Resources
CVE publication trends
CVE statistics built from every record published since 2020, split by CVSS severity and the organization that assigned it. Dates are publication dates, not discovery dates.
CVEs published per day
251
In 2026 — one every 6 minutes
Growth vs 2025
+92%
131 per day in 2025
High or Critical per day
130
+142% — up from 54 per day in 2025
Published without a CVSS score
18.8%
45,061 of 239,457 records
The current month is incomplete: the dashed segment is a run-rate estimate for the full month, scaled from the days elapsed so far. Low and Unknown are hidden by default — select them in the legend to add them. Dotted rules mark model releases, shown for timing reference only — not as an attribution of CVE volume to any release. Severity is the CVSS base severity from the CNA record, falling back to CISA ADP enrichment. Records with no score in either container are counted as Unknown.
Latest critical vulnerabilities
Last updated UTC
The 20 most recent records scored 9.0 or above. Every identifier links to its full record at cve.org.
| Published | CVE | CVSS | Assigner | Summary |
|---|---|---|---|---|
| 2026-09-15 | CVE-2026-91998 | 9.4 | VulnCheck | Casdoor through 4.4.0 Cross-Organization User Administration via /api/mcp |
| 2026-09-15 | CVE-2026-91995 | 9.3 | VulnCheck | pig before 4.1.0 Unverified Password Change via /register/password |
| 2026-09-15 | CVE-2026-91988 | 9.2 | VulnCheck | atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP |
| 2026-09-15 | CVE-2026-91949 | 9.2 | VulnCheck | FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass |
| 2026-09-15 | CVE-2026-91939 | 9.3 | VulnCheck | Cotonti 1.0.0 Comments Plugin PHP Object Injection via ci Parameter |
| 2026-09-15 | CVE-2026-91749 | 9.6 | Chrome | Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside… |
| 2026-09-15 | CVE-2026-91728 | 9.6 | Chrome | Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a… |
| 2026-09-15 | CVE-2026-91003 | 9.4 | VulDB | D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow |
| 2026-09-15 | CVE-2026-91001 | 9.4 | VulDB | D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow |
| 2026-09-15 | CVE-2026-90847 | 9.4 | VulDB | EFM ipTIME C200E System Setup iux_set.cgi os command injection |
| 2026-09-15 | CVE-2026-90711 | 9.1 | openjs | proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet |
| 2026-09-15 | CVE-2026-89308 | 9.3 | ENISA | Arbitrary command execution in TrxTimeATTENDANCE |
| 2026-09-15 | CVE-2026-89040 | 9.8 | cisa-cg | Tencent Mass Service Engine in Cluster (MSEC) path traversal |
| 2026-09-15 | CVE-2026-89026 | 9.3 | VulnCheck | Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate |
| 2026-09-15 | CVE-2026-89022 | 9.1 | VulnCheck | BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion |
| 2026-09-15 | CVE-2026-87230 | 10.0 | oracle | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is… |
| 2026-09-15 | CVE-2026-87223 | 9.1 | oracle | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is… |
| 2026-09-15 | CVE-2026-87217 | 9.1 | oracle | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is… |
| 2026-09-15 | CVE-2026-87214 | 9.1 | oracle | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is… |
| 2026-09-15 | CVE-2026-87189 | 9.1 | oracle | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is… |
Reading this data
Unknown is not a small bucket
18.8% of records carry no CVSS score in either the CNA container or CISA's ADP enrichment. Coverage improves sharply from 2023 onward, so the Unknown band shrinking over time reflects reporting practice, not a change in the vulnerabilities themselves.
History is not fixed
CISA's Vulnrichment programme retroactively adds severity to older records. A CVE published in 2022 with no score can be scored years later, which moves a bar that has already been drawn. Every refresh recomputes the full history rather than appending.
Triage does not scale by hand
At 130 High or Critical records a day, reading the feed is not a strategy. What matters is which of them reach code you actually ship, which is what vulnerability tracking against an SBOM is for.
Volume is concentrated
480 CNAs assigned these records, but the top 20 account for the bulk of them. Filter by organization to separate a genuine industry trend from one assigner changing how it publishes.
Source: CVEProject/cvelistV5 · Snapshot taken Sep 16, 2026 UTC
CVE data, explained
Common questions about CVE volume, severity scoring and what the trend means for compliance
How many CVEs are published each year?
47,804 CVE records were published in 2025, up 20% on the year before. 2026 has already reached 64,840 with months still to run.
Volume has grown every year since the CVE Program began, but the rate of growth changed sharply in 2026. Use the chart above to see the trend by month, quarter or year.
Where can I find current CVE statistics?
On this page. The chart and figures above are CVE statistics rebuilt daily from the CVE Program's cvelistV5 repository, the same source the CVE Program publishes from.
They cover publication volume by CVSS severity, by assigning organization and by week, month, quarter or year, along with the most recent critical records. For a single vulnerability's detail, follow any identifier through to cve.org.
Why has the number of CVEs increased so sharply?
Three things are happening at once, and the published record cannot separate them.
More organizations can now assign CVE IDs, so vulnerabilities that were previously never registered are being recorded. Automated and AI-assisted vulnerability discovery has raised how much any one researcher can find. And CISA's enrichment programme has back-filled detail on older records, which changes historical figures after the fact.
Rising CVE counts are therefore not by themselves evidence that software is getting less secure.
What is a CNA, or CVE Numbering Authority?
A CNA is an organization authorized to assign CVE IDs and publish records within its own scope, usually its own products. 480 CNAs appear in this dataset.
Vendors, open-source projects, bug-bounty platforms and national CERTs all act as CNAs. The largest here is mitre, with 38,999 records. Because a single CNA changing its process can move the totals noticeably, the chart lets you filter to one organization at a time.
What do the CVSS severity ratings mean?
CVSS scores a vulnerability from 0.0 to 10.0 and groups it into bands: Low (0.1-3.9), Medium (4.0-6.9), High (7.0-8.9) and Critical (9.0-10.0).
The score describes intrinsic technical characteristics such as how the vulnerability is reached and what it compromises. It is not a measure of how much any particular organization is at risk.
Why do so many CVEs have no severity score?
18.8% of the records published since 2020 carry no CVSS score in either the CNA's own data or CISA's enrichment.
Scoring was not required for most of the CVE Program's history. Coverage improves steeply from 2023 onward and is now near-universal, so the shrinking Unknown band on the chart reflects a change in reporting practice, not a change in the vulnerabilities themselves. Any analysis that ignores unscored records will understate older years.
What is the difference between a CVE and a vulnerability?
A vulnerability is a flaw in software. A CVE is a public identifier assigned to a specific, disclosed instance of one.
Most vulnerabilities never receive a CVE: they are found and fixed internally, or they fall outside any CNA's scope. CVE counts therefore measure disclosure activity, not the true quantity of flaws in existence.
Where does this CVE data come from and how current is it?
Every figure is built from the CVE Program's official cvelistV5 repository, using the snapshot taken on Sep 16, 2026 UTC.
Records are counted by publication date rather than by the year in the CVE ID, since roughly a fifth of records are published in a different year to the one their identifier names. Rejected and withdrawn records are excluded.
Does a high CVSS score mean a high risk to my product?
Not on its own. A Critical vulnerability in a component you ship but never call may be less urgent than a Medium one on your public API.
Real prioritization needs to know whether the affected component is present in your software, whether the vulnerable code is reachable, and whether the vulnerability is being exploited. CVSS answers none of those.
What does rising CVE volume mean for EU Cyber Resilience Act compliance?
The CRA requires manufacturers to handle vulnerabilities across a product's supported lifetime, report actively exploited vulnerabilities to ENISA within 24 hours of becoming aware, and keep technical documentation current.
Those duties scale with the volume in this chart. Triaging tens of thousands of new records a year against your own software is not realistic manually, which is why the CRA effectively assumes an SBOM and an automated matching process.
How can I find out which of these CVEs affect my products?
You need an accurate inventory of what your software contains, then continuous matching of that inventory against the CVE feed.
CRACI generates an SBOM from your build, matches it against new CVE records as they are published, and shows only the advisories that reach code you actually ship — along with the documentation the CRA expects you to keep.
See how vulnerability tracking works in practice.
Track the CVEs that affect your products
CRACI monitors your SBOM against the CVE feed and tells you which advisories actually reach your shipped software
Book a demo