| CVE-2026-53876 | 7.2 | — | — | — | — | RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbit | 114d ago |
| CVE-2026-11410 | 7.2 | — | — | — | tp-link / tl-wr940n firmware | An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in | 114d ago |
| CVE-2026-11409 | 7.2 | — | — | — | tp-link / tl-wr940n firmware | An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 | 114d ago |
| CVE-2026-46976 | 7.2 | — | — | — | oracle / public sector payroll | Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operatio | 114d ago |
| CVE-2026-46970 | 7.2 | — | — | — | oracle / hr intelligence | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). | 114d ago |
| CVE-2026-46969 | 7.2 | — | — | — | oracle / financials for emea | Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations | 114d ago |
| CVE-2026-46960 | 7.2 | — | — | — | oracle / project portfolio analysis | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Ope | 114d ago |
| CVE-2026-46956 | 7.2 | — | — | — | oracle / property manager | Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). | 114d ago |
| CVE-2026-46953 | 7.2 | — | — | — | oracle / human resources management system | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). | 114d ago |
| CVE-2026-46938 | 7.2 | — | — | — | oracle / cost management | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). | 114d ago |
| CVE-2026-46922 | 7.2 | — | — | — | oracle / hr intelligence | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). | 114d ago |
| CVE-2026-46868 | 7.2 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Exte | 114d ago |
| CVE-2026-46867 | 7.2 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Exte | 114d ago |
| CVE-2026-46769 | 7.2 | — | — | — | oracle / application development framework | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component | 114d ago |
| CVE-2026-35326 | 7.2 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 114d ago |
| CVE-2026-42650 | 7.2 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions. | 116d ago |
| CVE-2026-39499 | 7.2 | — | — | — | — | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | 116d ago |
| CVE-2026-39498 | 7.2 | — | — | — | — | Shop manager PHP Object Injection in YayMail <= 4.3.3 versions. | 116d ago |
| CVE-2026-39481 | 7.2 | — | — | — | — | Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions. | 116d ago |
| CVE-2026-39472 | 7.2 | — | — | — | — | Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | 116d ago |
| CVE-2026-39471 | 7.2 | — | — | — | — | Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions. | 116d ago |
| CVE-2026-39470 | 7.2 | — | — | — | — | Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions. | 116d ago |
| CVE-2026-39434 | 7.2 | — | — | — | — | Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions. | 116d ago |
| CVE-2026-27407 | 7.2 | — | — | — | — | Editor Privilege Escalation in AI Engine <= 3.4.9 versions. | 116d ago |
| CVE-2026-49954 | 7.2 | — | — | — | — | Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authentic | 116d ago |
| CVE-2016-20084 | 7.2 | — | — | — | — | WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow un | 116d ago |
| CVE-2016-20066 | 7.2 | — | — | — | — | WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject | 116d ago |
| CVE-2026-12197 | 7.2 | — | — | — | — | A security flaw has been discovered in Ruijie EG105G-P 2.340. | 116d ago |
| CVE-2026-5513 | 7.2 | — | — | — | — | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Si | 118d ago |
| CVE-2026-9109 | 7.2 | — | — | — | — | The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress | 118d ago |
| CVE-2026-42306 | 7.2 | — | — | — | docker / engine | Moby is an open source container framework. | 119d ago |
| CVE-2026-11845 | 7.2 | — | — | — | — | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerabili | 119d ago |
| CVE-2026-47366 | 7.2 | — | — | — | — | Improper verification of access permissions when modifying permissions through the Administration Control Panel (A | 119d ago |
| CVE-2026-53816 | 7.2 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that | 120d ago |
| CVE-2026-0273 | 7.2 | — | — | — | paloaltonetworks / pan-os | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to | 120d ago |
| CVE-2026-0272 | 7.2 | — | — | — | paloaltonetworks / pan-os | A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator w | 120d ago |
| CVE-2026-25700 | 7.2 | — | — | — | apache / answer | Improper Restriction of Security Token Assignment vulnerability in Apache Answer. | 121d ago |
| CVE-2026-24719 | 7.2 | — | — | — | qnap / qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 121d ago |
| CVE-2026-24716 | 7.2 | — | — | — | qnap / qts | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. | 121d ago |
| CVE-2026-22893 | 7.2 | — | — | — | qnap / qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 121d ago |
| CVE-2025-66281 | 7.2 | — | — | — | qnap / qts | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. | 121d ago |
| CVE-2025-66280 | 7.2 | — | — | — | qnap / qts | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions | 121d ago |
| CVE-2025-66279 | 7.2 | — | — | — | qnap / qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 121d ago |
| CVE-2025-66273 | 7.2 | — | — | — | qnap / qts | A command injection vulnerability has been reported to affect several QNAP operating system versions. | 121d ago |
| CVE-2025-62850 | 7.2 | — | — | — | qnap / quts hero | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. | 121d ago |
| CVE-2026-46492 | 7.2 | — | — | — | commenthol / md-fileserver | md-fileserver allows for local viewing of markdown files in a browser. | 122d ago |
| CVE-2026-10727 | 7.2 | — | — | — | — | An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remo | 122d ago |
| CVE-2026-7556 | 7.2 | — | — | — | — | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment te | 122d ago |
| CVE-2026-43972 | 7.2 | — | — | — | ninenines / gun | Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via | 123d ago |
| CVE-2023-54351 | 7.2 | — | — | — | — | WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated | 123d ago |
| CVE-2026-9851 | 7.2 | — | — | — | — | The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up | 125d ago |
| CVE-2026-7537 | 7.2 | — | — | — | — | The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and in | 125d ago |
| CVE-2026-8901 | 7.2 | — | — | — | — | The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is | 125d ago |
| CVE-2026-8438 | 7.2 | — | — | — | — | The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scri | 125d ago |
| CVE-2026-50232 | 7.2 | — | — | — | — | Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject mal | 126d ago |
| CVE-2026-50231 | 7.2 | — | — | — | — | Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer | 126d ago |
| CVE-2026-41567 | 7.2 | — | — | — | — | Moby is an open source container framework. | 126d ago |
| CVE-2026-10586 | 7.2 | — | — | — | — | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable t | 126d ago |
| CVE-2026-10873 | 7.2 | — | — | — | — | A vulnerability was determined in Shibby Tomato 1.28.0000. | 126d ago |
| CVE-2026-10872 | 7.2 | — | — | — | — | A vulnerability was found in Shibby Tomato 1.28.0000. | 126d ago |