boxscore/security
Monday, June 15, 2026 · all times UTC← 2026-06-14 · archive · 2026-06-16 →

400 CVEs published June 15, 2026: 80 critical, 191 high, 117 medium, 12 low; 2 in KEV; 15 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 375 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published3775814710612563
KEV catalog size1670

417 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9610628466331212730.37.8.0013-119
google59176567402272217460.88.1.0023+591
microsoft207697524661584378273.97.8.0043+68
red hat53117854496400.07.1.0030+49
apple146101636293711.55.7.0023+1
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
debian220020000.06.5.0023+2
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161800.04.3.0024+17
cisco4173250961058.87.0.1247+3
palo alto networks911017114218.24.8.0022+8
ivanti49230033555.68.8.5187+3
checkpoint3915303111.17.5.0410+3
ubiquiti584400400.08.9.0052+5
fortinet28132028337.57.3.0066+1
broadcom2400204250.05.3.0887+2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache679915404124011.07.3.0052+63
gitlab1120041224210.04.8.0024+11
mozilla51134401300.07.5.0032+1
docker250500100.08.8.0021+2
drupal0511305120.05.1.00260
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
adobe1241284477227532.35.5.0021+124
ibm11601329180700.07.5.0028+11
oracle330916404026.78.1.0027+3
progress591710900.07.5.0036+5
solarwinds36121011466.77.5.3995+3
veeam142200400.09.0.0046+1
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link91204252618.35.5.0058+9
siemens780440100.07.5.0020+6
abb550410000.07.2.0018+5
dahua330111200.06.9.0036+3
hitachi energy020020000.05.7.00140
moxa110100000.07.0.0007+1
schneider electric110100100.07.1.0023+1
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71
sourcecodester3658002434000.02.1.0026+36
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
openclaw3440024124000.07.4.0022+34

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9990100.010.0
CVE-2008-4250.987599.9
CVE-2026-35273.954799.99.8
CVE-2026-0257.939199.8
CVE-2010-0249.918899.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
CVE-2026-42271.830199.6
CVE-2026-50751.825599.69.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9990KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-2022310.0.0083
CVE-2026-4714010.0.0082
CVE-2026-4720810.0.0076
Most disclosures (vendor)
VendorCVEs
google759
linux521
microsoft238
adobe125
red hat90
apache84
spring72
ibm60
sourcecodester58
edimax51
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco10
apple7
google6
ivanti5
solarwinds4
synacor4
adobe3
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven35
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171671
CVE-2021-27102Accellion2021-11-171671
CVE-2021-27101Accellion2021-11-171671
CVE-2021-27103Accellion2021-11-171671
CVE-2021-21017Adobe2021-11-171671
CVE-2021-28550Adobe2021-11-171671
CVE-2021-42013Apache2021-11-171671
CVE-2021-41773Apache2021-11-171671
CVE-2021-30858Apple2021-11-171671
CVE-2021-30860Apple2021-11-171671

Transactions

EXPLOIT PUBLISHEDCVE-2025-55641. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55642. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55643. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55644. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55645. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55647. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55648. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55649. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55650. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55652. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55660. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55661. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-55663. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10634 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50889. Public exploit reference added.

DUE DATE PASSEDCVE-2026-10520 (ivanti Sentry). CISA remediation deadline was June 14, 2026; still in catalog.

Yesterday's Results

400 CVEs published. 25 box scores, 375 table rows — nothing truncated.

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .2817   97.9   YES
AFFECTED
  Product                        Versions   Fixed
  Cisco Catalyst SD-WAN Manager  20.1.12 –  —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 15  Added to CISA KEV, due Jun 29
  Jun 15  Published (CNA: cisco)
CWE-22 · CNA: cisco · 2 references · NVD status: Analyzed · KEV due June 29, 2026
LiteSpeed cPanel Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  C  H  H  H    8.5   .0144   70.9   YES
AFFECTED
  Product        Versions  Fixed
  cPanel Plugin  2.3 –     —
TIMELINE
  Jun 14  Reserved by CNA
  Jun 15  Added to CISA KEV, due Jun 18
  Jun 15  Published (CNA: mitre)
CWE-61 · CNA: mitre · 3 references · NVD status: Analyzed · KEV due June 18, 2026
Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0419   90.1     —
AFFECTED
  Product       Versions    Fixed
  Discuz! X5.0  20260320 –  —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 15  Published (CNA: VulnCheck)
CWE-323 · CNA: VulnCheck · 5 references · NVD status: Deferred
n/a n/a — An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linu…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0157   73.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-94 · CNA: mitre · 1 reference · NVD status: Deferred
n/a n/a — Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0135   69.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Deferred
eLightUp Meta Box – WordPress Custom Fields Framework — WordPress Meta Box – WordPress Custom Fields Framework plugin <= 5.11.1 - Arbitrary File Deletion vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  N  N  H    6.8   .0122   66.1     —
AFFECTED
  Product                                       Versions  Fixed
  Meta Box – WordPress Custom Fields Framework  n/a –     5.11.2
TIMELINE
  Apr 7   Reserved by CNA
  Jun 15  Published (CNA: Patchstack)
CWE-22 · CNA: Patchstack · 1 reference · NVD status: Deferred
Yealink SIP-T46U Web FastCGI Service tftpuploadiperf mod_webd.TFTPUploadIperf command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   L   N   L   L   L    2.0   .0119   65.4     —
AFFECTED
  Product   Versions        Fixed
  SIP-T46U  108.86.0.118 –  108.87.0.23
TIMELINE
  Jun 14  Reserved by CNA
  Jun 15  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
n/a n/a — An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscenc…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0112   63.4     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Deferred
Yealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0105   61.4     —
AFFECTED
  Product   Versions        Fixed
  SIP-T46U  108.86.0.118 –  108.87.0.23
TIMELINE
  Jun 14  Reserved by CNA
  Jun 15  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
n/a n/a — Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0105   61.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Deferred
n/a n/a — Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0105   61.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Deferred
n/a n/a — Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mod…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0105   61.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Deferred
n/a n/a — Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_wi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0105   61.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Deferred
n/a n/a — Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call v…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0105   61.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-78 · CNA: mitre · 1 reference · NVD status: Deferred
Fortra Core Privileged Access Manager (BoKS) — Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0099   59.7     —
AFFECTED
  Product                                Versions               Fixed
  Core Privileged Access Manager (BoKS)  boks-server 8.1.0.0 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 15  Published (CNA: Fortra)
CWE-78 · CNA: Fortra · 1 reference · NVD status: Analyzed
n/a n/a — remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0081   53.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-94 · CNA: mitre · 1 reference · NVD status: Analyzed
jamie Dharma Booking — WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   N   H   N   N    6.9   .0078   52.8     —
AFFECTED
  Product         Versions     Fixed
  Dharma Booking  unspecified  —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 15  Published (CNA: VulnCheck)
CWE-98 · CNA: VulnCheck · 3 references · NVD status: Deferred
Unknown WP Go Maps — WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0076   52.4     —
AFFECTED
  Product     Versions     Fixed
  WP Go Maps  unspecified  —
TIMELINE
  May 12  Reserved by CNA
  Jun 15  Published (CNA: WPScan)
CWE-200 · CNA: WPScan · 1 reference · NVD status: Deferred
n/a n/a — An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversa…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0072   50.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 15  Published (CNA: mitre)
CWE-22 · CNA: mitre · 1 reference · NVD status: Deferred
Unknown WP Go Maps — WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Marker ID
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0070   50.2     —
AFFECTED
  Product     Versions     Fixed
  WP Go Maps  unspecified  —
TIMELINE
  May 12  Reserved by CNA
  Jun 15  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Deferred
Henrique Dias IMDb Profile Widget — WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   N   H   N   N    6.9   .0069   49.7     —
AFFECTED
  Product              Versions  Fixed
  IMDb Profile Widget  1.0.8 –   —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 15  Published (CNA: VulnCheck)
CWE-98 · CNA: VulnCheck · 3 references · NVD status: Deferred
MetaSlider Responsive Slider by MetaSlider — WordPress Responsive Slider by MetaSlider plugin <= 3.106.0 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0068   49.4     —
AFFECTED
  Product                          Versions  Fixed
  Responsive Slider by MetaSlider  n/a –     3.107.0
TIMELINE
  Apr 7   Reserved by CNA
  Jun 15  Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · 1 reference · NVD status: Deferred
Shipster Baggage Freight Shipping Australia — WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0066   48.7     —
AFFECTED
  Product                             Versions  Fixed
  Baggage Freight Shipping Australia  0.1.0 –   —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 15  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · 4 references · NVD status: Deferred
Husain HB Audio Gallery Lite — WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0064   47.8     —
AFFECTED
  Product                Versions  Fixed
  HB Audio Gallery Lite  1.0.0 –   —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 15  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 3 references · NVD status: Deferred
Red Hat Red Hat Enterprise Linux 10 — Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0064   47.7     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:1.26.7-2.el10_2.4
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:1.24.11-3.el10_0.4
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.10.4-6.el7_9
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:0.10.23-25.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  0:1.16.1-8.el8_10
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:1.16.1-4.el8_4.2
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:1.16.1-4.el8_4.2
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:1.16.1-4.el8_6.2
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:1.16.1-4.el8_6.2
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service         unspecified  0:1.16.1-4.el8_8.2
  + 6 more
TIMELINE
  Jun 8   Reserved by CNA
  Jun 15  Published (CNA: redhat)
CWE-122 · CNA: redhat · 16 references · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-383299.847.1n/an/aCWE-862Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the A…
CVE-2026-497579.246.6team-alembicash_authenticationCWE-290OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
CVE-2016-200768.746.0ChrisHurstSimple BackupCWE-22WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and Download
CVE-2026-98638.845.6FortraCore Privileged Access Manager (BoKS)CWE-78Core Privileged Access Manager (BoKS) upgrade tooling command injection vulne…
CVE-2026-362137.845.2n/an/aCWE-269An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker t…
CVE-2026-508777.544.8n/an/aCWE-22An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory tr…
CVE-2026-488539.244.6elixir-grpcgrpcCWE-502Remote code execution and denial of service via unsafe Erlang term deserializ…
CVE-2026-4883610.044.6MantraBrainEasy InvoiceCWE-94WordPress Easy Invoice plugin <= 2.1.19 - Remote Code Execution (RCE) vulnera…
CVE-2026-508729.844.0n/an/aCWE-94An issue in the loopback request handling component of fossar selfoss v2.20-S…
CVE-2026-487237.842.6browserstackbrowserstack-cypress-cliCWE-78BrowserStack Cypress CL: Command Injection via cypress_config_file leads to a…
CVE-2026-499548.642.1Discuz!Discuz! X5.0CWE-98Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory
CVE-2026-121985.542.1n/aMicroweberCWE-22Microweber API Endpoint thumbnail_img userfiles_path path traversal
CVE-2026-390069.841.5n/an/aCWE-73An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary …
CVE-2026-365379.841.2n/an/aCWE-290ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAu…
CVE-2026-480178.841.2dbgatedbgateCWE-94DbGate: Remote Code Execution via functionName injection in loadReader endpoint
CVE-2026-497669.940.9WP User ManagerWP User ManagerCWE-22WordPress WP User Manager plugin <= 2.9.16 - Arbitrary File Deletion vulnerab…
CVE-2026-497819.840.6Brainstorm ForceOttoKitCWE-502WordPress OttoKit plugin <= 1.1.27 - PHP Object Injection vulnerability
CVE-2025-556426.540.6n/an/aCWE-369GPAC MP4Box v2.4 was discovered to contain a floating point exception in the …
CVE-2026-508897.539.5n/an/aCWE-400An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allo…
CVE-2026-96919.839.1CRM PerksIntegration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja FormsCWE-502WordPress Integration for ActiveCampaign and Contact Form 7, WPForms, Element…
CVE-2026-490859.839.1CRM PerksWP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja FormsCWE-502WordPress WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and…
CVE-2026-491049.839.1CRM PerksIntegration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja FormsCWE-502WordPress Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elem…
CVE-2026-491059.839.1CRM PerksWP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja FormsCWE-502WordPress WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and N…
CVE-2026-508809.839.1n/an/aCWE-94An issue in the sendmail transport integration component of YouTransfer v1.0.…
CVE-2026-395919.938.4CMSJunkie – WordPress Business Directory PluginsWP-BusinessDirectoryCWE-434WordPress WP-BusinessDirectory plugin <= 4.0.0 - Arbitrary File Upload vulner…
CVE-2026-394347.237.1WebAppickCTX FeedCWE-502WordPress CTX Feed plugin <= 6.6.26 - PHP Object Injection vulnerability
CVE-2026-394717.237.1ShortPixelShortPixel Image OptimizerCWE-502WordPress ShortPixel Image Optimizer plugin <= 6.4.3 - PHP Object Injection v…
CVE-2026-394727.237.1WP OvernightWooCommerce PDF Invoices & Packing SlipsCWE-502WordPress WooCommerce PDF Invoices & Packing Slips plugin < 5.9.0 - PHP Objec…
CVE-2026-394817.237.1WP ChillModula Image GalleryCWE-502WordPress Modula Image Gallery plugin <= 2.14.18 - PHP Object Injection vulne…
CVE-2026-394997.237.1Wombat PluginsAdvanced Product Fields (Product Addons) for WooCommerceCWE-502WordPress Advanced Product Fields (Product Addons) for WooCommerce plugin <= …
CVE-2026-54829.337.0TecrailResponsive FileManagerCWE-434Remote Code Execution via Unrestricted File Upload in Responsive FileManager
CVE-2026-407698.636.8Satinder SinghContact Form Extender for Divi &#8211; Save Entries, File Upload &amp; Country Code FieldCWE-22WordPress Contact Form Extender for Divi – Save Entries, File Upload & Countr…
CVE-2026-508739.836.7n/an/aCWE-434An arbitrary file upload vulnerability in the attachment handling component o…
CVE-2026-508787.536.7n/an/aCWE-400An issue in the attachment handling component of Feuerhamster MailForm v1.1.0…
CVE-2026-121618.836.5DevolutionsRemote Desktop ManagerCWE-78Improper input validation in the SSH Elevate Shell feature allows an authenti…
CVE-2026-527039.636.3Ninja TeamFastDupCWE-35WordPress FastDup plugin <= 2.7.2 - Path Traversal vulnerability
CVE-2026-394748.835.7metaphorcreationsPost DuplicatorCWE-502WordPress Post Duplicator plugin <= 3.0.10 - PHP Object Injection vulnerability
CVE-2026-394788.835.7Eli ScheetzAnti-Malware Security and Brute-Force FirewallCWE-502WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.87 - …
CVE-2026-426687.535.6OmnisendEmail Marketing for WooCommerce by OmnisendCWE-288WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.18.0 - Brok…
CVE-2026-487139.135.0i18nexti18next-fs-backendCWE-1321i18next-fs-backend: Prototype pollution via crafted missing-key string
CVE-2026-487149.135.0i18nexti18next-http-middlewareCWE-1321i18next-http-middleware missingKeyHandler does not reject keys whose segments…
CVE-2026-407767.534.5ArrayticsWP Event SOlutionCWE-862WordPress Eventin plugin <= 4.1.8 - Broken Access Control vulnerability
CVE-2026-488898.834.3TMSAmeliaCWE-266WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability
CVE-2026-424118.133.7XServerCloudSecure WP SecurityCWE-288WordPress CloudSecure WP Security plugin <= 1.4.7 - Broken Authentication vul…
CVE-2026-487087.533.4OliveTinOliveTinCWE-362OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cros…
CVE-2026-122035.533.4HKUDSAI-TraderCWE-200HKUDS AI-Trader Research Export agents.csv information disclosure
CVE-2026-497649.833.2MetagaussRegistrationMagicCWE-288WordPress RegistrationMagic plugin <= 6.0.8.6 - Broken Authentication vulnera…
CVE-2026-340286.932.9Wertheim GmbHWertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CWE-425Unauthenticated direct access to web data in Wertheim SafeController Software…
CVE-2026-340267.132.6Wertheim GmbHWertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CWE-23Path traversal in Wertheim SafeController Software allows authenticated users…
CVE-2026-388129.832.4n/an/aCWE-89RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable end…
CVE-2026-489708.132.5Really Simple PluginsReally Simple SSLCWE-288WordPress Really Simple SSL plugin <= 9.5.10 - Broken Authentication vulnerab…
CVE-2026-274077.232.5Meow AppsAI EngineCWE-266WordPress AI Engine plugin <= 3.4.9 - Privilege Escalation vulnerability
CVE-2026-527227.132.4Red HatRed Hat Enterprise Linux 10CWE-190Gstreamer1-plugins-bad-free: gstreamer: signed integer overflow in vmnc decod…
CVE-2016-200806.932.1BrandfolderBrandfolderCWE-98WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php
CVE-2026-423786.532.1ThemeisleWP Full Stripe FreeCWE-288WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnera…
CVE-2026-270539.831.8VideoWhisper.comBroadcast Live VideoCWE-502WordPress Broadcast Live Video plugin < 7.1.3 - PHP Object Injection vulnerab…
CVE-2026-490687.531.8RelyWPCoupon AffiliatesCWE-497WordPress Coupon Affiliates plugin <= 7.8.1 - Sensitive Data Exposure vulnera…
CVE-2026-527186.531.8Red HatRed Hat Enterprise Linux 10CWE-617Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_o…
CVE-2026-394507.131.7AmanFunnelKit AutomationsCWE-288WordPress FunnelKit Automations plugin <= 3.7.3 - Broken Authentication vulne…
CVE-2026-407857.131.7Ruben GarciaAutomatorWPCWE-288WordPress AutomatorWP plugin <= 5.6.7 - Broken Authentication vulnerability
CVE-2026-426618.831.5aguilatechnologiesWP Customer AreaCWE-35WordPress WP Customer Area plugin <= 8.3.4 - Path Traversal vulnerability
CVE-2026-491069.831.5CRM PerksIntegration for Contact Form 7 and Constant ContactCWE-502WordPress Integration for Contact Form 7 and Constant Contact plugin <= 1.1.6…
CVE-2026-491099.831.5crm perksIntegration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja FormsCWE-502WordPress Integration for Salesforce and Contact Form 7, WPForms, Elementor, …
CVE-2026-497639.831.5CRM PerksIntegration for Contact Form 7 HubSpotCWE-502WordPress Integration for Contact Form 7 HubSpot plugin <= 1.3.7 - PHP Object…
CVE-2026-497659.831.5CRM PerksIntegration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja FormsCWE-502WordPress Integration for Mailchimp and Contact Form 7, WPForms, Elementor, N…
CVE-2026-497689.831.5HappyformsHappyformsCWE-502WordPress Happyforms plugin <= 1.26.13 - PHP Object Injection vulnerability
CVE-2026-497699.831.5TomdeverwpForo ForumCWE-502WordPress wpForo Forum plugin <= 3.1.0 - PHP Object Injection vulnerability
CVE-2026-497709.831.5WP Travel EngineWP Travel EngineCWE-502WordPress WP Travel Engine plugin <= 6.7.12 - PHP Object Injection vulnerability
CVE-2026-394707.231.3Brainstorm ForceWooCommerce Cart Abandonment RecoveryCWE-266WordPress WooCommerce Cart Abandonment Recovery plugin < 2.1.0 - Privilege Es…
CVE-2026-394807.530.7InisevBackup MigrationCWE-201WordPress Backup Migration plugin <= 2.1.1 - Sensitive Data Exposure vulnerab…
CVE-2026-537057.630.6Red HatRed Hat Enterprise Linux 10CWE-190Gstreamer1-plugins-good: gstreamer: heap buffer overflow in wavpack decoder v…
CVE-2026-390077.530.6n/an/aCWE-200An issue in Observeinc's Observe v.2026-01-28 and before allows a remote atta…
CVE-2026-508839.630.5n/an/aCWE-79An HTML injection vulnerability in the /src/highlight.rs component of matze w…
CVE-2026-120879.130.5PEVANSSocketCWE-125Socket versions before 2.041 for Perl have an out-of-bounds heap read
CVE-2016-200776.930.6KaymeePhotographyPhotocart LinkCWE-98WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php
CVE-2026-453909.130.4n/an/aCWE-22In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its na…
CVE-2026-254257.530.4ThemeGrillUser RegistrationCWE-862WordPress User Registration plugin <= 5.1.2 - Broken Access Control vulnerabi…
CVE-2026-122112.030.3IntelbrasiNVU 7016 FTCWE-22Intelbras iNVU 7016 FT Web syslog path traversal
CVE-2026-122187.330.2YealinkSIP-T46UCWE-119Yealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation st…
CVE-2026-122207.330.2YealinkSIP-T46UCWE-119Yealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.…
CVE-2026-122217.330.2YealinkSIP-T46UCWE-119Yealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflow
CVE-2026-122227.330.2YealinkSIP-T46UCWE-119Yealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-base…
CVE-2026-481149.830.1NCEASmetacatCWE-89Metacat has an unauthenticated SQL injection vulnerability
CVE-2026-526978.530.1TaskbuilderTaskbuilderCWE-89WordPress Taskbuilder plugin <= 5.0.7 - SQL Injection vulnerability
CVE-2026-527008.530.1WcMultishipping – Mondial Relay & Chronopost for WooommerceWCMultiShippingCWE-89WordPress WCMultiShipping plugin <= 3.0.2 - SQL Injection vulnerability
CVE-2026-490567.529.6WebToffeeWooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping LabelsCWE-497WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shippin…
CVE-2026-394929.329.4Flipper Code – WordPress Development CompanyWP MapsCWE-89WordPress WP Maps plugin <= 4.9.1 - SQL Injection vulnerability
CVE-2026-394939.329.4NSquaredSimply Schedule AppointmentsCWE-89WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vul…
CVE-2026-490617.529.3WPCleverWPC Product Options for WooCommerceCWE-22WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary Fil…
CVE-2026-366708.829.2n/an/aCWE-89A Time-Based Blind SQL Injection vulnerability in the alias_management module…
CVE-2026-4077210.029.0AhmadGeekyBotCWE-434WordPress GeekyBot plugin <= 1.2.2 - Arbitrary File Upload vulnerability
CVE-2026-394987.229.0YeeaddonsYayMailCWE-502WordPress YayMail plugin <= 4.3.3 - PHP Object Injection vulnerability
CVE-2026-499536.929.0Discuz!Discuz! X5.0CWE-804Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set
CVE-2026-395839.828.8DatalogicsDatalogics Ecommerce DeliveryCWE-266WordPress Datalogics Ecommerce Delivery plugin <= 2.6.62 - Privilege Escalati…
CVE-2026-472617.528.8bytecodealliancewasmtimeCWE-284Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
CVE-2026-426867.128.5EventPrimeEventPrimeCWE-79WordPress EventPrime plugin <= 4.3.2.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-395156.528.3StylemixThemesMotorsCWE-862WordPress Motors plugin < 1.4.107 - Broken Access Control vulnerability
CVE-2026-534308.727.8elixir-grpcgrpcCWE-409grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
CVE-2026-488727.527.6WPDeveloperEmbedPressCWE-639WordPress EmbedPress plugin <= 4.5.2 - Sensitive Data Exposure vulnerability
CVE-2026-407966.527.5ollybachWPPizzaCWE-497WordPress WPPizza plugin <= 3.19.9 - Sensitive Data Exposure vulnerability
CVE-2026-426606.527.5Wasiliy StreckerContest GalleryCWE-497WordPress Contest Gallery plugin <= 28.1.7 - Sensitive Data Exposure vulnerab…
CVE-2026-488786.527.5Bootstrapped VenturesVisual Link PreviewCWE-497WordPress Visual Link Preview plugin <= 2.4.1 - Sensitive Data Exposure vulne…
CVE-2026-395328.827.4StiofanEvents Calendar for GeoDirectoryCWE-502WordPress Events Calendar for GeoDirectory plugin <= 2.3.25 - PHP Object Inje…
CVE-2026-488548.727.4elixir-grpcgrpcCWE-770Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc
CVE-2026-490837.527.4LatePointLatePointCWE-266WordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability
CVE-2026-407277.727.2GroundhoggGroundhoggCWE-22WordPress Groundhogg plugin <= 4.4 - Arbitrary File Deletion vulnerability
CVE-2026-527197.127.1Red HatRed Hat Enterprise Linux 10CWE-125Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment l…
CVE-2026-394894.426.7WP ChillDownload MonitorCWE-22WordPress Download Monitor plugin <= 5.1.9 - Non-Arbitrary File Download vuln…
CVE-2026-340237.126.4Wertheim GmbHWertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CWE-863Broken WebSocket authorization in Wertheim SafeController Software allows cro…
CVE-2026-407668.526.1StylemixThemesMasterStudy LMSCWE-89WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerability
CVE-2026-488748.526.1Ruben GarciaGamiPressCWE-89WordPress GamiPress plugin <= 7.8.7 - SQL Injection vulnerability
CVE-2026-488828.526.1codepeopleWP Time Slots Booking FormCWE-89WordPress WP Time Slots Booking Form plugin <= 1.2.50 - SQL Injection vulnera…
CVE-2026-489648.526.1ELEXtensionsELEX WordPress HelpDesk & Customer Ticketing SystemCWE-89WordPress ELEX WordPress HelpDesk & Customer Ticketing System plugin <= 3.3.6…
CVE-2026-487093.725.7OliveTinOliveTinCWE-862OliveTin: ValidateArgumentType API Endpoint Missing Authentication Allows Act…
CVE-2026-118329.125.6BIAFRADancer2::Plugin::Auth::OAuthCWE-338Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predi…
CVE-2016-200758.725.6EtoilewebdesignUltimate Product CatalogCWE-863WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
CVE-2026-407797.725.5Yannick LefebvreLink LibraryCWE-22WordPress Link Library plugin <= 7.8.8 - Arbitrary File Deletion vulnerability
CVE-2026-340306.925.5Wertheim GmbHWertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CWE-73Improper branch-code validation in Wertheim SafeController Software allows fi…
CVE-2026-508918.125.4n/an/aCWE-284Incorrect access control in the /admin/api/config component of Filestash v0.4…
CVE-2026-491127.525.4TammersoftShared FilesCWE-35WordPress Shared Files plugin <= 1.7.64 - Path Traversal vulnerability
CVE-2016-200826.925.4abtestAbtestCWE-98WordPress Plugin Abtest Local File Inclusion via abtest_admin.php
CVE-2025-693326.525.4myCredBookifyCWE-862WordPress Bookify plugin <= 1.1.1 - Broken Access Control vulnerability
CVE-2026-395846.525.4Webful CreationsRepairBuddyCWE-862WordPress RepairBuddy plugin <= 4.1132 - Broken Access Control vulnerability
CVE-2026-407906.525.4VeronaLabsWP SMSCWE-288WordPress WP SMS plugin <= 7.2.1 - Sensitive Data Exposure vulnerability
CVE-2026-489656.525.4watchfulXClonerCWE-201WordPress XCloner plugin <= 4.8.6 - Sensitive Data Exposure vulnerability
CVE-2026-301219.125.2n/an/aCWE-123remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file wr…
CVE-2026-508797.525.2n/an/aCWE-400An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.…
CVE-2026-508827.525.2n/an/aCWE-400An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows a…
CVE-2026-122005.525.2RitlabsTinyWeb ServerCWE-119Ritlabs TinyWeb Server Header libeay32.dll.html stack-based overflow
CVE-2026-349019.824.9PauliControlWPCWE-266WordPress iControlWP plugin <= 5.5.3 - Privilege Escalation vulnerability
CVE-2026-391969.824.9n/an/aCWE-89Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnera…
CVE-2026-508909.824.9n/an/aCWE-89Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerabi…
CVE-2026-273338.124.5VideoWhisper.comPaid Videochat Turnkey SiteCWE-502WordPress Paid Videochat Turnkey Site plugin <= 7.3.23 - Deserialization of u…
CVE-2026-426878.124.5EventPrimeEventPrimeCWE-502WordPress EventPrime plugin <= 4.3.2.1 - PHP Object Injection vulnerability
CVE-2026-426626.524.3Liquid Web / StellarWPEvent TicketsCWE-290WordPress Event Tickets plugin <= 5.27.5 - Bypass Vulnerability vulnerability
CVE-2026-122085.524.1jsonata-jsjsonataCWE-94jsonata-js jsonata Function Binding Frame System jsonata.js createFrame proto…
CVE-2026-122095.524.1RubyLouvreavalonCWE-94RubyLouvre avalon Template Filter index.js prototype pollution
CVE-2026-508869.123.9n/an/aCWE-284Incorrect access control in the webhook management component of Project Firef…
CVE-2016-200718.824.0404-redirection-manager404 Redirection ManagerCWE-89WordPress 404 Redirection Manager Plugin 1.0 SQL Injection
CVE-2026-407995.323.6RelyWPSimple Cloudflare TurnstileCWE-288WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authenticatio…
CVE-2026-508707.523.4n/an/aCWE-200An information disclosure vulnerability in the configuration endpoint of Ben …
CVE-2026-407887.123.3QuantumCloudChatBotCWE-862WordPress ChatBot plugin <= 7.9.7 - Broken Access Control vulnerability
CVE-2026-395347.523.2Wp Directory KitWP Directory KitCWE-862WordPress WP Directory Kit plugin <= 1.5.0 - Broken Access Control vulnerability
CVE-2026-5270410.023.1Edgar RojasWooCommerce PDF Invoice BuilderCWE-94WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Remote Code Execu…
CVE-2026-488357.523.1AwesomemotiveContact Form by WPFormsCWE-862WordPress Contact Form by WPForms plugin <= 1.10.0.4 - Broken Access Control …
CVE-2026-340275.323.1Wertheim GmbHWertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CWE-434Upload restriction bypass in Wertheim SafeController Software allows authenti…
CVE-2026-52428.823.0MIA Technology Inc.Pizzy LibraryCWE-1236Code Injection in Mia Technologies' Pizzy Library
CVE-2026-340248.623.0Wertheim GmbHWertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CWE-862Missing authorization checks in Wertheim SafeController Software allow low-pr…
CVE-2026-395337.523.0WPTastyAWP ClassifiedsCWE-862WordPress AWP Classifieds plugin <= 4.4.4 - Broken Access Control vulnerability
CVE-2026-478357.523.0SpringSpring AICWE-943Spring AI vector store metadata filtering to handle special characters in Ela…
CVE-2026-348917.522.8IDPayIDPay Payment Gateway for WoocommerceCWE-497WordPress IDPay Payment Gateway for Woocommerce plugin <= 2.2.5 - Sensitive D…
CVE-2016-200688.822.8dwboosterBooking Calendar Contact FormCWE-89WordPress Booking Calendar Contact Form 1.0.23 SQL Injection
CVE-2026-395309.322.1SpeakOut!SpeakOut! Email PetitionsCWE-89WordPress SpeakOut! Email Petitions plugin <= 4.6.5 - SQL Injection vulnerabi…
CVE-2026-395119.322.0Jacob N. BreetveltWP Photo Album PlusCWE-89WordPress WP Photo Album Plus plugin <= 9.1.08.001 - SQL Injection vulnerability
CVE-2026-348926.522.1Rank Math SEORank Math SEOCWE-862WordPress Rank Math SEO plugin <= 1.0.271 - Broken Access Control vulnerability
CVE-2026-407817.521.9ReviewXReviewXCWE-288WordPress ReviewX plugin <= 2.3.6 - Broken Authentication vulnerability
CVE-2026-407897.521.9TMSAmeliaCWE-201WordPress Amelia plugin <= 2.2 - Sensitive Data Exposure vulnerability
CVE-2026-423847.521.9NSquaredSimply Schedule AppointmentsCWE-201WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exp…
CVE-2026-426677.521.9BooklyBooklyCWE-201WordPress Bookly plugin <= 27.4 - Sensitive Data Exposure vulnerability
CVE-2026-490667.521.9Conekta GroupConekta Payment GatewayCWE-497WordPress Conekta Payment Gateway plugin <= 6.0.0 - Sensitive Data Exposure v…
CVE-2026-395029.321.810WebForm Maker by 10WebCWE-89WordPress Form Maker by 10Web plugin <= 1.15.38 - SQL Injection vulnerability
CVE-2026-122045.521.7n/aShopXOCWE-285ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization
CVE-2026-454399.321.6RealtynaRealtyna Organic IDX pluginCWE-89WordPress Realtyna Organic IDX plugin plugin <= 5.1.0 - SQL Injection vulnera…
CVE-2026-395275.421.6sc Internet VivooWpStreamCWE-434WordPress WpStream plugin < 4.11.2 - Arbitrary File Upload vulnerability
CVE-2026-490628.821.5WP EngineFaust.jsCWE-288WordPress Faust.js plugin <= 1.8.7 - Broken Authentication vulnerability
CVE-2026-490679.321.4yydevelopmentAdvanced 301 and 302 RedirectCWE-89WordPress Advanced 301 and 302 Redirect plugin <= 1.6.9 - SQL Injection vulne…
CVE-2026-497769.321.4JExtensions StoreGPTranslate – Multilingual AI Translation for WordPress: Automatically Translate WebsitesCWE-89WordPress GPTranslate – Multilingual AI Translation for WordPress: Automatica…
CVE-2026-526939.321.4impleCodeeCommerce Product CatalogCWE-89WordPress eCommerce Product Catalog plugin <= 3.5.5 - SQL Injection vulnerabi…
CVE-2026-122059.121.4TIMLEGGECrypt::DSACWE-323Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, …
CVE-2026-391976.521.4n/an/aCWE-400An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0…
CVE-2026-508879.121.2n/an/aCWE-918A Server-Side Request Forgery (SSRF) in the automatic short URL title resolut…
CVE-2018-254378.721.2CherryframeworkCherry Framework ThemesCWE-306WordPress CherryFramework Themes 3.1.4 Backup File Download
CVE-2025-591337.521.2ProjectopiaProjectopiaCWE-639WordPress Projectopia plugin <= 5.1.25.2 - Insecure Direct Object References …
CVE-2026-395137.521.2Easy AppointmentsEasy AppointmentsCWE-862WordPress Easy Appointments plugin <= 3.12.21 - Broken Access Control vulnera…
CVE-2026-407677.521.2TomdeverwpForo ForumCWE-281WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability
CVE-2026-508857.521.2n/an/aCWE-284Incorrect access control in the share-based read endpoints of Sismics Docs (T…
CVE-2026-395946.421.2ThemeficUltra Addons for WPFormsCWE-862WordPress Ultra Addons for WPForms plugin <= 1.0.11 - Broken Access Control v…
CVE-2026-508848.821.1n/an/aCWE-284Incorrect access control in statping-ng v0.93.0 allows attackers to escalate …
CVE-2025-556455.521.1n/an/aCWE-122A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.…
CVE-2025-556485.521.1n/an/aCWE-122A heap buffer overflow in the gf_opus_parse_packet_header function (media_too…
CVE-2025-687138.020.9n/an/aCWE-926An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android …
CVE-2026-441885.320.9Red HatRed Hat Ansible Automation Platform 2.7CWE-613Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized da…
CVE-2026-394419.320.8Naked Cat Plugins (by Webdados)Feed KuantoKusta for WooCommerce – FreeCWE-89WordPress Feed KuantoKusta for WooCommerce – Free plugin <= 5.3 - SQL Injecti…
CVE-2026-395129.320.8PaoloGeoDirectoryCWE-89WordPress GeoDirectory plugin <= 2.8.152 - SQL Injection vulnerability
CVE-2026-395199.320.8AhmadGeekyBotCWE-89WordPress GeekyBot plugin <= 1.2.0 - SQL Injection vulnerability
CVE-2026-407719.320.8Wasiliy StreckerContest GalleryCWE-89WordPress Contest Gallery plugin <= 28.1.6 - SQL Injection vulnerability
CVE-2026-407989.320.8TomdeverwpForo ForumCWE-89WordPress wpForo Forum plugin <= 3.0.4 - SQL Injection vulnerability
CVE-2026-423819.320.8FunnelKitFunnel Builder by FunnelKitCWE-89WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.1 - SQL Injection vuln…
CVE-2026-423869.320.8tychesoftwaresOrder Delivery Date for WooCommerceCWE-89WordPress Order Delivery Date for WooCommerce plugin <= 4.5.1 - SQL Injection…
CVE-2026-426399.320.8Dev4PressGD Rating SystemCWE-89WordPress GD Rating System plugin <= 3.6.2 - SQL Injection vulnerability
CVE-2026-426659.320.8Passionate Programmer PeterWP Data AccessCWE-89WordPress WP Data Access plugin <= 5.5.70 - SQL Injection vulnerability
CVE-2026-488869.320.8AhmadJS Help DeskCWE-89WordPress JS Help Desk plugin <= 3.0.9 - SQL Injection vulnerability
CVE-2026-497808.820.8Dokan, Inc.DokanCWE-266WordPress Dokan plugin <= 5.0.2 - Privilege Escalation vulnerability
CVE-2026-395878.120.8Hakan OzevinWP BASE BookingCWE-266WordPress WP BASE Booking plugin <= 5.9.0 - Privilege Escalation vulnerability
CVE-2026-340255.320.8Wertheim GmbHWertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CWE-290IP restriction bypass in Wertheim SafeController Software allows logins from …
CVE-2026-508758.120.7n/an/aCWE-284Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 …
CVE-2026-407736.520.4rtCamp Inc.rtMedia for WordPress, BuddyPress and bbPressCWE-862WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.9 - Bro…
CVE-2026-407936.520.4GroundhoggGroundhoggCWE-862WordPress Groundhogg plugin < 4.4.1 - Broken Access Control vulnerability
CVE-2026-407946.520.4myCredmyCredCWE-862WordPress myCred plugin <= 3.0.3 - Broken Access Control vulnerability
CVE-2026-488819.120.3themetechmountTrueBookerCWE-862WordPress TrueBooker plugin <= 1.1.9 - Broken Access Control vulnerability
CVE-2026-395798.820.2bPluginsB BlocksCWE-266WordPress B Blocks plugin <= 2.0.31 - Privilege Escalation vulnerability
CVE-2026-50387.520.3multermulterCWE-459multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
CVE-2026-50797.520.3multermulterCWE-400multer vulnerable to Denial of Service via deeply nested field names
CVE-2026-417087.520.2SpringSpring Cloud SleuthCWE-400Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability
CVE-2026-426667.520.3Dimitri GrassiSalon booking systemCWE-862WordPress Salon booking system plugin <= 10.30.25 - Broken Access Control vul…
CVE-2026-488687.520.3mra13 / Team Tips and Tricks HQSimple Shopping CartCWE-639WordPress Simple Shopping Cart plugin <= 5.2.9 - Insecure Direct Object Refer…
CVE-2026-395187.120.2EventPrimeEventPrimeCWE-639WordPress EventPrime plugin <= 4.3.0.0 - Insecure Direct Object References (I…
CVE-2026-106345.319.8zephyrprojectzephyrCWE-416Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_…
CVE-2026-485997.619.7elixir-grpcgrpcCWE-639Authorization bypass via path binding override in elixir-grpc/grpc HTTP trans…
CVE-2026-407956.519.3TMSAmeliaCWE-862WordPress Amelia plugin <= 2.2 - Broken Access Control vulnerability
CVE-2026-426596.519.3Nasir AhmedAdvanced Form IntegrationCWE-862WordPress Advanced Form Integration plugin <= 1.126.12 - Broken Access Contro…
CVE-2016-200728.819.3bbsethemeBBS e-FranchiseCWE-89BBS e-Franchise 1.1.1 WordPress Plugin SQL Injection via uid
CVE-2016-200738.819.3mattkayeAnswer My QuestionCWE-89Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php
CVE-2026-89359.819.0UnknownWP MAPS PROAdvanced Google Maps < 6.1.1 - Unauthenticated Administrator Account Creation
CVE-2026-270897.518.9Magepeople inc.WpTravellyCWE-290WordPress WpTravelly plugin <= 2.1.7 - Bypass Vulnerability vulnerability
CVE-2026-92587.118.9Canon Inc.EOS Network Setting Tool for WindowsCWE-295Improper validation of SSH host keys in Canon EOS Network Setting Tool Versio…
CVE-2026-490827.418.3Chatway Live ChatChatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat ButtonsCWE-201WordPress Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Cu…
CVE-2026-92627.118.3Canon Inc.EOS Network Setting Tool for WindowsCWE-1188Use of a non-secure protocol as the default FTP configuration in Canon EOS Ne…
CVE-2026-454417.517.7Magepeople inc.WpEventlyCWE-1284WordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerability
CVE-2026-489696.517.5Really Simple Plugins B.V.Really Simple SSLCWE-862WordPress Really Simple SSL plugin <= 9.5.9 - Broken Access Control vulnerabi…
CVE-2025-556525.517.2n/an/aCWE-122A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ex…
CVE-2025-556605.517.2n/an/aCWE-121A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.…
CVE-2025-556615.517.2n/an/aCWE-122A heap buffer overflow in the Opus audio stream parser component of GPAC MP4B…
CVE-2026-426648.217.1Motive Commerce SearchAI Product Search for WooCommerce &#8211; Motive Commerce SearchCWE-862WordPress AI Product Search for WooCommerce – Motive Commerce Search plugin <…
CVE-2026-246378.516.9Blubrry PodcastingPowerPress PodcastingCWE-89WordPress PowerPress Podcasting plugin <= 11.15.10 - SQL Injection vulnerability
CVE-2026-490787.516.8WP Travel EngineWP Travel EngineCWE-1284WordPress WP Travel Engine plugin <= 6.7.10 - Other Vulnerability Type vulner…
CVE-2026-407436.516.8ThemeumTutor LMSCWE-862WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability
CVE-2026-348867.516.7wp.insiderSimple MembershipCWE-862WordPress Simple Membership plugin <= 4.7.1 - Broken Access Control vulnerabi…
CVE-2026-407627.516.7WPGraphQLWPGraphQLCWE-89WordPress WPGraphQL plugin < 2.11.1 - SQL Injection vulnerability
CVE-2026-407926.316.5Iqonic DesignKiviCareCWE-639WordPress KiviCare plugin <= 4.2.1 - Insecure Direct Object References (IDOR)…
CVE-2026-426555.916.5WPManageNinjaBest Payments Plugin for WPCWE-472WordPress Best Payments Plugin for WP plugin <= 4.6.19 - Payment Bypass vulne…
CVE-2026-508818.116.3n/an/aCWE-284Incorrect access control in the impworks Bonsai v6.0 allows authenticated att…
CVE-2026-508888.116.3n/an/aCWE-918An authenticated Server-Side Request Forgery (SSRF) in the custom scraper sub…
CVE-2026-348987.516.1WP SwingsEvent Tickets Manager for WooCommerceCWE-862WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.3 - Broken Acce…
CVE-2026-395037.516.0AwesomemotiveEasy Digital DownloadsCWE-862WordPress Easy Digital Downloads plugin <= 3.6.5 - Broken Access Control vuln…
CVE-2026-395247.516.0ThemeGrillMasteriyo - LMSCWE-862WordPress Masteriyo - LMS plugin <= 2.1.5 - Payment Bypass vulnerability
CVE-2026-407417.516.0Jose ContiRedsys for WooCommerce LightCWE-862WordPress Redsys for WooCommerce Light plugin <= 7.0.0 - Broken Access Contro…
CVE-2026-537037.115.9Red HatRed Hat Enterprise Linux 10CWE-125Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demu…
CVE-2016-200845.115.9dwboosterBooking Calendar ContactCWE-79WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS
CVE-2026-526957.515.7Al MonsorABC Crypto CheckoutCWE-201WordPress ABC Crypto Checkout plugin <= 1.8.2 - Sensitive Data Exposure vulne…
CVE-2025-556415.515.7n/an/aCWE-476A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia…
CVE-2025-556435.515.7n/an/aCWE-476A NULL pointer dereference in the TrackWriter handling component (filters/mux…
CVE-2025-556445.515.7n/an/aCWE-416A heap use-after-free in the gf_node_get_tag function (scenegraph/base_sceneg…
CVE-2025-556475.515.7n/an/aCWE-190An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c…
CVE-2025-556495.515.7n/an/aCWE-476A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom…
CVE-2025-556505.515.7n/an/aCWE-416A heap use-after-free in the gf_node_get_tag function (scenegraph/base_sceneg…
CVE-2025-556635.515.7n/an/aCWE-476A segmentation violation in the Track_SetStreamDescriptor function (isomedia/…
CVE-2026-395256.515.6Booking Activities TeamBooking ActivitiesCWE-862WordPress Booking Activities plugin <= 1.16.48.1 - Broken Access Control vuln…
CVE-2026-407826.515.6Greg WiniarskiWPAdvertsCWE-862WordPress WPAdverts plugin <= 2.3.0 - Broken Access Control vulnerability
CVE-2025-680496.315.6bunny.netbunny.netCWE-862WordPress bunny.net plugin <= 2.3.6 - Broken Access Control vulnerability
CVE-2026-426516.315.6Mamunur RashidClassified ListingCWE-862WordPress Classified Listing plugin <= 5.3.9 - Broken Access Control vulnerab…
CVE-2016-200698.815.4dwboosterBooking Calendar Contact FormCWE-89WordPress Booking Calendar Contact Form 1.0.23 SQL Injection
CVE-2026-491118.815.1ThemeGrillMasteriyo - LMSCWE-266WordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerability
CVE-2026-407747.515.1SaasProjectBooking PackageCWE-862WordPress Booking Package plugin <= 1.7.06 - Broken Access Control vulnerability
CVE-2026-488737.515.1MontonioMontonio for WooCommerceCWE-862WordPress Montonio for WooCommerce plugin <= 10.1.2 - Broken Access Control v…
CVE-2026-488837.515.1WPCleverWPC Product Bundles for WooCommerceCWE-862WordPress WPC Product Bundles for WooCommerce plugin <= 8.5.3 - Broken Access…
CVE-2026-490647.515.0StiofanGetPaidCWE-201WordPress GetPaid plugin <= 2.8.49 - Sensitive Data Exposure vulnerability
CVE-2026-490707.515.1Knit PayKnit PayCWE-862WordPress Knit Pay plugin <= 9.4.0.0 - Broken Access Control vulnerability
CVE-2026-526927.515.0wp.insiderAffiliates ManagerCWE-201WordPress Affiliates Manager plugin <= 2.9.50 - Sensitive Data Exposure vulne…
CVE-2026-526947.515.0WP E-SignatureSignature Add-On for WooCommerceCWE-497WordPress Signature Add-On for WooCommerce plugin <= 2.0 - Sensitive Data Exp…
CVE-2026-490658.215.0hippoooHippoo Mobile App for WooCommerceCWE-862WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.5 - Broken Access C…
CVE-2026-239707.114.9ThemeisleRedirection for Contact Form 7CWE-79WordPress Redirection for Contact Form 7 plugin <= 3.2.8 - Cross Site Scripti…
CVE-2026-394477.114.9NSquaredSimply Schedule AppointmentsCWE-79WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Script…
CVE-2026-488387.114.9WPExpertsPost SMTPCWE-79WordPress Post SMTP plugin <= 3.6.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-491107.514.8WP SwingsUpsell Order Bump Offer for WooCommerceCWE-1284WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.4 - Price Man…
CVE-2026-426886.514.9WP ChillModula Image GalleryCWE-79WordPress Modula Image Gallery plugin <= 2.14.23 - Cross Site Scripting (XSS)…
CVE-2026-118607.514.7OpenSolutionQuick.CMSCWE-94Insecure Deserialisation via Plaintext HTTP leading to Remote Code Execution …
CVE-2026-488876.514.7AhmadJS Help DeskCWE-862WordPress JS Help Desk plugin <= 3.0.9 - Broken Access Control vulnerability
CVE-2026-92606.914.3Canon Inc.EOS Network Setting Tool for WindowsCWE-798Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Versio…
CVE-2016-200705.114.2dwboosterBooking Calendar Contact FormCWE-79WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS
CVE-2026-526997.514.1e4jvikwpVikRentCarCWE-639WordPress VikRentCar plugin <= 1.4.5 - Insecure Direct Object References (IDO…
CVE-2026-394497.114.1IT Path SolutionsContact Form to Any APICWE-79WordPress Contact Form to Any API plugin <= 3.0.3 - Cross Site Scripting (XSS…
CVE-2026-394637.114.1ManageWPManageWP WorkerCWE-79WordPress ManageWP Worker plugin <= 4.9.31 - Cross Site Scripting (XSS) vulne…
CVE-2026-488717.114.1Takashi KitajimaMW WP FormCWE-79WordPress MW WP Form plugin <= 5.1.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-490557.114.1Glen Don MongayaDrag and Drop Multiple File Upload – Contact Form 7CWE-79WordPress Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.9…
CVE-2026-394916.514.0artbeesJupiterX CoreCWE-79WordPress JupiterX Core plugin <= 4.14.1 - Cross Site Scripting (XSS) vulnera…
CVE-2026-537047.113.8Red HatRed Hat Enterprise Linux 10.0 Extended Update SupportCWE-125Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demu…
CVE-2026-122102.113.8universal-tool-calling-protocolpython-utcpCWE-918universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-si…
CVE-2019-257467.113.5SlicedInvoicesSliced InvoicesCWE-89WordPress Sliced Invoices 3.8.2 SQL Injection via post Parameter
CVE-2026-122072.113.5medkey-orgmedkeyCWE-99medkey-org medkey HTTP REST API PatientController.php actionGetPatientById re…
CVE-2026-453889.113.4n/an/aCWE-295In OCaml-TLS before 2.1.0, the client implementation does insufficient checks…
CVE-2026-407757.313.2Royal PluginsRoyal MCPCWE-862WordPress Royal MCP plugin <= 1.4.2 - Broken Access Control vulnerability
CVE-2026-427526.513.0mra13 / Team Tips and Tricks HQStripe PaymentsCWE-440WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerability
CVE-2026-426575.312.7Wasiliy StreckerContest GalleryCWE-1284WordPress Contest Gallery plugin <= 28.1.7 - Other Vulnerability Type vulnera…
CVE-2026-254405.312.0WPDeveloperEssential Addons for ElementorCWE-862WordPress Essential Addons for Elementor plugin < 6.6.0 - Broken Access Contr…
CVE-2026-122021.912.1IntelliantsSubrion CMSCWE-79Intelliants Subrion CMS Blocks Endpoint cross site scripting
CVE-2026-490637.311.8Webilia Inc.ListdomCWE-266WordPress Listdom plugin <= 5.5.0 - Privilege Escalation vulnerability
CVE-2026-407917.111.5codepeopleWP Time Slots Booking FormCWE-79WordPress WP Time Slots Booking Form plugin <= 1.2.46 - Cross Site Scripting …
CVE-2026-122122.111.1hcengineeringHuly PlatformCWE-266hcengineering Huly Platform RPC operations.ts getMailboxSecret access control
CVE-2026-52337.110.8MIA Technology Inc.Pizzy LibraryCWE-799Missing Rate Limiting in Mia Technologies' Pizzy Library
CVE-2026-395406.510.8Amit MittalShipment Tracker for WoocommerceCWE-79WordPress Shipment Tracker for Woocommerce plugin <= 1.5.3.2 - Cross Site Scr…
CVE-2026-415566.510.8properfractionProfilePressCWE-79WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnera…
CVE-2026-426566.510.8Wasiliy StreckerContest GalleryCWE-79WordPress Contest Gallery plugin <= 28.1.6 - Cross Site Scripting (XSS) vulne…
CVE-2026-488706.510.8King AddonsKing Addons for ElementorCWE-79WordPress King Addons for Elementor plugin <= 51.1.62 - Cross Site Scripting …
CVE-2026-488806.510.8AhmadWP Job PortalCWE-79WordPress WP Job Portal plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-122132.110.6hcengineeringHuly PlatformCWE-266hcengineering Huly Platform User Information operations.ts getAccountInfo imp…
CVE-2026-86836.510.1MattermostMattermostCWE-770Overly long URLs crash the Mattermost Desktop App
CVE-2026-340218.69.7Wertheim GmbHWertheim SafeController 5400 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)CWE-294Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-4…
CVE-2025-642156.59.7StylemixThemesMasterStudy LMS ProCWE-862WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnera…
CVE-2026-122062.19.7Grit42GritCWE-74Grit42 Grit data_table_entity.rb DataTableEntity sql injection
CVE-2026-426507.29.6Ruben GarciaAutomatorWPCWE-79WordPress AutomatorWP plugin <= 5.6.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-92597.19.5Canon Inc.EOS Network Setting Tool for WindowsCWE-295Improper validation of server certificates in Canon EOS Network Setting Tool …
CVE-2016-200665.19.2dwboosterCP PollsCWE-79WordPress CP Polls 1.0.8 Persistent Cross-Site Scripting
CVE-2026-453897.49.1n/an/aCWE-295In OCaml-TLS before 2.1.0, the server implementation does insufficient checks…
CVE-2026-497756.59.0info@welcartWelcart e-CommerceCWE-862WordPress Welcart e-Commerce plugin <= 2.11.28 - Broken Access Control vulner…
CVE-2026-426406.58.8Mamunur RashidClassified ListingCWE-862WordPress Classified Listing plugin <= 5.3.8 - Broken Access Control vulnerab…
CVE-2026-65177.78.6MattermostMattermostCWE-522Mattermost Desktop App fails to restrict the allow list of domains which NTLM…
CVE-2025-688517.18.5ArrayHQOkay ToolkitCWE-79WordPress Okay Toolkit plugin <= 2.3 - Reflected Cross Site Scripting (XSS) v…
CVE-2026-92617.68.3Canon Inc.EOS Network Setting Tool for WindowsCWE-327Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Ve…
CVE-2026-365216.18.0n/an/aCWE-79PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the s…
CVE-2026-372166.18.0n/an/aCWE-79Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /sys…
CVE-2025-688407.17.2markbeljaarsiRobots.txt SEOCWE-79WordPress iRobots.txt SEO plugin <= 1.1.2 - Reflected Cross Site Scripting (X…
CVE-2025-688727.17.2EliEli&#039;s WordCents adSense Widget with AnalyticsCWE-79WordPress Eli's WordCents adSense Widget with Analytics plugin <= 1.3.03.27 -…
CVE-2026-349007.17.2Liquid Web / StellarWPGiveWPCWE-79WordPress GiveWP plugin <= 4.14.2 - Reflected Cross Site Scripting (XSS) vuln…
CVE-2026-349027.17.2WC Product TableWooCommerce Product Table LiteCWE-79WordPress WooCommerce Product Table Lite plugin <= 4.6.3 - Cross Site Scripti…
CVE-2026-394357.17.2bgermannCformsIICWE-79WordPress CformsII plugin <= 15.1.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-395077.17.2ThemeisleSocial Slider FeedCWE-79WordPress Social Slider Feed plugin <= 2.3.2 - Cross Site Scripting (XSS) vul…
CVE-2026-395147.17.2CozmoslabsPaid Member SubscriptionsCWE-79WordPress Paid Member Subscriptions plugin <= 2.17.3 - Reflected Cross Site S…
CVE-2026-407327.17.3rainafaraiNotification for TelegramCWE-79WordPress Notification for Telegram plugin <= 3.5 - Cross Site Scripting (XSS…
CVE-2026-407707.17.3RelyWPCoupon AffiliatesCWE-79WordPress Coupon Affiliates plugin <= 7.5.3 - Cross Site Scripting (XSS) vuln…
CVE-2026-407877.17.3ExpressTechQuiz And Survey MasterCWE-79WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS…
CVE-2026-426497.17.2ArchetypedFavicon RotatorCWE-79WordPress Favicon Rotator plugin <= 1.2.11 - Cross Site Scripting (XSS) vulne…
CVE-2026-426587.17.2Mamunur RashidClassified ListingCWE-79WordPress Classified Listing plugin <= 5.3.8 - Cross Site Scripting (XSS) vul…
CVE-2026-427757.17.2Ruben GarciaAutomatorWPCWE-79WordPress AutomatorWP plugin <= 5.7.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-454377.17.2Bhavin ThummarProduct Filter Widget for ElementorCWE-79WordPress Product Filter Widget for Elementor plugin <= 1.0.6 - Cross Site Sc…
CVE-2026-488677.17.2ExpressTechQuiz And Survey MasterCWE-79WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS…
CVE-2026-488767.17.2Web GuyStop SpammersCWE-79WordPress Stop Spammers plugin <= 2026.3 - Cross Site Scripting (XSS) vulnera…
CVE-2026-488857.17.2GroundhoggHollerBoxCWE-79WordPress HollerBox plugin <= 2.3.10.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-489667.17.2FunnelKitFunnel Builder by FunnelKitCWE-79WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.2 - Cross Site Scripti…
CVE-2026-394516.37.2jgwhite33WP Google Review SliderCWE-79WordPress WP Google Review Slider plugin <= 18.0 - Cross Site Scripting (XSS)…
CVE-2026-52307.17.2MIA Technology Inc.Pizzy LibraryCWE-284Improper Access Control in Mia Technologies' Pizzy Library
CVE-2026-369336.87.1n/an/aCWE-284An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically prox…
CVE-2026-485184.36.9juice-shopmulti-juicerCWE-352MultiJuicer: Login CSRF allows attacker to force victims into their team
CVE-2026-508926.56.9n/an/aCWE-284Incorrect access control in the "Let's Encrypt" certificate download endpoint…
CVE-2026-83585.46.9The Document FoundationLibreOfficeCWE-787Heap buffer overflow in spreadsheet tracked-changes import
CVE-2025-701026.36.6n/an/aCWE-476A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd …
CVE-2025-601754.46.5vynnusPopAdCWE-918WordPress PopAd Plugin <= 1.0.4 - Server Side Request Forgery (SSRF) Vulnerab…
CVE-2026-477777.56.4mastodonmastodonCWE-345Mastodon has a consent-check bypass in its remote Collections
CVE-2026-481576.16.4slimphpSlimCWE-79Slim has Reflected XSS in the HtmlErrorRenderer
CVE-2026-497736.56.4FolioVisionFV Flowplayer Video PlayerCWE-79WordPress FV Flowplayer Video Player plugin < 7.5.51.7212 - Cross Site Script…
CVE-2025-568147.86.2n/an/aCWE-77A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0…
CVE-2026-95954.36.0webpack-dev-serverwebpack-dev-serverCWE-346webpack-dev-server vulnerable to HMR WebSocket interception via permissive us…
CVE-2026-508765.45.9n/an/aCWE-79A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attac…
CVE-2026-426636.55.8wp.insiderSimple MembershipCWE-79WordPress Simple Membership plugin <= 4.7.2 - Cross Site Scripting (XSS) vuln…
CVE-2026-92785.45.6UnknownForm Builder CPForm Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure
CVE-2026-60395.45.4The Document FoundationLibreOfficeCWE-197Heap buffer overflow in DXF polyline import
CVE-2026-83575.45.3The Document FoundationLibreOfficeCWE-193Heap buffer overflow in Calc formula compilation
CVE-2026-490434.75.0WP EngineWP Migrate LiteCWE-352WordPress WP Migrate Lite plugin <= 2.7.8 - Cross Site Request Forgery (CSRF)…
CVE-2026-492946.14.6valhallavalhallaCWE-79Valhalla has reflected XSS via unsanitized JSONP callback parameter
CVE-2026-121625.54.5DevolutionsRemote Desktop ManagerCWE-297Improper host validation in the social login autofill feature in Devolutions …
CVE-2026-527027.14.3wp-buySEO RedirectionCWE-79WordPress SEO Redirection plugin <= 9.17 - Cross Site Scripting (XSS) vulnera…
CVE-2026-481248.54.2cursorcursorCWE-94Cursor Desktop sandbox escape via Claude hook configuration
CVE-2026-427436.54.2ThemeGrillMasteriyo - LMSCWE-347WordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerability
CVE-2025-156585.93.8rewishWP EmmetCWE-79WordPress WP Emmet plugin <= 0.3.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-478258.63.8SpringSpring Cloud GatewayCWE-346Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certai…
CVE-2016-200836.93.7henrikmelinMore FieldsCWE-352WordPress More Fields Plugin 2.1 Cross-Site Request Forgery
CVE-2026-501008.53.2Ricoh Company, Ltd.Multiple printer driversCWE-427Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA J…
CVE-2025-156596.53.1liseperuElizaibotsCWE-79WordPress Elizaibots plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-120577.83.0Foxit Software Inc.Foxit AICWE-829DoS + Remote Code Execution via PDF JavaScript in Foxit AI
CVE-2026-122147.12.6Qihoo360 Total SecurityCWE-693Qihoo 360 Total Security Nucleus Engine Monitoring Logic RpcStringBindingComp…
CVE-2026-119316.82.4AWSKiro IDECWE-276Insecure Permissions on Authentication Token Cache File in Kiro IDE
CVE-2026-340296.82.1Wertheim GmbHWertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CWE-321Hard-coded cryptographic key in Wertheim SafeController Software allows decry…
CVE-2026-60455.42.1The Document FoundationLibreOfficeCWE-190Heap buffer overflow in EMF+ gradient brush import
CVE-2026-60475.42.1The Document FoundationLibreOfficeCWE-787Heap buffer overflow in OOXML text box element import
CVE-2026-83565.42.1The Document FoundationLibreOfficeCWE-121Stack buffer overflow in PPT presentation import
CVE-2026-391188.42.0n/an/aCWE-269An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacke…
CVE-2026-340227.11.9Wertheim GmbHWertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)CWE-321Weak custom cryptography and hard-coded keys in Wertheim SafeController 65000…
CVE-2016-200675.31.9dwboosterCP PollsCWE-352WordPress CP Polls 1.0.8 Cross-Site Request Forgery
CVE-2026-50648.51.7HP Inc.HP One Agent SoftwareCWE-427HP One Agent Software – Security Update
CVE-2026-60405.41.7The Document FoundationLibreOfficeCWE-416Heap use-after-free in ODF number-format blank-width parsing
CVE-2026-122161.91.6svaaraladuktapeCWE-119svaarala duktape duk_api_bytecode.c memory corruption
CVE-2026-122177.11.5DVDFabVirtual DriveCWE-266DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management
CVE-2026-527215.31.4Red HatRed Hat Enterprise Linux 10CWE-125Gstreamer1-plugins-bad-free: gstreamer: multiple out-of-bounds reads in pcapp…
CVE-2016-200745.31.3leethompsonLazy Content Slider PluginCWE-352WordPress Lazy Content Slider Plugin 3.4 CSRF
CVE-2026-122011.91.1IObitMalware FighterCWE-266IObit Malware Fighter DLL permission

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-15 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.