boxscore/security
Sunday, May 31, 2026 · all times UTC← 2026-05-30 · archive · 2026-06-01 →

51 CVEs published May 31, 2026: 0 critical, 19 high, 10 medium, 22 low; 0 in KEV; 0 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 26 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published3242437210262563
KEV catalog size1670

142 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux6409667961626912720.27.8.0013+475
microsoft170490433281020378275.57.8.0045-17
google168174101203567442.38.3.0023+167
red hat4164827263400.07.2.0037+27
apple204701227193714.96.2.0034+20
canonical14140455000.05.5.0009+14
freebsd770520000.07.8.0020+7
suse220200000.08.2.0020+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco513312096861.58.6.1247+2
checkpoint660330300.06.5.0338+6
fortinet16130028350.07.9.4330-2
ivanti25010033480.08.8.8056+1
f52320007133.39.2.0996+2
ubiquiti231200400.08.8.0068+2
palo alto networks220000142100.0.6299+2
broadcom02000042100.0.19900
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache21324151204013.17.4.0064+12
gitlab7901604222.24.3.0032+7
mozilla6632101300.08.8.0042+6
drupal5511305120.05.1.0026+5
docker330300100.08.8.0022+3
github221100000.08.1.0347+2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm49491024150700.07.5.0028+49
oracle2527815404000.08.1.0027+25
progress440400900.07.5.0036+4
adobe14010075375.08.6.2776-2
veeam331200400.08.6.0040+3
solarwinds031000113100.09.8.83620
zohocorp220110000.07.1.0104+2
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology181823103000.05.6.0025+18
d-link23011026133.37.3.0059+1
hitachi energy220020000.05.7.0014+2
siemens110100100.08.7.0032+1
hikvision01000021100.01.00000
dahua000000200
qnap000000800
schneider electric000000100
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax5151032019100.07.4.0059+51
concrete cms4444191321000.05.7.0015+44
open ises4444221210000.07.1.0021+44
helmholz424203930000.07.1.0026+42
mb connect line424203930000.07.1.0026+42
totolink353502609000.08.9.0191+35
netatalk3333113910000.06.4.0030+33
nvidia333381870000.07.8.0038+33

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4684010.0.0073
Most disclosures (vendor)
VendorCVEs
linux579
microsoft170
google168
edimax51
ibm49
concrete cms44
open ises44
helmholz42
mb connect line42
red hat41
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google4
ivanti4
synacor4
adobe3
fortinet3
smartertools3
solarwinds3
Most-affected ecosystems
EcosystemAdvisories
Maven12
Packagist7
PyPI2
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2025-34291Langflow0
CVE-2026-0257Palo Alto Networks0
CVE-2026-0300Palo Alto Networks0
CVE-2026-20182Cisco0
CVE-2026-34926Trend Micro, Inc.0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171656
CVE-2021-27102Accellion2021-11-171656
CVE-2021-27101Accellion2021-11-171656
CVE-2021-27103Accellion2021-11-171656
CVE-2021-21017Adobe2021-11-171656
CVE-2021-28550Adobe2021-11-171656
CVE-2021-42013Apache2021-11-171656
CVE-2021-41773Apache2021-11-171656
CVE-2021-30858Apple2021-11-171656
CVE-2021-30860Apple2021-11-171656

Transactions

DUE DATE PASSEDCVE-2026-8398 (Daemon Tools Lite). CISA remediation deadline was May 30, 2026; still in catalog.

Yesterday's Results

51 CVEs published. 25 box scores, 26 table rows — nothing truncated.

Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0734   93.9     —
AFFECTED
  Product  Versions               Fixed
  N300RH   6.1c.1353_B20190305 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 7 references · NVD status: Deferred
TRENDnet TEW-432BRP formSetWlanEncrypt stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0320   87.1     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Deferred
Edimax BR-6478AC POST Request formWlbasic command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0107   62.1     —
AFFECTED
  Product    Versions  Fixed
  BR-6478AC  1.23 –    —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 4 references · NVD status: Deferred
TRENDnet TEW-432BRP formWlanSetup command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0107   62.1     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
TRENDnet TEW-432BRP formSysCmd command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0105   61.4     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
Tenda W12 httpd cgiSysTimeInfoSet stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0050   40.8     —
AFFECTED
  Product  Versions         Fixed
  W12      3.0.0.7(4763) –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 6 references · NVD status: Deferred
Tenda W12 httpd set_local_time_0 stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0050   40.8     —
AFFECTED
  Product  Versions         Fixed
  W12      3.0.0.7(4763) –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 6 references · NVD status: Deferred
Tenda W12 httpd cgistaKickOff stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0048   39.1     —
AFFECTED
  Product  Versions         Fixed
  W12      3.0.0.7(4763) –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 6 references · NVD status: Deferred
Tenda W12 httpd cgiWifiMacFilterSet stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0048   39.1     —
AFFECTED
  Product  Versions         Fixed
  W12      3.0.0.7(4763) –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 6 references · NVD status: Deferred
TRENDnet TEW-432BRP formSetEnableWizard stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.8     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 4 references · NVD status: Deferred
TRENDnet TEW-432BRP formResetStatistic stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.8     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 4 references · NVD status: Deferred
TRENDnet TEW-432BRP formSetPassword stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.8     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 4 references · NVD status: Deferred
Edimax BR-6478AC POST Request formWanTcpipSetup stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.8     —
AFFECTED
  Product    Versions  Fixed
  BR-6478AC  1.23 –    —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 4 references · NVD status: Deferred
TRENDnet TEW-432BRP formSysCmd stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.8     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Deferred
TRENDnet TEW-432BRP formWlanSetup stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.8     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Deferred
wpengine Advanced Custom Fields (ACF®) — Advanced Custom Fields (ACF®) <= 6.8.1 - Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0046   38.3     —
AFFECTED
  Product                        Versions     Fixed
  Advanced Custom Fields (ACF®)  unspecified  —
TIMELINE
  May 12  Reserved by CNA
  May 31  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 3 references · NVD status: Deferred
TRENDnet TEW-432BRP formPortFw stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0046   38.2     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 4 references · NVD status: Deferred
TRENDnet TEW-432BRP formSysLog stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0046   38.2     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 4 references · NVD status: Deferred
Edimax BR-6478AC POST Request formUSBAccount buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0046   38.2     —
AFFECTED
  Product    Versions  Fixed
  BR-6478AC  1.23 –    —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · 4 references · NVD status: Deferred
Edimax BR-6478AC POST Request formUSBFolder buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0046   38.2     —
AFFECTED
  Product    Versions  Fixed
  BR-6478AC  1.23 –    —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · 4 references · NVD status: Deferred
n/a Open5GS — Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0042   35.0     —
AFFECTED
  Product  Versions  Fixed
  Open5GS  2.7.0 –   —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-287 · CNA: VulDB · 8 references · NVD status: Deferred
OUSL-GROUP-BrinaryBrains School Student Management System MY_Controller Login.php sign_auth_cookie improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0041   34.0     —
AFFECTED
  Product                           Versions                                    Fixed
  School Student Management System  1e70e5ad1125b86dca4ee086eb6bb121f17708b6 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-287 · CNA: VulDB · 4 references · NVD status: Deferred
YVES Sereal::Decoder — Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  N  H    8.1   .0040   33.1     —
AFFECTED
  Product          Versions     Fixed
  Sereal::Decoder  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  May 31  Published (CNA: CPANSec)
CWE-125 · CNA: CPANSec · 3 references · NVD status: Deferred
Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   H    5.7   .0037   29.8     —
AFFECTED
  Product  Versions         Fixed
  W12      3.0.0.7(4763) –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-404 · CNA: VulDB · 6 references · NVD status: Deferred
OUSL-GROUP-BrinaryBrains School Student Management System Forgot Password Endpoint Login.php ajax_forgot_password password recovery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   N   L   N    2.9   .0029   21.1     —
AFFECTED
  Product                           Versions                                    Fixed
  School Student Management System  1e70e5ad1125b86dca4ee086eb6bb121f17708b6 –  —
TIMELINE
  May 30  Reserved by CNA
  May 31  Published (CNA: VulDB)
CWE-640 · CNA: VulDB · 4 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-101732.120.3OrthancExplorer 2CWE-79Orthanc Explorer 2 URL StudyList.vue cross site scripting
CVE-2026-101785.519.1code-projectsOnline Music SiteCWE-74code-projects Online Music Site AdminEditAlbum.php sql injection
CVE-2026-101845.519.1SourceCodesterHospitals Patient Records Management SystemCWE-74SourceCodester Hospitals Patient Records Management System Users.php delete s…
CVE-2026-101855.519.1SourceCodesterHospitals Patient Records Management SystemCWE-74SourceCodester Hospitals Patient Records Management System Users.php save sql…
CVE-2026-101865.519.1code-projectsOnline Hospital Management SystemCWE-74code-projects Online Hospital Management System patient.php sql injection
CVE-2026-494898.418.3OpenCATSOpenCATSCWE-89OpenCATS - SQL Injection in DataGrid sortDirection Parameter
CVE-2026-494908.616.5OpenCATSOpenCATSCWE-89OpenCATS - SQL Injection in DataGrid Filter Handling for Tags Column
CVE-2026-482105.716.3OTRS AGOTRSCWE-200Possible information disclosure via External Interface
CVE-2026-101945.316.3OFFISDCMTKCWE-119OFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflow
CVE-2026-101702.115.8code-projectsVisitor Management SystemCWE-74code-projects Visitor Management System phone_0.php sql injection
CVE-2026-101682.115.7OUSL-GROUP-BrinaryBrainsSchool Student Management SystemCWE-99OUSL-GROUP-BrinaryBrains School Student Management System Parents.php marks r…
CVE-2026-101752.115.6Aider-AIAiderCWE-74Aider-AI Aider Architect Mode auth.py editor_coder.run code injection
CVE-2026-101742.113.8Aider-AIAiderCWE-693Aider-AI Aider Pre-commit Hook args.py protection mechanism
CVE-2026-101772.111.4Aider-AIAiderCWE-918Aider-AI Aider AWS EC2 Metadata Endpoint api_docs.py requests.get server-side…
CVE-2026-101722.110.9BdtaskMulti-Store Inventory Management SystemCWE-284Bdtask Multi-Store Inventory Management System Component Module.php upload un…
CVE-2026-101712.011.0code-projectsOnline Music SiteCWE-74code-projects Online Music Site AdminUpdateAlbum.php sql injection
CVE-2026-101762.110.7Aider-AIAiderCWE-74Aider-AI Aider Code Generation Workflow sql injection
CVE-2026-101932.19.7n/aOFCMSCWE-74OFCMS ComnController ComnController.java query sql injection
CVE-2026-102032.19.7n/aOFCMSCWE-74OFCMS JSON Query SystemParamController.java query sql injection
CVE-2026-102022.19.2n/aOFCMSCWE-74OFCMS JSON Query SystemDictController.java query sql injection
CVE-2026-102042.19.2n/aOFCMSCWE-74OFCMS JSON Query SysUserController.java query sql injection
CVE-2026-102001.92.6n/aAssimpCWE-119Assimp 4x4 Matrix glTFCommon.h CopyValue heap-based overflow
CVE-2026-101991.92.0n/aAssimpCWE-404Assimp glTF2Asset.h LazyDict null pointer dereference
CVE-2026-101971.91.8n/aAssimpCWE-404Assimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference
CVE-2026-101981.91.7n/aAssimpCWE-404Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference
CVE-2026-102011.91.6n/aAssimpCWE-369Assimp UV Channel FBXExporter.cpp WriteObjects divide by zero

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-31 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.