| CVE-2026-10734 | 7.2 | — | — | — | — | The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint | 21d ago |
| CVE-2026-18653 | 7.2 | — | — | — | — | The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a S | 21d ago |
| CVE-2026-17581 | 7.2 | — | — | — | — | The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via th | 21d ago |
| CVE-2026-17533 | 7.2 | — | — | — | — | The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functi | 21d ago |
| CVE-2026-15002 | 7.2 | — | — | — | — | The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver | 21d ago |
| CVE-2026-16145 | 7.2 | — | — | — | — | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stor | 22d ago |
| CVE-2026-13360 | 7.2 | — | — | — | — | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Sc | 22d ago |
| CVE-2026-14433 | 7.2 | — | — | — | — | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross | 22d ago |
| CVE-2026-73679 | 7.2 | — | — | — | — | ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows auth | 22d ago |
| CVE-2026-19628 | 7.2 | — | — | — | tenable / security center | A command injection vulnerability exists in Tenable Security Center. | 23d ago |
| CVE-2026-66271 | 7.2 | — | — | — | dell / wyse management suite | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerou | 23d ago |
| CVE-2026-66270 | 7.2 | — | — | — | dell / wyse management suite | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerou | 23d ago |
| CVE-2026-72828 | 7.2 | — | — | — | — | Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsControll | 23d ago |
| CVE-2026-19794 | 7.2 | — | — | — | — | The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin | 23d ago |
| CVE-2026-18109zero day | 7.2 | 0.27% | 1/3 | same day | — | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in al | 23d ago |
| CVE-2026-19771 | 7.2 | — | — | — | — | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. | 23d ago |
| CVE-2026-73670 | 7.2 | — | — | — | — | A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administra | 24d ago |
| CVE-2026-66256 | 7.2 | — | — | — | — | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. | 24d ago |
| CVE-2026-66704 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | 24d ago |
| CVE-2026-27380 | 7.2 | — | — | — | — | Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. | 24d ago |
| CVE-2026-6471 | 7.2 | — | — | — | postgresql / postgresql | Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen | 24d ago |
| CVE-2026-18146 | 7.2 | — | — | — | — | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is | 24d ago |
| CVE-2026-12618 | 7.2 | — | — | — | ibm / security verify access | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify | 24d ago |
| CVE-2026-12005 | 7.2 | — | — | — | ibm / security verify access | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify | 24d ago |
| CVE-2026-68759 | 7.2 | — | — | — | jfrog / artifactory | A holder of a valid integration credential may impersonate other users under specific conditions. | 25d ago |
| CVE-2026-68752 | 7.2 | — | — | — | jfrog / artifactory | A Project Resource Manager may gain broader administrative privileges under specific conditions. | 25d ago |
| CVE-2025-59319 | 7.2 | — | — | — | — | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partiti | 25d ago |
| CVE-2026-62910 | 7.2 | — | — | — | microsoft / exchange server | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized | 26d ago |
| CVE-2026-47299 | 7.2 | — | — | — | microsoft / azure monitor agent | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows | 26d ago |
| CVE-2026-20898 | 7.2 | — | — | — | intel / xeon 6315p firmware | Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) proces | 26d ago |
| CVE-2026-20885 | 7.2 | — | — | — | intel / tdx module | Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may all | 26d ago |
| CVE-2026-18635 | 7.2 | — | — | — | — | Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. | 26d ago |
| CVE-2026-72747 | 7.2 | — | — | — | — | AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject ma | 26d ago |
| CVE-2026-4757 | 7.2 | — | — | — | — | A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a priv | 26d ago |
| CVE-2026-14237 | 7.2 | — | — | — | — | The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target autho | 27d ago |
| CVE-2026-13170 | 7.2 | — | — | — | — | The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to i | 27d ago |
| CVE-2026-63725 | 7.2 | — | — | — | — | sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 build | 30d ago |
| CVE-2026-65559 | 7.2 | — | — | — | — | Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | 31d ago |
| CVE-2026-65549 | 7.2 | — | — | — | — | Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | 31d ago |
| CVE-2026-19036 | 7.2 | — | — | — | — | A security flaw has been discovered in Shibby Tomato 1.28.0000. | 31d ago |
| CVE-2026-19035 | 7.2 | — | — | — | — | A vulnerability was identified in Shibby Tomato 1.28.0000. | 31d ago |
| CVE-2025-15028 | 7.2 | — | — | — | — | The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPre | 31d ago |
| CVE-2026-19034 | 7.2 | — | — | — | — | A vulnerability was determined in Shibby Tomato 1.28.0000. | 31d ago |
| CVE-2026-18510 | 7.2 | — | — | — | — | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored | 31d ago |
| CVE-2026-18325 | 7.2 | — | — | — | — | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stor | 31d ago |
| CVE-2026-16636 | 7.2 | — | — | — | — | The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin | 31d ago |
| CVE-2026-70608 | 7.2 | — | — | — | — | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. | 31d ago |
| CVE-2026-17625 | 7.2 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thr | 31d ago |
| CVE-2026-17630 | 7.2 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper vali | 32d ago |
| CVE-2026-17506 | 7.2 | — | — | — | — | The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_ | 32d ago |
| CVE-2026-71292 | 7.2 | — | — | — | — | Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whiteli | 32d ago |
| CVE-2026-71284 | 7.2 | — | — | — | — | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes t | 32d ago |
| CVE-2026-71269 | 7.2 | — | — | — | — | Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/ | 32d ago |
| CVE-2026-18933 | 7.2 | — | — | — | — | The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an adm | 32d ago |
| CVE-2026-71232 | 7.2 | — | — | — | — | MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in tem | 32d ago |
| CVE-2026-7693 | 7.2 | — | — | — | — | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and includin | 32d ago |
| CVE-2026-6020 | 7.2 | — | — | — | — | The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-ac | 32d ago |
| CVE-2026-54416 | 7.2 | — | — | — | — | Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed black | 32d ago |
| CVE-2026-16605 | 7.2 | — | — | — | — | The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belon | 32d ago |
| CVE-2026-18902 | 7.2 | — | — | — | — | A vulnerability was detected in H3C NX15 V100R017. | 32d ago |