| CVE-2026-12462 | 7.5 | — | — | — | google / chrome | Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the | 116d ago |
| CVE-2026-12455 | 7.5 | — | — | — | google / chrome | Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a use | 116d ago |
| CVE-2026-12445 | 7.5 | — | — | — | google / chrome | Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to | 116d ago |
| CVE-2026-12360 | 7.5 | — | — | — | — | The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. | 116d ago |
| CVE-2026-12199 | 7.5 | — | — | — | — | A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local | 116d ago |
| CVE-2025-69131 | 7.5 | — | — | — | — | Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1. | 116d ago |
| CVE-2025-69103 | 7.5 | — | — | — | — | Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions. | 116d ago |
| CVE-2025-49403 | 7.5 | — | — | — | — | Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions. | 116d ago |
| CVE-2024-32729 | 7.5 | — | — | — | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conve | 116d ago |
| CVE-2026-46974 | 7.5 | — | — | — | oracle / vm virtualbox | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). | 116d ago |
| CVE-2026-46971 | 7.5 | — | — | — | oracle / hr intelligence | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). | 116d ago |
| CVE-2026-46966 | 7.5 | — | — | — | oracle / universal work queue | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site | 116d ago |
| CVE-2026-46959 | 7.5 | — | — | — | oracle / subledger accounting | Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operation | 116d ago |
| CVE-2026-46958 | 7.5 | — | — | — | oracle / subledger accounting | Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operation | 116d ago |
| CVE-2026-46957 | 7.5 | — | — | — | oracle / isupplier portal | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). | 116d ago |
| CVE-2026-46955 | 7.5 | — | — | — | oracle / human resources | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). | 116d ago |
| CVE-2026-46935 | 7.5 | — | — | — | oracle / complex maintenance repair and overhaul | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component | 116d ago |
| CVE-2026-46934 | 7.5 | — | — | — | oracle / complex maintenance repair and overhaul | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component | 116d ago |
| CVE-2026-46873 | 7.5 | — | — | — | oracle / vm virtualbox | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). | 116d ago |
| CVE-2026-46863 | 7.5 | — | — | — | oracle / mysql cluster | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). | 116d ago |
| CVE-2026-46862 | 7.5 | — | — | — | oracle / mysql router | Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). | 116d ago |
| CVE-2026-46791 | 7.5 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 116d ago |
| CVE-2026-35295 | 7.5 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 116d ago |
| CVE-2026-35275 | 7.5 | — | — | — | oracle / vm virtualbox | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). | 116d ago |
| CVE-2026-35269 | 7.5 | — | — | — | oracle / identity manager | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). | 116d ago |
| CVE-2026-0156 | 7.5 | — | — | — | google / android | In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. | 117d ago |
| CVE-2026-12398 | 7.5 | — | — | — | — | A command injection vulnerability was found in galaxy_ng. | 117d ago |
| CVE-2026-12317 | 7.5 | — | — | — | mozilla / firefox | Memory safety bug fixed in Firefox 152. | 117d ago |
| CVE-2026-12314 | 7.5 | — | — | — | mozilla / firefox | Memory safety bug fixed in Firefox 152. | 117d ago |
| CVE-2026-12312 | 7.5 | — | — | — | mozilla / firefox | Memory safety bug fixed in Firefox 152. | 117d ago |
| CVE-2026-12310 | 7.5 | — | — | — | mozilla / firefox | Memory safety bug fixed in Firefox 152. | 117d ago |
| CVE-2026-12305 | 7.5 | — | — | — | mozilla / firefox | Memory safety bug fixed in Firefox 152. | 117d ago |
| CVE-2026-8176 | 7.5 | — | — | — | — | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege | 117d ago |
| CVE-2026-52711 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions. | 117d ago |
| CVE-2026-39490 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions. | 117d ago |
| CVE-2025-68045 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions. | 117d ago |
| CVE-2026-52699 | 7.5 | — | — | — | — | Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions. | 117d ago |
| CVE-2026-52695 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions. | 117d ago |
| CVE-2026-52694 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions. | 117d ago |
| CVE-2026-52692 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. | 117d ago |
| CVE-2026-49112 | 7.5 | — | — | — | — | Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions. | 117d ago |
| CVE-2026-49110 | 7.5 | — | — | — | — | Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions. | 117d ago |
| CVE-2026-49083 | 7.5 | — | — | — | — | Contributor Privilege Escalation in LatePoint <= 5.5.1 versions. | 117d ago |
| CVE-2026-49078 | 7.5 | — | — | — | — | Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions. | 117d ago |
| CVE-2026-49070 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions. | 117d ago |
| CVE-2026-49068 | 7.5 | — | — | — | — | Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions. | 117d ago |
| CVE-2026-49066 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions. | 117d ago |
| CVE-2026-49061 | 7.5 | — | — | — | — | Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions. | 117d ago |
| CVE-2026-49056 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping La | 117d ago |
| CVE-2026-48883 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions. | 117d ago |
| CVE-2026-48873 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions. | 117d ago |
| CVE-2026-48872 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions. | 117d ago |
| CVE-2026-48868 | 7.5 | — | — | — | — | Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions. | 117d ago |
| CVE-2026-48835 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions. | 117d ago |
| CVE-2026-48708 | 7.5 | — | — | — | — | OliveTin gives access to predefined shell commands from a web interface. | 117d ago |
| CVE-2026-47261 | 7.5 | — | — | — | bytecodealliance / wasmtime | Wasmtime is a runtime for WebAssembly. | 117d ago |
| CVE-2026-45441 | 7.5 | — | — | — | — | Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions. | 117d ago |
| CVE-2026-42668 | 7.5 | — | — | — | — | Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. | 117d ago |
| CVE-2026-42667 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions. | 117d ago |
| CVE-2026-42666 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. | 117d ago |