| CVE-2026-84697 | 6.9 | 15.5 | axllent | mailpit | CWE-918 | Mailpit SSRF Deny List Bypass via Azure Metadata and IPv6 Prefix |
| CVE-2025-7963 | 6.4 | 9.0 | tymotey | Easy Waveform Player | CWE-79 | Easy Waveform Player <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Sit… |
| CVE-2026-84437 | 2.0 | 8.8 | n/a | OpenCart | CWE-79 | OpenCart Autocomplete Workflow address.php cross site scripting |
| CVE-2026-84438 | 2.0 | 8.8 | n/a | OpenCart | CWE-79 | OpenCart Autocomplete Workflow edit.php cross site scripting |
| CVE-2026-14215 | 6.5 | 8.3 | Unknown | Booking for Appointments and Events Calendar | CWE-862 | Amelia < 2.4.9 - Unauthenticated Post-Booking Action Trigger |
| CVE-2026-19704 | 5.3 | 8.2 | Unknown | Comments | CWE-89 | Comments – wpDiscuz < 7.6.66 - Unauthenticated Comment Disclosure via SQLi |
| CVE-2026-12865 | 7.1 | 8.1 | Unknown | Photo Gallery by 10Web | CWE-79 | Photo Gallery by 10Web < 1.8.44 - Reflected XSS via title and paged Parameters |
| CVE-2026-82968 | 6.4 | 7.2 | Red Hat | Red Hat Build of Keycloak | CWE-639 | Keycloak-services: keycloak-services: cross-session email verification proof … |
| CVE-2026-3851 | 6.4 | 6.8 | Elegant Themes | Divi | CWE-79 | Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via… |
| CVE-2026-81807 | 8.8 | 6.8 | Unknown | Simple Ajax Chat | CWE-79 | Simple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Lin… |
| CVE-2026-77792 | 7.5 | 6.8 | Unknown | RegistrationMagic | CWE-79 | RegistrationMagic < 6.0.9.9 - Unauthenticated Stored XSS via Rating Field |
| CVE-2026-84701 | 5.1 | 6.7 | nocobase | nocobase | CWE-79 | NocoBase Rich Text Field Stored Cross-Site Scripting via API |
| CVE-2026-53683 | 4.3 | 6.6 | Red Hat | Red Hat Enterprise Linux 10 | — | Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_passwor… |
| CVE-2026-84431 | 1.9 | 6.2 | AirAsia | MOVE App | CWE-22 | AirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRe… |
| CVE-2026-84442 | 1.9 | 6.2 | MapQuest | Get Directions App | CWE-22 | MapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt… |
| CVE-2026-19719 | 6.8 | 5.9 | Unknown | Social Media Share Buttons & Social Sharing Icons | CWE-79 | Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Contributor+ Stor… |
| CVE-2026-19723 | 7.1 | 5.8 | Unknown | Social Media Share Buttons & Social Sharing Icons | CWE-79 | Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Reflected XSS via… |
| CVE-2025-15663 | 6.8 | 5.8 | Unknown | Ultimate Before After Image Slider & Gallery | CWE-79 | BEAF < 4.7.19 - Author+ Stored XSS via After Label |
| CVE-2025-15664 | 6.8 | 5.8 | Unknown | Ultimate Before After Image Slider & Gallery | CWE-79 | BEAF < 4.7.19 - Author+ Stored XSS via Before Label |
| CVE-2026-3850 | 6.4 | 5.4 | Elegant Themes | Divi | CWE-79 | Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via… |
| CVE-2026-81737 | 8.8 | 5.1 | Unknown | FAQ Builder AYS | CWE-79 | FAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_i… |
| CVE-2026-77782 | 5.3 | 5.1 | Unknown | Rank Math SEO | CWE-200 | Rank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content D… |
| CVE-2026-82182 | 4.1 | 5.1 | Unknown | WPvivid — Backup, Migration & Staging | CWE-89 | WPvivid Backup & Migration < 0.9.133 - Admin+ SQLi via Upload Cleaner Isolation |
| CVE-2026-84696 | 9.3 | 4.4 | Phison Electronics Corporation | PS3111-S11 Controller Firmware | CWE-306 | Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique… |
| CVE-2026-82183 | 8.1 | 4.4 | Unknown | OAuth Single Sign On | CWE-287 | OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Un… |
| CVE-2026-82883 | 7.1 | 4.4 | Marcus | Login With Ajax | CWE-79 | WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-16966 | 5.3 | 4.4 | Unknown | Solace Extra | CWE-200 | Solace Extra < 1.7.0 - Unauthenticated Draft/Private Site Builder Content Dis… |
| CVE-2026-19251 | 5.3 | 4.4 | Unknown | Ultimate Member | CWE-200 | Ultimate Member < 2.13.0 - Unauthenticated Unapproved Comment Disclosure via … |
| CVE-2026-16983 | 4.3 | 4.4 | Unknown | Gutentor | CWE-200 | Gutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure vi… |
| CVE-2026-15232 | 5.3 | 4.2 | Unknown | MotoPress Appointment Booking | CWE-639 | Appointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Dele… |
| CVE-2026-74927 | 5.3 | 4.2 | Unknown | MultiVendorX | CWE-862 | MultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Dis… |
| CVE-2026-12526 | 8.1 | 4.1 | Unknown | Advanced Custom Fields: Extended | CWE-287 | Advanced Custom Fields: Extended < 0.9.2.7 - Unauthenticated Administrator Ac… |
| CVE-2026-78151 | 5.3 | 4.1 | Unknown | FormLayer | CWE-200 | FormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Su… |
| CVE-2026-81195 | 5.3 | 4.1 | Unknown | MasterStudy LMS WordPress Plugin | CWE-200 | MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via … |
| CVE-2026-81197 | 5.3 | 4.1 | Unknown | MasterStudy LMS WordPress Plugin | CWE-200 | MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosur… |
| CVE-2026-19453 | 7.1 | 3.8 | Unknown | JetBackup | CWE-269 | JetBackup 3.1.7.9 - 3.1.23.3 - Subscriber+ Privilege Escalation via Restore A… |
| CVE-2026-77764 | 4.3 | 3.8 | Unknown | GamiPress | CWE-639 | GamiPress < 7.9.9.6 - Subscriber+ Arbitrary User Points and Achievement Award… |
| CVE-2026-77783 | 3.7 | 3.8 | Unknown | Rank Math SEO | CWE-639 | Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content … |
| CVE-2026-77784 | 2.7 | 3.8 | Unknown | Rank Math SEO | CWE-639 | Rank Math SEO < 1.0.277 - Author+ Robots and Pillar Content Meta Update on No… |
| CVE-2026-81583 | 5.4 | 3.4 | Unknown | Theme My Login | CWE-269 | Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creatio… |
| CVE-2026-80467 | 8.1 | 3.1 | Unknown | Advanced Custom Fields: Extended | CWE-269 | Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privileg… |
| CVE-2026-81428 | 6.5 | 3.1 | Unknown | WC Vendors | CWE-639 | WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modifi… |
| CVE-2026-77788 | 4.9 | 3.1 | Unknown | Rank Math SEO | CWE-639 | Rank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite … |
| CVE-2026-81194 | 4.3 | 3.1 | Unknown | MasterStudy LMS WordPress Plugin | CWE-639 | MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure… |
| CVE-2026-81427 | 4.3 | 3.1 | Unknown | WC Vendors | CWE-862 | WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change |
| CVE-2026-81198 | 3.8 | 3.1 | Unknown | MasterStudy LMS WordPress Plugin | CWE-639 | MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and T… |
| CVE-2026-77785 | 2.7 | 3.1 | Unknown | Rank Math SEO | CWE-639 | Rank Math SEO < 1.0.277 - Author+ Non-Public Post Content Disclosure via Abil… |
| CVE-2026-77787 | 2.7 | 3.1 | Unknown | Rank Math SEO | CWE-862 | Rank Math SEO < 1.0.277 - Author+ Term Metadata Update and Cross-Object Post … |
| CVE-2026-81196 | 2.7 | 3.1 | Unknown | MasterStudy LMS WordPress Plugin | CWE-639 | MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR |
| CVE-2026-81426 | 4.3 | 1.7 | Unknown | WC Vendors | CWE-352 | WC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF |
| CVE-2026-81432 | 4.3 | 1.7 | Unknown | JetStyleManager for Gutenberg | CWE-352 | JetStyleManager < 1.3.9 - Skin Deletion and Modification via CSRF |
| CVE-2026-79621 | 4.3 | 0.9 | Unknown | CatalogX | CWE-345 | CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient |
| CVE-2026-81199 | 5.3 | 0.7 | Unknown | MasterStudy LMS WordPress Plugin | CWE-200 | MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via … |
| CVE-2026-4357 | 10.0 | — | Unknown | Embed HTML5 Game | CWE-434 | Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload |
| CVE-2026-77009 | 9.9 | — | Unknown | WatchMan-Site7 | CWE-94 | WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console |
| CVE-2025-9314 | 9.8 | — | Unknown | Developer Tools | CWE-434 | Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload |
| CVE-2026-19117 | 9.8 | — | Delinea | Secret Server (On-Prem) | CWE-290 | Delinea Secret Server FIDO2 credential registration authentication bypass vul… |
| CVE-2026-20212 | 9.8 | — | Cisco | Cisco NX-OS Software | CWE-1327 | Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction La… |
| CVE-2026-20274 | 9.8 | — | Cisco | Cisco IOS XR Software | CWE-664 | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20279 | 9.8 | — | Cisco | Cisco IOS XR Software | CWE-284 | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-53611 | 9.8 | — | AS203038 | looking-glass | CWE-78 | Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGP… |
| CVE-2026-81294 | 9.8 | — | Paul Ryan | Authorizer | CWE-266 | WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability |
| CVE-2026-53649 | 9.6 | — | BishopFox | joro | CWE-306 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE |
| CVE-2026-53670 | 9.3 | — | vbpf | prevail | CWE-682 | PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB acc… |
| CVE-2026-53671 | 9.3 | — | vbpf | prevail | CWE-682 | PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to p… |
| CVE-2026-81286 | 9.3 | — | WC Lovers | WCFM Marketplace | CWE-89 | WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability |
| CVE-2026-78689 | 9.2 | — | F5 | NGINX JavaScript | CWE-122 | NGINX ngx_http_js_module vulnerablility |
| CVE-2026-84795 | 9.2 | — | craftcms | cms | CWE-269 | Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance |
| CVE-2026-66786 | 9.1 | — | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.17 | CWE-94 | Submariner: submariner: ipsec.conf stanza injection via remote-supplied cable… |
| CVE-2026-73475 | 9.1 | — | Drupal | Commerce PayPal | CWE-863 | Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095 |
| CVE-2026-82955 | 9.0 | — | Eclipse Foundation | Eclipse aeriOS | CWE-295 | In the current development version of Eclipse aeriOS, which has not yet had a… |
| CVE-2026-18329 | 8.8 | — | F5 | NGINX JavaScript | CWE-636 | NGINX ngx_http_js_module vulnerability |
| CVE-2026-20275 | 8.8 | — | Cisco | Cisco IOS XR Software | CWE-682 | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20278 | 8.8 | — | Cisco | Cisco IOS XR Software | CWE-707 | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20280 | 8.8 | — | Cisco | Cisco IOS XR Software | CWE-703 | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-53706 | 8.8 | — | vbpf | prevail | CWE-682 | PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits… |
| CVE-2026-81283 | 8.8 | — | weDevs | WP User Frontend | CWE-502 | WordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerability |
| CVE-2026-81769 | 8.8 | — | LiquidThemes | Booking Hub | CWE-266 | WordPress Booking Hub plugin <= 1.3.1 - Privilege Escalation vulnerability |
| CVE-2026-81772 | 8.8 | — | Saturday Drive | Ninja Forms - Layout & Styles | CWE-502 | WordPress Ninja Forms - Layout & Styles plugin <= 3.0.31 - PHP Object Injecti… |
| CVE-2026-84645 | 8.8 | — | Jenkins Project | Jenkins | CWE-94 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marke… |
| CVE-2026-84647 | 8.8 | — | Jenkins Project | Jenkins | CWE-502 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, … |
| CVE-2026-84648 | 8.8 | — | Jenkins Project | Jenkins | CWE-79 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer … |
| CVE-2026-84649 | 8.8 | — | Jenkins Project | Jenkins | CWE-352 | In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive)… |
| CVE-2026-84650 | 8.8 | — | Jenkins Project | Jenkins | CWE-502 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields canno… |
| CVE-2026-84668 | 8.8 | — | Jenkins Project | Jenkins SAML Plugin | CWE-284 | Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the … |
| CVE-2026-84669 | 8.8 | — | Jenkins Project | Jenkins Allure Plugin | CWE-22 | A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier al… |
| CVE-2026-84670 | 8.8 | — | Jenkins Project | Jenkins Performance Plugin | CWE-502 | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict… |
| CVE-2026-84671 | 8.8 | — | Jenkins Project | Jenkins File Parameter Plugin | CWE-22 | Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing … |
| CVE-2026-84672 | 8.8 | — | Jenkins Project | Jenkins Microsoft Entra ID (previously Azure AD) Plugin | CWE-639 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 an… |
| CVE-2026-84673 | 8.8 | — | Jenkins Project | Jenkins Customizable Header Plugin | CWE-79 | Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows ov… |
| CVE-2026-84764 | 8.8 | — | NSquared | Simply Schedule Appointments | CWE-352 | WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Reque… |
| CVE-2026-84770 | 8.8 | — | Kitae Park | Mang Board WP | CWE-352 | WordPress Mang Board WP plugin <= 2.3.8 - Cross Site Request Forgery (CSRF) v… |
| CVE-2026-66842 | 8.7 | — | F5 | BIG-IP | CWE-918 | BIG-IP and BIG-IQ Configuration utility vulnerability |
| CVE-2026-77180 | 8.7 | — | F5 | NGINX Ingress Controller | CWE-76 | NGINX Ingress Controller vulnerability |
| CVE-2026-78222 | 8.7 | — | F5 | NGINX JavaScript | CWE-476 | NGINX ngx_http_js_module vulnerability |
| CVE-2026-79756 | 8.7 | — | nuclio | nuclio | CWE-78 | Nuclio: Unauthenticated OS command injection via namespace header in list-all… |
| CVE-2026-79989 | 8.7 | — | craftcms | cms | CWE-285 | Arbitrary user password reset leading to administrator account takeover |
| CVE-2026-79990 | 8.7 | — | craftcms | cms | CWE-639 | GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site c… |
| CVE-2026-84796 | 8.7 | — | craftcms | cms | CWE-639 | Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypass |
| CVE-2026-84801 | 8.7 | — | craftcms | cms | CWE-862 | Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers |
| CVE-2026-84851 | 8.7 | — | Amazon | ion-c | CWE-674 | Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6 |
| CVE-2026-20276 | 8.6 | — | Cisco | Cisco IOS XR Software | CWE-691 | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-66362 | 8.6 | — | F5 | NGINX Gateway Fabric | CWE-76 | NGF vulnerability |
| CVE-2026-82524 | 8.6 | — | unopim | unopim | CWE-434 | UnoPim File Upload RCE via TinyMCE Image Upload Endpoint |
| CVE-2026-84452 | 8.6 | — | microsoft | winml-cli | CWE-306 | Windows ML CLI: CORS misconfig enables localhost RCE |
| CVE-2026-84803 | 8.6 | — | siyuan-note | siyuan | CWE-79 | SiYuan before v3.8.2 Stored XSS via incomplete asset blocklist |
| CVE-2026-45730 | 8.3 | — | nuclio | nuclio | CWE-862 | Nuclio: Missing authorization on project write paths allows any authenticated… |
| CVE-2026-82404 | 8.3 | — | toon-format | toon | CWE-1321 | TOON: Prototype pollution when decoding untrusted TOON input |
| CVE-2025-15485 | 8.2 | — | Unknown | Auto x LINE | CWE-862 | Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call |
| CVE-2026-20277 | 8.2 | — | Cisco | Cisco IOS XR Software | CWE-693 | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-19219 | 8.1 | — | Progress Software | Telerik UI for ASP.NET AJAX | CWE-345 | DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX |
| CVE-2026-84381 | 8.1 | — | pydantic | httpx2 | CWE-319 | HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies |
| CVE-2026-49832 | 8.0 | — | DSpace | DSpace | CWE-94 | DSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LDN |
| CVE-2026-52831 | 8.0 | — | nuclio | nuclio | CWE-78 | Nuclio: Unsanitized cron trigger event headers/body injected into CronJob she… |
| CVE-2026-52833 | 8.0 | — | nuclio | nuclio | CWE-94 | Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build… |
| CVE-2026-79755 | 8.0 | — | nuclio | nuclio | CWE-78 | Nuclio: Unauthenticated OS command injection via function namespace in docker… |
| CVE-2026-84665 | 8.0 | — | Jenkins Project | Jenkins SonarQube Scanner Plugin | CWE-79 | Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL scheme… |
| CVE-2026-78408 | 7.9 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-775 | Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration aut… |
| CVE-2026-78410 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-367 | Util-linux: util-linux: restricted bind mounts do not pin the source, allowin… |
| CVE-2026-78604 | 7.8 | — | Elastic | Elastic Agent | CWE-732 | Incorrect Permission Assignment for Critical Resource in Elastic Agent Leadin… |
| CVE-2026-84837 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-78 | Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball… |
| CVE-2026-84838 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-78 | Rpm: command injection in rpmuncompress via unescaped filenames passed to pop… |
| CVE-2023-20576 | 7.7 | — | AMD | AMD Ryzen™ 3000 Series Desktop Processors | CWE-345 | Insufficient Verification of Data Authenticity in AGESA™ may allow an attacke… |
| CVE-2024-7956 | 7.6 | — | Rockwell Automation | DataMosaix™ Private Cloud | CWE-287 | Sensitive Data Exposure and Escalating Privileges Vulnerabilities in DataMosa… |
| CVE-2026-53635 | 7.6 | — | openedx | openedx-platform | CWE-862 | Open edX Platform: Insufficient Permission on set_course_mode_price() |
| CVE-2026-82958 | 7.6 | — | Eclipse Foundation | Eclipse Ditto | CWE-74 | In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMap… |
| CVE-2026-18672 | 7.5 | — | Progress Software | Telerik UI for ASP.NET AJAX | CWE-22 | RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability … |
| CVE-2026-20281 | 7.5 | — | Cisco | Cisco Session Initiation Protocol (SIP) Software | CWE-401 | Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone … |
| CVE-2026-77124 | 7.5 | — | Sonatype | Nexus Repository 3 | CWE-184 | Nexus Repository 3 - Script Execution Disable Setting Not Enforced |
| CVE-2026-81774 | 7.5 | — | Dotstore | WooCommerce Product Attachment | CWE-497 | WordPress WooCommerce Product Attachment plugin <= 2.3.3 - Sensitive Data Exp… |
| CVE-2026-84292 | 7.5 | — | fast-uri | fast-uri | CWE-116 | fast-uri vulnerable to authority injection via an unvalidated port in serialize |
| CVE-2026-84382 | 7.5 | — | pydantic | httpx2 | CWE-409 | HTTPX2: Streaming response decompression does not bound peak memory (decompre… |
| CVE-2026-84394 | 7.5 | — | fast-uri | fast-uri | CWE-436 | fast-uri vulnerable to host confusion via an unclosed bracket in the URI auth… |
| CVE-2023-20577 | 7.4 | — | AMD | 2nd Gen AMD EPYC™ Processors | CWE-121 | A heap overflow in SMM module may allow an attacker with access to a second v… |
| CVE-2026-84675 | 7.4 | — | Jenkins Project | Jenkins TICS Plugin | CWE-78 | OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlie… |
| CVE-2026-18058 | 7.3 | — | Motorola | Smart Connect Application | CWE-862 | The mobile Smart Connect dashboard UI was subject to manipulation by 3rd part… |
| CVE-2026-76759 | 7.3 | — | Drupal | Screenshot | CWE-79 | Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102 |
| CVE-2026-76782 | 7.3 | — | Drupal | Screenshot | CWE-79 | Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102 |
| CVE-2026-78590 | 7.3 | — | Elastic | Kibana | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading… |
| CVE-2026-14199 | 7.1 | — | Grafana | Grafana Enterprise | CWE-290 | Session takeover via Auth Proxy cache key collision |
| CVE-2026-49249 | 7.1 | — | malach-it | boruta-server | CWE-400 | Boruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsCo… |
| CVE-2026-77125 | 7.1 | — | Sonatype | Nexus Repository 3 | CWE-863 | Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints |
| CVE-2026-79754 | 7.1 | — | nuclio | nuclio | CWE-77 | Nuclio: Kaniko build tempDir command injection |
| CVE-2026-79991 | 7.1 | — | craftcms | cms | CWE-89 | Authenticated SQL Injection via nested eager-loading criteria |
| CVE-2026-81288 | 7.1 | — | WP Swings | Upsell Order Bump Offer for WooCommerce | CWE-79 | WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.5 - Cross Sit… |
| CVE-2026-81289 | 7.1 | — | sonaar | MP3 Audio Player for Music, Radio & Podcast by Sonaar | CWE-79 | WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.1… |
| CVE-2026-81770 | 7.1 | — | MapGeo | Interactive Geo Maps | CWE-79 | WordPress Interactive Geo Maps plugin <= 1.6.30 - Reflected Cross Site Script… |
| CVE-2026-81771 | 7.1 | — | TrustedSite | TrustedSite | CWE-79 | WordPress TrustedSite plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-81775 | 7.1 | — | Estatik | Estatik | CWE-79 | WordPress Estatik plugin <= 4.3.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-84667 | 7.1 | — | Jenkins Project | Jenkins ThinBackup Plugin | CWE-22 | Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's b… |
| CVE-2026-84759 | 7.1 | — | Elementor | Activity Log | CWE-352 | WordPress Activity Log plugin <= 2.13.1 - Cross Site Request Forgery (CSRF) v… |
| CVE-2026-84794 | 7.1 | — | craftcms | cms | CWE-862 | Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset |
| CVE-2026-84798 | 7.1 | — | craftcms | cms | CWE-862 | Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite |
| CVE-2026-84800 | 7.1 | — | craftcms | cms | CWE-862 | Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file |
| CVE-2026-84809 | 7.1 | — | Tencent | AI-Infra-Guard | CWE-693 | Tencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python Bytecode |
| CVE-2026-84810 | 7.1 | — | claude-world | claude-skill-antivirus | CWE-693 | claude-skill-antivirus Analysis Bypass via Manifest-Only Local Directory Scan |
| CVE-2026-84811 | 7.1 | — | agentverus | agentverus-scanner | CWE-693 | agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode |
| CVE-2026-78409 | 7.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-59 | Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape vi… |
| CVE-2026-75135 | 6.9 | — | Septeo IT Solutions | UpSignOn | CWE-316 | UpSignOn < 7.19.0 Sensitive Key Retention in Memory |
| CVE-2026-75136 | 6.9 | — | Septeo IT Solutions | UpSignOn | CWE-522 | UpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVault |
| CVE-2026-75137 | 6.9 | — | Septeo IT Solutions | UpSignOn | CWE-316 | UpSignOn < 7.19.0 Sensitive Data Exposure in Process Memory after Lock |
| CVE-2026-84886 | 6.9 | — | simular-ai | Agent-S | CWE-400 | simular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumption |
| CVE-2026-12704 | 6.8 | — | Grafana | Grafana Enterprise | CWE-294 | SAML assertion replay via skipped InResponseTo validation |
| CVE-2026-55421 | 6.8 | — | openedx | openedx-platform | CWE-918 | Open edX Platform: SSRF in Studio Video Download Endpoint |
| CVE-2026-82884 | 6.8 | — | Unknown | All in One SEO | CWE-79 | All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block |
| CVE-2026-83547 | 6.8 | — | Unknown | Xpro Addons | CWE-79 | Xpro Elementor Addons 1.6.0 - 1.7.3 - Contributor+ Stored XSS via Multiple Wi… |
| CVE-2026-10821 | 6.6 | — | Unknown | Yoast SEO Premium | CWE-74 | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection … |
| CVE-2026-2688 | 6.5 | — | Unknown | HIPAA FORMS | CWE-863 | CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass |
| CVE-2026-19475 | 6.5 | — | Grafana | PostgreSQL Datasource | CWE-400 | SQL Data Source Plugin: OOM DoS via $__timeGroup macro |
| CVE-2026-55221 | 6.5 | — | malach-it | boruta-server | CWE-532 | Boruta: OAuth credentials exposed in Boruta business logs |
| CVE-2026-78586 | 6.5 | — | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-78588 | 6.5 | — | Elastic | Filebeat | CWE-770 | Allocation of Resources Without Limits or Throttling in Filebeat Leading to D… |
| CVE-2026-78599 | 6.5 | — | Elastic | Kibana | CWE-22 | Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal … |
| CVE-2026-82223 | 6.5 | — | Arraytics | WP Event SOlution | CWE-862 | WordPress WP Event SOlution plugin <= 4.1.22 - Broken Access Control vulnerab… |
| CVE-2026-83562 | 6.5 | — | WC Lovers | WCFM Marketplace | CWE-79 | WordPress WCFM Marketplace plugin <= 3.8.2 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-84377 | 6.5 | — | BerriAI | litellm | CWE-918 | LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalida… |
| CVE-2026-84781 | 6.5 | — | WP Chill | Gallery PhotoBlocks | CWE-79 | WordPress Gallery PhotoBlocks plugin <= 1.3.4 - Cross Site Scripting (XSS) vu… |
| CVE-2026-53600 | 6.3 | — | dignifiedquire | async-tar | CWE-20 | async-tar PAX extension-header desync enables tar entry/content smuggling |
| CVE-2026-78591 | 6.3 | — | Elastic | Kibana | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'… |
| CVE-2026-84376 | 6.3 | — | withastro | astro | CWE-187 | Astro: Authorization bypass from missing path-segment boundary check when str… |
| CVE-2026-84651 | 6.3 | — | Jenkins Project | Jenkins | CWE-284 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI e… |
| CVE-2026-85084 | 6.3 | — | Samsung Open Source | TizenFX | CWE-787 | Out-of-bounds write in TizenFX MediaBufferBase indexer setter due to missing … |
| CVE-2026-32773 | 6.1 | — | Apache Software Foundation | Apache Spark | CWE-80 | Apache Spark: XSS Vulnerability in Spark Web 3.5.4 |
| CVE-2026-81160 | 6.1 | — | Drupal | Slick Carousel | CWE-79 | Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026… |
| CVE-2026-81201 | 6.1 | — | Drupal | Monster Menus | CWE-79 | Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116 |
| CVE-2026-77123 | 6.0 | — | Sonatype | Nexus Repository 3 | CWE-201 | Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API |
| CVE-2024-3773 | 5.9 | — | Unknown | LiveJournal Shortcode | CWE-79 | LiveJournal Shortcode <= 1.1.1 - Contributor+ Stored XSS via Shortcode |
| CVE-2026-20354 | 5.9 | — | Cisco | Cisco Secure Email | CWE-354 | Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty |
| CVE-2026-20355 | 5.9 | — | Cisco | Cisco Secure Email | CWE-345 | Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty |
| CVE-2026-76755 | 5.9 | — | Drupal | Gammu SMS Daemon | CWE-119 | Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 |
| CVE-2026-76756 | 5.9 | — | Drupal | Gammu SMS Daemon | CWE-119 | Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 |
| CVE-2026-76757 | 5.9 | — | Drupal | Gammu SMS Daemon | CWE-119 | Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 |
| CVE-2026-76758 | 5.9 | — | Drupal | Link content parser | CWE-20 | Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101 |
| CVE-2026-84378 | 5.9 | — | pydantic | httpx2 | CWE-407 | HTTPX2: Quadratic SSE line buffering can cause CPU denial of service |
| CVE-2026-84380 | 5.6 | — | pydantic | httpx2 | CWE-444 | HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-… |
| CVE-2026-14255 | 5.5 | — | Autodesk | Shared Components | CWE-674 | IFC File Parsing Uncontrolled Recursion in Certain Autodesk Products |
| CVE-2026-49831 | 5.5 | — | DSpace | DSpace | CWE-22 | DSpace: Curation Task Reporter output path is not restricted to trusted direc… |
| CVE-2026-49833 | 5.5 | — | DSpace | DSpace | CWE-22 | DSpace: Path Traversal possible in LDN message generation |
| CVE-2026-78601 | 5.5 | — | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index D… |
| CVE-2026-84772 | 5.5 | — | WPMU DEV | Broken Link Checker | CWE-918 | WordPress Broken Link Checker plugin <= 2.4.14 - Server Side Request Forgery … |
| CVE-2026-84839 | 5.5 | — | tsi-coop | tsi-dpdp-cms | CWE-287 | tsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing au… |
| CVE-2026-84840 | 5.5 | — | tsi-coop | tsi-dpdp-cms | CWE-287 | tsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missin… |
| CVE-2026-84841 | 5.5 | — | tsi-coop | tsi-dpdp-cms | CWE-602 | tsi-coop tsi-dpdp-cms client-side enforcement of server-side security |
| CVE-2026-84856 | 5.5 | — | rowboatlabs | rowboat | CWE-404 | rowboatlabs rowboat Composio Webhook Endpoint route.ts req.json denial of ser… |
| CVE-2026-84857 | 5.5 | — | sigoden | aichat | CWE-400 | sigoden aichat API Endpoint serve.rs memory allocation |
| CVE-2026-2811 | 5.4 | — | Unknown | Ajaxify Comments | CWE-113 | Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection |
| CVE-2026-8151 | 5.4 | — | Unknown | Simple Membership MailChimp Integration | CWE-352 | Simple Membership MailChimp Integration < 1.9.8 - API Key Update via CSRF |
| CVE-2026-66652 | 5.4 | — | ThemeGoods | Grand Tour | CWE-352 | WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulne… |
| CVE-2026-73476 | 5.4 | — | Drupal | External Authentication | CWE-178 | External Authentication - Moderately critical - Access bypass - SA-CONTRIB-20… |
| CVE-2026-78598 | 5.4 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposur… |
| CVE-2026-78609 | 5.4 | — | Elastic | Eck Operator | CWE-863 | Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorize… |
| CVE-2026-81164 | 5.4 | — | Drupal | Entity PDF | CWE-862 | Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114 |
| CVE-2026-84217 | 5.4 | — | Mamunur Rashid | Classified Listing | CWE-862 | WordPress Classified Listing plugin <= 6.1.1 - Broken Access Control vulnerab… |
| CVE-2026-84654 | 5.4 | — | Jenkins Project | Jenkins | CWE-472 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, … |
| CVE-2026-84660 | 5.4 | — | Jenkins Project | Jenkins Pipeline: Build Step Plugin | CWE-862 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67e… |
| CVE-2026-84661 | 5.4 | — | Jenkins Project | Jenkins Pipeline: Build Step Plugin | CWE-862 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67e… |
| CVE-2026-84663 | 5.4 | — | Jenkins Project | Jenkins Pipeline: Groovy Libraries Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy… |
| CVE-2026-84664 | 5.4 | — | Jenkins Project | Jenkins GitLab Plugin | CWE-471 | Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab… |
| CVE-2026-84674 | 5.4 | — | Jenkins Project | Jenkins XebiaLabs XL Deploy Plugin | CWE-862 | Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and ea… |
| CVE-2026-84677 | 5.4 | — | Jenkins Project | Jenkins update-center2 | CWE-79 | Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided val… |
| CVE-2025-8945 | 5.3 | — | Unknown | Wp Edit Password Protected | CWE-863 | Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API |
| CVE-2025-15481 | 5.3 | — | Unknown | Notification Bar for WordPress | CWE-306 | Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Dis… |
| CVE-2025-15489 | 5.3 | — | Unknown | Passster | CWE-863 | Passster < 4.2.24 - Password Protection Bypass |
| CVE-2025-15490 | 5.3 | — | Unknown | Passster | CWE-863 | Passster < 4.2.26 - Global Protection Bypass |
| CVE-2026-17563 | 5.3 | — | Unknown | User Frontend | CWE-862 | WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Ga… |
| CVE-2026-73474 | 5.3 | — | Drupal | Entity Share Websub | CWE-918 | Entity Share Websub - Moderately critical - Server-side request forgery (SSRF… |
| CVE-2026-73477 | 5.3 | — | Drupal | Quick Tabs | CWE-863 | Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099 |
| CVE-2026-73478 | 5.3 | — | Drupal | Diff | CWE-863 | Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096 |
| CVE-2026-77121 | 5.3 | — | Sonatype | Nexus Repository 3 | CWE-770 | Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields |
| CVE-2026-77122 | 5.3 | — | Sonatype | Nexus Repository 3 | CWE-863 | Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repo… |
| CVE-2026-77793 | 5.3 | — | Unknown | RegistrationMagic | CWE-602 | RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Pric… |
| CVE-2026-77794 | 5.3 | — | Unknown | RegistrationMagic | CWE-472 | RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero… |
| CVE-2026-78153 | 5.3 | — | Unknown | Restrict User Access | CWE-863 | Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass vi… |
| CVE-2026-78602 | 5.3 | — | Elastic | Elastic Maps Server | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps S… |
| CVE-2026-81158 | 5.3 | — | Drupal | Entity API | CWE-863 | Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113 |
| CVE-2026-81162 | 5.3 | — | Drupal | DXPR Builder: The Best Editing (AI) Experience for Drupal | CWE-201 | DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - I… |
| CVE-2026-81165 | 5.3 | — | Drupal | Blazy | CWE-863 | Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104 |
| CVE-2026-81166 | 5.3 | — | Drupal | Digital Signage Framework | CWE-862 | Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-… |
| CVE-2026-81205 | 5.3 | — | Drupal | LDAP / Active Directory Integration | CWE-90 | LDAP / Active Directory Integration - Moderately critical - Information Discl… |
| CVE-2026-81269 | 5.3 | — | Drupal | Data field | CWE-862 | Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108 |
| CVE-2026-82522 | 5.3 | — | libjxl | libjxl | CWE-681 | libjxl < 0.12.0 Container Box Parser Integer Underflow via 32-bit Size Trunca… |
| CVE-2026-83533 | 5.3 | — | Unknown | WP Express Checkout | CWE-345 | WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process… |
| CVE-2026-84379 | 5.3 | — | pydantic | httpx2 | CWE-93 | HTTPX2: Multipart part header injection via unvalidated file Content-Type and… |
| CVE-2026-84760 | 5.3 | — | WP Swings | Ultimate Gift Cards For WooCommerce | CWE-862 | WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.9 - Broken Access… |
| CVE-2026-84771 | 5.3 | — | PublishPress | PublishPress Permissions | CWE-639 | WordPress PublishPress Permissions plugin <= 4.8.3 - Insecure Direct Object R… |
| CVE-2026-84775 | 5.3 | — | Really Simple Plugins | Really Simple SSL | CWE-770 | WordPress Really Simple SSL plugin <= 9.8.0 - Denial of Service Attack vulner… |
| CVE-2026-84780 | 5.3 | — | WPGMaps | WP Go Maps | CWE-770 | WordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerability |
| CVE-2026-84792 | 5.3 | — | craftcms | cms | CWE-862 | Craft CMS before 5.10.11 Broken Access Control via element-indexes |
| CVE-2026-84797 | 5.3 | — | craftcms | cms | CWE-862 | Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate |
| CVE-2026-84799 | 5.3 | — | craftcms | cms | CWE-285 | Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations |
| CVE-2026-84802 | 5.3 | — | craftcms | cms | CWE-862 | Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController |
| CVE-2026-84804 | 5.3 | — | kimai | kimai | CWE-284 | Kimai before 2.65.0 Authorization Bypass via Team Activity API |
| CVE-2026-84805 | 5.3 | — | kimai | kimai | CWE-862 | Kimai 2.61.0 before 2.63.0 Authentication Bypass via API |
| CVE-2026-84806 | 5.3 | — | kimai | kimai | CWE-732 | Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints |
| CVE-2026-84807 | 5.3 | — | kimai | kimai | CWE-266 | Kimai before 2.65.0 Authentication Bypass via Team Creation |
| CVE-2026-84808 | 5.3 | — | kimai | kimai | CWE-863 | Kimai before 2.65.0 Authorization Bypass via API Timesheet |
| CVE-2026-84835 | 5.3 | — | DimaFreund | Rentsyst | CWE-862 | WordPress Rentsyst plugin <= 2.1.2 - Broken Access Control vulnerability |
| CVE-2026-84885 | 5.3 | — | simular-ai | Agent-S | CWE-404 | simular-ai Agent-S CodeAgent code_agent.py denial of service |
| CVE-2026-84887 | 5.3 | — | simular-ai | Agent-S | CWE-404 | simular-ai Agent-S Model-generated GUI Action Execution Workflow grounding.py… |
| CVE-2026-84888 | 5.3 | — | RightNow-AI | OpenFang | CWE-789 | RightNow-AI OpenFang tool_runner.rs shell_exec memory allocation |
| CVE-2026-75134 | 5.1 | — | SEOWriting | SEOWriting | CWE-79 | SEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload |
| CVE-2026-52832 | 4.9 | — | nuclio | nuclio | CWE-22 | Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file … |
| CVE-2026-78594 | 4.9 | — | Elastic | Apm Server | CWE-409 | Improper Handling of Highly Compressed Data in APM Server Leading to Persiste… |
| CVE-2026-18986 | 4.8 | — | Drupal | Entity Browser | CWE-79 | Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026… |
| CVE-2026-81167 | 4.8 | — | Drupal | Address Suggestion | CWE-79 | Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-… |
| CVE-2026-81571 | 4.8 | — | Unknown | Brave | CWE-74 | Brave Popup Builder < 0.8.8 - Unauthenticated Arbitrary Shortcode Execution v… |
| CVE-2026-84793 | 4.8 | — | craftcms | cms | CWE-79 | Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site name |
| CVE-2026-53636 | 4.7 | — | openedx | openedx-platform | CWE-294 | Open edX LTI OAuth Replay Attack |
| CVE-2026-49830 | 4.4 | — | DSpace | DSpace | CWE-20 | DSpace: ORE resource URI does not validate scheme for non-web resources |
| CVE-2026-78584 | 4.3 | — | Elastic | Kibana | CWE-204 | Observable Response Discrepancy in Kibana Leading to Cross-Space Information … |
| CVE-2026-82293 | 4.3 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption |
| CVE-2026-84646 | 4.3 | — | Jenkins Project | Jenkins | CWE-502 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appea… |
| CVE-2026-84655 | 4.3 | — | Jenkins Project | Jenkins | CWE-116 | Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys w… |
| CVE-2026-84656 | 4.3 | — | Jenkins Project | Jenkins | CWE-862 | A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earl… |
| CVE-2026-84658 | 4.3 | — | Jenkins Project | Jenkins Script Security Plugin | CWE-200 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@Dat… |
| CVE-2026-84659 | 4.3 | — | Jenkins Project | Jenkins Script Security Plugin | CWE-862 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enfor… |
| CVE-2026-84662 | 4.3 | — | Jenkins Project | Jenkins LDAP Plugin | CWE-601 | Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a… |
| CVE-2026-84676 | 4.3 | — | Jenkins Project | Jenkins Parameterized Remote Trigger Plugin | CWE-311 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens u… |
| CVE-2026-84657 | 4.2 | — | Jenkins Project | Jenkins | CWE-862 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command … |
| CVE-2026-14326 | 3.8 | — | Unknown | Timetics | CWE-639 | Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR |
| CVE-2026-81159 | 3.7 | — | Drupal | Commerce CyberSource | CWE-208 | Commerce CyberSource - Moderately critical - Insufficient input validation - … |
| CVE-2026-81168 | 3.7 | — | Drupal | CAPTCHA Protected Page | CWE-288 | CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-20… |
| CVE-2025-15692 | 3.5 | — | Unknown | Icegram Express | CWE-79 | Icegram Express < 5.8.6 - Admin+ Stored XSS |
| CVE-2026-19698 | 3.5 | — | Unknown | GutenKit | CWE-74 | GutenKit < 2.5.1 - Contributor+ Stored CSS Injection |
| CVE-2026-78600 | 3.5 | — | Elastic | Eck Operator | CWE-459 | Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cro… |
| CVE-2023-3360 | 3.3 | — | Unknown | Weaver Show Posts | CWE-502 | Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection |
| CVE-2026-81161 | 3.3 | — | Drupal | Content Moderation Notifications | CWE-267 | Content Moderation Notifications - Moderately critical - Access bypass - SA-C… |
| CVE-2026-78587 | 3.1 | — | Elastic | Fleet Server | CWE-863 | Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent… |
| CVE-2026-63020 | 2.3 | — | F5 | BIG-IP | CWE-451 | BIG-IP Configuration utility vulnerability |
| CVE-2026-84833 | 2.1 | — | ntegrals | openbrowser | CWE-400 | ntegrals openbrowser Browser Agent Message Construction agent.ts resource con… |
| CVE-2026-84852 | 1.9 | — | Reader Tools | PDF Reader App | CWE-22 | Reader Tools PDF Reader App File ActSplashNew.handleDeeplink path traversal |
| CVE-2026-16647 | await | — | Drupal | Disable Login Page | CWE-288 | Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111 |
| CVE-2026-56855 | await | — | golang.org/x/crypto | golang.org/x/crypto/ssh | — | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh |
| CVE-2026-78662 | await | — | golang.org/x/crypto | golang.org/x/crypto/ssh | — | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh |
| CVE-2026-84652 | await | — | Jenkins Project | Jenkins | — | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotat… |
| CVE-2026-84653 | await | — | Jenkins Project | Jenkins | — | Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (bo… |
| CVE-2026-84666 | await | — | Jenkins Project | Jenkins Job Configuration History Plugin | — | Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier all… |