| CVE-2026-4757 | 7.2 | — | — | — | — | A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a priv | 59d ago |
| CVE-2026-14237 | 7.2 | — | — | — | — | The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target autho | 60d ago |
| CVE-2026-13170 | 7.2 | — | — | — | — | The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to i | 60d ago |
| CVE-2026-63725 | 7.2 | — | — | — | — | sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 build | 64d ago |
| CVE-2026-65559 | 7.2 | — | — | — | — | Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | 64d ago |
| CVE-2026-65549 | 7.2 | — | — | — | — | Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | 64d ago |
| CVE-2026-19036 | 7.2 | — | — | — | — | A security flaw has been discovered in Shibby Tomato 1.28.0000. | 64d ago |
| CVE-2026-19035 | 7.2 | — | — | — | — | A vulnerability was identified in Shibby Tomato 1.28.0000. | 64d ago |
| CVE-2025-15028 | 7.2 | — | — | — | — | The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPre | 64d ago |
| CVE-2026-19034 | 7.2 | — | — | — | — | A vulnerability was determined in Shibby Tomato 1.28.0000. | 64d ago |
| CVE-2026-18510 | 7.2 | — | — | — | — | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored | 64d ago |
| CVE-2026-18325 | 7.2 | — | — | — | — | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stor | 64d ago |
| CVE-2026-16636 | 7.2 | — | — | — | — | The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin | 64d ago |
| CVE-2026-70608 | 7.2 | — | — | — | — | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. | 65d ago |
| CVE-2026-17625 | 7.2 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thr | 65d ago |
| CVE-2026-17630 | 7.2 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper vali | 65d ago |
| CVE-2026-17506 | 7.2 | — | — | — | — | The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_ | 65d ago |
| CVE-2026-71292 | 7.2 | — | — | — | — | Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whiteli | 65d ago |
| CVE-2026-71284 | 7.2 | — | — | — | — | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes t | 65d ago |
| CVE-2026-71269 | 7.2 | — | — | — | — | Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/ | 65d ago |
| CVE-2026-18933 | 7.2 | — | — | — | — | The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an adm | 65d ago |
| CVE-2026-71232 | 7.2 | — | — | — | — | MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in tem | 65d ago |
| CVE-2026-7693 | 7.2 | — | — | — | — | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and includin | 65d ago |
| CVE-2026-6020 | 7.2 | — | — | — | — | The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-ac | 65d ago |
| CVE-2026-54416 | 7.2 | — | — | — | — | Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed black | 65d ago |
| CVE-2026-16605 | 7.2 | — | — | — | — | The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belon | 65d ago |
| CVE-2026-18902 | 7.2 | — | — | — | — | A vulnerability was detected in H3C NX15 V100R017. | 65d ago |
| CVE-2026-16143 | 7.2 | — | — | — | — | The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scrip | 65d ago |
| CVE-2026-18901 | 7.2 | — | — | — | — | A security vulnerability has been detected in H3C NX15 V100R017. | 65d ago |
| CVE-2026-18900 | 7.2 | — | — | — | — | A weakness has been identified in H3C NX15 V100R017. | 65d ago |
| CVE-2026-18814 | 7.2 | — | — | — | — | A vulnerability was found in H3C NX15 V100R017. | 66d ago |
| CVE-2026-18813 | 7.2 | — | — | — | — | A vulnerability has been found in H3C NX15 V100R017. | 66d ago |
| CVE-2026-18812 | 7.2 | — | — | — | — | A flaw has been found in H3C NX15 V100R017. | 66d ago |
| CVE-2026-18811 | 7.2 | — | — | — | — | A vulnerability was detected in H3C NX15 V100R017. | 66d ago |
| CVE-2026-67243 | 7.2 | — | — | — | — | freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. | 66d ago |
| CVE-2026-14818 | 7.2 | — | — | — | — | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware | 66d ago |
| CVE-2026-6837 | 7.2 | — | — | — | — | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware ver | 66d ago |
| CVE-2026-69246 | 7.2 | — | — | — | — | Guzzle is an extensible PHP HTTP client. | 67d ago |
| CVE-2026-67599 | 7.2 | — | — | — | — | ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated a | 67d ago |
| CVE-2026-61524 | 7.2 | — | — | — | — | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feat | 67d ago |
| CVE-2026-61523 | 7.2 | — | — | — | — | WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authent | 67d ago |
| CVE-2026-39931 | 7.2 | — | — | — | open-emr / openemr | OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import fea | 67d ago |
| CVE-2026-67608 | 7.2 | — | — | — | — | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command i | 67d ago |
| CVE-2026-67340 | 7.2 | — | — | — | — | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.t | 69d ago |
| CVE-2026-67333 | 7.2 | — | — | — | — | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme o | 69d ago |
| CVE-2026-15052 | 7.2 | — | — | — | — | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Sto | 69d ago |
| CVE-2026-15244 | 7.2 | — | — | — | — | The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal befor | 69d ago |
| CVE-2026-13158 | 7.2 | — | — | — | — | The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-conten | 69d ago |
| CVE-2026-13157 | 7.2 | — | — | — | — | The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content im | 69d ago |
| CVE-2026-38710 | 7.2 | — | — | — | — | TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setcl | 70d ago |
| CVE-2026-16843 | 7.2 | — | — | — | — | Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input val | 70d ago |
| CVE-2026-13392 | 7.2 | — | — | — | — | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved | 70d ago |
| CVE-2026-15397 | 7.2 | — | — | — | — | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up t | 71d ago |
| CVE-2026-67244 | 7.2 | — | — | — | asustor / data master | A format string vulnerability was found in the Notification OAuth settings of ADM. | 71d ago |
| CVE-2026-12357 | 7.2 | — | — | — | — | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. | 72d ago |
| CVE-2026-18255 | 7.2 | — | — | — | — | A flaw was found in Quay. | 72d ago |
| CVE-2026-16655 | 7.2 | — | — | — | — | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is | 72d ago |
| CVE-2026-16597 | 7.2 | — | — | — | — | The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Si | 72d ago |
| CVE-2026-13425 | 7.2 | — | — | — | — | The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values | 72d ago |
| CVE-2026-24033 | 7.2 | — | — | — | apache / traffic server | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic S | 72d ago |