| CVE-2026-56414 | 7.2 | — | — | — | — | A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to sto | 71d ago |
| CVE-2026-55975 | 7.2 | — | — | — | — | A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML field | 71d ago |
| CVE-2026-13372 | 7.2 | — | — | — | devolutions / remote desktop manager | Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manage | 71d ago |
| CVE-2026-9640 | 7.2 | — | — | — | canonical / lxd | A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0. | 71d ago |
| CVE-2026-40083 | 7.2 | — | — | — | cacti / cacti | Cacti is an open source performance and fault management framework. | 72d ago |
| CVE-2026-9717 | 7.2 | — | — | — | schneider-electric / powerlogic p7 firmware | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that | 72d ago |
| CVE-2026-55477 | 7.2 | — | — | — | — | 3X-UI is a web control panel for managing Xray-core servers. | 72d ago |
| CVE-2026-49506 | 7.2 | — | — | — | dell / wyse management suite | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restr | 73d ago |
| CVE-2026-9779 | 7.2 | — | — | — | aten / unizon | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerabi | 73d ago |
| CVE-2026-9778 | 7.2 | — | — | — | aten / unizon | ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-9777 | 7.2 | — | — | — | aten / unizon | ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. | 73d ago |
| CVE-2026-50189 | 7.2 | — | — | — | appsmith / appsmith | Appsmith is a platform to build admin panels, internal tools, and dashboards. | 73d ago |
| CVE-2026-9643 | 7.2 | — | — | — | — | The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_U | 74d ago |
| CVE-2026-12100 | 7.2 | — | — | — | — | The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu | 74d ago |
| CVE-2026-12095 | 7.2 | — | — | — | — | The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu | 74d ago |
| CVE-2026-10749 | 7.2 | — | — | — | — | The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication | 74d ago |
| CVE-2026-10092 | 7.2 | — | — | — | — | The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa | 74d ago |
| CVE-2026-10091 | 7.2 | — | — | — | — | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ema | 74d ago |
| CVE-2026-3652 | 7.2 | — | — | — | — | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf | 74d ago |
| CVE-2026-54308 | 7.2 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 74d ago |
| CVE-2026-56222 | 7.2 | — | — | — | — | Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to | 75d ago |
| CVE-2026-10521 | 7.2 | — | — | — | — | An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any | 75d ago |
| CVE-2026-56447 | 7.2 | — | — | — | misp-project / misp | MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesyste | 76d ago |
| CVE-2026-56446 | 7.2 | — | — | — | misp-project / misp | MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonL | 76d ago |
| CVE-2026-44914 | 7.2 | — | — | — | apache / nifi | Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension co | 76d ago |
| CVE-2026-44913 | 7.2 | — | — | — | apache / nifi | Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 thro | 76d ago |
| CVE-2026-56382 | 7.2 | — | — | — | — | Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerab | 77d ago |
| CVE-2026-48895 | 7.2 | — | — | — | apache / apisix | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. | 79d ago |
| CVE-2025-52465 | 7.2 | — | — | — | osgeo / geoserver | GeoServer is an open source server that allows users to share and edit geospatial data. | 79d ago |
| CVE-2025-27511 | 7.2 | — | — | — | osgeo / geoserver | GeoServer is an open source server that allows users to share and edit geospatial data. | 79d ago |
| CVE-2026-11395 | 7.2 | — | — | — | — | The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in | 80d ago |
| CVE-2026-53676 | 7.2 | — | — | — | — | ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandb | 80d ago |
| CVE-2026-11407 | 7.2 | — | — | — | — | Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative at | 80d ago |
| CVE-2026-53876 | 7.2 | — | — | — | — | RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbit | 81d ago |
| CVE-2026-11410 | 7.2 | — | — | — | tp-link / tl-wr940n firmware | An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in | 81d ago |
| CVE-2026-11409 | 7.2 | — | — | — | tp-link / tl-wr940n firmware | An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 | 81d ago |
| CVE-2026-46976 | 7.2 | — | — | — | oracle / public sector payroll | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operatio | 81d ago |
| CVE-2026-46970 | 7.2 | — | — | — | oracle / hr intelligence | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). | 81d ago |
| CVE-2026-46969 | 7.2 | — | — | — | oracle / financials for emea | Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations | 81d ago |
| CVE-2026-46960 | 7.2 | — | — | — | oracle / project portfolio analysis | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Ope | 81d ago |
| CVE-2026-46956 | 7.2 | — | — | — | oracle / property manager | Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). | 81d ago |
| CVE-2026-46953 | 7.2 | — | — | — | oracle / human resources management system | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). | 81d ago |
| CVE-2026-46938 | 7.2 | — | — | — | oracle / cost management | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). | 81d ago |
| CVE-2026-46922 | 7.2 | — | — | — | oracle / hr intelligence | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). | 81d ago |
| CVE-2026-46868 | 7.2 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Exte | 81d ago |
| CVE-2026-46867 | 7.2 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Exte | 81d ago |
| CVE-2026-46769 | 7.2 | — | — | — | oracle / application development framework | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component | 81d ago |
| CVE-2026-35326 | 7.2 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 81d ago |
| CVE-2026-42650 | 7.2 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions. | 82d ago |
| CVE-2026-39499 | 7.2 | — | — | — | — | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | 82d ago |
| CVE-2026-39498 | 7.2 | — | — | — | — | Shop manager PHP Object Injection in YayMail <= 4.3.3 versions. | 82d ago |
| CVE-2026-39481 | 7.2 | — | — | — | — | Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions. | 82d ago |
| CVE-2026-39472 | 7.2 | — | — | — | — | Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | 82d ago |
| CVE-2026-39471 | 7.2 | — | — | — | — | Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions. | 82d ago |
| CVE-2026-39470 | 7.2 | — | — | — | — | Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions. | 82d ago |
| CVE-2026-39434 | 7.2 | — | — | — | — | Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions. | 82d ago |
| CVE-2026-27407 | 7.2 | — | — | — | — | Editor Privilege Escalation in AI Engine <= 3.4.9 versions. | 82d ago |
| CVE-2026-49954 | 7.2 | — | — | — | — | Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authentic | 82d ago |
| CVE-2016-20084 | 7.2 | — | — | — | — | WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow un | 83d ago |
| CVE-2016-20066 | 7.2 | — | — | — | — | WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject | 83d ago |