  MT3000   4.4.0 –   4.9.0_beta3-1012-0513-1778656146
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
vertex-app vertex Log Viewer Endpoint LogMod.js os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0111   63.5     —
AFFECTED
  Product  Versions     Fixed
  vertex   2026.02.0 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
chrisvrichardson MapPress Maps for WordPress — MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0102   60.7     —
AFFECTED
  Product                      Versions     Fixed
  MapPress Maps for WordPress  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · CVSS v3.1 · 24 references · NVD status: Deferred
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0066   48.8     —
AFFECTED
  Product                Versions     Fixed
  MDJM Event Management  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
thimpress LearnPress – Backup & Migration Tool — LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0065   48.2     —
AFFECTED
  Product                               Versions     Fixed
  LearnPress – Backup & Migration Tool  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
nextendweb Smart Slider 3 — Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0060   46.1     —
AFFECTED
  Product         Versions     Fixed
  Smart Slider 3  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
thimpress LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0053   42.3     —
AFFECTED
  Product                                                               Versions     Fixed
  LearnPress – WordPress LMS Plugin for Create and Sell Online Courses  unspecified  —
TIMELINE
  May 13  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
davidanderson All-In-One Security (AIOS) – Security and Firewall — All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0049   39.6     —
AFFECTED
  Product                                             Versions     Fixed
  All-In-One Security (AIOS) – Security and Firewall  unspecified  —
TIMELINE
  May 12  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0048   39.3     —
AFFECTED
  Product              Versions       Fixed
  JD Cloud Box AX6600  4.5.3.r4546 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
10web Photo Gallery by 10Web – Mobile-Friendly Image Gallery — Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0047   38.5     —
AFFECTED
  Product                                                 Versions     Fixed
  Photo Gallery by 10Web – Mobile-Friendly Image Gallery  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
thimpress LearnPress – Backup & Migration Tool — LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0045   37.2     —
AFFECTED
  Product                               Versions     Fixed
  LearnPress – Backup & Migration Tool  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
CRUX Protocol::HTTP2 — Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0041   34.2     —
AFFECTED
  Product          Versions     Fixed
  Protocol::HTTP2  unspecified  —
TIMELINE
  Jun 3   Reserved by CNA
  Jun 6   Published (CNA: CPANSec)
CWE-409 · CNA: CPANSec · CVSS v3.1 · 6 references · NVD status: Analyzed
perfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0041   33.7     —
AFFECTED
  Product         Versions  Fixed
  go-fastdfs-web  1.3.0 –   —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
holithemes Click to Chat – HoliThemes — Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0041   33.6     —
AFFECTED
  Product                     Versions     Fixed
  Click to Chat – HoliThemes  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
spacetime Ad Inserter – Ad Manager & AdSense Ads — Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0036   28.7     —
AFFECTED
  Product                                 Versions     Fixed
  Ad Inserter – Ad Manager & AdSense Ads  unspecified  —
TIMELINE
  May 22  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
masaakitanaka Booking Package — Booking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0036   28.5     —
AFFECTED
  Product          Versions     Fixed
  Booking Package  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
wpdevteam EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more — EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0033   25.5     —
AFFECTED
  Product                                                                                        Versions     Fixed
  EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
davidfcarr Quick Playground — Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  N  N    4.4   .0032   23.7     —
AFFECTED
  Product           Versions     Fixed
  Quick Playground  unspecified  —
TIMELINE
  Feb 13  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Deferred
plugcrux Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More — Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0031   23.5     —
AFFECTED
  Product                                                                                  Versions     Fixed
  Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
glenwpcoder Drag and Drop Multiple File Upload for Contact Form 7 — Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  L  L  N    4.4   .0031   23.3     —
AFFECTED
  Product                                                Versions     Fixed
  Drag and Drop Multiple File Upload for Contact Form 7  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
smub WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More — WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0030   22.2     —
AFFECTED
  Product                                                                                    Versions     Fixed
  WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-345 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
cifi SEO Plugin by Squirrly SEO — SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0030   21.6     —
AFFECTED
  Product                     Versions     Fixed
  SEO Plugin by Squirrly SEO  unspecified  —
TIMELINE
  May 1   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
flippercode WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters — WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  L  L  N    4.4   .0029   21.3     —
AFFECTED
  Product                                                                               Versions     Fixed
  WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters  unspecified  —
TIMELINE
  May 26  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
n/a FluentCMS — FluentCMS Blocks Plugin blocks cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   N   L   N    1.9   .0027   19.3     —
AFFECTED
  Product    Versions  Fixed
  FluentCMS  0.0.5 –   —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-114362.117.7n/aMage AICWE-79Mage AI Sign-in Flow index.tsx useMutation cross site scripting
CVE-2026-90165.317.5qriousladDebug Log Manager – Conveniently Monitor and Inspect ErrorsCWE-117Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization f…
CVE-2026-114355.517.2JinherOACWE-74Jinher OA nextselectplan.aspx sql injection
CVE-2026-89784.917.2crafiumOptinCraft – Drag & Drop Optins & Popup Builder for WordPressCWE-89OptinCraft <= 1.2.0 - Authenticated (Administrator+) SQL Injection via 'order…
CVE-2026-86114.314.0klamra22Klamra Paycal for AspaclariaCWE-639Klamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to A…
CVE-2026-90084.312.8webvitalyPage-listCWE-862Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sens…
CVE-2026-92816.411.6litonice13Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template KitsCWE-79Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-S…
CVE-2026-114385.311.5theonedevonedevCWE-266theonedev projects improper authorization
CVE-2026-114395.311.5theonedevonedevCWE-266theonedev Parent Project projects improper authorization
CVE-2026-114405.311.5theonedevonedevCWE-266theonedev REST API default-branch improper authorization
CVE-2026-114415.311.5theonedevonedevCWE-266theonedev Pull Request issues canAccessIssue improper authorization
CVE-2026-114122.19.3JinherOACWE-74Jinher OA GetFormSn.aspx sql injection
CVE-2026-114111.96.5iAI LabPDF AI AppCWE-22iAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal
CVE-2026-264228.45.7Clash Verge Revclash-verge-service-ipcCWE-732clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, lead…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-06 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.