Vendor score = sum of Active CVE scores · Each CVE: 10 pts base, boosted by:
KEV×2.0AC: Low×1.2PR: None×1.3PR: Low×1.1Auto×1.3
Vendor Risk Ranking
Ranked by cumulative score from Active CVEs in the selected period · AV:Network only · Click vendor name for CVE details
126 vendors
Recently Active CVEs
Newest 89 CVEs sorted by SSVC Active timestamp · NEW = Active from day one · NONE→ACT / POC→ACT = confirmed upgrade (git diff)
89 entries
| Status | CVE ID | Vendor | Product | Score |
|---|---|---|---|---|
| NONE→ACT | CVE-2026-21962 | Oracle | Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in | 40.6 |
| NONE→ACT | CVE-2026-73570 | Zimbra | Collaboration | 26.0 |
| NONE→ACT | CVE-2026-72529 | TrueConf | TrueConf Server | 40.6 |
| NONE→ACT | CVE-2026-72530 | TrueConf | TrueConf Server | 26.0 |
| NONE→ACT | CVE-2026-64849 | mlflow | MLflow | 40.6 |
| NONE→ACT | CVE-2026-65400 | Apple | macOS | 40.6 |
| POC→ACT | CVE-2026-55040 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | 40.6 |
| NONE→ACT | CVE-2026-59310 | VMware | Cloud Foundation | 40.6 |
| NONE→ACT | CVE-2026-33824 | Microsoft | Windows 10 Version 1607 | 40.6 |
| NONE→ACT | CVE-2026-72898 | Metabase | Metabase | 40.6 |
| NONE→ACT | CVE-2026-20349 | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 40.6 |
| NONE→ACT | CVE-2026-63077 | JetBrains | TeamCity | 40.6 |
| NONE→ACT | CVE-2026-9198 | IBM | Langflow OSS | 40.6 |
| NONE→ACT | CVE-2026-34486 | Apache Software Foundation | Apache Tomcat | 40.6 |
| NONE→ACT | CVE-2026-18556 | N-able | N-central | 33.8 |
| NONE→ACT | CVE-2026-18577 | N-able | N-central | 33.8 |
| NONE→ACT | CVE-2026-20316 | Cisco | Cisco Secure Firewall Management Center (FMC) | 40.6 |
| NONE→ACT | CVE-2026-16812 | Arista Networks | VeloCloud Orchestrator On-Prem | 40.6 |
| NONE→ACT | CVE-2025-68686 | Fortinet | FortiOS | 26.0 |
| NONE→ACT | CVE-2026-50522 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | 40.6 |
| NONE→ACT | CVE-2026-16232 | checkpoint | Multi-Domain Security Management | 40.6 |
| NONE→ACT | CVE-2026-0770 | Langflow | Langflow | 40.6 |
| NONE→ACT | CVE-2026-63030 | WordPress | WordPress | 40.6 |
| NONE→ACT | CVE-2026-60137 | WordPress | WordPress | 26.0 |
| POC→ACT | CVE-2026-39808 | Fortinet | FortiSandbox | 40.6 |
| NONE→ACT | CVE-2026-25089 | Fortinet | FortiSandbox | 40.6 |
| NONE→ACT | CVE-2026-58644 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | 40.6 |
| NONE→ACT | CVE-2023-4346 | KNX Association | KNX Protocol Connection Authorization Option 1 | 40.6 |
| NONE→ACT | CVE-2026-46817 | Oracle | Oracle Payments | 40.6 |
| NEW | CVE-2026-15410 | SonicWall | SMA1000 | 24.0 |
| NEW | CVE-2026-15409 | SonicWall | SMA1000 | 40.6 |
| NEW | CVE-2026-56164 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | 40.6 |
| POC→ACT | CVE-2026-48939 | icagenda.com | iCagenda extension for Joomla | 40.6 |
| NONE→ACT | CVE-2026-56291 | balbooa.com | balbooa.com Balbooa Forms extension for Joomla | 40.6 |
| NONE→ACT | CVE-2026-48282 | Adobe | ColdFusion 2023 | 40.6 |
| NONE→ACT | CVE-2026-56290 | joomlack.fr | JoomlaCK.fr Page Builder CK extension for Joomla | 40.6 |
| POC→ACT | CVE-2026-55255 | langflow-ai | langflow | 22.0 |
| NONE→ACT | CVE-2026-48908 | joomshaper.net | SP Page Builder extension for Joomla | 40.6 |
| NONE→ACT | CVE-2026-45659 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | 26.4 |
| NONE→ACT | CVE-2026-48558 | SimpleHelp | SimpleHelp | 40.6 |
| POC→ACT | CVE-2026-20230 | Cisco | Cisco Unified Communications Manager | 31.2 |
| NONE→ACT | CVE-2026-12569 | PTC | FlexPLM | 40.6 |
| NONE→ACT | CVE-2026-34908 | Ubiquiti Inc | EFG | 40.6 |
| NONE→ACT | CVE-2026-34909 | Ubiquiti Inc | EFG | 40.6 |
| NONE→ACT | CVE-2026-34910 | Ubiquiti Inc | EFG | 40.6 |
| POC→ACT | CVE-2026-20253 | Splunk | Splunk Enterprise | 40.6 |
| NONE→ACT | CVE-2026-48907 | joomlacontenteditor.net | Joomla Content Editor (JCE) extension for Joomla | 40.6 |
| NEW | CVE-2026-20262 | Cisco | Cisco Catalyst SD-WAN Manager | 26.4 |
| NONE→ACT | CVE-2026-54420 | LiteSpeed Technologies | cPanel Plugin | 22.0 |
| NONE→ACT | CVE-2026-35273 | Oracle | PeopleSoft Enterprise PeopleTools | 40.6 |
| POC→ACT | CVE-2026-10520 | Ivanti | Sentry | 40.6 |
| NONE→ACT | CVE-2026-7473 | Arista Networks | EOS | 40.6 |
| NONE→ACT | CVE-2026-50751 | checkpoint | Quantum Security Gateway | 40.6 |
| NONE→ACT | CVE-2026-42271 | BerriAI | litellm | 26.4 |
| NONE→ACT | CVE-2026-28318 | SolarWinds | Serv-U | 40.6 |
| NONE→ACT | CVE-2026-45247 | Mirasvit | Full Page Cache Warmer for Magento 2 | 40.6 |
| NONE→ACT | CVE-2024-21182 | Oracle | WebLogic Server | 40.6 |
| NONE→ACT | CVE-2026-0257 | Palo Alto Networks | Cloud NGFW | 31.2 |
| NONE→ACT | CVE-2026-8398 | AVB Disc Soft | DAEMON Tools Lite | 40.6 |
| NEW | CVE-2026-48027 | nrwl | nx-console | 40.6 |
| NONE→ACT | CVE-2026-48172 | LiteSpeed Technologies | cPanel Plugin | 40.6 |
| NONE→ACT | CVE-2026-9082 | Drupal | Drupal core | 40.6 |
| NEW | CVE-2026-20182 | Cisco | Cisco Catalyst SD-WAN Controller | 40.6 |
| NONE→ACT | CVE-2026-42208 | BerriAI | litellm | 40.6 |
| NEW | CVE-2026-6973 | Ivanti | Endpoint Manager Mobile | 24.0 |
| NEW | CVE-2026-0300 | Palo Alto Networks | Cloud NGFW | 40.6 |
| POC→ACT | CVE-2026-41940 | WebPros | cPanel | 40.6 |
| NONE→ACT | CVE-2024-7399 | Samsung Electronics | MagicINFO 9 Server | 26.4 |
| NONE→ACT | CVE-2026-39987 | marimo-team | marimo | 40.6 |
| NONE→ACT | CVE-2026-20122 | Cisco | Cisco Catalyst SD-WAN Manager | 26.4 |
| NONE→ACT | CVE-2026-20133 | Cisco | Cisco Catalyst SD-WAN Manager | 26.4 |
| NONE→ACT | CVE-2025-2749 | Kentico | Xperience | 24.0 |
| POC→ACT | CVE-2024-27199 | JetBrains | TeamCity | 40.6 |
| NONE→ACT | CVE-2026-34197 | Apache Software Foundation | Apache ActiveMQ | 26.4 |
| NEW | CVE-2026-32201 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | 40.6 |
| POC→ACT | CVE-2026-21643 | Fortinet | FortiClientEMS | 40.6 |
| NONE→ACT | CVE-2026-1340 | Ivanti | Endpoint Manager Mobile | 40.6 |
| NONE→ACT | CVE-2026-35616 | Fortinet | FortiClientEMS | 40.6 |
| NONE→ACT | CVE-2026-3055 | Citrix | NetScaler ADC | 40.6 |
| NONE→ACT | CVE-2025-53521 | F5 | BIG-IP | 40.6 |
| POC→ACT | CVE-2026-33634 | BerriAI | litellm | 26.4 |
| POC→ACT | CVE-2026-33017 | langflow-ai | langflow | 40.6 |
| NONE→ACT | CVE-2025-54068 | livewire | livewire | 26.0 |
| POC→ACT | CVE-2025-32432 | craftcms | cms | 40.6 |
| NONE→ACT | CVE-2026-20131 | Cisco | Cisco Secure Firewall Management Center (FMC) | 40.6 |
| NONE→ACT | CVE-2026-20963 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | 40.6 |
| NONE→ACT | CVE-2025-66376 | Zimbra | Collaboration | 31.2 |
| POC→ACT | CVE-2025-47813 | wftpserver | Wing FTP Server | 26.4 |
| NONE→ACT | CVE-2025-68613 | n8n-io | n8n | 26.4 |
Monthly Risk Score TrendAug 2023 – Aug 2026
Rolling 36-month cumulative score — CVEs older than 3 years expire · hover for breakdown
Cisco
Microsoft
Ivanti
Fortinet
Palo Alto Networks
Oracle
Apache Software Foundation
SolarWinds
Apple
Adobe
SonicWall
Citrix
JetBrains
Progress Software Corporation
Atlassian