| CVE-2026-54568 | 4.3 | 59.5 | microsoft | UFO | CWE-639 | Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE C… |
| CVE-2026-46562 | 9.8 | 59.4 | yamcs | yamcs | CWE-94 | Yamcs: Remote Code Execution via Mission Database algorithm override |
| CVE-2026-53597 | 8.7 | 59.3 | microsoft | prompty | CWE-94 | Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript lo… |
| CVE-2023-49900 | 9.8 | 59.0 | X-Rite | MA-T6 | CWE-78 | Origin Validation Error in X-Rite MA-T6 |
| CVE-2026-57206 | 8.6 | 58.7 | microsoft | simplechat | CWE-306 | SimpleChat plugin validation endpoints missing authentication and authorization |
| CVE-2026-57205 | 4.3 | 57.3 | microsoft | simplechat | CWE-200 | SimpleChat: Authenticated users can access other users' profile metadata thro… |
| CVE-2026-23538 | 7.5 | 56.8 | Feast | Feast Feature Server | CWE-770 | Feast: resource exhaustion via websocket endpoint |
| CVE-2026-15422 | 9.1 | 56.4 | illumos | illumos-gate | CWE-122 | SCTP needs to better-check INIT ACK chunk parameters |
| CVE-2026-54733 | 9.3 | 56.2 | microsoft | o365-moodle | CWE-347 | moodle-local_o365: Authentication bypass via unverified JWT signature in Team… |
| CVE-2024-32386 | 7.3 | 55.4 | n/a | n/a | CWE-22 | Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerO… |
| CVE-2026-53535 | 5.9 | 55.1 | activepieces | activepieces | CWE-22 | Activepieces: Arbitrary file write in git-sync via path traversal and symlinks |
| CVE-2026-48863 | 7.5 | 54.5 | OpenSUSE | libsolv | CWE-121 | Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verificat… |
| CVE-2026-15013 | 9.8 | 53.4 | cyberlord92 | SAML Single Sign On – SSO Login | CWE-347 | SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAM… |
| CVE-2026-47751 | 5.3 | 52.7 | anthropics | claude-code-action | CWE-78 | Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote … |
| CVE-2026-44177 | 8.8 | 50.5 | getkirby | kirby | CWE-22 | Kirby: Pre-authentication path traversal and PHP file inclusion during user l… |
| CVE-2026-44181 | 10.0 | 50.4 | jupyter-server | enterprise_gateway | CWE-1336 | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection re… |
| CVE-2026-3031 | 9.8 | 50.4 | TOKUHIROM | Image::EPEG | CWE-1104 | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of t… |
| CVE-2026-45367 | 7.5 | 49.8 | hapifhir | org.hl7.fhir.core | CWE-1333 | HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HT… |
| CVE-2026-55629 | 8.7 | 49.2 | avwo | whistle | CWE-22 | Whistle: Path traversal |
| CVE-2025-71377 | 8.7 | 49.0 | stoatchat | stoatchat | CWE-1025 | stoatchat before 20250210-1 Unrestricted Message History Fetch |
| CVE-2026-62309 | 7.5 | 48.9 | coredns | coredns | CWE-476 | CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — s… |
| CVE-2026-57073 | 9.1 | 48.5 | CODECHILD | HTML::Bare | CWE-125 | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead |
| CVE-2026-46512 | 9.9 | 48.4 | mwtcmi | frogman | CWE-94 | Frogman: Dialplan template parameters interpolated into extensions_custom.con… |
| CVE-2026-53412 | 9.8 | 48.2 | Zoom Communications | Zoom Workplace for Windows | CWE-20 | Zoom Workplace VDI Plugin for Windows - Improper Input Validation |
| CVE-2026-59237 | 6.9 | 47.9 | Roskus | Prospero Flow CRM | CWE-639 | IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification… |
| CVE-2026-57074 | 9.1 | 47.6 | CODECHILD | XML::Bare | CWE-125 | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead |
| CVE-2026-45336 | 10.0 | 47.1 | StratonWebDesigners | HireFlow | CWE-798 | HireFlow: Use of Hard-coded Credentials |
| CVE-2026-63087 | 9.3 | 46.5 | grafana-cold-storage | oncall | CWE-306 | Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint |
| CVE-2026-15352 | 8.2 | 46.5 | NASA | Core Flight System (cFS) Health & Safety (HS) Application | CWE-476 | NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer D… |
| CVE-2026-13397 | 7.5 | 46.5 | CODECHILD | HTML::Bare | CWE-835 | HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when … |
| CVE-2026-13401 | 7.5 | 46.5 | CODECHILD | XML::Bare | CWE-835 | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when p… |
| CVE-2026-59117 | 7.5 | 46.4 | Microsoft | Windows Terminal App | CWE-190 | Windows Terminal Remote Code Execution Vulnerability |
| CVE-2026-15727 | 4.9 | 45.9 | xylus | WP Bulk Delete | CWE-89 | WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'd… |
| CVE-2026-62826 | 5.4 | 45.2 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | CWE-79 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-14254 | 8.3 | 44.9 | Perforce | Delphix Continuous Data | CWE-307 | Improper Restriction of Excessive Authentication Attempts in Delphix Continuo… |
| CVE-2026-15022 | 6.5 | 44.7 | themeum | Tutor LMS – eLearning and online course solution | CWE-89 | Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Qui… |
| CVE-2026-46515 | 9.3 | 44.5 | mwtcmi | frogman | CWE-862 | Frogman: Multiple read-tier tools expose admin-grade data and arbitrary Graph… |
| CVE-2026-1609 | 8.1 | 44.2 | Keycloak | Keycloak | CWE-284 | Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt a… |
| CVE-2026-44180 | 9.8 | 43.7 | jupyter-server | enterprise_gateway | CWE-20 | Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can… |
| CVE-2026-55407 | 6.3 | 43.4 | anthropics | buffa | CWE-400 | Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unboun… |
| CVE-2026-45568 | 9.9 | 43.2 | openziti | zrok | CWE-22 | zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths |
| CVE-2026-62299 | 5.3 | 42.9 | coredns | coredns | CWE-476 | CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) … |
| CVE-2026-63085 | 8.7 | 42.8 | axelor | axelor-open-platform | CWE-863 | Axelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational R… |
| CVE-2026-45368 | 8.4 | 42.7 | getkirby | kirby | CWE-79 | Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in… |
| CVE-2026-11386 | 9.0 | 42.2 | Canonical | ubuntu-pro-client (ubuntu-advantage-tools) | CWE-20 | ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Dir… |
| CVE-2026-62963 | 8.7 | 42.0 | centrifugal | centrifugo | CWE-409 | Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional W… |
| CVE-2026-59249 | 6.3 | 42.0 | elixir-mint | mint | CWE-444 | Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling aga… |
| CVE-2026-44981 | 8.2 | 40.9 | crowdsecurity | crowdsec | CWE-409 | CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression |
| CVE-2025-45868 | 8.8 | 40.9 | n/a | n/a | CWE-89 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injecti… |
| CVE-2026-63088 | 7.7 | 40.9 | stoatchat | stoatchat | CWE-918 | stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass |
| CVE-2026-12753 | 7.5 | 40.8 | themehunk | Advance Product Search- Voice & Ajax Search for WooCommerce | CWE-89 | Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauth… |
| CVE-2026-22752 | 9.6 | 40.8 | Spring Security | Spring Authorization Server | CWE-287 | Spring Security Authorization Server Dynamic Client Registration endpoints pe… |
| CVE-2026-46336 | 7.1 | 40.6 | manyfold3d | manyfold | CWE-22 | Manyfold: Authenticated Path Traversal via File Rename |
| CVE-2026-44182 | 10.0 | 40.4 | jupyter-server | enterprise_gateway | CWE-74 | Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Templ… |
| CVE-2026-12492 | 9.8 | 40.4 | Unknown | Happy Coders OTP Login for WooCommerce | CWE-287 | Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeov… |
| CVE-2026-38158 | 9.8 | 40.3 | n/a | n/a | CWE-89 | A SQL injection vulnerability in the /ureport/datasource/previewData componen… |
| CVE-2026-45576 | 8.3 | 40.3 | openziti | zrok | CWE-22 | zrok copy writes attacker-controlled WebDAV paths outside the destination root |
| CVE-2026-44436 | 7.5 | 40.1 | h2o | quicly | CWE-120 | Quicly is vulnerable to connection state corruption |
| CVE-2026-54340 | 7.5 | 40.1 | h2o | h2o | CWE-400 | h2o has HTTP/2 state amplification |
| CVE-2025-45870 | 6.5 | 39.8 | n/a | n/a | CWE-22 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclus… |
| CVE-2026-44435 | 7.5 | 39.8 | h2o | quicly | CWE-400 | Quicly: Remote Denial of Service via assertion failure when CRYPTO stream han… |
| CVE-2026-44453 | 7.5 | 39.8 | h2o | h2o | CWE-770 | h2o is vulnerable to musl libc stack overflow |
| CVE-2026-44174 | 8.7 | 39.7 | getkirby | kirby | CWE-470 | Kirby: Arbitrary Method Call via REST API search and collection query endpoints |
| CVE-2026-15651 | 4.9 | 39.4 | jgwhite33 | WP TripAdvisor Review Slider | CWE-89 | WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Inj… |
| CVE-2025-71388 | 7.6 | 39.1 | stoatchat | stoatchat | CWE-639 | stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions |
| CVE-2026-63397 | 7.1 | 39.1 | remorses | genql | CWE-116 | remorses/genql code injection |
| CVE-2026-46353 | 8.1 | 39.0 | bigbluebutton | bigbluebutton | CWE-284 | BigBlueButton API checksum bypass via presentationUploadExternalUrl |
| CVE-2026-15106 | 5.3 | 38.8 | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | CWE-862 | WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Sess… |
| CVE-2026-15407 | 4.3 | 38.7 | themifyme | Themify Builder | CWE-862 | Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber… |
| CVE-2026-45325 | 8.2 | 38.1 | tmlmobilidade | go | CWE-1321 | Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath |
| CVE-2026-46351 | 8.1 | 38.0 | bigbluebutton | bigbluebutton | CWE-330 | BigBlueButton: Insecure Randomness allows to guess user's conference session … |
| CVE-2026-21729 | 7.5 | 37.9 | Grafana | Loki | CWE-770 | Loki detected_fields query limits results in unbounded memory allocation |
| CVE-2026-62994 | 3.7 | 37.8 | coredns | coredns | CWE-248 | CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that pa… |
| CVE-2026-56455 | 7.5 | 37.7 | HCL Software | DFXAnalytics | CWE-121 | HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead… |
| CVE-2026-46514 | 6.5 | 37.4 | mwtcmi | frogman | CWE-532 | Frogman: Plaintext passwords and secrets persisted to audit log |
| CVE-2026-33692 | 7.5 | 37.3 | WWBN | AVideo | CWE-20 | AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Con… |
| CVE-2024-58360 | 6.9 | 37.2 | stoatchat | stoatchat | CWE-1173 | stoatchat before 0.7.8 Unrestricted Account Creation |
| CVE-2026-46686 | 8.5 | 36.7 | emlog | emlog | CWE-79 | Emlog Reflected Cross-Site Scripting |
| CVE-2026-13741 | 8.8 | 36.6 | UnitedOver | Digits: WordPress Mobile Number Signup and Login | CWE-269 | Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (… |
| CVE-2026-15445 | 4.9 | 36.6 | cleverplugins | SEO Booster | CWE-89 | SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orde… |
| CVE-2026-15458 | 4.9 | 36.6 | cleverplugins | SEO Booster | CWE-89 | SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort… |
| CVE-2026-46687 | 7.7 | 36.2 | emlog | emlog | CWE-24 | Emlog Local File Inclusion (LFI) |
| CVE-2026-46404 | 6.8 | 36.0 | bigbluebutton | bigbluebutton | CWE-918 | BigBlueButton: Presentation URL Security Hardening |
| CVE-2026-63086 | 6.9 | 36.0 | huggingface | text-generation-inference | CWE-918 | text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat compl… |
| CVE-2026-15336 | 4.3 | 36.0 | catchplugins | Catch Themes Demo Import | CWE-862 | Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Sub… |
| CVE-2026-46513 | 7.4 | 35.9 | mwtcmi | frogman | CWE-256 | Frogman: API tokens stored in plaintext |
| CVE-2026-44175 | 8.5 | 35.6 | getkirby | kirby | CWE-79 | Kirby: Cross-site scripting (XSS) from list field content in the site frontend |
| CVE-2026-61718 | 5.4 | 35.6 | bunkerity | bunkerweb | CWE-285 | bunkerweb: Read-only Web UI users can delete job cache files due to missing a… |
| CVE-2026-13042 | 7.2 | 35.5 | yo35 | RPB Chessboard | CWE-79 | RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Com… |
| CVE-2026-44023 | 8.6 | 35.4 | docling-project | docling-core | CWE-22 | Docling Core has unsafe remote filename resolution |
| CVE-2026-35147 | 8.2 | 35.3 | HCL Software | DFXServer | CWE-639 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct… |
| CVE-2026-12684 | 6.5 | 35.3 | Unknown | Customer Reviews for WooCommerce | CWE-434 | Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media … |
| CVE-2026-44019 | 8.1 | 34.6 | docling-project | docling-core | CWE-73 | Docling Core has insufficient validation of image reference URIs |
| CVE-2026-35149 | 8.2 | 34.4 | HCL Software | DFXServer | CWE-294 | HCL DFXServer is affected by an Authentication Bypass vulnerability via serve… |
| CVE-2026-63089 | 9.0 | 34.2 | wg-easy | wg-easy | CWE-338 | WireGuard Easy Weak Token Generation Information Disclosure via OTL Route |
| CVE-2026-12941 | 6.5 | 34.1 | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions | CWE-89 | MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order… |
| CVE-2026-13754 | 6.5 | 34.1 | tickera | Tickera – Sell Tickets & Manage Events | CWE-89 | Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter |
| CVE-2026-13767 | 6.5 | 34.1 | expresstech | Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker | CWE-89 | Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injectio… |
| CVE-2026-58643 | 6.1 | 34.1 | Microsoft | Windows Admin Center | CWE-79 | Windows Admin Center Spoofing Vulnerability |
| CVE-2026-44452 | 5.9 | 34.0 | h2o | h2o | CWE-125 | h2o is vulnerable to heap overrun |
| CVE-2026-63306 | 9.2 | 33.7 | stoatchat | stoatchat | CWE-918 | stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints |
| CVE-2026-14782 | 4.9 | 33.5 | melograno | Booking for Appointments and Events Calendar – Amelia | CWE-89 | Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticate… |
| CVE-2026-12434 | 4.3 | 33.5 | fernandobt | List category posts | CWE-862 | List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contr… |
| CVE-2026-15610 | 4.3 | 33.2 | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | CWE-862 | WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitra… |
| CVE-2026-56456 | 5.3 | 33.0 | HCL Software | DFXAnalytics | CWE-200 | HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. |
| CVE-2026-58078 | 8.7 | 32.9 | themexpert.com | Quix Page Builder Pro extension for Joomla | CWE-89 | Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Pag… |
| CVE-2026-33434 | 7.1 | 32.9 | wazuh | wazuh | CWE-799 | Wazuh: Rate Limit Bypass via /events Endpoint |
| CVE-2026-43977 | 7.5 | 32.2 | wger-project | wger | CWE-639 | wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data … |
| CVE-2026-36425 | 6.5 | 32.3 | n/a | n/a | CWE-269 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier… |
| CVE-2026-13755 | 6.4 | 31.3 | tickera | Tickera – Sell Tickets & Manage Events | CWE-79 | Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-15350 | 4.3 | 31.3 | kevp75 | The Cache Purger | CWE-862 | The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscrib… |
| CVE-2026-12585 | 8.1 | 31.1 | Unknown | Abandoned Cart Lite for WooCommerce | CWE-287 | Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeove… |
| CVE-2026-15737 | 5.7 | 30.9 | AWS | bedrock-agentcore | CWE-532 | Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK |
| CVE-2026-54728 | 6.1 | 30.9 | bunkerity | bunkerweb | CWE-20 | bunkerweb: Improper Input Validation and Improper Neutralization of Special E… |
| CVE-2026-15306 | 6.1 | 30.7 | rextheme | Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces | CWE-79 | Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scriptin… |
| CVE-2026-57075 | 9.1 | 30.1 | TODDR | YAML::Syck | CWE-125 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a si… |
| CVE-2026-44970 | 4.3 | 30.0 | dbt-labs | dbt-mcp | CWE-201 | dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Tran… |
| CVE-2026-44982 | 7.2 | 30.0 | crowdsecurity | crowdsec | CWE-693 | CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests |
| CVE-2026-43978 | 8.1 | 29.8 | wger-project | wger | CWE-269 | wger: Privilege escalation via trainer-login session chaining allows gym trai… |
| CVE-2026-34150 | 7.5 | 29.5 | wazuh | wazuh | CWE-122 | Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing |
| CVE-2026-33754 | 6.5 | 29.6 | wazuh | wazuh | CWE-400 | Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory all… |
| CVE-2026-12395 | 6.5 | 29.2 | Unknown | WP Job Portal | CWE-89 | WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Pa… |
| CVE-2026-15909 | 5.3 | 29.2 | RafyMrX | TOKO-ONLINE-ROTI | CWE-285 | RafyMrX TOKO-ONLINE-ROTI add.php authorization |
| CVE-2026-44176 | 6.0 | 29.1 | getkirby | kirby | CWE-862 | Kirby: `pages.access` permission is not checked during rendering of page drafts |
| CVE-2026-45334 | 5.3 | 29.1 | getkirby | kirby | CWE-862 | Kirby: Content locks disclose IDs and emails of inaccessible users from `user… |
| CVE-2026-54526 | 8.9 | 29.0 | argoproj | argo-workflows | CWE-284 | Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch by… |
| CVE-2026-39359 | 7.5 | 28.7 | wazuh | wazuh | CWE-22 | Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name |
| CVE-2026-55548 | 4.3 | 28.7 | yamcs | yamcs | CWE-284 | Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivile… |
| CVE-2026-14987 | 6.4 | 28.4 | stellarwp | GiveWP – Donation Plugin and Fundraising Platform | CWE-79 | GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting v… |
| CVE-2026-15021 | 6.4 | 28.4 | tomdever | wpForo Forum | CWE-79 | wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripti… |
| CVE-2026-56453 | 9.8 | 27.9 | HCL Software | DFXAnalytics | CWE-294 | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation… |
| CVE-2026-47084 | 6.5 | 27.4 | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCA… |
| CVE-2026-46341 | 6.1 | 26.2 | apify | apify-mcp-server | CWE-20 | Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Pref… |
| CVE-2026-12979 | 5.5 | 26.0 | Unknown | FunnelKit | CWE-73 | FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in T… |
| CVE-2026-15324 | 4.4 | 25.9 | phppoet | SysBasics Customize My Account for WooCommerce – Live My Account Customizer | CWE-79 | SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Sho… |
| CVE-2026-15005 | 8.8 | 25.8 | timwhitlock | Loco Translate | CWE-352 | Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution… |
| CVE-2026-15099 | 6.4 | 25.5 | wpdelicious | WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) | CWE-79 | WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scrip… |
| CVE-2026-15652 | 6.4 | 25.5 | shapedplugin | Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ | CWE-79 | Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-35141 | 5.3 | 25.4 | HCL Software | DFXAnalytics | CWE-294 | HCL DFXAnalytics is affected by a Login Replay Attack vulnerability |
| CVE-2026-13005 | 4.4 | 25.0 | mxchat | MxChat – AI Chatbot & Content Generation for WordPress | CWE-79 | MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'in… |
| CVE-2026-7543 | 7.2 | 24.0 | Breakdance | Breakdance | CWE-79 | Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook… |
| CVE-2024-34268 | 7.1 | 24.0 | n/a | n/a | CWE-306 | EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the l… |
| CVE-2026-35142 | 8.2 | 23.8 | HCL Software | DFXAnalytics | CWE-200 | HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. |
| CVE-2023-49899 | 9.8 | 23.3 | X-Rite | MA-T6 | CWE-346 | Origin Validation Error in X-Rite MA-T6 |
| CVE-2026-11889 | 7.1 | 23.3 | SALTO | ProAccess Space | CWE-639 | SALTO ProAccess Space Authorization Bypass Through User-Controlled Key |
| CVE-2026-15103 | 8.8 | 23.1 | getwpfunnels | WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell | CWE-269 | WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation vi… |
| CVE-2026-46338 | 4.3 | 23.1 | facelessuser | pymdown-extensions | CWE-22 | PyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-pref… |
| CVE-2024-32385 | 4.3 | 22.9 | n/a | n/a | CWE-200 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 … |
| CVE-2026-47083 | 4.3 | 22.7 | cyrusimap | Cyrus IMAP | CWE-204 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is… |
| CVE-2024-32389 | 3.5 | 22.4 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.… |
| CVE-2026-12906 | 2.7 | 21.9 | Unknown | RTMKit | CWE-639 | RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure |
| CVE-2026-47082 | 5.4 | 21.9 | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vaca… |
| CVE-2026-35148 | 6.3 | 21.7 | HCL Software | DFXServer | CWE-284 | HCL DFXServer is affected by a Missing Access Control vulnerability |
| CVE-2024-32387 | 5.7 | 21.7 | n/a | n/a | CWE-200 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 … |
| CVE-2026-47085 | 4.0 | 21.7 | cyrusimap | Cyrus IMAP | CWE-340 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH … |
| CVE-2026-15925 | 9.2 | 20.7 | Snowflake | Snowflake Connector for Python | CWE-297 | Improper TLS Hostname Verification in Snowflake Connector for Python |
| CVE-2026-47087 | 3.5 | 20.5 | cyrusimap | Cyrus IMAP | CWE-672 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH … |
| CVE-2026-12978 | 7.1 | 20.1 | Unknown | FunnelKit | CWE-79 | FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form |
| CVE-2026-47089 | 4.3 | 20.0 | cyrusimap | Cyrus IMAP | CWE-862 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGH… |
| CVE-2026-12907 | 2.7 | 20.1 | Unknown | RTMKit | CWE-862 | RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Templat… |
| CVE-2026-44433 | 7.5 | 19.8 | h2o | quicly | CWE-400 | Quicly is vulnerable to memory exhaustion |
| CVE-2026-35140 | 7.2 | 19.7 | HCL Software | DFXAnalytics | CWE-200 | HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Sessi… |
| CVE-2026-11371 | 6.1 | 19.4 | Unknown | BetterDocs | CWE-79 | BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt … |
| CVE-2026-35145 | 3.1 | 19.1 | HCL Software | DFXAnalytics | CWE-200 | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Head… |
| CVE-2026-47086 | 3.5 | 18.3 | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAU… |
| CVE-2026-49998 | 8.2 | 18.1 | centrifugal | centrifugo | CWE-347 | Centrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JW… |
| CVE-2026-47088 | 3.1 | 17.9 | cyrusimap | Cyrus IMAP | CWE-126 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is… |
| CVE-2026-63082 | 5.3 | 17.3 | Ultimate Fosters | Perfect Support Ticketing & Document Management System | CWE-862 | Perfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment |
| CVE-2026-45795 | 5.3 | 17.2 | JanssenProject | jans | CWE-347 | Janssen Project: JWE Request Object Signature Verification Bypass in jans-aut… |
| CVE-2026-15945 | 2.7 | 17.2 | Red Hat | Red Hat Build of Keycloak | CWE-639 | Keycloak-services: keycloak-services: group hierarchy search discloses hidden… |
| CVE-2026-12869 | 6.1 | 16.4 | Unknown | Header Footer Builder for Elementor | CWE-79 | Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Tem… |
| CVE-2026-60073 | 5.2 | 15.5 | AutomationDirect | Productivity Suite | CWE-125 | AutomationDirect Productivity Suite Out-of-bounds Read |
| CVE-2026-47081 | 3.1 | 15.2 | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is… |
| CVE-2026-53536 | 5.3 | 14.4 | activepieces | activepieces | CWE-345 | Activepieces: Cross-tenant file download via missing JWT audience check on st… |
| CVE-2026-63081 | 5.1 | 14.2 | Ultimate Fosters | Perfect Support Ticketing & Document Management System | CWE-79 | Perfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field |
| CVE-2026-12510 | 5.9 | 13.8 | Unknown | AI Engine | CWE-639 | AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via… |
| CVE-2026-12525 | 8.8 | 13.6 | Unknown | Redux Framework | CWE-269 | Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator |
| CVE-2026-56454 | 7.5 | 12.4 | HCL Software | DFXAnalytics | CWE-327 | HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to th… |
| CVE-2026-44434 | 5.3 | 11.0 | h2o | quicly | CWE-345 | Quicly is vulnerable to stateless reset injection |
| CVE-2026-12379 | 6.8 | 10.6 | Qt | Axivion | CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dash… |
| CVE-2026-5674 | 8.8 | 10.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-427 | Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious… |
| CVE-2026-44968 | 6.3 | 10.6 | dbt-labs | dbt-mcp | CWE-88 | dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and r… |
| CVE-2026-12391 | 5.0 | 10.6 | Canonical | ubuntu-pro-client (ubuntu-advantage-tools) | CWE-59 | ubuntu-pro-client Local Privilege Escalation and Information Disclosure via S… |
| CVE-2026-33731 | 6.5 | 10.4 | WWBN | AVideo | CWE-345 | AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Bala… |
| CVE-2026-12409 | 4.3 | 8.8 | umarbajwa | Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages | CWE-352 | Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_da… |
| CVE-2026-35146 | 6.3 | 8.6 | HCLSoftware | DFXServer | CWE-326 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. |
| CVE-2026-58598 | 7.0 | 8.4 | Microsoft | Windows 10 Version 21H2 | CWE-362 | Windows Backup Service Elevation of Privilege Vulnerability |
| CVE-2026-46377 | 6.2 | 8.0 | TomWright | dasel | CWE-129 | Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash… |
| CVE-2026-13103 | 7.0 | 7.7 | Lenovo | App Store | CWE-22 | A potential path traversal vulnerability was reported in Lenovo App Store, di… |
| CVE-2026-45612 | 5.5 | 6.8 | rizinorg | rz-libdemangle | CWE-125 | rz-libdemangle: Out of bound read in rust demangler |
| CVE-2026-53366 | 7.8 | 6.5 | Linux | Linux | — | ipv4: account for fraggap on the paged allocation path |
| CVE-2026-6423 | 8.5 | 6.3 | ESET, spol. s.r.o. | ESET Inspect Connector | CWE-269 | Local privilege escalation via unauthenticated ALPC in ESET Inspect Connector |
| CVE-2026-3842 | 7.8 | 6.2 | — | qemu | CWE-787 | Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memor… |
| CVE-2026-10590 | 6.7 | 6.0 | Lenovo | Yoga Pro 7 15IPH11 BIOS | — | A potential missing authentication vulnerability could allow a local privileg… |
| CVE-2026-13104 | 7.0 | 5.9 | Lenovo | App Store | CWE-250 | A potential vulnerability was reported in Lenovo App Store, distributed exclu… |
| CVE-2026-44969 | 3.3 | 5.9 | dbt-labs | dbt-mcp | CWE-532 | dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plain… |
| CVE-2026-53409 | 7.8 | 5.5 | Zoom Communications | Zoom Rooms | CWE-20 | Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 … |
| CVE-2026-10589 | 6.8 | 5.5 | Lenovo | Yoga Pro 7 15IPH11 BIOS | CWE-787 | A potential out of bounds write vulnerability could allow a local privileged … |
| CVE-2026-35143 | 6.5 | 5.5 | HCL Software | DFXAnalytics | CWE-352 | HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. |
| CVE-2026-61378 | 6.8 | 5.4 | AutomationDirect | Productivity Suite | CWE-369 | AutomationDirect Productivity Suite Divide By Zero |
| CVE-2026-6424 | 6.7 | 5.3 | ESET, spol. s.r.o. | ESET Endpoint Antivirus for Linux | CWE-416 | Use-after-free vulnerability in ESET security products for Linux |
| CVE-2026-46378 | 6.2 | 5.4 | TomWright | dasel | CWE-835 | Dasel: Denial of service in dasel selector lexer due to infinite loop on unte… |
| CVE-2026-55406 | 5.9 | 5.2 | anthropics | buffa | CWE-200 | Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in … |
| CVE-2026-10588 | 6.7 | 4.8 | Lenovo | Yoga Pro 7 15IPH11 BIOS | CWE-497 | A potential vulnerability could allow a local privileged attacker to disclose… |
| CVE-2026-57896 | 6.9 | 4.5 | AutomationDirect | Productivity Suite | CWE-125 | AutomationDirect Productivity Suite Out-of-bounds Read |
| CVE-2026-60140 | 6.9 | 4.5 | AutomationDirect | Productivity Suite | CWE-125 | AutomationDirect Productivity Suite Out-of-bounds Read |
| CVE-2026-10587 | 6.8 | 4.2 | Lenovo | Yoga Pro 7 15IPH11 BIOS | CWE-787 | A potential out-of-bounds write vulnerability could allow a local privileged … |
| CVE-2026-60063 | 7.3 | 4.1 | AutomationDirect | Productivity Suite | CWE-787 | AutomationDirect Productivity Suite Out-of-bounds Write |
| CVE-2026-61389 | 7.3 | 4.1 | AutomationDirect | Productivity Suite | CWE-787 | AutomationDirect Productivity Suite Out-of-bounds Write |
| CVE-2026-9494 | 5.5 | 4.1 | Canonical | ubuntu-pro-client (ubuntu-advantage-tools) | CWE-214 | ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure … |
| CVE-2026-57077 | 7.7 | 3.7 | TODDR | YAML::Syck | CWE-125 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an u… |
| CVE-2026-11866 | 5.4 | 3.4 | Unknown | Appointment Booking Plugin | CWE-352 | LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF |
| CVE-2026-15997 | 1.7 | 3.3 | Legion of the Bouncy Castle Inc. | BC-LTS | CWE-787 | Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow i… |
| CVE-2026-40106 | 7.8 | 3.1 | wazuh | wazuh | CWE-122 | Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LP… |
| CVE-2026-6511 | 6.8 | 3.2 | Lenovo | Smart Connect | CWE-306 | During an internal security assessment, a potential improper access control v… |
| CVE-2026-13713 | 6.2 | 3.1 | TODDR | YAML::Syck | CWE-415 | YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-fr… |
| CVE-2026-53411 | 7.0 | 3.0 | Zoom Communications | Zoom Workplace VDI Plugin | CWE-20 | Zoom Workplace VDI Plugin for Windows - Improper Input Validation |
| CVE-2026-57076 | 7.8 | 2.4 | TODDR | YAML::Syck | CWE-416 | YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an a… |
| CVE-2026-9046 | 7.3 | 2.4 | Lenovo | Legion Zone | CWE-277 | A potential insecure permissions vulnerability was reported in Legion Zone an… |
| CVE-2026-15449 | 5.8 | 1.8 | illumos | illumos-gate | CWE-122 | TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption |
| CVE-2026-62290 | 7.3 | 1.1 | cert-manager | cert-manager | CWE-863 | cert-manager: Direct ACME Challenge resources can bypass Issuer DNS01 solver … |
| CVE-2026-53410 | 7.0 | 0.8 | Zoom Communications | Zoom Clients | CWE-367 | Zoom Clients for Windows - Race Condition |