| CVE-2026-59521 | 7.2 | — | — | — | — | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Obje | 55d ago |
| CVE-2026-57407 | 7.2 | — | — | — | — | Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp all | 55d ago |
| CVE-2026-57372 | 7.2 | — | — | — | — | Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Fo | 55d ago |
| CVE-2026-6939 | 7.2 | — | — | — | — | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the | 57d ago |
| CVE-2026-13378 | 7.2 | — | — | — | — | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via | 57d ago |
| CVE-2026-3576 | 7.2 | — | — | — | — | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to L | 57d ago |
| CVE-2026-13114 | 7.2 | — | — | — | — | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site S | 57d ago |
| CVE-2026-53448 | 7.2 | — | — | — | coturn project / coturn | Coturn is a free open source implementation of TURN and STUN Server. | 57d ago |
| CVE-2026-1667 | 7.2 | — | — | — | — | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site | 57d ago |
| CVE-2026-60091 | 7.2 | — | — | — | — | PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api | 58d ago |
| CVE-2026-22660 | 7.2 | — | — | — | — | FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated admi | 58d ago |
| CVE-2026-15298 | 7.2 | — | — | — | — | The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and incl | 58d ago |
| CVE-2026-13430 | 7.2 | — | — | — | — | The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up t | 58d ago |
| CVE-2026-0286 | 7.2 | — | — | — | paloaltonetworks / pan-os | A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authent | 58d ago |
| CVE-2026-0283 | 7.2 | — | — | — | paloaltonetworks / pan-os | An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS softw | 58d ago |
| CVE-2026-0280 | 7.2 | — | — | — | paloaltonetworks / pan-os | An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthen | 58d ago |
| CVE-2026-61343 | 7.2 | — | — | — | — | LibreBooking's email template editor save action passes the submitted template name directly into the destination | 58d ago |
| CVE-2026-59721 | 7.2 | — | — | — | — | Hoppscotch is an open source API development ecosystem. | 58d ago |
| CVE-2026-54801 | 7.2 | — | — | — | — | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Bas | 59d ago |
| CVE-2026-9253 | 7.2 | — | — | — | — | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site | 59d ago |
| CVE-2026-13441 | 7.2 | — | — | — | — | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scr | 59d ago |
| CVE-2026-8848 | 7.2 | — | — | — | — | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordP | 59d ago |
| CVE-2026-15000 | 7.2 | — | — | — | — | The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mai | 59d ago |
| CVE-2026-44161 | 7.2 | — | — | — | fluentd / fluentd | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and s | 59d ago |
| CVE-2026-59821exploited | 7.2 | 0.66% | 1/3 | +18d | litellm / litellm | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. | 59d ago |
| CVE-2026-24700 | 7.2 | — | — | — | cisco / rv130 firmware | An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W | 60d ago |
| CVE-2026-24699 | 7.2 | — | — | — | cisco / rv130 firmware | An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W | 60d ago |
| CVE-2026-24698 | 7.2 | — | — | — | cisco / rv130 firmware | An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco | 60d ago |
| CVE-2026-24697 | 7.2 | — | — | — | cisco / rv130 firmware | An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV1 | 60d ago |
| CVE-2026-10698 | 7.2 | — | — | — | progress / moveit transfer | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom | 60d ago |
| CVE-2026-6820 | 7.2 | — | — | — | — | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the | 60d ago |
| CVE-2026-6818 | 7.2 | — | — | — | — | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the | 60d ago |
| CVE-2026-55077 | 7.2 | — | — | — | coder / coder | Coder allows organizations to provision remote development environments via Terraform. | 60d ago |
| CVE-2026-23698 | 7.2 | — | — | — | — | Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import | 60d ago |
| CVE-2026-53479 | 7.2 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 61d ago |
| CVE-2026-58298 | 7.2 | — | — | — | microsoft / edge chromium | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-b | 64d ago |
| CVE-2026-53478 | 7.2 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 65d ago |
| CVE-2026-49815 | 7.2 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 65d ago |
| CVE-2026-49814 | 7.2 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 65d ago |
| CVE-2026-9148 | 7.2 | — | — | — | — | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter ' | 65d ago |
| CVE-2026-13040 | 7.2 | — | — | — | — | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Script | 65d ago |
| CVE-2026-13722 | 7.2 | — | — | — | watchguard / fireware | WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore | 65d ago |
| CVE-2026-13384 | 7.2 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privil | 65d ago |
| CVE-2026-13383 | 7.2 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privi | 65d ago |
| CVE-2026-13054 | 7.2 | — | — | — | watchguard / fireware | A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated a | 65d ago |
| CVE-2026-13053 | 7.2 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user | 65d ago |
| CVE-2026-13050 | 7.2 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privi | 65d ago |
| CVE-2026-57348 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. | 66d ago |
| CVE-2026-9834 | 7.2 | — | — | — | — | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to O | 66d ago |
| CVE-2026-58263 | 7.2 | — | — | — | — | Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. | 66d ago |
| CVE-2026-12142 | 7.2 | — | — | — | — | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Script | 67d ago |
| CVE-2026-50043 | 7.2 | — | — | — | — | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBrid | 67d ago |
| CVE-2026-11883 | 7.2 | — | — | — | — | The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor a | 67d ago |
| CVE-2026-7829 | 7.2 | — | — | — | uvnc / ultravnc | UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. | 67d ago |
| CVE-2026-7517 | 7.2 | — | — | — | — | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t | 67d ago |
| CVE-2026-13731zero day | 7.2 | 0.89% | 1/3 | same day | — | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored | 67d ago |
| CVE-2026-11806 | 7.2 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnera | 67d ago |
| CVE-2026-10513 | 7.2 | — | — | — | — | The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5 | 67d ago |
| CVE-2026-8141 | 7.2 | — | — | — | — | The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_in | 68d ago |
| CVE-2026-56808 | 7.2 | — | — | — | — | DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead | 68d ago |