| CVE-2026-6177 | 7.2 | — | — | — | — | The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and in | 149d ago |
| CVE-2026-35506 | 7.2 | — | — | — | — | ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_ad | 149d ago |
| CVE-2026-6888 | 7.2 | — | — | — | — | Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute a | 149d ago |
| CVE-2026-43685 | 7.2 | — | — | — | claris / filemaker cloud | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to in | 149d ago |
| CVE-2026-43680 | 7.2 | — | — | — | claris / filemaker cloud | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to by | 149d ago |
| CVE-2026-44871 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol | 149d ago |
| CVE-2026-44403 | 7.2 | — | — | — | wftpserver / wing ftp server | Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serializ | 149d ago |
| CVE-2026-44246 | 7.2 | — | — | — | dkfz / nnu-net | nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. | 149d ago |
| CVE-2026-44872 | 7.2 | — | — | — | arubanetworks / arubaos | A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Syste | 150d ago |
| CVE-2026-44870 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol | 150d ago |
| CVE-2026-44869 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 150d ago |
| CVE-2026-44868 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 150d ago |
| CVE-2026-44867 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 150d ago |
| CVE-2026-44866 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 150d ago |
| CVE-2026-44865 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 150d ago |
| CVE-2026-44864 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 150d ago |
| CVE-2026-44863 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 150d ago |
| CVE-2026-44862 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 150d ago |
| CVE-2026-44861 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 150d ago |
| CVE-2026-44860 | 7.2 | — | — | — | arubanetworks / arubaos | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS- | 150d ago |
| CVE-2026-44859 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 150d ago |
| CVE-2026-44858 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 150d ago |
| CVE-2026-44857 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 150d ago |
| CVE-2026-44856 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 150d ago |
| CVE-2026-44855 | 7.2 | — | — | — | arubanetworks / arubaos | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed thr | 150d ago |
| CVE-2026-44854 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 150d ago |
| CVE-2026-44853 | 7.2 | — | — | — | arubanetworks / arubaos | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating System | 150d ago |
| CVE-2026-44852 | 7.2 | — | — | — | arubanetworks / arubaos | An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface | 150d ago |
| CVE-2026-8431 | 7.2 | — | — | — | — | An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then tri | 150d ago |
| CVE-2026-23823 | 7.2 | — | — | — | arubanetworks / arubaos | A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote | 150d ago |
| CVE-2026-23821 | 7.2 | — | — | — | arubanetworks / arubaos | A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated | 150d ago |
| CVE-2026-23820 | 7.2 | — | — | — | arubanetworks / arubaos | A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an aut | 150d ago |
| CVE-2025-53681 | 7.2 | — | — | — | fortinet / fortimail | An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vu | 150d ago |
| CVE-2026-8051 | 7.2 | — | — | — | ivanti / virtual traffic manager | OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker | 150d ago |
| CVE-2026-6690 | 7.2 | — | — | — | — | The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_upd | 150d ago |
| CVE-2026-43874 | 7.2 | — | — | — | — | WWBN AVideo is an open source video platform. | 150d ago |
| CVE-2026-41951 | 7.2 | — | — | — | — | Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary | 151d ago |
| CVE-2026-33157 | 7.2 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 199d ago |
| CVE-2025-64998 | 7.2 | — | — | — | checkmk / checkmk | Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote s | 199d ago |
| CVE-2026-4627 | 7.2 | — | — | — | — | A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. | 199d ago |
| CVE-2026-4611 | 7.2 | — | — | — | totolink / x6000r firmware | A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. | 199d ago |
| CVE-2026-23882 | 7.2 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 199d ago |
| CVE-2026-33681 | 7.2 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 200d ago |
| CVE-2025-15519 | 7.2 | — | — | — | tp-link / archer nx600 firmware | Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and | 200d ago |
| CVE-2025-15518 | 7.2 | — | — | — | tp-link / archer nx600 firmware | Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and | 200d ago |
| CVE-2026-3478 | 7.2 | — | — | — | — | The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u | 202d ago |
| CVE-2026-3003 | 7.2 | — | — | — | — | The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ p | 202d ago |
| CVE-2026-2440 | 7.2 | — | — | — | — | The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including | 202d ago |
| CVE-2026-2279 | 7.2 | — | — | — | — | The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters i | 202d ago |
| CVE-2026-1648 | 7.2 | — | — | — | — | The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an | 202d ago |
| CVE-2026-4302 | 7.2 | — | — | — | — | The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all version | 202d ago |
| CVE-2026-3368 | 7.2 | — | — | — | — | The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter | 202d ago |
| CVE-2025-55988 | 7.2 | — | — | — | dreamfactory / dreamfactory core | An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute | 202d ago |
| CVE-2026-33133 | 7.2 | — | — | — | wegia / wegia | WeGIA is a web manager for charitable institutions. | 203d ago |
| CVE-2026-29109 | 7.2 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 203d ago |
| CVE-2026-29102 | 7.2 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 203d ago |
| CVE-2026-27043 | 7.2 | — | — | — | — | Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This | 204d ago |
| CVE-2026-1238 | 7.2 | — | — | — | — | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) | 204d ago |
| CVE-2026-3090 | 7.2 | — | — | — | — | The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App p | 205d ago |
| CVE-2026-22317 | 7.2 | — | — | — | — | A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged a | 205d ago |