| CVE-2026-23698 | 7.2 | — | — | — | — | Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import | 94d ago |
| CVE-2026-53479 | 7.2 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 94d ago |
| CVE-2026-58298 | 7.2 | — | — | — | microsoft / edge chromium | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-b | 98d ago |
| CVE-2026-53478 | 7.2 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 98d ago |
| CVE-2026-49815 | 7.2 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 98d ago |
| CVE-2026-49814 | 7.2 | — | — | — | dell / data domain operating system | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS | 98d ago |
| CVE-2026-9148 | 7.2 | — | — | — | — | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter ' | 98d ago |
| CVE-2026-13040 | 7.2 | — | — | — | — | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Script | 98d ago |
| CVE-2026-13722 | 7.2 | — | — | — | watchguard / fireware | WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore | 98d ago |
| CVE-2026-13384 | 7.2 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privil | 98d ago |
| CVE-2026-13383 | 7.2 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privi | 98d ago |
| CVE-2026-13054 | 7.2 | — | — | — | watchguard / fireware | A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated a | 98d ago |
| CVE-2026-13053 | 7.2 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user | 98d ago |
| CVE-2026-13050 | 7.2 | — | — | — | watchguard / fireware | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privi | 98d ago |
| CVE-2026-57348 | 7.2 | — | — | — | — | Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. | 99d ago |
| CVE-2026-9834 | 7.2 | — | — | — | — | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to O | 99d ago |
| CVE-2026-58263 | 7.2 | — | — | — | — | Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. | 100d ago |
| CVE-2026-12142 | 7.2 | — | — | — | — | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Script | 100d ago |
| CVE-2026-50043 | 7.2 | — | — | — | — | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBrid | 100d ago |
| CVE-2026-11883 | 7.2 | — | — | — | — | The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor a | 100d ago |
| CVE-2026-7829 | 7.2 | — | — | — | uvnc / ultravnc | UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. | 100d ago |
| CVE-2026-7517 | 7.2 | — | — | — | — | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t | 100d ago |
| CVE-2026-13731zero day | 7.2 | 0.89% | 1/3 | same day | — | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored | 100d ago |
| CVE-2026-11806 | 7.2 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnera | 101d ago |
| CVE-2026-10513 | 7.2 | — | — | — | — | The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5 | 101d ago |
| CVE-2026-8141 | 7.2 | — | — | — | — | The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_in | 101d ago |
| CVE-2026-56808 | 7.2 | — | — | — | — | DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead | 101d ago |
| CVE-2026-56414 | 7.2 | — | — | — | — | A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to sto | 104d ago |
| CVE-2026-55975 | 7.2 | — | — | — | — | A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML field | 104d ago |
| CVE-2026-13372 | 7.2 | — | — | — | devolutions / remote desktop manager | Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manage | 105d ago |
| CVE-2026-9640 | 7.2 | — | — | — | canonical / lxd | A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0. | 105d ago |
| CVE-2026-40083 | 7.2 | — | — | — | cacti / cacti | Cacti is an open source performance and fault management framework. | 105d ago |
| CVE-2026-9717 | 7.2 | — | — | — | schneider-electric / powerlogic p7 firmware | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that | 106d ago |
| CVE-2026-55477 | 7.2 | — | — | — | — | 3X-UI is a web control panel for managing Xray-core servers. | 106d ago |
| CVE-2026-49506 | 7.2 | — | — | — | dell / wyse management suite | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restr | 106d ago |
| CVE-2026-9779 | 7.2 | — | — | — | aten / unizon | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerabi | 106d ago |
| CVE-2026-9778 | 7.2 | — | — | — | aten / unizon | ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. | 106d ago |
| CVE-2026-9777 | 7.2 | — | — | — | aten / unizon | ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. | 106d ago |
| CVE-2026-50189 | 7.2 | — | — | — | appsmith / appsmith | Appsmith is a platform to build admin panels, internal tools, and dashboards. | 106d ago |
| CVE-2026-9643 | 7.2 | — | — | — | — | The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_U | 107d ago |
| CVE-2026-12100 | 7.2 | — | — | — | — | The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu | 107d ago |
| CVE-2026-12095 | 7.2 | — | — | — | — | The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu | 107d ago |
| CVE-2026-10749 | 7.2 | — | — | — | — | The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication | 107d ago |
| CVE-2026-10092 | 7.2 | — | — | — | — | The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa | 107d ago |
| CVE-2026-10091 | 7.2 | — | — | — | — | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ema | 107d ago |
| CVE-2026-3652 | 7.2 | — | — | — | — | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf | 107d ago |
| CVE-2026-54308 | 7.2 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 108d ago |
| CVE-2026-56222 | 7.2 | — | — | — | — | Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to | 108d ago |
| CVE-2026-10521 | 7.2 | — | — | — | — | An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any | 108d ago |
| CVE-2026-56447 | 7.2 | — | — | — | misp-project / misp | MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesyste | 109d ago |
| CVE-2026-56446 | 7.2 | — | — | — | misp-project / misp | MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonL | 109d ago |
| CVE-2026-44914 | 7.2 | — | — | — | apache / nifi | Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension co | 109d ago |
| CVE-2026-44913 | 7.2 | — | — | — | apache / nifi | Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 thro | 109d ago |
| CVE-2026-56382 | 7.2 | — | — | — | — | Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerab | 110d ago |
| CVE-2026-48895 | 7.2 | — | — | — | apache / apisix | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. | 112d ago |
| CVE-2025-52465 | 7.2 | — | — | — | osgeo / geoserver | GeoServer is an open source server that allows users to share and edit geospatial data. | 113d ago |
| CVE-2025-27511 | 7.2 | — | — | — | osgeo / geoserver | GeoServer is an open source server that allows users to share and edit geospatial data. | 113d ago |
| CVE-2026-11395 | 7.2 | — | — | — | — | The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in | 113d ago |
| CVE-2026-53676 | 7.2 | — | — | — | — | ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandb | 113d ago |
| CVE-2026-11407 | 7.2 | — | — | — | — | Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative at | 114d ago |