Patchstack

First CVE: Sep 9, 2021Active for: 5 years
17,246
CVEs Published
More CVEs Published than 100% of tracked CNAs
2874.3
Avg CVEs / Year
More Avg CVEs / Year than 99% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 34% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Patchstack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2021
4 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Patchstack as a CNA, regardless of affected vendor or product.

17,246 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n
Oct 20, 20249.892NOYES
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1
Jun 4, 202410.092NOYES
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n
Mar 21, 20249.891NOYES
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.
Aug 21, 20249.884NOYES
Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.
May 1, 20259.883NOYES
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 throu
May 12, 20239.881NOYES
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue
May 17, 20249.379NOYES
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.
Apr 12, 20249.876NOYES
Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: f
Oct 28, 20249.870NOYES
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8
Mar 13, 20237.570NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA17,246 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local4 (0.0%)
Network17,240 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (0.0%)
Attack Complexity
Low16,012 (92.8%)
High1,234 (7.2%)
Unknown0 (0.0%)
User Interaction
None7,834 (45.4%)
Unknown0 (0.0%)
Required9,412 (54.6%)
Privileges Required
Low6,047 (35.1%)
High1,828 (10.6%)
None9,371 (54.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (17246 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
0.0% of CVEs· 77th percentile
Nuclei
121 CVEs
0.7% of CVEs· 78th percentile
ExploitDB
11 CVEs
0.1% of CVEs· 73rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Patchstack as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Patchstack as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs