| CVE-2026-42384 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions. | 117d ago |
| CVE-2026-40789 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions. | 117d ago |
| CVE-2026-40781 | 7.5 | — | — | — | — | Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions. | 117d ago |
| CVE-2026-40776 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions. | 117d ago |
| CVE-2026-40774 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions. | 117d ago |
| CVE-2026-40767 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions. | 117d ago |
| CVE-2026-40762 | 7.5 | — | — | — | — | Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions. | 117d ago |
| CVE-2026-40741 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions. | 117d ago |
| CVE-2026-39534 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions. | 117d ago |
| CVE-2026-39533 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions. | 117d ago |
| CVE-2026-39524 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions. | 117d ago |
| CVE-2026-39513 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions. | 117d ago |
| CVE-2026-39503 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions. | 117d ago |
| CVE-2026-39480 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions. | 117d ago |
| CVE-2026-34898 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions. | 117d ago |
| CVE-2026-34891 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions. | 117d ago |
| CVE-2026-34886 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions. | 117d ago |
| CVE-2026-27089 | 7.5 | — | — | — | — | Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions. | 117d ago |
| CVE-2026-25425 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions. | 117d ago |
| CVE-2025-59133 | 7.5 | — | — | — | — | Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions. | 117d ago |
| CVE-2026-50889 | 7.5 | — | — | — | lldap / lldap | An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Ser | 117d ago |
| CVE-2026-50885 | 7.5 | — | — | — | — | Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attack | 117d ago |
| CVE-2026-50882 | 7.5 | — | — | — | — | An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service | 117d ago |
| CVE-2026-50879 | 7.5 | — | — | — | — | An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial | 117d ago |
| CVE-2026-50878 | 7.5 | — | — | — | — | An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial o | 117d ago |
| CVE-2026-50877 | 7.5 | — | — | — | — | An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with name | 117d ago |
| CVE-2026-50870 | 7.5 | — | — | — | — | An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows at | 117d ago |
| CVE-2026-41708 | 7.5 | — | — | — | broadcom / spring cloud sleuth | In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-se | 117d ago |
| CVE-2026-39007 | 7.5 | — | — | — | — | An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information | 117d ago |
| CVE-2026-47777 | 7.5 | — | — | — | — | Mastodon is a free, open-source social network server based on ActivityPub. | 117d ago |
| CVE-2026-9863 | 7.5 | — | — | — | fortra / core privileged access manager server | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for lega | 118d ago |
| CVE-2026-5079 | 7.5 | — | — | — | expressjs / multer | Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nest | 118d ago |
| CVE-2026-49064 | 7.5 | — | — | — | — | Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensit | 118d ago |
| CVE-2018-25437 | 7.5 | — | — | — | — | WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticate | 118d ago |
| CVE-2016-20081 | 7.5 | — | — | — | — | WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated a | 118d ago |
| CVE-2016-20076 | 7.5 | — | — | — | — | WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete ar | 118d ago |
| CVE-2026-9848 | 7.5 | — | — | — | — | The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in | 120d ago |
| CVE-2026-53868 | 7.5 | — | — | — | — | Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arb | 120d ago |
| CVE-2026-53834 | 7.5 | — | — | — | openclaw / openclaw | OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that | 120d ago |
| CVE-2026-4870 | 7.5 | — | — | — | ibm / qiskit software development kit | IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of | 120d ago |
| CVE-2026-44786 | 7.5 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 120d ago |
| CVE-2026-50108 | 7.5 | — | — | — | — | The Naxclow platform API that returns device relay registration details exposes a persistent credential without ve | 120d ago |
| CVE-2026-12143 | 7.5 | — | — | — | — | form-data is a library for creating readable multipart/form-data streams. | 120d ago |
| CVE-2026-9638 | 7.5 | — | — | — | — | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. | 121d ago |
| CVE-2026-50011 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-50010 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-48748 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-48059 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-48006 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-46340 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-45416 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-44894 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-44893 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-50645 | 7.5 | — | — | — | apache / cxf | There is no restriction on the amount of attachment headers that a message can contain when being deserialized by | 121d ago |
| CVE-2026-44892 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-44890 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-44250 | 7.5 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2025-46315 | 7.5 | — | — | — | apple / macos | A permissions issue was addressed with additional restrictions. | 121d ago |
| CVE-2026-46697 | 7.5 | — | — | — | — | Fediverse Embeds embeds fediverse posts on WordPress sites. | 121d ago |
| CVE-2026-3329 | 7.5 | — | — | — | sonatype / nexus repository manager | A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonat | 121d ago |