boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, October 6, 2026 · all times UTC← 2026-10-05 · archive

Security Box Score — October 6, 2026

1020 CVEs published, led by Google (253).

1020 CVEs published October 6, 2026: 90 critical, 346 high, 266 medium, 44 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 274 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 620 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published240452395——
KEV catalog size1734

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3385 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux2086413532269073411560.17.8.0018+20 ▲
google2913122379119113341368090.37.5.0026+253 ▲
microsoft122913203199869517290311.17.8.0047+3 ▲
red hat629615439245955200.06.6.0034+29 ▲
apple056467166317148991.66.5.00190
suse053827162000.07.5.0036-9 ▼
canonical2521612195000.07.8.0022+2 ▲
freebsd04823673000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco0182547255160179.37.8.0046-11 ▼
ubiquiti065362810334.69.1.00500
palo alto networks0461426151324.34.7.00220
fortinet142121017330819.07.2.0040+1 ▲
netgear03400277000.04.3.00270
f502671441527.78.7.0050-7 ▼
ivanti0246162025520.88.8.01520
sonicwall019784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache109816166372256193320.27.5.0058+101 ▲
mozilla2381122169870900.08.8.0031-32 ▼
gitlab11058246211532.95.3.0035+1 ▲
drupal094119668411.15.7.0027-26 ▼
github225212110000.07.4.0054-1 ▼
docker1131840000.08.2.0018+1 ▲
wordpress0614103350.08.7.03920
eclipse022000000.09.3.00500
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle0290558116605631012840.17.8.00360
ibm11103419448433818610.17.5.0037-59 ▼
adobe08308236437592150.67.5.0036-2 ▼
progress6721642131611.48.1.0045+4 ▲
zohocorp04262970000.08.3.0117-1 ▼
solarwinds0261853010415.49.1.00670
veeam01961030100.08.6.00420
atlassian11028001300.07.8.0043+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link07422281212300.08.5.0164-3 ▼
siemens052633103000.07.3.0026-1 ▼
synology046510256000.05.6.00320
rockwell automation04353260000.08.6.0029-18 ▼
advantech02021710000.08.6.00710
schneider electric01821150000.08.5.0044-4 ▼
hitachi energy0122460000.07.0.0025-4 ▼
abb0111640000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell224004217915722210.37.2.0027+3 ▲
nvidia230325207710000.07.8.0019-28 ▼
sourcecodester1725400149105000.05.5.0041+3 ▲
openclaw022341148421000.07.1.00310
hewlett packard enterprise (hpe)382043992649110.57.3.0042-48 ▼
mongodb1170699605100.07.1.0037-9 ▼
spring017013608314000.06.5.00330
itsourcecode141670042125000.02.1.0033+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.929699.810.0
CVE-2026-87902.461298.88.1
CVE-2026-76461.282798.19.8
CVE-2026-93616.196597.39.8
CVE-2026-76460.140396.510.0
CVE-2026-85102.075594.39.8
CVE-2026-12269.069994.08.8
CVE-2026-77692.065693.67.5
CVE-2026-17176.049792.07.7
CVE-2026-79697.049391.98.6
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9296KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-10548410.0.0213
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
CVE-2026-7569910.0.0125
CVE-2026-7570310.0.0125
CVE-2026-7572110.0.0125
Most disclosures (vendor)
VendorCVEs
linux2135
microsoft1005
google915
oracle634
ibm345
apache296
red hat293
apple247
adobe222
dell210
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco17
apple9
google9
fortinet8
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven126
NuGet30
Packagist25
npm24
PyPI18
crates.io10
Go9
RubyGems4
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-86950Apple0
CVE-2026-87491Google0
CVE-2026-88779NetScaler0
CVE-2026-93952Arista Networks0
CVE-2026-102489Zammad GmbH1
CVE-2026-102490Zammad GmbH1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171784
CVE-2021-27102n/a2021-11-171784
CVE-2021-27101n/a2021-11-171784
CVE-2021-27103n/a2021-11-171784
CVE-2021-21017Adobe2021-11-171784
CVE-2021-28550Adobe2021-11-171784
CVE-2021-42013Apache Software Foundation2021-11-171784
CVE-2021-41773Apache Software Foundation2021-11-171784
CVE-2021-30858Apple2021-11-171784
CVE-2021-30860Apple2021-11-171784

Transactions

EXPLOIT PUBLISHED — jpadilla pyjwt: 6 CVEs (CVE-2026-102269, CVE-2026-102270, CVE-2026-102271, CVE-2026-102272, CVE-2026-102274, CVE-2026-102275). Public exploit references added.

EXPLOIT PUBLISHED — MacWarrior clipbucket-v5: 6 CVEs (CVE-2026-95812, CVE-2026-96272, CVE-2026-100372, CVE-2026-102569, CVE-2026-102570, CVE-2026-103766). Public exploit references added.

EXPLOIT PUBLISHED — GNOME GLib: 5 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015). Public exploit references added.

EXPLOIT PUBLISHED — girishsaraf Online-Appointment-Booking-System: 3 CVEs (CVE-2026-105387, CVE-2026-105469, CVE-2026-105470). Public exploit references added.

EXPLOIT PUBLISHED — onetwothreeneth HospitalManagementSystem: 3 CVEs (CVE-2026-104609, CVE-2026-105383, CVE-2026-105386). Public exploit references added.

EXPLOIT PUBLISHED — vllm-project vllm: 3 CVEs (CVE-2026-100650, CVE-2026-100651, CVE-2026-100652). Public exploit references added.

EXPLOIT PUBLISHED — Wireshark Foundation Wireshark: 3 CVEs (CVE-2026-96421, CVE-2026-96422, CVE-2026-96423). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-104612 (SourceCodester Student Result Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-104625 (CodeAstro Simple Loan Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-104982 (Linux Mint Xreader). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105098 (Omega Solution CoinEx Crypto). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105135 (InternLM MindSearch). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105145 (Weaviate Verba). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105166 (kishor-23 food-waste-management-system). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105170 (kishor-23 food-waste-management-system). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105174 (Gerapy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105182 (SourceCodester Online Reviewer Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105186 (itsourcecode Online Admission System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105314 (Papermerge). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105388 (feelec-yishu feelcrm-os). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105392 (Lybbn Django-Vue-Lyadmin). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105438 (O2OA). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105643 (TryGhost Ghost). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19856 (Unknown All in One SEO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59870 (nodeca js-yaml). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67421 (rabbitmq-server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73547 (envoyproxy envoy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97062 (Webkul Aureus ERP). Public exploit reference added.

DUE DATE PASSED — CVE-2026-102489 (Zammad GmbH Zammad). CISA remediation deadline was October 5, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-102490 (Zammad GmbH Zammad). CISA remediation deadline was October 5, 2026; still in catalog.

RESCORED — IBM DataStage on Cloud Pak for Data: 5 CVEs (CVE-2026-16335, CVE-2026-16338, CVE-2026-16432, CVE-2026-80423, CVE-2026-81549). CVSS rescored — before/after on each CVE page.

RESCORED — jpadilla pyjwt: 4 CVEs (CVE-2026-102269, CVE-2026-102270, CVE-2026-102274, CVE-2026-102275). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-105471 (girishsaraf Online-Appointment-Booking-System). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-25255 (Qualcomm, Inc. Snapdragon). CVSS 8.8 → 7.8 (NVD).

RESCORED — CVE-2026-25262 (Qualcomm, Inc. Snapdragon). CVSS 6.9 → 6.3 (NVD).

RESCORED — CVE-2026-66269 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 7.3 → 7.5 (NVD).

RESCORED — CVE-2026-70341 (Microsoft Edge (Chromium-based)). CVSS 8.5 → 8.8 (NVD).

RESCORED — CVE-2026-7700 (langflow-ai langflow). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-80442 (IBM Guardium Data Protection). CVSS 9.9 → 8.8 (NVD).

RESCORED — CVE-2026-81478 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-81623 (IBM Guardium Data Protection). CVSS 6.3 → 8.8 (NVD).

RESCORED — CVE-2026-96420 (Wireshark Foundation Wireshark). CVSS 4.7 → 5.5 (NVD).

RESCORED — CVE-2026-96423 (Wireshark Foundation Wireshark). CVSS 5.5 → 7.1 (NVD).

PATCH SHIPPED — CVE-2025-62973 (Themekraft BuddyForms). Fixed in BuddyForms 2.10.4.

PATCH SHIPPED — CVE-2026-42418 (Socialrocket Social Rocket). Fixed in Social Rocket 1.3.6.

PATCH SHIPPED — CVE-2026-42638 (Awesomemotive Easy Digital Downloads). Fixed in Easy Digital Downloads 3.7.1.1.

PATCH SHIPPED — CVE-2026-81792 (MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX). Fixed in Product Catalog Enquiry for WooCommerce by MultiVendorX 6.1.6.

ENRICHED — Linux: 7 CVEs (CVE-2026-64040, CVE-2026-98049, CVE-2026-98051, CVE-2026-98053, CVE-2026-98054, CVE-2026-98080, CVE-2026-98082). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

1020 CVEs published. 25 box scores and 375 table rows below; the remaining 620 continue on page 2 · page 3 — every CVE is listed, nothing truncated.

TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0213   81.3     —
AFFECTED
  Product  Versions                 Fixed
  X6000R   9.4.0cu.652_B20230116 –  —
TIMELINE
  Oct 5   Reserved by CNA
  Oct 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
yogeshojha reNgine listTargets Endpoint tasks.py subdomain_discovery os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0109   64.2     —
AFFECTED
  Product  Versions  Fixed
  reNgine  2.0 –     —
TIMELINE
  Oct 5   Reserved by CNA
  Oct 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
JMAPlugins WooCommerce Designer Pro — WordPress WooCommerce Designer Pro plugin <= 1.9.33 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0074   52.9     —
AFFECTED
  Product                   Versions  Fixed
  WooCommerce Designer Pro  n/a –     —
TIMELINE
  Mar 12  Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Jonathan Horowitz Content Visibility for Divi Builder — WordPress Content Visibility for Divi Builder plugin <= 5.03 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0074   52.9     —
AFFECTED
  Product                              Versions  Fixed
  Content Visibility for Divi Builder  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Mauro Cassani ACPT (Premium) — ACPT (Premium) <= 2.0.66 - Authenticated (Subscriber+) Remote Code Execution via REST API Email Template
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0055   44.2     —
AFFECTED
  Product         Versions     Fixed
  ACPT (Premium)  unspecified  —
TIMELINE
  Oct 5   Reserved by CNA
  Oct 6   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
OSSRS srs System API api.go systemAPI.Run missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0050   40.4     —
AFFECTED
  Product  Versions  Fixed
  srs      7.0-a1 –  8.0-d0
TIMELINE
  Oct 5   Reserved by CNA
  Oct 6   Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
kognetiks Kognetiks Chatbot for WordPress — WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0049   39.8     —
AFFECTED
  Product                          Versions  Fixed
  Kognetiks Chatbot for WordPress  n/a –     —
TIMELINE
  Mar 12  Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-434 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Iqonic Design Graphina — WordPress Graphina plugin <= 3.1.12 - Broken Authentication vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0049   39.7     —
AFFECTED
  Product   Versions  Fixed
  Graphina  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-288 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Ping Identity PingGateway — Open Redirect in PingGateway Fragment Filter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   L   L   N    5.1   .0048   39.6     —
AFFECTED
  Product      Versions  Fixed
  PingGateway  7.1.0 –   —
TIMELINE
  Aug 26  Reserved by CNA
  Oct 6   Published (CNA: Ping Identity)
CWE-601 · CNA: Ping Identity · CVSS v4.0 · 3 references · NVD status: Awaiting Analysis
eLightUp Meta Box AIO — WordPress Meta Box AIO plugin <= 3.7.1 - Privilege Escalation vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0048   39.5     —
AFFECTED
  Product       Versions  Fixed
  Meta Box AIO  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-266 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
AmentoTech Taskbot — WordPress Taskbot plugin <= 6.6 - Arbitrary File Upload vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0048   39.3     —
AFFECTED
  Product  Versions  Fixed
  Taskbot  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-434 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
AmentoTech Workreap Core — WordPress Workreap Core plugin <= 3.4.5 - Arbitrary File Upload vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0048   39.3     —
AFFECTED
  Product        Versions  Fixed
  Workreap Core  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-434 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Tenda AC5 Wifi setWifi stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0048   39.1     —
AFFECTED
  Product  Versions              Fixed
  AC5      02.03.01.111_multi –  —
TIMELINE
  Oct 5   Reserved by CNA
  Oct 6   Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
WebAppick Challan — WordPress Challan plugin <= 3.7.88 - Privilege Escalation vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0046   37.9     —
AFFECTED
  Product  Versions  Fixed
  Challan  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-266 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
PublishPress PublishPress Capabilities — WordPress PublishPress Capabilities plugin <= 2.45.0 - Privilege Escalation vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0046   37.9     —
AFFECTED
  Product                    Versions     Fixed
  PublishPress Capabilities  unspecified  2.50.0
TIMELINE
  May 21  Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-266 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
AmentoTech Taskbot — WordPress Taskbot plugin <= 6.6 - Privilege Escalation vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0045   37.0     —
AFFECTED
  Product  Versions  Fixed
  Taskbot  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-266 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
BlueGlass Interactive AG Jobs for WordPress — WordPress Jobs for WordPress plugin <= 2.8.2 - Arbitrary File Deletion vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  N  N  H    7.7   .0045   37.0     —
AFFECTED
  Product             Versions  Fixed
  Jobs for WordPress  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-22 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
revmakx WP Duplicate — WordPress WP Duplicate plugin <= 1.1.11 - Arbitrary File Upload vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0045   36.7     —
AFFECTED
  Product       Versions  Fixed
  WP Duplicate  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-434 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
AmentoTech Doctreat — WordPress Doctreat theme <= 1.7.0 - Arbitrary File Upload vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0042   34.5     —
AFFECTED
  Product   Versions  Fixed
  Doctreat  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-434 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Nicu Micle Simple JWT Login — WordPress Simple JWT Login plugin 4.0.0 - Broken Authentication vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0042   34.5     —
AFFECTED
  Product           Versions  Fixed
  Simple JWT Login  4.0.0 –   —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-288 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
baseapp WPBase Cache — WordPress WPBase Cache plugin <= 5.5.6 - Denial of Service Attack vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  N  H    6.5   .0041   33.2     —
AFFECTED
  Product       Versions  Fixed
  WPBase Cache  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-770 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
StylemixThemes Motors — WordPress Motors plugin <= 1.4.124 - Sensitive Data Exposure vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0041   33.0     —
AFFECTED
  Product  Versions  Fixed
  Motors   n/a –     1.4.125
TIMELINE
  Oct 2   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-201 · CNA: Patchstack · CVSS v4.0 · 1 reference · NVD status: Deferred
Royal Plugins SiteVault – Backup, Restore, Migration &amp; Cloning — WordPress SiteVault – Backup, Restore, Migration & Cloning plugin <= 1.5.17 - Sensitive Data Exposure vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0040   31.8     —
AFFECTED
  Product                                               Versions  Fixed
  SiteVault – Backup, Restore, Migration &amp; Cloning  n/a –     1.5.18
TIMELINE
  Oct 3   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-201 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
SourceCodester Drug Recommendation System Auth Guard improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0040   31.7     —
AFFECTED
  Product                     Versions  Fixed
  Drug Recommendation System  1.0 –     —
TIMELINE
  Oct 5   Reserved by CNA
  Oct 6   Published (CNA: VulDB)
CWE-287 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
WC Lovers WooCommerce Multivendor Marketplace – REST API — WordPress WooCommerce Multivendor Marketplace – REST API plugin <= 1.6.3 - Broken Access Control vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0039   31.3     —
AFFECTED
  Product                                         Versions  Fixed
  WooCommerce Multivendor Marketplace – REST API  n/a –     —
TIMELINE
  Apr 7   Reserved by CNA
  Oct 6   Published (CNA: Patchstack)
CWE-862 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-481997.531.3BeplusthemesSermon'eCWE-862WordPress Sermon'e plugin <= 1.0.2 - Broken Access Control vulnerability
CVE-2026-397768.030.2wpshopmartTabsCWE-94WordPress Tabs plugin <= 2.5 - Remote Code Execution (RCE) vulnerability
CVE-2026-325579.330.1Bot Verification bookingwp.com: Verifying that you are not a robot...WooCommerce AppointmentsCWE-89WordPress WooCommerce Appointments plugin <= 5.3.2 - SQL Injection vulnerability
CVE-2026-397469.330.1fs-codeBookneticCWE-89WordPress Booknetic plugin <= 4.8.5 - SQL Injection vulnerability
CVE-2026-851539.328.9SchmoozeSchmooze dating mobile ApplicationCWE-321Information Disclosure Vulnerability in Schmooze dating mobile Application
CVE-2026-397928.627.6Mitchell BennisSimple File ListCWE-22WordPress Simple File List plugin <= 6.3.11 - Arbitrary File Deletion vulnera…
CVE-2026-397725.327.3bestwebsoftCaptcha by BestWebSoftCWE-290WordPress Captcha by BestWebSoft plugin <= 5.2.8 - Bypass Vulnerability vulne…
CVE-2026-1050596.526.7royalnavneetDelete All Comments of wordpressCWE-862WordPress Delete All Comments of wordpress plugin <= 7.1 - Broken Access Cont…
CVE-2026-942939.326.4MurrelektronikSoftware AAS Edge Client all versionsCWE-306Missing authentication for critical function in the aas-edge-client REST API
CVE-2026-254337.126.2Tobias @Saleswonder.bizWP2LEADSCWE-862WordPress WP2LEADS plugin <= 3.5.7 - Broken Access Control vulnerability
CVE-2026-1058092.126.2SourceCodesterSimple Student Information SystemCWE-79SourceCodester Simple Student Information System Profile Field register.php c…
CVE-2026-593587.625.9Cloud FoundryUAACWE-287UAA OAuth Token Endpoint Vulnerability allows user access token reuse for cli…
CVE-2026-254348.525.6Tobias @Saleswonder.bizWP2LEADSCWE-89WordPress WP2LEADS plugin <= 3.5.7 - SQL Injection vulnerability
CVE-2026-397478.525.6WofficeIOWofficeCWE-89WordPress Woffice theme <= 5.4.35 - SQL Injection vulnerability
CVE-2026-397758.825.1DexignZoneJobZilla - Job Board WordPress ThemeCWE-266WordPress JobZilla - Job Board WordPress Theme theme <= 2.2 - Privilege Escal…
CVE-2026-620728.825.1Progress PlannerProgress PlannerCWE-862WordPress Progress Planner plugin <= 1.10.0 - Broken Access Control vulnerabi…
CVE-2026-397979.824.9Data443 Risk Mitigation, Inc.GDPR Framework By Data443CWE-502WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vu…
CVE-2026-397297.224.8WisdmLabsEdwiser BridgeCWE-201WordPress Edwiser Bridge plugin <= 4.3.4 - Sensitive Data Exposure vulnerability
CVE-2026-397626.524.3Patterns In The CloudAutoship Cloud for WooCommerce Subscription ProductsCWE-862WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.17…
CVE-2026-426376.524.3PayplugPayPlug for WooCommerce (Official)CWE-862WordPress PayPlug for WooCommerce (Official) plugin <= 3.1.0 - Settings Chang…
CVE-2026-1057075.523.8n/auptraceCWE-200uptrace user_handler.go Login information exposure
CVE-2026-397546.523.8About PiotnetPiotnet Addons For ElementorCWE-22WordPress Piotnet Addons For Elementor plugin <= 7.1.71 - Arbitrary File Down…
CVE-2026-1057765.523.8bhagya3929Employee-Movement-Tracking-and-Monitoring-Website-for-IOCLCWE-74bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL admin_t…
CVE-2026-397959.323.4brewlabsSendPress NewslettersCWE-89WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerabi…
CVE-2026-424179.323.4reputeinfosystemsARMember PremiumCWE-89WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability
CVE-2026-397517.523.2PayplugPayPlug for WooCommerce (Official)CWE-862WordPress PayPlug for WooCommerce (Official) plugin <= 3.1.0 - Broken Access …
CVE-2026-1043877.222.7blubrryPowerPress PodcastingCWE-862WordPress PowerPress Podcasting plugin <= 11.17.9 - Broken Access Control vul…
CVE-2026-415597.522.4PluginjoySafeSnap – Verified WordPress Backup &amp; RestoreCWE-201WordPress SafeSnap – Verified WordPress Backup & Restore plugin <= 2.1.2 - Se…
CVE-2026-415617.522.4Adrian LinMuseder RestoreOneCWE-201WordPress Museder RestoreOne plugin <= 2.7.276 - Sensitive Data Exposure vuln…
CVE-2026-415627.522.4norvisgabrielNorvis BackupCWE-201WordPress Norvis Backup plugin <= 1.1.0 - Sensitive Data Exposure vulnerability
CVE-2026-424137.522.4DaftPlugSnapshotify &#8211; All-in-One Backup &amp; Restore &amp; MigrateCWE-201WordPress Snapshotify – All-in-One Backup & Restore & Migrate plugin <= 1.3.2…
CVE-2026-1047577.222.5Javier CarazoImport and export users and customersCWE-266WordPress Import and export users and customers plugin <= 2.5.5 - Privilege E…
CVE-2026-1050588.822.4John James JacobyWP User ProfilesCWE-266WordPress WP User Profiles plugin <= 2.7.3 - Privilege Escalation vulnerability
CVE-2026-1050575.322.3Ben MarshallZero SpamCWE-290WordPress Zero Spam plugin <= 5.7.11 - Bypass vulnerability vulnerability
CVE-2026-928216.821.8Red HatRed Hat Enterprise Linux 10CWE-393Sssd: sssd: access control bypass via premature ldap access rule evaluation
CVE-2026-325787.121.5techsupportECPay Ecommerce for WooCommerceCWE-862WordPress ECPay Ecommerce for WooCommerce plugin <= 1.1.2606090 - Broken Acce…
CVE-2026-397307.121.5MarcinWise ChatCWE-862WordPress Wise Chat plugin <= 3.4.2 - Broken Access Control vulnerability
CVE-2026-325807.521.4wpgenieWooCommerce LotteryCWE-89WordPress WooCommerce Lottery plugin <= 2.2.9 - SQL Injection vulnerability
CVE-2026-397649.321.2RadiusThemeRadius Booking — Booking Calendar for Appointments &amp; ServicesCWE-89WordPress Radius Booking — Booking Calendar for Appointments & Services plugi…
CVE-2026-1023877.521.0XServerXserver MigratorCWE-497WordPress Xserver Migrator plugin <= 1.6.6 - Sensitive Data Exposure vulnerab…
CVE-2026-1043857.521.0Adrian TobeyGroundhoggCWE-201WordPress Groundhogg plugin <= 4.8.3 - Sensitive Data Exposure vulnerability
CVE-2026-48897.820.7RDL TechnologieseLoanApp PlatformCWE-89SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies
CVE-2026-397967.520.7Flipper Code – WordPress Development CompanyAdvanced Posts Listing – Show Post List EasilyCWE-862WordPress Advanced Posts Listing – Show Post List Easily plugin <= 1.0.8 - Br…
CVE-2026-415607.520.7wxdlabsWXD Backup LiteCWE-862WordPress WXD Backup Lite plugin <= 1.0.2 - Broken Access Control vulnerability
CVE-2026-665887.520.7Dream-ThemeThe7CWE-862WordPress The7 theme <= 14.2.2 - Broken Access Control vulnerability
CVE-2026-1057752.120.3vllm-projectvLLMCWE-119vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of…
CVE-2026-1050708.820.0Dimitri GrassiSalon booking systemCWE-266WordPress Salon booking system plugin <= 10.31.7 - Privilege Escalation vulne…
CVE-2026-397718.519.7MightyNetworks vs BuddyBossBuddyboss PlatformCWE-89WordPress Buddyboss Platform plugin <= 3.1.0 - SQL Injection vulnerability
CVE-2026-424148.519.7CridioStudioListingProCWE-89WordPress ListingPro plugin <= 2.9.12 - SQL Injection vulnerability
CVE-2026-424168.519.7AndonDesignUDesign CoreCWE-89WordPress UDesign Core plugin <= 4.15.0 - SQL Injection vulnerability
CVE-2026-397876.519.710Web10Web Social Photo FeedCWE-862WordPress 10Web Social Photo Feed plugin <= 1.4.35 - Broken Access Control vu…
CVE-2026-3977310.019.5AmentoTechDoctreat CoreCWE-266WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability
CVE-2026-1044067.319.5picupicuCWE-862WordPress picu plugin <= 3.10.1 - Broken Access Control vulnerability
CVE-2026-1044058.118.9NexcessGiveWPCWE-266WordPress GiveWP plugin <= 4.17.0 - Privilege Escalation vulnerability
CVE-2026-397496.518.6digitalpointApp for Cloudflare®CWE-862WordPress App for Cloudflare® plugin <= 1.10.1 - Broken Access Control vulner…
CVE-2026-1053178.518.4CozmoslabsPaid Member SubscriptionsCWE-89WordPress Paid Member Subscriptions plugin <= 3.1.1 - SQL Injection vulnerabi…
CVE-2026-759627.218.5saadiqbalPost SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile AppCWE-79Post SMTP <= 4.0.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting vi…
CVE-2026-1055715.518.5n/aPickMall LilishopCWE-266PickMall Lilishop Mobile Binding bindMobile improper authorization
CVE-2026-325817.118.0mooberrydreamsMooberry Book ManagerCWE-89WordPress Mooberry Book Manager plugin 4.16.2 - SQL Injection vulnerability
CVE-2026-1057052.118.0SourceCodesterDrug Recommendation SystemCWE-79SourceCodester Drug Recommendation System add_drug.php cross site scripting
CVE-2026-1057082.118.0n/aimgproxyCWE-79imgproxy SVG svg.go sanitizeElement cross site scripting
CVE-2026-98184await17.6LinuxLinux—wifi: mwifiex: prevent authentication frame length truncation
CVE-2026-426387.516.6AwesomemotiveEasy Digital DownloadsCWE-862WordPress Easy Digital Downloads plugin <= 3.7.1 - Broken Access Control vuln…
CVE-2026-575467.516.5Qualcomm, Inc.SnapdragonCWE-126Buffer Over-read in WLAN HAL
CVE-2026-1058076.916.6SourceCodesterSimple Student Information SystemCWE-74SourceCodester Simple Student Information System searchquery.php sql injection
CVE-2026-1058082.016.6SourceCodesterSimple Student Information SystemCWE-79SourceCodester Simple Student Information System searchresults.php clean cros…
CVE-2026-415587.516.1WP SynchroWP Migration Plugin DB & Files – WP SynchroCWE-290WordPress WP Migration Plugin DB & Files – WP Synchro plugin <= 1.16.1 - 2FA …
CVE-2026-1047478.115.9Edge-ThemesHaakenCWE-502WordPress Haaken theme <= 1.5 - PHP Object Injection vulnerability
CVE-2026-942066.315.7danielberkompascloak_ectoCWE-916Cloak PBKDF2 field ignores the configured iteration count and runs only :size…
CVE-2026-1005185.315.8WebFactoryAdvanced Google reCAPTCHACWE-288WordPress Advanced Google reCAPTCHA plugin <= 5.40 - Broken Authentication vu…
CVE-2026-397197.215.6DeKnowsPDF Smart Viewer for ElementorCWE-918WordPress PDF Smart Viewer for Elementor plugin <= 1.0.4 - Server Side Reques…
CVE-2026-397287.215.6instapagedevInstapage PluginCWE-918WordPress Instapage Plugin plugin <= 3.7.2 - Server Side Request Forgery (SSR…
CVE-2026-397566.515.6Wappointment teamWappointmentCWE-639WordPress Wappointment plugin <= 2.7.7 - Insecure Direct Object References (I…
CVE-2026-397986.515.3ThemetechMountTrueBookerCWE-862WordPress TrueBooker plugin <= 1.2.9 - Settings Change vulnerability
CVE-2026-397587.115.1MidtransMidtrans-WooCommerceCWE-79WordPress Midtrans-WooCommerce plugin <= 2.32.3 - Cross Site Scripting (XSS) …
CVE-2026-397667.115.1reputeinfosystemsARFormsCWE-79WordPress ARForms plugin <= 7.1.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-397907.115.1e4jvikwpVikRentCarCWE-79WordPress VikRentCar plugin <= 1.4.6 - Cross Site Scripting (XSS) vulnerability
CVE-2026-424187.115.1SocialrocketSocial RocketCWE-79WordPress Social Rocket plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-426347.115.1bPluginsVideo Background Block – Use video as background in the section.CWE-79WordPress Video Background Block – Use video as background in the section. pl…
CVE-2026-426357.115.1wpgenieWooCommerce Simple AuctionsCWE-79WordPress WooCommerce Simple Auctions plugin <= 3.0.10 - Cross Site Scripting…
CVE-2026-426367.115.1WP Legal PagesWP Cookie Notice for GDPR, CCPA & ePrivacy ConsentCWE-79WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.6 …
CVE-2026-397915.315.0MailjetMailjet Email MarketingCWE-201WordPress Mailjet Email Marketing plugin <= 6.2.3 - Sensitive Data Exposure v…
CVE-2026-397748.814.8Tourfic AI StudioTourfic ProCWE-266WordPress Tourfic Pro plugin <= 1.17.3 - Privilege Escalation vulnerability
CVE-2026-397859.314.6Serhii PasyukGmedia Photo GalleryCWE-89WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability
CVE-2026-415559.314.6Weblizar – WordPress Themes & PluginNewsletter Subscription Form – User Subscriptions Form, Capture EmailCWE-89WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Ema…
CVE-2026-424159.314.6p-themesPorto Theme - FunctionalityCWE-89WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnera…
CVE-2026-415637.514.4Dawer DrewSitemovrCWE-201WordPress Sitemovr plugin <= 1.0.1 - Sensitive Data Exposure vulnerability
CVE-2026-1056112.013.9chillzhuangSpringBladeCWE-266chillzhuang SpringBlade User Detail Endpoint RoleController.java improper aut…
CVE-2026-325697.113.4JoomunitedWP Media folderCWE-79WordPress WP Media folder plugin <= 6.2.2 - Cross Site Scripting (XSS) vulner…
CVE-2026-325707.113.4DaftPlugProgressify - Progressive Web App (PWA)CWE-79WordPress Progressify - Progressive Web App (PWA) plugin <= 1.6.0 - Cross Sit…
CVE-2026-325727.113.4weDevsWP User Frontend ProCWE-79WordPress WP User Frontend Pro plugin <= 4.2.13 - Cross Site Scripting (XSS) …
CVE-2026-325747.113.4EDGARROJASSmart FormsCWE-79WordPress Smart Forms plugin <= 2.6.104 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-325757.113.4Fantastic PluginsSUMO Affiliates ProCWE-79WordPress SUMO Affiliates Pro plugin <= 11.7.0 - Cross Site Scripting (XSS) v…
CVE-2026-325777.113.4N-MediaFrontend File ManagerCWE-79WordPress Frontend File Manager plugin <= 23.6 - Cross Site Scripting (XSS) v…
CVE-2026-397207.113.4mapsterMapster WP MapsCWE-79WordPress Mapster WP Maps plugin <= 2.0.4 - Cross Site Scripting (XSS) vulner…
CVE-2026-397227.113.4VibeThemesWPLMSCWE-79WordPress WPLMS theme <= 4.972 - Reflected Cross Site Scripting (XSS) vulnera…
CVE-2026-397247.113.4veppaHTTP Requests ManagerCWE-79WordPress HTTP Requests Manager plugin <= 1.3.11 - Cross Site Scripting (XSS)…
CVE-2026-397267.113.4Lumise NEOLumise Product DesignerCWE-79WordPress Lumise Product Designer plugin <= 2.1.1 - Cross Site Scripting (XSS…
CVE-2026-397317.113.4code4lifeDatabase for CF7CWE-79WordPress Database for CF7 plugin <= 1.2.6 - Cross Site Scripting (XSS) vulne…
CVE-2026-397457.113.4bestweblayoutContact Form to DB by BestWebSoftCWE-79WordPress Contact Form to DB by BestWebSoft plugin <= 1.7.6 - Cross Site Scri…
CVE-2026-397487.113.4ThemeMoveEduMallCWE-79WordPress EduMall theme <= 4.5.3 - Reflected Cross Site Scripting (XSS) vulne…
CVE-2026-397507.113.4weDevsStoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side CartCWE-79WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, D…
CVE-2026-1043947.113.4Syed BalkhiCharitableCWE-79WordPress Charitable plugin <= 1.8.12.3 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-1043957.113.4picupicuCWE-79WordPress picu plugin <= 3.10.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-1048147.113.4epiphytForm BlockCWE-79WordPress Form Block plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-1050617.113.4Bởi brandtossWP MailsterCWE-79WordPress WP Mailster plugin <= 1.9.0.0 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-955948.113.4Cozy Vision Technologies Pvt. Ltd.SMS Alert Order NotificationsCWE-266WordPress SMS Alert Order Notifications plugin <= 4.0.0 - Privilege Escalatio…
CVE-2026-1056212.112.6jishenghuajshERPCWE-266jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAcco…
CVE-2026-955267.312.5RealMag777BEARCWE-862WordPress BEAR plugin <= 1.2.2 - Broken Access Control vulnerability
CVE-2026-1055732.112.5newbee-ltdnewbee-mallCWE-840newbee-ltd newbee-mall Shopping Cart Quantity updateAccountHeadAndDetail logi…
CVE-2026-1056102.012.3chillzhuangSpringBladeCWE-266chillzhuang SpringBlade Parameter Submit Management ParamController.java impr…
CVE-2026-1057032.012.3PHPGurukulUser Registration & Login and User Management SystemCWE-285PHPGurukul User Registration & Login and User Management System Change Passwo…
CVE-2026-1029158.512.0Marco van WierenWPO365CWE-862WordPress WPO365 plugin <= 44.1 - Broken Access Control vulnerability
CVE-2026-98167await12.1LinuxLinux—smb: client: fix server->total_read for compound encrypted PDUs
CVE-2026-397886.512.0Shamim HasanFront End PMCWE-79WordPress Front End PM plugin <= 11.4.6 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-1055722.111.8n/aPickMall LilishopCWE-285PickMall Lilishop Buyer Invoice List receipt authorization
CVE-2026-98240await11.8LinuxLinux—net: ip_tunnel: initialize `options_len` before referencing options
CVE-2026-1040385.911.8Red HatRed Hat Enterprise Linux 10CWE-476Sssd: sssd: denial of service via missing sid extension in certificate mapping
CVE-2026-983117.811.4LinuxLinux—wifi: virt_wifi: don't transfer operstate before register
CVE-2026-983207.811.3LinuxLinux—netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-981977.011.4LinuxLinux—hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
CVE-2026-982527.011.4LinuxLinux—RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
CVE-2026-98188await11.4LinuxLinux—wifi: p54: validate curve data length in the calibration curve converters
CVE-2026-98209await11.4LinuxLinux—mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
CVE-2026-98233await11.4LinuxLinux—net/packet: clear RX owner on VNET header error
CVE-2026-98234await11.4LinuxLinux—net/sched: hhf: cap hh_flows_limit at change time
CVE-2026-98275await11.4LinuxLinux—net: ethernet: cortina: Ack RX overrun interrupt correctly
CVE-2026-98319await11.3LinuxLinux—drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
CVE-2026-98322await11.3LinuxLinux—netfilter: nft_nat: fully initialise new_addr in netmap setup
CVE-2026-98214await11.3LinuxLinux—selinux: recheck intermediate backing files on mprotect()
CVE-2026-981718.810.8LinuxLinux—smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-981697.110.8LinuxLinux—smb: client: fix potential OOB read in smb3_enum_snapshots()
CVE-2026-98172await10.8LinuxLinux—smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
CVE-2026-98181await10.8LinuxLinux—drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
CVE-2026-98199await10.8LinuxLinux—hwmon: (pmbus/core) increase number of phases and add new mask
CVE-2026-98213await10.8LinuxLinux—mmc: core: Cancel SDIO IRQ work before freeing host
CVE-2026-98221await10.8LinuxLinux—KEYS: trusted: Fix tpm2_load_cmd() boundary check
CVE-2026-98247await10.8LinuxLinux—Bluetooth: hci_codec: validate vendor codec count length
CVE-2026-98264await10.8LinuxLinux—ALSA: virtio: reset device before deleting virtqueues
CVE-2026-325716.510.4ColabrioOhio ExtraCWE-79WordPress Ohio Extra plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-397276.510.4Saravana Kumar KWC Fields FactoryCWE-79WordPress WC Fields Factory plugin <= 4.1.12 - Cross Site Scripting (XSS) vul…
CVE-2026-982297.810.1LinuxLinux—xfrm: save input state data before secpath resets
CVE-2026-981737.510.0LinuxLinux—smb: client: fix use-after-free of iface in cifs_try_adding_channels()
CVE-2026-981757.510.0LinuxLinux—smb: client: cancel reconnect work in clean_demultiplex_info()
CVE-2026-982307.010.1LinuxLinux—xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
CVE-2026-98168await10.0LinuxLinux—smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
CVE-2026-98170await10.0LinuxLinux—smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
CVE-2026-98211await10.1LinuxLinux—mmc: mmci: Fix use-after-free in busy-timeout work
CVE-2026-98212await10.1LinuxLinux—mmc: hsq: Fix use-after-free in retry work
CVE-2026-98215await10.1LinuxLinux—selinux: preserve user SID across nested backing files
CVE-2026-98222await10.1LinuxLinux—KEYS: encrypted: fix integer overflow of datablob_len
CVE-2026-98231await10.1LinuxLinux—xfrm: serialize state GC with device state flush
CVE-2026-98245await10.1LinuxLinux—btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
CVE-2026-98248await10.1LinuxLinux—arm64: percpu: Fix LSE operations on {8,16}-bit types
CVE-2026-98266await10.1LinuxLinux—ALSA: core: Fix potential UAF after asynchronous card release
CVE-2026-973006.59.8ArrayticsWP Event SolutionCWE-799WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerab…
CVE-2026-981807.19.8LinuxLinux—drm/msm: RCU-free the scheduler-containing ring and VM objects
CVE-2026-98244await9.8LinuxLinux—btrfs: clear free space tree creation state on rebuild failure
CVE-2026-98259await9.8LinuxLinux—fs/dax: check zero or empty entry before converting xarray entry
CVE-2026-98296await9.8LinuxLinux—Bluetooth: btintel_pcie: validate TX skb length in send_sync
CVE-2026-98272await9.4LinuxLinux—net: mvpp2: prevent buffer overflow in page_pool allocation
CVE-2026-397237.59.2Green InvoiceMorning for WooCommerceCWE-862WordPress Morning for WooCommerce plugin <= 2.4.1 - Broken Access Control vul…
CVE-2026-397897.59.2WP Manage NinjaFluent Affiliate ProCWE-862WordPress Fluent Affiliate Pro plugin <= 1.6.4 - Broken Access Control vulner…
CVE-2026-1050727.59.2WP Manage NinjaFluentBooking ProCWE-862WordPress FluentBooking Pro plugin < 2.5.0 - Broken Access Control vulnerability
CVE-2026-325766.59.1ZWEISCHNEIDERFaktur Pro for WooCommerceCWE-639WordPress Faktur Pro for WooCommerce plugin <= 3.2.2 - Insecure Direct Object…
CVE-2026-1054722.19.0girishsarafOnline-Appointment-Booking-SystemCWE-74girishsaraf Online-Appointment-Booking-System Booking book.php sql injection
CVE-2026-981667.88.7LinuxLinux—drm/ttm: fix swapped-out resources never leaving their bulk_move range
CVE-2026-98165await8.7LinuxLinux—drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only
CVE-2026-98177await8.7LinuxLinux—drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
CVE-2026-98178await8.7LinuxLinux—drm/amdgpu: Skip KFD mapping clear before initialization
CVE-2026-98220await8.7LinuxLinux—sched_ext: Fix NULL sched deref in kfunc sub-sched error paths
CVE-2026-98242await8.7LinuxLinux—dma-buf: Fix silent overflow for phys vec to sgt
CVE-2026-98268await8.7LinuxLinux—perf: Fix null pointer access in is_include_guest_event()
CVE-2026-98350await8.5LinuxLinux—wifi: brcmfmac: cyw: pass PMKID to firmware if present
CVE-2026-1040335.48.2Red HatRed Hat Enterprise Linux 10CWE-193Sssd: sssd: access control bypass via improper ldap shadow expiration check
CVE-2026-973084.88.1WebFactoryLogin LockdownCWE-290WordPress Login Lockdown plugin <= 2.17 - Bypass Vulnerability vulnerability
CVE-2026-397687.18.0CleanTalk IncSecurity & Malware scan by CleanTalkCWE-79WordPress Security & Malware scan by CleanTalk plugin <= 2.189 - Cross Site S…
CVE-2026-397787.18.0themeansarAnsar Import – One Click Starter Sites – for Elementor &amp; ThemesCWE-79WordPress Ansar Import – One Click Starter Sites – for Elementor & Themes plu…
CVE-2026-397807.18.0YouzifyYouzifyCWE-79WordPress Youzify plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-397817.18.0Dan RossiterDocument GalleryCWE-79WordPress Document Gallery plugin <= 5.1.1 - Cross Site Scripting (XSS) vulne…
CVE-2026-397847.18.0nicdarkHotel BookingCWE-79WordPress Hotel Booking plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-408067.18.0Plugin DevsBlog, Posts and Category Filter for ElementorCWE-79WordPress Blog, Posts and Category Filter for Elementor plugin <= 2.1.0 - Cro…
CVE-2026-408077.18.0AmanCF7 Views &#8211; Complete Entry Management for Contact Form 7CWE-79WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= …
CVE-2026-946757.18.0Fluent Forms Free vs ProFluent Forms Pro Add On PackCWE-79WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Cross Site Scriptin…
CVE-2026-1053055.47.7Red HatRed Hat Build of KeycloakCWE-287Keycloak-services: keycloak-services: device authorization grant bypasses per…
CVE-2026-98277await7.5LinuxLinux—eth: fbnic: ring the doorbell if a burst ends in a drop
CVE-2026-593576.57.4Cloud FoundryUAACWE-345Self-UAA OIDC Configuration allows JWT injection to establish unauthorized se…
CVE-2026-983239.87.3LinuxLinux—RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-982828.87.3LinuxLinux—powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-983398.87.3LinuxLinux—wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-982417.87.3LinuxLinux—ipv6: xfrm: use full sockets in local error paths
CVE-2026-982517.87.3LinuxLinux—openvswitch: avoid reallocating confirmed conntrack labels
CVE-2026-982537.87.3LinuxLinux—RDMA/ucma: Serialize join and leave on copy_to_user failure
CVE-2026-982767.87.3LinuxLinux—net: lock the socket in sock_gettstamp()
CVE-2026-982577.57.3LinuxLinux—rds: ib: use rds_conn_drop() on protocol version mismatch
CVE-2026-98185await7.3LinuxLinux—wifi: mwifiex: validate scan response extents
CVE-2026-98186await7.3LinuxLinux—wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length
CVE-2026-98187await7.3LinuxLinux—wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
CVE-2026-98189await7.3LinuxLinux—wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext()
CVE-2026-98190await7.3LinuxLinux—wifi: wilc1000: fix out-of-bounds read in P2P public action frames
CVE-2026-98191await7.3LinuxLinux—wifi: wlcore: release runtime PM ref on regdomain config failure
CVE-2026-98194await7.3LinuxLinux—wifi: libertas_tf: fix UAF in lbtf_free_adapter()
CVE-2026-98195await7.3LinuxLinux—wifi: iwlegacy: fix broadcast stations deallocation
CVE-2026-98196await7.3LinuxLinux—wifi: brcmsmac: fix UAF in brcms_free_timer()
CVE-2026-98201await7.3LinuxLinux—Input: zero ff_effect before compat copy in input_ff_effect_from_user
CVE-2026-98202await7.3LinuxLinux—Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
CVE-2026-98203await7.3LinuxLinux—Input: soc_button_array - check btns_desc->package.count
CVE-2026-98204await7.3LinuxLinux—Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
CVE-2026-98205await7.3LinuxLinux—Input: evdev - zero absinfo before partial copy in EVIOCSABS
CVE-2026-98207await7.3LinuxLinux—mmc: spi: reset bytes_xfered before retrying CRC failures
CVE-2026-98208await7.3LinuxLinux—mmc: sdio_uart: fix xmit_fifo leak when the port table is full
CVE-2026-98210await7.3LinuxLinux—mmc: mxcmmc: cancel data work and watchdog on remove
CVE-2026-98217await7.3LinuxLinux—IB/mlx4: Fix use-after-free on pkey sysfs registration failure
CVE-2026-98255await7.3LinuxLinux—tcp: exclude old ACKs from tcp fast path
CVE-2026-98262await7.3LinuxLinux—ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
CVE-2026-98298await7.3LinuxLinux—dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
CVE-2026-98299await7.3LinuxLinux—tcp: do not let tcp_rmem be set below 4096
CVE-2026-98302await7.3LinuxLinux—net: fddi: skfp: fix NULL deref when setting the MAC address while down
CVE-2026-98306await7.3LinuxLinux—seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
CVE-2026-98308await7.3LinuxLinux—ALSA: hda: trace PCM open only after assigning a stream
CVE-2026-98314await7.3LinuxLinux—ALSA: pcm: set timer->private_data before registering the PCM timer
CVE-2026-98317await7.3LinuxLinux—neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
CVE-2026-98340await7.3LinuxLinux—wifi: cfg80211: only group hidden BSSes with beacon entries
CVE-2026-98342await7.3LinuxLinux—dmaengine: wait for RCU readers before releasing dma_device
CVE-2026-98343await7.3LinuxLinux—dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
CVE-2026-98344await7.3LinuxLinux—dmaengine: Fix device kref underflow in dma_chan_put()
CVE-2026-98345await7.3LinuxLinux—wifi: cfg80211: check IP header size in cfg80211_classify8021d()
CVE-2026-98347await7.3LinuxLinux—IB/IPoIB: Avoid restoring OPER_UP after multicast flush
CVE-2026-982838.86.9LinuxLinux—KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-982398.16.9LinuxLinux—net: lan743x: fix RX checksum use-after-free
CVE-2026-983697.87.0LinuxLinux—xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_tr…
CVE-2026-982907.56.9LinuxLinux—Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
CVE-2026-1046707.16.9ThimPressLearnPressCWE-79WordPress LearnPress plugin <= 4.4.9 - Cross Site Scripting (XSS) vulnerability
CVE-2026-1046727.16.9NexcessGiveWPCWE-79WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-983317.06.9LinuxLinux—wifi: mac80211: unlist vifs when their netdev is unregistered
CVE-2026-98227await6.9LinuxLinux—memstick: ms_block: destroy io_queue workqueue on removal
CVE-2026-98236await6.9LinuxLinux—net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value
CVE-2026-98237await6.9LinuxLinux—net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
CVE-2026-98238await6.9LinuxLinux—net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()
CVE-2026-98246await6.9LinuxLinux—Bluetooth: hci_sync: Serialize local codec list cleanup
CVE-2026-98249await6.9LinuxLinux—arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
CVE-2026-98287await6.9LinuxLinux—pppoatm: ensure a writable skb header and linear data
CVE-2026-98301await6.9LinuxLinux—net: bridge: mst: move switchdev call outside rcu
CVE-2026-98303await6.9LinuxLinux—ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
CVE-2026-98312await6.9LinuxLinux—ALSA: 6fire: fix OOB write from device-reported iso length
CVE-2026-98316await6.9LinuxLinux—ALSA: bcd2000: Fix race between rawmidi and disconnect
CVE-2026-98325await6.9LinuxLinux—wifi: mac80211: set up the TX info early to fix failure paths
CVE-2026-98326await6.9LinuxLinux—wifi: mac80211: mesh: release the channel if start fails
CVE-2026-98328await6.9LinuxLinux—wifi: mac80211: add HE 6 GHz capability in the scan elems len
CVE-2026-98278await6.8LinuxLinux—net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check
CVE-2026-983607.06.5LinuxLinux—RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
CVE-2026-98300await6.6LinuxLinux—tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_r…
CVE-2026-982618.16.4LinuxLinux—cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-982547.86.4LinuxLinux—swiotlb: use the adjusted address for the highmem page lookup
CVE-2026-982607.86.4LinuxLinux—exec: Cleanup POSIX timers right after de_thread()
CVE-2026-981747.56.4LinuxLinux—smb: client: fix rlist race and missing initialization
CVE-2026-982167.16.4LinuxLinux—IB/hfi1: Fix the PIO_CRED credit-return mmap
CVE-2026-98179await6.4LinuxLinux—drm/amdgpu: fix rmmio iounmap skipped on device removal
CVE-2026-98182await6.4LinuxLinux—wifi: mac80211: refuse to make a monitor active when it has no queue
CVE-2026-98192await6.4LinuxLinux—wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown
CVE-2026-98193await6.4LinuxLinux—wifi: libipw: reject TKIP frames without a full MIC
CVE-2026-98198await6.4LinuxLinux—hwmon: (pwm-fan) Stop RPM timer before freeing tach data
CVE-2026-98200await6.4LinuxLinux—hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
CVE-2026-98206await6.4LinuxLinux—Input: cyttsp5 - clamp the HID report size before memcpy
CVE-2026-98218await6.4LinuxLinux—i2c: atr: fix dangling adapter pointer on add failure
CVE-2026-98232await6.4LinuxLinux—scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
CVE-2026-98235await6.4LinuxLinux—net/sched: act_api: release tail references on DELACTION failure
CVE-2026-98263await6.4LinuxLinux—ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
CVE-2026-98265await6.4LinuxLinux—ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity
CVE-2026-98267await6.4LinuxLinux—9p: Fix v9fs_issue_write() to update i_size and remote_i_size
CVE-2026-98269await6.4LinuxLinux—btrfs: abort transaction on failure to update inode for hole punching and ref…
CVE-2026-98270await6.4LinuxLinux—drm/amdgpu: check ras and obj before dereference
CVE-2026-98271await6.4LinuxLinux—net: skbuff: do not leave stale header offsets after pskb_carve()
CVE-2026-98291await6.4LinuxLinux—Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
CVE-2026-98293await6.4LinuxLinux—Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()
CVE-2026-98295await6.4LinuxLinux—Bluetooth: coredump: Quiesce dump work on unregister
CVE-2026-98297await6.4LinuxLinux—Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
CVE-2026-98307await6.4LinuxLinux—wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()
CVE-2026-98309await6.4LinuxLinux—drm/vc4: Use managed KMS polling to fix UAF on unbind
CVE-2026-98327await6.4LinuxLinux—wifi: mac80211: mesh: reset the CSA state when leaving
CVE-2026-98329await6.4LinuxLinux—wifi: mac80211: don't allow injecting frames wider than the chanctx
CVE-2026-98334await6.4LinuxLinux—wifi: mac80211: reset state when starting AP fails
CVE-2026-98335await6.4LinuxLinux—wifi: mac80211: abort chanswitch when leaving a mesh
CVE-2026-98336await6.4LinuxLinux—wifi: mac80211: don't offload TC setup on AP_VLAN interfaces
CVE-2026-98337await6.4LinuxLinux—wifi: mac80211: don't start a ROC while scanning
CVE-2026-98346await6.4LinuxLinux—wifi: cfg80211: don't get the radio mask for netdev-less wdevs
CVE-2026-325826.56.3iatoaiIATO MCPCWE-862WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability
CVE-2026-982567.86.2LinuxLinux—signal: Prevent exec() race
CVE-2026-982587.86.2LinuxLinux—posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-982817.86.2LinuxLinux—futex: Also allocate private hash on vfork()
CVE-2026-983417.86.2LinuxLinux—wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-983307.06.2LinuxLinux—wifi: cfg80211: get the wiphy out of a dying network namespace
CVE-2026-98223await6.2LinuxLinux—mm: filemap: retain mapped dropbehind folios
CVE-2026-98224await6.2LinuxLinux—mm/vma: correctly unaccount on mmap_prepare() failure
CVE-2026-98226await6.2LinuxLinux—mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count
CVE-2026-98273await6.2LinuxLinux—x86/kprobes: Fix crash when probing CS CALL instructions
CVE-2026-98274await6.2LinuxLinux—net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
CVE-2026-98279await6.2LinuxLinux—btrfs: handle lack of space when cleaning up verity items
CVE-2026-98286await6.2LinuxLinux—drop_monitor: use timer_shutdown_sync() to prevent timer rearming during tear…
CVE-2026-98289await6.2LinuxLinux—af_unix: Unify scc_index when finalising SCC in __unix_walk_scc().
CVE-2026-98294await6.2LinuxLinux—Bluetooth: hci_qca: Do not write to the serial port after it is closed
CVE-2026-98304await6.2LinuxLinux—net: bcmgenet: restore the hardware filters on open
CVE-2026-98313await6.2LinuxLinux—drm/msm/dp: skip PUSH_IDLE when the link was never enabled
CVE-2026-98321await6.2LinuxLinux—netfilter: nf_nat: unregister and release hooks on error
CVE-2026-983677.86.0LinuxLinux—RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
CVE-2026-983487.15.9LinuxLinux—wifi: libipw: reject too-short association responses
CVE-2026-983497.16.0LinuxLinux—wifi: libipw: reject too-short beacon and probe responses
CVE-2026-98351await6.0LinuxLinux—wifi: virt_wifi: free skb when disconnected
CVE-2026-98354await5.9LinuxLinux—RDMA/mad: Fix receive buffer leak when PKey enforcement fails
CVE-2026-98362await6.0LinuxLinux—clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
CVE-2026-98363await6.0LinuxLinux—firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
CVE-2026-98370await5.9LinuxLinux—xfrm: fix compat ALLOCSPI request use-after-free
CVE-2026-1058796.55.9CrocoblockJetElements For ElementorCWE-79WordPress JetElements For Elementor plugin <= 2.9.2.2 - Cross Site Scripting …
CVE-2026-983687.85.6LinuxLinux—esp: downgrade zerocopy managed frags before mutating skb frags
CVE-2026-983597.05.5LinuxLinux—RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
CVE-2026-98352await5.5LinuxLinux—RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
CVE-2026-983659.85.1LinuxLinux—RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-983578.15.1LinuxLinux—IB/isert: wait for deferred control PDU completions before releasing the conn…
CVE-2026-98358await5.1LinuxLinux—IB/iser: reject a remote invalidation of an unregistered direction
CVE-2026-983057.84.8LinuxLinux—net: dsa: mxl862xx: disable the stats poll on teardown
CVE-2026-983157.84.8LinuxLinux—ntfs: protect runlist updates with the runlist lock
CVE-2026-983187.84.8LinuxLinux—smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-983247.84.8LinuxLinux—dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-983617.84.8LinuxLinux—RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths
CVE-2026-982437.14.8LinuxLinux—dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3
CVE-2026-98176await4.8LinuxLinux—drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc
CVE-2026-98183await4.8LinuxLinux—wifi: mac80211: avoid out-of-bounds read for empty PREQ elements
CVE-2026-98219await4.8LinuxLinux—sched_ext: Close the pre-enable ops error claim window
CVE-2026-98225await4.8LinuxLinux—mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem
CVE-2026-98250await4.8LinuxLinux—nfsd: fix handling of NFSEXP_PNFS in the netlink codepath
CVE-2026-98280await4.8LinuxLinux—drm/xe/i2c: Disable IRQ on unbind
CVE-2026-98284await4.8LinuxLinux—netlink: do not free nlk->groups while lockless readers can use it
CVE-2026-98285await4.8LinuxLinux—net: bridge: vlan: fix bugs caused by switchdev deletion errors
CVE-2026-98288await4.8LinuxLinux—net: stmmac: fix TSO header length truncation
CVE-2026-98292await4.8LinuxLinux—Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access
CVE-2026-98310await4.8LinuxLinux—drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory
CVE-2026-98332await4.8LinuxLinux—wifi: mac80211: only operate on TDLS peers in the TDLS code
CVE-2026-98333await4.8LinuxLinux—wifi: mac80211: reset the LED state when ifup fails
CVE-2026-98338await4.8LinuxLinux—wifi: cfg80211: ibss: ref BSS entry for joined event
CVE-2026-98356await4.7LinuxLinux—RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup
CVE-2026-98371await4.7LinuxLinux—xfrm: iptfs: fix runt reassembly panic from short inner tot_len
CVE-2026-98372await4.7LinuxLinux—xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()
CVE-2026-1057062.14.4SourceCodesterDrug Recommendation SystemCWE-352SourceCodester Drug Recommendation System cross-site request forgery
CVE-2026-983667.84.2LinuxLinux—RDMA/rxe: validate access flags before swapping the MR's PD
CVE-2026-982287.84.1LinuxLinux—mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-983647.83.7LinuxLinux—xfrm: hold net_device reference under RCU in bundle creation
CVE-2026-395994.33.8wallstrdevWDS MCP Content ManagerCWE-862WordPress WDS MCP Content Manager plugin <= 3.10.4 - Broken Access Control vu…
CVE-2026-98353await3.7LinuxLinux—RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables
CVE-2026-98355await3.7LinuxLinux—RDMA/rtrs: guard against null kobj name
CVE-2026-397607.13.3Creative interactive mediaReal 3D FlipBookCWE-79WordPress Real 3D FlipBook plugin <= 5.5 - Cross Site Scripting (XSS) vulnera…
CVE-2026-1033467.13.3TomlisterPayflex Payment GatewayCWE-79WordPress Payflex Payment Gateway plugin <= 2.7.1 - Cross Site Scripting (XSS…
CVE-2026-867865.33.3UnknownSlider ProCWE-200Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro…
CVE-2026-942996.52.6Unknownelegro Crypto PaymentCWE-863elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Chang…
CVE-2026-892895.32.6UnknownFast CourierCWE-862Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-st…
CVE-2026-942705.32.6UnknownDeema Payment GatewayCWE-287Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Man…
CVE-2026-942715.32.6UnknownDeema Payment GatewayCWE-287Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery…
CVE-2026-942785.52.4UnknownFile Media RenamerCWE-284File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment…
CVE-2026-1043805.32.2—PunkCWE-1385Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests …
CVE-2026-575457.81.6Qualcomm, Inc.SnapdragonCWE-822Untrusted Pointer Dereference in Graphics
CVE-2026-1040446.21.6Red HatRed Hat Enterprise Linux 10CWE-476Sssd: sssd: denial of service via crafted passkey kerberos authentication req…
CVE-2026-951058.21.4danielberkompascloakCWE-649Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plainte…
CVE-2026-252696.71.4Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Camera Driver
CVE-2026-252706.71.4Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Camera Driver
CVE-2026-252726.71.4Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Camera Driver
CVE-2026-252736.71.4Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in Camera Driver
CVE-2026-252746.71.4Qualcomm, Inc.SnapdragonCWE-416Use After Free in Windows WLAN Host
CVE-2026-252917.81.2Qualcomm, Inc.SnapdragonCWE-416Use After Free in Graphics
CVE-2026-575377.81.2Qualcomm, Inc.SnapdragonCWE-416Use After Free in DSP Service
CVE-2026-575547.81.2Qualcomm, Inc.SnapdragonCWE-416Use After Free in DSP Service
CVE-2026-575557.81.2Qualcomm, Inc.SnapdragonCWE-416Use After Free in DSP Service
CVE-2026-575597.81.2Qualcomm, Inc.SnapdragonCWE-416Use After Free in DSP_Services
CVE-2026-1040425.51.1Red HatRed Hat Enterprise Linux 10CWE-125Sssd: sssd: denial of service via out-of-bounds read in pam responder
CVE-2026-1040394.70.9Red HatRed Hat Enterprise Linux 10CWE-825Sssd: sssd: denial of service via stale connection state reuse in pam gssapi …
CVE-2026-252677.80.7Qualcomm, Inc.SnapdragonCWE-862Missing Authorization in Core
CVE-2026-1040404.40.7Red HatRed Hat Enterprise Linux 10CWE-140Sssd: sssd: information disclosure via odata injection in entra id lookups

Results continue: ranks 401–1020.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-10-06 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.