| CVE-2026-70950 | 7.2 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 52d ago |
| CVE-2026-70939 | 7.2 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 52d ago |
| CVE-2026-70932 | 7.2 | — | — | — | oracle / order management | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Too | 52d ago |
| CVE-2026-70861 | 7.2 | — | — | — | — | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Comm | 52d ago |
| CVE-2026-70834 | 7.2 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 52d ago |
| CVE-2026-70820 | 7.2 | — | — | — | oracle / complex maintenance repair and overhaul | Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operati | 52d ago |
| CVE-2026-70797 | 7.2 | — | — | — | oracle / purchasing | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). | 52d ago |
| CVE-2026-70796 | 7.2 | — | — | — | oracle / general ledger | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). | 52d ago |
| CVE-2026-70781 | 7.2 | — | — | — | oracle / proposals | Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations). | 52d ago |
| CVE-2026-70735 | 7.2 | — | — | — | oracle / hyperion profitability and cost management | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Depl | 52d ago |
| CVE-2026-62616 | 7.2 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 52d ago |
| CVE-2026-62540 | 7.2 | — | — | — | — | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). | 52d ago |
| CVE-2026-62459 | 7.2 | — | — | — | oracle / hyperion calculation manager | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). | 52d ago |
| CVE-2026-60994 | 7.2 | — | — | — | oracle / identity manager connector | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). | 52d ago |
| CVE-2026-60883 | 7.2 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). | 52d ago |
| CVE-2026-60873 | 7.2 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data Mover). | 52d ago |
| CVE-2026-54348 | 7.2 | — | — | — | — | Froxlor is open source server administration software. | 52d ago |
| CVE-2026-73367 | 7.2 | — | — | — | — | Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | 52d ago |
| CVE-2026-66620 | 7.2 | — | — | — | — | Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | 52d ago |
| CVE-2026-32553 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | 52d ago |
| CVE-2026-32473 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | 52d ago |
| CVE-2026-75091 | 7.2 | — | — | — | — | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored | 52d ago |
| CVE-2026-16139 | 7.2 | — | — | — | progress / sharefile storage zones controller | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrato | 53d ago |
| CVE-2026-16137 | 7.2 | — | — | — | progress / sharefile storage zones controller | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform | 53d ago |
| CVE-2026-74998 | 7.2 | — | — | — | — | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy w | 53d ago |
| CVE-2026-2497 | 7.2 | — | — | — | — | The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' p | 54d ago |
| CVE-2026-13424 | 7.2 | — | — | — | — | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-S | 54d ago |
| CVE-2026-10734 | 7.2 | — | — | — | — | The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint | 54d ago |
| CVE-2026-18653 | 7.2 | — | — | — | — | The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a S | 54d ago |
| CVE-2026-17581 | 7.2 | — | — | — | — | The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via th | 54d ago |
| CVE-2026-17533 | 7.2 | — | — | — | — | The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functi | 54d ago |
| CVE-2026-15002 | 7.2 | — | — | — | — | The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver | 54d ago |
| CVE-2026-16145 | 7.2 | — | — | — | — | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stor | 55d ago |
| CVE-2026-13360 | 7.2 | — | — | — | — | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Sc | 55d ago |
| CVE-2026-14433 | 7.2 | — | — | — | — | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross | 55d ago |
| CVE-2026-73679 | 7.2 | — | — | — | — | ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows auth | 56d ago |
| CVE-2026-19628 | 7.2 | — | — | — | tenable / security center | A command injection vulnerability exists in Tenable Security Center. | 56d ago |
| CVE-2026-66271 | 7.2 | — | — | — | dell / wyse management suite | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerou | 56d ago |
| CVE-2026-66270 | 7.2 | — | — | — | dell / wyse management suite | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerou | 56d ago |
| CVE-2026-72828 | 7.2 | — | — | — | — | Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsControll | 56d ago |
| CVE-2026-19794 | 7.2 | — | — | — | — | The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin | 56d ago |
| CVE-2026-18109zero day | 7.2 | 0.43% | 1/3 | same day | — | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in al | 56d ago |
| CVE-2026-19771 | 7.2 | — | — | — | — | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. | 56d ago |
| CVE-2026-73670 | 7.2 | — | — | — | — | A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administra | 57d ago |
| CVE-2026-66256 | 7.2 | — | — | — | — | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. | 57d ago |
| CVE-2026-66704 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | 57d ago |
| CVE-2026-27380 | 7.2 | — | — | — | — | Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. | 57d ago |
| CVE-2026-6471 | 7.2 | — | — | — | postgresql / postgresql | Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen | 57d ago |
| CVE-2026-18146 | 7.2 | — | — | — | — | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is | 57d ago |
| CVE-2026-12618 | 7.2 | — | — | — | ibm / security verify access | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify | 58d ago |
| CVE-2026-12005 | 7.2 | — | — | — | ibm / security verify access | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify | 58d ago |
| CVE-2026-68759 | 7.2 | — | — | — | jfrog / artifactory | A holder of a valid integration credential may impersonate other users under specific conditions. | 58d ago |
| CVE-2026-68752 | 7.2 | — | — | — | jfrog / artifactory | A Project Resource Manager may gain broader administrative privileges under specific conditions. | 58d ago |
| CVE-2025-59319 | 7.2 | — | — | — | — | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partiti | 58d ago |
| CVE-2026-62910 | 7.2 | — | — | — | microsoft / exchange server | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized | 59d ago |
| CVE-2026-47299 | 7.2 | — | — | — | microsoft / azure monitor agent | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows | 59d ago |
| CVE-2026-20898 | 7.2 | — | — | — | intel / xeon 6315p firmware | Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) proces | 59d ago |
| CVE-2026-20885 | 7.2 | — | — | — | intel / tdx module | Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may all | 59d ago |
| CVE-2026-18635 | 7.2 | — | — | — | — | Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. | 59d ago |
| CVE-2026-72747 | 7.2 | — | — | — | — | AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject ma | 59d ago |