AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.6 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
109 CVEs published, led by scriban (15).
109 CVEs published August 16, 2026: 14 critical, 33 high, 43 medium, 19 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 84 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 5925 | 28089 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
1586 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1262 | 3577 | 363 | 1781 | 637 | 1 | 11 | 2 | 0.1 | 7.8 | .0017 | +1221 ▲ |
| microsoft | 442 | 1864 | 132 | 1271 | 447 | 14 | 286 | 25 | 1.3 | 7.8 | .0044 | -202 ▼ |
| 49 | 1810 | 222 | 749 | 783 | 56 | 77 | 6 | 0.3 | 7.5 | .0025 | -45 ▼ | |
| red hat | 142 | 528 | 30 | 215 | 252 | 31 | 2 | 0 | 0.0 | 6.5 | .0028 | +86 ▲ |
| apple | 2 | 273 | 58 | 79 | 133 | 3 | 88 | 7 | 2.6 | 7.0 | .0027 | +2 ▲ |
| canonical | 11 | 38 | 12 | 9 | 12 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | +7 ▲ |
| suse | 5 | 26 | 5 | 14 | 6 | 1 | 0 | 0 | 0.0 | 8.1 | .0039 | -3 ▼ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 31 | 69 | 13 | 37 | 19 | 0 | 56 | 13 | 18.8 | 7.5 | .0046 | +16 ▲ |
| palo alto networks | 12 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | -2 ▼ |
| ubiquiti | 0 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | -25 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | +3 ▲ |
| fortinet | 7 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | -6 ▼ |
| vmware | 0 | 17 | 4 | 9 | 2 | 2 | 7 | 1 | 5.9 | 8.3 | .0040 | -1 ▼ |
| f5 | 0 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | -8 ▼ |
| ivanti | 3 | 14 | 4 | 8 | 2 | 0 | 25 | 5 | 35.7 | 8.3 | .0754 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 101 | 437 | 86 | 189 | 149 | 12 | 33 | 2 | 0.5 | 7.5 | .0049 | +25 ▲ |
| mozilla | 1 | 128 | 51 | 42 | 35 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | -5 ▼ |
| gitlab | 13 | 64 | 1 | 13 | 42 | 8 | 4 | 2 | 3.1 | 4.9 | .0028 | +6 ▲ |
| drupal | 0 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | -46 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0043 | +4 ▲ |
| docker | 1 | 8 | 0 | 5 | 3 | 0 | 0 | 0 | 0.0 | 7.7 | .0015 | +1 ▲ |
| wordpress | 1 | 4 | 1 | 2 | 1 | 0 | 2 | 2 | 50.0 | 8.8 | .5550 | +1 ▲ |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1379 | 343 | 653 | 322 | 61 | 27 | 3 | 0.2 | 8.1 | .0036 | -1 ▼ |
| ibm | 192 | 421 | 99 | 180 | 137 | 5 | 6 | 1 | 0.2 | 7.5 | .0031 | +190 ▲ |
| adobe | 60 | 312 | 39 | 145 | 123 | 5 | 19 | 3 | 1.0 | 7.8 | .0026 | -33 ▼ |
| progress | 16 | 58 | 14 | 34 | 10 | 0 | 6 | 1 | 1.7 | 8.1 | .0036 | +6 ▲ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | 0 |
| veeam | 10 | 16 | 5 | 9 | 2 | 0 | 1 | 0 | 0.0 | 8.6 | .0034 | +10 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | +4 ▲ |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 16 | 36 | 15 | 5 | 9 | 7 | 3 | 0 | 0.0 | 7.4 | .0157 | +15 ▲ |
| siemens | 19 | 35 | 2 | 23 | 8 | 2 | 0 | 0 | 0.0 | 7.3 | .0016 | +12 ▲ |
| synology | 1 | 24 | 2 | 6 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +1 ▲ |
| rockwell automation | 0 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | -17 ▼ |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 20 | 140 | 0 | 0 | 75 | 65 | 0 | 0 | 0.0 | 5.5 | .0032 | -17 ▼ |
| dell | 18 | 117 | 9 | 58 | 47 | 3 | 2 | 1 | 0.9 | 7.2 | .0021 | -19 ▼ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -16 ▼ |
| nvidia | 16 | 98 | 13 | 66 | 19 | 0 | 0 | 0 | 0.0 | 7.7 | .0034 | -24 ▼ |
| gitea | 48 | 89 | 19 | 36 | 30 | 4 | 0 | 0 | 0.0 | 7.5 | .0034 | +8 ▲ |
| elastic | 48 | 86 | 0 | 18 | 68 | 0 | 1 | 0 | 0.0 | 6.5 | .0029 | +39 ▲ |
| capgo | 0 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | -22 ▼ |
| itsourcecode | 11 | 82 | 0 | 0 | 19 | 63 | 0 | 0 | 0.0 | 2.1 | .0032 | -1 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63030 | .9779 | 99.9 | 9.8 |
| CVE-2026-16232 | .8912 | 99.8 | 9.3 |
| CVE-2026-63077 | .8473 | 99.7 | 9.8 |
| CVE-2026-60137 | .7979 | 99.6 | 5.9 |
| CVE-2026-72898 | .7922 | 99.6 | 10.0 |
| CVE-2026-0770 | .6342 | 99.1 | 9.8 |
| CVE-2026-59310 | .4588 | 98.7 | 9.8 |
| CVE-2026-61511 | .3399 | 98.3 | 9.3 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .7922 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0486 | |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-47668 | 10.0 | .0388 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-44359 | 10.0 | .0180 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-16812 | 10.0 | .0157 | KEV |
| CVE-2026-73299 | 10.0 | .0121 |
| Vendor | CVEs |
|---|---|
| linux | 2056 |
| oracle | 1108 |
| microsoft | 461 |
| 451 | |
| ibm | 261 |
| red hat | 241 |
| apache | 205 |
| apple | 169 |
| adobe | 74 |
| elastic | 67 |
| Vendor | KEV |
|---|---|
| microsoft | 25 |
| cisco | 13 |
| apple | 7 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 66 |
| PyPI | 5 |
| Go | 3 |
| npm | 3 |
| Packagist | 2 |
| crates.io | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1733 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1733 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1733 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1733 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1733 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1733 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1733 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1733 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1733 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1733 |
EXPLOIT PUBLISHED — Webkul Bagisto: 5 CVEs (CVE-2026-19993, CVE-2026-19994, CVE-2026-19995, CVE-2026-19996, CVE-2026-19997). Public exploit references added.
EXPLOIT PUBLISHED — Open Asset Import Library Assimp: 4 CVEs (CVE-2026-19967, CVE-2026-19968, CVE-2026-19969, CVE-2026-19970). Public exploit references added.
EXPLOIT PUBLISHED — itsourcecode Hospital Management System: 3 CVEs (CVE-2026-19972, CVE-2026-19973, CVE-2026-20000). Public exploit references added.
EXPLOIT PUBLISHED — Unknown ECS: 3 CVEs (CVE-2026-14229, CVE-2026-14230, CVE-2026-18807). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-13700 (Unknown WooMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14832 (Unknown ShopSmart Loyalty for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16007 (AppFlowy-IO AppFlowy-Cloud). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16541 (Unknown Simply Schedule Appointments). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16611 (Unknown Product Feed PRO for WooCommerce by AdTribes). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18216 (Unknown Backup Migration). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19478 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19650 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19895 (opensourcepos Open Source Point of Sale). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19897 (mangroup dtale). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19900 (LB-LINK X-PRO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19903 (SourceCodester Online Clothing Store). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19917 (code-projects Online Food Order System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19965 (automad). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19966 (CodeCanyon TimeCamp Integration for CRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19974 (treefrogframework treefrog-framework). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19976 (COMFAST CF-N1-S). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19977 (EFM ipTIME A3004T). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19978 (jiantao88 android-mcp-server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19984 (jkawamoto mcp-florence2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19986 (Adblock for Youtube Extension). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19988 (Alaev SEO Tools Extension). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19992 (Orange View Limited DualSafe Password Manager & Digital Vault Extension). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19998 (code-projects Online Shopping System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19999 (Open Asset Import Library Assimp Assimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-72743 (dataease SQLBot). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74842 (Kira-Pgr PromptShopMCP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74843 (Wavlink WN531P3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75011 (kylecui NetForensicMCP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75012 (TOTOLINK EX1200L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75013 (TOTOLINK EX1200L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75014 (SourceCodester Pet Grooming Management Software). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75077 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75078 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
RESCORED — CVE-2026-19918 (SpaceX Starlink Router Gen 3). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19919 (code-projects Online Shopping System). CVSS 6.9 → 5.5 (NVD).
How to read these box scores · glossary
109 CVEs published. 25 box scores, 84 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.6 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.7 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 15 Public exploit reference published Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.6 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 15 Public exploit reference published Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0090 57.0 —
AFFECTED Product Versions Fixed AC10 16.03.10.09_multi_TDE01 – —
TIMELINE Aug 15 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0080 54.0 —
AFFECTED Product Versions Fixed Kirki – Freeform Page Builder, Website Builder & Customizer unspecified —
TIMELINE Jul 27 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0079 53.5 —
AFFECTED Product Versions Fixed StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More unspecified —
TIMELINE Jul 8 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0071 50.9 —
AFFECTED Product Versions Fixed WCPOS – Point of Sale (POS) plugin for WooCommerce unspecified —
TIMELINE Jul 27 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0070 50.5 —
AFFECTED Product Versions Fixed ProSolution WP Client unspecified —
TIMELINE Jul 2 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0064 47.9 —
AFFECTED Product Versions Fixed ProSolution WP Client unspecified —
TIMELINE Jul 17 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0057 44.6 —
AFFECTED Product Versions Fixed Podlove Podcast Publisher unspecified —
TIMELINE Jul 17 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0055 43.5 —
AFFECTED Product Versions Fixed Net-OAuth unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 16 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0053 42.6 —
AFFECTED Product Versions Fixed Query Wrangler unspecified —
TIMELINE Jul 2 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0052 41.8 —
AFFECTED Product Versions Fixed Contact Form, Survey, Quiz & Popup Form Builder – ARForms unspecified —
TIMELINE Jan 28 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0051 41.1 —
AFFECTED Product Versions Fixed Frontend Admin by DynamiApps unspecified —
TIMELINE Jul 30 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0048 39.4 —
AFFECTED Product Versions Fixed Simply Schedule Appointments unspecified —
TIMELINE Jun 25 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0048 39.3 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0048 39.3 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 15 Public exploit reference published Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0046 37.6 —
AFFECTED Product Versions Fixed Lemonldap-NG-Portal 2.0.0 – —
TIMELINE Aug 8 Reserved by CNA Aug 16 Published (CNA: CPANSec)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0045 37.2 —
AFFECTED Product Versions Fixed siyuan unspecified 3.7.4
TIMELINE Aug 10 Reserved by CNA Aug 16 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0044 36.7 —
AFFECTED Product Versions Fixed Extra Product Options Builder for WooCommerce unspecified —
TIMELINE Aug 13 Reserved by CNA Aug 15 Public exploit reference published Aug 16 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N N H 6.5 .0044 36.1 —
AFFECTED Product Versions Fixed Net-OAuth unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 16 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0042 34.2 —
AFFECTED Product Versions Fixed WP Travel Engine – Tour Booking Plugin – Tour Operator Software unspecified —
TIMELINE Jul 24 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U H H H 6.6 .0039 31.7 —
AFFECTED Product Versions Fixed Turnkey bbPress by WeaverTheme unspecified —
TIMELINE May 28 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0039 31.4 —
AFFECTED Product Versions Fixed Product Table & List Builder For WooCommerce unspecified —
TIMELINE Jul 10 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0037 30.0 —
AFFECTED Product Versions Fixed WPvivid — Backup, Migration & Staging unspecified —
TIMELINE Aug 13 Reserved by CNA Aug 15 Public exploit reference published Aug 16 Published (CNA: WPScan)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-73060 | 8.7 | 30.0 | scriban | scriban | CWE-770 | Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply |
| CVE-2026-74251 | 9.3 | 29.9 | phoca.cz | Phoca Cart extension for Joomla | CWE-89 | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute fil… |
| CVE-2026-19717 | 7.5 | 27.1 | Unknown | CatFolders Document Gallery & PDF Library | CWE-200 | CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure v… |
| CVE-2026-13167 | 4.3 | 27.2 | wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI | CWE-862 | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builde… |
| CVE-2026-17123 | 8.8 | 27.0 | wproyal | Royal Addons for Elementor – Addons and Templates Kit for Elementor | CWE-918 | Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-… |
| CVE-2026-74789 | 8.7 | 26.5 | scriban | scriban | CWE-400 | Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations |
| CVE-2026-13424 | 7.2 | 25.3 | ladela | Online Scheduling and Appointment Booking System – Bookly | CWE-79 | Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated St… |
| CVE-2026-15602 | 4.9 | 25.2 | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | CWE-89 | NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_par… |
| CVE-2026-19714 | 9.1 | 24.6 | Unknown | Simple JWT Login | CWE-287 | Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Googl… |
| CVE-2026-9767 | 6.5 | 24.1 | weblizar | The School Management – Education & Learning ERP | CWE-89 | The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'ord… |
| CVE-2026-74795 | 8.7 | 23.9 | scriban | scriban | CWE-674 | Scriban before 6.6.0 Denial of Service via Uncontrolled Recursion |
| CVE-2026-17533 | 7.2 | 23.8 | Unknown | All-in-One WP Migration and Backup | CWE-269 | All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network… |
| CVE-2026-18316 | 9.1 | 23.6 | solacewp | Solace Extra | CWE-862 | Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content… |
| CVE-2026-18385 | 5.4 | 23.0 | properfraction | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | CWE-94 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User P… |
| CVE-2026-74792 | 8.7 | 22.8 | scriban | scriban | CWE-674 | Scriban before 7.0.0 Stack Overflow via nested array initializers |
| CVE-2026-15002 | 7.2 | 22.7 | bluemediapl | Autopay | CWE-79 | Autopay <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting via 'bm_woocom… |
| CVE-2026-18653 | 7.2 | 22.8 | Unknown | WP Directory Kit | CWE-89 | WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter |
| CVE-2026-2497 | 7.2 | 22.7 | bestwebsoft | Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress | CWE-89 | Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via G… |
| CVE-2026-15345 | 4.3 | 22.6 | shortpixel | ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization | CWE-862 | ShortPixel Adaptive Images <= 3.11.5 - Missing Authorization to Authenticated… |
| CVE-2026-18347 | 4.3 | 22.6 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-862 | Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensiti… |
| CVE-2026-73061 | 9.3 | 22.2 | scriban | scriban | CWE-284 | Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor |
| CVE-2026-12998 | 5.3 | 22.2 | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | CWE-639 | Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenti… |
| CVE-2026-11780 | 6.4 | 21.8 | expresstech | Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker | CWE-79 | Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored … |
| CVE-2026-19955 | 2.0 | 21.3 | n/a | TrailDB | CWE-119 | TrailDB TOC Validation tdb.c tdb_open out-of-bounds |
| CVE-2026-12905 | 4.3 | 20.9 | ladela | Online Scheduling and Appointment Booking System – Bookly | CWE-639 | Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authentic… |
| CVE-2026-2283 | 4.9 | 20.7 | faiyazalam | User Login History | CWE-89 | User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection vi… |
| CVE-2026-15351 | 4.9 | 20.7 | wcvendors | WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors | CWE-89 | WC Vendors <= 2.7.0 - Authenticated (Shop Manager+) SQL Injection via 'status… |
| CVE-2026-17582 | 4.9 | 20.7 | quantumcloud | Slider Hero with Video Background, Animation | CWE-89 | Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Admini… |
| CVE-2026-74790 | 9.3 | 20.5 | scriban | scriban | CWE-693 | Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache |
| CVE-2026-19929 | 2.1 | 20.3 | n/a | OpenBoxes | CWE-791 | OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate sp… |
| CVE-2026-15009 | 6.1 | 19.9 | saadiqbal | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | CWE-79 | Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMess… |
| CVE-2026-73057 | 8.7 | 19.7 | stoatchat | stoatchat | CWE-400 | stoatchat before 0.15.0 Uncapped SVG Rendering Denial of Service |
| CVE-2026-73062 | 8.7 | 19.7 | scriban | scriban | CWE-770 | Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication |
| CVE-2026-74783 | 8.7 | 19.7 | scriban | scriban | CWE-674 | Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service |
| CVE-2026-74787 | 8.7 | 19.7 | scriban | scriban | CWE-674 | Scriban before 7.0.0 Uncontrolled Recursion via object.to_json |
| CVE-2026-74788 | 8.7 | 19.8 | scriban | scriban | CWE-770 | Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right |
| CVE-2026-74794 | 8.7 | 19.8 | scriban | scriban | CWE-674 | Scriban before 6.6.0 Denial of Service via Infinite Recursion |
| CVE-2026-16079 | 6.5 | 19.1 | pdamsten | Fullscreen Galleria | CWE-89 | Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection vi… |
| CVE-2026-74785 | 7.1 | 19.0 | scriban | scriban | CWE-400 | Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption |
| CVE-2026-74786 | 7.1 | 19.0 | scriban | scriban | CWE-770 | Scriban before 7.0.0 Denial of Service via Unbounded Template Output |
| CVE-2026-19613 | 6.5 | 18.7 | Unknown | ECS | CWE-200 | ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeat… |
| CVE-2026-19957 | 2.1 | 18.7 | graphlit | graphlit-mcp-server | CWE-918 | graphlit graphlit-mcp-server ssrf-test Endpoint tools.ts fetch server-side re… |
| CVE-2026-74791 | 9.2 | 18.6 | scriban | scriban | CWE-226 | Scriban before 7.0.0 Authorization Bypass via Stale Include Cache |
| CVE-2026-19926 | 5.5 | 18.0 | n/a | Evergreen | CWE-74 | Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection |
| CVE-2026-74784 | 8.7 | 17.6 | scriban | scriban | CWE-770 | Scriban before 7.2.0 Denial of Service via array.insert_at |
| CVE-2026-15963 | 6.5 | 17.4 | expresstech | Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker | CWE-89 | Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Inj… |
| CVE-2026-12477 | 4.4 | 17.1 | wpmonks | Gravity Booster – Styles & Layouts for Gravity Forms | CWE-79 | Gravity Booster <= 5.26 - Authenticated (Editor+) Stored Cross-Site Scripting… |
| CVE-2024-58375 | 8.7 | 16.7 | opentofu | opentofu | CWE-497 | OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation |
| CVE-2026-10734 | 7.2 | 16.5 | infility | Infility Global | CWE-79 | Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via … |
| CVE-2026-15066 | 6.4 | 16.6 | timwhitlock | Loco Translate | CWE-79 | Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scrip… |
| CVE-2026-19933 | 2.1 | 16.4 | DefaultFuction | Customer-Relationship-Management-In-C-Project | CWE-119 | DefaultFuction Customer-Relationship-Management-In-C-Project Customer Search … |
| CVE-2026-19927 | 2.1 | 16.2 | n/a | OpenBoxes | CWE-918 | OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side… |
| CVE-2026-19928 | 2.1 | 16.2 | n/a | OpenBoxes | CWE-266 | OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges mana… |
| CVE-2026-19726 | 6.5 | 15.8 | Unknown | Visualizer | CWE-863 | Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure |
| CVE-2025-10005 | 4.3 | 15.2 | buildwps | PPWP – Password Protect Pages | CWE-639 | Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference … |
| CVE-2026-19930 | 2.1 | 15.1 | n/a | Dolibarr | CWE-74 | Dolibarr User Cloning card.php ldap injection |
| CVE-2026-73058 | 6.9 | 14.6 | stoatchat | stoatchat | CWE-918 | stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass |
| CVE-2026-19932 | 2.1 | 14.4 | DefaultFuction | Notice-System-Managent | CWE-74 | DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.ev… |
| CVE-2026-74796 | 7.0 | 13.5 | opentofu | opentofu | CWE-59 | OpenTofu before 1.11.7 Symlink Following Path Traversal |
| CVE-2026-19958 | 2.1 | 13.3 | iatsiuk | pptr-mcp | CWE-74 | iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection |
| CVE-2026-16779 | 4.3 | 12.5 | extendthemes | Kubio AI Page Builder | CWE-862 | Kubio AI Page Builder <= 2.8.5 - Missing Authorization to Authenticated (Cont… |
| CVE-2026-73059 | 7.1 | 12.5 | stoatchat | stoatchat | CWE-863 | stoatchat before 0.15.0 Permission Bypass via message_fetch |
| CVE-2026-19964 | 2.0 | 12.0 | Jij-Inc | Jij-MCP-Server | CWE-74 | Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection |
| CVE-2026-19956 | 5.3 | 11.6 | gomarble-ai | facebook-ads-mcp-server | CWE-918 | gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-sid… |
| CVE-2026-19711 | 6.5 | 11.4 | Unknown | Premium Packages | CWE-284 | Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbit… |
| CVE-2026-19925 | 2.0 | 11.0 | SourceCodester | Stock Management System | CWE-74 | SourceCodester Stock Management System Master.php delete_supplier sql injection |
| CVE-2026-2487 | 4.4 | 10.2 | weblizar | Admin Custom Login | CWE-79 | Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Sit… |
| CVE-2026-19921 | 2.1 | 9.8 | code-projects | Online Shopping System | CWE-74 | code-projects Online Shopping System homeaction.php sql injection |
| CVE-2026-19923 | 2.1 | 9.8 | code-projects | Online Shopping System | CWE-74 | code-projects Online Shopping System checkout_process.php sql injection |
| CVE-2026-19934 | 2.1 | 9.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System vieworder.php sql injection |
| CVE-2026-19922 | 2.0 | 9.6 | code-projects | Online Shopping System | CWE-79 | code-projects Online Shopping System checkout.php cross site scripting |
| CVE-2026-15726 | 6.4 | 9.2 | cryout-creations | Serious Slider | CWE-79 | Serious Slider <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-15790 | 6.4 | 8.8 | emarket-design | Video Gallery – YouTube Gallery, Playlist & Video Grid | CWE-79 | Video Gallery <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting … |
| CVE-2026-15604 | 6.4 | 8.4 | toocheke | Toocheke Companion | CWE-79 | Toocheke Companion <= 2.10 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-16758 | 6.4 | 8.4 | aliakro | Snippet Shortcodes | CWE-79 | Snippet Shortcodes <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site … |
| CVE-2026-16775 | 6.4 | 8.4 | smub | Smash Balloon Social Post Feed – Simple Social Feeds for WordPress | CWE-79 | Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored… |
| CVE-2026-18402 | 6.4 | 8.4 | brainstormforce | SureDash – Community, Courses & Member Dashboard | CWE-79 | SureDash <= 1.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-2357 | 6.4 | 7.7 | boldthemes | Bold Page Builder | CWE-79 | Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-19712 | 6.1 | 7.7 | Unknown | Masteriyo LMS | CWE-79 | Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description |
| CVE-2026-74797 | 2.3 | 6.9 | opentofu | opentofu | CWE-400 | OpenTofu before 1.11.4 Denial of Service via malicious zip |
| CVE-2026-13712 | 5.4 | 5.1 | Unknown | Divi | CWE-79 | Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL |
| CVE-2026-17608 | 6.5 | 4.9 | aresit | WP Compress – Instant Performance & Speed Optimization | CWE-352 | WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Dele… |
| CVE-2026-74578 | 7.1 | 4.1 | Linux | Linux | — | crypto: algif_skcipher - force synchronous processing on trees without ctx->s… |
| CVE-2026-15384 | 5.7 | 1.5 | Unknown | Manual Image Crop | CWE-287 | Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite v… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-16 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.