Security Box Score — September 30, 2026 — page 2
Edition of September 30, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-97065 | 7.1 | — | Happyforms | Happyforms | CWE-79 | WordPress Happyforms plugin <= 1.26.15 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-97077 | 7.1 | — | Spacetime | Ad Inserter | CWE-79 | WordPress Ad Inserter plugin <= 2.8.18 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-97235 | 7.1 | — | ThemeRex | ThemeREX Addons | CWE-79 | WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-97237 | 7.1 | — | Crocoblock. Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-97250 | 7.1 | — | Dylan Kuhn | Geo Mashup | CWE-79 | WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-97253 | 7.1 | — | Kreatura | LayerSlider | CWE-79 | WordPress LayerSlider plugin <= 8.4.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-97271 | 7.1 | — | WPFunnels | WPFunnels | CWE-79 | WordPress WPFunnels plugin <= 3.13.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-97272 | 7.1 | — | Premmerce | Premmerce Permalink Manager for WooCommerce | CWE-79 | WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.13 - Cros… |
| CVE-2026-97289 | 7.1 | — | ExpressTech Systems | Quiz And Survey Master | CWE-79 | WordPress Quiz And Survey Master plugin <= 11.2.6 - Cross Site Scripting (XSS… |
| CVE-2026-97290 | 7.1 | — | Sayontan Sinha | Photonic Gallery & Lightbox for Flickr, SmugMug & Others | CWE-79 | WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= … |
| CVE-2026-100507 | 7.1 | — | If-So Dynamic Content | If-So Dynamic Content Personalization | CWE-79 | WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site… |
| CVE-2026-100510 | 7.1 | — | BoldGrid | Post and Page Builder by BoldGrid | CWE-79 | WordPress Post and Page Builder by BoldGrid plugin <= 1.27.14 - Cross Site Sc… |
| CVE-2026-101879 | 7.1 | — | OpenClaw | OpenClaw Windows Node | CWE-862 | OpenClaw Windows Node before 2026.7.1-3 Missing Authorization |
| CVE-2026-101881 | 7.1 | — | OpenClaw | OpenClaw Windows Node | CWE-770 | OpenClaw Windows Node before 2026.7.1 Denial of Service |
| CVE-2026-102109 | 7.1 | — | Kiteworks | Secure Data Forms | CWE-89 | Kiteworks Secure Data Forms SQL injection |
| CVE-2026-102376 | 7.1 | — | WPMU DEV | Branda | CWE-79 | WordPress Branda plugin <= 3.4.32 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-102385 | 7.1 | — | Kevin Stover | Ninja Forms | CWE-79 | WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-102391 | 7.1 | — | jetmonsters | JetFormBuilder | CWE-79 | WordPress JetFormBuilder plugin <= 3.6.5.4 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-102395 | 7.1 | — | supsystic | Easy Google Maps | CWE-79 | WordPress Easy Google Maps plugin <= 1.14.6 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-102396 | 7.1 | — | supsystic | Ultimate Maps by Supsystic | CWE-79 | WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Cross Site Scripting (… |
| CVE-2026-102398 | 7.1 | — | supsystic | Popup by Supsystic | CWE-79 | WordPress Popup by Supsystic plugin <= 1.13.1 - Cross Site Scripting (XSS) vu… |
| CVE-2026-103242 | 7.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_fil… |
| CVE-2026-47582 | 7.0 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47596 | 7.0 | — | NVIDIA | GeForce | CWE-281 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47598 | 7.0 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-sour… |
| CVE-2026-102127 | 7.0 | — | Kiteworks | Email Protection Gateway | CWE-611 | Kiteworks Email Protection Gateway Improper Restriction of XML External Entit… |
| CVE-2026-96342 | 6.9 | — | Amauri.IO | WPMobile.App | CWE-862 | WordPress WPMobile.App plugin <= 11.83 - Sensitive Data Exposure vulnerability |
| CVE-2026-100275 | 6.9 | — | JetBrains | YouTrack | CWE-79 | In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error no… |
| CVE-2026-103243 | 6.9 | — | ModelTC | LightLLM | CWE-918 | LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints |
| CVE-2026-103476 | 6.9 | — | yii2-starter-kit | yii2-starter-kit | CWE-639 | yii2-starter-kit through 4.2.0 Unauthorized File Download via attachment-down… |
| CVE-2026-103530 | 6.9 | — | decolua | 9Router | CWE-918 | decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery |
| CVE-2026-103592 | 6.9 | — | pecee | simple-router | CWE-348 | simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers |
| CVE-2026-10726 | 6.8 | — | Cato Networks | SDP Client | CWE-73 | Cato Windows SDP Client arbitrary file disclosure due to improper TLS certifi… |
| CVE-2026-96824 | 6.8 | — | envato | Template Kit – Import | CWE-22 | WordPress Template Kit – Import plugin <= 1.0.16 - Arbitrary File Deletion vu… |
| CVE-2026-97242 | 6.8 | — | phuongwebo | WEBO MCP | CWE-22 | WordPress WEBO MCP plugin <= 3.0.18 - Arbitrary File Deletion vulnerability |
| CVE-2026-47509 | 6.7 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47515 | 6.7 | — | NVIDIA | GeForce | CWE-125 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47522 | 6.7 | — | NVIDIA | GeForce | CWE-20 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47524 | 6.7 | — | NVIDIA | GeForce | CWE-125 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47525 | 6.7 | — | NVIDIA | GeForce | CWE-129 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47527 | 6.7 | — | NVIDIA | GeForce | CWE-125 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47529 | 6.7 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47532 | 6.7 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47533 | 6.7 | — | NVIDIA | GeForce | CWE-129 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47537 | 6.7 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47538 | 6.7 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47539 | 6.7 | — | NVIDIA | Virtual GPU Manager | CWE-681 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker… |
| CVE-2026-47542 | 6.7 | — | NVIDIA | GeForce | CWE-20 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47543 | 6.7 | — | NVIDIA | GeForce | CWE-20 | VIDIA GPU Display Driver for Windows and Linux contains a vulnerability in th… |
| CVE-2026-47544 | 6.7 | — | NVIDIA | Virtual GPU Manager | CWE-125 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker… |
| CVE-2026-47546 | 6.7 | — | NVIDIA | GeForce | CWE-20 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47547 | 6.7 | — | NVIDIA | GeForce | CWE-20 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-102141 | 6.7 | — | Kiteworks | Core | CWE-73 | Kiteworks Core Privilege Escalation through External Control of File Name or … |
| CVE-2026-102133 | 6.6 | — | Kiteworks | Core | CWE-77 | Kiteworks Core Arbitrary File Write through Command Injection |
| CVE-2026-102135 | 6.6 | — | Kiteworks | Email Protection Gateway | CWE-502 | Kiteworks Email Protection Gateway Deserialization of Untrusted Data |
| CVE-2026-102145 | 6.6 | — | Kiteworks | Core | CWE-93 | Kiteworks Core Server-Side Request Forgery through CRLF Injection |
| CVE-2026-62078 | 6.5 | — | Leap13 | Premium Addons for Elementor | CWE-79 | WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Script… |
| CVE-2026-62079 | 6.5 | — | Qode | Qi Addons For Elementor | CWE-79 | WordPress Qi Addons For Elementor plugin <= 1.11 - Cross Site Scripting (XSS)… |
| CVE-2026-62080 | 6.5 | — | Leevio | Happy Addons for Elementor | CWE-79 | WordPress Happy Addons for Elementor plugin <= 3.23.1 - Cross Site Scripting … |
| CVE-2026-62084 | 6.5 | — | Jeff Starr | User Submitted Posts | CWE-79 | WordPress User Submitted Posts plugin <= 20260810 - Cross Site Scripting (XSS… |
| CVE-2026-94074 | 6.5 | — | NSquared | Simply Schedule Appointments | CWE-862 | WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Co… |
| CVE-2026-94077 | 6.5 | — | 10up | Safe SVG | CWE-79 | WordPress Safe SVG plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-94674 | 6.5 | — | SweetCode | Pixel Manager for WooCommerce | CWE-79 | WordPress Pixel Manager for WooCommerce plugin <= 1.69.0 - Cross Site Scripti… |
| CVE-2026-96338 | 6.5 | — | Cozmoslabs | Profile Builder | CWE-79 | WordPress Profile Builder plugin <= 4.0.2 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-96347 | 6.5 | — | Bookly | Bookly | CWE-639 | WordPress Bookly plugin <= 28.2 - Insecure Direct Object References (IDOR) vu… |
| CVE-2026-96829 | 6.5 | — | POSIMYTH | The Plus Addons for Elementor Page Builder Lite | CWE-79 | WordPress The Plus Addons for Elementor Page Builder Lite plugin <= 6.5.1 - C… |
| CVE-2026-96834 | 6.5 | — | Nexcess | GiveWP | CWE-862 | WordPress GiveWP plugin <= 4.16.9 - Sensitive Data Exposure vulnerability |
| CVE-2026-96835 | 6.5 | — | KingAddons.com | King Addons for Elementor | CWE-79 | WordPress King Addons for Elementor plugin <= 51.1.85 - Cross Site Scripting … |
| CVE-2026-97067 | 6.5 | — | Shane Bishop | EWWW Image Optimizer | CWE-79 | WordPress EWWW Image Optimizer plugin <= 8.7.7 - Cross Site Scripting (XSS) v… |
| CVE-2026-97236 | 6.5 | — | ThemeRex | ThemeREX Addons | CWE-79 | WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-97239 | 6.5 | — | Jose Conti | MCP Content Manager Lite | CWE-862 | WordPress MCP Content Manager Lite plugin <= 1.1.0 - Broken Access Control vu… |
| CVE-2026-97247 | 6.5 | — | Creative Themes | Blocksy Companion | CWE-862 | WordPress Blocksy Companion plugin <= 2.1.55 - Broken Access Control vulnerab… |
| CVE-2026-97262 | 6.5 | — | Visual Composer | Visual Composer Website Builder | CWE-79 | WordPress Visual Composer Website Builder plugin <= 45.16.2 - Cross Site Scri… |
| CVE-2026-97265 | 6.5 | — | Crocoblock. Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.15.3 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-97266 | 6.5 | — | Nexcess | Virtue/Ascend/Pinnacle Toolkit | CWE-79 | WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12.1 - Cross Site Scri… |
| CVE-2026-97270 | 6.5 | — | Justin Sternberg | CMB2 | CWE-79 | WordPress CMB2 plugin <= 2.13.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-97279 | 6.5 | — | Chouby | Polylang | CWE-79 | WordPress Polylang plugin <= 3.8.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-97286 | 6.5 | — | WP Chill | Strong Testimonials | CWE-79 | WordPress Strong Testimonials plugin <= 3.3.11 - Cross Site Scripting (XSS) v… |
| CVE-2026-97288 | 6.5 | — | Jayson T Cote | OAuth Server | CWE-79 | WordPress OAuth Server plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-97292 | 6.5 | — | YITHEMES | YITH WooCommerce Tab Manager | CWE-79 | WordPress YITH WooCommerce Tab Manager plugin <= 2.15.0 - Cross Site Scriptin… |
| CVE-2026-97298 | 6.5 | — | KingAddons | King Addons for Elementor | CWE-79 | WordPress King Addons for Elementor plugin <= 51.1.86 - Cross Site Scripting … |
| CVE-2026-97301 | 6.5 | — | Cool Plugins | Cool Formkit Lite | CWE-79 | WordPress Cool Formkit Lite plugin <= 2.7.8 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-100274 | 6.5 | — | JetBrains | YouTrack | CWE-770 | In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via… |
| CVE-2026-100279 | 6.5 | — | JetBrains | YouTrack | CWE-918 | In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed… |
| CVE-2026-100513 | 6.5 | — | Aman | CF7 Views – Complete Entry Management for Contact Form 7 | CWE-79 | WordPress CF7 Views – Complete Entry Management for Contact Form 7 plug… |
| CVE-2026-102124 | 6.5 | — | Kiteworks | Core | CWE-306 | Kiteworks Core Missing Authentication for Critical Function |
| CVE-2026-102139 | 6.5 | — | Kiteworks | Email Protection Gateway | CWE-639 | Kiteworks Email Protection Gateway Incorrect Authorization |
| CVE-2026-102146 | 6.5 | — | Kiteworks | Email Protection Gateway | CWE-73 | Kiteworks Email Protection Gateway Arbitrary File Write through Server-Side T… |
| CVE-2026-102375 | 6.5 | — | Optimole | Optimole | CWE-862 | WordPress Optimole plugin <= 4.2.14 - Broken Access Control vulnerability |
| CVE-2026-102386 | 6.5 | — | Jacob N. Breetvelt | WP Photo Album Plus | CWE-79 | WordPress WP Photo Album Plus plugin <= 9.3.02.003 - Cross Site Scripting (XS… |
| CVE-2026-102397 | 6.5 | — | supsystic | Ultimate Maps by Supsystic | CWE-862 | WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Broken Access Control … |
| CVE-2026-102991 | 6.5 | — | sqlalchemy | mako | CWE-22 | Mako: Path traversal via drive-letter URI on Windows in TemplateLookup |
| CVE-2026-103001 | 6.5 | — | jpadilla | pyjwt | CWE-471 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-veri… |
| CVE-2026-47565 | 6.4 | — | NVIDIA | GeForce | CWE-362 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47586 | 6.4 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-91860 | 6.3 | — | vaadin | vaadin | CWE-1321 | Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep M… |
| CVE-2026-96821 | 6.3 | — | Mahmudul Hasan Arif | FluentBoards | CWE-266 | WordPress FluentBoards plugin <= 2.0.12 - Privilege Escalation vulnerability |
| CVE-2026-102136 | 6.3 | — | Kiteworks | Core | CWE-93 | Kiteworks Core Command Execution through Configuration Injection |
| CVE-2026-102983 | 6.3 | — | withastro | astro | CWE-625 | Astro: Netlify Image CDN allowlist bypass enables SSRF |
| CVE-2026-103222 | 6.3 | — | Blosc | C-Blosc2 | CWE-189 | Blosc C-Blosc2 blosclz Decompression blosclz.c blosclz_decompress integer ove… |
| CVE-2026-103397 | 6.3 | — | Liquid-co | OpenSave | CWE-290 | OpenSave before 2.4.0-beta.1 Authentication Bypass via Spoofed Relay Sender |
| CVE-2026-103388 | 6.2 | — | MISP | MISP | CWE-79 | MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source … |
| CVE-2026-103389 | 6.2 | — | MISP | MISP | CWE-20 | MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correla… |
| CVE-2026-47518 | 6.0 | — | NVIDIA | GeForce | CWE-732 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a… |
| CVE-2026-55174 | 5.9 | — | shrec | UltrafastSecp256k1 | CWE-345 | UltrafastSecp256k1: ECDSA adaptor verification accepts non-adaptable pre-sign… |
| CVE-2026-94681 | 5.9 | — | Tijmen Smit | WP Store Locator | CWE-770 | WordPress WP Store Locator plugin < 3.0.0 - Denial of Service Attack vulnerab… |
| CVE-2026-100267 | 5.9 | — | JetBrains | YouTrack | CWE-1333 | In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailb… |
| CVE-2026-100276 | 5.9 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow… |
| CVE-2026-102110 | 5.9 | — | Kiteworks | Core | CWE-306 | Missing authentication on a Kiteworks appliance setup function |
| CVE-2026-102384 | 5.9 | — | Supreme Modules | Supreme Modules Lite | CWE-79 | WordPress Supreme Modules Lite plugin <= 2.5.63 - Cross Site Scripting (XSS) … |
| CVE-2026-47492 | 5.5 | — | NVIDIA | GeForce | CWE-862 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47506 | 5.5 | — | NVIDIA | GeForce | CWE-121 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel-… |
| CVE-2026-47517 | 5.5 | — | NVIDIA | GeForce | CWE-476 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47534 | 5.5 | — | NVIDIA | GeForce | CWE-369 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47549 | 5.5 | — | NVIDIA | GeForce | CWE-476 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47555 | 5.5 | — | NVIDIA | GeForce | CWE-908 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47557 | 5.5 | — | NVIDIA | GeForce | CWE-476 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47566 | 5.5 | — | NVIDIA | GeForce | CWE-401 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47567 | 5.5 | — | NVIDIA | GeForce | CWE-400 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47568 | 5.5 | — | NVIDIA | GeForce | CWE-400 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47581 | 5.5 | — | NVIDIA | GeForce | CWE-667 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47584 | 5.5 | — | NVIDIA | GeForce | CWE-476 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47603 | 5.5 | — | NVIDIA | GeForce | CWE-862 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47604 | 5.5 | — | NVIDIA | GeForce | CWE-862 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-97238 | 5.5 | — | Crocoblock. Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-103229 | 5.5 | — | AdithyaYelloju | Restaurant-Management-System | CWE-74 | AdithyaYelloju Restaurant-Management-System Unauthenticated Action Script del… |
| CVE-2026-103230 | 5.5 | — | AdithyaYelloju | Restaurant-Management-System | CWE-74 | AdithyaYelloju Restaurant-Management-System Order Placement ord.php mysqli_qu… |
| CVE-2026-103231 | 5.5 | — | AdithyaYelloju | Restaurant-Management-System | CWE-74 | AdithyaYelloju Restaurant-Management-System Order Cancellation cancel.php mys… |
| CVE-2026-103232 | 5.5 | — | AdithyaYelloju | Restaurant-Management-System | CWE-74 | AdithyaYelloju Restaurant-Management-System table_booking.php mysqli_query sq… |
| CVE-2026-103241 | 5.5 | — | vllm-project | vLLM | CWE-404 | vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service |
| CVE-2026-13720 | 5.4 | — | Grafana | Grafana OSS | CWE-285 | Editor can forge file-provisioning provenance on dashboards via the dashboard… |
| CVE-2026-62081 | 5.4 | — | wpdesk | Flexible PDF Coupons | CWE-639 | WordPress Flexible PDF Coupons plugin <= 1.14.11 - Insecure Direct Object Ref… |
| CVE-2026-62083 | 5.4 | — | WPFunnels | Creator LMS | CWE-1284 | WordPress Creator LMS plugin <= 1.2.19 - Other vulnerability Type vulnerability |
| CVE-2026-94173 | 5.4 | — | Strategy11 Team | Business Directory | CWE-639 | WordPress Business Directory plugin <= 6.4.27 - Insecure Direct Object Refere… |
| CVE-2026-96450 | 5.4 | — | pixfort | pixfort Core | CWE-79 | WordPress pixfort Core plugin < 4.3.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-97243 | 5.4 | — | flexyma | AllAble Connector | CWE-862 | WordPress AllAble Connector plugin <= 0.13.4 - Broken Access Control vulnerab… |
| CVE-2026-97285 | 5.4 | — | Nexcess | The Events Calendar | CWE-862 | WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulner… |
| CVE-2026-97299 | 5.4 | — | KnitPay | Razorpay Payment Links for WooCommerce | CWE-352 | WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.5 - Cross Site… |
| CVE-2026-100261 | 5.4 | — | JetBrains | YouTrack | CWE-288 | In JetBrains YouTrack before 2026.2.18991 changing article visibility setting… |
| CVE-2026-102134 | 5.4 | — | Kiteworks | Core | CWE-420 | Kiteworks Core Unprotected Alternate Channel |
| CVE-2026-102399 | 5.4 | — | supsystic | Photo Gallery by Supsystic | CWE-352 | WordPress Photo Gallery by Supsystic plugin <= 1.21.0 - Cross Site Request Fo… |
| CVE-2026-47096 | 5.3 | — | AJA Video Systems | HELO Plus | CWE-79 | AJA HELO Plus < 2.1.7 Stored XSS via System Name Parameter |
| CVE-2026-86778 | 5.3 | — | Maksisoft Technology, IT, and Software Industry and Trade Inc. | Maksisoft Gym | CWE-204 | Username Enumeration in Maksisoft Technology's Maksisoft Gym |
| CVE-2026-93547 | 5.3 | — | vaadin | vaadin | CWE-285 | Missing Authorization Check in Vaadin Spreadsheet Allows Cell Comments to Be … |
| CVE-2026-94545 | 5.3 | — | vercel | satori | CWE-116 | Satori-generated SVG has improper escaping |
| CVE-2026-94673 | 5.3 | — | NSquared | Simply Schedule Appointments | CWE-639 | WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct … |
| CVE-2026-97066 | 5.3 | — | Nexcess | GiveWP | CWE-639 | WordPress GiveWP plugin <= 4.16.9 - Insecure Direct Object References (IDOR) … |
| CVE-2026-97078 | 5.3 | — | BoldGrid | Client Invoicing by Sprout Invoices | CWE-639 | WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.17 - Insecure Di… |
| CVE-2026-97249 | 5.3 | — | Cozmoslabs | Paid Member Subscriptions | CWE-290 | WordPress Paid Member Subscriptions plugin <= 3.0.9 - Bypass Vulnerability vu… |
| CVE-2026-97259 | 5.3 | — | WP Hosting AS | Pay with Vipps for WooCommerce | CWE-639 | WordPress Pay with Vipps for WooCommerce plugin <= 6.2.4 - Insecure Direct Ob… |
| CVE-2026-97261 | 5.3 | — | VillaTheme | Notivo | CWE-201 | WordPress Notivo plugin <= 1.4.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-97282 | 5.3 | — | RadiusTheme | Review Schema | CWE-639 | WordPress Review Schema plugin <= 3.1.0 - Insecure Direct Object References (… |
| CVE-2026-97302 | 5.3 | — | Themeisle | MPG | CWE-201 | WordPress MPG plugin <= 4.2.3 - Sensitive Data Exposure vulnerability |
| CVE-2026-100260 | 5.3 | — | JetBrains | YouTrack | CWE-1188 | In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authent… |
| CVE-2026-100508 | 5.3 | — | WordPress.org | Two Factor | CWE-770 | WordPress Two Factor plugin <= 0.16.0 - Denial of Service Attack vulnerability |
| CVE-2026-101883 | 5.3 | — | OpenClaw | OpenClaw Windows Node | CWE-918 | OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present |
| CVE-2026-102144 | 5.3 | — | Kiteworks | Email Protection Gateway | CWE-306 | Kiteworks Email Protection Gateway Uncontrolled Resource Consumption |
| CVE-2026-103118 | 5.3 | — | n/a | GraphicsMagick | CWE-404 | GraphicsMagick WPG File wpg.c ExtractPostscript recursion |
| CVE-2026-103227 | 5.3 | — | n/a | GPAC | CWE-119 | GPAC DASH Client dash_client.c gf_dash_resolve_url buffer overflow |
| CVE-2026-103396 | 5.3 | — | mlogclub | bbs-go | CWE-863 | bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount |
| CVE-2026-103399 | 5.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-444 | Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-conti… |
| CVE-2026-103548 | 5.3 | — | Itron | MV-90 xi | CWE-257 | Improperly Stored Credentials |
| CVE-2026-103587 | 5.1 | — | Webkul | QloApps | CWE-79 | QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters |
| CVE-2026-103588 | 5.1 | — | Webkul | QloApps | CWE-79 | QloApps through 1.7.0 Reflected XSS via exceptions field |
| CVE-2026-103589 | 5.1 | — | Webkul | QloApps | CWE-79 | QloApps through 1.7.0 Reflected XSS via Room Type Editor |
| CVE-2026-103590 | 5.1 | — | Webkul | QloApps | CWE-79 | QloApps through 1.7.0 Reflected XSS via Length of Stay Fields |
| CVE-2026-97246 | 4.9 | — | ShortPixel | ShortPixel Image Optimizer | CWE-502 | WordPress ShortPixel Image Optimizer plugin <= 6.5.5 - PHP Object Injection v… |
| CVE-2026-100272 | 4.9 | — | JetBrains | YouTrack | CWE-639 | In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notifi… |
| CVE-2026-100278 | 4.9 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.19197 users with restricted permission co… |
| CVE-2026-102111 | 4.9 | — | Kiteworks | Core | CWE-1284 | Kiteworks Core Improper Validation of Specified Quantity in Input |
| CVE-2026-102140 | 4.9 | — | Kiteworks | Core | CWE-345 | Kiteworks Core Insufficient Verification of Data Authenticity |
| CVE-2026-92899 | 4.8 | — | Apache Software Foundation | Apache WSS4J | CWE-290 | Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce |
| CVE-2026-100265 | 4.8 | — | JetBrains | Rider | CWE-494 | In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party… |
| CVE-2026-100263 | 4.7 | — | JetBrains | YouTrack | CWE-79 | In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-… |
| CVE-2026-102107 | 4.6 | — | Kiteworks | Core | CWE-639 | Kiteworks Core user impersonation in a file-request feature |
| CVE-2026-47526 | 4.4 | — | NVIDIA | GeForce | CWE-476 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47531 | 4.4 | — | NVIDIA | GeForce | CWE-476 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47562 | 4.4 | — | NVIDIA | GeForce | CWE-116 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-13719 | 4.3 | — | Grafana | Grafana Enterprise | CWE-200 | Alert rules in restricted folders disclosed via the alert rules list API |
| CVE-2026-94672 | 4.3 | — | 10up | Safe SVG | CWE-639 | WordPress Safe SVG plugin <= 2.5.0 - Insecure Direct Object References (IDOR)… |
| CVE-2026-97074 | 4.3 | — | Omnisend | Newsletters, Email Marketing, SMS and Popups by Omnisend | CWE-639 | WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin <= … |
| CVE-2026-97079 | 4.3 | — | Webba Appointment Booking | Webba Booking | CWE-639 | WordPress Webba Booking plugin <= 6.5.0 - Insecure Direct Object References (… |
| CVE-2026-97267 | 4.3 | — | miniOrange | Prevent files / folders access | CWE-862 | WordPress Prevent files / folders access plugin <= 2.6.7 - Broken Access Cont… |
| CVE-2026-100257 | 4.3 | — | JetBrains | YouTrack | CWE-918 | In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was… |
| CVE-2026-100258 | 4.3 | — | JetBrains | YouTrack | CWE-201 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-… |
| CVE-2026-100259 | 4.3 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt ch… |
| CVE-2026-100269 | 4.3 | — | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Repor… |
| CVE-2026-102090 | 4.3 | — | Kiteworks | Core | CWE-601 | Kiteworks Core content injection |
| CVE-2026-102122 | 4.3 | — | Kiteworks | Core | CWE-863 | Kiteworks Core Incorrect Authorization |
| CVE-2026-96825 | 4.2 | — | David Anderson / Team Updraft | All In One WP Security & Firewall | CWE-290 | WordPress All In One WP Security & Firewall plugin <= 5.4.8 - Bypass Vulnerab… |
| CVE-2026-102137 | 4.1 | — | Kiteworks | Core | CWE-434 | Kiteworks Core Unrestricted Upload of File with Dangerous Type |
| CVE-2026-103436 | 3.7 | — | apcupsd | apcupsd | CWE-457 | apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() i… |
| CVE-2026-100270 | 3.3 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission use… |
| CVE-2026-102138 | 3.3 | — | Kiteworks | Core | CWE-918 | Kiteworks Core Server-Side Request Forgery (SSRF) |
| CVE-2026-100280 | 3.1 | — | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadab… |
| CVE-2026-27085 | 2.7 | — | Brainstorm Force | Astra WordPress Theme | CWE-80 | WordPress Astra WordPress theme theme <= 4.13.12 - Content Injection vulnerab… |
| CVE-2026-100264 | 2.7 | — | JetBrains | YouTrack | CWE-522 | In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials coul… |
| CVE-2026-100271 | 2.7 | — | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.19197 missing authorisation on several en… |
| CVE-2026-103114 | 2.1 | — | OS4ED | openSIS-Classic | CWE-74 | OS4ED openSIS-Classic Assignment Management Endpoint Assignments.php DBQuery_… |
| CVE-2026-103115 | 2.1 | — | OS4ED | openSIS-Classic | CWE-74 | OS4ED openSIS-Classic Student Search CustomFieldsFnc.php sql injection |
| CVE-2026-103116 | 2.1 | — | OS4ED | openSIS-Classic | CWE-74 | OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery … |
| CVE-2026-103226 | 2.1 | — | Artifex | Ghostscript | CWE-119 | Artifex Ghostscript Pdfwrite gdevpsfx.c type1_callsubr stack-based overflow |
| CVE-2026-103233 | 2.1 | — | AdithyaYelloju | Restaurant-Management-System | CWE-285 | AdithyaYelloju Restaurant-Management-System Admin Area admin authorization |
| CVE-2026-103387 | 2.1 | — | garycourt | uri-js | CWE-248 | garycourt uri-js Mailto Header mailto.ts URI.parse uncaught exception |
| CVE-2026-103012 | 2.0 | — | Anthropic | @anthropic-ai/claude-code | CWE-696 | Claude Code selected an API key stored by Claude Code, for example from an ea… |
| CVE-2026-103113 | 2.0 | — | OS4ED | openSIS-Classic | CWE-74 | OS4ED openSIS-Classic General Information Tab Student.php save action sql inj… |
| CVE-2026-103117 | 2.0 | — | OS4ED | openSIS-Classic | CWE-74 | OS4ED openSIS-Classic Save Data DatabaseInc.php db_properties sql injection |
| CVE-2026-103440 | 1.2 | — | The Wikimedia Foundation | MediaWiki PageTriage extension | CWE-202 | pagetriagelist discloses suppressed reviewer usernames |
| CVE-2026-103445 | 1.2 | — | The Wikimedia Foundation | MediaWiki Page_Forms extension | CWE-80 | Stored XSS through PageForms #autoedit redirect links |
| CVE-2026-103585 | 1.2 | — | The Wikimedia Foundation | MediaWiki MediaSearch extension | CWE-80 | attacker-controlled javascript license URL via XSS |
| CVE-2026-103437 | 1.1 | — | The Wikimedia Foundation | MediaWiki ReadingLists extension | CWE-80 | ReadingLists imported metadata permits JavaScript URL XSS |
| CVE-2026-103443 | 1.1 | — | The Wikimedia Foundation | MediaWiki Collection (Book) extension | CWE-80 | API permits session-seeded javascript URL XSS |
| CVE-2026-103444 | 1.1 | — | The Wikimedia Foundation | MediaWiki WikiForum extension | CWE-80 | Stored XSS through system messages in WikiForum |
| CVE-2026-103584 | 1.1 | — | The Wikimedia Foundation | MediaWiki CommonsMetadata extension | CWE-80 | attacker-controlled javascript license URL via XSS |
| CVE-2026-103438 | 0.3 | — | The Wikimedia Foundation | MediaWiki Wikistories extension | CWE-80 | Various rawParams() and escaped() updates to prevent XSS in Wikistories exten… |
| CVE-2026-103439 | 0.3 | — | The Wikimedia Foundation | MediaWiki Wikbase extension | CWE-80 | Various rawParams() and escaped() updates to prevent XSS in Wikibase extension |
| CVE-2026-51852 | await | — | n/a | n/a | — | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in py… |
| CVE-2026-51853 | await | — | n/a | n/a | — | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in py… |
| CVE-2026-51856 | await | — | n/a | n/a | — | In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session expos… |
| CVE-2026-51857 | await | — | n/a | n/a | — | In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can… |
| CVE-2026-51858 | await | — | n/a | n/a | — | In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_ex… |
| CVE-2026-51859 | await | — | n/a | n/a | — | bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in… |
| CVE-2026-51860 | await | — | n/a | n/a | — | bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in… |
| CVE-2026-51861 | await | — | n/a | n/a | — | bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/… |
| CVE-2026-51862 | await | — | n/a | n/a | — | DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app… |
| CVE-2026-51864 | await | — | n/a | n/a | — | DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (… |
| CVE-2026-51866 | await | — | n/a | n/a | — | In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/u… |
| CVE-2026-51867 | await | — | n/a | n/a | — | agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server… |
| CVE-2026-51869 | await | — | n/a | n/a | — | DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes co… |
| CVE-2026-51870 | await | — | n/a | n/a | — | DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/… |
| CVE-2026-51871 | await | — | n/a | n/a | — | Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in… |
| CVE-2026-51872 | await | — | n/a | n/a | — | Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function … |
| CVE-2026-80490 | await | — | — | Algorithm-AhoCorasick-XS | CWE-125 | Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack s… |
| CVE-2026-92172 | await | — | Meta Platforms, Inc | Meta Horizon OS | — | Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced… |
| CVE-2026-92173 | await | — | Meta Platforms, Inc | Meta Horizon OS | — | Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be i… |
| CVE-2026-103500 | await | — | Mozilla | Thunderbird | — | Heap buffer overflow opening large email |