boxscore/security
Saturday, August 1, 2026 · all times UTC← 2026-07-31 · archive · 2026-08-02 →

147 CVEs published August 1, 2026: 17 critical, 48 high, 74 medium, 8 low; 0 in KEV; 7 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 122 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published147895213902563
KEV catalog size1670

333 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux0158520711279802730.27.8.0016-6
microsoft013611059293028378322.47.8.0039-2
google041264104226157351.26.5.00220
apple0244566711229372.97.1.00270
red hat022291099212400.07.1.0027-3
canonical030210000.07.8.00130
android010100161100.08.4.01710
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco0204620961365.08.2.18530
fortinet018249028633.36.1.00540
palo alto networks015017514213.34.7.00280
vmware01247012100.08.7.00440
f50540007120.09.2.04020
ivanti051000335100.010.0.81520
broadcom0400204250.05.1.08770
checkpoint0431003250.09.2.46960
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache013724743904010.77.5.00510
mozilla0724226401300.09.1.00310
gitlab015021014213.34.9.00290
docker030120100.05.7.00150
wordpress0311105266.78.6.73100
github020110000.06.1.00290
drupal01100051100.09.8.88320
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01113212539304574030.37.6.00310
ibm01083143340700.07.5.00260
adobe04010224075410.08.4.00390
progress02331550900.08.1.00320
solarwinds0201611011420.09.1.00500
atlassian0303001300.08.0.00260
zohocorp031110000.07.1.00480
veeam020110400.06.8.00160
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link08006126112.55.5.00730
hikvision0704202114.37.2.00250
bosch030300000.08.1.00280
schneider electric031200100.08.7.00200
honeywell010010000.06.9.00310
mitsubishi electric010100000.07.1.00130
rockwell automation011000000.09.2.00300
siemens010100100.08.7.00320
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb057326253000.07.1.00250
grafana041214223000.06.5.00330
netty04162771000.07.5.00460
open ises037214210000.06.9.00210
erlang032114143100.06.9.00330
freerdp212981641000.08.7.0034+21
regularlabs.com02961490000.07.5.00220
watchguard02811890400.07.3.00260

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1109
linux659
microsoft651
google403
apple167
red hat120
apache105
ibm100
mozilla67
surrealdb57
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven29
Go3
crates.io2
npm2
NuGet1
Packagist1
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-20316Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171718
CVE-2021-27102Accellion2021-11-171718
CVE-2021-27101Accellion2021-11-171718
CVE-2021-27103Accellion2021-11-171718
CVE-2021-21017Adobe2021-11-171718
CVE-2021-28550Adobe2021-11-171718
CVE-2021-42013Apache2021-11-171718
CVE-2021-41773Apache2021-11-171718
CVE-2021-30858Apple2021-11-171718
CVE-2021-30860Apple2021-11-171718

Transactions

EXPLOIT PUBLISHEDCVE-2024-21536 (http-proxy-middleware). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10773 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-2411 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54894 (ueberauth guardian). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55733 (ueberauth guardian). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55734 (ueberauth guardian). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55735 (ueberauth guardian). Public exploit reference added.

RESCOREDCVE-2024-10918 (libmodbus). CVSS 4.8 → 9.8 (NVD).

RESCOREDCVE-2024-21536 (http-proxy-middleware). CVSS 8.7 → 7.7 (NVD).

RESCOREDCVE-2026-15105 (davenardella snap7). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPEDCVE-2026-18577 (N-able N-central). Fixed in N-central 2026.3.1.7.

Yesterday's Results

147 CVEs published. 25 box scores, 122 table rows — nothing truncated.

gitpython-developers GitPython — GitPython before 3.1.51 Command Injection via option prefix abbreviation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0148   71.8     —
AFFECTED
  Product    Versions     Fixed
  GitPython  unspecified  3.1.51
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Received
gitpython-developers GitPython — GitPython before 3.1.51 Command Injection via unguarded Git options
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   N   H   H   H    8.6   .0102   60.4     —
AFFECTED
  Product    Versions     Fixed
  GitPython  unspecified  3.1.51
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-77 · CNA: VulnCheck · 2 references · NVD status: Received
bitpressadmin Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation — Bit integrations <= 2.9.0 - Unauthenticated Arbitrary File Read via Optional CF7 File Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0083   54.7     —
AFFECTED
  Product                                                                                  Versions     Fixed
  Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 10 references · NVD status: Deferred
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0077   52.5     —
AFFECTED
  Product                                                      Versions     Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  unspecified  —
TIMELINE
  Jul 13  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 14 references · NVD status: Deferred
Unknown HUSKY — HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0072   51.0     —
AFFECTED
  Product  Versions     Fixed
  HUSKY    unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Aug 1   Published (CNA: WPScan)
CWE-22 · CNA: WPScan · 1 reference · NVD status: Received
stiofansisland Payment forms, Buy now buttons, and Invoicing System | GetPaid — Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0071   50.5     —
AFFECTED
  Product                                                         Versions     Fixed
  Payment forms, Buy now buttons, and Invoicing System | GetPaid  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · 10 references · NVD status: Deferred
wpchill Kali Forms — Contact Form & Drag-and-Drop Builder — Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0069   49.7     —
AFFECTED
  Product                                            Versions     Fixed
  Kali Forms — Contact Form & Drag-and-Drop Builder  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · 12 references · NVD status: Deferred
gm_alex User Access Manager — User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0068   49.3     —
AFFECTED
  Product              Versions     Fixed
  User Access Manager  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 6 references · NVD status: Deferred
cubewp1211 CubeWP Framework — CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0064   47.8     —
AFFECTED
  Product           Versions     Fixed
  CubeWP Framework  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 3 references · NVD status: Deferred
ArcadeData arcadedb — ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0052   42.0     —
AFFECTED
  Product   Versions     Fixed
  arcadedb  unspecified  26.7.2
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 2 references · NVD status: Received
Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   N    7.8   .0049   40.1     —
AFFECTED
  Product  Versions  Fixed
  traefik  3.7.0 –   3.7.8
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 4 references · NVD status: Received
britcoder Single Sign On For TNG — Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0049   39.9     —
AFFECTED
  Product                 Versions     Fixed
  Single Sign On For TNG  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-620 · CNA: Wordfence · 6 references · NVD status: Deferred
FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4   .0049   39.9     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-122 · CNA: VulnCheck · 2 references · NVD status: Received
Unknown Support Genix — Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0048   39.5     —
AFFECTED
  Product        Versions     Fixed
  Support Genix  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 1   Published (CNA: WPScan)
CWE-22 · CNA: WPScan · 1 reference · NVD status: Received
wpwax FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More — FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0047   38.5     —
AFFECTED
  Product                                                                                      Versions     Fixed
  FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More  unspecified  —
TIMELINE
  Feb 24  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 7 references · NVD status: Deferred
Wazuh GitHub Actions Shell Injection via Fork Pull Request
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.3   .0045   37.4     —
AFFECTED
  Product  Versions     Fixed
  wazuh    unspecified  44bf114d2f4901aa82ecbb9e5b0780f7c3ca5263
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Received
FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0043   36.0     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-125 · CNA: VulnCheck · 3 references · NVD status: Received
WPWeb WooCommerce - Social Login — WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0040   33.2     —
AFFECTED
  Product                     Versions     Fixed
  WooCommerce - Social Login  unspecified  —
TIMELINE
  May 13  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-289 · CNA: Wordfence · 2 references · NVD status: Deferred
better-auth before 1.1.16 Reflected XSS via error parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   L   L   N    5.1   .0040   33.0     —
AFFECTED
  Product      Versions     Fixed
  better-auth  unspecified  1.1.16
TIMELINE
  Jul 18  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · 3 references · NVD status: Received
FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0038   31.2     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-191 · CNA: VulnCheck · 5 references · NVD status: Received
FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0038   31.2     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.29.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-113 · CNA: VulnCheck · 3 references · NVD status: Received
gitpython-developers GitPython — GitPython 3.1.50 Authentication Bypass via Joined Short Options
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0038   31.0     —
AFFECTED
  Product    Versions  Fixed
  GitPython  3.1.50 –  3.1.51
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Received
webaways NEX-Forms – Ultimate Forms Plugin for WordPress — NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0038   30.7     —
AFFECTED
  Product                                          Versions     Fixed
  NEX-Forms – Ultimate Forms Plugin for WordPress  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Aug 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 5 references · NVD status: Deferred
axios before 1.18.0 Prototype Pollution via auth subfields
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   L   L    6.3   .0037   29.6     —
AFFECTED
  Product  Versions  Fixed
  axios    1.15.2 –  1.18.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-1321 · CNA: VulnCheck · 2 references · NVD status: Received
axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0036   29.0     —
AFFECTED
  Product  Versions  Fixed
  axios    1.7.0 –   1.18.0
TIMELINE
  Jul 29  Reserved by CNA
  Aug 1   Published (CNA: VulnCheck)
CWE-770 · CNA: VulnCheck · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-673186.328.7axiosaxiosCWE-400axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2
CVE-2026-673048.728.5FreeRDPFreeRDPCWE-476FreeRDP before 3.29.0 NULL Dereference via smartcard cleanup
CVE-2026-673309.428.2better-authscimCWE-20better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-I…
CVE-2026-672888.728.1FreeRDPFreeRDPCWE-476FreeRDP before 3.29.0 Denial of Service via smartcard cache
CVE-2026-672968.727.3FreeRDPFreeRDPCWE-20FreeRDP before 3.29.0 Denial of Service via RDPEI PDU
CVE-2026-672978.727.3FreeRDPFreeRDPCWE-770FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response
CVE-2026-672918.726.8FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADD
CVE-2026-673018.726.8FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Out-of-bounds Read via Polygon async message-proxy
CVE-2026-673126.326.7axiosaxiosCWE-400axios 0.28.0 before 0.33.0 Denial of Service via formToJSON
CVE-2026-673136.326.8axiosaxiosCWE-400axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON
CVE-2026-154148.826.4wpswingsSubscriptions for WooCommerceCWE-269Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privile…
CVE-2026-180595.326.0pixelyoursitePixelYourSite – Your smart PIXEL (TAG) & API ManagerCWE-200PixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via …
CVE-2026-672998.725.8FreeRDPFreeRDPCWE-416FreeRDP before 3.29.0 Use-After-Free via WindowIcon async message
CVE-2026-673008.725.8FreeRDPFreeRDPCWE-416FreeRDP before 3.29.0 Use-After-Free via async message proxy
CVE-2026-119955.325.1saadiqbalGutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form BuilderCWE-862Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Cu…
CVE-2026-673419.324.7ArcadeDataarcadedbCWE-863ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION
CVE-2026-673429.324.7ArcadeDataarcadedbCWE-639ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers
CVE-2026-673025.324.4FreeRDPFreeRDPCWE-369FreeRDP rdpecam StartStreamsRequest divide-by-zero denial of service
CVE-2026-175806.524.2wplakeorgAdvanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…CWE-862Advanced Views <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+…
CVE-2026-166358.823.5pronamicPronamic PayCWE-269Pronamic Pay <= 10.1.0 - Authenticated (Subscriber+) Privilege Escalation via…
CVE-2026-134586.423.3edge22GenerateBlocksCWE-79GenerateBlocks <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-673208.323.0axiosaxiosCWE-200axios before 0.33.0 Prototype Pollution via Node HTTP adapter
CVE-2026-673438.722.4ArcadeDataarcadedbCWE-200ArcadeDB before 26.7.2 Cluster Token Disclosure via GET /api/v1/server
CVE-2026-107824.322.1inspirythemesRealHomes MembershipsCWE-862RealHomes Memberships <= 3.0.9 - Missing Authorization to Authenticated (Subs…
CVE-2026-673156.921.6axiosaxiosCWE-183axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
CVE-2026-673216.921.6axiosaxiosCWE-674axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via max…
CVE-2026-664029.321.5FreeRDPFreeRDPCWE-295FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass
CVE-2026-557346.921.1ueberauthguardianCWE-770guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1
CVE-2026-557358.220.7ueberauthguardianCWE-347Guardian.revoke/3 acts on unverified token claims, allowing forged-token sess…
CVE-2026-64536.520.6cubewp1211CubeWP FrameworkCWE-89CubeWP Framework <= 1.1.30 - Authenticated (Subscriber+) SQL Injection via 'r…
CVE-2026-673288.620.3better-authssoCWE-79@better-auth/sso before 1.6.21 Account Takeover via SSO
CVE-2026-131577.220.2UnknownTheme Demo ImportCWE-434Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
CVE-2026-131587.220.2UnknownEverest ToolkitCWE-434Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
CVE-2026-673065.320.1FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLE
CVE-2026-672949.319.3FreeRDPFreeRDPCWE-295FreeRDP before 3.29.0 TLS Certificate EKU Bypass
CVE-2026-548946.919.3ueberauthguardianCWE-770Atom-table exhaustion denial of service in Guardian via unbounded atom creati…
CVE-2026-557336.919.3ueberauthguardianCWE-770Atom-table exhaustion denial of service in Guardian permissions AtomEncoding …
CVE-2026-673377.119.1better-authbetter-authCWE-288better-auth before 1.4.9 Two-Factor Authentication Bypass via session.cookieC…
CVE-2026-160876.519.1icegramIcegram Engage – Popups, Optins, CTAs & Lead GenerationCWE-89Icegram Engage <= 3.1.42 - Authenticated (Contributor+) Second-Order SQL Inje…
CVE-2026-673228.718.6gitpython-developersGitPythonCWE-200GitPython before 3.1.52 Environment Variable Exfiltration via clone_from
CVE-2026-154034.918.8dotonpaperPinpoint Booking System – Version 2CWE-89Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Inj…
CVE-2026-159514.918.8icegramIcegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logsCWE-89Icegram Mailer <= 1.0.12 - Authenticated (Administrator+) SQL Injection via '…
CVE-2026-166144.918.8westerndealGSheetConnector – CF7 Google Sheets ConnectorCWE-89GSheetConnector <= 5.2.1 - Authenticated (Administrator+) SQL Injection via '…
CVE-2026-175554.918.8wpvividpluginsWPvivid — Backup, Migration & StagingCWE-89WPvivid <= 0.9.131 - Authenticated (Administrator+) SQL Injection via 'export…
CVE-2026-150185.318.5davejeschDatabase Collation FixCWE-89Database Collation Fix <= 1.2.10 - Unauthenticated SQL Injection via 'force-c…
CVE-2026-672929.318.3FreeRDPFreeRDPCWE-130FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure
CVE-2026-135969.118.1UnknownParticipants DatabaseCWE-89Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
CVE-2026-673166.317.6axiosaxiosCWE-1321axios before 1.18.0 Prototype Pollution via bodyless methods
CVE-2026-673196.317.6axiosaxiosCWE-1321axios before 0.33.0 Prototype Pollution via nested option objects
CVE-2026-673118.217.4BudibasebudibaseCWE-918Budibase before 3.38.1 SSRF Blacklist Bypass via HTTP Redirect
CVE-2026-148397.517.4UnknownMapster WP MapsCWE-200Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Dis…
CVE-2026-673548.216.8guzzleguzzleCWE-201guzzlehttp/guzzle before 7.15.1 URI Fragment Disclosure via Referer
CVE-2026-673035.316.4FreeRDPFreeRDPCWE-617FreeRDP before 3.29.0 Denial of Service via serial DeviceControl
CVE-2026-673536.916.2guzzleguzzleCWE-770guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service
CVE-2026-672955.315.9FreeRDPFreeRDPCWE-22FreeRDP before 3.29.0 Path Traversal via drive redirection
CVE-2026-150527.215.5umarbajwaMailChimp Subscribe Form, Optin Builder, PopUp Builder, Form BuilderCWE-79MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3…
CVE-2026-166856.415.5codename065Download ManagerCWE-79Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-673318.715.3better-authscimCWE-639better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass
CVE-2025-714037.115.1better-authbetter-authCWE-601better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass
CVE-2026-156626.414.6mihail-barinovAdvanced Woo Labels – Product Labels & Badges for WooCommerceCWE-79Advanced Woo Labels <= 2.48 - Authenticated (Contributor+) Stored Cross-Site …
CVE-2026-673396.914.4guzzleguzzleCWE-200guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure
CVE-2025-140735.314.3woocommerceWooCommerce PayPal PaymentsCWE-639WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information …
CVE-2026-673278.714.1better-authbetter-authCWE-287better-auth before 1.6.22 Account Takeover via Magic-Link Email-OTP
CVE-2026-673558.213.9guzzleguzzleCWE-201guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope
CVE-2026-143098.113.6UnknownChat On Desk Order NotificationsCWE-287Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OT…
CVE-2026-148368.113.6UnknownLogin & Register FormsCWE-287Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Re…
CVE-2026-153688.113.6UnknownUser Profile BuilderCWE-269Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login Af…
CVE-2026-145968.813.1UnknownDynamicKit for ElementorCWE-287DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Passw…
CVE-2026-129665.312.9UnknownDirect Payments for WooCommerceCWE-284Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Orde…
CVE-2026-159888.812.4tigroumeowAI Engine – The Chatbot, AI Framework & MCP for WordPressCWE-352AI Engine <= 3.6.5 - Cross-Site Request Forgery to Privilege Escalation via R…
CVE-2026-29164.312.4jegthemeJeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPressCWE-200Jeg Kit for Elementor <= 3.1.1 - Authenticated (Contributor+) Exposure of Sen…
CVE-2026-183446.112.2nik00726Responsive Thumbnail SliderCWE-79Responsive Thumbnail Slider < 1.1.53 - Reflected Cross-Site Scripting via 'id…
CVE-2026-673526.812.1openwrtluciCWE-79luci-app-https-dns-proxy Stored XSS via resolver_url
CVE-2026-175716.111.6wpmanageninjaFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-79Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param'
CVE-2026-148405.311.4UnknownYOP PollCWE-290YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoo…
CVE-2026-76236.410.9brainstormforceSureForms – Contact Form Builder, AI Forms, Payment Form, Survey & QuizCWE-79SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-156446.410.9codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-156456.410.9codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-180626.410.9stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-79Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Sc…
CVE-2025-714022.011.0better-authbetter-authCWE-347better-auth before 1.4.0 Session Revocation via Forged Cookie
CVE-2026-133626.410.6sendpulseSendPulse Email Marketing NewsletterCWE-79SendPulse Email Marketing Newsletter <= 2.2.5 - Authenticated (Contributor+) …
CVE-2026-156496.410.3codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-160916.410.3rubengcGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-79GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-673345.110.1better-authbetter-authCWE-459better-auth Stale Sessions Persist After User Deletion
CVE-2026-673297.19.6better-authstripeCWE-639@better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subsc…
CVE-2026-159506.49.3cozythemesCozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & TemplatesCWE-79Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-160906.49.3rubengcGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPressCWE-79GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-166846.49.3mervb1Easy Property ListingsCWE-79Easy Property Listings <= 3.5.24 - Authenticated (Subscriber+) Stored Cross-S…
CVE-2026-184356.49.3stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-79Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-118823.79.2UnknownBuilderall for WordPressCWE-284Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoni…
CVE-2026-673267.39.1gitpython-developersGitPythonCWE-20GitPython before 3.1.50 Newline Injection via config_writer section
CVE-2026-148225.38.0UnknownEvent Tickets and RegistrationCWE-284Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
CVE-2026-673105.38.1openremoteopenremoteCWE-863openremote before 1.27.0 Cross-Tenant IDOR via setAssetLinks
CVE-2026-107735.48.0zephyrprojectzephyrCWE-125Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_…
CVE-2026-141952.77.7UnknownBrizyCWE-639Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure…
CVE-2026-136045.37.4UnknownPixelavoCWE-918Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo…
CVE-2026-673385.17.2jupyterlabjupyterlabCWE-84JupyterLab before 4.5.9 Stored XSS via Extension Manager
CVE-2026-133296.57.2UnknownBuckaroo Woocommerce Payments PluginCWE-284WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
CVE-2025-156694.87.1UnknownBit FormCWE-79Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
CVE-2026-673356.06.9better-authbetter-authCWE-287better-auth before 1.6.2 OAuth State Validation Bypass
CVE-2026-673077.06.6wazuhwazuhCWE-345Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync
CVE-2026-142142.76.6UnknownBooking for Appointments and Events CalendarCWE-287Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass A…
CVE-2026-672939.36.3FreeRDPFreeRDPCWE-295FreeRDP before 3.29.0 Improper Certificate Hostname Validation
CVE-2026-137257.16.0UnknownDynamic Pricing With Discount Rules for WooCommerceCWE-79Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS v…
CVE-2026-143156.56.1UnknownPixel Tag Manager for WooCommerceCWE-284Pixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion…
CVE-2026-145616.56.1UnknownAuthora : Easy login with mobile numberCWE-287Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Tak…
CVE-2026-673325.35.9better-authoauth-providerCWE-285@better-auth/oauth-provider before 1.7.0-beta.4 Authorization Bypass
CVE-2026-185367.55.7RRWOData::EntropyCWE-319Data::Entropy versions before 0.010 for Perl read remote entropy sources over…
CVE-2026-673369.45.5better-authbetter-authCWE-327better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider
CVE-2026-142925.45.6UnknownDownload ManagerCWE-79WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
CVE-2026-673335.15.4better-authbetter-authCWE-79better-auth before 1.6.13 Stored XSS via javascript redirect_uri
CVE-2026-141973.84.9UnknownFluent SupportCWE-639Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
CVE-2026-664012.44.8FreeRDPFreeRDPCWE-125FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264
CVE-2026-148232.24.5UnknownEvent Tickets and RegistrationCWE-639Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory M…
CVE-2026-673448.54.2ArcadeDataarcadedbCWE-862ArcadeDB before 26.7.2 Authentication Bypass via ALTER TYPE
CVE-2026-126965.43.3UnknownwpForo ForumCWE-79wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
CVE-2026-152345.43.3UnknownCodeless Page BuilderCWE-79Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
CVE-2026-152625.43.3UnknownAdmin Columns for ACF FieldsCWE-79Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field…
CVE-2025-144694.32.9mndpsingh287Theme EditorCWE-352Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification
CVE-2026-24116.52.4zephyrprojectzephyrCWE-863Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, by…
CVE-2026-108273.51.3UnknownSpectra LegacyCWE-345Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS In…
CVE-2026-137294.30.9UnknownPodlove Podcast PublisherCWE-352Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation a…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-01 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.