| CVE-2026-12197 | 7.2 | — | — | — | — | A security flaw has been discovered in Ruijie EG105G-P 2.340. | 83d ago |
| CVE-2026-5513 | 7.2 | — | — | — | — | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Si | 85d ago |
| CVE-2026-9109 | 7.2 | — | — | — | — | The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress | 85d ago |
| CVE-2026-42306 | 7.2 | — | — | — | docker / engine | Moby is an open source container framework. | 85d ago |
| CVE-2026-11845 | 7.2 | — | — | — | — | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerabili | 86d ago |
| CVE-2026-47366 | 7.2 | — | — | — | — | Improper verification of access permissions when modifying permissions through the Administration Control Panel (A | 86d ago |
| CVE-2026-53816 | 7.2 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that | 86d ago |
| CVE-2026-0273 | 7.2 | — | — | — | paloaltonetworks / pan-os | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to | 87d ago |
| CVE-2026-0272 | 7.2 | — | — | — | paloaltonetworks / pan-os | A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator w | 87d ago |
| CVE-2026-25700 | 7.2 | — | — | — | apache / answer | Improper Restriction of Security Token Assignment vulnerability in Apache Answer. | 87d ago |
| CVE-2026-24719 | 7.2 | — | — | — | qnap / qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2026-24716 | 7.2 | — | — | — | qnap / qts | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2026-22893 | 7.2 | — | — | — | qnap / qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2025-66281 | 7.2 | — | — | — | qnap / qts | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2025-66280 | 7.2 | — | — | — | qnap / qts | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions | 88d ago |
| CVE-2025-66279 | 7.2 | — | — | — | qnap / qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2025-66273 | 7.2 | — | — | — | qnap / qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2025-62850 | 7.2 | — | — | — | qnap / quts hero | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. | 88d ago |
| CVE-2026-46492 | 7.2 | — | — | — | commenthol / md-fileserver | md-fileserver allows for local viewing of markdown files in a browser. | 88d ago |
| CVE-2026-10727 | 7.2 | — | — | — | — | An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remo | 88d ago |
| CVE-2026-7556 | 7.2 | — | — | — | — | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment te | 89d ago |
| CVE-2026-43972 | 7.2 | — | — | — | ninenines / gun | Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via | 89d ago |
| CVE-2023-54351 | 7.2 | — | — | — | — | WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated | 90d ago |
| CVE-2026-9851 | 7.2 | — | — | — | — | The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up | 92d ago |
| CVE-2026-7537 | 7.2 | — | — | — | — | The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and in | 92d ago |
| CVE-2026-8901 | 7.2 | — | — | — | — | The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is | 92d ago |
| CVE-2026-8438 | 7.2 | — | — | — | — | The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scri | 92d ago |
| CVE-2026-50232 | 7.2 | — | — | — | — | Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject mal | 93d ago |
| CVE-2026-50231 | 7.2 | — | — | — | — | Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer | 93d ago |
| CVE-2026-41567 | 7.2 | — | — | — | — | Moby is an open source container framework. | 93d ago |
| CVE-2026-10586 | 7.2 | — | — | — | — | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable t | 93d ago |
| CVE-2026-10873 | 7.2 | — | — | — | — | A vulnerability was determined in Shibby Tomato 1.28.0000. | 93d ago |
| CVE-2026-10872 | 7.2 | — | — | — | — | A vulnerability was found in Shibby Tomato 1.28.0000. | 93d ago |
| CVE-2026-10871 | 7.2 | — | — | — | — | A vulnerability has been found in Shibby Tomato 1.28.0000. | 93d ago |
| CVE-2026-10870 | 7.2 | — | — | — | — | A flaw has been found in Shibby Tomato 1.28.0000. | 93d ago |
| CVE-2026-10843 | 7.2 | — | — | — | — | A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. | 94d ago |
| CVE-2026-3820 | 7.2 | — | — | — | — | There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. | 94d ago |
| CVE-2026-24092 | 7.2 | — | — | — | qualcomm / ar8031 firmware | Memory Corruption when processing fastboot commands to set display mode. | 96d ago |
| CVE-2026-24091 | 7.2 | — | — | — | qualcomm / c-v2x 9150 firmware | Memory corruption while processing fastboot commands with improperly formatted input. | 96d ago |
| CVE-2026-24089 | 7.2 | — | — | — | qualcomm / ar8031 firmware | Memory corruption while processing fastboot commands with invalid input. | 96d ago |
| CVE-2026-24087 | 7.2 | — | — | — | qualcomm / ar8031 firmware | Memory corruption while processing fastboot OEM commands. | 96d ago |
| CVE-2026-24085 | 7.2 | — | — | — | qualcomm / qca6391 firmware | Memory Corruption when processing display command line information due to improper initialization of a variable. | 96d ago |
| CVE-2026-40961 | 7.2 | — | — | — | apache / airflow | A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `i | 97d ago |
| CVE-2026-39276 | 7.2 | — | — | — | emlog / emlog | The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated adminis | 99d ago |
| CVE-2026-45609 | 7.2 | — | — | — | springaicommunity / mcp security | mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. | 99d ago |
| CVE-2026-10072 | 7.2 | — | — | — | — | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers | 100d ago |
| CVE-2025-41279 | 7.2 | — | — | — | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS C | 100d ago |
| CVE-2025-41267 | 7.2 | — | — | — | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS C | 100d ago |
| CVE-2025-41266 | 7.2 | — | — | — | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS C | 100d ago |
| CVE-2025-41265 | 7.2 | — | — | — | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS C | 100d ago |
| CVE-2026-49196 | 7.2 | — | — | — | acer / predator connect w6x firmware | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitra | 100d ago |
| CVE-2025-11262zero day | 7.2 | 0.24% | 1/3 | same day | — | The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter | 100d ago |
| CVE-2026-7634 | 7.2 | — | — | — | — | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' heade | 101d ago |
| CVE-2026-7052 | 7.2 | — | — | — | — | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit | 101d ago |
| CVE-2026-2374 | 7.2 | — | — | — | — | The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER[ | 101d ago |
| CVE-2026-5509 | 7.2 | — | — | — | tp-link / archer be450 firmware | An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an | 101d ago |
| CVE-2024-56462 | 7.2 | — | — | — | ibm / qradar security information and event manager | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup arc | 102d ago |
| CVE-2026-40852 | 7.2 | — | — | — | — | A highly authenticated attacker can alter the config generator injecting a payload into future created configurati | 102d ago |
| CVE-2026-8143 | 7.2 | — | — | — | — | The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state | 102d ago |
| CVE-2026-6169 | 7.2 | — | — | — | — | The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and includ | 102d ago |