boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, September 12, 2026 · all times UTC← 2026-09-11 · archive

Security Box Score — September 12, 2026

94 CVEs published, led by WWBN (17).

94 CVEs published September 12, 2026: 13 critical, 26 high, 51 medium, 4 low; 1 in the KEV catalog at press time; 3 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 69 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published558240467——
KEV catalog size1709

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2586 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux6314714491222870611230.17.8.0017+219 ▲
microsoft9772876189197869316289301.07.8.0044+538 ▲
google361252731897311101207980.37.5.0025+312 ▲
red hat736984328932937200.06.7.0028-52 ▼
apple0316598516578882.56.5.0029-2 ▼
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.0021-11 ▼
suse1240721111000.07.6.0037+7 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco12962446260571414.67.5.0041-19 ▼
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022+9 ▲
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
ivanti102410122025520.88.8.0146+7 ▲
f572461431414.28.7.0047+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache32541117228181133320.47.5.0049-62 ▼
mozilla352228079630900.08.1.0029+34 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab278517479533.85.3.0029-11 ▼
github32011090000.07.3.0044-1 ▼
docker090630000.07.2.0016-1 ▼
wordpress0513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
adobe17077657343366102040.57.5.0023+110 ▲
ibm1217401613412299610.17.5.0030+21 ▲
progress3641539100611.68.1.0035-13 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0099+3 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link8531619108300.08.5.0157-7 ▼
siemens145163393000.07.3.0018-3 ▼
rockwell automation184353260000.08.6.0029+18 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1343052514012218210.37.2.0020+122 ▲
sourcecodester261950011481000.05.5.0028+14 ▲
spring017012608315000.06.5.00240
nvidia3216620117290000.07.8.0029+16 ▲
mongodb50148487534100.07.1.0026+18 ▲
itsourcecode241400036104000.02.1.0026+16 ▲
wwbn891292143650000.06.9.0026+87 ▲
elastic42129127983100.06.5.0028+42 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-64849.164196.89.3
CVE-2026-83549.085194.77.8
CVE-2026-19681.078094.39.4
CVE-2026-82329.076794.29.8
CVE-2026-19478.058192.79.1
CVE-2026-19586.057092.69.3
CVE-2026-19490.056092.59.3
CVE-2026-79756.051591.98.7
CVE-2026-83548.046791.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-1918810.0.0193
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8570610.0.0115KEV
Most disclosures (vendor)
VendorCVEs
linux1860
microsoft1015
oracle890
google714
ibm337
adobe211
dell194
red hat170
splunk110
apache105
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco14
apple8
google8
fortinet7
ivanti5
adobe4
berriai4
jfrog4
oracle4
Most-affected ecosystems
EcosystemAdvisories
Maven47
Packagist38
npm19
PyPI15
RubyGems2
Go1
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-64849mlflow1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171760
CVE-2021-27102n/a2021-11-171760
CVE-2021-27101n/a2021-11-171760
CVE-2021-27103n/a2021-11-171760
CVE-2021-21017Adobe2021-11-171760
CVE-2021-28550Adobe2021-11-171760
CVE-2021-42013Apache Software Foundation2021-11-171760
CVE-2021-41773Apache Software Foundation2021-11-171760
CVE-2021-30858Apple2021-11-171760
CVE-2021-30860Apple2021-11-171760

Transactions

DUE DATE PASSED — CVE-2026-75650 (Adobe Commerce). CISA remediation deadline was September 11, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-86218 (N-able N-central). CISA remediation deadline was September 11, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

94 CVEs published. 25 box scores, 69 table rows — nothing truncated.

GitLab GitLab — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  N   10.0   .0115   65.0   YES
AFFECTED
  Product  Versions  Fixed
  GitLab   18.7 –    —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 11  Added to CISA KEV, due Sep 14
  Sep 12  Published (CNA: GitLab)
CWE-22 · CNA: GitLab · CVSS v3.1 · 3 references · NVD status: Received · KEV due September 14, 2026
stellarwp The Events Calendar — The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0078   53.8     —
AFFECTED
  Product              Versions     Fixed
  The Events Calendar  unspecified  —
TIMELINE
  Aug 21  Reserved by CNA
  Sep 12  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
stellarwp The Events Calendar — The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   53.3     —
AFFECTED
  Product              Versions     Fixed
  The Events Calendar  unspecified  —
TIMELINE
  Aug 23  Reserved by CNA
  Sep 12  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
ninjew GEO my WP — GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0076   53.3     —
AFFECTED
  Product    Versions     Fixed
  GEO my WP  unspecified  —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 12  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Received
GitLab GitLab — Deserialization of Untrusted Data in GitLab
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0061   47.4     —
AFFECTED
  Product  Versions  Fixed
  GitLab   18.3 –    —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 12  Published (CNA: GitLab)
CWE-502 · CNA: GitLab · CVSS v3.1 · 2 references · NVD status: Received
themeum Tutor LMS – eLearning and online course solution — Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0059   46.2     —
AFFECTED
  Product                                           Versions     Fixed
  Tutor LMS – eLearning and online course solution  unspecified  —
TIMELINE
  Aug 23  Reserved by CNA
  Sep 12  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
rtcamp rtMedia for WordPress, BuddyPress and bbPress — rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 - Unauthenticated SQL Injection via 'compare' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0034   27.5     —
AFFECTED
  Product                                        Versions     Fixed
  rtMedia for WordPress, BuddyPress and bbPress  unspecified  —
TIMELINE
  Jul 21  Reserved by CNA
  Sep 12  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Received
wproyal Royal Addons for Elementor – Addons and Templates Kit for Elementor — Royal Addons for Elementor <= 1.7.1066 - Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0032   25.2     —
AFFECTED
  Product                                                              Versions     Fixed
  Royal Addons for Elementor – Addons and Templates Kit for Elementor  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Sep 12  Published (CNA: Wordfence)
CWE-200 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Received
themeisle MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO — MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0029   21.2     —
AFFECTED
  Product                                                               Versions     Fixed
  MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO  unspecified  —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 12  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
egoi Smart Marketing SMS and Newsletters Forms — Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Authenticated (Subscriber+) SQL Injection via Parameter Name
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0027   19.0     —
AFFECTED
  Product                                    Versions     Fixed
  Smart Marketing SMS and Newsletters Forms  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Sep 12  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
designthemes DT LMS – elearning, WordPress LMS Plugin — DT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX Actions
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0024   15.8     —
AFFECTED
  Product                                    Versions     Fixed
  DT LMS – elearning,  WordPress LMS Plugin  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Sep 12  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
cole aiosmtplib — aiosmtplib before 5.1.3 ESMTP Parameter Injection via unvalidated addresses
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   L   N    6.3   .0023   13.8     —
AFFECTED
  Product     Versions     Fixed
  aiosmtplib  unspecified  5.1.3
TIMELINE
  Sep 11  Reserved by CNA
  Sep 12  Published (CNA: VulnCheck)
CWE-88 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
Microchip AN1044 — Side-channel attack of AN1044/AN953/SW300052 cryptographic algorithms
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   P   H   P   N   N   H   N   N    5.6   .0020   10.1     —
AFFECTED
  Product   Versions     Fixed
  AN1044    unspecified  —
  AN953     unspecified  —
  SW300052  unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 12  Published (CNA: Microchip)
CWE-1300 · CNA: Microchip · CVSS v4.0 · 4 references · NVD status: Received
Unknown DS Ad Rotator — DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0020    9.6     —
AFFECTED
  Product        Versions     Fixed
  DS Ad Rotator  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-434 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
jowilf starlette-admin — starlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    5.3   .0019    9.1     —
AFFECTED
  Product          Versions  Fixed
  starlette-admin  0.16.1 –  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 12  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
Unknown SAMO Forms — SAMO Forms <= 1.0.0 - Unauthenticated SQLi
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0019    8.8     —
AFFECTED
  Product     Versions     Fixed
  SAMO Forms  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-89 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Frontegg SAML SSO — Frontegg SAML SSO <= 1.0.1 - Unauthenticated Account Takeover via Unverified SAMLResponse
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0019    8.4     —
AFFECTED
  Product            Versions     Fixed
  Frontegg SAML SSO  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-287 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Album Cover Finder — Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0018    7.4     —
AFFECTED
  Product             Versions     Fixed
  Album Cover Finder  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-89 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Zonify — Zonify < 1.0.5 - Unauthenticated Account Login Token Disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0018    7.2     —
AFFECTED
  Product  Versions     Fixed
  Zonify   unspecified  —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-200 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown BE REST Endpoints — BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0017    6.8     —
AFFECTED
  Product            Versions     Fixed
  BE REST Endpoints  unspecified  —
TIMELINE
  Aug 27  Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-79 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Webkul QloApps — QloApps through 1.7.0 Reflected XSS via List Filter Parameters
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   L   L   N    5.1   .0017    6.7     —
AFFECTED
  Product  Versions     Fixed
  QloApps  unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 12  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
Unknown Masteriyo LMS — Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0017    6.2     —
AFFECTED
  Product        Versions     Fixed
  Masteriyo LMS  unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-502 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown WP images upload on piclect — WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0016    5.7     —
AFFECTED
  Product                      Versions     Fixed
  WP images upload on piclect  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-434 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown wpstorecart — IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0016    5.2     —
AFFECTED
  Product      Versions     Fixed
  wpstorecart  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-502 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Yogeta WP Cloud — Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0016    5.1     —
AFFECTED
  Product          Versions     Fixed
  Yogeta WP Cloud  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Sep 12  Published (CNA: WPScan)
CWE-552 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-867906.84.7UnknownWP Highlight BoxCWE-79WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode
CVE-2026-878888.04.7UnknownYayPricingCWE-79YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route
CVE-2026-828476.84.7UnknownMasteriyo LMSCWE-79Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights
CVE-2026-835326.84.7UnknownCustom Menu Wizard WidgetCWE-79Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes
CVE-2026-770059.64.4UnknownCODE MONKEYS PROPOSALSCWE-73Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Pat…
CVE-2026-781525.34.4UnknownSureRank SEOCWE-200SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person …
CVE-2026-776895.34.2UnknownBooking for Appointments and Events CalendarCWE-284Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass
CVE-2026-878925.34.1UnknownRox Appointment BookingCWE-284Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Paym…
CVE-2026-879165.34.1UnknownWPBotCWE-200WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure
CVE-2026-810907.23.9UnknownGpx2GraphicsCWE-352Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF
CVE-2026-777057.23.8UnknownBooking for Appointments and Events CalendarCWE-639Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover
CVE-2026-777527.23.8UnknownTemporary Login Without PasswordCWE-269Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Netwo…
CVE-2026-777535.53.8UnknownTemporary Login Without PasswordCWE-284Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Rev…
CVE-2026-856819.83.4UnknownWP ComponentCWE-269WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Bl…
CVE-2026-878916.53.4UnknownRox Appointment BookingCWE-284Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modificati…
CVE-2026-878945.33.4UnknownRox Appointment BookingCWE-639Rox Appointment Booking 1.0.9 - 1.2.2 - Unauthenticated Customer PII Disclosu…
CVE-2026-879185.33.4UnknownWPBotCWE-284WPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX Actions
CVE-2026-877598.83.1UnknownAdd User AutocompleteCWE-269Add User Autocomplete < 1.2 - Subscriber+ Privilege Escalation
CVE-2026-879194.93.1UnknownProduct XML Feed Manager for WooCommerceCWE-862Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Pro…
CVE-2026-877974.33.1UnknownSprout InvoicesCWE-862Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Over…
CVE-2026-828512.73.1UnknownMasteriyo LMSCWE-639Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR
CVE-2026-840252.23.1UnknownBEARCWE-639BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 …
CVE-2026-770069.61.8UnknownWebTotem BackupsCWE-73WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Trav…
CVE-2026-814297.11.2UnknownExport & Import WPBakery Page BuilderCWE-79Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF
CVE-2026-840236.50.8UnknownBEARCWE-352BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 …
CVE-2026-840244.30.8UnknownBEARCWE-352BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 …
CVE-2026-905589.3—irontecsngrepCWE-121sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers
CVE-2026-906479.1—KalkitechASE2000 V2 Communication Test SetCWE-295ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows …
CVE-2026-154518.8—MemberPressMemberPress Corporate AccountsCWE-269MemberPress Corporate Accounts <= 1.5.39 - Authenticated (Subscriber+) Privil…
CVE-2026-905378.8—WWBNAVideoCWE-862WWBN AVideo Scheduler sendEmail Missing Authorization via Token
CVE-2026-905608.8—lubenzstd-jniCWE-125zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictDecompress
CVE-2026-905598.7—xerialsnappy-javaCWE-787snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress
CVE-2026-905538.5—vllm-projectvLLMCWE-94vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor
CVE-2026-905568.5—freecivfreecivCWE-122Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load
CVE-2026-906518.1—SocketSocket FirewallCWE-295Socket Firewall (socketdev/socket-registry-firewall) in registry mode before …
CVE-2026-904747.6—samanhappymcphubCWE-287MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass
CVE-2026-906167.4—FlatpakFlatpakCWE-61In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read…
CVE-2026-905557.1—vllm-projectvLLMCWE-409vLLM before 0.28.0 Denial of Service via Audio Header
CVE-2026-906487.1—WebAssemblywabtCWE-252wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situa…
CVE-2026-904726.9—msgpackmsgpack-javaCWE-674msgpack-java through 0.9.12 Stack Overflow via Nested Arrays
CVE-2026-904736.9—msgpackmsgpack-javaCWE-190msgpack-java through 0.9.12 Integer Overflow via MAP32
CVE-2026-905366.9—WWBNAVideoCWE-200WWBN AVideo Missing Authorization via adsInfo API Endpoint
CVE-2026-905386.9—WWBNAVideoCWE-200WWBN AVideo Missing Authorization via playlistsFromUser.json.php
CVE-2026-905396.9—WWBNAVideoCWE-200WWBN AVideo Missing Authentication via menuItems.json.php
CVE-2026-905416.9—WWBNAVideoCWE-200WWBN AVideo Unauthenticated Information Disclosure via menus.json.php
CVE-2026-905436.9—WWBNAVideoCWE-306WWBN AVideo Missing Authentication via socketMessageLiveOwner.json.php
CVE-2026-905476.9—WWBNAVideoCWE-862WWBN AVideo Missing Authorization via getBookmarks.json.php
CVE-2026-905486.9—WWBNAVideoCWE-200WWBN AVideo Missing Authorization in ImageGallery list.json.php
CVE-2026-905496.9—WWBNAVideoCWE-200WWBN AVideo Missing Authorization via videosAndroid.json.php Endpoint
CVE-2026-905506.9—WWBNAVideoCWE-200WWBN AVideo Missing Authorization via mediaSession.json.php
CVE-2026-905516.9—WWBNAVideoCWE-862WWBN AVideo Missing Authorization via video_from_program API
CVE-2026-905546.9—vllm-projectvLLMCWE-400vLLM before 0.28.0 Denial of Service via audio extraction
CVE-2026-905576.9—freecivfreecivCWE-125Freeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via Savegame
CVE-2026-101486.4—melogranoBooking for Appointments and Events Calendar – AmeliaCWE-79Booking for Appointments and Events Calendar – Amelia <= 2.4.9 - Authenticate…
CVE-2026-905356.3—FlowiseAIFlowiseCWE-862Flowise before 3.1.4 Denial of Service via text-to-speech/abort
CVE-2026-905346.1—FlowiseAIFlowiseCWE-639Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method
CVE-2026-905336.0—FlowiseAIFlowiseCWE-862Flowise before 3.1.4 Broken Access Control via organizationuser
CVE-2026-904855.4—IOBitUninstallerCWE-404IOBit Uninstaller IOCTL Dispatch IURegistryFilter.sys sub_11838 null pointer …
CVE-2026-904865.3—openstatusHQopenstatusCWE-918openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request …
CVE-2026-904885.3—Xuxuelixxl-jobCWE-94Xuxueli xxl-job GlueFactory.java GroovyClassLoader.parseClass code injection
CVE-2026-905405.3—WWBNAVideoCWE-862WWBN AVideo Missing Authorization via playListAddVideo.json.php
CVE-2026-905425.3—WWBNAVideoCWE-639WWBN AVideo Missing Authorization via remindMe.json.php
CVE-2026-905445.3—WWBNAVideoCWE-862WWBN AVideo Missing Authorization via videoAddViewCount.json.php
CVE-2026-905455.3—WWBNAVideoCWE-862WWBN AVideo Missing Authorization via commentAddNew.json.php
CVE-2026-905465.3—WWBNAVideoCWE-862WWBN AVideo Missing Authorization via like.json.php
CVE-2026-905525.3—WWBNAVideoCWE-639WWBN AVideo Missing Authorization via Playlists_schedules list.json.php
CVE-2026-904895.1—Xuxuelixxl-jobCWE-79Xuxueli xxl-job insert cross site scripting
CVE-2026-793003.5—SEPsesamCWE-180SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authe…
CVE-2026-904872.1—Xuxuelixxl-jobCWE-266Xuxueli xxl-job JobGroupController.java privileges management

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-12 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.