boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, August 1, 2026 · all times UTC← 2026-07-31 · archive · 2026-08-02 →

Security Box Score — August 1, 2026

147 CVEs published, led by FreeRDP (21).

147 CVEs published August 1, 2026: 17 critical, 48 high, 74 medium, 8 low; 0 in the KEV catalog at press time; 7 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 122 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published14722311——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1052 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux02315207123163711120.17.8.0016-31 ▼
google01761214713781537760.37.5.0025-52 ▼
microsoft0142210698132114286241.77.8.0047-2 ▼
red hat03861615419125200.06.5.0030-8 ▼
apple0271577813338872.66.5.00270
canonical02738115000.05.6.00140
suse02141241000.08.5.00390
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco038818120561231.67.5.0057-8 ▼
ubiquiti036142110338.38.8.00490
palo alto networks025131471328.04.7.00280
fortinet0236611028626.17.2.00400
netgear02300221000.04.6.00240
vmware0174922715.98.3.00400
f50165830416.38.6.00570
checkpoint01236303216.77.7.04550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache033665143116113310.37.5.0053-2 ▼
mozilla01275142340900.08.1.0031-2 ▼
drupal05165355412.05.9.00260
gitlab05107377423.94.9.00290
github0121380000.06.0.0042-1 ▼
docker070520000.08.2.00160
wordpress0311102266.78.6.79790
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01379343653322612730.28.1.00360
adobe02522711610541931.27.8.00260
ibm02296786760600.07.5.00320
progress04262970600.08.0.00380
solarwinds0231733010417.49.1.00580
veeam062310100.08.5.00350
zohocorp062220000.07.8.01460
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation02441820000.08.7.00290
synology02325133000.05.6.00250
d-link0200596300.05.5.01050
siemens0161870000.07.6.00240
schneider electric091620000.08.6.00370
abb070430000.07.2.00180
hikvision060420000.07.2.00400
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester0120006258000.05.5.00340
openclaw01110583914000.07.0.00260
dell099547443211.07.1.0021-1 ▼
capgo083242381000.07.1.00370
nvidia0821254160000.07.8.0037-17 ▼
spring079234412000.06.5.00220
imagemagick078156012000.05.3.0018-8 ▼
itsourcecode071001952000.02.1.00330

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-0770.634299.19.8
CVE-2026-59310.458898.79.8
CVE-2026-48282.423998.610.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
CVE-2026-898510.0.0660
CVE-2026-651610.0.0486
CVE-2026-4766810.0.0388
Most disclosures (vendor)
VendorCVEs
oracle1109
linux802
microsoft658
google444
apache179
apple167
red hat155
adobe108
ibm105
mozilla69
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco12
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven65
PyPI6
NuGet4
Go3
npm3
Packagist2
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-20316Cisco0
CVE-2026-25089Fortinet0
CVE-2026-46817Oracle Corporation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171718
CVE-2021-27102n/a2021-11-171718
CVE-2021-27101n/a2021-11-171718
CVE-2021-27103n/a2021-11-171718
CVE-2021-21017Adobe2021-11-171718
CVE-2021-28550Adobe2021-11-171718
CVE-2021-42013Apache Software Foundation2021-11-171718
CVE-2021-41773Apache Software Foundation2021-11-171718
CVE-2021-30858Apple2021-11-171718
CVE-2021-30860Apple2021-11-171718

Transactions

EXPLOIT PUBLISHED — ueberauth guardian: 4 CVEs (CVE-2026-54894, CVE-2026-55733, CVE-2026-55734, CVE-2026-55735). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2024-21536 (http-proxy-middleware). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10773 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-2411 (zephyrproject zephyr). Public exploit reference added.

RESCORED — CVE-2024-10918 (libmodbus). CVSS 4.8 → 9.8 (NVD).

RESCORED — CVE-2024-21536 (http-proxy-middleware). CVSS 8.7 → 7.7 (NVD).

RESCORED — CVE-2026-15105 (davenardella snap7). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPED — CVE-2026-18577 (N-able N-central). Fixed in N-central 2026.3.1.7.

Yesterday's Results

How to read these box scores · glossary

147 CVEs published. 25 box scores, 122 table rows — nothing truncated.

gitpython-developers GitPython — GitPython before 3.1.51 Command Injection via option prefix abbreviation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0145   71.3     —
AFFECTED
  Product    Versions     Fixed
  GitPython  unspecified  3.1.51
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
gitpython-developers GitPython — GitPython before 3.1.51 Command Injection via unguarded Git options
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   N   H   H   H    8.6   .0095   58.6     —
AFFECTED
  Product    Versions     Fixed
  GitPython  unspecified  3.1.51
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-77 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
bitpressadmin Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation — Bit integrations <= 2.9.0 - Unauthenticated Arbitrary File Read via Optional CF7 File Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0083   54.9     —
AFFECTED
  Product                                                                                  Versions     Fixed
  Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0075   52.0     —
AFFECTED
  Product                                                      Versions     Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  unspecified  —
TIMELINE
  Jul 13  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
gm_alex User Access Manager — User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0074   51.8     —
AFFECTED
  Product              Versions     Fixed
  User Access Manager  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Unknown HUSKY — HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0070   50.5     —
AFFECTED
  Product  Versions     Fixed
  HUSKY    unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Aug 1   Published (CNA: WPScan)
CWE-22 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
cubewp1211 CubeWP Framework — CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0070   50.4     —
AFFECTED
  Product           Versions     Fixed
  CubeWP Framework  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Deferred
stiofansisland Payment forms, Buy now buttons, and Invoicing System | GetPaid — Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0069   50.0     —
AFFECTED
  Product                                                         Versions     Fixed
  Payment forms, Buy now buttons, and Invoicing System | GetPaid  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
wpchill Kali Forms — Contact Form & Drag-and-Drop Builder — Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0069   50.0     —
AFFECTED
  Product                                            Versions     Fixed
  Kali Forms — Contact Form & Drag-and-Drop Builder  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
britcoder Single Sign On For TNG — Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0063   47.3     —
AFFECTED
  Product                 Versions     Fixed
  Single Sign On For TNG  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-620 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
ArcadeData arcadedb — ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0061   46.7     —
AFFECTED
  Product   Versions     Fixed
  arcadedb  unspecified  26.7.2
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
wpwax FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More — FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0056   44.3     —
AFFECTED
  Product                                                                                      Versions     Fixed
  FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More  unspecified  —
TIMELINE
  Feb 24  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   N    7.8   .0049   40.0     —
AFFECTED
  Product  Versions  Fixed
  traefik  3.7.0 –   3.7.8
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4   .0049   39.9     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-122 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Unknown Support Genix — Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0048   39.4     —
AFFECTED
  Product        Versions     Fixed
  Support Genix  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 1   Published (CNA: WPScan)
CWE-22 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Wazuh GitHub Actions Shell Injection via Fork Pull Request
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.3   .0045   37.3     —
AFFECTED
  Product  Versions     Fixed
  wazuh    unspecified  44bf114d2f4901aa82ecbb9e5b0780f7c3ca5263
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
WPWeb WooCommerce - Social Login — WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0044   36.3     —
AFFECTED
  Product                     Versions     Fixed
  WooCommerce - Social Login  unspecified  —
TIMELINE
  May 13  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-289 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0043   35.3     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-125 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
better-auth before 1.1.16 Reflected XSS via error parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   L   L   N    5.1   .0040   32.7     —
AFFECTED
  Product      Versions     Fixed
  better-auth  unspecified  1.1.16
TIMELINE
  Jul 18  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0040   32.5     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-113 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
gitpython-developers GitPython — GitPython 3.1.50 Authentication Bypass via Joined Short Options
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0038   30.7     —
AFFECTED
  Product    Versions  Fixed
  GitPython  3.1.50 –  3.1.51
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0038   30.3     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-191 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
axios before 1.18.0 Prototype Pollution via auth subfields
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   L   L    6.3   .0037   29.2     —
AFFECTED
  Product  Versions  Fixed
  axios    1.15.2 –  1.18.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-1321 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
webaways NEX-Forms – Ultimate Forms Plugin for WordPress — NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0037   29.2     —
AFFECTED
  Product                                          Versions     Fixed
  NEX-Forms – Ultimate Forms Plugin for WordPress  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0036   28.6     —
AFFECTED
  Product  Versions  Fixed
  axios    1.7.0 –   1.18.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-770 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-673186.328.3axiosaxiosCWE-400axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2
CVE-2026-673309.427.8better-authscimCWE-20better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-I…
CVE-2026-673048.727.5FreeRDPFreeRDPCWE-476FreeRDP before 3.29.0 NULL Dereference via smartcard cleanup
CVE-2026-131577.227.3UnknownTheme Demo ImportCWE-434Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
CVE-2026-131587.227.3UnknownEverest ToolkitCWE-434Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
CVE-2026-672888.727.1FreeRDPFreeRDPCWE-476FreeRDP before 3.29.0 Denial of Service via smartcard cache
CVE-2026-672968.726.9FreeRDPFreeRDPCWE-20FreeRDP before 3.29.0 Denial of Service via RDPEI PDU
CVE-2026-672978.726.9FreeRDPFreeRDPCWE-770FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response
CVE-2026-673126.326.3axiosaxiosCWE-400axios 0.28.0 before 0.33.0 Denial of Service via formToJSON
CVE-2026-673136.326.3axiosaxiosCWE-400axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON
CVE-2026-557358.226.1ueberauthguardianCWE-347Guardian.revoke/3 acts on unverified token claims, allowing forged-token sess…
CVE-2026-672918.725.9FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADD
CVE-2026-673018.725.9FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Out-of-bounds Read via Polygon async message-proxy
CVE-2026-557346.925.4ueberauthguardianCWE-770guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1
CVE-2026-180595.325.5pixelyoursitePixelYourSite – Your smart PIXEL (TAG) & API ManagerCWE-200PixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via …
CVE-2026-154148.824.8wpswingsSubscriptions for WooCommerceCWE-269Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privile…
CVE-2026-672998.724.8FreeRDPFreeRDPCWE-416FreeRDP before 3.29.0 Use-After-Free via WindowIcon async message
CVE-2026-673008.724.8FreeRDPFreeRDPCWE-416FreeRDP before 3.29.0 Use-After-Free via async message proxy
CVE-2026-119955.324.6saadiqbalGutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form BuilderCWE-862Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Cu…
CVE-2026-548946.924.5ueberauthguardianCWE-770Atom-table exhaustion denial of service in Guardian via unbounded atom creati…
CVE-2026-557336.924.5ueberauthguardianCWE-770Atom-table exhaustion denial of service in Guardian permissions AtomEncoding …
CVE-2026-673419.324.1ArcadeDataarcadedbCWE-863ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION
CVE-2026-673429.324.1ArcadeDataarcadedbCWE-639ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers
CVE-2026-673025.323.4FreeRDPFreeRDPCWE-369FreeRDP rdpecam StartStreamsRequest divide-by-zero denial of service
CVE-2026-673208.322.5axiosaxiosCWE-200axios before 0.33.0 Prototype Pollution via Node HTTP adapter
CVE-2026-175806.522.6wplakeorgAdvanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…CWE-862Advanced Views <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+…
CVE-2026-150527.222.2umarbajwaMailChimp Subscribe Form, Optin Builder, PopUp Builder, Form BuilderCWE-79MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3…
CVE-2026-166358.822.0pronamicPronamic PayCWE-269Pronamic Pay <= 10.1.0 - Authenticated (Subscriber+) Privilege Escalation via…
CVE-2026-673438.721.9ArcadeDataarcadedbCWE-200ArcadeDB before 26.7.2 Cluster Token Disclosure via GET /api/v1/server
CVE-2026-134586.421.8edge22GenerateBlocksCWE-79GenerateBlocks <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-107824.321.5inspirythemesRealHomes MembershipsCWE-862RealHomes Memberships <= 3.0.9 - Missing Authorization to Authenticated (Subs…
CVE-2026-673156.921.1axiosaxiosCWE-183axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
CVE-2026-673216.921.1axiosaxiosCWE-674axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via max…
CVE-2026-664029.320.6FreeRDPFreeRDPCWE-295FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass
CVE-2026-107735.420.2zephyrprojectzephyrCWE-125Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_…
CVE-2026-673166.319.8axiosaxiosCWE-1321axios before 1.18.0 Prototype Pollution via bodyless methods
CVE-2026-673288.619.7better-authssoCWE-79@better-auth/sso before 1.6.21 Account Takeover via SSO
CVE-2026-64536.519.1cubewp1211CubeWP FrameworkCWE-89CubeWP Framework <= 1.1.30 - Authenticated (Subscriber+) SQL Injection via 'r…
CVE-2026-673065.319.1FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLE
CVE-2026-672949.318.8FreeRDPFreeRDPCWE-295FreeRDP before 3.29.0 TLS Certificate EKU Bypass
CVE-2026-673377.118.5better-authbetter-authCWE-288better-auth before 1.4.9 Two-Factor Authentication Bypass via session.cookieC…
CVE-2026-673228.718.1gitpython-developersGitPythonCWE-200GitPython before 3.1.52 Environment Variable Exfiltration via clone_from
CVE-2026-150185.318.0davejeschDatabase Collation FixCWE-89Database Collation Fix <= 1.2.10 - Unauthenticated SQL Injection via 'force-c…
CVE-2026-672929.317.8FreeRDPFreeRDPCWE-130FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure
CVE-2026-135969.117.6UnknownParticipants DatabaseCWE-89Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
CVE-2026-160876.517.4icegramIcegram Engage – Popups, Optins, CTAs & Lead GenerationCWE-89Icegram Engage <= 3.1.42 - Authenticated (Contributor+) Second-Order SQL Inje…
CVE-2026-154034.917.2dotonpaperPinpoint Booking System – Version 2CWE-89Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Inj…
CVE-2026-159514.917.2icegramIcegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logsCWE-89Icegram Mailer <= 1.0.12 - Authenticated (Administrator+) SQL Injection via '…
CVE-2026-166144.917.2westerndealGSheetConnector – CF7 Google Sheets ConnectorCWE-89GSheetConnector <= 5.2.1 - Authenticated (Administrator+) SQL Injection via '…
CVE-2026-175554.917.2wpvividpluginsWPvivid — Backup, Migration & StagingCWE-89WPvivid <= 0.9.131 - Authenticated (Administrator+) SQL Injection via 'export…
CVE-2026-673196.317.1axiosaxiosCWE-1321axios before 0.33.0 Prototype Pollution via nested option objects
CVE-2026-673118.216.9BudibasebudibaseCWE-918Budibase before 3.38.1 SSRF Blacklist Bypass via HTTP Redirect
CVE-2026-148397.516.9UnknownMapster WP MapsCWE-200Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Dis…
CVE-2026-673548.216.4guzzleguzzleCWE-201guzzlehttp/guzzle before 7.15.1 URI Fragment Disclosure via Referer
CVE-2026-673536.915.7guzzleguzzleCWE-770guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service
CVE-2026-673035.315.5FreeRDPFreeRDPCWE-617FreeRDP before 3.29.0 Denial of Service via serial DeviceControl
CVE-2026-672955.315.0FreeRDPFreeRDPCWE-22FreeRDP before 3.29.0 Path Traversal via drive redirection
CVE-2026-673318.714.8better-authscimCWE-639better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass
CVE-2025-714037.114.6better-authbetter-authCWE-601better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass
CVE-2026-166856.414.1codename065Download ManagerCWE-79Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-673396.913.9guzzleguzzleCWE-200guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure
CVE-2025-140735.313.8woocommerceWooCommerce PayPal PaymentsCWE-639WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information …
CVE-2026-673278.713.7better-authbetter-authCWE-287better-auth before 1.6.22 Account Takeover via Magic-Link Email-OTP
CVE-2026-673558.213.5guzzleguzzleCWE-201guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope
CVE-2026-156626.413.3mihail-barinovAdvanced Woo Labels – Product Labels & Badges for WooCommerceCWE-79Advanced Woo Labels <= 2.48 - Authenticated (Contributor+) Stored Cross-Site …
CVE-2026-143098.113.1UnknownChat On Desk Order NotificationsCWE-287Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OT…
CVE-2026-148368.113.1UnknownLogin & Register FormsCWE-287Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Re…
CVE-2026-153688.113.1UnknownUser Profile BuilderCWE-269Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login Af…
CVE-2026-145968.812.7UnknownDynamicKit for ElementorCWE-287DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Passw…
CVE-2026-148405.312.5UnknownYOP PollCWE-290YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoo…
CVE-2026-129665.312.4UnknownDirect Payments for WooCommerceCWE-284Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Orde…
CVE-2026-159888.811.9tigroumeowAI Engine – The Chatbot, AI Framework & MCP for WordPressCWE-352AI Engine <= 3.6.5 - Cross-Site Request Forgery to Privilege Escalation via R…
CVE-2026-29164.312.0jegthemeJeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPressCWE-200Jeg Kit for Elementor <= 3.1.1 - Authenticated (Contributor+) Exposure of Sen…
CVE-2026-183446.111.8nik00726Responsive Thumbnail SliderCWE-79Responsive Thumbnail Slider < 1.1.53 - Reflected Cross-Site Scripting via 'id…
CVE-2026-673526.811.6openwrtluciCWE-79luci-app-https-dns-proxy Stored XSS via resolver_url
CVE-2026-175716.111.2wpmanageninjaFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-79Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param'
CVE-2025-714022.010.6better-authbetter-authCWE-347better-auth before 1.4.0 Session Revocation via Forged Cookie
CVE-2026-76236.49.7brainstormforceSureForms – Contact Form Builder, AI Forms, Payment Form, Survey & QuizCWE-79SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-156446.49.7codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-156456.49.7codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-180626.49.7stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-79Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Sc…
CVE-2026-673345.19.7better-authbetter-authCWE-459better-auth Stale Sessions Persist After User Deletion
CVE-2026-133626.49.4sendpulseSendPulse Email Marketing NewsletterCWE-79SendPulse Email Marketing Newsletter <= 2.2.5 - Authenticated (Contributor+) …
CVE-2026-673297.19.3better-authstripeCWE-639@better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subsc…
CVE-2026-156496.49.2codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-160916.49.2rubengcGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-79GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-673267.39.1gitpython-developersGitPythonCWE-20GitPython before 3.1.50 Newline Injection via config_writer section
CVE-2026-118823.78.8UnknownBuilderall for WordPressCWE-284Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoni…
CVE-2026-159506.48.4cozythemesCozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & TemplatesCWE-79Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-160906.48.4rubengcGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-79GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-166846.48.4mervb1Easy Property ListingsCWE-79Easy Property Listings <= 3.5.24 - Authenticated (Subscriber+) Stored Cross-S…
CVE-2026-184356.48.4stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-79Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-24116.58.2zephyrprojectzephyrCWE-863Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, by…
CVE-2026-148225.37.7UnknownEvent Tickets and RegistrationCWE-284Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
CVE-2026-673105.37.8openremoteopenremoteCWE-863openremote before 1.27.0 Cross-Tenant IDOR via setAssetLinks
CVE-2026-133296.56.9UnknownBuckaroo Woocommerce Payments PluginCWE-284WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
CVE-2026-141952.76.9UnknownBrizyCWE-639Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure…
CVE-2026-673356.06.6better-authbetter-authCWE-287better-auth before 1.6.2 OAuth State Validation Bypass
CVE-2026-673385.16.7jupyterlabjupyterlabCWE-84JupyterLab before 4.5.9 Stored XSS via Extension Manager
CVE-2026-136045.36.5UnknownPixelavoCWE-918Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo…
CVE-2026-673077.06.3wazuhwazuhCWE-345Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync
CVE-2025-156694.86.3UnknownBit FormCWE-79Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
CVE-2026-672939.36.0FreeRDPFreeRDPCWE-295FreeRDP before 3.29.0 Improper Certificate Hostname Validation
CVE-2026-137257.15.7UnknownDynamic Pricing With Discount Rules for WooCommerceCWE-79Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS v…
CVE-2026-143156.55.8UnknownPixel Tag Manager for WooCommerceCWE-284Pixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion…
CVE-2026-145616.55.8UnknownAuthora : Easy login with mobile numberCWE-287Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Tak…
CVE-2026-142142.75.7UnknownBooking for Appointments and Events CalendarCWE-287Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass A…
CVE-2026-673325.35.6better-authoauth-providerCWE-285@better-auth/oauth-provider before 1.7.0-beta.4 Authorization Bypass
CVE-2026-185367.55.5RRWOData::EntropyCWE-319Data::Entropy versions before 0.010 for Perl read remote entropy sources over…
CVE-2026-673369.45.2better-authbetter-authCWE-327better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider
CVE-2026-673335.15.1better-authbetter-authCWE-79better-auth before 1.6.13 Stored XSS via javascript redirect_uri
CVE-2026-142925.44.8UnknownDownload ManagerCWE-79WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
CVE-2026-141973.84.6UnknownFluent SupportCWE-639Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
CVE-2026-664012.44.3FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264
CVE-2026-148232.24.2UnknownEvent Tickets and RegistrationCWE-639Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory M…
CVE-2026-673448.53.9ArcadeDataarcadedbCWE-862ArcadeDB before 26.7.2 Authentication Bypass via ALTER TYPE
CVE-2026-126965.42.8UnknownwpForo ForumCWE-79wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
CVE-2026-152345.42.8UnknownCodeless Page BuilderCWE-79Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
CVE-2026-152625.42.8UnknownAdmin Columns for ACF FieldsCWE-79Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field…
CVE-2025-144694.32.7mndpsingh287Theme EditorCWE-352Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification
CVE-2026-108273.51.2UnknownSpectra LegacyCWE-345Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS In…
CVE-2026-137294.30.8UnknownPodlove Podcast PublisherCWE-352Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation a…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-01 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.