| CVE-2026-66707 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. | 64d ago |
| CVE-2026-66705 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions. | 64d ago |
| CVE-2026-66702 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. | 64d ago |
| CVE-2026-66694 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. | 64d ago |
| CVE-2026-66690 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | 64d ago |
| CVE-2026-66664 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. | 64d ago |
| CVE-2026-66663 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | 64d ago |
| CVE-2026-66470 | 7.1 | — | — | — | — | Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. | 64d ago |
| CVE-2026-66457exploited | 7.1 | 0.25% | 1/3 | +47d | — | Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | 64d ago |
| CVE-2026-66440 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | 64d ago |
| CVE-2026-66439 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | 64d ago |
| CVE-2026-65565 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | 64d ago |
| CVE-2026-65560 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | 64d ago |
| CVE-2026-65554 | 7.1 | — | — | — | — | Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. | 64d ago |
| CVE-2026-65545 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | 64d ago |
| CVE-2026-65544 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | 64d ago |
| CVE-2026-65517 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | 64d ago |
| CVE-2026-65515 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | 64d ago |
| CVE-2026-65513 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | 64d ago |
| CVE-2026-65509 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | 64d ago |
| CVE-2026-61982 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | 64d ago |
| CVE-2026-61964 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | 64d ago |
| CVE-2026-61963 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | 64d ago |
| CVE-2026-61961 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | 64d ago |
| CVE-2026-28177 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | 64d ago |
| CVE-2026-28172 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. | 64d ago |
| CVE-2026-28143 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | 64d ago |
| CVE-2026-28141 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. | 64d ago |
| CVE-2026-28082 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. | 64d ago |
| CVE-2026-9130 | 7.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that all | 64d ago |
| CVE-2026-9081 | 7.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulne | 64d ago |
| CVE-2026-70448 | 7.1 | — | — | — | — | Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) a | 64d ago |
| CVE-2026-71276 | 7.1 | — | — | — | — | Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/tr | 65d ago |
| CVE-2026-71211 | 7.1 | — | — | — | — | MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.p | 65d ago |
| CVE-2026-64576 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_mi | 65d ago |
| CVE-2026-70485 | 7.1 | — | — | — | — | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. | 65d ago |
| CVE-2026-11368 | 7.1 | — | — | — | zephyrproject / zephyr | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning | 66d ago |
| CVE-2026-18806 | 7.1 | — | — | — | — | External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute par | 66d ago |
| CVE-2026-66322 | 7.1 | — | — | — | microsoft / edge chromium | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove | 66d ago |
| CVE-2026-65875 | 7.1 | — | — | — | — | BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. | 67d ago |
| CVE-2026-9856 | 7.1 | — | — | — | — | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writ | 68d ago |
| CVE-2025-71400 | 7.1 | — | — | — | — | better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey | 68d ago |
| CVE-2026-67329 | 7.1 | — | — | — | — | @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authoriza | 69d ago |
| CVE-2025-71403 | 7.1 | — | — | — | — | better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting abs | 69d ago |
| CVE-2026-13725 | 7.1 | — | — | — | — | The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or | 69d ago |
| CVE-2026-65981 | 7.1 | — | — | — | — | Coturn is a free open source implementation of TURN and STUN Server. | 69d ago |
| CVE-2026-55502 | 7.1 | — | — | — | — | Cloudreve is a self-hosted file management and sharing system. | 70d ago |
| CVE-2026-12945 | 7.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs | 70d ago |
| CVE-2026-44097 | 7.1 | — | — | — | — | A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended | 71d ago |
| CVE-2026-14239 | 7.1 | — | — | — | — | The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label tak | 71d ago |
| CVE-2026-17888 | 7.1 | — | — | — | google / chrome | Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attac | 71d ago |
| CVE-2026-17867 | 7.1 | — | — | — | google / chrome | Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attack | 71d ago |
| CVE-2026-17811 | 7.1 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentiall | 71d ago |
| CVE-2026-17750 | 7.1 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a | 71d ago |
| CVE-2026-17744 | 7.1 | — | — | — | google / chrome | Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attac | 71d ago |
| CVE-2026-17741 | 7.1 | — | — | — | google / chrome | Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a | 71d ago |
| CVE-2026-14234 | 7.1 | — | — | — | — | The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, al | 72d ago |
| CVE-2026-14976 | 7.1 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the | 72d ago |
| CVE-2026-13442 | 7.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owne | 72d ago |
| CVE-2026-16192 | 7.1 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerabil | 72d ago |