| CVE-2026-60335 | 7.2 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 80d ago |
| CVE-2026-60316 | 7.2 | — | — | — | oracle / mysql server | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). | 80d ago |
| CVE-2026-60245 | 7.2 | — | — | — | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 80d ago |
| CVE-2026-60153 | 7.2 | — | — | — | oracle / weblogic server | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). | 80d ago |
| CVE-2026-47006 | 7.2 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self | 80d ago |
| CVE-2026-47005 | 7.2 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self | 80d ago |
| CVE-2026-46988 | 7.2 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Conn | 80d ago |
| CVE-2026-46981 | 7.2 | — | — | — | oracle / utilities network management system | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (componen | 80d ago |
| CVE-2026-46954 | 7.2 | — | — | — | oracle / human resources | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). | 80d ago |
| CVE-2026-44879 | 7.2 | — | — | — | — | A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remot | 80d ago |
| CVE-2026-44878 | 7.2 | — | — | — | — | A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authentic | 80d ago |
| CVE-2026-63454 | 7.2 | — | — | — | hpe / arubaos-cx | An authenticated path traversal vulnerability exists in AOS-CX. | 80d ago |
| CVE-2026-63453 | 7.2 | — | — | — | hpe / arubaos-cx | Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. | 80d ago |
| CVE-2026-1771 | 7.2 | — | — | — | — | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the | 80d ago |
| CVE-2026-6952 | 7.2 | — | — | — | — | A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7 | 80d ago |
| CVE-2026-14448 | 7.2 | — | — | — | — | An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_c | 81d ago |
| CVE-2026-51082 | 7.2 | — | — | — | — | A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-mana | 84d ago |
| CVE-2026-15395 | 7.2 | — | — | — | — | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scri | 84d ago |
| CVE-2026-44982 | 7.2 | — | — | — | — | CrowdSec offers crowdsourced protection against malicious IPs. | 85d ago |
| CVE-2026-7543 | 7.2 | — | — | — | — | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in vers | 85d ago |
| CVE-2026-13042 | 7.2 | — | — | — | — | The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all ve | 85d ago |
| CVE-2026-62350 | 7.2 | — | — | — | — | TDengine is an open source, time-series database optimized for Internet of Things devices. | 86d ago |
| CVE-2026-20297 | 7.2 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions | 86d ago |
| CVE-2026-47992 | 7.2 | — | — | — | adobe / commerce | Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injectio | 87d ago |
| CVE-2026-15410zero day | 7.2 | 11.8% | 3/3 | same day | sonicwall / sma6210 firmware | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in | 87d ago |
| CVE-2026-54433 | 7.2 | — | — | — | roundcube / webmail | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafte | 87d ago |
| CVE-2026-62643 | 7.2 | — | — | — | roundcube / webmail | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization | 87d ago |
| CVE-2026-59521 | 7.2 | — | — | — | — | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Obje | 88d ago |
| CVE-2026-57407 | 7.2 | — | — | — | — | Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp all | 88d ago |
| CVE-2026-57372 | 7.2 | — | — | — | — | Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Fo | 88d ago |
| CVE-2026-6939 | 7.2 | — | — | — | — | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the | 90d ago |
| CVE-2026-13378 | 7.2 | — | — | — | — | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via | 90d ago |
| CVE-2026-3576 | 7.2 | — | — | — | — | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to L | 90d ago |
| CVE-2026-13114 | 7.2 | — | — | — | — | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site S | 90d ago |
| CVE-2026-53448 | 7.2 | — | — | — | coturn project / coturn | Coturn is a free open source implementation of TURN and STUN Server. | 91d ago |
| CVE-2026-1667 | 7.2 | — | — | — | — | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site | 91d ago |
| CVE-2026-60091 | 7.2 | — | — | — | — | PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api | 91d ago |
| CVE-2026-22660 | 7.2 | — | — | — | — | FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated admi | 91d ago |
| CVE-2026-15298 | 7.2 | — | — | — | — | The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and incl | 91d ago |
| CVE-2026-13430 | 7.2 | — | — | — | — | The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up t | 91d ago |
| CVE-2026-0286 | 7.2 | — | — | — | paloaltonetworks / pan-os | A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authent | 92d ago |
| CVE-2026-0283 | 7.2 | — | — | — | paloaltonetworks / pan-os | An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS softw | 92d ago |
| CVE-2026-0280 | 7.2 | — | — | — | paloaltonetworks / pan-os | An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthen | 92d ago |
| CVE-2026-61343 | 7.2 | — | — | — | — | LibreBooking's email template editor save action passes the submitted template name directly into the destination | 92d ago |
| CVE-2026-59721 | 7.2 | — | — | — | — | Hoppscotch is an open source API development ecosystem. | 92d ago |
| CVE-2026-54801 | 7.2 | — | — | — | — | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Bas | 92d ago |
| CVE-2026-9253 | 7.2 | — | — | — | — | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site | 92d ago |
| CVE-2026-13441 | 7.2 | — | — | — | — | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scr | 92d ago |
| CVE-2026-8848 | 7.2 | — | — | — | — | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordP | 92d ago |
| CVE-2026-15000 | 7.2 | — | — | — | — | The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mai | 92d ago |
| CVE-2026-44161 | 7.2 | — | — | — | fluentd / fluentd | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and s | 93d ago |
| CVE-2026-59821exploited | 7.2 | 0.90% | 1/3 | +18d | litellm / litellm | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. | 93d ago |
| CVE-2026-24700 | 7.2 | — | — | — | cisco / rv130 firmware | An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W | 93d ago |
| CVE-2026-24699 | 7.2 | — | — | — | cisco / rv130 firmware | An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W | 93d ago |
| CVE-2026-24698 | 7.2 | — | — | — | cisco / rv130 firmware | An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco | 93d ago |
| CVE-2026-24697 | 7.2 | — | — | — | cisco / rv130 firmware | An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV1 | 93d ago |
| CVE-2026-10698 | 7.2 | — | — | — | progress / moveit transfer | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom | 93d ago |
| CVE-2026-6820 | 7.2 | — | — | — | — | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the | 93d ago |
| CVE-2026-6818 | 7.2 | — | — | — | — | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the | 93d ago |
| CVE-2026-55077 | 7.2 | — | — | — | coder / coder | Coder allows organizations to provision remote development environments via Terraform. | 93d ago |