AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.4 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
109 CVEs published August 16, 2026: 14 critical, 33 high, 43 medium, 19 low; 0 in KEV; 3 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 84 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 5927 | 14732 | 1444 | 2563 |
| KEV catalog size | 1670 | |||
867 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1263 | 2848 | 363 | 1678 | 98 | 0 | 27 | 3 | 0.1 | 7.8 | .0017 | +1247 |
| microsoft | 442 | 1803 | 131 | 1219 | 428 | 8 | 378 | 33 | 1.8 | 7.8 | .0038 | -195 |
| 49 | 461 | 72 | 140 | 228 | 18 | 73 | 5 | 1.1 | 6.5 | .0023 | +48 | |
| red hat | 142 | 364 | 22 | 166 | 158 | 18 | 4 | 0 | 0.0 | 7.1 | .0025 | +124 |
| apple | 2 | 246 | 57 | 68 | 112 | 2 | 93 | 7 | 2.8 | 7.1 | .0027 | +2 |
| canonical | 11 | 14 | 9 | 3 | 2 | 0 | 0 | 0 | 0.0 | 9.9 | .0029 | +11 |
| suse | 5 | 5 | 1 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.3 | .0022 | +5 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 31 | 51 | 9 | 25 | 9 | 0 | 96 | 14 | 27.5 | 7.8 | .0033 | +24 |
| palo alto networks | 12 | 27 | 0 | 1 | 14 | 10 | 14 | 2 | 7.4 | 4.5 | .0019 | +2 |
| fortinet | 7 | 25 | 3 | 6 | 12 | 1 | 28 | 6 | 24.0 | 6.0 | .0051 | -3 |
| sonicwall | 10 | 12 | 3 | 5 | 4 | 0 | 17 | 2 | 16.7 | 7.8 | .0024 | +8 |
| vmware | 0 | 12 | 4 | 7 | 0 | 1 | 21 | 0 | 0.0 | 8.7 | .0044 | 0 |
| netgear | 9 | 9 | 0 | 0 | 5 | 4 | 8 | 0 | 0.0 | 4.3 | .0031 | +9 |
| ivanti | 3 | 8 | 1 | 3 | 0 | 0 | 33 | 5 | 62.5 | 7.9 | .5751 | +3 |
| checkpoint | 1 | 5 | 4 | 1 | 0 | 0 | 3 | 2 | 40.0 | 9.3 | .2062 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 101 | 238 | 45 | 120 | 72 | 1 | 40 | 2 | 0.8 | 7.5 | .0048 | +100 |
| mozilla | 1 | 73 | 42 | 26 | 5 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | -1 |
| gitlab | 13 | 28 | 0 | 8 | 16 | 2 | 4 | 2 | 7.1 | 5.1 | .0026 | +13 |
| github | 5 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0041 | +5 |
| docker | 1 | 4 | 0 | 1 | 3 | 0 | 1 | 0 | 0.0 | 5.7 | .0014 | +1 |
| wordpress | 1 | 4 | 1 | 2 | 1 | 0 | 5 | 2 | 50.0 | 8.8 | .3700 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | -1 |
| ibm | 192 | 300 | 61 | 139 | 94 | 6 | 7 | 1 | 0.3 | 7.5 | .0030 | +192 |
| adobe | 60 | 100 | 22 | 51 | 22 | 1 | 75 | 4 | 4.0 | 7.8 | .0036 | +46 |
| progress | 16 | 39 | 11 | 20 | 8 | 0 | 9 | 1 | 2.6 | 8.1 | .0027 | +16 |
| solarwinds | 0 | 20 | 16 | 1 | 1 | 0 | 11 | 4 | 20.0 | 9.1 | .0050 | 0 |
| veeam | 10 | 12 | 3 | 7 | 2 | 0 | 4 | 0 | 0.0 | 8.6 | .0027 | +10 |
| zohocorp | 4 | 7 | 2 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.8 | .0099 | +4 |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 16 | 24 | 15 | 0 | 6 | 2 | 26 | 1 | 4.2 | 9.3 | .0209 | +16 |
| siemens | 19 | 20 | 1 | 16 | 1 | 2 | 1 | 0 | 0.0 | 7.3 | .0011 | +19 |
| hikvision | 0 | 7 | 0 | 4 | 2 | 0 | 2 | 1 | 14.3 | 7.2 | .0025 | 0 |
| bosch | 0 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0028 | 0 |
| schneider electric | 0 | 3 | 1 | 2 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0020 | 0 |
| synology | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0013 | +1 |
| honeywell | 0 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 6.9 | .0031 | 0 |
| mitsubishi electric | 0 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.1 | .0013 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| elastic | 48 | 67 | 0 | 13 | 54 | 0 | 3 | 0 | 0.0 | 6.5 | .0027 | +48 |
| siyuan-note | 54 | 61 | 30 | 8 | 23 | 0 | 0 | 0 | 0.0 | 8.8 | .0025 | +54 |
| mongodb | 32 | 58 | 3 | 37 | 16 | 2 | 2 | 0 | 0.0 | 7.1 | .0024 | +32 |
| surrealdb | 0 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | -1 |
| zephyrproject | 27 | 49 | 0 | 17 | 26 | 6 | 0 | 0 | 0.0 | 6.5 | .0016 | +26 |
| gitea | 48 | 48 | 7 | 15 | 22 | 4 | 0 | 0 | 0.0 | 6.5 | .0027 | +48 |
| netty | 3 | 44 | 6 | 28 | 9 | 1 | 0 | 0 | 0.0 | 7.5 | .0046 | +3 |
| grafana | 1 | 42 | 3 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | -5 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9931 | 99.9 | 9.8 |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-34486 | .8293 | 99.6 | 7.5 |
| CVE-2026-16232 | .7330 | 99.4 | 9.3 |
| CVE-2026-60137 | .7310 | 99.4 | 5.9 |
| CVE-2026-0770 | .5688 | 99.0 | 9.8 |
| CVE-2026-62144 | .2062 | 97.3 | 9.1 |
| CVE-2021-27137 | .1649 | 96.7 | 8.1 |
| CVE-2026-15733 | .1354 | 96.1 | 9.8 |
| CVE-2026-63077 | .1072 | 95.4 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .1040 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-48362 | 10.0 | .0207 | |
| CVE-2026-19188 | 10.0 | .0189 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2026-45618 | 10.0 | .0095 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| linux | 1914 |
| oracle | 1108 |
| microsoft | 461 |
| 451 | |
| ibm | 261 |
| red hat | 241 |
| apache | 205 |
| apple | 169 |
| adobe | 74 |
| elastic | 67 |
| Vendor | KEV |
|---|---|
| microsoft | 33 |
| cisco | 14 |
| apple | 7 |
| fortinet | 6 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 66 |
| PyPI | 5 |
| Go | 3 |
| npm | 3 |
| Packagist | 2 |
| crates.io | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1733 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1733 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1733 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1733 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1733 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1733 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1733 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1733 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1733 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1733 |
EXPLOIT PUBLISHED — CVE-2026-13700 (Unknown WooMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14229 (Unknown ECS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14230 (Unknown ECS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14832 (Unknown ShopSmart Loyalty for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16007 (AppFlowy-IO AppFlowy-Cloud). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16541 (Unknown Simply Schedule Appointments). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16611 (Unknown Product Feed PRO for WooCommerce by AdTribes). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18216 (Unknown Backup Migration). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18807 (Unknown ECS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19478 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19650 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19895 (opensourcepos Open Source Point of Sale). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19897 (mangroup dtale). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19900 (LB-LINK X-PRO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19903 (SourceCodester Online Clothing Store). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19917 (code-projects Online Food Order System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19965 (automad). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19966 (CodeCanyon TimeCamp Integration for CRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19967 (Open Asset Import Library Assimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19968 (Open Asset Import Library Assimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19969 (Open Asset Import Library Assimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19970 (Open Asset Import Library Assimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19972 (itsourcecode Hospital Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19973 (itsourcecode Hospital Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19974 (treefrogframework treefrog-framework). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19976 (COMFAST CF-N1-S). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19977 (EFM ipTIME A3004T). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19978 (jiantao88 android-mcp-server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19984 (jkawamoto mcp-florence2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19986 (Adblock for Youtube Extension). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19988 (Alaev SEO Tools Extension). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19992 (Orange View Limited DualSafe Password Manager & Digital Vault Extension). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19993 (Webkul Bagisto). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19994 (Webkul Bagisto). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19995 (Webkul Bagisto). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19996 (Webkul Bagisto). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19997 (Webkul Bagisto). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19998 (code-projects Online Shopping System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19999 (Open Asset Import Library Assimp Assimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-20000 (itsourcecode Hospital Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-72743 (dataease SQLBot). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74842 (Kira-Pgr PromptShopMCP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74843 (Wavlink WN531P3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75011 (kylecui NetForensicMCP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75012 (TOTOLINK EX1200L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75013 (TOTOLINK EX1200L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75014 (SourceCodester Pet Grooming Management Software). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75077 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75078 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
RESCORED — CVE-2026-19918 (SpaceX Starlink Router Gen 3). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19919 (code-projects Online Shopping System). CVSS 6.9 → 5.5 (NVD).
109 CVEs published. 25 box scores, 84 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.4 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.4 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 15 Public exploit reference published Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 64.4 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 15 Public exploit reference published Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0090 56.7 —
AFFECTED Product Versions Fixed AC10 16.03.10.09_multi_TDE01 – —
TIMELINE Aug 15 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0082 54.2 —
AFFECTED Product Versions Fixed Lemonldap-NG-Portal 2.0.0 – —
TIMELINE Aug 8 Reserved by CNA Aug 16 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0081 54.0 —
AFFECTED Product Versions Fixed StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More unspecified —
TIMELINE Jul 8 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0080 53.7 —
AFFECTED Product Versions Fixed Kirki – Freeform Page Builder, Website Builder & Customizer unspecified —
TIMELINE Jul 27 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0073 51.4 —
AFFECTED Product Versions Fixed WCPOS – Point of Sale (POS) plugin for WooCommerce unspecified —
TIMELINE Jul 27 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0070 50.2 —
AFFECTED Product Versions Fixed ProSolution WP Client unspecified —
TIMELINE Jul 2 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0064 47.8 —
AFFECTED Product Versions Fixed ProSolution WP Client unspecified —
TIMELINE Jul 17 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0059 45.3 —
AFFECTED Product Versions Fixed Podlove Podcast Publisher unspecified —
TIMELINE Jul 17 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0055 43.4 —
AFFECTED Product Versions Fixed Net-OAuth unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 16 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0055 43.4 —
AFFECTED Product Versions Fixed Query Wrangler unspecified —
TIMELINE Jul 2 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0052 41.7 —
AFFECTED Product Versions Fixed Contact Form, Survey, Quiz & Popup Form Builder – ARForms unspecified —
TIMELINE Jan 28 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0049 39.7 —
AFFECTED Product Versions Fixed Simply Schedule Appointments unspecified —
TIMELINE Jun 25 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0047 38.7 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0047 38.7 —
AFFECTED Product Versions Fixed EW-7478APC 1.04 – —
TIMELINE Aug 15 Public exploit reference published Aug 16 Reserved by CNA Aug 16 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0045 37.4 —
AFFECTED Product Versions Fixed siyuan unspecified 3.7.4
TIMELINE Aug 10 Reserved by CNA Aug 16 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0045 37.2 —
AFFECTED Product Versions Fixed Frontend Admin by DynamiApps unspecified —
TIMELINE Jul 30 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0044 36.9 —
AFFECTED Product Versions Fixed Extra Product Options Builder for WooCommerce unspecified —
TIMELINE Aug 13 Reserved by CNA Aug 15 Public exploit reference published Aug 16 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N N H 6.5 .0044 36.3 —
AFFECTED Product Versions Fixed Net-OAuth unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 16 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0042 34.6 —
AFFECTED Product Versions Fixed WP Travel Engine – Tour Booking Plugin – Tour Operator Software unspecified —
TIMELINE Jul 24 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U H H H 6.6 .0040 33.3 —
AFFECTED Product Versions Fixed Turnkey bbPress by WeaverTheme unspecified —
TIMELINE May 28 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0039 31.8 —
AFFECTED Product Versions Fixed Product Table & List Builder For WooCommerce unspecified —
TIMELINE Jul 10 Reserved by CNA Aug 16 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0037 30.4 —
AFFECTED Product Versions Fixed WPvivid — Backup, Migration & Staging unspecified —
TIMELINE Aug 13 Reserved by CNA Aug 15 Public exploit reference published Aug 16 Published (CNA: WPScan)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-73060 | 8.7 | 30.4 | scriban | scriban | CWE-770 | Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply |
| CVE-2026-74251 | 9.3 | 30.3 | phoca.cz | Phoca Cart extension for Joomla | CWE-89 | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute fil… |
| CVE-2026-17123 | 8.8 | 28.6 | wproyal | Royal Addons for Elementor – Addons and Templates Kit for Elementor | CWE-918 | Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-… |
| CVE-2026-19717 | 7.5 | 27.6 | Unknown | CatFolders Document Gallery & PDF Library | CWE-200 | CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure v… |
| CVE-2026-13167 | 4.3 | 27.7 | wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI | CWE-862 | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builde… |
| CVE-2026-74789 | 8.7 | 27.0 | scriban | scriban | CWE-400 | Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations |
| CVE-2026-13424 | 7.2 | 25.8 | ladela | Online Scheduling and Appointment Booking System – Bookly | CWE-79 | Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated St… |
| CVE-2026-15602 | 4.9 | 25.8 | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | CWE-89 | NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_par… |
| CVE-2026-9767 | 6.5 | 25.7 | weblizar | The School Management – Education & Learning ERP | CWE-89 | The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'ord… |
| CVE-2026-18316 | 9.1 | 25.2 | solacewp | Solace Extra | CWE-862 | Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content… |
| CVE-2026-19714 | 9.1 | 25.2 | Unknown | Simple JWT Login | CWE-287 | Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Googl… |
| CVE-2026-74795 | 8.7 | 24.5 | scriban | scriban | CWE-674 | Scriban before 6.6.0 Denial of Service via Uncontrolled Recursion |
| CVE-2026-18385 | 5.4 | 24.6 | properfraction | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | CWE-94 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User P… |
| CVE-2026-17533 | 7.2 | 24.4 | Unknown | All-in-One WP Migration and Backup | CWE-269 | All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network… |
| CVE-2026-2497 | 7.2 | 24.3 | bestwebsoft | Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress | CWE-89 | Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via G… |
| CVE-2026-74792 | 8.7 | 23.4 | scriban | scriban | CWE-674 | Scriban before 7.0.0 Stack Overflow via nested array initializers |
| CVE-2026-15002 | 7.2 | 23.3 | bluemediapl | Autopay | CWE-79 | Autopay <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting via 'bm_woocom… |
| CVE-2026-18653 | 7.2 | 23.3 | Unknown | WP Directory Kit | CWE-89 | WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter |
| CVE-2026-11780 | 6.4 | 23.3 | expresstech | Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker | CWE-79 | Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored … |
| CVE-2026-15345 | 4.3 | 23.2 | shortpixel | ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization | CWE-862 | ShortPixel Adaptive Images <= 3.11.5 - Missing Authorization to Authenticated… |
| CVE-2026-18347 | 4.3 | 23.1 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-862 | Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensiti… |
| CVE-2026-73061 | 9.3 | 22.8 | scriban | scriban | CWE-284 | Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor |
| CVE-2026-12998 | 5.3 | 22.7 | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | CWE-639 | Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenti… |
| CVE-2026-19955 | 2.0 | 21.9 | n/a | TrailDB | CWE-119 | TrailDB TOC Validation tdb.c tdb_open out-of-bounds |
| CVE-2026-12905 | 4.3 | 21.5 | ladela | Online Scheduling and Appointment Booking System – Bookly | CWE-639 | Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authentic… |
| CVE-2026-2283 | 4.9 | 21.3 | faiyazalam | User Login History | CWE-89 | User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection vi… |
| CVE-2026-15351 | 4.9 | 21.3 | wcvendors | WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors | CWE-89 | WC Vendors <= 2.7.0 - Authenticated (Shop Manager+) SQL Injection via 'status… |
| CVE-2026-17582 | 4.9 | 21.3 | quantumcloud | Slider Hero with Video Background, Animation | CWE-89 | Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Admini… |
| CVE-2026-74790 | 9.3 | 21.1 | scriban | scriban | CWE-693 | Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache |
| CVE-2026-19929 | 2.1 | 20.9 | n/a | OpenBoxes | CWE-791 | OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate sp… |
| CVE-2026-16079 | 6.5 | 20.6 | pdamsten | Fullscreen Galleria | CWE-89 | Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection vi… |
| CVE-2026-15009 | 6.1 | 20.5 | saadiqbal | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | CWE-79 | Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMess… |
| CVE-2026-73057 | 8.7 | 20.3 | stoatchat | stoatchat | CWE-400 | stoatchat before 0.15.0 Uncapped SVG Rendering Denial of Service |
| CVE-2026-73062 | 8.7 | 20.3 | scriban | scriban | CWE-770 | Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication |
| CVE-2026-74783 | 8.7 | 20.3 | scriban | scriban | CWE-674 | Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service |
| CVE-2026-74787 | 8.7 | 20.3 | scriban | scriban | CWE-674 | Scriban before 7.0.0 Uncontrolled Recursion via object.to_json |
| CVE-2026-74788 | 8.7 | 20.3 | scriban | scriban | CWE-770 | Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right |
| CVE-2026-74794 | 8.7 | 20.3 | scriban | scriban | CWE-674 | Scriban before 6.6.0 Denial of Service via Infinite Recursion |
| CVE-2026-74785 | 7.1 | 19.6 | scriban | scriban | CWE-400 | Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption |
| CVE-2026-74786 | 7.1 | 19.6 | scriban | scriban | CWE-770 | Scriban before 7.0.0 Denial of Service via Unbounded Template Output |
| CVE-2026-19613 | 6.5 | 19.2 | Unknown | ECS | CWE-200 | ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeat… |
| CVE-2026-19957 | 2.1 | 19.2 | graphlit | graphlit-mcp-server | CWE-918 | graphlit graphlit-mcp-server ssrf-test Endpoint tools.ts fetch server-side re… |
| CVE-2026-74791 | 9.2 | 19.1 | scriban | scriban | CWE-226 | Scriban before 7.0.0 Authorization Bypass via Stale Include Cache |
| CVE-2026-15963 | 6.5 | 19.1 | expresstech | Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker | CWE-89 | Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Inj… |
| CVE-2026-19926 | 5.5 | 18.5 | n/a | Evergreen | CWE-74 | Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection |
| CVE-2026-74784 | 8.7 | 18.2 | scriban | scriban | CWE-770 | Scriban before 7.2.0 Denial of Service via array.insert_at |
| CVE-2026-15066 | 6.4 | 18.1 | timwhitlock | Loco Translate | CWE-79 | Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scrip… |
| CVE-2026-12477 | 4.4 | 17.7 | wpmonks | Gravity Booster – Styles & Layouts for Gravity Forms | CWE-79 | Gravity Booster <= 5.26 - Authenticated (Editor+) Stored Cross-Site Scripting… |
| CVE-2024-58375 | 8.7 | 17.2 | opentofu | opentofu | CWE-497 | OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation |
| CVE-2026-10734 | 7.2 | 17.0 | infility | Infility Global | CWE-79 | Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via … |
| CVE-2026-19933 | 2.1 | 16.9 | DefaultFuction | Customer-Relationship-Management-In-C-Project | CWE-119 | DefaultFuction Customer-Relationship-Management-In-C-Project Customer Search … |
| CVE-2026-19927 | 2.1 | 16.8 | n/a | OpenBoxes | CWE-918 | OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side… |
| CVE-2026-19928 | 2.1 | 16.8 | n/a | OpenBoxes | CWE-266 | OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges mana… |
| CVE-2026-19726 | 6.5 | 16.3 | Unknown | Visualizer | CWE-863 | Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure |
| CVE-2025-10005 | 4.3 | 15.7 | buildwps | PPWP – Password Protect Pages | CWE-639 | Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference … |
| CVE-2026-19930 | 2.1 | 15.6 | n/a | Dolibarr | CWE-74 | Dolibarr User Cloning card.php ldap injection |
| CVE-2026-73058 | 6.9 | 15.1 | stoatchat | stoatchat | CWE-918 | stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass |
| CVE-2026-19932 | 2.1 | 14.9 | DefaultFuction | Notice-System-Managent | CWE-74 | DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.ev… |
| CVE-2026-74796 | 7.0 | 13.9 | opentofu | opentofu | CWE-59 | OpenTofu before 1.11.7 Symlink Following Path Traversal |
| CVE-2026-19958 | 2.1 | 13.7 | iatsiuk | pptr-mcp | CWE-74 | iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection |
| CVE-2026-16779 | 4.3 | 13.0 | extendthemes | Kubio AI Page Builder | CWE-862 | Kubio AI Page Builder <= 2.8.5 - Missing Authorization to Authenticated (Cont… |
| CVE-2026-73059 | 7.1 | 12.9 | stoatchat | stoatchat | CWE-863 | stoatchat before 0.15.0 Permission Bypass via message_fetch |
| CVE-2026-19964 | 2.0 | 12.5 | Jij-Inc | Jij-MCP-Server | CWE-94 | Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection |
| CVE-2026-19956 | 5.3 | 12.1 | gomarble-ai | facebook-ads-mcp-server | CWE-918 | gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-sid… |
| CVE-2026-19711 | 6.5 | 11.8 | Unknown | Premium Packages | CWE-284 | Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbit… |
| CVE-2026-19925 | 2.0 | 11.5 | SourceCodester | Stock Management System | CWE-74 | SourceCodester Stock Management System Master.php delete_supplier sql injection |
| CVE-2026-2487 | 4.4 | 10.6 | weblizar | Admin Custom Login | CWE-79 | Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Sit… |
| CVE-2026-15726 | 6.4 | 10.3 | cryout-creations | Serious Slider | CWE-79 | Serious Slider <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-19921 | 2.1 | 10.2 | code-projects | Online Shopping System | CWE-74 | code-projects Online Shopping System homeaction.php sql injection |
| CVE-2026-19923 | 2.1 | 10.2 | code-projects | Online Shopping System | CWE-74 | code-projects Online Shopping System checkout_process.php sql injection |
| CVE-2026-19934 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System vieworder.php sql injection |
| CVE-2026-19922 | 2.0 | 10.0 | code-projects | Online Shopping System | CWE-79 | code-projects Online Shopping System checkout.php cross site scripting |
| CVE-2026-15790 | 6.4 | 9.9 | emarket-design | Video Gallery – YouTube Gallery, Playlist & Video Grid | CWE-79 | Video Gallery <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting … |
| CVE-2026-15604 | 6.4 | 9.3 | toocheke | Toocheke Companion | CWE-79 | Toocheke Companion <= 2.10 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-16758 | 6.4 | 9.3 | aliakro | Snippet Shortcodes | CWE-79 | Snippet Shortcodes <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site … |
| CVE-2026-16775 | 6.4 | 9.3 | smub | Smash Balloon Social Post Feed – Simple Social Feeds for WordPress | CWE-79 | Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored… |
| CVE-2026-18402 | 6.4 | 9.3 | brainstormforce | SureDash – Community, Courses & Member Dashboard | CWE-79 | SureDash <= 1.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-2357 | 6.4 | 8.6 | boldthemes | Bold Page Builder | CWE-79 | Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-19712 | 6.1 | 8.0 | Unknown | Masteriyo LMS | CWE-79 | Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description |
| CVE-2026-74797 | 2.3 | 7.2 | opentofu | opentofu | CWE-400 | OpenTofu before 1.11.4 Denial of Service via malicious zip |
| CVE-2026-13712 | 5.4 | 5.9 | Unknown | Divi | CWE-79 | Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL |
| CVE-2026-17608 | 6.5 | 5.3 | aresit | WP Compress – Instant Performance & Speed Optimization | CWE-352 | WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Dele… |
| CVE-2026-74578 | 7.1 | 4.4 | Linux | Linux | — | crypto: algif_skcipher - force synchronous processing on trees without ctx->s… |
| CVE-2026-15384 | 5.7 | 1.5 | Unknown | Manual Image Crop | CWE-287 | Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite v… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-16 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.