| CVE-2026-10871 | 7.2 | — | — | — | — | A vulnerability has been found in Shibby Tomato 1.28.0000. | 126d ago |
| CVE-2026-10870 | 7.2 | — | — | — | — | A flaw has been found in Shibby Tomato 1.28.0000. | 126d ago |
| CVE-2026-10843 | 7.2 | — | — | — | — | A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. | 127d ago |
| CVE-2026-3820 | 7.2 | — | — | — | — | There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. | 127d ago |
| CVE-2026-24092 | 7.2 | — | — | — | qualcomm / ar8031 firmware | Memory Corruption when processing fastboot commands to set display mode. | 129d ago |
| CVE-2026-24091 | 7.2 | — | — | — | qualcomm / c-v2x 9150 firmware | Memory corruption while processing fastboot commands with improperly formatted input. | 129d ago |
| CVE-2026-24089 | 7.2 | — | — | — | qualcomm / ar8031 firmware | Memory corruption while processing fastboot commands with invalid input. | 129d ago |
| CVE-2026-24087 | 7.2 | — | — | — | qualcomm / ar8031 firmware | Memory corruption while processing fastboot OEM commands. | 129d ago |
| CVE-2026-24085 | 7.2 | — | — | — | qualcomm / qca6391 firmware | Memory Corruption when processing display command line information due to improper initialization of a variable. | 129d ago |
| CVE-2026-40961 | 7.2 | — | — | — | apache / airflow | A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `i | 130d ago |
| CVE-2026-39276 | 7.2 | — | — | — | emlog / emlog | The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated adminis | 133d ago |
| CVE-2026-45609 | 7.2 | — | — | — | springaicommunity / mcp security | mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. | 133d ago |
| CVE-2026-10072 | 7.2 | — | — | — | — | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers | 133d ago |
| CVE-2025-41279 | 7.2 | — | — | — | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS C | 133d ago |
| CVE-2025-41267 | 7.2 | — | — | — | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS C | 133d ago |
| CVE-2025-41266 | 7.2 | — | — | — | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS C | 133d ago |
| CVE-2025-41265 | 7.2 | — | — | — | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS C | 133d ago |
| CVE-2026-49196 | 7.2 | — | — | — | acer / predator connect w6x firmware | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitra | 133d ago |
| CVE-2025-11262zero day | 7.2 | 0.24% | 1/3 | same day | — | The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter | 133d ago |
| CVE-2026-7634 | 7.2 | — | — | — | — | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' heade | 134d ago |
| CVE-2026-7052 | 7.2 | — | — | — | — | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit | 134d ago |
| CVE-2026-2374 | 7.2 | — | — | — | — | The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER[ | 134d ago |
| CVE-2026-5509 | 7.2 | — | — | — | tp-link / archer be450 firmware | An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an | 135d ago |
| CVE-2024-56462 | 7.2 | — | — | — | ibm / qradar security information and event manager | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup arc | 135d ago |
| CVE-2026-40852 | 7.2 | — | — | — | — | A highly authenticated attacker can alter the config generator injecting a payload into future created configurati | 135d ago |
| CVE-2026-8143 | 7.2 | — | — | — | — | The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state | 135d ago |
| CVE-2026-6169 | 7.2 | — | — | — | — | The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and includ | 135d ago |
| CVE-2026-3375 | 7.2 | — | — | — | — | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1 | 135d ago |
| CVE-2026-4051 | 7.2 | — | — | — | ibm / engineering lifecycle management | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges | 136d ago |
| CVE-2026-44730 | 7.2 | — | — | — | citeum / opencti | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. | 136d ago |
| CVE-2026-42785 | 7.2 | — | — | — | — | OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute a | 136d ago |
| CVE-2026-42425 | 7.2 | — | — | — | — | OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users | 136d ago |
| CVE-2026-24937 | 7.2 | — | — | — | — | Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video a | 136d ago |
| CVE-2026-48848 | 7.2 | — | — | — | — | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to C | 137d ago |
| CVE-2026-48843 | 7.2 | — | — | — | — | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets ( | 137d ago |
| CVE-2026-42782 | 7.2 | — | — | — | apache / syncope | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | 137d ago |
| CVE-2026-8135 | 7.2 | — | — | — | concretecms / concrete cms | Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in th | 140d ago |
| CVE-2026-8134 | 7.2 | — | — | — | concretecms / concrete cms | Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustom | 140d ago |
| CVE-2026-44058 | 7.2 | — | — | — | — | An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenti | 141d ago |
| CVE-2026-7613 | 7.2 | — | — | — | — | The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvda | 142d ago |
| CVE-2026-22315 | 7.2 | — | — | — | — | Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Comp | 142d ago |
| CVE-2026-27891 | 7.2 | — | — | — | — | FacturaScripts is an open source accounting and invoicing software. | 143d ago |
| CVE-2026-8764 | 7.2 | — | — | — | — | A security vulnerability has been detected in H3C Magic B3 up to 100R002. | 144d ago |
| CVE-2021-47975 | 7.2 | — | — | — | — | WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers | 146d ago |
| CVE-2026-45395 | 7.2 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 146d ago |
| CVE-2021-47963 | 7.2 | — | — | — | — | Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code | 147d ago |
| CVE-2026-8597 | 7.2 | — | — | — | — | Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 an | 148d ago |
| CVE-2026-8596 | 7.2 | — | — | — | — | Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK befor | 148d ago |
| CVE-2026-22599 | 7.2 | — | — | — | strapi / strapi | Strapi is an open source headless content management system. | 148d ago |
| CVE-2026-41937 | 7.2 | — | — | — | — | Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows | 148d ago |
| CVE-2026-6476 | 7.2 | — | — | — | postgresql / postgresql | SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute ar | 148d ago |
| CVE-2026-3718 | 7.2 | — | — | — | — | The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP r | 148d ago |
| CVE-2026-45708 | 7.2 | — | — | — | — | CubeCart is an ecommerce software solution. | 148d ago |
| CVE-2026-44380 | 7.2 | — | — | — | misp-project / misp | MISP is an open source threat intelligence and sharing platform. | 148d ago |
| CVE-2026-39358 | 7.2 | — | — | — | — | CubeCart is an ecommerce software solution. | 148d ago |
| CVE-2026-0261 | 7.2 | — | — | — | paloaltonetworks / pan-os | Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administr | 149d ago |
| CVE-2026-0241 | 7.2 | — | — | — | paloaltonetworks / trust protection foundation | Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls an | 149d ago |
| CVE-2026-39459 | 7.2 | — | — | — | f5 / big-ip access policy manager | A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacke | 149d ago |
| CVE-2026-36741 | 7.2 | — | — | — | u-speed / t18-21k firmware | U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. | 149d ago |
| CVE-2020-37222 | 7.2 | — | — | — | — | Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers t | 149d ago |