AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0188 78.5 —
AFFECTED Product Versions Fixed A3002MU Hh-B20211125.1046 – —
TIMELINE Sep 18 Reserved by CNA Sep 19 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
103 CVEs published, led by Exim (4).
103 CVEs published September 19, 2026: 7 critical, 23 high, 62 medium, 10 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 78 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 10438 | 45380 | — | — |
| KEV catalog size | 1716 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2836 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1507 | 5597 | 526 | 2513 | 712 | 1 | 15 | 6 | 0.1 | 7.8 | .0017 | +245 ▲ |
| microsoft | 1000 | 2899 | 204 | 1984 | 695 | 16 | 289 | 30 | 1.0 | 7.8 | .0044 | +554 ▲ |
| 516 | 2682 | 331 | 1048 | 1182 | 121 | 80 | 9 | 0.3 | 7.5 | .0025 | +452 ▲ | |
| red hat | 156 | 782 | 44 | 324 | 374 | 40 | 2 | 0 | 0.0 | 6.6 | .0028 | -16 ▼ |
| apple | 246 | 563 | 67 | 165 | 317 | 14 | 88 | 8 | 1.4 | 6.5 | .0020 | +212 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | -23 ▼ |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0021 | -11 ▼ |
| suse | 13 | 41 | 7 | 21 | 12 | 1 | 0 | 0 | 0.0 | 7.5 | .0036 | +8 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 97 | 181 | 53 | 72 | 55 | 1 | 59 | 16 | 8.8 | 7.7 | .0039 | +51 ▲ |
| ubiquiti | 0 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | 0 |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 10 | 40 | 10 | 10 | 17 | 3 | 29 | 7 | 17.5 | 7.0 | .0038 | +3 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0025 | -7 ▼ |
| f5 | 8 | 25 | 6 | 14 | 4 | 1 | 4 | 1 | 4.0 | 8.7 | .0045 | +8 ▲ |
| ivanti | 10 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0147 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -5 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 93 | 605 | 140 | 253 | 195 | 15 | 33 | 2 | 0.3 | 7.5 | .0049 | -8 ▼ |
| mozilla | 113 | 300 | 81 | 118 | 67 | 0 | 9 | 0 | 0.0 | 8.8 | .0026 | +54 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0024 | +26 ▲ |
| gitlab | 17 | 93 | 5 | 23 | 55 | 10 | 5 | 3 | 3.2 | 5.3 | .0032 | +2 ▲ |
| github | 3 | 20 | 1 | 10 | 9 | 0 | 0 | 0 | 0.0 | 7.3 | .0044 | -2 ▼ |
| docker | 3 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0016 | +1 ▲ |
| wordpress | 0 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | -2 ▼ |
| go | 4 | 4 | 0 | 2 | 1 | 1 | 0 | 0 | 0.0 | 5.9 | .0029 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 634 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0034 | -255 ▼ |
| ibm | 297 | 916 | 183 | 415 | 305 | 13 | 6 | 1 | 0.1 | 7.5 | .0030 | -2 ▼ |
| adobe | 171 | 777 | 57 | 344 | 366 | 10 | 20 | 4 | 0.5 | 7.5 | .0023 | +111 ▲ |
| progress | 3 | 64 | 15 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0035 | -16 ▼ |
| solarwinds | 1 | 24 | 17 | 4 | 3 | 0 | 10 | 4 | 16.7 | 9.1 | .0058 | +1 ▲ |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | -10 ▼ |
| zohocorp | 7 | 17 | 3 | 8 | 6 | 0 | 0 | 0 | 0.0 | 7.7 | .0106 | +3 ▲ |
| atlassian | 3 | 9 | 1 | 8 | 0 | 0 | 13 | 0 | 0.0 | 7.6 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 21 | 66 | 19 | 24 | 11 | 12 | 3 | 0 | 0.0 | 8.5 | .0154 | +5 ▲ |
| siemens | 15 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0018 | -4 ▼ |
| synology | 19 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0027 | +18 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +17 ▲ |
| advantech | 17 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0068 | +17 ▲ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0040 | +9 ▲ |
| hikvision | 3 | 9 | 0 | 5 | 4 | 0 | 0 | 0 | 0.0 | 7.1 | .0036 | +3 ▲ |
| abb | 1 | 8 | 1 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 177 | 348 | 26 | 166 | 133 | 23 | 2 | 1 | 0.3 | 7.2 | .0021 | +121 ▲ |
| sourcecodester | 48 | 217 | 0 | 0 | 128 | 89 | 0 | 0 | 0.0 | 5.5 | .0028 | +18 ▲ |
| spring | 0 | 170 | 13 | 60 | 82 | 15 | 0 | 0 | 0.0 | 6.5 | .0024 | 0 |
| nvidia | 32 | 166 | 20 | 117 | 29 | 0 | 0 | 0 | 0.0 | 7.8 | .0029 | +8 ▲ |
| mongodb | 64 | 162 | 6 | 94 | 58 | 4 | 1 | 0 | 0.0 | 7.1 | .0026 | +32 ▲ |
| itsourcecode | 34 | 150 | 0 | 0 | 37 | 113 | 0 | 0 | 0.0 | 2.1 | .0026 | +17 ▲ |
| wwbn | 106 | 146 | 23 | 49 | 74 | 0 | 0 | 0 | 0.0 | 6.9 | .0024 | +104 ▲ |
| hewlett packard enterprise (hpe) | 129 | 138 | 15 | 71 | 46 | 6 | 1 | 1 | 0.7 | 7.2 | .0029 | +126 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-60004 | .8678 | 99.7 | 9.8 |
| CVE-2026-85706 | .1456 | 96.5 | 10.0 |
| CVE-2026-83549 | .0851 | 94.8 | 7.8 |
| CVE-2026-82329 | .0767 | 94.3 | 9.8 |
| CVE-2026-86218 | .0749 | 94.2 | 10.0 |
| CVE-2026-79756 | .0515 | 92.0 | 8.7 |
| CVE-2026-83548 | .0467 | 91.3 | 10.0 |
| CVE-2026-77806 | .0420 | 90.5 | 9.8 |
| CVE-2026-76698 | .0411 | 90.3 | 6.5 |
| CVE-2026-47864 | .0408 | 90.2 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .1456 | KEV |
| CVE-2026-86218 | 10.0 | .0749 | KEV |
| CVE-2026-83548 | 10.0 | .0467 | KEV |
| CVE-2026-75650 | 10.0 | .0215 | KEV |
| CVE-2026-86152 | 10.0 | .0186 | |
| CVE-2026-76195 | 10.0 | .0159 | |
| CVE-2026-76197 | 10.0 | .0159 | |
| CVE-2026-82222 | 10.0 | .0155 | |
| CVE-2026-82004 | 10.0 | .0144 | |
| CVE-2026-82456 | 10.0 | .0139 |
| Vendor | CVEs |
|---|---|
| linux | 1889 |
| microsoft | 1010 |
| 847 | |
| oracle | 635 |
| ibm | 313 |
| apple | 252 |
| adobe | 212 |
| red hat | 197 |
| dell | 193 |
| apache | 151 |
| Vendor | KEV |
|---|---|
| microsoft | 30 |
| cisco | 16 |
| 9 | |
| apple | 8 |
| fortinet | 7 |
| linux | 6 |
| ivanti | 5 |
| adobe | 4 |
| berriai | 4 |
| jfrog | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 93 |
| Packagist | 41 |
| npm | 19 |
| PyPI | 15 |
| crates.io | 3 |
| Go | 2 |
| RubyGems | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-87491 | 0 | |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE-2026-81578 | PaperCut | 3 |
| CVE-2026-82078 | PaperCut | 3 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1767 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1767 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1767 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1767 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1767 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1767 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1767 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1767 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1767 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1767 |
EXPLOIT PUBLISHED — GitLab: 3 CVEs (CVE-2026-12910, CVE-2026-13210, CVE-2026-82837). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-61516 (Netis Systems NX10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82536 (RooCodeInc Roo-Code). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86749 (grokability snipe-it). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90509 (dromara orion-visor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90515 (SourceCodester School Registration and Fee System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90520 (jaychouchannel Tourism-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90525 (itsourcecode Sales and Inventory System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90940 (201206030 novel-plus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91836 (OpenClaw ClawScan). Public exploit reference added.
DUE DATE PASSED — CVE-2026-85046 (Google Chrome). CISA remediation deadline was September 18, 2026; still in catalog.
RESCORED — CVE-2025-39964 (Linux). CVSS 3.3 → 5.5 (NVD).
How to read these box scores · glossary
103 CVEs published. 25 box scores, 78 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0188 78.5 —
AFFECTED Product Versions Fixed A3002MU Hh-B20211125.1046 – —
TIMELINE Sep 18 Reserved by CNA Sep 19 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0070 51.6 —
AFFECTED Product Versions Fixed Gravity Forms unspecified —
TIMELINE Sep 1 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0070 51.6 —
AFFECTED Product Versions Fixed The Welcomizer unspecified —
TIMELINE Mar 17 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0064 49.4 —
AFFECTED Product Versions Fixed A3002MU Hh-B20211125.1046 – —
TIMELINE Sep 18 Reserved by CNA Sep 19 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0053 43.5 —
AFFECTED Product Versions Fixed WP Photo Album Plus unspecified —
TIMELINE Sep 9 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0040 34.2 —
AFFECTED Product Versions Fixed Forminator Forms – Contact Form, Payment Form & Custom Form Builder unspecified —
TIMELINE Sep 15 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0040 33.9 —
AFFECTED Product Versions Fixed Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots unspecified —
TIMELINE Sep 11 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0039 32.6 —
AFFECTED Product Versions Fixed Quill Forms | Conversational Multi Step Forms, Surveys & quizzes unspecified —
TIMELINE Jul 13 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0038 31.8 —
AFFECTED Product Versions Fixed WP Recipe Maker unspecified —
TIMELINE Sep 11 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0036 29.9 —
AFFECTED Product Versions Fixed Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0036 29.4 —
AFFECTED Product Versions Fixed WordLift – AI powered SEO – Schema unspecified —
TIMELINE May 22 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0034 28.1 —
AFFECTED Product Versions Fixed Custom Field Template unspecified —
TIMELINE May 28 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0034 28.0 —
AFFECTED Product Versions Fixed Datalogics Ecommerce Delivery – Datalogics unspecified —
TIMELINE May 26 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L L N 6.1 .0033 26.6 —
AFFECTED Product Versions Fixed WP Customer Reviews unspecified —
TIMELINE Jun 8 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0033 26.5 —
AFFECTED Product Versions Fixed Bread unspecified —
TIMELINE Mar 24 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0032 25.8 —
AFFECTED Product Versions Fixed Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots unspecified —
TIMELINE Sep 10 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0030 23.1 —
AFFECTED Product Versions Fixed WP Optimizer – PageSpeed, Cache, Minify & Core Web Vitals unspecified —
TIMELINE Apr 14 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0029 22.4 —
AFFECTED Product Versions Fixed YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers unspecified —
TIMELINE Jan 20 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0028 20.9 —
AFFECTED Product Versions Fixed Create unspecified —
TIMELINE Jun 24 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0028 20.8 —
AFFECTED Product Versions Fixed Tutor LMS – eLearning and online course solution unspecified —
TIMELINE Sep 10 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L L 6.5 .0028 20.3 —
AFFECTED Product Versions Fixed Wow Elements Addons for Elementor unspecified —
TIMELINE Jan 29 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0027 19.4 —
AFFECTED Product Versions Fixed Easy Appointments unspecified —
TIMELINE May 21 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0027 19.3 —
AFFECTED Product Versions Fixed Tutor LMS – eLearning and online course solution unspecified —
TIMELINE Sep 11 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0027 19.1 —
AFFECTED Product Versions Fixed GoPay for WooCommerce unspecified —
TIMELINE Aug 18 Reserved by CNA Sep 19 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0026 18.1 —
AFFECTED Product Versions Fixed TikTok unspecified —
TIMELINE Jul 29 Reserved by CNA Sep 19 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-92807 | 8.8 | 17.2 | pdfcrowd | Save as PDF Plugin by PDFCrowd | CWE-94 | Save as PDF Plugin by PDFCrowd <= 4.6.1 - Authenticated (Contributor+) Arbitr… |
| CVE-2026-9615 | 4.3 | 16.7 | flextheme | Flex Import | CWE-862 | Flex Import <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Arb… |
| CVE-2026-13200 | 6.5 | 16.5 | mischiefmarmot | Create | CWE-89 | Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order' Parameter |
| CVE-2026-77820 | 6.4 | 15.7 | stellarwp | WPComplete | CWE-79 | WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Script… |
| CVE-2026-13354 | 7.2 | 15.6 | gabelivan | Asset CleanUp: Page Speed Booster | CWE-79 | Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Unauthenticated Stored Cross-S… |
| CVE-2026-5400 | 6.4 | 15.6 | davidanderson | Redux Framework | CWE-79 | Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Cross-Site Scripting … |
| CVE-2026-9766 | 4.3 | 14.4 | empik | Empik for Woocommerce | CWE-862 | Empik for Woocommerce <= 1.5.1 - Missing Authorization to Authenticated (Subs… |
| CVE-2026-15946 | 4.3 | 14.4 | shahrukhlinkgraph | Search Atlas SEO – OTTO AI SEO Automation for WordPress | CWE-862 | Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscrib… |
| CVE-2026-76579 | 4.7 | 14.1 | litespeedtech | LiteSpeed Cache | CWE-79 | LiteSpeed Cache <= 7.9 - Reflected Cross-Site Scripting via ESI 'esi' Parameter |
| CVE-2026-1984 | 5.3 | 13.8 | vowelweb | Ibtana – Ecommerce Product Addons | CWE-862 | Ibtana – Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authe… |
| CVE-2026-9832 | 5.3 | 13.6 | themehigh | Payment Gateway of Stripe for WooCommerce | CWE-347 | Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper… |
| CVE-2026-7527 | 4.7 | 13.3 | johndarrel | Hide My WP Ghost – Security & Firewall | CWE-601 | WP Ghost (Hide My WP Ghost) <= 7.0.02 - Unauthenticated Open Redirect via 're… |
| CVE-2026-15760 | 6.5 | 13.0 | Divi Essential | Divi Essentials | CWE-862 | Divi Essentials <= 5.8.1 - Missing Authorization to Authenticated (Subscriber… |
| CVE-2026-5410 | 6.4 | 12.3 | davidanderson | Redux Framework | CWE-79 | Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Stored Cross-Site Scr… |
| CVE-2026-87917 | 6.1 | 12.2 | dvankooten | MC4WP: Mailchimp for WordPress | CWE-79 | MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via… |
| CVE-2026-89081 | 6.1 | 12.2 | themeum | Tutor LMS – eLearning and online course solution | CWE-79 | Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'searc… |
| CVE-2026-92967 | 6.1 | 12.2 | wppochipp | Pochipp | CWE-79 | Pochipp <= 1.20.2 - Reflected Cross-Site Scripting via 'keyword' Parameter |
| CVE-2026-9858 | 4.3 | 12.2 | wpexpertshub | Partial Shipment for WooCommerce | CWE-862 | Partial Shipment for Woocommerce <= 3.4 - Missing Authorization to Authentica… |
| CVE-2026-11899 | 4.3 | 12.1 | edgarrojas | PDF Builder for WooCommerce. Create invoices,packing slips and more | CWE-862 | PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.11… |
| CVE-2026-15947 | 4.3 | 12.0 | shahrukhlinkgraph | Search Atlas SEO – OTTO AI SEO Automation for WordPress | CWE-862 | Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscrib… |
| CVE-2026-12042 | 4.4 | 11.2 | f1logic | WP2Social Auto Publish | CWE-79 | WP2Social Auto Publish <= 2.4.12 - Authenticated (Administrator+) Stored Cros… |
| CVE-2026-2422 | 6.4 | 11.2 | ghozylab | WP Composer – The Easiest Page Builder | CWE-79 | WP Composer <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripti… |
| CVE-2026-1256 | 6.4 | 10.7 | ysinnovations | YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers | CWE-79 | YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization … |
| CVE-2026-84750 | 6.5 | 10.6 | Unknown | Ultra Addons for Contact Form 7 | CWE-434 | Ultimate Addons for Contact Form 7 3.2.4 - 3.5.50 - Unauthenticated Arbitrary… |
| CVE-2026-8354 | 6.4 | 10.3 | celomitan | Gum Addon for Elementor | CWE-79 | Gum Addon for Elementor <= 1.3.15 - Authenticated (Contributor+) Stored Cross… |
| CVE-2026-13770 | 6.4 | 10.3 | appmysite | AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) | CWE-79 | AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting… |
| CVE-2026-2278 | 4.3 | 9.6 | vowelweb | VW Writer Blog | CWE-862 | VW Writer Blog <= 1.3.8 - Missing Authorization to Authenticated (Subscriber+… |
| CVE-2026-15660 | 4.3 | 9.6 | cleverplugins | SEO Booster | CWE-862 | SEO Booster <= 7.4.7 - Authenticated (Subscriber+) Missing Authorization to A… |
| CVE-2026-12402 | 4.4 | 9.5 | xootix | OTP Login & Register Woocommerce | CWE-79 | OTP Login & Register Woocommerce <= 2.7.3 - Authenticated (Administrator+) St… |
| CVE-2026-15098 | 6.4 | 9.3 | creativeinteractivemedia | Real3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder | CWE-79 | Real 3D Flipbook <= 5.1.1 - Authenticated (Contributor+) Stored Cross-Site Sc… |
| CVE-2026-86591 | 9.8 | 8.2 | Unknown | Botiga Pro | CWE-862 | Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templa… |
| CVE-2026-92430 | 5.3 | 8.2 | Unknown | Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit | CWE-862 | Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation… |
| CVE-2026-88926 | 8.6 | 7.5 | Unknown | VikRentItems Flexible Rental Management System | CWE-89 | VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi |
| CVE-2026-1242 | 4.3 | 7.5 | blockspare | BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites | CWE-863 | BlockSpare - Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorre… |
| CVE-2026-85680 | 8.8 | 7.0 | Unknown | Ultimate Member | CWE-79 | Ultimate Member < 2.13.1 - Unauthenticated Stored XSS via Profile Page Title |
| CVE-2026-88824 | 8.8 | 6.7 | Unknown | Master Blocks | CWE-79 | Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Se… |
| CVE-2026-19860 | 5.5 | 6.7 | Unknown | JetFormBuilder — Dynamic Blocks Form Builder | CWE-73 | JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-… |
| CVE-2026-76790 | 7.1 | 5.4 | Unknown | Estatik Real Estate Plugin | CWE-79 | Estatik < 4.3.5 - Reflected XSS via get_listings hash Parameter |
| CVE-2025-15698 | 3.5 | 4.8 | Unknown | Business Name Generator | CWE-79 | Business Name Generator <= 1.3 - Admin+ Stored XSS via Button Color Setting |
| CVE-2026-92404 | 7.5 | 4.2 | Unknown | MgoSync | CWE-200 | MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure |
| CVE-2026-16557 | 4.3 | 3.7 | Unknown | Nimble Page Builder | CWE-200 | Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_g… |
| CVE-2026-86814 | 8.1 | 3.4 | Unknown | UsersWP | CWE-269 | UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unveri… |
| CVE-2026-92099 | 6.5 | 3.4 | Unknown | WPGraphQL Smart Cache | CWE-284 | WPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration … |
| CVE-2026-15463 | 6.1 | 3.4 | sslzen | SSL Zen — SSL Certificate Installer & HTTPS Redirects | CWE-79 | SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' and 'host' Param… |
| CVE-2026-92435 | 5.3 | 3.4 | Unknown | Mailchimp for WooCommerce | CWE-862 | Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in … |
| CVE-2026-92403 | 3.7 | 3.4 | Unknown | Secure Custom Fields | CWE-863 | Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-En… |
| CVE-2026-85574 | 8.0 | 3.2 | Unknown | Unbounce Landing Pages | CWE-862 | Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijac… |
| CVE-2026-76554 | 7.2 | 3.2 | Unknown | WP Import Export Lite | CWE-269 | WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User … |
| CVE-2026-92425 | 5.5 | 3.2 | Unknown | Hydra Booking — Appointment Scheduling & Booking Calendar | CWE-639 | Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Delet… |
| CVE-2026-91847 | 4.8 | 3.2 | Unknown | Online Scheduling and Appointment Booking System | CWE-639 | Bookly < 28.2 - Unauthenticated AI Assistant Conversation Disclosure and Mess… |
| CVE-2026-92421 | 4.7 | 3.2 | Unknown | Hydra Booking — Appointment Scheduling & Booking Calendar | CWE-639 | Hydra Booking 1.1.0 - < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR |
| CVE-2026-92420 | 3.8 | 3.2 | Unknown | Hydra Booking — Appointment Scheduling & Booking Calendar | CWE-639 | Hydra Booking < 1.2.2 - Hydra Host+ Cross-Host Booking Deletion and Modificat… |
| CVE-2026-78030 | 9.8 | — | — | DBI | CWE-470 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm… |
| CVE-2026-93985 | 9.4 | — | Openpanel-dev | openpanel | CWE-94 | OpenPanel js-runtime JavaScript Template Sandbox Escape RCE |
| CVE-2026-93990 | 8.7 | — | libexpat | libexpat | CWE-176 | Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate |
| CVE-2026-93993 | 8.6 | — | mistralai | mistral-vibe | CWE-829 | Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout |
| CVE-2026-93991 | 8.3 | — | argoproj | argo-workflows | CWE-639 | Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Sel… |
| CVE-2026-94056 | 7.5 | — | Exim | Exim | CWE-908 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled … |
| CVE-2026-93988 | 7.1 | — | webkul | qloapps | CWE-22 | QloApps through 1.7.0 Arbitrary File Read via getEmailHTML |
| CVE-2026-93992 | 7.0 | — | GopeedLab | gopeed | CWE-22 | Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal |
| CVE-2026-94054 | 7.0 | — | Exim | Exim | CWE-787 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled … |
| CVE-2026-93984 | 6.9 | — | Openpanel-dev | openpanel | CWE-287 | OpenPanel API Authentication Bypass via Unverified Client Secret |
| CVE-2026-94000 | 6.6 | — | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: delegated admin with manage-users can e… |
| CVE-2026-94001 | 6.5 | — | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: admin credential delete bypasses denied… |
| CVE-2026-82672 | 6.3 | — | elixir-mint | mint | CWE-444 | Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smugg… |
| CVE-2026-93983 | 5.3 | — | Openpanel-dev | openpanel | CWE-89 | OpenPanel SQL Injection via ClickHouse Property Key Filter |
| CVE-2026-93982 | 4.8 | — | Openpanel-dev | openpanel | CWE-532 | OpenPanel MCP Authentication Token in Query Parameter Logged Plaintext |
| CVE-2026-93987 | 4.6 | — | rclone | rclone | CWE-73 | rclone serve docker Path Traversal via Volume Name |
| CVE-2026-93999 | 4.2 | — | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: token refresh continues issuing tokens … |
| CVE-2026-94057 | 4.0 | — | Exim | Exim | CWE-93 | Exim before 4.100.1 allows SMTP smuggling in which the received message does … |
| CVE-2026-94055 | 3.7 | — | Exim | Exim | CWE-416 | Exim before 4.100.1, when certain non-default TLS settings are used with GnuT… |
| CVE-2026-93981 | 2.3 | — | honojs | hono | CWE-79 | hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings |
| CVE-2026-93986 | 2.3 | — | rclone | rclone | CWE-22 | rclone before 1.75.1 Path Traversal via Directory Listing Names |
| CVE-2026-93989 | 2.3 | — | vllm-project | vllm | CWE-129 | vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words |
| CVE-2026-93954 | 2.1 | — | grimmory-tools | grimmory | CWE-285 | grimmory-tools grimmory Settings API Endpoint AppSettingController.java AppSe… |
| CVE-2026-93955 | 2.1 | — | grimmory-tools | grimmory | CWE-285 | grimmory-tools grimmory Download Endpoint KoboController.java streamFileToRes… |
| CVE-2026-93956 | 2.0 | — | olivier-ls | PHP-FTS | CWE-79 | olivier-ls PHP-FTS Search SearchEngine.php buildHighlights cross site scripting |
| CVE-2026-82560 | await | — | — | podlators | CWE-835 | Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion form… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-19 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.