boxscore/security
Sunday, August 16, 2026 · all times UTC← 2026-08-15 · archive · 2026-08-17 →

109 CVEs published August 16, 2026: 14 critical, 33 high, 43 medium, 19 low; 0 in KEV; 3 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 84 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published59271473214442563
KEV catalog size1670

867 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux1263284836316789802730.17.8.0017+1247
microsoft442180313112194288378331.87.8.0038-195
google4946172140228187351.16.5.0023+48
red hat1423642216615818400.07.1.0025+124
apple2246576811229372.87.1.0027+2
canonical11149320000.09.9.0029+11
suse551220000.07.3.0022+5
android010100161100.08.4.01710
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco315192590961427.57.8.0033+24
palo alto networks12270114101427.44.5.0019+2
fortinet7253612128624.06.0.0051-3
sonicwall1012354017216.77.8.0024+8
vmware01247012100.08.7.00440
netgear990054800.04.3.0031+9
ivanti38130033562.57.9.5751+3
checkpoint1541003240.09.3.2062+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache101238451207214020.87.5.0048+100
mozilla1734226501300.09.1.0031-1
gitlab132808162427.15.1.0026+13
github570520000.08.6.0041+5
docker140130100.05.7.0014+1
wordpress1412105250.08.8.3700+1
drupal01100051100.09.8.88320
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01113212539304574030.37.6.0031-1
ibm19230061139946710.37.5.0030+192
adobe6010022512217544.07.8.0036+46
progress1639112080912.68.1.0027+16
solarwinds0201611011420.09.1.00500
veeam10123720400.08.6.0027+10
zohocorp472410000.08.8.0099+4
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link1624150622614.29.3.0209+16
siemens192011612100.07.3.0011+19
hikvision0704202114.37.2.00250
bosch030300000.08.1.00280
schneider electric031200100.08.7.00200
synology110100000.07.3.0013+1
honeywell010010000.06.9.00310
mitsubishi electric010100000.07.1.00130
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
elastic4867013540300.06.5.0027+48
siyuan-note5461308230000.08.8.0025+54
mongodb3258337162200.07.1.0024+32
surrealdb057326253000.07.1.0025-1
zephyrproject2749017266000.06.5.0016+26
gitea4848715224000.06.5.0027+48
netty34462891000.07.5.0046+3
grafana142314223000.06.5.0033-5

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.993199.99.8
CVE-2026-63030.956099.99.8
CVE-2026-34486.829399.67.5
CVE-2026-16232.733099.49.3
CVE-2026-60137.731099.45.9
CVE-2026-0770.568899.09.8
CVE-2026-62144.206297.39.1
CVE-2021-27137.164996.78.1
CVE-2026-15733.135496.19.8
CVE-2026-63077.107295.49.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.1040KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4836210.0.0207
CVE-2026-1918810.0.0189
CVE-2026-7329910.0.0121
CVE-2026-4435910.0.0100
CVE-2026-4561810.0.0095
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
linux1914
oracle1108
microsoft461
google451
ibm261
red hat241
apache205
apple169
adobe74
elastic67
Most KEV additions (YTD)
VendorKEV
microsoft33
cisco14
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171733
CVE-2021-27102Accellion2021-11-171733
CVE-2021-27101Accellion2021-11-171733
CVE-2021-27103Accellion2021-11-171733
CVE-2021-21017Adobe2021-11-171733
CVE-2021-28550Adobe2021-11-171733
CVE-2021-42013Apache2021-11-171733
CVE-2021-41773Apache2021-11-171733
CVE-2021-30858Apple2021-11-171733
CVE-2021-30860Apple2021-11-171733

Transactions

EXPLOIT PUBLISHEDCVE-2026-13700 (Unknown WooMS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14229 (Unknown ECS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14230 (Unknown ECS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14832 (Unknown ShopSmart Loyalty for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16007 (AppFlowy-IO AppFlowy-Cloud). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16541 (Unknown Simply Schedule Appointments). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16611 (Unknown Product Feed PRO for WooCommerce by AdTribes). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18216 (Unknown Backup Migration). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18807 (Unknown ECS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19478 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19650 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19895 (opensourcepos Open Source Point of Sale). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19897 (mangroup dtale). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19900 (LB-LINK X-PRO). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19903 (SourceCodester Online Clothing Store). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19917 (code-projects Online Food Order System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19965 (automad). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19966 (CodeCanyon TimeCamp Integration for CRM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19967 (Open Asset Import Library Assimp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19968 (Open Asset Import Library Assimp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19969 (Open Asset Import Library Assimp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19970 (Open Asset Import Library Assimp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19972 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19973 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19974 (treefrogframework treefrog-framework). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19976 (COMFAST CF-N1-S). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19977 (EFM ipTIME A3004T). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19978 (jiantao88 android-mcp-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19984 (jkawamoto mcp-florence2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19986 (Adblock for Youtube Extension). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19988 (Alaev SEO Tools Extension). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19992 (Orange View Limited DualSafe Password Manager & Digital Vault Extension). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19993 (Webkul Bagisto). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19994 (Webkul Bagisto). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19995 (Webkul Bagisto). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19996 (Webkul Bagisto). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19997 (Webkul Bagisto). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19998 (code-projects Online Shopping System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19999 (Open Asset Import Library Assimp Assimp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-20000 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-72743 (dataease SQLBot). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-74842 (Kira-Pgr PromptShopMCP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-74843 (Wavlink WN531P3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75011 (kylecui NetForensicMCP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75012 (TOTOLINK EX1200L). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75013 (TOTOLINK EX1200L). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75014 (SourceCodester Pet Grooming Management Software). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75077 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75078 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

RESCOREDCVE-2026-19918 (SpaceX Starlink Router Gen 3). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-19919 (code-projects Online Shopping System). CVSS 6.9 → 5.5 (NVD).

Yesterday's Results

109 CVEs published. 25 box scores, 84 table rows — nothing truncated.

Edimax EW-7478APC formWlbasic command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.4     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Received
Edimax EW-7478APC setWAN command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.4     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 15  Public exploit reference published
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-77, CWE-74 · CNA: VulDB · 5 references · NVD status: Received
Edimax EW-7478APC stainfo command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.4     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 15  Public exploit reference published
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-77, CWE-74 · CNA: VulDB · 5 references · NVD status: Received
Tenda AC10 httpd R7WebsSecurityHandler improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0090   56.7     —
AFFECTED
  Product  Versions                   Fixed
  AC10     16.03.10.09_multi_TDE01 –  —
TIMELINE
  Aug 15  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-287 · CNA: VulDB · 6 references · NVD status: Received
Lemonldap-NG-Portal — Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0082   54.2     —
AFFECTED
  Product              Versions  Fixed
  Lemonldap-NG-Portal  2.0.0 –   —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 16  Published (CNA: CPANSec)
CWE-305, CWE-628 · CNA: CPANSec · 4 references · NVD status: Received
kodezen StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More — StoreEngine <= 2.1.1 - Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0081   54.0     —
AFFECTED
  Product                                                                                   Versions     Fixed
  StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 16 references · NVD status: Received
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki <= 6.1.1 - Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0080   53.7     —
AFFECTED
  Product                                                      Versions     Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 12 references · NVD status: Received
kilbot WCPOS – Point of Sale (POS) plugin for WooCommerce — WCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0073   51.4     —
AFFECTED
  Product                                             Versions     Fixed
  WCPOS – Point of Sale (POS) plugin for WooCommerce  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · 12 references · NVD status: Received
ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0070   50.2     —
AFFECTED
  Product                Versions     Fixed
  ProSolution WP Client  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 5 references · NVD status: Received
ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0064   47.8     —
AFFECTED
  Product                Versions     Fixed
  ProSolution WP Client  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 6 references · NVD status: Received
eteubert Podlove Podcast Publisher — Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0059   45.3     —
AFFECTED
  Product                    Versions     Fixed
  Podlove Podcast Publisher  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · 8 references · NVD status: Received
Net-OAuth — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0055   43.4     —
AFFECTED
  Product    Versions     Fixed
  Net-OAuth  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 16  Published (CNA: CPANSec)
CWE-757 · CNA: CPANSec · 6 references · NVD status: Received
daggerhart Query Wrangler — Query Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0055   43.4     —
AFFECTED
  Product         Versions     Fixed
  Query Wrangler  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 6 references · NVD status: Received
reputeinfosystems Contact Form, Survey, Quiz & Popup Form Builder – ARForms — Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0052   41.7     —
AFFECTED
  Product                                                    Versions     Fixed
  Contact Form, Survey, Quiz & Popup Form Builder – ARForms  unspecified  —
TIMELINE
  Jan 28  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · 2 references · NVD status: Received
croixhaug Simply Schedule Appointments — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0049   39.7     —
AFFECTED
  Product                       Versions     Fixed
  Simply Schedule Appointments  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · 12 references · NVD status: Received
Edimax EW-7478APC formWanTcpipSetup stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0047   38.7     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Received
Edimax EW-7478APC formWlSiteSurvey buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0047   38.7     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Aug 15  Public exploit reference published
  Aug 16  Reserved by CNA
  Aug 16  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · 5 references · NVD status: Received
siyuan-note siyuan — SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0045   37.4     —
AFFECTED
  Product  Versions     Fixed
  siyuan   unspecified  3.7.4
TIMELINE
  Aug 10  Reserved by CNA
  Aug 16  Published (CNA: VulnCheck)
CWE-307 · CNA: VulnCheck · 2 references · NVD status: Received
shabti Frontend Admin by DynamiApps — Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0045   37.2     —
AFFECTED
  Product                       Versions     Fixed
  Frontend Admin by DynamiApps  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · 12 references · NVD status: Received
Unknown Extra Product Options Builder for WooCommerce — Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Disclosure via getpublicfileupload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0044   36.9     —
AFFECTED
  Product                                        Versions     Fixed
  Extra Product Options Builder for WooCommerce  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 15  Public exploit reference published
  Aug 16  Published (CNA: WPScan)
CWE-862 · CNA: WPScan · 1 reference · NVD status: Received
Net-OAuth — Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  N  H    6.5   .0044   36.3     —
AFFECTED
  Product    Versions     Fixed
  Net-OAuth  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 16  Published (CNA: CPANSec)
CWE-770 · CNA: CPANSec · 4 references · NVD status: Received
wptravelengine WP Travel Engine – Tour Booking Plugin – Tour Operator Software — WP Travel Engine <= 6.8.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0042   34.6     —
AFFECTED
  Product                                                          Versions     Fixed
  WP Travel Engine – Tour Booking Plugin – Tour Operator Software  unspecified  —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 12 references · NVD status: Received
wpweaver Turnkey bbPress by WeaverTheme — Turnkey bbPress by WeaverTheme <= 1.7.1 - Authenticated (Administrator+) PHP Object Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0040   33.3     —
AFFECTED
  Product                         Versions     Fixed
  Turnkey bbPress by WeaverTheme  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · 5 references · NVD status: Received
wcproducttable Product Table & List Builder For WooCommerce — Product Table & List Builder For WooCommerce <= 5.6.0 - Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0039   31.8     —
AFFECTED
  Product                                       Versions     Fixed
  Product Table & List Builder For WooCommerce  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Aug 16  Published (CNA: Wordfence)
CWE-74 · CNA: Wordfence · 8 references · NVD status: Received
Unknown WPvivid — Backup, Migration & Staging — WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_connect
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0037   30.4     —
AFFECTED
  Product                                Versions     Fixed
  WPvivid — Backup, Migration & Staging  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 15  Public exploit reference published
  Aug 16  Published (CNA: WPScan)
CWE-22 · CNA: WPScan · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-730608.730.4scribanscribanCWE-770Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply
CVE-2026-742519.330.3phoca.czPhoca Cart extension for JoomlaCWE-89Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute fil…
CVE-2026-171238.828.6wproyalRoyal Addons for Elementor – Addons and Templates Kit for ElementorCWE-918Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-…
CVE-2026-197177.527.6UnknownCatFolders Document Gallery & PDF LibraryCWE-200CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure v…
CVE-2026-131674.327.7wpeverestEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AICWE-862Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builde…
CVE-2026-747898.727.0scribanscribanCWE-400Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations
CVE-2026-134247.225.8ladelaOnline Scheduling and Appointment Booking System – BooklyCWE-79Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated St…
CVE-2026-156024.925.8webawaysNEX-Forms – Ultimate Forms Plugin for WordPressCWE-89NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_par…
CVE-2026-97676.525.7weblizarThe School Management – Education & Learning ERPCWE-89The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'ord…
CVE-2026-183169.125.2solacewpSolace ExtraCWE-862Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content…
CVE-2026-197149.125.2UnknownSimple JWT LoginCWE-287Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Googl…
CVE-2026-747958.724.5scribanscribanCWE-674Scriban before 6.6.0 Denial of Service via Uncontrolled Recursion
CVE-2026-183855.424.6properfractionPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePressCWE-94Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User P…
CVE-2026-175337.224.4UnknownAll-in-One WP Migration and BackupCWE-269All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network…
CVE-2026-24977.224.3bestwebsoftGallery by BestWebSoft – Customizable Image and Photo Galleries for WordPressCWE-89Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via G…
CVE-2026-747928.723.4scribanscribanCWE-674Scriban before 7.0.0 Stack Overflow via nested array initializers
CVE-2026-150027.223.3bluemediaplAutopayCWE-79Autopay <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting via 'bm_woocom…
CVE-2026-186537.223.3UnknownWP Directory KitCWE-89WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter
CVE-2026-117806.423.3expresstechQuiz and Survey Master (QSM) – Quiz Maker & Survey MakerCWE-79Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored …
CVE-2026-153454.323.2shortpixelShortPixel Adaptive Images – WebP, AVIF, CDN, Image OptimizationCWE-862ShortPixel Adaptive Images <= 3.11.5 - Missing Authorization to Authenticated…
CVE-2026-183474.323.1themeumKirki – Freeform Page Builder, Website Builder & CustomizerCWE-862Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensiti…
CVE-2026-730619.322.8scribanscribanCWE-284Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor
CVE-2026-129985.322.7wpmudevForminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-639Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenti…
CVE-2026-199552.021.9n/aTrailDBCWE-119TrailDB TOC Validation tdb.c tdb_open out-of-bounds
CVE-2026-129054.321.5ladelaOnline Scheduling and Appointment Booking System – BooklyCWE-639Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authentic…
CVE-2026-22834.921.3faiyazalamUser Login HistoryCWE-89User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection vi…
CVE-2026-153514.921.3wcvendorsWC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product VendorsCWE-89WC Vendors <= 2.7.0 - Authenticated (Shop Manager+) SQL Injection via 'status…
CVE-2026-175824.921.3quantumcloudSlider Hero with Video Background, AnimationCWE-89Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Admini…
CVE-2026-747909.321.1scribanscribanCWE-693Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache
CVE-2026-199292.120.9n/aOpenBoxesCWE-791OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate sp…
CVE-2026-160796.520.6pdamstenFullscreen GalleriaCWE-89Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection vi…
CVE-2026-150096.120.5saadiqbalAdvanced File Manager – Ultimate File Manager for WordPress And Document Library SolutionCWE-79Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMess…
CVE-2026-730578.720.3stoatchatstoatchatCWE-400stoatchat before 0.15.0 Uncapped SVG Rendering Denial of Service
CVE-2026-730628.720.3scribanscribanCWE-770Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication
CVE-2026-747838.720.3scribanscribanCWE-674Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service
CVE-2026-747878.720.3scribanscribanCWE-674Scriban before 7.0.0 Uncontrolled Recursion via object.to_json
CVE-2026-747888.720.3scribanscribanCWE-770Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right
CVE-2026-747948.720.3scribanscribanCWE-674Scriban before 6.6.0 Denial of Service via Infinite Recursion
CVE-2026-747857.119.6scribanscribanCWE-400Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption
CVE-2026-747867.119.6scribanscribanCWE-770Scriban before 7.0.0 Denial of Service via Unbounded Template Output
CVE-2026-196136.519.2UnknownECSCWE-200ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeat…
CVE-2026-199572.119.2graphlitgraphlit-mcp-serverCWE-918graphlit graphlit-mcp-server ssrf-test Endpoint tools.ts fetch server-side re…
CVE-2026-747919.219.1scribanscribanCWE-226Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
CVE-2026-159636.519.1expresstechQuiz and Survey Master (QSM) – Quiz Maker & Survey MakerCWE-89Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Inj…
CVE-2026-199265.518.5n/aEvergreenCWE-74Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection
CVE-2026-747848.718.2scribanscribanCWE-770Scriban before 7.2.0 Denial of Service via array.insert_at
CVE-2026-150666.418.1timwhitlockLoco TranslateCWE-79Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scrip…
CVE-2026-124774.417.7wpmonksGravity Booster – Styles & Layouts for Gravity FormsCWE-79Gravity Booster <= 5.26 - Authenticated (Editor+) Stored Cross-Site Scripting…
CVE-2024-583758.717.2opentofuopentofuCWE-497OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation
CVE-2026-107347.217.0infilityInfility GlobalCWE-79Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via …
CVE-2026-199332.116.9DefaultFuctionCustomer-Relationship-Management-In-C-ProjectCWE-119DefaultFuction Customer-Relationship-Management-In-C-Project Customer Search …
CVE-2026-199272.116.8n/aOpenBoxesCWE-918OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side…
CVE-2026-199282.116.8n/aOpenBoxesCWE-266OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges mana…
CVE-2026-197266.516.3UnknownVisualizerCWE-863Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure
CVE-2025-100054.315.7buildwpsPPWP – Password Protect PagesCWE-639Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference …
CVE-2026-199302.115.6n/aDolibarrCWE-74Dolibarr User Cloning card.php ldap injection
CVE-2026-730586.915.1stoatchatstoatchatCWE-918stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass
CVE-2026-199322.114.9DefaultFuctionNotice-System-ManagentCWE-74DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.ev…
CVE-2026-747967.013.9opentofuopentofuCWE-59OpenTofu before 1.11.7 Symlink Following Path Traversal
CVE-2026-199582.113.7iatsiukpptr-mcpCWE-74iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection
CVE-2026-167794.313.0extendthemesKubio AI Page BuilderCWE-862Kubio AI Page Builder <= 2.8.5 - Missing Authorization to Authenticated (Cont…
CVE-2026-730597.112.9stoatchatstoatchatCWE-863stoatchat before 0.15.0 Permission Bypass via message_fetch
CVE-2026-199642.012.5Jij-IncJij-MCP-ServerCWE-94Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection
CVE-2026-199565.312.1gomarble-aifacebook-ads-mcp-serverCWE-918gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-sid…
CVE-2026-197116.511.8UnknownPremium PackagesCWE-284Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbit…
CVE-2026-199252.011.5SourceCodesterStock Management SystemCWE-74SourceCodester Stock Management System Master.php delete_supplier sql injection
CVE-2026-24874.410.6weblizarAdmin Custom LoginCWE-79Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Sit…
CVE-2026-157266.410.3cryout-creationsSerious SliderCWE-79Serious Slider <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-199212.110.2code-projectsOnline Shopping SystemCWE-74code-projects Online Shopping System homeaction.php sql injection
CVE-2026-199232.110.2code-projectsOnline Shopping SystemCWE-74code-projects Online Shopping System checkout_process.php sql injection
CVE-2026-199342.110.2itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System vieworder.php sql injection
CVE-2026-199222.010.0code-projectsOnline Shopping SystemCWE-79code-projects Online Shopping System checkout.php cross site scripting
CVE-2026-157906.49.9emarket-designVideo Gallery – YouTube Gallery, Playlist & Video GridCWE-79Video Gallery <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting …
CVE-2026-156046.49.3toochekeToocheke CompanionCWE-79Toocheke Companion <= 2.10 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-167586.49.3aliakroSnippet ShortcodesCWE-79Snippet Shortcodes <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site …
CVE-2026-167756.49.3smubSmash Balloon Social Post Feed – Simple Social Feeds for WordPressCWE-79Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored…
CVE-2026-184026.49.3brainstormforceSureDash – Community, Courses & Member DashboardCWE-79SureDash <= 1.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-23576.48.6boldthemesBold Page BuilderCWE-79Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-197126.18.0UnknownMasteriyo LMSCWE-79Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description
CVE-2026-747972.37.2opentofuopentofuCWE-400OpenTofu before 1.11.4 Denial of Service via malicious zip
CVE-2026-137125.45.9UnknownDiviCWE-79Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL
CVE-2026-176086.55.3aresitWP Compress – Instant Performance & Speed OptimizationCWE-352WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Dele…
CVE-2026-745787.14.4LinuxLinuxcrypto: algif_skcipher - force synchronous processing on trees without ctx->s…
CVE-2026-153845.71.5UnknownManual Image CropCWE-287Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite v…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-16 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.