| CVE-2026-12048 | 9.3 | — | — | — | pgadmin / pgadmin 4 | Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. | 79d ago |
| CVE-2026-48768 | 9.3 | — | — | — | — | TypeBot is a chatbot builder tool. | 80d ago |
| CVE-2026-54812 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThem | 80d ago |
| CVE-2026-54819 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. | 80d ago |
| CVE-2026-54815 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Car | 80d ago |
| CVE-2026-54809 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme G | 80d ago |
| CVE-2026-54808 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP | 80d ago |
| CVE-2025-59554 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | 80d ago |
| CVE-2026-54811 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. | 80d ago |
| CVE-2026-54187 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. | 80d ago |
| CVE-2026-54186 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. | 80d ago |
| CVE-2026-49084 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. | 80d ago |
| CVE-2026-49080 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. | 80d ago |
| CVE-2026-49079 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. | 80d ago |
| CVE-2026-49076 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. | 80d ago |
| CVE-2026-48875 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. | 80d ago |
| CVE-2026-48745 | 9.3 | — | — | — | — | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source | 80d ago |
| CVE-2026-48616 | 9.3 | — | — | — | rocket.chat / rocket.chat | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerabilit | 80d ago |
| CVE-2026-39596 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. | 80d ago |
| CVE-2026-39438 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. | 80d ago |
| CVE-2026-22340 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. | 80d ago |
| CVE-2026-22332 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. | 80d ago |
| CVE-2026-46913 | 9.3 | — | — | — | oracle / jd edwards enterpriseone tools | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security | 81d ago |
| CVE-2026-46912 | 9.3 | — | — | — | oracle / jd edwards enterpriseone tools | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security) | 81d ago |
| CVE-2026-46805 | 9.3 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 81d ago |
| CVE-2026-46795 | 9.3 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 81d ago |
| CVE-2026-46785 | 9.3 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 81d ago |
| CVE-2026-35306 | 9.3 | — | — | — | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars | 81d ago |
| CVE-2026-35305 | 9.3 | — | — | — | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars | 81d ago |
| CVE-2026-52715 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. | 82d ago |
| CVE-2026-49772 | 9.3 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / | 82d ago |
| CVE-2026-39574 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. | 82d ago |
| CVE-2026-52693 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. | 82d ago |
| CVE-2026-49776 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate | 82d ago |
| CVE-2026-49067 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions. | 82d ago |
| CVE-2026-48886 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. | 82d ago |
| CVE-2026-45439 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions. | 82d ago |
| CVE-2026-42665 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. | 82d ago |
| CVE-2026-42639 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. | 82d ago |
| CVE-2026-42386 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. | 82d ago |
| CVE-2026-42381 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions. | 82d ago |
| CVE-2026-40798 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions. | 82d ago |
| CVE-2026-40771 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions. | 82d ago |
| CVE-2026-39530 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions. | 82d ago |
| CVE-2026-39519 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions. | 82d ago |
| CVE-2026-39512 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions. | 82d ago |
| CVE-2026-39511 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions. | 82d ago |
| CVE-2026-39502 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions. | 82d ago |
| CVE-2026-39493 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions. | 82d ago |
| CVE-2026-39492 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions. | 82d ago |
| CVE-2026-39441 | 9.3 | — | — | — | — | Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions. | 82d ago |
| CVE-2026-44990 | 9.3 | — | — | — | — | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML saniti | 85d ago |
| CVE-2026-50090 | 9.3 | — | — | — | aqara / cloud oauth authorization endpoint | The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypas | 85d ago |
| CVE-2026-42647zero day | 9.3 | 1.3% | 1/3 | 43d before | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev Joom | 86d ago |
| CVE-2026-39494zero day | 9.3 | 0.39% | 1/3 | same day | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins | 86d ago |
| CVE-2026-53475 | 9.3 | — | — | — | kubev2v / assisted migration agent | A flaw was found in assisted-migration-agent. | 87d ago |
| CVE-2026-45328 | 9.3 | — | — | — | espressif / esp-idf | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. | 88d ago |
| CVE-2026-34691 | 9.3 | — | — | — | adobe / experience manager | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scri | 88d ago |
| CVE-2026-46316 | 9.3 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cac | 88d ago |
| CVE-2026-50751zero day | 9.3 | 83.8% | 3/3 | same day | checkpoint / gaia os | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange a | 89d ago |