boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, August 16, 2026 · all times UTC← 2026-08-15 · archive · 2026-08-17 →

109 CVEs published, led by scriban (15).

109 CVEs published August 16, 2026: 14 critical, 33 high, 43 medium, 19 low; 0 in the KEV catalog at press time; 5 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 84 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published59252807214452564
KEV catalog size1671

1582 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux12623579363178163512730.17.8.0016+1221 ▲
microsoft4421873130127344714380331.87.8.0039-202 ▼
google491809222745783567460.37.5.0023-45 ▼
red hat1424982920224126400.06.5.0024+86 ▲
apple2268577412739472.67.0.0024+2 ▲
canonical1138129125000.07.8.0017+7 ▲
suse52651461000.08.1.0030-3 ▼
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco31711135170961419.77.5.0034+15 ▲
palo alto networks12370221121425.44.6.0018-2 ▼
ubiquiti036142110438.38.8.0036-25 ▼
netgear93200275800.04.3.0023+3 ▲
fortinet7304814128620.06.6.0048-7 ▼
f50175830715.98.6.0057-8 ▼
vmware01648222200.08.2.0039-1 ▼
ivanti314262033535.77.9.0754+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache10143586189147124020.57.5.0048+25 ▲
mozilla112851423501300.08.1.0029-5 ▼
gitlab1366013438423.04.9.0025+6 ▲
drupal05165355512.05.9.0018-46 ▼
github5171790000.06.6.0037+4 ▲
docker180530100.07.7.0015+1 ▲
wordpress1412105250.08.8.3700+1 ▲
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01379342653322614030.28.1.0032-1 ▼
ibm192421971821366710.27.5.0029+190 ▲
adobe603143914412357541.37.8.0021-33 ▼
progress16581434100911.78.1.0032+6 ▲
solarwinds0231623011417.49.1.00440
veeam10165920400.08.6.0028+10 ▲
zohocorp4103520000.08.7.0129+4 ▲
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link1637155972612.77.4.0104+15 ▲
siemens193522382100.07.3.0013+12 ▲
synology12426133000.05.6.0025+1 ▲
rockwell automation02441820000.08.7.0025-17 ▼
schneider electric091620100.08.6.00240
abb070430000.07.2.00180
hikvision0704202114.37.2.00250
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester20140007565000.05.5.0026-17 ▼
dell18117858473210.97.2.0019-19 ▼
openclaw01110583914000.07.0.0022-16 ▼
nvidia16981366190000.07.7.0025-24 ▼
gitea48891936304000.07.5.0030+8 ▲
elastic4886018680300.06.5.0027+39 ▲
capgo083242381000.07.1.0028-22 ▼
itsourcecode1182001963000.02.1.0020-1 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.993199.99.8
CVE-2026-63030.956099.99.8
CVE-2026-34486.829399.67.5
CVE-2026-16232.733099.49.3
CVE-2026-60137.731099.45.9
CVE-2026-0770.568899.09.8
CVE-2026-62144.206297.39.1
CVE-2021-27137.164996.78.1
CVE-2026-15733.135496.19.8
CVE-2026-63077.107295.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.1040KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4836210.0.0207
CVE-2026-1918810.0.0189
CVE-2026-7329910.0.0121
CVE-2026-4435910.0.0100
CVE-2026-4561810.0.0095
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
linux2056
oracle1108
microsoft461
google451
ibm261
red hat241
apache205
apple169
adobe74
elastic67
Most KEV additions (YTD)
VendorKEV
microsoft33
cisco14
apple7
fortinet6
google6
ivanti5
adobe4
solarwinds4
synacor4
langflow3
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171733
CVE-2021-27102Accellion2021-11-171733
CVE-2021-27101Accellion2021-11-171733
CVE-2021-27103Accellion2021-11-171733
CVE-2021-21017Adobe2021-11-171733
CVE-2021-28550Adobe2021-11-171733
CVE-2021-42013Apache2021-11-171733
CVE-2021-41773Apache2021-11-171733
CVE-2021-30858Apple2021-11-171733
CVE-2021-30860Apple2021-11-171733

Transactions

EXPLOIT PUBLISHED — Webkul Bagisto: 5 CVEs (CVE-2026-19993, CVE-2026-19994, CVE-2026-19995, CVE-2026-19996, CVE-2026-19997). Public exploit references added.

EXPLOIT PUBLISHED — Open Asset Import Library Assimp: 4 CVEs (CVE-2026-19967, CVE-2026-19968, CVE-2026-19969, CVE-2026-19970). Public exploit references added.

EXPLOIT PUBLISHED — itsourcecode Hospital Management System: 3 CVEs (CVE-2026-19972, CVE-2026-19973, CVE-2026-20000). Public exploit references added.

EXPLOIT PUBLISHED — Unknown ECS: 3 CVEs (CVE-2026-14229, CVE-2026-14230, CVE-2026-18807). Public exploit references added.

EXPLOIT PUBLISHEDCVE-2026-13700 (Unknown WooMS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14832 (Unknown ShopSmart Loyalty for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16007 (AppFlowy-IO AppFlowy-Cloud). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16541 (Unknown Simply Schedule Appointments). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16611 (Unknown Product Feed PRO for WooCommerce by AdTribes). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18216 (Unknown Backup Migration). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19478 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19650 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19895 (opensourcepos Open Source Point of Sale). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19897 (mangroup dtale). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19900 (LB-LINK X-PRO). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19903 (SourceCodester Online Clothing Store). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19917 (code-projects Online Food Order System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19965 (automad). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19966 (CodeCanyon TimeCamp Integration for CRM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19974 (treefrogframework treefrog-framework). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19976 (COMFAST CF-N1-S). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19977 (EFM ipTIME A3004T). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19978 (jiantao88 android-mcp-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19984 (jkawamoto mcp-florence2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19986 (Adblock for Youtube Extension). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19988 (Alaev SEO Tools Extension). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19992 (Orange View Limited DualSafe Password Manager & Digital Vault Extension). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19998 (code-projects Online Shopping System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19999 (Open Asset Import Library Assimp Assimp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-72743 (dataease SQLBot). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-74842 (Kira-Pgr PromptShopMCP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-74843 (Wavlink WN531P3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75011 (kylecui NetForensicMCP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75012 (TOTOLINK EX1200L). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75013 (TOTOLINK EX1200L). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75014 (SourceCodester Pet Grooming Management Software). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75077 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75078 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

RESCOREDCVE-2026-19918 (SpaceX Starlink Router Gen 3). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-19919 (code-projects Online Shopping System). CVSS 6.9 → 5.5 (NVD).

Yesterday's Results

How to read these box scores · glossary

109 CVEs published. 25 box scores, 84 table rows — nothing truncated.

Edimax EW-7478APC formWlbasic command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-77, CWE-74 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
Edimax EW-7478APC setWAN command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 15  Public exploit reference published
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
Edimax EW-7478APC stainfo command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 15  Public exploit reference published
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-77, CWE-74 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
Tenda AC10 httpd R7WebsSecurityHandler improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0090   56.9     —
AFFECTED
  Product  Versions                   Fixed
  AC10     16.03.10.09_multi_TDE01 –  —
TIMELINE
  Aug 15  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-287 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
Lemonldap-NG-Portal — Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0082   54.3     —
AFFECTED
  Product              Versions  Fixed
  Lemonldap-NG-Portal  2.0.0 –   —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 16  Published (CNA: CPANSec)
CWE-305, CWE-628 · CNA: CPANSec · CVSS v3.1 · 4 references · NVD status: Received
kodezen StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More — StoreEngine <= 2.1.1 - Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0081   54.2     —
AFFECTED
  Product                                                                                   Versions     Fixed
  StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 16 references · NVD status: Received
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki <= 6.1.1 - Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0080   53.9     —
AFFECTED
  Product                                                      Versions     Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Received
kilbot WCPOS – Point of Sale (POS) plugin for WooCommerce — WCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0073   51.6     —
AFFECTED
  Product                                             Versions     Fixed
  WCPOS – Point of Sale (POS) plugin for WooCommerce  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Received
ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0070   50.4     —
AFFECTED
  Product                Versions     Fixed
  ProSolution WP Client  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Received
ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0064   48.0     —
AFFECTED
  Product                Versions     Fixed
  ProSolution WP Client  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
eteubert Podlove Podcast Publisher — Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0059   45.5     —
AFFECTED
  Product                    Versions     Fixed
  Podlove Podcast Publisher  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
Net-OAuth — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0055   43.7     —
AFFECTED
  Product    Versions     Fixed
  Net-OAuth  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 16  Published (CNA: CPANSec)
CWE-757 · CNA: CPANSec · CVSS v3.1 · 6 references · NVD status: Received
daggerhart Query Wrangler — Query Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0055   43.6     —
AFFECTED
  Product         Versions     Fixed
  Query Wrangler  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
reputeinfosystems Contact Form, Survey, Quiz & Popup Form Builder – ARForms — Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0052   41.9     —
AFFECTED
  Product                                                    Versions     Fixed
  Contact Form, Survey, Quiz & Popup Form Builder – ARForms  unspecified  —
TIMELINE
  Jan 28  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Received
croixhaug Simply Schedule Appointments — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0049   39.9     —
AFFECTED
  Product                       Versions     Fixed
  Simply Schedule Appointments  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Received
Edimax EW-7478APC formWanTcpipSetup stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0047   38.9     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
Edimax EW-7478APC formWlSiteSurvey buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0047   38.9     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 15  Public exploit reference published
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
siyuan-note siyuan — SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0045   37.6     —
AFFECTED
  Product  Versions     Fixed
  siyuan   unspecified  3.7.4
TIMELINE
  Aug 10  Reserved by CNA
  Aug 16  Published (CNA: VulnCheck)
CWE-307 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
shabti Frontend Admin by DynamiApps — Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0045   37.4     —
AFFECTED
  Product                       Versions     Fixed
  Frontend Admin by DynamiApps  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Received
Unknown Extra Product Options Builder for WooCommerce — Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Disclosure via getpublicfileupload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0044   37.1     —
AFFECTED
  Product                                        Versions     Fixed
  Extra Product Options Builder for WooCommerce  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 15  Public exploit reference published
  Aug 16  Published (CNA: WPScan)
CWE-862 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Net-OAuth — Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  N  H    6.5   .0044   36.5     —
AFFECTED
  Product    Versions     Fixed
  Net-OAuth  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 16  Published (CNA: CPANSec)
CWE-770 · CNA: CPANSec · CVSS v3.1 · 4 references · NVD status: Received
wptravelengine WP Travel Engine – Tour Booking Plugin – Tour Operator Software — WP Travel Engine <= 6.8.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0042   34.7     —
AFFECTED
  Product                                                          Versions     Fixed
  WP Travel Engine – Tour Booking Plugin – Tour Operator Software  unspecified  —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Received
wpweaver Turnkey bbPress by WeaverTheme — Turnkey bbPress by WeaverTheme <= 1.7.1 - Authenticated (Administrator+) PHP Object Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0040   33.4     —
AFFECTED
  Product                         Versions     Fixed
  Turnkey bbPress by WeaverTheme  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Received
wcproducttable Product Table & List Builder For WooCommerce — Product Table & List Builder For WooCommerce <= 5.6.0 - Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0039   32.0     —
AFFECTED
  Product                                       Versions     Fixed
  Product Table & List Builder For WooCommerce  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-74 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
Unknown WPvivid — Backup, Migration & Staging — WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_connect
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0037   30.6     —
AFFECTED
  Product                                Versions     Fixed
  WPvivid — Backup, Migration & Staging  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 15  Public exploit reference published
  Aug 16  Published (CNA: WPScan)
CWE-22 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-730608.730.6scribanscribanCWE-770Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply
CVE-2026-742519.330.5phoca.czPhoca Cart extension for JoomlaCWE-89Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute fil…
CVE-2026-171238.828.8wproyalRoyal Addons for Elementor – Addons and Templates Kit for ElementorCWE-918Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-…
CVE-2026-197177.527.7UnknownCatFolders Document Gallery & PDF LibraryCWE-200CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure v…
CVE-2026-131674.327.8wpeverestEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AICWE-862Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builde…
CVE-2026-747898.727.2scribanscribanCWE-400Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations
CVE-2026-134247.225.9ladelaOnline Scheduling and Appointment Booking System – BooklyCWE-79Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated St…
CVE-2026-156024.925.9webawaysNEX-Forms – Ultimate Forms Plugin for WordPressCWE-89NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_par…
CVE-2026-97676.525.8weblizarThe School Management – Education & Learning ERPCWE-89The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'ord…
CVE-2026-183169.125.3solacewpSolace ExtraCWE-862Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content…
CVE-2026-197149.125.3UnknownSimple JWT LoginCWE-287Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Googl…
CVE-2026-747958.724.6scribanscribanCWE-674Scriban before 6.6.0 Denial of Service via Uncontrolled Recursion
CVE-2026-183855.424.6properfractionPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePressCWE-94Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User P…
CVE-2026-175337.224.5UnknownAll-in-One WP Migration and BackupCWE-269All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network…
CVE-2026-24977.224.3bestwebsoftGallery by BestWebSoft – Customizable Image and Photo Galleries for WordPressCWE-89Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via G…
CVE-2026-747928.723.4scribanscribanCWE-674Scriban before 7.0.0 Stack Overflow via nested array initializers
CVE-2026-150027.223.4bluemediaplAutopayCWE-79Autopay <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting via 'bm_woocom…
CVE-2026-186537.223.4UnknownWP Directory KitCWE-89WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter
CVE-2026-117806.423.4expresstechQuiz and Survey Master (QSM) – Quiz Maker & Survey MakerCWE-79Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored …
CVE-2026-153454.323.3shortpixelShortPixel Adaptive Images – WebP, AVIF, CDN, Image OptimizationCWE-862ShortPixel Adaptive Images <= 3.11.5 - Missing Authorization to Authenticated…
CVE-2026-183474.323.2themeumKirki – Freeform Page Builder, Website Builder & CustomizerCWE-862Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensiti…
CVE-2026-730619.322.8scribanscribanCWE-284Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor
CVE-2026-129985.322.8wpmudevForminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-639Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenti…
CVE-2026-199552.022.0n/aTrailDBCWE-125TrailDB TOC Validation tdb.c tdb_open out-of-bounds
CVE-2026-129054.321.5ladelaOnline Scheduling and Appointment Booking System – BooklyCWE-639Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authentic…
CVE-2026-22834.921.3faiyazalamUser Login HistoryCWE-89User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection vi…
CVE-2026-153514.921.3wcvendorsWC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product VendorsCWE-89WC Vendors <= 2.7.0 - Authenticated (Shop Manager+) SQL Injection via 'status…
CVE-2026-175824.921.3quantumcloudSlider Hero with Video Background, AnimationCWE-89Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Admini…
CVE-2026-747909.321.1scribanscribanCWE-693Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache
CVE-2026-199292.121.0n/aOpenBoxesCWE-1336OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate sp…
CVE-2026-160796.520.7pdamstenFullscreen GalleriaCWE-89Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection vi…
CVE-2026-150096.120.6saadiqbalAdvanced File Manager – Ultimate File Manager for WordPress And Document Library SolutionCWE-79Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMess…
CVE-2026-730578.720.4stoatchatstoatchatCWE-400stoatchat before 0.15.0 Uncapped SVG Rendering Denial of Service
CVE-2026-730628.720.4scribanscribanCWE-770Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication
CVE-2026-747838.720.4scribanscribanCWE-674Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service
CVE-2026-747878.720.4scribanscribanCWE-674Scriban before 7.0.0 Uncontrolled Recursion via object.to_json
CVE-2026-747888.720.4scribanscribanCWE-770Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right
CVE-2026-747948.720.4scribanscribanCWE-674Scriban before 6.6.0 Denial of Service via Infinite Recursion
CVE-2026-747857.119.6scribanscribanCWE-400Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption
CVE-2026-747867.119.6scribanscribanCWE-770Scriban before 7.0.0 Denial of Service via Unbounded Template Output
CVE-2026-196136.519.3UnknownECSCWE-200ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeat…
CVE-2026-199572.119.3graphlitgraphlit-mcp-serverCWE-918graphlit graphlit-mcp-server ssrf-test Endpoint tools.ts fetch server-side re…
CVE-2026-747919.219.2scribanscribanCWE-226Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
CVE-2026-159636.519.1expresstechQuiz and Survey Master (QSM) – Quiz Maker & Survey MakerCWE-89Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Inj…
CVE-2026-199265.518.6n/aEvergreenCWE-74Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection
CVE-2026-747848.718.2scribanscribanCWE-770Scriban before 7.2.0 Denial of Service via array.insert_at
CVE-2026-150666.418.1timwhitlockLoco TranslateCWE-79Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scrip…
CVE-2026-124774.417.7wpmonksGravity Booster – Styles & Layouts for Gravity FormsCWE-79Gravity Booster <= 5.26 - Authenticated (Editor+) Stored Cross-Site Scripting…
CVE-2024-583758.717.2opentofuopentofuCWE-497OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation
CVE-2026-107347.217.1infilityInfility GlobalCWE-79Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via …
CVE-2026-199332.116.9DefaultFuctionCustomer-Relationship-Management-In-C-ProjectCWE-119DefaultFuction Customer-Relationship-Management-In-C-Project Customer Search …
CVE-2026-199272.116.8n/aOpenBoxesCWE-918OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side…
CVE-2026-199282.116.8n/aOpenBoxesCWE-266OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges mana…
CVE-2026-197266.516.4UnknownVisualizerCWE-863Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure
CVE-2025-100054.315.7buildwpsPPWP – Password Protect PagesCWE-639Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference …
CVE-2026-199302.115.7n/aDolibarrCWE-74Dolibarr User Cloning card.php ldap injection
CVE-2026-730586.915.1stoatchatstoatchatCWE-918stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass
CVE-2026-199322.115.0DefaultFuctionNotice-System-ManagentCWE-74DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.ev…
CVE-2026-747967.013.9opentofuopentofuCWE-59OpenTofu before 1.11.7 Symlink Following Path Traversal
CVE-2026-199582.113.8iatsiukpptr-mcpCWE-74iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection
CVE-2026-167794.313.0extendthemesKubio AI Page BuilderCWE-862Kubio AI Page Builder <= 2.8.5 - Missing Authorization to Authenticated (Cont…
CVE-2026-730597.113.0stoatchatstoatchatCWE-863stoatchat before 0.15.0 Permission Bypass via message_fetch
CVE-2026-199642.012.5Jij-IncJij-MCP-ServerCWE-74Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection
CVE-2026-199565.312.1gomarble-aifacebook-ads-mcp-serverCWE-918gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-sid…
CVE-2026-197116.511.8UnknownPremium PackagesCWE-284Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbit…
CVE-2026-199252.011.5SourceCodesterStock Management SystemCWE-74SourceCodester Stock Management System Master.php delete_supplier sql injection
CVE-2026-24874.410.6weblizarAdmin Custom LoginCWE-79Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Sit…
CVE-2026-157266.410.3cryout-creationsSerious SliderCWE-79Serious Slider <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-199212.110.2code-projectsOnline Shopping SystemCWE-74code-projects Online Shopping System homeaction.php sql injection
CVE-2026-199232.110.2code-projectsOnline Shopping SystemCWE-74code-projects Online Shopping System checkout_process.php sql injection
CVE-2026-199342.110.2itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System vieworder.php sql injection
CVE-2026-199222.010.0code-projectsOnline Shopping SystemCWE-79code-projects Online Shopping System checkout.php cross site scripting
CVE-2026-157906.49.9emarket-designVideo Gallery – YouTube Gallery, Playlist & Video GridCWE-79Video Gallery <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting …
CVE-2026-156046.49.4toochekeToocheke CompanionCWE-79Toocheke Companion <= 2.10 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-167586.49.4aliakroSnippet ShortcodesCWE-79Snippet Shortcodes <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site …
CVE-2026-167756.49.4smubSmash Balloon Social Post Feed – Simple Social Feeds for WordPressCWE-79Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored…
CVE-2026-184026.49.4brainstormforceSureDash – Community, Courses & Member DashboardCWE-79SureDash <= 1.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-23576.48.6boldthemesBold Page BuilderCWE-79Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-197126.18.0UnknownMasteriyo LMSCWE-79Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description
CVE-2026-747972.37.2opentofuopentofuCWE-400OpenTofu before 1.11.4 Denial of Service via malicious zip
CVE-2026-137125.45.9UnknownDiviCWE-79Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL
CVE-2026-176086.55.3aresitWP Compress – Instant Performance & Speed OptimizationCWE-352WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Dele…
CVE-2026-745787.14.4LinuxLinuxcrypto: algif_skcipher - force synchronous processing on trees without ctx->s…
CVE-2026-153845.71.5UnknownManual Image CropCWE-287Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite v…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-16 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.