131 CVEs published September 5, 2026: 17 critical, 32 high, 45 medium, 3 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 34 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 106 in the results table.
Yesterday's Results
How to read these box scores · glossary
131 CVEs published. 25 box scores, 106 table rows — nothing truncated.
wpmudev Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN — Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0082 54.6 —
AFFECTED
Product Versions Fixed
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN unspecified —
TIMELINE
Aug 31 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
JoomUnited WP File Download — WP File Download <= 6.3.8 - Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H N N 6.5 .0068 49.7 —
AFFECTED
Product Versions Fixed
WP File Download unspecified —
TIMELINE
Jul 7 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
uscnanbu Welcart e-Commerce — Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R U H H H 8.8 .0057 45.0 —
AFFECTED
Product Versions Fixed
Welcart e-Commerce unspecified —
TIMELINE
Aug 14 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
pickplugins Post Grid — Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0044 36.8 —
AFFECTED
Product Versions Fixed
Post Grid 2.2.85 – —
TIMELINE
Nov 11 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
inspireui MStore API – Create Native Android & iOS Apps On The Cloud — MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0038 31.0 —
AFFECTED
Product Versions Fixed
MStore API – Create Native Android & iOS Apps On The Cloud unspecified —
TIMELINE
Jun 26 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
supsysticcom Contact Form by Supsystic — Contact Form by Supsystic <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via IP Address Header
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0033 25.6 —
AFFECTED
Product Versions Fixed
Contact Form by Supsystic unspecified —
TIMELINE
Aug 31 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, …
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N H L 8.2 .0032 24.0 —
AFFECTED
Product Versions Fixed
PCRE2 10.32 – —
TIMELINE
Sep 5 Reserved by CNA
Sep 5 Published (CNA: mitre)
outlawgt Custom Contact Forms — Custom Contact Forms <= 7.16 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parameters
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0030 22.1 —
AFFECTED
Product Versions Fixed
Custom Contact Forms unspecified —
TIMELINE
Aug 17 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0029 21.4 —
AFFECTED
Product Versions Fixed
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more unspecified —
TIMELINE
Aug 20 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
boldgrid W3 Total Cache — W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0029 20.9 —
AFFECTED
Product Versions Fixed
W3 Total Cache unspecified —
TIMELINE
Aug 24 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
brainstormforce SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz — SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0029 20.7 —
AFFECTED
Product Versions Fixed
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz unspecified —
TIMELINE
Jul 30 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
Elegant Themes Divi — Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L N N 5.0 .0027 19.6 —
AFFECTED
Product Versions Fixed
Divi unspecified —
TIMELINE
Mar 17 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk — Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0027 19.3 —
AFFECTED
Product Versions Fixed
Spam protection, Honeypot, Anti-Spam by CleanTalk unspecified —
TIMELINE
Aug 21 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
kstover Ninja Forms – The Contact Form Builder That Grows With You — Ninja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0025 15.9 —
AFFECTED
Product Versions Fixed
Ninja Forms – The Contact Form Builder That Grows With You unspecified —
TIMELINE
Aug 13 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0025 15.9 —
AFFECTED
Product Versions Fixed
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more unspecified —
TIMELINE
Aug 20 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
Tyche Softwares Abandoned Cart Pro for WooCommerce — Abandoned Cart Pro for WooCommerce <= 10.7.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0025 15.7 —
AFFECTED
Product Versions Fixed
Abandoned Cart Pro for WooCommerce unspecified —
TIMELINE
Aug 27 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
fooplugins Gallery : FooGallery — Gallery : FooGallery <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0024 15.2 —
AFFECTED
Product Versions Fixed
Gallery : FooGallery unspecified —
TIMELINE
Sep 3 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
jfarthing84 Theme My Login — Theme My Login <= 7.1.15 - Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via 'gimmeanotherblog' Signup Stage
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0024 15.0 —
AFFECTED
Product Versions Fixed
Theme My Login unspecified —
TIMELINE
Aug 31 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
netweblogic Events Manager – Calendar, Bookings, Tickets, and more! — Events Manager - Calendar, Bookings, Tickets, and more! <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H N N C L L N 5.4 .0022 12.0 —
AFFECTED
Product Versions Fixed
Events Manager – Calendar, Bookings, Tickets, and more! unspecified —
TIMELINE
Dec 19 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
unitecms Unlimited Elements For Elementor — Unlimited Elements For Elementor <= 2.0.17 - Reflected Cross-Site Scripting via 'formData[id]' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R C L L N 6.1 .0022 11.8 —
AFFECTED
Product Versions Fixed
Unlimited Elements For Elementor unspecified —
TIMELINE
Aug 17 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
dearhive DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer — Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.dvcss' Element Class Attribute
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0021 11.5 —
AFFECTED
Product Versions Fixed
DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer unspecified —
TIMELINE
May 14 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
dearhive DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer — Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.df-element' Element Inner HTML
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0021 10.6 —
AFFECTED
Product Versions Fixed
DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer unspecified —
TIMELINE
May 14 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
quadlayers Social Chat – Click To Chat App Button — Social Chat <= 8.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0020 10.0 —
AFFECTED
Product Versions Fixed
Social Chat – Click To Chat App Button unspecified —
TIMELINE
Jul 30 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
sc0ttkclark Pods – Custom Content Types and Fields — Pods <= 3.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0020 10.0 —
AFFECTED
Product Versions Fixed
Pods – Custom Content Types and Fields unspecified —
TIMELINE
Aug 19 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
Themovation QuickCal — QuickCal <= 1.0.20 - Unauthenticated Stored Cross-Site Scripting via Custom Field Parameters
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0019 8.7 —
AFFECTED
Product Versions Fixed
QuickCal unspecified —
TIMELINE
Jul 16 Reserved by CNA
Sep 5 Published (CNA: Wordfence)
Remainder (ranked, continued)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
| CVE-2026-16649 | 7.2 | 8.7 | Gravity Forms | Gravity Forms | CWE-79 | Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Pos… |
| CVE-2026-82304 | await | 8.7 | Unknown | Music Store | — | Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-d… |
| CVE-2026-19861 | await | 8.1 | Unknown | JetFormBuilder — Dynamic Blocks Form Builder | — | JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in No… |
| CVE-2026-81404 | await | 8.1 | Unknown | IPGP Visitors Origin | — | IPGP Visitors Origin < 1.6 - Reflected XSS |
| CVE-2025-15694 | await | 7.4 | Unknown | Joli Table Of Contents | — | Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS |
| CVE-2026-18843 | 6.1 | 6.4 | The Beaver Builder Team | Beaver Builder Plugin (Starter Version) | CWE-79 | Beaver Builder Plugin (Pro Version) <= 2.11.0.1 - Reflected Cross-Site Script… |
| CVE-2026-3853 | 6.4 | 6.0 | Elegant Themes | Divi | CWE-79 | Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scr… |
| CVE-2026-86144 | 5.6 | 5.6 | xmlsoft | libxml2 | CWE-669 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProce… |
| CVE-2025-15693 | await | 5.5 | Unknown | JCH Optimize | — | JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal |
| CVE-2026-81423 | await | 5.4 | Unknown | Accept Stripe Payments | — | Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler |
| CVE-2026-84934 | await | 5.3 | Unknown | JCH Optimize | — | JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override |
| CVE-2026-84898 | await | 5.2 | Unknown | Eventin | — | Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta |
| CVE-2026-19858 | await | 5.1 | Unknown | JetFormBuilder — Dynamic Blocks Form Builder | — | JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metada… |
| CVE-2026-78149 | await | 5.1 | Unknown | Smart Post | — | Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content… |
| CVE-2026-81348 | await | 5.1 | Unknown | My Private Site | — | My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via … |
| CVE-2026-84937 | await | 5.1 | Unknown | Video Player for YouTube | — | YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax |
| CVE-2026-82846 | await | 4.7 | Unknown | Masteriyo LMS | — | Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields |
| CVE-2026-83544 | await | 4.7 | Unknown | Greenshift | — | Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps… |
| CVE-2026-84021 | await | 4.7 | Unknown | Bold Page Builder | — | Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_he… |
| CVE-2026-84022 | await | 4.7 | Unknown | Bold Page Builder | — | Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode El… |
| CVE-2026-84221 | await | 4.7 | Unknown | Kirki | — | Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID |
| CVE-2026-84896 | await | 4.7 | Unknown | King Addons for Elementor | — | King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Gr… |
| CVE-2026-84899 | await | 4.7 | Unknown | VikWidgetsLoader | — | VikWidgetsLoader < 1.12.0 - Contributor+ Stored XSS via Gutenberg Block class… |
| CVE-2026-84930 | await | 4.7 | Unknown | CatFolders Document Gallery & PDF Library | — | CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block A… |
| CVE-2026-84931 | await | 4.7 | Unknown | Joli Table Of Contents | — | Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Th… |
| CVE-2026-84935 | await | 4.7 | Unknown | HT Menu | — | HT Menu < 1.2.7 - Subscriber+ Stored XSS via Menu Settings |
| CVE-2026-77826 | await | 4.2 | Unknown | RegistrationMagic | — | RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass v… |
| CVE-2026-78362 | await | 4.2 | Unknown | SEO Flow by LupsOnline | — | SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation v… |
| CVE-2026-81424 | await | 4.2 | Unknown | Accept Stripe Payments | — | Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR |
| CVE-2026-15247 | await | 3.8 | Unknown | Search Atlas SEO | — | Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Ove… |
| CVE-2026-78150 | await | 3.8 | Unknown | Smart Post | — | Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content… |
| CVE-2026-84745 | await | 3.6 | Unknown | The Events Calendar | — | The Events Calendar < 6.17.3.1 - Contributor+ Non-Public Event, Venue and … |
| CVE-2026-84926 | await | 3.6 | Unknown | EmbedPress | — | EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Go… |
| CVE-2026-86140 | 8.0 | 3.3 | xmlsoft | libxml2 | CWE-121 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-b… |
| CVE-2026-84936 | await | 3.4 | Unknown | EmbedPress | — | EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumpti… |
| CVE-2026-86142 | 6.9 | 3.0 | xmlsoft | libxml2 | CWE-122 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEva… |
| CVE-2026-83543 | await | 3.1 | Unknown | Greenshift | — | Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint |
| CVE-2026-84225 | await | 3.1 | Unknown | Kirki | — | Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification… |
| CVE-2026-84901 | await | 3.1 | Unknown | Eventin | — | Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manip… |
| CVE-2026-84927 | await | 3.1 | Unknown | EmbedPress | — | EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification |
| CVE-2026-86138 | 6.9 | 2.0 | xmlsoft | libxml2 | CWE-190 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow… |
| CVE-2026-86143 | 6.9 | 2.0 | xmlsoft | libxml2 | CWE-192 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback… |
| CVE-2026-86137 | 2.9 | 1.8 | xmlsoft | libxml2 | CWE-125 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, a… |
| CVE-2026-86141 | 2.9 | 1.8 | xmlsoft | libxml2 | CWE-252 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNe… |
| CVE-2026-86139 | 6.9 | 1.3 | xmlsoft | libxml2 | CWE-190 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. |
| CVE-2026-10196 | 9.8 | — | getwpfunnels | Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails | CWE-502 | Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form … |
| CVE-2026-86123 | 9.4 | — | sqlchat | sqlchat | CWE-918 | SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection End… |
| CVE-2026-86148 | 9.4 | — | Tenda | CP3 | CWE-77 | Tenda CP3 Kylin system.c SystemAsh os command injection |
| CVE-2026-86149 | 9.4 | — | Tenda | CP3 | CWE-77 | Tenda CP3 NetCheckPing.cpp os command injection |
| CVE-2026-86151 | 9.4 | — | Tenda | CP3 | CWE-78 | Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command inj… |
| CVE-2026-86121 | 9.3 | — | trycua | cua-computer-server | CWE-306 | Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control |
| CVE-2026-86124 | 9.3 | — | HKUDS | AutoAgent | CWE-306 | AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command S… |
| CVE-2026-86184 | 9.3 | — | laradashboard | laradashboard | CWE-306 | Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route |
| CVE-2026-86189 | 9.3 | — | WWBN | AVideo | CWE-73 | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php |
| CVE-2026-86190 | 9.3 | — | WWBN | AVideo | CWE-200 | WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter |
| CVE-2026-67276 | 9.2 | — | Mikrotik | RouterOS | CWE-347 | SSH user impersonation possible in Mikrotik RouterOS |
| CVE-2026-86060 | 9.2 | — | Mikrotik | RouterOS | CWE-88 | SSH session privilege manipulation via a crafted username in Mikrotik RouterOS |
| CVE-2026-86117 | 9.2 | — | coollabsio | coolify | CWE-287 | Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching |
| CVE-2026-86119 | 9.2 | — | webstudio-is | webstudio | CWE-918 | Webstudio through 0.296.0 SSRF via /cgi proxy routes |
| CVE-2025-9049 | 8.8 | — | scriptsbundle | Nokri – Job Board WordPress Theme | CWE-862 | Nokri – Job Board WordPress Theme <= 1.6.4 - Missing Authorization to Authent… |
| CVE-2026-67277 | 8.8 | — | Mikrotik | RouterOS | CWE-306 | Kernel memory disclosure and denial of service in MikroTik RouterOS btest ser… |
| CVE-2026-0799 | 8.7 | — | The Tcpdump Group | libpcap | CWE-125 | OOBR and OOBW in libpcap before 1.10.7 |
| CVE-2026-67281 | 8.7 | — | Mikrotik | RouterOS | CWE-22 | Unauthenticated file read in Mikrotik RouterOS |
| CVE-2026-86169 | 8.7 | — | axolotl-ai-cloud | axolotl | CWE-829 | Axolotl through 0.18.0 Remote Code Execution via Multipack Patching |
| CVE-2026-86173 | 8.7 | — | mindsdb | mindsdb | CWE-918 | MindsDB through 26.1.0 Unauthenticated SSRF via Web Crawler |
| CVE-2026-86177 | 8.7 | — | pterodactyl | panel | CWE-862 | Pterodactyl Panel before 1.14.1 Privilege Escalation via Schedule Tasks |
| CVE-2026-86193 | 8.7 | — | getgrav | grav-plugin-api | CWE-863 | Grav API Plugin Authentication Bypass via Group-Inherited Super |
| CVE-2026-86195 | 8.7 | — | getgrav | grav-plugin-api | CWE-269 | grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super… |
| CVE-2026-86196 | 8.7 | — | getgrav | grav-plugin-api | CWE-290 | Grav API Plugin before 1.0.20 Authentication Bypass via Host Header |
| CVE-2026-86185 | 8.6 | — | Bilibili | Bilibili Desktop | CWE-295 | Bilibili Desktop through 1.18.0 Remote Code Execution via TLS Verification By… |
| CVE-2026-86207 | 7.7 | — | N-able | N-central | CWE-305 | Authentication bypass leads to unauthorised access to N-central |
| CVE-2026-86187 | 7.4 | — | WWBN | AVideo | CWE-330 | WWBN AVideo Weak PRNG Password Generation via External Login |
| CVE-2026-86111 | 7.1 | — | bookwyrm-social | bookwyrm | CWE-639 | BookWyrm through 0.9.1 Insecure Direct Object Reference in EditStatus Exposes… |
| CVE-2026-86113 | 7.1 | — | bookwyrm-social | bookwyrm | CWE-639 | BookWyrm through 0.9.1 Insecure Direct Object Reference in edit-readthrough A… |
| CVE-2026-86114 | 7.1 | — | getarcaneapp | arcane | CWE-862 | Arcane before 2.0.0 Missing Administrator Authorization on the Compose Templa… |
| CVE-2026-86116 | 7.1 | — | metabase | metabase | CWE-862 | Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary M… |
| CVE-2026-86175 | 7.1 | — | netbox-community | netbox | CWE-522 | NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs |
| CVE-2026-86192 | 7.1 | — | siyuan-note | siyuan | CWE-639 | SiYuan before v3.8.2 Information Disclosure via Attribute-View |
| CVE-2026-67279 | 6.9 | — | Mikrotik | RouterOS | CWE-841 | SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS |
| CVE-2026-86188 | 6.9 | — | WWBN | AVideo | CWE-79 | AVideo YPTSocket Plugin Unauthenticated Cross-Site Scripting |
| CVE-2026-86194 | 6.9 | — | getgrav | grav-plugin-form | CWE-862 | Grav Form Plugin before 9.1.22 Cross-Page Form Execution |
| CVE-2026-86206 | 6.9 | — | N-able | N-central | CWE-791 | Access control filter bypass allows unauthorised access to APIs |
| CVE-2025-15647 | 6.8 | — | artem-ogre | CDT | CWE-125 | CDT before 1.4.5 Out-of-Bounds Read via opposedVertexInd |
| CVE-2026-67278 | 6.3 | — | Mikrotik | RouterOS | CWE-347 | TLS server impersonation possible in Mikrotik RouterOS |
| CVE-2026-86186 | 6.3 | — | WWBN | AVideo | CWE-307 | AVideo API Rate Limit Bypass via Bot User-Agent Header |
| CVE-2026-82752 | 5.9 | — | ash-project | ash | CWE-1284 | Ash string length constraints count graphemes, so a combining-mark string of … |
| CVE-2026-6244 | 5.5 | — | The Tcpdump Group | libpcap | CWE-369 | division by zero in libpcap before 1.10.7 |
| CVE-2026-6554 | 5.5 | — | The Tcpdump Group | libpcap | CWE-835 | infinte loop in libpcap before 1.10.7 |
| CVE-2026-31911 | 5.5 | — | The Tcpdump Group | libpcap | CWE-617 | abort() in libpcap before 1.10.7 on an invalid BPF opcode |
| CVE-2026-31912 | 5.5 | — | The Tcpdump Group | libpcap | CWE-125 | OOBR in libpcap before 1.10.7 |
| CVE-2026-12843 | 5.4 | — | StellarWP | LearnDash LMS | CWE-862 | LearnDash LMS 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment vi… |
| CVE-2026-86112 | 5.3 | — | bookwyrm-social | bookwyrm | CWE-639 | BookWyrm through 0.9.1 Missing Authorization on the Favorite and Unfavorite E… |
| CVE-2026-86115 | 5.3 | — | simstudioai | sim | CWE-441 | Sim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token… |
| CVE-2026-86118 | 5.3 | — | sentriz | gonic | CWE-862 | gonic before 0.22.0 Missing Administrator Check on the Subsonic startScan End… |
| CVE-2026-86120 | 5.3 | — | apitable | apitable | CWE-636 | APITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node… |
| CVE-2026-86122 | 5.3 | — | rowboatlabs | rowboat | CWE-918 | Rowboat through 0.9.1 Server-Side Request Forgery via Custom MCP Server |
| CVE-2026-86174 | 5.3 | — | makeplane | plane | CWE-639 | Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board |
| CVE-2026-86176 | 5.3 | — | netbox-community | netbox | CWE-639 | NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs |
| CVE-2026-86178 | 5.3 | — | pixelfed | pixelfed | CWE-862 | Pixelfed through 0.12.9 Unauthorized Story Access via API |
| CVE-2026-86191 | 5.3 | — | siyuan-note | siyuan | CWE-639 | SiYuan before v3.8.2 Private Attribute View Key Enumeration |
| CVE-2026-86197 | 5.1 | — | getgrav | grav | CWE-79 | Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox |
| CVE-2026-18238 | 5.0 | — | The Tcpdump Group | libpcap | CWE-126 | OOBR in rpcap client in libpcap before 1.10.7 |
| CVE-2025-15614 | 4.8 | — | Genivia | ugrep | CWE-125 | ugrep before 7.6.0 Heap Buffer Over-read via .Z decompression |
| CVE-2026-15550 | 4.3 | — | Saturday Drive | Ninja Forms - Save Progress | CWE-862 | Ninja Forms - Save Progress <= 3.0.30 - Missing Authorization to Authenticate… |
| CVE-2026-18313 | 4.3 | — | The Tcpdump Group | libpcap | CWE-401 | rpcapd memory leak in libpcap before 1.10.7 |
| CVE-2026-86150 | 2.0 | — | Tenda | CP3 | CWE-259 | Tenda CP3 hostapd hard-coded credentials |
Methodology
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-05 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.