| CVE-2026-44852 | 7.2 | — | — | — | arubanetworks / arubaos | An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface | 116d ago |
| CVE-2026-8431 | 7.2 | — | — | — | — | An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then tri | 116d ago |
| CVE-2026-23823 | 7.2 | — | — | — | arubanetworks / arubaos | A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote | 116d ago |
| CVE-2026-23821 | 7.2 | — | — | — | arubanetworks / arubaos | A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated | 116d ago |
| CVE-2026-23820 | 7.2 | — | — | — | arubanetworks / arubaos | A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an aut | 116d ago |
| CVE-2025-53681 | 7.2 | — | — | — | fortinet / fortimail | An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vu | 116d ago |
| CVE-2026-8051 | 7.2 | — | — | — | ivanti / virtual traffic manager | OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker | 116d ago |
| CVE-2026-6690 | 7.2 | — | — | — | — | The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_upd | 117d ago |
| CVE-2026-43874 | 7.2 | — | — | — | — | WWBN AVideo is an open source video platform. | 117d ago |
| CVE-2026-41951 | 7.2 | — | — | — | — | Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary | 118d ago |
| CVE-2026-33157 | 7.2 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 165d ago |
| CVE-2025-64998 | 7.2 | — | — | — | checkmk / checkmk | Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote s | 166d ago |
| CVE-2026-4627 | 7.2 | — | — | — | — | A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. | 166d ago |
| CVE-2026-4611 | 7.2 | — | — | — | totolink / x6000r firmware | A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. | 166d ago |
| CVE-2026-23882 | 7.2 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 166d ago |
| CVE-2026-33681 | 7.2 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2025-15519 | 7.2 | — | — | — | tp-link / archer nx600 firmware | Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and | 166d ago |
| CVE-2025-15518 | 7.2 | — | — | — | tp-link / archer nx600 firmware | Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and | 166d ago |
| CVE-2026-3478 | 7.2 | — | — | — | — | The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u | 169d ago |
| CVE-2026-3003 | 7.2 | — | — | — | — | The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ p | 169d ago |
| CVE-2026-2440 | 7.2 | — | — | — | — | The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including | 169d ago |
| CVE-2026-2279 | 7.2 | — | — | — | — | The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters i | 169d ago |
| CVE-2026-1648 | 7.2 | — | — | — | — | The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an | 169d ago |
| CVE-2026-4302 | 7.2 | — | — | — | — | The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all version | 169d ago |
| CVE-2026-3368 | 7.2 | — | — | — | — | The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter | 169d ago |
| CVE-2025-55988 | 7.2 | — | — | — | dreamfactory / dreamfactory core | An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute | 169d ago |
| CVE-2026-33133 | 7.2 | — | — | — | wegia / wegia | WeGIA is a web manager for charitable institutions. | 170d ago |
| CVE-2026-29109 | 7.2 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-29102 | 7.2 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-27043 | 7.2 | — | — | — | — | Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This | 170d ago |
| CVE-2026-1238 | 7.2 | — | — | — | — | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) | 171d ago |
| CVE-2026-3090 | 7.2 | — | — | — | — | The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App p | 171d ago |
| CVE-2026-22317 | 7.2 | — | — | — | — | A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged a | 172d ago |
| CVE-2026-22179 | 7.2 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that | 172d ago |
| CVE-2026-28674 | 7.2 | — | — | — | danvei233 / xiaoheifs | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. | 172d ago |
| CVE-2026-28673 | 7.2 | — | — | — | danvei233 / xiaoheifs | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. | 172d ago |
| CVE-2026-23759 | 7.2 | — | — | — | — | Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command inje | 172d ago |
| CVE-2026-32264 | 7.2 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 173d ago |
| CVE-2026-32263 | 7.2 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 173d ago |
| CVE-2026-4172 | 7.2 | — | — | — | — | A vulnerability was detected in TRENDnet TEW-632BRP 1.010B32. | 173d ago |
| CVE-2026-31386 | 7.2 | — | — | — | litespeedtech / litespeed web server | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability | 173d ago |
| CVE-2016-20032 | 7.2 | — | — | — | — | ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers t | 173d ago |
| CVE-2015-20118 | 7.2 | — | — | — | nextclickventures / realtyscript | Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name p | 173d ago |
| CVE-2015-20115 | 7.2 | — | — | — | nextclickventures / realtyscript | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malici | 173d ago |
| CVE-2026-3873 | 7.2 | — | — | — | — | Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by A | 176d ago |
| CVE-2026-32414 | 7.2 | — | — | — | — | Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo- | 176d ago |
| CVE-2026-32401 | 7.2 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 176d ago |
| CVE-2026-20163 | 7.2 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10 | 178d ago |
| CVE-2025-67037 | 7.2 | — | — | — | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 178d ago |
| CVE-2025-67036 | 7.2 | — | — | — | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 178d ago |
| CVE-2025-67034 | 7.2 | — | — | — | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 178d ago |
| CVE-2026-1497 | 7.2 | — | — | — | neo4j / neo4j | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and | 178d ago |
| CVE-2026-86091 | 7.1 | — | — | — | — | ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated | 1d ago |
| CVE-2026-86090 | 7.1 | — | — | — | — | ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 hand | 1d ago |
| CVE-2026-80118 | 7.1 | — | — | — | — | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 bu | 1d ago |
| CVE-2026-80117 | 7.1 | — | — | — | — | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 bu | 1d ago |
| CVE-2026-80113 | 7.1 | — | — | — | — | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 bu | 1d ago |
| CVE-2022-35499 | 7.1 | — | — | — | — | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via | 1d ago |
| CVE-2026-19051 | 7.1 | — | — | — | — | Plaintext storage of a password vulnerability in Menulux Software Inc. | 2d ago |
| CVE-2026-16281 | 7.1 | — | — | — | — | The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target l | 2d ago |