AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0213 81.3 —
AFFECTED Product Versions Fixed X6000R 9.4.0cu.652_B20230116 – —
TIMELINE Oct 5 Reserved by CNA Oct 6 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
1020 CVEs published, led by Google (253).
1020 CVEs published October 6, 2026: 90 critical, 346 high, 266 medium, 44 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 274 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 620 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 2404 | 52395 | — | — |
| KEV catalog size | 1734 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3385 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 208 | 6413 | 532 | 2690 | 734 | 1 | 15 | 6 | 0.1 | 7.8 | .0018 | +20 ▲ |
| 291 | 3122 | 379 | 1191 | 1334 | 136 | 80 | 9 | 0.3 | 7.5 | .0026 | +253 ▲ | |
| microsoft | 12 | 2913 | 203 | 1998 | 695 | 17 | 290 | 31 | 1.1 | 7.8 | .0047 | +3 ▲ |
| red hat | 62 | 961 | 54 | 392 | 459 | 55 | 2 | 0 | 0.0 | 6.6 | .0034 | +29 ▲ |
| apple | 0 | 564 | 67 | 166 | 317 | 14 | 89 | 9 | 1.6 | 6.5 | .0019 | 0 |
| suse | 0 | 53 | 8 | 27 | 16 | 2 | 0 | 0 | 0.0 | 7.5 | .0036 | -9 ▼ |
| canonical | 2 | 52 | 16 | 12 | 19 | 5 | 0 | 0 | 0.0 | 7.8 | .0022 | +2 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 0 | 182 | 54 | 72 | 55 | 1 | 60 | 17 | 9.3 | 7.8 | .0046 | -11 ▼ |
| ubiquiti | 0 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | 0 |
| palo alto networks | 0 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | 0 |
| fortinet | 1 | 42 | 12 | 10 | 17 | 3 | 30 | 8 | 19.0 | 7.2 | .0040 | +1 ▲ |
| netgear | 0 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | 0 |
| f5 | 0 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | -7 ▼ |
| ivanti | 0 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | 0 |
| sonicwall | 0 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -5 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 109 | 816 | 166 | 372 | 256 | 19 | 33 | 2 | 0.2 | 7.5 | .0058 | +101 ▲ |
| mozilla | 2 | 381 | 122 | 169 | 87 | 0 | 9 | 0 | 0.0 | 8.8 | .0031 | -32 ▼ |
| gitlab | 1 | 105 | 8 | 24 | 62 | 11 | 5 | 3 | 2.9 | 5.3 | .0035 | +1 ▲ |
| drupal | 0 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | -26 ▼ |
| github | 2 | 25 | 2 | 12 | 11 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | -1 ▼ |
| docker | 1 | 13 | 1 | 8 | 4 | 0 | 0 | 0 | 0.0 | 8.2 | .0018 | +1 ▲ |
| wordpress | 0 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0392 | 0 |
| eclipse | 0 | 2 | 2 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.3 | .0050 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | 0 |
| ibm | 11 | 1034 | 194 | 484 | 338 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | -59 ▼ |
| adobe | 0 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | -2 ▼ |
| progress | 6 | 72 | 16 | 42 | 13 | 1 | 6 | 1 | 1.4 | 8.1 | .0045 | +4 ▲ |
| zohocorp | 0 | 42 | 6 | 29 | 7 | 0 | 0 | 0 | 0.0 | 8.3 | .0117 | -1 ▼ |
| solarwinds | 0 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | 0 |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | 0 |
| atlassian | 1 | 10 | 2 | 8 | 0 | 0 | 13 | 0 | 0.0 | 7.8 | .0043 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 0 | 74 | 22 | 28 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0164 | -3 ▼ |
| siemens | 0 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -1 ▼ |
| synology | 0 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | 0 |
| rockwell automation | 0 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | -18 ▼ |
| advantech | 0 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | 0 |
| schneider electric | 0 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | -4 ▼ |
| hitachi energy | 0 | 12 | 2 | 4 | 6 | 0 | 0 | 0 | 0.0 | 7.0 | .0025 | -4 ▼ |
| abb | 0 | 11 | 1 | 6 | 4 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 22 | 400 | 42 | 179 | 157 | 22 | 2 | 1 | 0.3 | 7.2 | .0027 | +3 ▲ |
| nvidia | 2 | 303 | 25 | 207 | 71 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | -28 ▼ |
| sourcecodester | 17 | 254 | 0 | 0 | 149 | 105 | 0 | 0 | 0.0 | 5.5 | .0041 | +3 ▲ |
| openclaw | 0 | 223 | 4 | 114 | 84 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | 0 |
| hewlett packard enterprise (hpe) | 38 | 204 | 39 | 92 | 64 | 9 | 1 | 1 | 0.5 | 7.3 | .0042 | -48 ▼ |
| mongodb | 1 | 170 | 6 | 99 | 60 | 5 | 1 | 0 | 0.0 | 7.1 | .0037 | -9 ▼ |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | 0 |
| itsourcecode | 14 | 167 | 0 | 0 | 42 | 125 | 0 | 0 | 0.0 | 2.1 | .0033 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9296 | 99.8 | 10.0 |
| CVE-2026-87902 | .4612 | 98.8 | 8.1 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-76460 | .1403 | 96.5 | 10.0 |
| CVE-2026-85102 | .0755 | 94.3 | 9.8 |
| CVE-2026-12269 | .0699 | 94.0 | 8.8 |
| CVE-2026-77692 | .0656 | 93.6 | 7.5 |
| CVE-2026-17176 | .0497 | 92.0 | 7.7 |
| CVE-2026-79697 | .0493 | 91.9 | 8.6 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9296 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-105484 | 10.0 | .0213 | |
| CVE-2026-85978 | 10.0 | .0144 | |
| CVE-2026-73369 | 10.0 | .0125 | |
| CVE-2026-75699 | 10.0 | .0125 | |
| CVE-2026-75703 | 10.0 | .0125 | |
| CVE-2026-75721 | 10.0 | .0125 |
| Vendor | CVEs |
|---|---|
| linux | 2135 |
| microsoft | 1005 |
| 915 | |
| oracle | 634 |
| ibm | 345 |
| apache | 296 |
| red hat | 293 |
| apple | 247 |
| adobe | 222 |
| dell | 210 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 17 |
| apple | 9 |
| 9 | |
| fortinet | 8 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 126 |
| NuGet | 30 |
| Packagist | 25 |
| npm | 24 |
| PyPI | 18 |
| crates.io | 10 |
| Go | 9 |
| RubyGems | 4 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-86950 | Apple | 0 |
| CVE-2026-87491 | 0 | |
| CVE-2026-88779 | NetScaler | 0 |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-102489 | Zammad GmbH | 1 |
| CVE-2026-102490 | Zammad GmbH | 1 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1784 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1784 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1784 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1784 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1784 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1784 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1784 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1784 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1784 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1784 |
EXPLOIT PUBLISHED — jpadilla pyjwt: 6 CVEs (CVE-2026-102269, CVE-2026-102270, CVE-2026-102271, CVE-2026-102272, CVE-2026-102274, CVE-2026-102275). Public exploit references added.
EXPLOIT PUBLISHED — MacWarrior clipbucket-v5: 6 CVEs (CVE-2026-95812, CVE-2026-96272, CVE-2026-100372, CVE-2026-102569, CVE-2026-102570, CVE-2026-103766). Public exploit references added.
EXPLOIT PUBLISHED — GNOME GLib: 5 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015). Public exploit references added.
EXPLOIT PUBLISHED — girishsaraf Online-Appointment-Booking-System: 3 CVEs (CVE-2026-105387, CVE-2026-105469, CVE-2026-105470). Public exploit references added.
EXPLOIT PUBLISHED — onetwothreeneth HospitalManagementSystem: 3 CVEs (CVE-2026-104609, CVE-2026-105383, CVE-2026-105386). Public exploit references added.
EXPLOIT PUBLISHED — vllm-project vllm: 3 CVEs (CVE-2026-100650, CVE-2026-100651, CVE-2026-100652). Public exploit references added.
EXPLOIT PUBLISHED — Wireshark Foundation Wireshark: 3 CVEs (CVE-2026-96421, CVE-2026-96422, CVE-2026-96423). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-104612 (SourceCodester Student Result Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-104625 (CodeAstro Simple Loan Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-104982 (Linux Mint Xreader). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105098 (Omega Solution CoinEx Crypto). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105135 (InternLM MindSearch). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105145 (Weaviate Verba). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105166 (kishor-23 food-waste-management-system). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105170 (kishor-23 food-waste-management-system). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105174 (Gerapy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105182 (SourceCodester Online Reviewer Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105186 (itsourcecode Online Admission System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105314 (Papermerge). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105388 (feelec-yishu feelcrm-os). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105392 (Lybbn Django-Vue-Lyadmin). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105438 (O2OA). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105643 (TryGhost Ghost). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19856 (Unknown All in One SEO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59870 (nodeca js-yaml). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67421 (rabbitmq-server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-73547 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97062 (Webkul Aureus ERP). Public exploit reference added.
DUE DATE PASSED — CVE-2026-102489 (Zammad GmbH Zammad). CISA remediation deadline was October 5, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-102490 (Zammad GmbH Zammad). CISA remediation deadline was October 5, 2026; still in catalog.
RESCORED — IBM DataStage on Cloud Pak for Data: 5 CVEs (CVE-2026-16335, CVE-2026-16338, CVE-2026-16432, CVE-2026-80423, CVE-2026-81549). CVSS rescored — before/after on each CVE page.
RESCORED — jpadilla pyjwt: 4 CVEs (CVE-2026-102269, CVE-2026-102270, CVE-2026-102274, CVE-2026-102275). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2026-105471 (girishsaraf Online-Appointment-Booking-System). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-25255 (Qualcomm, Inc. Snapdragon). CVSS 8.8 → 7.8 (NVD).
RESCORED — CVE-2026-25262 (Qualcomm, Inc. Snapdragon). CVSS 6.9 → 6.3 (NVD).
RESCORED — CVE-2026-66269 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 7.3 → 7.5 (NVD).
RESCORED — CVE-2026-70341 (Microsoft Edge (Chromium-based)). CVSS 8.5 → 8.8 (NVD).
RESCORED — CVE-2026-7700 (langflow-ai langflow). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-80442 (IBM Guardium Data Protection). CVSS 9.9 → 8.8 (NVD).
RESCORED — CVE-2026-81478 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2026-81623 (IBM Guardium Data Protection). CVSS 6.3 → 8.8 (NVD).
RESCORED — CVE-2026-96420 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD).
RESCORED — CVE-2026-96423 (Wireshark Foundation Wireshark). CVSS 5.5 → 7.1 (NVD).
PATCH SHIPPED — CVE-2025-62973 (Themekraft BuddyForms). Fixed in BuddyForms 2.10.4.
PATCH SHIPPED — CVE-2026-42418 (Socialrocket Social Rocket). Fixed in Social Rocket 1.3.6.
PATCH SHIPPED — CVE-2026-42638 (Awesomemotive Easy Digital Downloads). Fixed in Easy Digital Downloads 3.7.1.1.
PATCH SHIPPED — CVE-2026-81792 (MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX). Fixed in Product Catalog Enquiry for WooCommerce by MultiVendorX 6.1.6.
ENRICHED — Linux: 7 CVEs (CVE-2026-64040, CVE-2026-98049, CVE-2026-98051, CVE-2026-98053, CVE-2026-98054, CVE-2026-98080, CVE-2026-98082). Received CVSS/CPE analysis.
How to read these box scores · glossary
1020 CVEs published. 25 box scores and 375 table rows below; the remaining 620 continue on page 2 · page 3 — every CVE is listed, nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0213 81.3 —
AFFECTED Product Versions Fixed X6000R 9.4.0cu.652_B20230116 – —
TIMELINE Oct 5 Reserved by CNA Oct 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0109 64.2 —
AFFECTED Product Versions Fixed reNgine 2.0 – —
TIMELINE Oct 5 Reserved by CNA Oct 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0074 52.9 —
AFFECTED Product Versions Fixed WooCommerce Designer Pro n/a – —
TIMELINE Mar 12 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0074 52.9 —
AFFECTED Product Versions Fixed Content Visibility for Divi Builder n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0055 44.2 —
AFFECTED Product Versions Fixed ACPT (Premium) unspecified —
TIMELINE Oct 5 Reserved by CNA Oct 6 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0050 40.4 —
AFFECTED Product Versions Fixed srs 7.0-a1 – 8.0-d0
TIMELINE Oct 5 Reserved by CNA Oct 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0049 39.8 —
AFFECTED Product Versions Fixed Kognetiks Chatbot for WordPress n/a – —
TIMELINE Mar 12 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0049 39.7 —
AFFECTED Product Versions Fixed Graphina n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A L L N 5.1 .0048 39.6 —
AFFECTED Product Versions Fixed PingGateway 7.1.0 – —
TIMELINE Aug 26 Reserved by CNA Oct 6 Published (CNA: Ping Identity)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0048 39.5 —
AFFECTED Product Versions Fixed Meta Box AIO n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0048 39.3 —
AFFECTED Product Versions Fixed Taskbot n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0048 39.3 —
AFFECTED Product Versions Fixed Workreap Core n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0048 39.1 —
AFFECTED Product Versions Fixed AC5 02.03.01.111_multi – —
TIMELINE Oct 5 Reserved by CNA Oct 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0046 37.9 —
AFFECTED Product Versions Fixed Challan n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0046 37.9 —
AFFECTED Product Versions Fixed PublishPress Capabilities unspecified 2.50.0
TIMELINE May 21 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0045 37.0 —
AFFECTED Product Versions Fixed Taskbot n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C N N H 7.7 .0045 37.0 —
AFFECTED Product Versions Fixed Jobs for WordPress n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0045 36.7 —
AFFECTED Product Versions Fixed WP Duplicate n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0042 34.5 —
AFFECTED Product Versions Fixed Doctreat n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0042 34.5 —
AFFECTED Product Versions Fixed Simple JWT Login 4.0.0 – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N N H 6.5 .0041 33.2 —
AFFECTED Product Versions Fixed WPBase Cache n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 6.9 .0041 33.0 —
AFFECTED Product Versions Fixed Motors n/a – 1.4.125
TIMELINE Oct 2 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0040 31.8 —
AFFECTED Product Versions Fixed SiteVault – Backup, Restore, Migration & Cloning n/a – 1.5.18
TIMELINE Oct 3 Reserved by CNA Oct 6 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0040 31.7 —
AFFECTED Product Versions Fixed Drug Recommendation System 1.0 – —
TIMELINE Oct 5 Reserved by CNA Oct 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0039 31.3 —
AFFECTED Product Versions Fixed WooCommerce Multivendor Marketplace – REST API n/a – —
TIMELINE Apr 7 Reserved by CNA Oct 6 Published (CNA: Patchstack)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-48199 | 7.5 | 31.3 | Beplusthemes | Sermon'e | CWE-862 | WordPress Sermon'e plugin <= 1.0.2 - Broken Access Control vulnerability |
| CVE-2026-39776 | 8.0 | 30.2 | wpshopmart | Tabs | CWE-94 | WordPress Tabs plugin <= 2.5 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-32557 | 9.3 | 30.1 | Bot Verification bookingwp.com: Verifying that you are not a robot... | WooCommerce Appointments | CWE-89 | WordPress WooCommerce Appointments plugin <= 5.3.2 - SQL Injection vulnerability |
| CVE-2026-39746 | 9.3 | 30.1 | fs-code | Booknetic | CWE-89 | WordPress Booknetic plugin <= 4.8.5 - SQL Injection vulnerability |
| CVE-2026-85153 | 9.3 | 28.9 | Schmooze | Schmooze dating mobile Application | CWE-321 | Information Disclosure Vulnerability in Schmooze dating mobile Application |
| CVE-2026-39792 | 8.6 | 27.6 | Mitchell Bennis | Simple File List | CWE-22 | WordPress Simple File List plugin <= 6.3.11 - Arbitrary File Deletion vulnera… |
| CVE-2026-39772 | 5.3 | 27.3 | bestwebsoft | Captcha by BestWebSoft | CWE-290 | WordPress Captcha by BestWebSoft plugin <= 5.2.8 - Bypass Vulnerability vulne… |
| CVE-2026-105059 | 6.5 | 26.7 | royalnavneet | Delete All Comments of wordpress | CWE-862 | WordPress Delete All Comments of wordpress plugin <= 7.1 - Broken Access Cont… |
| CVE-2026-94293 | 9.3 | 26.4 | Murrelektronik | Software AAS Edge Client all versions | CWE-306 | Missing authentication for critical function in the aas-edge-client REST API |
| CVE-2026-25433 | 7.1 | 26.2 | Tobias @Saleswonder.biz | WP2LEADS | CWE-862 | WordPress WP2LEADS plugin <= 3.5.7 - Broken Access Control vulnerability |
| CVE-2026-105809 | 2.1 | 26.2 | SourceCodester | Simple Student Information System | CWE-79 | SourceCodester Simple Student Information System Profile Field register.php c… |
| CVE-2026-59358 | 7.6 | 25.9 | Cloud Foundry | UAA | CWE-287 | UAA OAuth Token Endpoint Vulnerability allows user access token reuse for cli… |
| CVE-2026-25434 | 8.5 | 25.6 | Tobias @Saleswonder.biz | WP2LEADS | CWE-89 | WordPress WP2LEADS plugin <= 3.5.7 - SQL Injection vulnerability |
| CVE-2026-39747 | 8.5 | 25.6 | WofficeIO | Woffice | CWE-89 | WordPress Woffice theme <= 5.4.35 - SQL Injection vulnerability |
| CVE-2026-39775 | 8.8 | 25.1 | DexignZone | JobZilla - Job Board WordPress Theme | CWE-266 | WordPress JobZilla - Job Board WordPress Theme theme <= 2.2 - Privilege Escal… |
| CVE-2026-62072 | 8.8 | 25.1 | Progress Planner | Progress Planner | CWE-862 | WordPress Progress Planner plugin <= 1.10.0 - Broken Access Control vulnerabi… |
| CVE-2026-39797 | 9.8 | 24.9 | Data443 Risk Mitigation, Inc. | GDPR Framework By Data443 | CWE-502 | WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vu… |
| CVE-2026-39729 | 7.2 | 24.8 | WisdmLabs | Edwiser Bridge | CWE-201 | WordPress Edwiser Bridge plugin <= 4.3.4 - Sensitive Data Exposure vulnerability |
| CVE-2026-39762 | 6.5 | 24.3 | Patterns In The Cloud | Autoship Cloud for WooCommerce Subscription Products | CWE-862 | WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.17… |
| CVE-2026-42637 | 6.5 | 24.3 | Payplug | PayPlug for WooCommerce (Official) | CWE-862 | WordPress PayPlug for WooCommerce (Official) plugin <= 3.1.0 - Settings Chang… |
| CVE-2026-105707 | 5.5 | 23.8 | n/a | uptrace | CWE-200 | uptrace user_handler.go Login information exposure |
| CVE-2026-39754 | 6.5 | 23.8 | About Piotnet | Piotnet Addons For Elementor | CWE-22 | WordPress Piotnet Addons For Elementor plugin <= 7.1.71 - Arbitrary File Down… |
| CVE-2026-105776 | 5.5 | 23.8 | bhagya3929 | Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL | CWE-74 | bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL admin_t… |
| CVE-2026-39795 | 9.3 | 23.4 | brewlabs | SendPress Newsletters | CWE-89 | WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerabi… |
| CVE-2026-42417 | 9.3 | 23.4 | reputeinfosystems | ARMember Premium | CWE-89 | WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability |
| CVE-2026-39751 | 7.5 | 23.2 | Payplug | PayPlug for WooCommerce (Official) | CWE-862 | WordPress PayPlug for WooCommerce (Official) plugin <= 3.1.0 - Broken Access … |
| CVE-2026-104387 | 7.2 | 22.7 | blubrry | PowerPress Podcasting | CWE-862 | WordPress PowerPress Podcasting plugin <= 11.17.9 - Broken Access Control vul… |
| CVE-2026-41559 | 7.5 | 22.4 | Pluginjoy | SafeSnap – Verified WordPress Backup & Restore | CWE-201 | WordPress SafeSnap – Verified WordPress Backup & Restore plugin <= 2.1.2 - Se… |
| CVE-2026-41561 | 7.5 | 22.4 | Adrian Lin | Museder RestoreOne | CWE-201 | WordPress Museder RestoreOne plugin <= 2.7.276 - Sensitive Data Exposure vuln… |
| CVE-2026-41562 | 7.5 | 22.4 | norvisgabriel | Norvis Backup | CWE-201 | WordPress Norvis Backup plugin <= 1.1.0 - Sensitive Data Exposure vulnerability |
| CVE-2026-42413 | 7.5 | 22.4 | DaftPlug | Snapshotify – All-in-One Backup & Restore & Migrate | CWE-201 | WordPress Snapshotify – All-in-One Backup & Restore & Migrate plugin <= 1.3.2… |
| CVE-2026-104757 | 7.2 | 22.5 | Javier Carazo | Import and export users and customers | CWE-266 | WordPress Import and export users and customers plugin <= 2.5.5 - Privilege E… |
| CVE-2026-105058 | 8.8 | 22.4 | John James Jacoby | WP User Profiles | CWE-266 | WordPress WP User Profiles plugin <= 2.7.3 - Privilege Escalation vulnerability |
| CVE-2026-105057 | 5.3 | 22.3 | Ben Marshall | Zero Spam | CWE-290 | WordPress Zero Spam plugin <= 5.7.11 - Bypass vulnerability vulnerability |
| CVE-2026-92821 | 6.8 | 21.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-393 | Sssd: sssd: access control bypass via premature ldap access rule evaluation |
| CVE-2026-32578 | 7.1 | 21.5 | techsupport | ECPay Ecommerce for WooCommerce | CWE-862 | WordPress ECPay Ecommerce for WooCommerce plugin <= 1.1.2606090 - Broken Acce… |
| CVE-2026-39730 | 7.1 | 21.5 | Marcin | Wise Chat | CWE-862 | WordPress Wise Chat plugin <= 3.4.2 - Broken Access Control vulnerability |
| CVE-2026-32580 | 7.5 | 21.4 | wpgenie | WooCommerce Lottery | CWE-89 | WordPress WooCommerce Lottery plugin <= 2.2.9 - SQL Injection vulnerability |
| CVE-2026-39764 | 9.3 | 21.2 | RadiusTheme | Radius Booking — Booking Calendar for Appointments & Services | CWE-89 | WordPress Radius Booking — Booking Calendar for Appointments & Services plugi… |
| CVE-2026-102387 | 7.5 | 21.0 | XServer | Xserver Migrator | CWE-497 | WordPress Xserver Migrator plugin <= 1.6.6 - Sensitive Data Exposure vulnerab… |
| CVE-2026-104385 | 7.5 | 21.0 | Adrian Tobey | Groundhogg | CWE-201 | WordPress Groundhogg plugin <= 4.8.3 - Sensitive Data Exposure vulnerability |
| CVE-2026-4889 | 7.8 | 20.7 | RDL Technologies | eLoanApp Platform | CWE-89 | SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies |
| CVE-2026-39796 | 7.5 | 20.7 | Flipper Code – WordPress Development Company | Advanced Posts Listing – Show Post List Easily | CWE-862 | WordPress Advanced Posts Listing – Show Post List Easily plugin <= 1.0.8 - Br… |
| CVE-2026-41560 | 7.5 | 20.7 | wxdlabs | WXD Backup Lite | CWE-862 | WordPress WXD Backup Lite plugin <= 1.0.2 - Broken Access Control vulnerability |
| CVE-2026-66588 | 7.5 | 20.7 | Dream-Theme | The7 | CWE-862 | WordPress The7 theme <= 14.2.2 - Broken Access Control vulnerability |
| CVE-2026-105775 | 2.1 | 20.3 | vllm-project | vLLM | CWE-119 | vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of… |
| CVE-2026-105070 | 8.8 | 20.0 | Dimitri Grassi | Salon booking system | CWE-266 | WordPress Salon booking system plugin <= 10.31.7 - Privilege Escalation vulne… |
| CVE-2026-39771 | 8.5 | 19.7 | MightyNetworks vs BuddyBoss | Buddyboss Platform | CWE-89 | WordPress Buddyboss Platform plugin <= 3.1.0 - SQL Injection vulnerability |
| CVE-2026-42414 | 8.5 | 19.7 | CridioStudio | ListingPro | CWE-89 | WordPress ListingPro plugin <= 2.9.12 - SQL Injection vulnerability |
| CVE-2026-42416 | 8.5 | 19.7 | AndonDesign | UDesign Core | CWE-89 | WordPress UDesign Core plugin <= 4.15.0 - SQL Injection vulnerability |
| CVE-2026-39787 | 6.5 | 19.7 | 10Web | 10Web Social Photo Feed | CWE-862 | WordPress 10Web Social Photo Feed plugin <= 1.4.35 - Broken Access Control vu… |
| CVE-2026-39773 | 10.0 | 19.5 | AmentoTech | Doctreat Core | CWE-266 | WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability |
| CVE-2026-104406 | 7.3 | 19.5 | picu | picu | CWE-862 | WordPress picu plugin <= 3.10.1 - Broken Access Control vulnerability |
| CVE-2026-104405 | 8.1 | 18.9 | Nexcess | GiveWP | CWE-266 | WordPress GiveWP plugin <= 4.17.0 - Privilege Escalation vulnerability |
| CVE-2026-39749 | 6.5 | 18.6 | digitalpoint | App for Cloudflare® | CWE-862 | WordPress App for Cloudflare® plugin <= 1.10.1 - Broken Access Control vulner… |
| CVE-2026-105317 | 8.5 | 18.4 | Cozmoslabs | Paid Member Subscriptions | CWE-89 | WordPress Paid Member Subscriptions plugin <= 3.1.1 - SQL Injection vulnerabi… |
| CVE-2026-75962 | 7.2 | 18.5 | saadiqbal | Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | CWE-79 | Post SMTP <= 4.0.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting vi… |
| CVE-2026-105571 | 5.5 | 18.5 | n/a | PickMall Lilishop | CWE-266 | PickMall Lilishop Mobile Binding bindMobile improper authorization |
| CVE-2026-32581 | 7.1 | 18.0 | mooberrydreams | Mooberry Book Manager | CWE-89 | WordPress Mooberry Book Manager plugin 4.16.2 - SQL Injection vulnerability |
| CVE-2026-105705 | 2.1 | 18.0 | SourceCodester | Drug Recommendation System | CWE-79 | SourceCodester Drug Recommendation System add_drug.php cross site scripting |
| CVE-2026-105708 | 2.1 | 18.0 | n/a | imgproxy | CWE-79 | imgproxy SVG svg.go sanitizeElement cross site scripting |
| CVE-2026-98184 | await | 17.6 | Linux | Linux | — | wifi: mwifiex: prevent authentication frame length truncation |
| CVE-2026-42638 | 7.5 | 16.6 | Awesomemotive | Easy Digital Downloads | CWE-862 | WordPress Easy Digital Downloads plugin <= 3.7.1 - Broken Access Control vuln… |
| CVE-2026-57546 | 7.5 | 16.5 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in WLAN HAL |
| CVE-2026-105807 | 6.9 | 16.6 | SourceCodester | Simple Student Information System | CWE-74 | SourceCodester Simple Student Information System searchquery.php sql injection |
| CVE-2026-105808 | 2.0 | 16.6 | SourceCodester | Simple Student Information System | CWE-79 | SourceCodester Simple Student Information System searchresults.php clean cros… |
| CVE-2026-41558 | 7.5 | 16.1 | WP Synchro | WP Migration Plugin DB & Files – WP Synchro | CWE-290 | WordPress WP Migration Plugin DB & Files – WP Synchro plugin <= 1.16.1 - 2FA … |
| CVE-2026-104747 | 8.1 | 15.9 | Edge-Themes | Haaken | CWE-502 | WordPress Haaken theme <= 1.5 - PHP Object Injection vulnerability |
| CVE-2026-94206 | 6.3 | 15.7 | danielberkompas | cloak_ecto | CWE-916 | Cloak PBKDF2 field ignores the configured iteration count and runs only :size… |
| CVE-2026-100518 | 5.3 | 15.8 | WebFactory | Advanced Google reCAPTCHA | CWE-288 | WordPress Advanced Google reCAPTCHA plugin <= 5.40 - Broken Authentication vu… |
| CVE-2026-39719 | 7.2 | 15.6 | DeKnows | PDF Smart Viewer for Elementor | CWE-918 | WordPress PDF Smart Viewer for Elementor plugin <= 1.0.4 - Server Side Reques… |
| CVE-2026-39728 | 7.2 | 15.6 | instapagedev | Instapage Plugin | CWE-918 | WordPress Instapage Plugin plugin <= 3.7.2 - Server Side Request Forgery (SSR… |
| CVE-2026-39756 | 6.5 | 15.6 | Wappointment team | Wappointment | CWE-639 | WordPress Wappointment plugin <= 2.7.7 - Insecure Direct Object References (I… |
| CVE-2026-39798 | 6.5 | 15.3 | ThemetechMount | TrueBooker | CWE-862 | WordPress TrueBooker plugin <= 1.2.9 - Settings Change vulnerability |
| CVE-2026-39758 | 7.1 | 15.1 | Midtrans | Midtrans-WooCommerce | CWE-79 | WordPress Midtrans-WooCommerce plugin <= 2.32.3 - Cross Site Scripting (XSS) … |
| CVE-2026-39766 | 7.1 | 15.1 | reputeinfosystems | ARForms | CWE-79 | WordPress ARForms plugin <= 7.1.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-39790 | 7.1 | 15.1 | e4jvikwp | VikRentCar | CWE-79 | WordPress VikRentCar plugin <= 1.4.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-42418 | 7.1 | 15.1 | Socialrocket | Social Rocket | CWE-79 | WordPress Social Rocket plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-42634 | 7.1 | 15.1 | bPlugins | Video Background Block – Use video as background in the section. | CWE-79 | WordPress Video Background Block – Use video as background in the section. pl… |
| CVE-2026-42635 | 7.1 | 15.1 | wpgenie | WooCommerce Simple Auctions | CWE-79 | WordPress WooCommerce Simple Auctions plugin <= 3.0.10 - Cross Site Scripting… |
| CVE-2026-42636 | 7.1 | 15.1 | WP Legal Pages | WP Cookie Notice for GDPR, CCPA & ePrivacy Consent | CWE-79 | WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.6 … |
| CVE-2026-39791 | 5.3 | 15.0 | Mailjet | Mailjet Email Marketing | CWE-201 | WordPress Mailjet Email Marketing plugin <= 6.2.3 - Sensitive Data Exposure v… |
| CVE-2026-39774 | 8.8 | 14.8 | Tourfic AI Studio | Tourfic Pro | CWE-266 | WordPress Tourfic Pro plugin <= 1.17.3 - Privilege Escalation vulnerability |
| CVE-2026-39785 | 9.3 | 14.6 | Serhii Pasyuk | Gmedia Photo Gallery | CWE-89 | WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability |
| CVE-2026-41555 | 9.3 | 14.6 | Weblizar – WordPress Themes & Plugin | Newsletter Subscription Form – User Subscriptions Form, Capture Email | CWE-89 | WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Ema… |
| CVE-2026-42415 | 9.3 | 14.6 | p-themes | Porto Theme - Functionality | CWE-89 | WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnera… |
| CVE-2026-41563 | 7.5 | 14.4 | Dawer Drew | Sitemovr | CWE-201 | WordPress Sitemovr plugin <= 1.0.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-105611 | 2.0 | 13.9 | chillzhuang | SpringBlade | CWE-266 | chillzhuang SpringBlade User Detail Endpoint RoleController.java improper aut… |
| CVE-2026-32569 | 7.1 | 13.4 | Joomunited | WP Media folder | CWE-79 | WordPress WP Media folder plugin <= 6.2.2 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-32570 | 7.1 | 13.4 | DaftPlug | Progressify - Progressive Web App (PWA) | CWE-79 | WordPress Progressify - Progressive Web App (PWA) plugin <= 1.6.0 - Cross Sit… |
| CVE-2026-32572 | 7.1 | 13.4 | weDevs | WP User Frontend Pro | CWE-79 | WordPress WP User Frontend Pro plugin <= 4.2.13 - Cross Site Scripting (XSS) … |
| CVE-2026-32574 | 7.1 | 13.4 | EDGARROJAS | Smart Forms | CWE-79 | WordPress Smart Forms plugin <= 2.6.104 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-32575 | 7.1 | 13.4 | Fantastic Plugins | SUMO Affiliates Pro | CWE-79 | WordPress SUMO Affiliates Pro plugin <= 11.7.0 - Cross Site Scripting (XSS) v… |
| CVE-2026-32577 | 7.1 | 13.4 | N-Media | Frontend File Manager | CWE-79 | WordPress Frontend File Manager plugin <= 23.6 - Cross Site Scripting (XSS) v… |
| CVE-2026-39720 | 7.1 | 13.4 | mapster | Mapster WP Maps | CWE-79 | WordPress Mapster WP Maps plugin <= 2.0.4 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-39722 | 7.1 | 13.4 | VibeThemes | WPLMS | CWE-79 | WordPress WPLMS theme <= 4.972 - Reflected Cross Site Scripting (XSS) vulnera… |
| CVE-2026-39724 | 7.1 | 13.4 | veppa | HTTP Requests Manager | CWE-79 | WordPress HTTP Requests Manager plugin <= 1.3.11 - Cross Site Scripting (XSS)… |
| CVE-2026-39726 | 7.1 | 13.4 | Lumise NEO | Lumise Product Designer | CWE-79 | WordPress Lumise Product Designer plugin <= 2.1.1 - Cross Site Scripting (XSS… |
| CVE-2026-39731 | 7.1 | 13.4 | code4life | Database for CF7 | CWE-79 | WordPress Database for CF7 plugin <= 1.2.6 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-39745 | 7.1 | 13.4 | bestweblayout | Contact Form to DB by BestWebSoft | CWE-79 | WordPress Contact Form to DB by BestWebSoft plugin <= 1.7.6 - Cross Site Scri… |
| CVE-2026-39748 | 7.1 | 13.4 | ThemeMove | EduMall | CWE-79 | WordPress EduMall theme <= 4.5.3 - Reflected Cross Site Scripting (XSS) vulne… |
| CVE-2026-39750 | 7.1 | 13.4 | weDevs | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | CWE-79 | WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, D… |
| CVE-2026-104394 | 7.1 | 13.4 | Syed Balkhi | Charitable | CWE-79 | WordPress Charitable plugin <= 1.8.12.3 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-104395 | 7.1 | 13.4 | picu | picu | CWE-79 | WordPress picu plugin <= 3.10.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-104814 | 7.1 | 13.4 | epiphyt | Form Block | CWE-79 | WordPress Form Block plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-105061 | 7.1 | 13.4 | Bởi brandtoss | WP Mailster | CWE-79 | WordPress WP Mailster plugin <= 1.9.0.0 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-95594 | 8.1 | 13.4 | Cozy Vision Technologies Pvt. Ltd. | SMS Alert Order Notifications | CWE-266 | WordPress SMS Alert Order Notifications plugin <= 4.0.0 - Privilege Escalatio… |
| CVE-2026-105621 | 2.1 | 12.6 | jishenghua | jshERP | CWE-266 | jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAcco… |
| CVE-2026-95526 | 7.3 | 12.5 | RealMag777 | BEAR | CWE-862 | WordPress BEAR plugin <= 1.2.2 - Broken Access Control vulnerability |
| CVE-2026-105573 | 2.1 | 12.5 | newbee-ltd | newbee-mall | CWE-840 | newbee-ltd newbee-mall Shopping Cart Quantity updateAccountHeadAndDetail logi… |
| CVE-2026-105610 | 2.0 | 12.3 | chillzhuang | SpringBlade | CWE-266 | chillzhuang SpringBlade Parameter Submit Management ParamController.java impr… |
| CVE-2026-105703 | 2.0 | 12.3 | PHPGurukul | User Registration & Login and User Management System | CWE-285 | PHPGurukul User Registration & Login and User Management System Change Passwo… |
| CVE-2026-102915 | 8.5 | 12.0 | Marco van Wieren | WPO365 | CWE-862 | WordPress WPO365 plugin <= 44.1 - Broken Access Control vulnerability |
| CVE-2026-98167 | await | 12.1 | Linux | Linux | — | smb: client: fix server->total_read for compound encrypted PDUs |
| CVE-2026-39788 | 6.5 | 12.0 | Shamim Hasan | Front End PM | CWE-79 | WordPress Front End PM plugin <= 11.4.6 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-105572 | 2.1 | 11.8 | n/a | PickMall Lilishop | CWE-285 | PickMall Lilishop Buyer Invoice List receipt authorization |
| CVE-2026-98240 | await | 11.8 | Linux | Linux | — | net: ip_tunnel: initialize `options_len` before referencing options |
| CVE-2026-104038 | 5.9 | 11.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-476 | Sssd: sssd: denial of service via missing sid extension in certificate mapping |
| CVE-2026-98311 | 7.8 | 11.4 | Linux | Linux | — | wifi: virt_wifi: don't transfer operstate before register |
| CVE-2026-98320 | 7.8 | 11.3 | Linux | Linux | — | netfilter: flowtable: hold reference on ct until flow is released |
| CVE-2026-98197 | 7.0 | 11.4 | Linux | Linux | — | hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove |
| CVE-2026-98252 | 7.0 | 11.4 | Linux | Linux | — | RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() |
| CVE-2026-98188 | await | 11.4 | Linux | Linux | — | wifi: p54: validate curve data length in the calibration curve converters |
| CVE-2026-98209 | await | 11.4 | Linux | Linux | — | mmc: sdhci-of-aspeed: Remove children before releasing SDC resources |
| CVE-2026-98233 | await | 11.4 | Linux | Linux | — | net/packet: clear RX owner on VNET header error |
| CVE-2026-98234 | await | 11.4 | Linux | Linux | — | net/sched: hhf: cap hh_flows_limit at change time |
| CVE-2026-98275 | await | 11.4 | Linux | Linux | — | net: ethernet: cortina: Ack RX overrun interrupt correctly |
| CVE-2026-98319 | await | 11.3 | Linux | Linux | — | drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr |
| CVE-2026-98322 | await | 11.3 | Linux | Linux | — | netfilter: nft_nat: fully initialise new_addr in netmap setup |
| CVE-2026-98214 | await | 11.3 | Linux | Linux | — | selinux: recheck intermediate backing files on mprotect() |
| CVE-2026-98171 | 8.8 | 10.8 | Linux | Linux | — | smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs |
| CVE-2026-98169 | 7.1 | 10.8 | Linux | Linux | — | smb: client: fix potential OOB read in smb3_enum_snapshots() |
| CVE-2026-98172 | await | 10.8 | Linux | Linux | — | smb: client: fix smbd_connection leak on cifs_get_tcp_session() error |
| CVE-2026-98181 | await | 10.8 | Linux | Linux | — | drm/gud: fix out-of-bounds write in gud_plane_atomic_check() |
| CVE-2026-98199 | await | 10.8 | Linux | Linux | — | hwmon: (pmbus/core) increase number of phases and add new mask |
| CVE-2026-98213 | await | 10.8 | Linux | Linux | — | mmc: core: Cancel SDIO IRQ work before freeing host |
| CVE-2026-98221 | await | 10.8 | Linux | Linux | — | KEYS: trusted: Fix tpm2_load_cmd() boundary check |
| CVE-2026-98247 | await | 10.8 | Linux | Linux | — | Bluetooth: hci_codec: validate vendor codec count length |
| CVE-2026-98264 | await | 10.8 | Linux | Linux | — | ALSA: virtio: reset device before deleting virtqueues |
| CVE-2026-32571 | 6.5 | 10.4 | Colabrio | Ohio Extra | CWE-79 | WordPress Ohio Extra plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-39727 | 6.5 | 10.4 | Saravana Kumar K | WC Fields Factory | CWE-79 | WordPress WC Fields Factory plugin <= 4.1.12 - Cross Site Scripting (XSS) vul… |
| CVE-2026-98229 | 7.8 | 10.1 | Linux | Linux | — | xfrm: save input state data before secpath resets |
| CVE-2026-98173 | 7.5 | 10.0 | Linux | Linux | — | smb: client: fix use-after-free of iface in cifs_try_adding_channels() |
| CVE-2026-98175 | 7.5 | 10.0 | Linux | Linux | — | smb: client: cancel reconnect work in clean_demultiplex_info() |
| CVE-2026-98230 | 7.0 | 10.1 | Linux | Linux | — | xfrm: use hlist_del_init_rcu for state_cache and state_cache_input |
| CVE-2026-98168 | await | 10.0 | Linux | Linux | — | smb: client: fix reparse buffer bounds in cifs_query_reparse_point() |
| CVE-2026-98170 | await | 10.0 | Linux | Linux | — | smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() |
| CVE-2026-98211 | await | 10.1 | Linux | Linux | — | mmc: mmci: Fix use-after-free in busy-timeout work |
| CVE-2026-98212 | await | 10.1 | Linux | Linux | — | mmc: hsq: Fix use-after-free in retry work |
| CVE-2026-98215 | await | 10.1 | Linux | Linux | — | selinux: preserve user SID across nested backing files |
| CVE-2026-98222 | await | 10.1 | Linux | Linux | — | KEYS: encrypted: fix integer overflow of datablob_len |
| CVE-2026-98231 | await | 10.1 | Linux | Linux | — | xfrm: serialize state GC with device state flush |
| CVE-2026-98245 | await | 10.1 | Linux | Linux | — | btrfs: take commit root semaphore when iterating in mark_block_group_to_copy() |
| CVE-2026-98248 | await | 10.1 | Linux | Linux | — | arm64: percpu: Fix LSE operations on {8,16}-bit types |
| CVE-2026-98266 | await | 10.1 | Linux | Linux | — | ALSA: core: Fix potential UAF after asynchronous card release |
| CVE-2026-97300 | 6.5 | 9.8 | Arraytics | WP Event Solution | CWE-799 | WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerab… |
| CVE-2026-98180 | 7.1 | 9.8 | Linux | Linux | — | drm/msm: RCU-free the scheduler-containing ring and VM objects |
| CVE-2026-98244 | await | 9.8 | Linux | Linux | — | btrfs: clear free space tree creation state on rebuild failure |
| CVE-2026-98259 | await | 9.8 | Linux | Linux | — | fs/dax: check zero or empty entry before converting xarray entry |
| CVE-2026-98296 | await | 9.8 | Linux | Linux | — | Bluetooth: btintel_pcie: validate TX skb length in send_sync |
| CVE-2026-98272 | await | 9.4 | Linux | Linux | — | net: mvpp2: prevent buffer overflow in page_pool allocation |
| CVE-2026-39723 | 7.5 | 9.2 | Green Invoice | Morning for WooCommerce | CWE-862 | WordPress Morning for WooCommerce plugin <= 2.4.1 - Broken Access Control vul… |
| CVE-2026-39789 | 7.5 | 9.2 | WP Manage Ninja | Fluent Affiliate Pro | CWE-862 | WordPress Fluent Affiliate Pro plugin <= 1.6.4 - Broken Access Control vulner… |
| CVE-2026-105072 | 7.5 | 9.2 | WP Manage Ninja | FluentBooking Pro | CWE-862 | WordPress FluentBooking Pro plugin < 2.5.0 - Broken Access Control vulnerability |
| CVE-2026-32576 | 6.5 | 9.1 | ZWEISCHNEIDER | Faktur Pro for WooCommerce | CWE-639 | WordPress Faktur Pro for WooCommerce plugin <= 3.2.2 - Insecure Direct Object… |
| CVE-2026-105472 | 2.1 | 9.0 | girishsaraf | Online-Appointment-Booking-System | CWE-74 | girishsaraf Online-Appointment-Booking-System Booking book.php sql injection |
| CVE-2026-98166 | 7.8 | 8.7 | Linux | Linux | — | drm/ttm: fix swapped-out resources never leaving their bulk_move range |
| CVE-2026-98165 | await | 8.7 | Linux | Linux | — | drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only |
| CVE-2026-98177 | await | 8.7 | Linux | Linux | — | drm/amdkfd: Avoid integer underflow in EOP ring size calculation. |
| CVE-2026-98178 | await | 8.7 | Linux | Linux | — | drm/amdgpu: Skip KFD mapping clear before initialization |
| CVE-2026-98220 | await | 8.7 | Linux | Linux | — | sched_ext: Fix NULL sched deref in kfunc sub-sched error paths |
| CVE-2026-98242 | await | 8.7 | Linux | Linux | — | dma-buf: Fix silent overflow for phys vec to sgt |
| CVE-2026-98268 | await | 8.7 | Linux | Linux | — | perf: Fix null pointer access in is_include_guest_event() |
| CVE-2026-98350 | await | 8.5 | Linux | Linux | — | wifi: brcmfmac: cyw: pass PMKID to firmware if present |
| CVE-2026-104033 | 5.4 | 8.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-193 | Sssd: sssd: access control bypass via improper ldap shadow expiration check |
| CVE-2026-97308 | 4.8 | 8.1 | WebFactory | Login Lockdown | CWE-290 | WordPress Login Lockdown plugin <= 2.17 - Bypass Vulnerability vulnerability |
| CVE-2026-39768 | 7.1 | 8.0 | CleanTalk Inc | Security & Malware scan by CleanTalk | CWE-79 | WordPress Security & Malware scan by CleanTalk plugin <= 2.189 - Cross Site S… |
| CVE-2026-39778 | 7.1 | 8.0 | themeansar | Ansar Import – One Click Starter Sites – for Elementor & Themes | CWE-79 | WordPress Ansar Import – One Click Starter Sites – for Elementor & Themes plu… |
| CVE-2026-39780 | 7.1 | 8.0 | Youzify | Youzify | CWE-79 | WordPress Youzify plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-39781 | 7.1 | 8.0 | Dan Rossiter | Document Gallery | CWE-79 | WordPress Document Gallery plugin <= 5.1.1 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-39784 | 7.1 | 8.0 | nicdark | Hotel Booking | CWE-79 | WordPress Hotel Booking plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-40806 | 7.1 | 8.0 | Plugin Devs | Blog, Posts and Category Filter for Elementor | CWE-79 | WordPress Blog, Posts and Category Filter for Elementor plugin <= 2.1.0 - Cro… |
| CVE-2026-40807 | 7.1 | 8.0 | Aman | CF7 Views – Complete Entry Management for Contact Form 7 | CWE-79 | WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= … |
| CVE-2026-94675 | 7.1 | 8.0 | Fluent Forms Free vs Pro | Fluent Forms Pro Add On Pack | CWE-79 | WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Cross Site Scriptin… |
| CVE-2026-105305 | 5.4 | 7.7 | Red Hat | Red Hat Build of Keycloak | CWE-287 | Keycloak-services: keycloak-services: device authorization grant bypasses per… |
| CVE-2026-98277 | await | 7.5 | Linux | Linux | — | eth: fbnic: ring the doorbell if a burst ends in a drop |
| CVE-2026-59357 | 6.5 | 7.4 | Cloud Foundry | UAA | CWE-345 | Self-UAA OIDC Configuration allows JWT injection to establish unauthorized se… |
| CVE-2026-98323 | 9.8 | 7.3 | Linux | Linux | — | RDMA/siw: Bound fragmented header copies by the remaining length |
| CVE-2026-98282 | 8.8 | 7.3 | Linux | Linux | — | powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba |
| CVE-2026-98339 | 8.8 | 7.3 | Linux | Linux | — | wifi: cfg80211: don't filter by BSS type when removing stale entries |
| CVE-2026-98241 | 7.8 | 7.3 | Linux | Linux | — | ipv6: xfrm: use full sockets in local error paths |
| CVE-2026-98251 | 7.8 | 7.3 | Linux | Linux | — | openvswitch: avoid reallocating confirmed conntrack labels |
| CVE-2026-98253 | 7.8 | 7.3 | Linux | Linux | — | RDMA/ucma: Serialize join and leave on copy_to_user failure |
| CVE-2026-98276 | 7.8 | 7.3 | Linux | Linux | — | net: lock the socket in sock_gettstamp() |
| CVE-2026-98257 | 7.5 | 7.3 | Linux | Linux | — | rds: ib: use rds_conn_drop() on protocol version mismatch |
| CVE-2026-98185 | await | 7.3 | Linux | Linux | — | wifi: mwifiex: validate scan response extents |
| CVE-2026-98186 | await | 7.3 | Linux | Linux | — | wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length |
| CVE-2026-98187 | await | 7.3 | Linux | Linux | — | wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST |
| CVE-2026-98189 | await | 7.3 | Linux | Linux | — | wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() |
| CVE-2026-98190 | await | 7.3 | Linux | Linux | — | wifi: wilc1000: fix out-of-bounds read in P2P public action frames |
| CVE-2026-98191 | await | 7.3 | Linux | Linux | — | wifi: wlcore: release runtime PM ref on regdomain config failure |
| CVE-2026-98194 | await | 7.3 | Linux | Linux | — | wifi: libertas_tf: fix UAF in lbtf_free_adapter() |
| CVE-2026-98195 | await | 7.3 | Linux | Linux | — | wifi: iwlegacy: fix broadcast stations deallocation |
| CVE-2026-98196 | await | 7.3 | Linux | Linux | — | wifi: brcmsmac: fix UAF in brcms_free_timer() |
| CVE-2026-98201 | await | 7.3 | Linux | Linux | — | Input: zero ff_effect before compat copy in input_ff_effect_from_user |
| CVE-2026-98202 | await | 7.3 | Linux | Linux | — | Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound |
| CVE-2026-98203 | await | 7.3 | Linux | Linux | — | Input: soc_button_array - check btns_desc->package.count |
| CVE-2026-98204 | await | 7.3 | Linux | Linux | — | Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() |
| CVE-2026-98205 | await | 7.3 | Linux | Linux | — | Input: evdev - zero absinfo before partial copy in EVIOCSABS |
| CVE-2026-98207 | await | 7.3 | Linux | Linux | — | mmc: spi: reset bytes_xfered before retrying CRC failures |
| CVE-2026-98208 | await | 7.3 | Linux | Linux | — | mmc: sdio_uart: fix xmit_fifo leak when the port table is full |
| CVE-2026-98210 | await | 7.3 | Linux | Linux | — | mmc: mxcmmc: cancel data work and watchdog on remove |
| CVE-2026-98217 | await | 7.3 | Linux | Linux | — | IB/mlx4: Fix use-after-free on pkey sysfs registration failure |
| CVE-2026-98255 | await | 7.3 | Linux | Linux | — | tcp: exclude old ACKs from tcp fast path |
| CVE-2026-98262 | await | 7.3 | Linux | Linux | — | ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY |
| CVE-2026-98298 | await | 7.3 | Linux | Linux | — | dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() |
| CVE-2026-98299 | await | 7.3 | Linux | Linux | — | tcp: do not let tcp_rmem be set below 4096 |
| CVE-2026-98302 | await | 7.3 | Linux | Linux | — | net: fddi: skfp: fix NULL deref when setting the MAC address while down |
| CVE-2026-98306 | await | 7.3 | Linux | Linux | — | seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation |
| CVE-2026-98308 | await | 7.3 | Linux | Linux | — | ALSA: hda: trace PCM open only after assigning a stream |
| CVE-2026-98314 | await | 7.3 | Linux | Linux | — | ALSA: pcm: set timer->private_data before registering the PCM timer |
| CVE-2026-98317 | await | 7.3 | Linux | Linux | — | neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS. |
| CVE-2026-98340 | await | 7.3 | Linux | Linux | — | wifi: cfg80211: only group hidden BSSes with beacon entries |
| CVE-2026-98342 | await | 7.3 | Linux | Linux | — | dmaengine: wait for RCU readers before releasing dma_device |
| CVE-2026-98343 | await | 7.3 | Linux | Linux | — | dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() |
| CVE-2026-98344 | await | 7.3 | Linux | Linux | — | dmaengine: Fix device kref underflow in dma_chan_put() |
| CVE-2026-98345 | await | 7.3 | Linux | Linux | — | wifi: cfg80211: check IP header size in cfg80211_classify8021d() |
| CVE-2026-98347 | await | 7.3 | Linux | Linux | — | IB/IPoIB: Avoid restoring OPER_UP after multicast flush |
| CVE-2026-98283 | 8.8 | 6.9 | Linux | Linux | — | KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() |
| CVE-2026-98239 | 8.1 | 6.9 | Linux | Linux | — | net: lan743x: fix RX checksum use-after-free |
| CVE-2026-98369 | 7.8 | 7.0 | Linux | Linux | — | xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_tr… |
| CVE-2026-98290 | 7.5 | 6.9 | Linux | Linux | — | Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup |
| CVE-2026-104670 | 7.1 | 6.9 | ThimPress | LearnPress | CWE-79 | WordPress LearnPress plugin <= 4.4.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-104672 | 7.1 | 6.9 | Nexcess | GiveWP | CWE-79 | WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-98331 | 7.0 | 6.9 | Linux | Linux | — | wifi: mac80211: unlist vifs when their netdev is unregistered |
| CVE-2026-98227 | await | 6.9 | Linux | Linux | — | memstick: ms_block: destroy io_queue workqueue on removal |
| CVE-2026-98236 | await | 6.9 | Linux | Linux | — | net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value |
| CVE-2026-98237 | await | 6.9 | Linux | Linux | — | net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain |
| CVE-2026-98238 | await | 6.9 | Linux | Linux | — | net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() |
| CVE-2026-98246 | await | 6.9 | Linux | Linux | — | Bluetooth: hci_sync: Serialize local codec list cleanup |
| CVE-2026-98249 | await | 6.9 | Linux | Linux | — | arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc |
| CVE-2026-98287 | await | 6.9 | Linux | Linux | — | pppoatm: ensure a writable skb header and linear data |
| CVE-2026-98301 | await | 6.9 | Linux | Linux | — | net: bridge: mst: move switchdev call outside rcu |
| CVE-2026-98303 | await | 6.9 | Linux | Linux | — | ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup |
| CVE-2026-98312 | await | 6.9 | Linux | Linux | — | ALSA: 6fire: fix OOB write from device-reported iso length |
| CVE-2026-98316 | await | 6.9 | Linux | Linux | — | ALSA: bcd2000: Fix race between rawmidi and disconnect |
| CVE-2026-98325 | await | 6.9 | Linux | Linux | — | wifi: mac80211: set up the TX info early to fix failure paths |
| CVE-2026-98326 | await | 6.9 | Linux | Linux | — | wifi: mac80211: mesh: release the channel if start fails |
| CVE-2026-98328 | await | 6.9 | Linux | Linux | — | wifi: mac80211: add HE 6 GHz capability in the scan elems len |
| CVE-2026-98278 | await | 6.8 | Linux | Linux | — | net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check |
| CVE-2026-98360 | 7.0 | 6.5 | Linux | Linux | — | RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds |
| CVE-2026-98300 | await | 6.6 | Linux | Linux | — | tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_r… |
| CVE-2026-98261 | 8.1 | 6.4 | Linux | Linux | — | cifs: Fix server use-after-free in cifs_chan_skip_or_disable() |
| CVE-2026-98254 | 7.8 | 6.4 | Linux | Linux | — | swiotlb: use the adjusted address for the highmem page lookup |
| CVE-2026-98260 | 7.8 | 6.4 | Linux | Linux | — | exec: Cleanup POSIX timers right after de_thread() |
| CVE-2026-98174 | 7.5 | 6.4 | Linux | Linux | — | smb: client: fix rlist race and missing initialization |
| CVE-2026-98216 | 7.1 | 6.4 | Linux | Linux | — | IB/hfi1: Fix the PIO_CRED credit-return mmap |
| CVE-2026-98179 | await | 6.4 | Linux | Linux | — | drm/amdgpu: fix rmmio iounmap skipped on device removal |
| CVE-2026-98182 | await | 6.4 | Linux | Linux | — | wifi: mac80211: refuse to make a monitor active when it has no queue |
| CVE-2026-98192 | await | 6.4 | Linux | Linux | — | wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown |
| CVE-2026-98193 | await | 6.4 | Linux | Linux | — | wifi: libipw: reject TKIP frames without a full MIC |
| CVE-2026-98198 | await | 6.4 | Linux | Linux | — | hwmon: (pwm-fan) Stop RPM timer before freeing tach data |
| CVE-2026-98200 | await | 6.4 | Linux | Linux | — | hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() |
| CVE-2026-98206 | await | 6.4 | Linux | Linux | — | Input: cyttsp5 - clamp the HID report size before memcpy |
| CVE-2026-98218 | await | 6.4 | Linux | Linux | — | i2c: atr: fix dangling adapter pointer on add failure |
| CVE-2026-98232 | await | 6.4 | Linux | Linux | — | scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() |
| CVE-2026-98235 | await | 6.4 | Linux | Linux | — | net/sched: act_api: release tail references on DELACTION failure |
| CVE-2026-98263 | await | 6.4 | Linux | Linux | — | ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type |
| CVE-2026-98265 | await | 6.4 | Linux | Linux | — | ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity |
| CVE-2026-98267 | await | 6.4 | Linux | Linux | — | 9p: Fix v9fs_issue_write() to update i_size and remote_i_size |
| CVE-2026-98269 | await | 6.4 | Linux | Linux | — | btrfs: abort transaction on failure to update inode for hole punching and ref… |
| CVE-2026-98270 | await | 6.4 | Linux | Linux | — | drm/amdgpu: check ras and obj before dereference |
| CVE-2026-98271 | await | 6.4 | Linux | Linux | — | net: skbuff: do not leave stale header offsets after pskb_carve() |
| CVE-2026-98291 | await | 6.4 | Linux | Linux | — | Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit |
| CVE-2026-98293 | await | 6.4 | Linux | Linux | — | Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() |
| CVE-2026-98295 | await | 6.4 | Linux | Linux | — | Bluetooth: coredump: Quiesce dump work on unregister |
| CVE-2026-98297 | await | 6.4 | Linux | Linux | — | Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained |
| CVE-2026-98307 | await | 6.4 | Linux | Linux | — | wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() |
| CVE-2026-98309 | await | 6.4 | Linux | Linux | — | drm/vc4: Use managed KMS polling to fix UAF on unbind |
| CVE-2026-98327 | await | 6.4 | Linux | Linux | — | wifi: mac80211: mesh: reset the CSA state when leaving |
| CVE-2026-98329 | await | 6.4 | Linux | Linux | — | wifi: mac80211: don't allow injecting frames wider than the chanctx |
| CVE-2026-98334 | await | 6.4 | Linux | Linux | — | wifi: mac80211: reset state when starting AP fails |
| CVE-2026-98335 | await | 6.4 | Linux | Linux | — | wifi: mac80211: abort chanswitch when leaving a mesh |
| CVE-2026-98336 | await | 6.4 | Linux | Linux | — | wifi: mac80211: don't offload TC setup on AP_VLAN interfaces |
| CVE-2026-98337 | await | 6.4 | Linux | Linux | — | wifi: mac80211: don't start a ROC while scanning |
| CVE-2026-98346 | await | 6.4 | Linux | Linux | — | wifi: cfg80211: don't get the radio mask for netdev-less wdevs |
| CVE-2026-32582 | 6.5 | 6.3 | iatoai | IATO MCP | CWE-862 | WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability |
| CVE-2026-98256 | 7.8 | 6.2 | Linux | Linux | — | signal: Prevent exec() race |
| CVE-2026-98258 | 7.8 | 6.2 | Linux | Linux | — | posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list |
| CVE-2026-98281 | 7.8 | 6.2 | Linux | Linux | — | futex: Also allocate private hash on vfork() |
| CVE-2026-98341 | 7.8 | 6.2 | Linux | Linux | — | wifi: cfg80211: don't free driver-owned scan requests |
| CVE-2026-98330 | 7.0 | 6.2 | Linux | Linux | — | wifi: cfg80211: get the wiphy out of a dying network namespace |
| CVE-2026-98223 | await | 6.2 | Linux | Linux | — | mm: filemap: retain mapped dropbehind folios |
| CVE-2026-98224 | await | 6.2 | Linux | Linux | — | mm/vma: correctly unaccount on mmap_prepare() failure |
| CVE-2026-98226 | await | 6.2 | Linux | Linux | — | mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count |
| CVE-2026-98273 | await | 6.2 | Linux | Linux | — | x86/kprobes: Fix crash when probing CS CALL instructions |
| CVE-2026-98274 | await | 6.2 | Linux | Linux | — | net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() |
| CVE-2026-98279 | await | 6.2 | Linux | Linux | — | btrfs: handle lack of space when cleaning up verity items |
| CVE-2026-98286 | await | 6.2 | Linux | Linux | — | drop_monitor: use timer_shutdown_sync() to prevent timer rearming during tear… |
| CVE-2026-98289 | await | 6.2 | Linux | Linux | — | af_unix: Unify scc_index when finalising SCC in __unix_walk_scc(). |
| CVE-2026-98294 | await | 6.2 | Linux | Linux | — | Bluetooth: hci_qca: Do not write to the serial port after it is closed |
| CVE-2026-98304 | await | 6.2 | Linux | Linux | — | net: bcmgenet: restore the hardware filters on open |
| CVE-2026-98313 | await | 6.2 | Linux | Linux | — | drm/msm/dp: skip PUSH_IDLE when the link was never enabled |
| CVE-2026-98321 | await | 6.2 | Linux | Linux | — | netfilter: nf_nat: unregister and release hooks on error |
| CVE-2026-98367 | 7.8 | 6.0 | Linux | Linux | — | RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept |
| CVE-2026-98348 | 7.1 | 5.9 | Linux | Linux | — | wifi: libipw: reject too-short association responses |
| CVE-2026-98349 | 7.1 | 6.0 | Linux | Linux | — | wifi: libipw: reject too-short beacon and probe responses |
| CVE-2026-98351 | await | 6.0 | Linux | Linux | — | wifi: virt_wifi: free skb when disconnected |
| CVE-2026-98354 | await | 5.9 | Linux | Linux | — | RDMA/mad: Fix receive buffer leak when PKey enforcement fails |
| CVE-2026-98362 | await | 6.0 | Linux | Linux | — | clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate |
| CVE-2026-98363 | await | 6.0 | Linux | Linux | — | firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS |
| CVE-2026-98370 | await | 5.9 | Linux | Linux | — | xfrm: fix compat ALLOCSPI request use-after-free |
| CVE-2026-105879 | 6.5 | 5.9 | Crocoblock | JetElements For Elementor | CWE-79 | WordPress JetElements For Elementor plugin <= 2.9.2.2 - Cross Site Scripting … |
| CVE-2026-98368 | 7.8 | 5.6 | Linux | Linux | — | esp: downgrade zerocopy managed frags before mutating skb frags |
| CVE-2026-98359 | 7.0 | 5.5 | Linux | Linux | — | RDMA/core: Reject unregistering netdevs in ib_get_eth_speed |
| CVE-2026-98352 | await | 5.5 | Linux | Linux | — | RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted |
| CVE-2026-98365 | 9.8 | 5.1 | Linux | Linux | — | RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access |
| CVE-2026-98357 | 8.1 | 5.1 | Linux | Linux | — | IB/isert: wait for deferred control PDU completions before releasing the conn… |
| CVE-2026-98358 | await | 5.1 | Linux | Linux | — | IB/iser: reject a remote invalidation of an unregistered direction |
| CVE-2026-98305 | 7.8 | 4.8 | Linux | Linux | — | net: dsa: mxl862xx: disable the stats poll on teardown |
| CVE-2026-98315 | 7.8 | 4.8 | Linux | Linux | — | ntfs: protect runlist updates with the runlist lock |
| CVE-2026-98318 | 7.8 | 4.8 | Linux | Linux | — | smb: client: validate absolute native symlink targets before NT fixups |
| CVE-2026-98324 | 7.8 | 4.8 | Linux | Linux | — | dmaengine: pxa: fix double counting of the hw descriptors |
| CVE-2026-98361 | 7.8 | 4.8 | Linux | Linux | — | RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths |
| CVE-2026-98243 | 7.1 | 4.8 | Linux | Linux | — | dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3 |
| CVE-2026-98176 | await | 4.8 | Linux | Linux | — | drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc |
| CVE-2026-98183 | await | 4.8 | Linux | Linux | — | wifi: mac80211: avoid out-of-bounds read for empty PREQ elements |
| CVE-2026-98219 | await | 4.8 | Linux | Linux | — | sched_ext: Close the pre-enable ops error claim window |
| CVE-2026-98225 | await | 4.8 | Linux | Linux | — | mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem |
| CVE-2026-98250 | await | 4.8 | Linux | Linux | — | nfsd: fix handling of NFSEXP_PNFS in the netlink codepath |
| CVE-2026-98280 | await | 4.8 | Linux | Linux | — | drm/xe/i2c: Disable IRQ on unbind |
| CVE-2026-98284 | await | 4.8 | Linux | Linux | — | netlink: do not free nlk->groups while lockless readers can use it |
| CVE-2026-98285 | await | 4.8 | Linux | Linux | — | net: bridge: vlan: fix bugs caused by switchdev deletion errors |
| CVE-2026-98288 | await | 4.8 | Linux | Linux | — | net: stmmac: fix TSO header length truncation |
| CVE-2026-98292 | await | 4.8 | Linux | Linux | — | Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access |
| CVE-2026-98310 | await | 4.8 | Linux | Linux | — | drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory |
| CVE-2026-98332 | await | 4.8 | Linux | Linux | — | wifi: mac80211: only operate on TDLS peers in the TDLS code |
| CVE-2026-98333 | await | 4.8 | Linux | Linux | — | wifi: mac80211: reset the LED state when ifup fails |
| CVE-2026-98338 | await | 4.8 | Linux | Linux | — | wifi: cfg80211: ibss: ref BSS entry for joined event |
| CVE-2026-98356 | await | 4.7 | Linux | Linux | — | RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup |
| CVE-2026-98371 | await | 4.7 | Linux | Linux | — | xfrm: iptfs: fix runt reassembly panic from short inner tot_len |
| CVE-2026-98372 | await | 4.7 | Linux | Linux | — | xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() |
| CVE-2026-105706 | 2.1 | 4.4 | SourceCodester | Drug Recommendation System | CWE-352 | SourceCodester Drug Recommendation System cross-site request forgery |
| CVE-2026-98366 | 7.8 | 4.2 | Linux | Linux | — | RDMA/rxe: validate access flags before swapping the MR's PD |
| CVE-2026-98228 | 7.8 | 4.1 | Linux | Linux | — | mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ |
| CVE-2026-98364 | 7.8 | 3.7 | Linux | Linux | — | xfrm: hold net_device reference under RCU in bundle creation |
| CVE-2026-39599 | 4.3 | 3.8 | wallstrdev | WDS MCP Content Manager | CWE-862 | WordPress WDS MCP Content Manager plugin <= 3.10.4 - Broken Access Control vu… |
| CVE-2026-98353 | await | 3.7 | Linux | Linux | — | RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables |
| CVE-2026-98355 | await | 3.7 | Linux | Linux | — | RDMA/rtrs: guard against null kobj name |
| CVE-2026-39760 | 7.1 | 3.3 | Creative interactive media | Real 3D FlipBook | CWE-79 | WordPress Real 3D FlipBook plugin <= 5.5 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-103346 | 7.1 | 3.3 | Tomlister | Payflex Payment Gateway | CWE-79 | WordPress Payflex Payment Gateway plugin <= 2.7.1 - Cross Site Scripting (XSS… |
| CVE-2026-86786 | 5.3 | 3.3 | Unknown | Slider Pro | CWE-200 | Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro… |
| CVE-2026-94299 | 6.5 | 2.6 | Unknown | elegro Crypto Payment | CWE-863 | elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Chang… |
| CVE-2026-89289 | 5.3 | 2.6 | Unknown | Fast Courier | CWE-862 | Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-st… |
| CVE-2026-94270 | 5.3 | 2.6 | Unknown | Deema Payment Gateway | CWE-287 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Man… |
| CVE-2026-94271 | 5.3 | 2.6 | Unknown | Deema Payment Gateway | CWE-287 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery… |
| CVE-2026-94278 | 5.5 | 2.4 | Unknown | File Media Renamer | CWE-284 | File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment… |
| CVE-2026-104380 | 5.3 | 2.2 | — | Punk | CWE-1385 | Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests … |
| CVE-2026-57545 | 7.8 | 1.6 | Qualcomm, Inc. | Snapdragon | CWE-822 | Untrusted Pointer Dereference in Graphics |
| CVE-2026-104044 | 6.2 | 1.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-476 | Sssd: sssd: denial of service via crafted passkey kerberos authentication req… |
| CVE-2026-95105 | 8.2 | 1.4 | danielberkompas | cloak | CWE-649 | Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plainte… |
| CVE-2026-25269 | 6.7 | 1.4 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-25270 | 6.7 | 1.4 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-25272 | 6.7 | 1.4 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-25273 | 6.7 | 1.4 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-25274 | 6.7 | 1.4 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in Windows WLAN Host |
| CVE-2026-25291 | 7.8 | 1.2 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in Graphics |
| CVE-2026-57537 | 7.8 | 1.2 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in DSP Service |
| CVE-2026-57554 | 7.8 | 1.2 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in DSP Service |
| CVE-2026-57555 | 7.8 | 1.2 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in DSP Service |
| CVE-2026-57559 | 7.8 | 1.2 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in DSP_Services |
| CVE-2026-104042 | 5.5 | 1.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: sssd: denial of service via out-of-bounds read in pam responder |
| CVE-2026-104039 | 4.7 | 0.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-825 | Sssd: sssd: denial of service via stale connection state reuse in pam gssapi … |
| CVE-2026-25267 | 7.8 | 0.7 | Qualcomm, Inc. | Snapdragon | CWE-862 | Missing Authorization in Core |
| CVE-2026-104040 | 4.4 | 0.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-140 | Sssd: sssd: information disclosure via odata injection in entra id lookups |
Results continue: ranks 401–1020.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-10-06 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.