| CVE-2026-71905 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. | 12d ago |
| CVE-2026-71904 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. | 12d ago |
| CVE-2026-71364 | 7.2 | — | — | — | — | A path traversal vulnerability was found in AWX's project archive extraction. | 13d ago |
| CVE-2026-21756 | 7.2 | — | — | — | — | HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user t | 13d ago |
| CVE-2026-19221 | 7.2 | — | — | — | — | The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administ | 15d ago |
| CVE-2026-66722 | 7.2 | — | — | — | apache / cloudstack | Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in Clou | 16d ago |
| CVE-2026-75796 | 7.2 | — | — | — | — | The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the t | 16d ago |
| CVE-2026-16576 | 7.2 | — | — | — | — | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correct | 16d ago |
| CVE-2026-18409 | 7.2 | — | — | — | — | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragra | 16d ago |
| CVE-2026-53804 | 7.2 | — | — | — | — | OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module t | 16d ago |
| CVE-2026-18274 | 7.2 | — | — | — | — | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. | 17d ago |
| CVE-2026-15686 | 7.2 | — | — | — | — | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. | 17d ago |
| CVE-2026-76635 | 7.2 | — | — | — | — | baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated ad | 17d ago |
| CVE-2026-14947 | 7.2 | — | — | — | — | A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such a | 17d ago |
| CVE-2026-14946 | 7.2 | — | — | — | — | A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php | 17d ago |
| CVE-2026-15049 | 7.2 | — | — | — | — | The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded | 17d ago |
| CVE-2026-23501 | 7.2 | — | — | — | — | Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements use | 18d ago |
| CVE-2026-70421 | 7.2 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. | 18d ago |
| CVE-2026-54796 | 7.2 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used | 18d ago |
| CVE-2026-54794 | 7.2 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. | 18d ago |
| CVE-2026-75981 | 7.2 | — | — | — | — | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauth | 18d ago |
| CVE-2026-15780exploited | 7.2 | 0.39% | 1/3 | +1d | — | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to St | 18d ago |
| CVE-2026-17565 | 7.2 | — | — | — | — | The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before us | 18d ago |
| CVE-2026-13174 | 7.2 | — | — | — | — | The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, | 18d ago |
| CVE-2026-73928 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-73886 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-73885 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-73876 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-73875 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 18d ago |
| CVE-2026-71104 | 7.2 | — | — | — | oracle / human resources management system | Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Business Suite (component: Netherlands Payroll) | 18d ago |
| CVE-2026-71099 | 7.2 | — | — | — | oracle / business intelligence | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analy | 18d ago |
| CVE-2026-71032 | 7.2 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-71030 | 7.2 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 18d ago |
| CVE-2026-70950 | 7.2 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 18d ago |
| CVE-2026-70939 | 7.2 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 18d ago |
| CVE-2026-70932 | 7.2 | — | — | — | oracle / order management | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Too | 18d ago |
| CVE-2026-70861 | 7.2 | — | — | — | — | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Comm | 18d ago |
| CVE-2026-70834 | 7.2 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 18d ago |
| CVE-2026-70820 | 7.2 | — | — | — | oracle / complex maintenance repair and overhaul | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operati | 18d ago |
| CVE-2026-70797 | 7.2 | — | — | — | oracle / purchasing | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). | 18d ago |
| CVE-2026-70796 | 7.2 | — | — | — | oracle / general ledger | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). | 18d ago |
| CVE-2026-70781 | 7.2 | — | — | — | oracle / proposals | Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations). | 18d ago |
| CVE-2026-70735 | 7.2 | — | — | — | oracle / hyperion profitability and cost management | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Depl | 18d ago |
| CVE-2026-62616 | 7.2 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 18d ago |
| CVE-2026-62540 | 7.2 | — | — | — | — | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). | 18d ago |
| CVE-2026-62459 | 7.2 | — | — | — | oracle / hyperion calculation manager | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). | 18d ago |
| CVE-2026-60994 | 7.2 | — | — | — | oracle / identity manager connector | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). | 18d ago |
| CVE-2026-60883 | 7.2 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). | 18d ago |
| CVE-2026-60873 | 7.2 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data Mover). | 18d ago |
| CVE-2026-54348 | 7.2 | — | — | — | — | Froxlor is open source server administration software. | 18d ago |
| CVE-2026-73367 | 7.2 | — | — | — | — | Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | 19d ago |
| CVE-2026-66620 | 7.2 | — | — | — | — | Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | 19d ago |
| CVE-2026-32553 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | 19d ago |
| CVE-2026-32473 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | 19d ago |
| CVE-2026-75091 | 7.2 | — | — | — | — | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored | 19d ago |
| CVE-2026-16139 | 7.2 | — | — | — | progress / sharefile storage zones controller | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrato | 20d ago |
| CVE-2026-16137 | 7.2 | — | — | — | progress / sharefile storage zones controller | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform | 20d ago |
| CVE-2026-74998 | 7.2 | — | — | — | — | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy w | 20d ago |
| CVE-2026-2497 | 7.2 | — | — | — | — | The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' p | 21d ago |
| CVE-2026-13424 | 7.2 | — | — | — | — | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-S | 21d ago |