| CVE-2026-71938 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. | 46d ago |
| CVE-2026-71937 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. | 46d ago |
| CVE-2026-71936 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. | 46d ago |
| CVE-2026-71935 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. | 46d ago |
| CVE-2026-71934 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. | 46d ago |
| CVE-2026-71931 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. | 46d ago |
| CVE-2026-71930 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. | 46d ago |
| CVE-2026-71929 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. | 46d ago |
| CVE-2026-71928 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. | 46d ago |
| CVE-2026-71927 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. | 46d ago |
| CVE-2026-71926 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. | 46d ago |
| CVE-2026-71925 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. | 46d ago |
| CVE-2026-71924 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. | 46d ago |
| CVE-2026-71923 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. | 46d ago |
| CVE-2026-71919 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. | 46d ago |
| CVE-2026-71918 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. | 46d ago |
| CVE-2026-71917 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. | 46d ago |
| CVE-2026-71916 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. | 46d ago |
| CVE-2026-71915 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. | 46d ago |
| CVE-2026-71913 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. | 46d ago |
| CVE-2026-71912 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. | 46d ago |
| CVE-2026-71911 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. | 46d ago |
| CVE-2026-71910 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. | 46d ago |
| CVE-2026-71909 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. | 46d ago |
| CVE-2026-71908 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. | 46d ago |
| CVE-2026-71907 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. | 46d ago |
| CVE-2026-71906 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. | 46d ago |
| CVE-2026-71905 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. | 46d ago |
| CVE-2026-71904 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. | 46d ago |
| CVE-2026-71364 | 7.2 | — | — | — | — | A path traversal vulnerability was found in AWX's project archive extraction. | 46d ago |
| CVE-2026-21756 | 7.2 | — | — | — | — | HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user t | 46d ago |
| CVE-2026-19221 | 7.2 | — | — | — | — | The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administ | 48d ago |
| CVE-2026-66722 | 7.2 | — | — | — | apache / cloudstack | Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in Clou | 49d ago |
| CVE-2026-75796 | 7.2 | — | — | — | — | The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the t | 49d ago |
| CVE-2026-16576 | 7.2 | — | — | — | — | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correct | 49d ago |
| CVE-2026-18409 | 7.2 | — | — | — | — | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragra | 49d ago |
| CVE-2026-53804 | 7.2 | — | — | — | — | OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module t | 50d ago |
| CVE-2026-18274 | 7.2 | — | — | — | — | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. | 50d ago |
| CVE-2026-15686 | 7.2 | — | — | — | — | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. | 50d ago |
| CVE-2026-76635 | 7.2 | — | — | — | — | baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated ad | 50d ago |
| CVE-2026-14947 | 7.2 | — | — | — | — | A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such a | 50d ago |
| CVE-2026-14946 | 7.2 | — | — | — | — | A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php | 50d ago |
| CVE-2026-15049 | 7.2 | — | — | — | — | The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded | 50d ago |
| CVE-2026-23501 | 7.2 | — | — | — | — | Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements use | 51d ago |
| CVE-2026-70421 | 7.2 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. | 51d ago |
| CVE-2026-54796 | 7.2 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used | 51d ago |
| CVE-2026-54794 | 7.2 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. | 51d ago |
| CVE-2026-75981exploited | 7.2 | 0.39% | 1/3 | +22d | — | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauth | 51d ago |
| CVE-2026-15780exploited | 7.2 | 0.65% | 1/3 | +1d | — | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to St | 51d ago |
| CVE-2026-17565 | 7.2 | — | — | — | — | The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before us | 51d ago |
| CVE-2026-13174 | 7.2 | — | — | — | — | The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, | 51d ago |
| CVE-2026-73928 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 52d ago |
| CVE-2026-73886 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 52d ago |
| CVE-2026-73885 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 52d ago |
| CVE-2026-73876 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 52d ago |
| CVE-2026-73875 | 7.2 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 52d ago |
| CVE-2026-71104 | 7.2 | — | — | — | oracle / human resources management system | Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Business Suite (component: Netherlands Payroll) | 52d ago |
| CVE-2026-71099 | 7.2 | — | — | — | oracle / business intelligence | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analy | 52d ago |
| CVE-2026-71032 | 7.2 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 52d ago |
| CVE-2026-71030 | 7.2 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 52d ago |