| CVE-2026-66605 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 ver | 50d ago |
| CVE-2026-66604 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. | 50d ago |
| CVE-2026-66598 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. | 50d ago |
| CVE-2026-66597 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. | 50d ago |
| CVE-2026-66590 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | 50d ago |
| CVE-2026-66582zero day | 7.1 | 0.25% | 1/3 | 1d before | — | Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | 50d ago |
| CVE-2026-66581 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | 50d ago |
| CVE-2026-76336 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk role | 50d ago |
| CVE-2026-76333 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role c | 50d ago |
| CVE-2026-76332 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an aut | 50d ago |
| CVE-2026-76330 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an aut | 50d ago |
| CVE-2026-76251 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Sp | 50d ago |
| CVE-2026-68553 | 7.1 | — | — | — | — | Coturn is a free open source implementation of TURN and STUN Server. | 50d ago |
| CVE-2026-54491 | 7.1 | — | — | — | — | Koel is a free, open-source music streaming solution. | 50d ago |
| CVE-2026-62680 | 7.1 | — | — | — | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. | 51d ago |
| CVE-2026-17183 | 7.1 | — | — | — | — | An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by m | 51d ago |
| CVE-2026-75147 | 7.1 | — | — | — | — | FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). | 51d ago |
| CVE-2026-49253 | 7.1 | — | — | — | — | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. | 51d ago |
| CVE-2026-76223 | 7.1 | — | — | — | — | ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFI | 51d ago |
| CVE-2026-56088 | 7.1 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used | 51d ago |
| CVE-2026-73354 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. | 51d ago |
| CVE-2026-73184 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. | 51d ago |
| CVE-2026-73182 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. | 51d ago |
| CVE-2026-66596 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. | 51d ago |
| CVE-2026-61986 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. | 51d ago |
| CVE-2026-49421 | 7.1 | — | — | — | freebsd / freebsd | The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed | 51d ago |
| CVE-2026-19056 | 7.1 | — | — | — | — | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflectin | 51d ago |
| CVE-2026-19055 | 7.1 | — | — | — | — | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before re | 51d ago |
| CVE-2026-16570 | 7.1 | — | — | — | — | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-strin | 51d ago |
| CVE-2026-71012 | 7.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 51d ago |
| CVE-2026-71003 | 7.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 51d ago |
| CVE-2026-70971 | 7.1 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation | 51d ago |
| CVE-2026-70967 | 7.1 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation | 51d ago |
| CVE-2026-70936 | 7.1 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 51d ago |
| CVE-2026-70935 | 7.1 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 51d ago |
| CVE-2026-70934 | 7.1 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 51d ago |
| CVE-2026-70933 | 7.1 | — | — | — | oracle / hyperion financial management | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | 51d ago |
| CVE-2026-70902 | 7.1 | — | — | — | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 51d ago |
| CVE-2026-70867 | 7.1 | — | — | — | oracle / application testing suite | Vulnerability in Oracle Application Testing Suite. | 51d ago |
| CVE-2026-70858 | 7.1 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 51d ago |
| CVE-2026-70845 | 7.1 | — | — | — | oracle / loans | Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-70844 | 7.1 | — | — | — | oracle / loans | Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-70839 | 7.1 | — | — | — | oracle / financials for emea | Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations | 51d ago |
| CVE-2026-70837 | 7.1 | — | — | — | oracle / e-business suite | Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Op | 51d ago |
| CVE-2026-70833 | 7.1 | — | — | — | oracle / landed cost management | Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operati | 51d ago |
| CVE-2026-70816 | 7.1 | — | — | — | oracle / financials for emea | Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations | 51d ago |
| CVE-2026-70809 | 7.1 | — | — | — | oracle / scripting | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-70808 | 7.1 | — | — | — | oracle / scripting | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-70806 | 7.1 | — | — | — | oracle / e-business tax | Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-70801 | 7.1 | — | — | — | oracle / flow manufacturing | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations) | 51d ago |
| CVE-2026-70774 | 7.1 | — | — | — | oracle / warehouse management | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operation | 51d ago |
| CVE-2026-70760 | 7.1 | — | — | — | oracle / order management | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Too | 51d ago |
| CVE-2026-70736 | 7.1 | — | — | — | oracle / hyperion profitability and cost management | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Depl | 51d ago |
| CVE-2026-70733 | 7.1 | — | — | — | oracle / hyperion profitability and cost management | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Depl | 51d ago |
| CVE-2026-70705 | 7.1 | — | — | — | oracle / hyperion calculation manager | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). | 51d ago |
| CVE-2026-70680 | 7.1 | — | — | — | oracle / applications dba | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-62627 | 7.1 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 51d ago |
| CVE-2026-62601 | 7.1 | — | — | — | oracle / sales | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). | 51d ago |
| CVE-2026-62587 | 7.1 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). | 51d ago |
| CVE-2026-62537 | 7.1 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation | 51d ago |