| CVE-2026-16143 | 7.2 | — | — | — | — | The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scrip | 32d ago |
| CVE-2026-18901 | 7.2 | — | — | — | — | A security vulnerability has been detected in H3C NX15 V100R017. | 32d ago |
| CVE-2026-18900 | 7.2 | — | — | — | — | A weakness has been identified in H3C NX15 V100R017. | 32d ago |
| CVE-2026-18814 | 7.2 | — | — | — | — | A vulnerability was found in H3C NX15 V100R017. | 32d ago |
| CVE-2026-18813 | 7.2 | — | — | — | — | A vulnerability has been found in H3C NX15 V100R017. | 32d ago |
| CVE-2026-18812 | 7.2 | — | — | — | — | A flaw has been found in H3C NX15 V100R017. | 32d ago |
| CVE-2026-18811 | 7.2 | — | — | — | — | A vulnerability was detected in H3C NX15 V100R017. | 32d ago |
| CVE-2026-67243 | 7.2 | — | — | — | — | freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. | 33d ago |
| CVE-2026-14818 | 7.2 | — | — | — | — | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware | 33d ago |
| CVE-2026-6837 | 7.2 | — | — | — | — | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware ver | 33d ago |
| CVE-2026-69246 | 7.2 | — | — | — | — | Guzzle is an extensible PHP HTTP client. | 33d ago |
| CVE-2026-67599 | 7.2 | — | — | — | — | ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated a | 33d ago |
| CVE-2026-61524 | 7.2 | — | — | — | — | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feat | 33d ago |
| CVE-2026-61523 | 7.2 | — | — | — | — | WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authent | 33d ago |
| CVE-2026-39931 | 7.2 | — | — | — | open-emr / openemr | OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import fea | 33d ago |
| CVE-2026-67608 | 7.2 | — | — | — | — | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command i | 34d ago |
| CVE-2026-67340 | 7.2 | — | — | — | — | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.t | 36d ago |
| CVE-2026-67333 | 7.2 | — | — | — | — | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme o | 36d ago |
| CVE-2026-15052 | 7.2 | — | — | — | — | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Sto | 36d ago |
| CVE-2026-15244 | 7.2 | — | — | — | — | The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal befor | 36d ago |
| CVE-2026-13158 | 7.2 | — | — | — | — | The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-conten | 36d ago |
| CVE-2026-13157 | 7.2 | — | — | — | — | The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content im | 36d ago |
| CVE-2026-38710 | 7.2 | — | — | — | — | TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setcl | 36d ago |
| CVE-2026-16843 | 7.2 | — | — | — | — | Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input val | 37d ago |
| CVE-2026-13392 | 7.2 | — | — | — | — | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved | 37d ago |
| CVE-2026-15397 | 7.2 | — | — | — | — | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up t | 38d ago |
| CVE-2026-67244 | 7.2 | — | — | — | asustor / data master | A format string vulnerability was found in the Notification OAuth settings of ADM. | 38d ago |
| CVE-2026-12357 | 7.2 | — | — | — | — | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. | 38d ago |
| CVE-2026-18255 | 7.2 | — | — | — | — | A flaw was found in Quay. | 38d ago |
| CVE-2026-16655 | 7.2 | — | — | — | — | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is | 39d ago |
| CVE-2026-16597 | 7.2 | — | — | — | — | The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Si | 39d ago |
| CVE-2026-13425 | 7.2 | — | — | — | — | The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values | 39d ago |
| CVE-2026-24033 | 7.2 | — | — | — | apache / traffic server | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic S | 39d ago |
| CVE-2026-12476 | 7.2 | — | — | — | — | The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and inclu | 39d ago |
| CVE-2026-54605 | 7.2 | — | — | — | — | OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. | 39d ago |
| CVE-2026-13440 | 7.2 | — | — | — | — | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugi | 40d ago |
| CVE-2026-61376 | 7.2 | — | — | — | — | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Set | 40d ago |
| CVE-2026-59764 | 7.2 | — | — | — | — | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. | 40d ago |
| CVE-2026-16585 | 7.2 | — | — | — | — | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable t | 40d ago |
| CVE-2026-65442exploited | 7.2 | 0.42% | 1/3 | +7d | — | Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions. | 40d ago |
| CVE-2026-61953 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. | 40d ago |
| CVE-2026-66015 | 7.2 | — | — | — | jfrog / artifactory | An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned acc | 40d ago |
| CVE-2026-59552 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | 41d ago |
| CVE-2026-65711 | 7.2 | — | — | — | — | sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administra | 43d ago |
| CVE-2026-65693 | 7.2 | — | — | — | — | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated ad | 44d ago |
| CVE-2026-15401 | 7.2 | — | — | — | — | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th | 44d ago |
| CVE-2026-66138 | 7.2 | — | — | — | — | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary | 44d ago |
| CVE-2026-65898 | 7.2 | — | — | — | cure53 / dompurify | DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAtt | 45d ago |
| CVE-2026-65516 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | 45d ago |
| CVE-2026-65497 | 7.2 | — | — | — | — | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | 45d ago |
| CVE-2026-12421 | 7.2 | — | — | — | — | The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all v | 45d ago |
| CVE-2026-7534 | 7.2 | — | — | — | — | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the RE | 45d ago |
| CVE-2026-7232 | 7.2 | — | — | — | — | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' paramete | 45d ago |
| CVE-2026-40714 | 7.2 | — | — | — | dell / powerprotect data manager | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. | 46d ago |
| CVE-2026-61391 | 7.2 | — | — | — | — | There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated atta | 46d ago |
| CVE-2026-62548 | 7.2 | — | — | — | oracle / human resources management system | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). | 46d ago |
| CVE-2026-62466 | 7.2 | — | — | — | oracle / human resources | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). | 46d ago |
| CVE-2026-61336 | 7.2 | — | — | — | oracle / lease and finance management | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal O | 46d ago |
| CVE-2026-61314 | 7.2 | — | — | — | oracle / e-business suite | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issue | 46d ago |
| CVE-2026-61285 | 7.2 | — | — | — | oracle / process manufacturing systems | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal | 46d ago |