boxscore/security
Saturday, June 6, 2026 · all times UTC← 2026-06-05 · archive · 2026-06-07 →

39 CVEs published June 6, 2026: 0 critical, 7 high, 26 medium, 6 low; 0 in KEV; 0 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 14 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1584595610472563
KEV catalog size1670

257 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux3410008163028612730.37.8.0013-112
google48866258331255157450.87.8.0023+488
microsoft7497443331030378275.47.8.0046+7
red hat1983840305400.07.4.0033+17
apple04701227193714.96.2.00340
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco215314096853.37.0.0694+2
ivanti16020033466.78.8.5751+1
checkpoint060330300.06.5.03380
fortinet06130028350.07.9.43300
zyxel2300301100.06.5.0017+2
f50320007133.39.2.09960
ubiquiti031200400.08.8.00680
broadcom02000042100.0.19900
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache32648262724011.67.2.0053+28
mozilla41033401300.07.4.0035+4
gitlab0901604222.24.3.00320
docker250500100.08.8.0021+2
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm5541326150700.07.5.0031+5
oracle128815404013.68.1.0027+1
progress591710900.07.5.0036+5
solarwinds25120011480.07.5.7155+2
adobe04010075375.08.6.27760
veeam031200400.08.6.00400
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link58031326112.56.0.0087+5
abb440400000.07.3.0024+4
siemens120110100.07.3.0026+1
hitachi energy020020000.05.7.00140
hikvision01000021100.01.00000
dahua000000200
qnap000000800
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax051032019100.07.4.00590
concrete cms1451101321000.06.0.0015+1
open ises044221210000.07.1.00210
sourcecodester2143001429000.02.1.0025+21
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
acer2636111960000.08.7.0024+26
nvidia23582070000.07.8.0029+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4399710.0.0098
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
Most disclosures (vendor)
VendorCVEs
google656
linux528
microsoft165
red hat56
ibm54
edimax51
apache49
concrete cms45
open ises44
sourcecodester43
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google5
ivanti4
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven24
PyPI10
Packagist7
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171662
CVE-2021-27102Accellion2021-11-171662
CVE-2021-27101Accellion2021-11-171662
CVE-2021-27103Accellion2021-11-171662
CVE-2021-21017Adobe2021-11-171662
CVE-2021-28550Adobe2021-11-171662
CVE-2021-42013Apache2021-11-171662
CVE-2021-41773Apache2021-11-171662
CVE-2021-30858Apple2021-11-171662
CVE-2021-30860Apple2021-11-171662

Transactions

DUE DATE PASSEDCVE-2022-0492 (Linux Kernel). CISA remediation deadline was June 5, 2026; still in catalog.

DUE DATE PASSEDCVE-2025-48595 (Google Android). CISA remediation deadline was June 5, 2026; still in catalog.

Yesterday's Results

39 CVEs published. 25 box scores, 14 table rows — nothing truncated.

wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets — Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0724   93.8     —
AFFECTED
  Product                                                                 Versions     Fixed
  Essential Addons for Elementor – Popular Elementor Templates & Widgets  unspecified  —
TIMELINE
  May 1   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · 14 references · NVD status: Deferred
GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0123   66.4     —
AFFECTED
  Product  Versions  Fixed
  MT3000   4.4.0 –   4.9.0_beta3-1012-0513-1778656146
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 6 references · NVD status: Deferred
vertex-app vertex Log Viewer Endpoint LogMod.js os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0111   63.3     —
AFFECTED
  Product  Versions     Fixed
  vertex   2026.02.0 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 8 references · NVD status: Deferred
chrisvrichardson MapPress Maps for WordPress — MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0102   60.5     —
AFFECTED
  Product                      Versions     Fixed
  MapPress Maps for WordPress  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · 24 references · NVD status: Deferred
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0066   48.6     —
AFFECTED
  Product                Versions     Fixed
  MDJM Event Management  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 10 references · NVD status: Deferred
thimpress LearnPress – Backup & Migration Tool — LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0065   48.0     —
AFFECTED
  Product                               Versions     Fixed
  LearnPress – Backup & Migration Tool  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 8 references · NVD status: Deferred
nextendweb Smart Slider 3 — Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0060   45.9     —
AFFECTED
  Product         Versions     Fixed
  Smart Slider 3  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 5 references · NVD status: Deferred
thimpress LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0053   42.2     —
AFFECTED
  Product                                                               Versions     Fixed
  LearnPress – WordPress LMS Plugin for Create and Sell Online Courses  unspecified  —
TIMELINE
  May 13  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 14 references · NVD status: Deferred
davidanderson All-In-One Security (AIOS) – Security and Firewall — All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0049   39.7     —
AFFECTED
  Product                                             Versions     Fixed
  All-In-One Security (AIOS) – Security and Firewall  unspecified  —
TIMELINE
  May 12  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 10 references · NVD status: Deferred
JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0048   39.4     —
AFFECTED
  Product              Versions       Fixed
  JD Cloud Box AX6600  4.5.3.r4546 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Deferred
10web Photo Gallery by 10Web – Mobile-Friendly Image Gallery — Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0047   38.6     —
AFFECTED
  Product                                                 Versions     Fixed
  Photo Gallery by 10Web – Mobile-Friendly Image Gallery  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 12 references · NVD status: Deferred
thimpress LearnPress – Backup & Migration Tool — LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0045   37.4     —
AFFECTED
  Product                               Versions     Fixed
  LearnPress – Backup & Migration Tool  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · 8 references · NVD status: Deferred
CRUX Protocol::HTTP2 — Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0041   34.5     —
AFFECTED
  Product          Versions     Fixed
  Protocol::HTTP2  unspecified  —
TIMELINE
  Jun 3   Reserved by CNA
  Jun 6   Published (CNA: CPANSec)
CWE-409 · CNA: CPANSec · 6 references · NVD status: Analyzed
perfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0041   34.0     —
AFFECTED
  Product         Versions  Fixed
  go-fastdfs-web  1.3.0 –   —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-918 · CNA: VulDB · 5 references · NVD status: Deferred
holithemes Click to Chat – HoliThemes — Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0041   33.9     —
AFFECTED
  Product                     Versions     Fixed
  Click to Chat – HoliThemes  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 11 references · NVD status: Deferred
spacetime Ad Inserter – Ad Manager & AdSense Ads — Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0036   29.1     —
AFFECTED
  Product                                 Versions     Fixed
  Ad Inserter – Ad Manager & AdSense Ads  unspecified  —
TIMELINE
  May 22  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 8 references · NVD status: Deferred
masaakitanaka Booking Package — Booking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0036   28.9     —
AFFECTED
  Product          Versions     Fixed
  Booking Package  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · 5 references · NVD status: Deferred
wpdevteam EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more — EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0033   26.0     —
AFFECTED
  Product                                                                                        Versions     Fixed
  EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 11 references · NVD status: Deferred
davidfcarr Quick Playground — Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  N  N    4.4   .0032   24.3     —
AFFECTED
  Product           Versions     Fixed
  Quick Playground  unspecified  —
TIMELINE
  Feb 13  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 4 references · NVD status: Deferred
plugcrux Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More — Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0031   24.1     —
AFFECTED
  Product                                                                                  Versions     Fixed
  Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 10 references · NVD status: Deferred
glenwpcoder Drag and Drop Multiple File Upload for Contact Form 7 — Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  L  L  N    4.4   .0031   23.9     —
AFFECTED
  Product                                                Versions     Fixed
  Drag and Drop Multiple File Upload for Contact Form 7  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 8 references · NVD status: Deferred
smub WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More — WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0030   22.7     —
AFFECTED
  Product                                                                                    Versions     Fixed
  WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-345 · CNA: Wordfence · 14 references · NVD status: Deferred
cifi SEO Plugin by Squirrly SEO — SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0030   22.2     —
AFFECTED
  Product                     Versions     Fixed
  SEO Plugin by Squirrly SEO  unspecified  —
TIMELINE
  May 1   Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 14 references · NVD status: Deferred
flippercode WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters — WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  L  L  N    4.4   .0029   21.9     —
AFFECTED
  Product                                                                               Versions     Fixed
  WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters  unspecified  —
TIMELINE
  May 26  Reserved by CNA
  Jun 6   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 6 references · NVD status: Deferred
n/a FluentCMS — FluentCMS Blocks Plugin blocks cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   N   L   N    1.9   .0027   19.9     —
AFFECTED
  Product    Versions  Fixed
  FluentCMS  0.0.5 –   —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 6   Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · 7 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-114362.118.3n/aMage AICWE-79Mage AI Sign-in Flow index.tsx useMutation cross site scripting
CVE-2026-90165.318.0qriousladDebug Log Manager – Conveniently Monitor and Inspect ErrorsCWE-117Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization f…
CVE-2026-114355.517.8JinherOACWE-74Jinher OA nextselectplan.aspx sql injection
CVE-2026-89784.917.7crafiumOptinCraft – Drag & Drop Optins & Popup Builder for WordPressCWE-89OptinCraft <= 1.2.0 - Authenticated (Administrator+) SQL Injection via 'order…
CVE-2026-86114.314.5klamra22Klamra Paycal for AspaclariaCWE-639Klamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to A…
CVE-2026-90084.313.2webvitalyPage-listCWE-862Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sens…
CVE-2026-92816.412.1litonice13Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template KitsCWE-79Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-S…
CVE-2026-114385.312.0theonedevonedevCWE-266theonedev projects improper authorization
CVE-2026-114395.312.0theonedevonedevCWE-266theonedev Parent Project projects improper authorization
CVE-2026-114405.312.0theonedevonedevCWE-266theonedev REST API default-branch improper authorization
CVE-2026-114415.312.0theonedevonedevCWE-266theonedev Pull Request issues canAccessIssue improper authorization
CVE-2026-114122.19.7JinherOACWE-74Jinher OA GetFormSn.aspx sql injection
CVE-2026-114111.96.8iAI LabPDF AI AppCWE-22iAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal
CVE-2026-264228.46.0Clash Verge Revclash-verge-service-ipcCWE-732clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, lead…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-06 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.