boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, August 1, 2026 · all times UTC← 2026-07-31 · archive · 2026-08-02 →

147 CVEs published, led by FreeRDP (21).

147 CVEs published August 1, 2026: 17 critical, 48 high, 74 medium, 8 low; 0 in the KEV catalog at press time; 7 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 122 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1472229413912564
KEV catalog size1671

1048 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux02317207123163512730.17.8.0014-31 ▼
google01760214709781537460.37.5.0023-52 ▼
microsoft0143110498332114380322.27.8.0041-2 ▼
red hat03561614517520400.06.5.0025-8 ▼
apple0266567312739472.66.5.00240
canonical02738115000.05.6.00110
suse02141241000.08.5.00330
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco040616100961332.57.5.0050-8 ▼
ubiquiti036142110438.38.8.00360
palo alto networks025021471428.04.7.00210
fortinet0233611028626.16.7.00390
netgear02300221800.04.6.00220
f50175830715.98.6.00570
vmware01648222200.08.2.00390
checkpoint01236303216.77.7.04450
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache033465143114114010.37.5.0048-2 ▼
mozilla012751423401300.08.1.0029-2 ▼
gitlab05307377423.84.9.00250
drupal05165355512.05.9.00180
github0121380000.06.0.0027-1 ▼
docker070520100.08.2.00160
wordpress0311105266.78.6.73100
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01379342653322614030.28.1.00320
adobe02542711510547541.67.8.00210
ibm02296786760700.07.5.00260
progress04262970900.08.0.00330
solarwinds0231623011417.49.1.00440
veeam062310400.08.5.00300
zohocorp062220000.07.8.01090
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation02441820000.08.7.00250
synology02325133000.05.6.00250
d-link02105962614.85.5.00690
siemens0161870100.07.6.00190
schneider electric091620100.08.6.00240
abb070430000.07.2.00180
hikvision0704202114.37.2.00250
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester0120006258000.05.5.00260
openclaw01110583914000.07.0.00220
dell099447443211.07.0.0020-1 ▼
capgo083242381000.07.1.00280
nvidia0821254160000.07.8.0019-17 ▼
spring079234412000.06.5.00220
imagemagick078156012300.05.3.0017-8 ▼
itsourcecode071001952000.02.1.00200

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.910.0
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4633910.0.0239
Most disclosures (vendor)
VendorCVEs
oracle1109
linux802
microsoft658
google444
apache179
apple167
red hat155
adobe108
ibm105
mozilla69
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google6
ivanti5
adobe4
solarwinds4
synacor4
langflow3
Most-affected ecosystems
EcosystemAdvisories
Maven65
PyPI6
NuGet4
Go3
npm3
Packagist2
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-20316Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171718
CVE-2021-27102Accellion2021-11-171718
CVE-2021-27101Accellion2021-11-171718
CVE-2021-27103Accellion2021-11-171718
CVE-2021-21017Adobe2021-11-171718
CVE-2021-28550Adobe2021-11-171718
CVE-2021-42013Apache2021-11-171718
CVE-2021-41773Apache2021-11-171718
CVE-2021-30858Apple2021-11-171718
CVE-2021-30860Apple2021-11-171718

Transactions

EXPLOIT PUBLISHED — ueberauth guardian: 4 CVEs (CVE-2026-54894, CVE-2026-55733, CVE-2026-55734, CVE-2026-55735). Public exploit references added.

EXPLOIT PUBLISHEDCVE-2024-21536 (http-proxy-middleware). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10773 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-2411 (zephyrproject zephyr). Public exploit reference added.

RESCOREDCVE-2024-10918 (libmodbus). CVSS 4.8 → 9.8 (NVD).

RESCOREDCVE-2024-21536 (http-proxy-middleware). CVSS 8.7 → 7.7 (NVD).

RESCOREDCVE-2026-15105 (davenardella snap7). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPEDCVE-2026-18577 (N-able N-central). Fixed in N-central 2026.3.1.7.

Yesterday's Results

How to read these box scores · glossary

147 CVEs published. 25 box scores, 122 table rows — nothing truncated.

gitpython-developers GitPython — GitPython before 3.1.51 Command Injection via option prefix abbreviation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0148   71.9     —
AFFECTED
  Product    Versions     Fixed
  GitPython  unspecified  3.1.51
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
gitpython-developers GitPython — GitPython before 3.1.51 Command Injection via unguarded Git options
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   N   H   H   H    8.6   .0102   60.6     —
AFFECTED
  Product    Versions     Fixed
  GitPython  unspecified  3.1.51
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-77 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
bitpressadmin Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation — Bit integrations <= 2.9.0 - Unauthenticated Arbitrary File Read via Optional CF7 File Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0083   54.9     —
AFFECTED
  Product                                                                                  Versions     Fixed
  Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0077   52.7     —
AFFECTED
  Product                                                      Versions     Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  unspecified  —
TIMELINE
  Jul 13  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
Unknown HUSKY — HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0072   51.2     —
AFFECTED
  Product  Versions     Fixed
  HUSKY    unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Aug 1   Published (CNA: WPScan)
CWE-22 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
stiofansisland Payment forms, Buy now buttons, and Invoicing System | GetPaid — Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0071   50.7     —
AFFECTED
  Product                                                         Versions     Fixed
  Payment forms, Buy now buttons, and Invoicing System | GetPaid  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
wpchill Kali Forms — Contact Form & Drag-and-Drop Builder — Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0069   49.9     —
AFFECTED
  Product                                            Versions     Fixed
  Kali Forms — Contact Form & Drag-and-Drop Builder  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
gm_alex User Access Manager — User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0068   49.4     —
AFFECTED
  Product              Versions     Fixed
  User Access Manager  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
cubewp1211 CubeWP Framework — CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0064   48.0     —
AFFECTED
  Product           Versions     Fixed
  CubeWP Framework  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Deferred
ArcadeData arcadedb — ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0052   42.2     —
AFFECTED
  Product   Versions     Fixed
  arcadedb  unspecified  26.7.2
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   N    7.8   .0049   40.3     —
AFFECTED
  Product  Versions  Fixed
  traefik  3.7.0 –   3.7.8
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
britcoder Single Sign On For TNG — Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0049   40.1     —
AFFECTED
  Product                 Versions     Fixed
  Single Sign On For TNG  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-620 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4   .0049   40.2     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-122 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Unknown Support Genix — Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0048   39.7     —
AFFECTED
  Product        Versions     Fixed
  Support Genix  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 1   Published (CNA: WPScan)
CWE-22 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
wpwax FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More — FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0047   38.7     —
AFFECTED
  Product                                                                                      Versions     Fixed
  FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More  unspecified  —
TIMELINE
  Feb 24  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
Wazuh GitHub Actions Shell Injection via Fork Pull Request
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.3   .0045   37.6     —
AFFECTED
  Product  Versions     Fixed
  wazuh    unspecified  44bf114d2f4901aa82ecbb9e5b0780f7c3ca5263
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0043   36.1     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-125 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
WPWeb WooCommerce - Social Login — WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0040   33.4     —
AFFECTED
  Product                     Versions     Fixed
  WooCommerce - Social Login  unspecified  —
TIMELINE
  May 13  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-289 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
better-auth before 1.1.16 Reflected XSS via error parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   L   L   N    5.1   .0040   33.2     —
AFFECTED
  Product      Versions     Fixed
  better-auth  unspecified  1.1.16
TIMELINE
  Jul 18  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0038   31.4     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-191 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0038   31.3     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-113 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
gitpython-developers GitPython — GitPython 3.1.50 Authentication Bypass via Joined Short Options
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0038   31.2     —
AFFECTED
  Product    Versions  Fixed
  GitPython  3.1.50 –  3.1.51
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
webaways NEX-Forms – Ultimate Forms Plugin for WordPress — NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0038   30.9     —
AFFECTED
  Product                                          Versions     Fixed
  NEX-Forms – Ultimate Forms Plugin for WordPress  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
axios before 1.18.0 Prototype Pollution via auth subfields
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   L   L    6.3   .0037   29.8     —
AFFECTED
  Product  Versions  Fixed
  axios    1.15.2 –  1.18.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-1321 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0036   29.1     —
AFFECTED
  Product  Versions  Fixed
  axios    1.7.0 –   1.18.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-770 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-673186.328.8axiosaxiosCWE-400axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2
CVE-2026-673048.728.6FreeRDPFreeRDPCWE-476FreeRDP before 3.29.0 NULL Dereference via smartcard cleanup
CVE-2026-673309.428.4better-authscimCWE-20better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-I…
CVE-2026-672888.728.2FreeRDPFreeRDPCWE-476FreeRDP before 3.29.0 Denial of Service via smartcard cache
CVE-2026-672968.727.5FreeRDPFreeRDPCWE-20FreeRDP before 3.29.0 Denial of Service via RDPEI PDU
CVE-2026-672978.727.5FreeRDPFreeRDPCWE-770FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response
CVE-2026-672918.727.0FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADD
CVE-2026-673018.727.0FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Out-of-bounds Read via Polygon async message-proxy
CVE-2026-673126.326.9axiosaxiosCWE-400axios 0.28.0 before 0.33.0 Denial of Service via formToJSON
CVE-2026-673136.326.9axiosaxiosCWE-400axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON
CVE-2026-154148.826.5wpswingsSubscriptions for WooCommerceCWE-269Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privile…
CVE-2026-180595.326.2pixelyoursitePixelYourSite – Your smart PIXEL (TAG) & API ManagerCWE-200PixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via …
CVE-2026-672998.725.9FreeRDPFreeRDPCWE-416FreeRDP before 3.29.0 Use-After-Free via WindowIcon async message
CVE-2026-673008.725.9FreeRDPFreeRDPCWE-416FreeRDP before 3.29.0 Use-After-Free via async message proxy
CVE-2026-119955.325.2saadiqbalGutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form BuilderCWE-862Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Cu…
CVE-2026-673419.324.8ArcadeDataarcadedbCWE-863ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION
CVE-2026-673429.324.8ArcadeDataarcadedbCWE-639ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers
CVE-2026-673025.324.5FreeRDPFreeRDPCWE-369FreeRDP rdpecam StartStreamsRequest divide-by-zero denial of service
CVE-2026-175806.524.3wplakeorgAdvanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…CWE-862Advanced Views <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+…
CVE-2026-166358.823.6pronamicPronamic PayCWE-269Pronamic Pay <= 10.1.0 - Authenticated (Subscriber+) Privilege Escalation via…
CVE-2026-134586.423.4edge22GenerateBlocksCWE-79GenerateBlocks <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-673208.323.1axiosaxiosCWE-200axios before 0.33.0 Prototype Pollution via Node HTTP adapter
CVE-2026-673438.722.5ArcadeDataarcadedbCWE-200ArcadeDB before 26.7.2 Cluster Token Disclosure via GET /api/v1/server
CVE-2026-107824.322.2inspirythemesRealHomes MembershipsCWE-862RealHomes Memberships <= 3.0.9 - Missing Authorization to Authenticated (Subs…
CVE-2026-673156.921.7axiosaxiosCWE-183axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
CVE-2026-673216.921.7axiosaxiosCWE-674axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via max…
CVE-2026-664029.321.6FreeRDPFreeRDPCWE-295FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass
CVE-2026-557346.921.2ueberauthguardianCWE-770guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1
CVE-2026-557358.220.8ueberauthguardianCWE-347Guardian.revoke/3 acts on unverified token claims, allowing forged-token sess…
CVE-2026-64536.520.7cubewp1211CubeWP FrameworkCWE-89CubeWP Framework <= 1.1.30 - Authenticated (Subscriber+) SQL Injection via 'r…
CVE-2026-673288.620.3better-authssoCWE-79@better-auth/sso before 1.6.21 Account Takeover via SSO
CVE-2026-131577.220.3UnknownTheme Demo ImportCWE-434Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
CVE-2026-131587.220.3UnknownEverest ToolkitCWE-434Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
CVE-2026-673065.320.2FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLE
CVE-2026-672949.319.4FreeRDPFreeRDPCWE-295FreeRDP before 3.29.0 TLS Certificate EKU Bypass
CVE-2026-548946.919.4ueberauthguardianCWE-770Atom-table exhaustion denial of service in Guardian via unbounded atom creati…
CVE-2026-557336.919.4ueberauthguardianCWE-770Atom-table exhaustion denial of service in Guardian permissions AtomEncoding …
CVE-2026-673377.119.2better-authbetter-authCWE-288better-auth before 1.4.9 Two-Factor Authentication Bypass via session.cookieC…
CVE-2026-160876.519.1icegramIcegram Engage – Popups, Optins, CTAs & Lead GenerationCWE-89Icegram Engage <= 3.1.42 - Authenticated (Contributor+) Second-Order SQL Inje…
CVE-2026-673228.718.6gitpython-developersGitPythonCWE-200GitPython before 3.1.52 Environment Variable Exfiltration via clone_from
CVE-2026-154034.918.9dotonpaperPinpoint Booking System – Version 2CWE-89Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Inj…
CVE-2026-159514.918.9icegramIcegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logsCWE-89Icegram Mailer <= 1.0.12 - Authenticated (Administrator+) SQL Injection via '…
CVE-2026-166144.918.9westerndealGSheetConnector – CF7 Google Sheets ConnectorCWE-89GSheetConnector <= 5.2.1 - Authenticated (Administrator+) SQL Injection via '…
CVE-2026-175554.918.9wpvividpluginsWPvivid — Backup, Migration & StagingCWE-89WPvivid <= 0.9.131 - Authenticated (Administrator+) SQL Injection via 'export…
CVE-2026-150185.318.6davejeschDatabase Collation FixCWE-89Database Collation Fix <= 1.2.10 - Unauthenticated SQL Injection via 'force-c…
CVE-2026-672929.318.4FreeRDPFreeRDPCWE-130FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure
CVE-2026-135969.118.2UnknownParticipants DatabaseCWE-89Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
CVE-2026-673166.317.7axiosaxiosCWE-1321axios before 1.18.0 Prototype Pollution via bodyless methods
CVE-2026-673196.317.7axiosaxiosCWE-1321axios before 0.33.0 Prototype Pollution via nested option objects
CVE-2026-673118.217.4BudibasebudibaseCWE-918Budibase before 3.38.1 SSRF Blacklist Bypass via HTTP Redirect
CVE-2026-148397.517.4UnknownMapster WP MapsCWE-200Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Dis…
CVE-2026-673548.216.9guzzleguzzleCWE-201guzzlehttp/guzzle before 7.15.1 URI Fragment Disclosure via Referer
CVE-2026-673035.316.5FreeRDPFreeRDPCWE-617FreeRDP before 3.29.0 Denial of Service via serial DeviceControl
CVE-2026-673536.916.3guzzleguzzleCWE-770guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service
CVE-2026-672955.316.0FreeRDPFreeRDPCWE-22FreeRDP before 3.29.0 Path Traversal via drive redirection
CVE-2026-150527.215.5umarbajwaMailChimp Subscribe Form, Optin Builder, PopUp Builder, Form BuilderCWE-79MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3…
CVE-2026-166856.415.5codename065Download ManagerCWE-79Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-673318.715.3better-authscimCWE-639better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass
CVE-2025-714037.115.1better-authbetter-authCWE-601better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass
CVE-2026-156626.414.7mihail-barinovAdvanced Woo Labels – Product Labels & Badges for WooCommerceCWE-79Advanced Woo Labels <= 2.48 - Authenticated (Contributor+) Stored Cross-Site …
CVE-2026-673396.914.4guzzleguzzleCWE-200guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure
CVE-2025-140735.314.3woocommerceWooCommerce PayPal PaymentsCWE-639WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information …
CVE-2026-673278.714.1better-authbetter-authCWE-287better-auth before 1.6.22 Account Takeover via Magic-Link Email-OTP
CVE-2026-673558.214.0guzzleguzzleCWE-201guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope
CVE-2026-143098.113.6UnknownChat On Desk Order NotificationsCWE-287Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OT…
CVE-2026-148368.113.6UnknownLogin & Register FormsCWE-287Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Re…
CVE-2026-153688.113.6UnknownUser Profile BuilderCWE-269Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login Af…
CVE-2026-145968.813.2UnknownDynamicKit for ElementorCWE-287DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Passw…
CVE-2026-129665.312.9UnknownDirect Payments for WooCommerceCWE-284Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Orde…
CVE-2026-159888.812.4tigroumeowAI Engine – The Chatbot, AI Framework & MCP for WordPressCWE-352AI Engine <= 3.6.5 - Cross-Site Request Forgery to Privilege Escalation via R…
CVE-2026-29164.312.5jegthemeJeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPressCWE-200Jeg Kit for Elementor <= 3.1.1 - Authenticated (Contributor+) Exposure of Sen…
CVE-2026-183446.112.3nik00726Responsive Thumbnail SliderCWE-79Responsive Thumbnail Slider < 1.1.53 - Reflected Cross-Site Scripting via 'id…
CVE-2026-673526.812.1openwrtluciCWE-79luci-app-https-dns-proxy Stored XSS via resolver_url
CVE-2026-175716.111.6wpmanageninjaFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-79Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param'
CVE-2026-148405.311.5UnknownYOP PollCWE-290YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoo…
CVE-2026-76236.410.9brainstormforceSureForms – Contact Form Builder, AI Forms, Payment Form, Survey & QuizCWE-79SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-156446.410.9codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-156456.410.9codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-180626.410.9stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-79Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Sc…
CVE-2025-714022.011.0better-authbetter-authCWE-347better-auth before 1.4.0 Session Revocation via Forged Cookie
CVE-2026-133626.410.6sendpulseSendPulse Email Marketing NewsletterCWE-79SendPulse Email Marketing Newsletter <= 2.2.5 - Authenticated (Contributor+) …
CVE-2026-156496.410.3codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-160916.410.3rubengcGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-79GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-673345.110.1better-authbetter-authCWE-459better-auth Stale Sessions Persist After User Deletion
CVE-2026-673297.19.7better-authstripeCWE-639@better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subsc…
CVE-2026-159506.49.4cozythemesCozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & TemplatesCWE-79Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-160906.49.4rubengcGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-79GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-166846.49.4mervb1Easy Property ListingsCWE-79Easy Property Listings <= 3.5.24 - Authenticated (Subscriber+) Stored Cross-S…
CVE-2026-184356.49.4stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-79Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-118823.79.2UnknownBuilderall for WordPressCWE-284Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoni…
CVE-2026-673267.39.2gitpython-developersGitPythonCWE-20GitPython before 3.1.50 Newline Injection via config_writer section
CVE-2026-148225.38.1UnknownEvent Tickets and RegistrationCWE-284Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
CVE-2026-673105.38.1openremoteopenremoteCWE-863openremote before 1.27.0 Cross-Tenant IDOR via setAssetLinks
CVE-2026-107735.48.0zephyrprojectzephyrCWE-125Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_…
CVE-2026-141952.77.7UnknownBrizyCWE-639Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure…
CVE-2026-136045.37.4UnknownPixelavoCWE-918Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo…
CVE-2026-673385.17.3jupyterlabjupyterlabCWE-84JupyterLab before 4.5.9 Stored XSS via Extension Manager
CVE-2026-133296.57.2UnknownBuckaroo Woocommerce Payments PluginCWE-284WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
CVE-2025-156694.87.1UnknownBit FormCWE-79Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
CVE-2026-673356.07.0better-authbetter-authCWE-287better-auth before 1.6.2 OAuth State Validation Bypass
CVE-2026-673077.06.7wazuhwazuhCWE-345Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync
CVE-2026-142142.76.6UnknownBooking for Appointments and Events CalendarCWE-287Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass A…
CVE-2026-672939.36.3FreeRDPFreeRDPCWE-295FreeRDP before 3.29.0 Improper Certificate Hostname Validation
CVE-2026-137257.16.1UnknownDynamic Pricing With Discount Rules for WooCommerceCWE-79Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS v…
CVE-2026-143156.56.2UnknownPixel Tag Manager for WooCommerceCWE-284Pixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion…
CVE-2026-145616.56.2UnknownAuthora : Easy login with mobile numberCWE-287Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Tak…
CVE-2026-673325.35.9better-authoauth-providerCWE-285@better-auth/oauth-provider before 1.7.0-beta.4 Authorization Bypass
CVE-2026-185367.55.8RRWOData::EntropyCWE-319Data::Entropy versions before 0.010 for Perl read remote entropy sources over…
CVE-2026-673369.45.6better-authbetter-authCWE-327better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider
CVE-2026-142925.45.6UnknownDownload ManagerCWE-79WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
CVE-2026-673335.15.4better-authbetter-authCWE-79better-auth before 1.6.13 Stored XSS via javascript redirect_uri
CVE-2026-141973.84.9UnknownFluent SupportCWE-639Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
CVE-2026-664012.44.8FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264
CVE-2026-148232.24.5UnknownEvent Tickets and RegistrationCWE-639Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory M…
CVE-2026-673448.54.2ArcadeDataarcadedbCWE-862ArcadeDB before 26.7.2 Authentication Bypass via ALTER TYPE
CVE-2026-126965.43.3UnknownwpForo ForumCWE-79wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
CVE-2026-152345.43.3UnknownCodeless Page BuilderCWE-79Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
CVE-2026-152625.43.3UnknownAdmin Columns for ACF FieldsCWE-79Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field…
CVE-2025-144694.32.9mndpsingh287Theme EditorCWE-352Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification
CVE-2026-24116.52.4zephyrprojectzephyrCWE-863Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, by…
CVE-2026-108273.51.3UnknownSpectra LegacyCWE-345Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS In…
CVE-2026-137294.30.9UnknownPodlove Podcast PublisherCWE-352Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation a…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-01 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.