| CVE-2026-4237 | 7.3 | — | — | — | — | A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. | 174d ago |
| CVE-2026-4236 | 7.3 | — | — | — | — | A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. | 174d ago |
| CVE-2026-4235 | 7.3 | — | — | — | — | A weakness has been identified in itsourcecode Online Enrollment System 1.0. | 174d ago |
| CVE-2026-4232 | 7.3 | — | — | — | — | A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. | 174d ago |
| CVE-2026-4231 | 7.3 | — | — | — | — | A vulnerability was found in vanna-ai vanna up to 2.0.2. | 174d ago |
| CVE-2026-4229 | 7.3 | — | — | — | — | A flaw has been found in vanna-ai vanna up to 2.0.2. | 174d ago |
| CVE-2026-4223 | 7.3 | — | — | — | angeljudesuarez / payroll management system | A vulnerability was identified in itsourcecode Payroll Management System 1.0. | 174d ago |
| CVE-2026-4221 | 7.3 | — | — | — | — | A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. | 174d ago |
| CVE-2026-4220 | 7.3 | — | — | — | — | A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. | 174d ago |
| CVE-2026-4201 | 7.3 | — | — | — | — | A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. | 174d ago |
| CVE-2026-4200 | 7.3 | — | — | — | — | A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. | 174d ago |
| CVE-2026-4194 | 7.3 | — | — | — | dlink / dnr-202l firmware | A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L | 174d ago |
| CVE-2026-4193 | 7.3 | — | — | — | dlink / dir-823g firmware | A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. | 174d ago |
| CVE-2026-4191 | 7.3 | — | — | — | — | A flaw has been found in JawherKl node-api-postgres up to 2.5. | 174d ago |
| CVE-2026-4190 | 7.3 | — | — | — | — | A vulnerability was detected in JawherKl node-api-postgres up to 2.5. | 174d ago |
| CVE-2026-4180 | 7.3 | — | — | — | dlink / dir-816 firmware | A vulnerability was identified in D-Link DIR-816 1.10CNB05. | 174d ago |
| CVE-2026-3839 | 7.3 | — | — | — | unraid / unraid | Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability. | 174d ago |
| CVE-2026-32594 | 7.3 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 174d ago |
| CVE-2026-25076 | 7.3 | — | — | — | — | Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. | 176d ago |
| CVE-2026-4014 | 7.3 | — | — | — | luffypirates / cafe reservation system | A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. | 178d ago |
| CVE-2026-3981 | 7.3 | — | — | — | unguardable / online doctor appointment system | A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. | 178d ago |
| CVE-2026-3980 | 7.3 | — | — | — | unguardable / online doctor appointment system | A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. | 178d ago |
| CVE-2026-3969 | 7.3 | — | — | — | — | A vulnerability was detected in FeMiner wms up to 1.0. | 178d ago |
| CVE-2026-86188 | 7.2 | — | — | — | — | AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attack | 1d ago |
| CVE-2026-83625 | 7.2 | — | — | — | — | The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Hea | 1d ago |
| CVE-2026-78438 | 7.2 | — | — | — | — | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyL | 1d ago |
| CVE-2026-77830 | 7.2 | — | — | — | — | The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scri | 1d ago |
| CVE-2026-19769 | 7.2 | — | — | — | — | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross- | 1d ago |
| CVE-2026-18406 | 7.2 | — | — | — | — | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to | 1d ago |
| CVE-2026-16649 | 7.2 | — | — | — | — | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in a | 1d ago |
| CVE-2026-15984 | 7.2 | — | — | — | — | The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all | 1d ago |
| CVE-2026-77263 | 7.2 | — | — | — | — | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to St | 1d ago |
| CVE-2026-77233 | 7.2 | — | — | — | — | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to St | 1d ago |
| CVE-2026-85599 | 7.2 | — | — | — | — | Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter | 2d ago |
| CVE-2026-19224 | 7.2 | — | — | — | — | The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network adm | 2d ago |
| CVE-2026-84773 | 7.2 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | 3d ago |
| CVE-2026-84761 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions. | 3d ago |
| CVE-2026-82524 | 7.2 | — | — | — | — | UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators t | 3d ago |
| CVE-2026-75528 | 7.2 | — | — | — | — | The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / | 4d ago |
| CVE-2026-73767 | 7.2 | — | — | — | hpe / arubaos-cx | Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. | 4d ago |
| CVE-2026-73766 | 7.2 | — | — | — | hpe / arubaos-cx | Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with | 4d ago |
| CVE-2026-73765 | 7.2 | — | — | — | hpe / arubaos-cx | Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. | 4d ago |
| CVE-2026-73722 | 7.2 | — | — | — | arubanetworks / fabric composer | Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could al | 4d ago |
| CVE-2026-73721 | 7.2 | — | — | — | arubanetworks / fabric composer | Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to condu | 4d ago |
| CVE-2026-73720 | 7.2 | — | — | — | arubanetworks / fabric composer | Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker | 4d ago |
| CVE-2026-73719 | 7.2 | — | — | — | arubanetworks / fabric composer | An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authe | 4d ago |
| CVE-2026-83551 | 7.2 | — | — | — | — | Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMak | 4d ago |
| CVE-2024-14047 | 7.2 | — | — | — | — | A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writabl | 5d ago |
| CVE-2026-84190 | 7.2 | — | — | — | — | LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snm | 5d ago |
| CVE-2026-19914 | 7.2 | — | — | — | — | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' pa | 5d ago |
| CVE-2026-75921 | 7.2 | — | — | — | — | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Te | 5d ago |
| CVE-2026-19796 | 7.2 | — | — | — | — | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Sto | 5d ago |
| CVE-2026-19573 | 7.2 | — | — | — | — | The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doComment | 5d ago |
| CVE-2026-75123 | 7.2 | — | — | — | — | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability | 8d ago |
| CVE-2026-75122 | 7.2 | — | — | — | — | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability | 8d ago |
| CVE-2026-75121 | 7.2 | — | — | — | — | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability | 8d ago |
| CVE-2026-81757 | 7.2 | — | — | — | — | Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | 9d ago |
| CVE-2026-6176 | 7.2 | — | — | — | — | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggr | 9d ago |
| CVE-2026-5934 | 7.2 | — | — | — | — | The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3 | 9d ago |
| CVE-2026-79996 | 7.2 | — | — | — | — | The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving i | 9d ago |