| CVE-2026-85599 | 7.2 | — | — | — | — | Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter | 35d ago |
| CVE-2026-19224 | 7.2 | — | — | — | — | The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network adm | 35d ago |
| CVE-2026-84773 | 7.2 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | 36d ago |
| CVE-2026-84761 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions. | 36d ago |
| CVE-2026-82524 | 7.2 | — | — | — | — | UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators t | 37d ago |
| CVE-2026-75528 | 7.2 | — | — | — | — | The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / | 37d ago |
| CVE-2026-73767 | 7.2 | — | — | — | hpe / arubaos-cx | Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. | 38d ago |
| CVE-2026-73766 | 7.2 | — | — | — | hpe / arubaos-cx | Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with | 38d ago |
| CVE-2026-73765 | 7.2 | — | — | — | hpe / arubaos-cx | Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. | 38d ago |
| CVE-2026-73722 | 7.2 | — | — | — | arubanetworks / fabric composer | Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Composer could al | 38d ago |
| CVE-2026-73721 | 7.2 | — | — | — | arubanetworks / fabric composer | Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to condu | 38d ago |
| CVE-2026-73720 | 7.2 | — | — | — | arubanetworks / fabric composer | Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker | 38d ago |
| CVE-2026-73719 | 7.2 | — | — | — | arubanetworks / fabric composer | An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could allow an authe | 38d ago |
| CVE-2026-83551 | 7.2 | — | — | — | — | Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMak | 38d ago |
| CVE-2024-14047 | 7.2 | — | — | — | — | A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writabl | 38d ago |
| CVE-2026-84190 | 7.2 | — | — | — | — | LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snm | 38d ago |
| CVE-2026-19914 | 7.2 | — | — | — | — | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' pa | 38d ago |
| CVE-2026-75921 | 7.2 | — | — | — | — | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Te | 38d ago |
| CVE-2026-19796 | 7.2 | — | — | — | — | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Sto | 38d ago |
| CVE-2026-19573 | 7.2 | — | — | — | — | The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doComment | 38d ago |
| CVE-2026-75123 | 7.2 | — | — | — | — | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability | 42d ago |
| CVE-2026-75122 | 7.2 | — | — | — | — | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability | 42d ago |
| CVE-2026-75121 | 7.2 | — | — | — | — | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability | 42d ago |
| CVE-2026-81757 | 7.2 | — | — | — | — | Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | 42d ago |
| CVE-2026-6176 | 7.2 | — | — | — | — | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggr | 42d ago |
| CVE-2026-5934 | 7.2 | — | — | — | — | The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3 | 42d ago |
| CVE-2026-79996 | 7.2 | — | — | — | — | The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving i | 42d ago |
| CVE-2026-6286 | 7.2 | — | — | — | — | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site S | 42d ago |
| CVE-2026-14558 | 7.2 | — | — | — | — | The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialise | 42d ago |
| CVE-2026-77365 | 7.2 | — | — | — | — | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress i | 42d ago |
| CVE-2026-76053 | 7.2 | — | — | — | — | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored | 42d ago |
| CVE-2026-18978 | 7.2 | — | — | — | — | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all v | 42d ago |
| CVE-2026-18324 | 7.2 | — | — | — | — | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stor | 42d ago |
| CVE-2026-75417 | 7.2 | — | — | — | — | A SQL injection vulnerability was found in YzmCMS 7.5. | 43d ago |
| CVE-2026-54718 | 7.2 | — | — | — | — | Silverstripe Advanced Workflow is a highly configurable step-based workflow module. | 43d ago |
| CVE-2026-36102 | 7.2 | — | — | — | — | An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated admin | 43d ago |
| CVE-2026-78276 | 7.2 | — | — | — | — | Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | 43d ago |
| CVE-2026-78271 | 7.2 | — | — | — | — | Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions. | 43d ago |
| CVE-2026-19223 | 7.2 | — | — | — | — | The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowi | 43d ago |
| CVE-2026-13415 | 7.2 | — | — | — | — | The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one | 43d ago |
| CVE-2026-71171 | 7.2 | — | — | — | dell / cloud disaster recovery | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used | 44d ago |
| CVE-2026-47836 | 7.2 | — | — | — | vmware / spring cloud config | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN re | 44d ago |
| CVE-2026-81031 | 7.2 | — | — | — | — | IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the reques | 44d ago |
| CVE-2026-80233 | 7.2 | — | — | — | — | CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerab | 44d ago |
| CVE-2026-18331 | 7.2 | — | — | — | — | The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress | 44d ago |
| CVE-2026-74851 | 7.2 | — | — | — | — | The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked | 44d ago |
| CVE-2026-19760 | 7.2 | — | — | — | — | The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi | 44d ago |
| CVE-2026-45019 | 7.2 | — | — | — | — | Chainlit is a Python framework for building production-ready conversational AI applications. | 45d ago |
| CVE-2026-75498 | 7.2 | — | — | — | — | Webkul QloApps does not validate request parameters before a database query. | 45d ago |
| CVE-2026-75497 | 7.2 | — | — | — | — | Webkul QloApps does not validate request parameters before a database query. | 45d ago |
| CVE-2026-75496 | 7.2 | — | — | — | — | Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file | 45d ago |
| CVE-2026-75971 | 7.2 | — | — | — | — | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulne | 45d ago |
| CVE-2026-18328 | 7.2 | — | — | — | — | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM- | 45d ago |
| CVE-2026-18323 | 7.2 | — | — | — | — | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stor | 45d ago |
| CVE-2026-56703 | 7.2 | — | — | — | — | Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is | 45d ago |
| CVE-2026-71943 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. | 46d ago |
| CVE-2026-71942 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. | 46d ago |
| CVE-2026-71941 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. | 46d ago |
| CVE-2026-71940 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE func | 46d ago |
| CVE-2026-71939 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE funct | 46d ago |