| CVE-2026-3375 | 7.2 | — | — | — | — | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1 | 102d ago |
| CVE-2026-4051 | 7.2 | — | — | — | ibm / engineering lifecycle management | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges | 102d ago |
| CVE-2026-44730 | 7.2 | — | — | — | citeum / opencti | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. | 102d ago |
| CVE-2026-42785 | 7.2 | — | — | — | — | OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute a | 102d ago |
| CVE-2026-42425 | 7.2 | — | — | — | — | OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users | 102d ago |
| CVE-2026-24937 | 7.2 | — | — | — | — | Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video a | 103d ago |
| CVE-2026-48848 | 7.2 | — | — | — | — | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to C | 103d ago |
| CVE-2026-48843 | 7.2 | — | — | — | — | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets ( | 103d ago |
| CVE-2026-42782 | 7.2 | — | — | — | apache / syncope | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | 103d ago |
| CVE-2026-8135 | 7.2 | — | — | — | concretecms / concrete cms | Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in th | 107d ago |
| CVE-2026-8134 | 7.2 | — | — | — | concretecms / concrete cms | Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustom | 107d ago |
| CVE-2026-44058 | 7.2 | — | — | — | — | An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenti | 108d ago |
| CVE-2026-7613 | 7.2 | — | — | — | — | The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvda | 108d ago |
| CVE-2026-22315 | 7.2 | — | — | — | — | Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Comp | 109d ago |
| CVE-2026-27891 | 7.2 | — | — | — | — | FacturaScripts is an open source accounting and invoicing software. | 110d ago |
| CVE-2026-8764 | 7.2 | — | — | — | — | A security vulnerability has been detected in H3C Magic B3 up to 100R002. | 111d ago |
| CVE-2021-47975 | 7.2 | — | — | — | — | WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers | 112d ago |
| CVE-2026-45395 | 7.2 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 113d ago |
| CVE-2021-47963 | 7.2 | — | — | — | — | Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code | 113d ago |
| CVE-2026-8597 | 7.2 | — | — | — | — | Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 an | 114d ago |
| CVE-2026-8596 | 7.2 | — | — | — | — | Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK befor | 114d ago |
| CVE-2026-22599 | 7.2 | — | — | — | strapi / strapi | Strapi is an open source headless content management system. | 114d ago |
| CVE-2026-41937 | 7.2 | — | — | — | — | Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows | 114d ago |
| CVE-2026-6476 | 7.2 | — | — | — | postgresql / postgresql | SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute ar | 115d ago |
| CVE-2026-3718 | 7.2 | — | — | — | — | The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP r | 115d ago |
| CVE-2026-45708 | 7.2 | — | — | — | — | CubeCart is an ecommerce software solution. | 115d ago |
| CVE-2026-44380 | 7.2 | — | — | — | misp-project / misp | MISP is an open source threat intelligence and sharing platform. | 115d ago |
| CVE-2026-39358 | 7.2 | — | — | — | — | CubeCart is an ecommerce software solution. | 115d ago |
| CVE-2026-0261 | 7.2 | — | — | — | paloaltonetworks / pan-os | Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administr | 115d ago |
| CVE-2026-0241 | 7.2 | — | — | — | paloaltonetworks / trust protection foundation | Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls an | 115d ago |
| CVE-2026-39459 | 7.2 | — | — | — | f5 / big-ip access policy manager | A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacke | 115d ago |
| CVE-2026-36741 | 7.2 | — | — | — | u-speed / t18-21k firmware | U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. | 115d ago |
| CVE-2020-37222 | 7.2 | — | — | — | — | Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers t | 115d ago |
| CVE-2026-6177 | 7.2 | — | — | — | — | The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and in | 116d ago |
| CVE-2026-35506 | 7.2 | — | — | — | — | ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_ad | 116d ago |
| CVE-2026-6888 | 7.2 | — | — | — | — | Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute a | 116d ago |
| CVE-2026-43685 | 7.2 | — | — | — | claris / filemaker cloud | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to in | 116d ago |
| CVE-2026-43680 | 7.2 | — | — | — | claris / filemaker cloud | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to by | 116d ago |
| CVE-2026-44871 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol | 116d ago |
| CVE-2026-44403 | 7.2 | — | — | — | wftpserver / wing ftp server | Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serializ | 116d ago |
| CVE-2026-44246 | 7.2 | — | — | — | dkfz / nnu-net | nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. | 116d ago |
| CVE-2026-44872 | 7.2 | — | — | — | arubanetworks / arubaos | A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Syste | 116d ago |
| CVE-2026-44870 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol | 116d ago |
| CVE-2026-44869 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 116d ago |
| CVE-2026-44868 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 116d ago |
| CVE-2026-44867 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 116d ago |
| CVE-2026-44866 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 116d ago |
| CVE-2026-44865 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 116d ago |
| CVE-2026-44864 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 116d ago |
| CVE-2026-44863 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 116d ago |
| CVE-2026-44862 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 116d ago |
| CVE-2026-44861 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 116d ago |
| CVE-2026-44860 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 116d ago |
| CVE-2026-44859 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 116d ago |
| CVE-2026-44858 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 116d ago |
| CVE-2026-44857 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 116d ago |
| CVE-2026-44856 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 116d ago |
| CVE-2026-44855 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 116d ago |
| CVE-2026-44854 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 116d ago |
| CVE-2026-44853 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 116d ago |