AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H N 6.5 .2817 97.9 YES
AFFECTED Product Versions Fixed Cisco Catalyst SD-WAN Manager 20.1.12 – —
TIMELINE Oct 8 Reserved by CNA Jun 15 Added to CISA KEV, due Jun 29 Jun 15 Published (CNA: cisco)
400 CVEs published June 15, 2026: 80 critical, 191 high, 117 medium, 12 low; 2 in KEV; 15 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 375 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 3775 | 8147 | 1061 | 2563 |
| KEV catalog size | 1670 | |||
417 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 96 | 1062 | 84 | 663 | 312 | 1 | 27 | 3 | 0.3 | 7.8 | .0013 | -119 |
| 591 | 765 | 67 | 402 | 272 | 21 | 74 | 6 | 0.8 | 8.1 | .0023 | +591 | |
| microsoft | 207 | 697 | 52 | 466 | 158 | 4 | 378 | 27 | 3.9 | 7.8 | .0043 | +68 |
| red hat | 53 | 117 | 8 | 54 | 49 | 6 | 4 | 0 | 0.0 | 7.1 | .0030 | +49 |
| apple | 14 | 61 | 0 | 16 | 36 | 2 | 93 | 7 | 11.5 | 5.7 | .0023 | +1 |
| canonical | 0 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | 0 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| debian | 2 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 6.5 | .0023 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | +17 |
| cisco | 4 | 17 | 3 | 2 | 5 | 0 | 96 | 10 | 58.8 | 7.0 | .1247 | +3 |
| palo alto networks | 9 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | +8 |
| ivanti | 4 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | +3 |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 |
| ubiquiti | 5 | 8 | 4 | 4 | 0 | 0 | 4 | 0 | 0.0 | 8.9 | .0052 | +5 |
| fortinet | 2 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | +1 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.3 | .0887 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 67 | 99 | 15 | 40 | 41 | 2 | 40 | 1 | 1.0 | 7.3 | .0052 | +63 |
| gitlab | 11 | 20 | 0 | 4 | 12 | 2 | 4 | 2 | 10.0 | 4.8 | .0024 | +11 |
| mozilla | 5 | 11 | 3 | 4 | 4 | 0 | 13 | 0 | 0.0 | 7.5 | .0032 | +1 |
| docker | 2 | 5 | 0 | 5 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0021 | +2 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| adobe | 124 | 128 | 4 | 47 | 72 | 2 | 75 | 3 | 2.3 | 5.5 | .0021 | +124 |
| ibm | 11 | 60 | 13 | 29 | 18 | 0 | 7 | 0 | 0.0 | 7.5 | .0028 | +11 |
| oracle | 3 | 30 | 9 | 16 | 4 | 0 | 40 | 2 | 6.7 | 8.1 | .0027 | +3 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +5 |
| solarwinds | 3 | 6 | 1 | 2 | 1 | 0 | 11 | 4 | 66.7 | 7.5 | .3995 | +3 |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | +1 |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 9 | 12 | 0 | 4 | 2 | 5 | 26 | 1 | 8.3 | 5.5 | .0058 | +9 |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 1 | 0 | 0.0 | 7.5 | .0020 | +6 |
| abb | 5 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +5 |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | +3 |
| hitachi energy | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | 0 |
| moxa | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.0 | .0007 | +1 |
| schneider electric | 1 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 7.1 | .0023 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 71 | 72 | 2 | 30 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0023 | +71 |
| sourcecodester | 36 | 58 | 0 | 0 | 24 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +36 |
| edimax | 0 | 51 | 0 | 32 | 0 | 19 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| concrete cms | 2 | 46 | 1 | 11 | 13 | 21 | 0 | 0 | 0.0 | 6.2 | .0015 | +2 |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | 0 |
| helmholz | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| mb connect line | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| openclaw | 34 | 40 | 0 | 24 | 12 | 4 | 0 | 0 | 0.0 | 7.4 | .0022 | +34 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2009-3459 | .8658 | 99.7 | — |
| CVE-2025-34291 | .8384 | 99.7 | — |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-47140 | 10.0 | .0082 | |
| CVE-2026-47208 | 10.0 | .0076 |
| Vendor | CVEs |
|---|---|
| 759 | |
| linux | 521 |
| microsoft | 238 |
| adobe | 125 |
| red hat | 90 |
| apache | 84 |
| spring | 72 |
| ibm | 60 |
| sourcecodester | 58 |
| edimax | 51 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 10 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 35 |
| Packagist | 22 |
| PyPI | 11 |
| npm | 4 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1671 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1671 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1671 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1671 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1671 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1671 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1671 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1671 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1671 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1671 |
EXPLOIT PUBLISHED — CVE-2025-55641. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55642. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55643. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55644. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55645. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55647. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55648. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55649. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55650. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55652. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55660. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55661. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-55663. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10634 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50889. Public exploit reference added.
DUE DATE PASSED — CVE-2026-10520 (ivanti Sentry). CISA remediation deadline was June 14, 2026; still in catalog.
400 CVEs published. 25 box scores, 375 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H N 6.5 .2817 97.9 YES
AFFECTED Product Versions Fixed Cisco Catalyst SD-WAN Manager 20.1.12 – —
TIMELINE Oct 8 Reserved by CNA Jun 15 Added to CISA KEV, due Jun 29 Jun 15 Published (CNA: cisco)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N C H H H 8.5 .0144 70.9 YES
AFFECTED Product Versions Fixed cPanel Plugin 2.3 – —
TIMELINE Jun 14 Reserved by CNA Jun 15 Added to CISA KEV, due Jun 18 Jun 15 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H N 9.3 .0419 90.1 —
AFFECTED Product Versions Fixed Discuz! X5.0 20260320 – —
TIMELINE Jun 2 Reserved by CNA Jun 15 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0157 73.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 7 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0135 69.0 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N C N N H 6.8 .0122 66.1 —
AFFECTED Product Versions Fixed Meta Box – WordPress Custom Fields Framework n/a – 5.11.2
TIMELINE Apr 7 Reserved by CNA Jun 15 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N L N L L L 2.0 .0119 65.4 —
AFFECTED Product Versions Fixed SIP-T46U 108.86.0.118 – 108.87.0.23
TIMELINE Jun 14 Reserved by CNA Jun 15 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0112 63.4 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 7 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0105 61.4 —
AFFECTED Product Versions Fixed SIP-T46U 108.86.0.118 – 108.87.0.23
TIMELINE Jun 14 Reserved by CNA Jun 15 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0105 61.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0105 61.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0105 61.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0105 61.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0105 61.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0099 59.7 —
AFFECTED Product Versions Fixed Core Privileged Access Manager (BoKS) boks-server 8.1.0.0 – —
TIMELINE May 28 Reserved by CNA Jun 15 Published (CNA: Fortra)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0081 53.9 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 4 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N N H N N 6.9 .0078 52.8 —
AFFECTED Product Versions Fixed Dharma Booking unspecified —
TIMELINE Jun 15 Reserved by CNA Jun 15 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0076 52.4 —
AFFECTED Product Versions Fixed WP Go Maps unspecified —
TIMELINE May 12 Reserved by CNA Jun 15 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0072 50.8 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 7 Reserved by CNA Jun 15 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0070 50.2 —
AFFECTED Product Versions Fixed WP Go Maps unspecified —
TIMELINE May 12 Reserved by CNA Jun 15 Published (CNA: WPScan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N N H N N 6.9 .0069 49.7 —
AFFECTED Product Versions Fixed IMDb Profile Widget 1.0.8 – —
TIMELINE Jun 15 Reserved by CNA Jun 15 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0068 49.4 —
AFFECTED Product Versions Fixed Responsive Slider by MetaSlider n/a – 3.107.0
TIMELINE Apr 7 Reserved by CNA Jun 15 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0066 48.7 —
AFFECTED Product Versions Fixed Baggage Freight Shipping Australia 0.1.0 – —
TIMELINE Jun 15 Reserved by CNA Jun 15 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0064 47.8 —
AFFECTED Product Versions Fixed HB Audio Gallery Lite 1.0.0 – —
TIMELINE Jun 15 Reserved by CNA Jun 15 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0064 47.7 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 10 unspecified 0:1.26.7-2.el10_2.4 Red Hat Enterprise Linux 10.0 Extended Update Support unspecified 0:1.24.11-3.el10_0.4 Red Hat Enterprise Linux 7 Extended Lifecycle Support unspecified 0:1.10.4-6.el7_9 Red Hat Enterprise Linux 7 Extended Lifecycle Support unspecified 0:0.10.23-25.el7_9 Red Hat Enterprise Linux 8 unspecified 0:1.16.1-8.el8_10 Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support unspecified 0:1.16.1-4.el8_4.2 Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On unspecified 0:1.16.1-4.el8_4.2 Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support unspecified 0:1.16.1-4.el8_6.2 Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On unspecified 0:1.16.1-4.el8_6.2 Red Hat Enterprise Linux 8.8 Telecommunications Update Service unspecified 0:1.16.1-4.el8_8.2 + 6 more
TIMELINE Jun 8 Reserved by CNA Jun 15 Published (CNA: redhat)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-38329 | 9.8 | 47.1 | n/a | n/a | CWE-862 | Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the A… |
| CVE-2026-49757 | 9.2 | 46.6 | team-alembic | ash_authentication | CWE-290 | OAuth2/OIDC account takeover in AshAuthentication via email-based user matching |
| CVE-2016-20076 | 8.7 | 46.0 | ChrisHurst | Simple Backup | CWE-22 | WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and Download |
| CVE-2026-9863 | 8.8 | 45.6 | Fortra | Core Privileged Access Manager (BoKS) | CWE-78 | Core Privileged Access Manager (BoKS) upgrade tooling command injection vulne… |
| CVE-2026-36213 | 7.8 | 45.2 | n/a | n/a | CWE-269 | An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker t… |
| CVE-2026-50877 | 7.5 | 44.8 | n/a | n/a | CWE-22 | An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory tr… |
| CVE-2026-48853 | 9.2 | 44.6 | elixir-grpc | grpc | CWE-502 | Remote code execution and denial of service via unsafe Erlang term deserializ… |
| CVE-2026-48836 | 10.0 | 44.6 | MantraBrain | Easy Invoice | CWE-94 | WordPress Easy Invoice plugin <= 2.1.19 - Remote Code Execution (RCE) vulnera… |
| CVE-2026-50872 | 9.8 | 44.0 | n/a | n/a | CWE-94 | An issue in the loopback request handling component of fossar selfoss v2.20-S… |
| CVE-2026-48723 | 7.8 | 42.6 | browserstack | browserstack-cypress-cli | CWE-78 | BrowserStack Cypress CL: Command Injection via cypress_config_file leads to a… |
| CVE-2026-49954 | 8.6 | 42.1 | Discuz! | Discuz! X5.0 | CWE-98 | Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory |
| CVE-2026-12198 | 5.5 | 42.1 | n/a | Microweber | CWE-22 | Microweber API Endpoint thumbnail_img userfiles_path path traversal |
| CVE-2026-39006 | 9.8 | 41.5 | n/a | n/a | CWE-73 | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary … |
| CVE-2026-36537 | 9.8 | 41.2 | n/a | n/a | CWE-290 | ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAu… |
| CVE-2026-48017 | 8.8 | 41.2 | dbgate | dbgate | CWE-94 | DbGate: Remote Code Execution via functionName injection in loadReader endpoint |
| CVE-2026-49766 | 9.9 | 40.9 | WP User Manager | WP User Manager | CWE-22 | WordPress WP User Manager plugin <= 2.9.16 - Arbitrary File Deletion vulnerab… |
| CVE-2026-49781 | 9.8 | 40.6 | Brainstorm Force | OttoKit | CWE-502 | WordPress OttoKit plugin <= 1.1.27 - PHP Object Injection vulnerability |
| CVE-2025-55642 | 6.5 | 40.6 | n/a | n/a | CWE-369 | GPAC MP4Box v2.4 was discovered to contain a floating point exception in the … |
| CVE-2026-50889 | 7.5 | 39.5 | n/a | n/a | CWE-400 | An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allo… |
| CVE-2026-9691 | 9.8 | 39.1 | CRM Perks | Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms | CWE-502 | WordPress Integration for ActiveCampaign and Contact Form 7, WPForms, Element… |
| CVE-2026-49085 | 9.8 | 39.1 | CRM Perks | WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms | CWE-502 | WordPress WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and… |
| CVE-2026-49104 | 9.8 | 39.1 | CRM Perks | Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms | CWE-502 | WordPress Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elem… |
| CVE-2026-49105 | 9.8 | 39.1 | CRM Perks | WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms | CWE-502 | WordPress WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and N… |
| CVE-2026-50880 | 9.8 | 39.1 | n/a | n/a | CWE-94 | An issue in the sendmail transport integration component of YouTransfer v1.0.… |
| CVE-2026-39591 | 9.9 | 38.4 | CMSJunkie – WordPress Business Directory Plugins | WP-BusinessDirectory | CWE-434 | WordPress WP-BusinessDirectory plugin <= 4.0.0 - Arbitrary File Upload vulner… |
| CVE-2026-39434 | 7.2 | 37.1 | WebAppick | CTX Feed | CWE-502 | WordPress CTX Feed plugin <= 6.6.26 - PHP Object Injection vulnerability |
| CVE-2026-39471 | 7.2 | 37.1 | ShortPixel | ShortPixel Image Optimizer | CWE-502 | WordPress ShortPixel Image Optimizer plugin <= 6.4.3 - PHP Object Injection v… |
| CVE-2026-39472 | 7.2 | 37.1 | WP Overnight | WooCommerce PDF Invoices & Packing Slips | CWE-502 | WordPress WooCommerce PDF Invoices & Packing Slips plugin < 5.9.0 - PHP Objec… |
| CVE-2026-39481 | 7.2 | 37.1 | WP Chill | Modula Image Gallery | CWE-502 | WordPress Modula Image Gallery plugin <= 2.14.18 - PHP Object Injection vulne… |
| CVE-2026-39499 | 7.2 | 37.1 | Wombat Plugins | Advanced Product Fields (Product Addons) for WooCommerce | CWE-502 | WordPress Advanced Product Fields (Product Addons) for WooCommerce plugin <= … |
| CVE-2026-5482 | 9.3 | 37.0 | Tecrail | Responsive FileManager | CWE-434 | Remote Code Execution via Unrestricted File Upload in Responsive FileManager |
| CVE-2026-40769 | 8.6 | 36.8 | Satinder Singh | Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field | CWE-22 | WordPress Contact Form Extender for Divi – Save Entries, File Upload & Countr… |
| CVE-2026-50873 | 9.8 | 36.7 | n/a | n/a | CWE-434 | An arbitrary file upload vulnerability in the attachment handling component o… |
| CVE-2026-50878 | 7.5 | 36.7 | n/a | n/a | CWE-400 | An issue in the attachment handling component of Feuerhamster MailForm v1.1.0… |
| CVE-2026-12161 | 8.8 | 36.5 | Devolutions | Remote Desktop Manager | CWE-78 | Improper input validation in the SSH Elevate Shell feature allows an authenti… |
| CVE-2026-52703 | 9.6 | 36.3 | Ninja Team | FastDup | CWE-35 | WordPress FastDup plugin <= 2.7.2 - Path Traversal vulnerability |
| CVE-2026-39474 | 8.8 | 35.7 | metaphorcreations | Post Duplicator | CWE-502 | WordPress Post Duplicator plugin <= 3.0.10 - PHP Object Injection vulnerability |
| CVE-2026-39478 | 8.8 | 35.7 | Eli Scheetz | Anti-Malware Security and Brute-Force Firewall | CWE-502 | WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.87 - … |
| CVE-2026-42668 | 7.5 | 35.6 | Omnisend | Email Marketing for WooCommerce by Omnisend | CWE-288 | WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.18.0 - Brok… |
| CVE-2026-48713 | 9.1 | 35.0 | i18next | i18next-fs-backend | CWE-1321 | i18next-fs-backend: Prototype pollution via crafted missing-key string |
| CVE-2026-48714 | 9.1 | 35.0 | i18next | i18next-http-middleware | CWE-1321 | i18next-http-middleware missingKeyHandler does not reject keys whose segments… |
| CVE-2026-40776 | 7.5 | 34.5 | Arraytics | WP Event SOlution | CWE-862 | WordPress Eventin plugin <= 4.1.8 - Broken Access Control vulnerability |
| CVE-2026-48889 | 8.8 | 34.3 | TMS | Amelia | CWE-266 | WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability |
| CVE-2026-42411 | 8.1 | 33.7 | XServer | CloudSecure WP Security | CWE-288 | WordPress CloudSecure WP Security plugin <= 1.4.7 - Broken Authentication vul… |
| CVE-2026-48708 | 7.5 | 33.4 | OliveTin | OliveTin | CWE-362 | OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cros… |
| CVE-2026-12203 | 5.5 | 33.4 | HKUDS | AI-Trader | CWE-200 | HKUDS AI-Trader Research Export agents.csv information disclosure |
| CVE-2026-49764 | 9.8 | 33.2 | Metagauss | RegistrationMagic | CWE-288 | WordPress RegistrationMagic plugin <= 6.0.8.6 - Broken Authentication vulnera… |
| CVE-2026-34028 | 6.9 | 32.9 | Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | CWE-425 | Unauthenticated direct access to web data in Wertheim SafeController Software… |
| CVE-2026-34026 | 7.1 | 32.6 | Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | CWE-23 | Path traversal in Wertheim SafeController Software allows authenticated users… |
| CVE-2026-38812 | 9.8 | 32.4 | n/a | n/a | CWE-89 | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable end… |
| CVE-2026-48970 | 8.1 | 32.5 | Really Simple Plugins | Really Simple SSL | CWE-288 | WordPress Really Simple SSL plugin <= 9.5.10 - Broken Authentication vulnerab… |
| CVE-2026-27407 | 7.2 | 32.5 | Meow Apps | AI Engine | CWE-266 | WordPress AI Engine plugin <= 3.4.9 - Privilege Escalation vulnerability |
| CVE-2026-52722 | 7.1 | 32.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Gstreamer1-plugins-bad-free: gstreamer: signed integer overflow in vmnc decod… |
| CVE-2016-20080 | 6.9 | 32.1 | Brandfolder | Brandfolder | CWE-98 | WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php |
| CVE-2026-42378 | 6.5 | 32.1 | Themeisle | WP Full Stripe Free | CWE-288 | WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnera… |
| CVE-2026-27053 | 9.8 | 31.8 | VideoWhisper.com | Broadcast Live Video | CWE-502 | WordPress Broadcast Live Video plugin < 7.1.3 - PHP Object Injection vulnerab… |
| CVE-2026-49068 | 7.5 | 31.8 | RelyWP | Coupon Affiliates | CWE-497 | WordPress Coupon Affiliates plugin <= 7.8.1 - Sensitive Data Exposure vulnera… |
| CVE-2026-52718 | 6.5 | 31.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-617 | Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_o… |
| CVE-2026-39450 | 7.1 | 31.7 | Aman | FunnelKit Automations | CWE-288 | WordPress FunnelKit Automations plugin <= 3.7.3 - Broken Authentication vulne… |
| CVE-2026-40785 | 7.1 | 31.7 | Ruben Garcia | AutomatorWP | CWE-288 | WordPress AutomatorWP plugin <= 5.6.7 - Broken Authentication vulnerability |
| CVE-2026-42661 | 8.8 | 31.5 | aguilatechnologies | WP Customer Area | CWE-35 | WordPress WP Customer Area plugin <= 8.3.4 - Path Traversal vulnerability |
| CVE-2026-49106 | 9.8 | 31.5 | CRM Perks | Integration for Contact Form 7 and Constant Contact | CWE-502 | WordPress Integration for Contact Form 7 and Constant Contact plugin <= 1.1.6… |
| CVE-2026-49109 | 9.8 | 31.5 | crm perks | Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms | CWE-502 | WordPress Integration for Salesforce and Contact Form 7, WPForms, Elementor, … |
| CVE-2026-49763 | 9.8 | 31.5 | CRM Perks | Integration for Contact Form 7 HubSpot | CWE-502 | WordPress Integration for Contact Form 7 HubSpot plugin <= 1.3.7 - PHP Object… |
| CVE-2026-49765 | 9.8 | 31.5 | CRM Perks | Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms | CWE-502 | WordPress Integration for Mailchimp and Contact Form 7, WPForms, Elementor, N… |
| CVE-2026-49768 | 9.8 | 31.5 | Happyforms | Happyforms | CWE-502 | WordPress Happyforms plugin <= 1.26.13 - PHP Object Injection vulnerability |
| CVE-2026-49769 | 9.8 | 31.5 | Tomdever | wpForo Forum | CWE-502 | WordPress wpForo Forum plugin <= 3.1.0 - PHP Object Injection vulnerability |
| CVE-2026-49770 | 9.8 | 31.5 | WP Travel Engine | WP Travel Engine | CWE-502 | WordPress WP Travel Engine plugin <= 6.7.12 - PHP Object Injection vulnerability |
| CVE-2026-39470 | 7.2 | 31.3 | Brainstorm Force | WooCommerce Cart Abandonment Recovery | CWE-266 | WordPress WooCommerce Cart Abandonment Recovery plugin < 2.1.0 - Privilege Es… |
| CVE-2026-39480 | 7.5 | 30.7 | Inisev | Backup Migration | CWE-201 | WordPress Backup Migration plugin <= 2.1.1 - Sensitive Data Exposure vulnerab… |
| CVE-2026-53705 | 7.6 | 30.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Gstreamer1-plugins-good: gstreamer: heap buffer overflow in wavpack decoder v… |
| CVE-2026-39007 | 7.5 | 30.6 | n/a | n/a | CWE-200 | An issue in Observeinc's Observe v.2026-01-28 and before allows a remote atta… |
| CVE-2026-50883 | 9.6 | 30.5 | n/a | n/a | CWE-79 | An HTML injection vulnerability in the /src/highlight.rs component of matze w… |
| CVE-2026-12087 | 9.1 | 30.5 | PEVANS | Socket | CWE-125 | Socket versions before 2.041 for Perl have an out-of-bounds heap read |
| CVE-2016-20077 | 6.9 | 30.6 | KaymeePhotography | Photocart Link | CWE-98 | WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php |
| CVE-2026-45390 | 9.1 | 30.4 | n/a | n/a | CWE-22 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its na… |
| CVE-2026-25425 | 7.5 | 30.4 | ThemeGrill | User Registration | CWE-862 | WordPress User Registration plugin <= 5.1.2 - Broken Access Control vulnerabi… |
| CVE-2026-12211 | 2.0 | 30.3 | Intelbras | iNVU 7016 FT | CWE-22 | Intelbras iNVU 7016 FT Web syslog path traversal |
| CVE-2026-12218 | 7.3 | 30.2 | Yealink | SIP-T46U | CWE-119 | Yealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation st… |
| CVE-2026-12220 | 7.3 | 30.2 | Yealink | SIP-T46U | CWE-119 | Yealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.… |
| CVE-2026-12221 | 7.3 | 30.2 | Yealink | SIP-T46U | CWE-119 | Yealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflow |
| CVE-2026-12222 | 7.3 | 30.2 | Yealink | SIP-T46U | CWE-119 | Yealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-base… |
| CVE-2026-48114 | 9.8 | 30.1 | NCEAS | metacat | CWE-89 | Metacat has an unauthenticated SQL injection vulnerability |
| CVE-2026-52697 | 8.5 | 30.1 | Taskbuilder | Taskbuilder | CWE-89 | WordPress Taskbuilder plugin <= 5.0.7 - SQL Injection vulnerability |
| CVE-2026-52700 | 8.5 | 30.1 | WcMultishipping – Mondial Relay & Chronopost for Wooommerce | WCMultiShipping | CWE-89 | WordPress WCMultiShipping plugin <= 3.0.2 - SQL Injection vulnerability |
| CVE-2026-49056 | 7.5 | 29.6 | WebToffee | WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | CWE-497 | WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shippin… |
| CVE-2026-39492 | 9.3 | 29.4 | Flipper Code – WordPress Development Company | WP Maps | CWE-89 | WordPress WP Maps plugin <= 4.9.1 - SQL Injection vulnerability |
| CVE-2026-39493 | 9.3 | 29.4 | NSquared | Simply Schedule Appointments | CWE-89 | WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vul… |
| CVE-2026-49061 | 7.5 | 29.3 | WPClever | WPC Product Options for WooCommerce | CWE-22 | WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary Fil… |
| CVE-2026-36670 | 8.8 | 29.2 | n/a | n/a | CWE-89 | A Time-Based Blind SQL Injection vulnerability in the alias_management module… |
| CVE-2026-40772 | 10.0 | 29.0 | Ahmad | GeekyBot | CWE-434 | WordPress GeekyBot plugin <= 1.2.2 - Arbitrary File Upload vulnerability |
| CVE-2026-39498 | 7.2 | 29.0 | Yeeaddons | YayMail | CWE-502 | WordPress YayMail plugin <= 4.3.3 - PHP Object Injection vulnerability |
| CVE-2026-49953 | 6.9 | 29.0 | Discuz! | Discuz! X5.0 | CWE-804 | Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set |
| CVE-2026-39583 | 9.8 | 28.8 | Datalogics | Datalogics Ecommerce Delivery | CWE-266 | WordPress Datalogics Ecommerce Delivery plugin <= 2.6.62 - Privilege Escalati… |
| CVE-2026-47261 | 7.5 | 28.8 | bytecodealliance | wasmtime | CWE-284 | Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction |
| CVE-2026-42686 | 7.1 | 28.5 | EventPrime | EventPrime | CWE-79 | WordPress EventPrime plugin <= 4.3.2.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-39515 | 6.5 | 28.3 | StylemixThemes | Motors | CWE-862 | WordPress Motors plugin < 1.4.107 - Broken Access Control vulnerability |
| CVE-2026-53430 | 8.7 | 27.8 | elixir-grpc | grpc | CWE-409 | grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1 |
| CVE-2026-48872 | 7.5 | 27.6 | WPDeveloper | EmbedPress | CWE-639 | WordPress EmbedPress plugin <= 4.5.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-40796 | 6.5 | 27.5 | ollybach | WPPizza | CWE-497 | WordPress WPPizza plugin <= 3.19.9 - Sensitive Data Exposure vulnerability |
| CVE-2026-42660 | 6.5 | 27.5 | Wasiliy Strecker | Contest Gallery | CWE-497 | WordPress Contest Gallery plugin <= 28.1.7 - Sensitive Data Exposure vulnerab… |
| CVE-2026-48878 | 6.5 | 27.5 | Bootstrapped Ventures | Visual Link Preview | CWE-497 | WordPress Visual Link Preview plugin <= 2.4.1 - Sensitive Data Exposure vulne… |
| CVE-2026-39532 | 8.8 | 27.4 | Stiofan | Events Calendar for GeoDirectory | CWE-502 | WordPress Events Calendar for GeoDirectory plugin <= 2.3.25 - PHP Object Inje… |
| CVE-2026-48854 | 8.7 | 27.4 | elixir-grpc | grpc | CWE-770 | Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc |
| CVE-2026-49083 | 7.5 | 27.4 | LatePoint | LatePoint | CWE-266 | WordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability |
| CVE-2026-40727 | 7.7 | 27.2 | Groundhogg | Groundhogg | CWE-22 | WordPress Groundhogg plugin <= 4.4 - Arbitrary File Deletion vulnerability |
| CVE-2026-52719 | 7.1 | 27.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment l… |
| CVE-2026-39489 | 4.4 | 26.7 | WP Chill | Download Monitor | CWE-22 | WordPress Download Monitor plugin <= 5.1.9 - Non-Arbitrary File Download vuln… |
| CVE-2026-34023 | 7.1 | 26.4 | Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | CWE-863 | Broken WebSocket authorization in Wertheim SafeController Software allows cro… |
| CVE-2026-40766 | 8.5 | 26.1 | StylemixThemes | MasterStudy LMS | CWE-89 | WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerability |
| CVE-2026-48874 | 8.5 | 26.1 | Ruben Garcia | GamiPress | CWE-89 | WordPress GamiPress plugin <= 7.8.7 - SQL Injection vulnerability |
| CVE-2026-48882 | 8.5 | 26.1 | codepeople | WP Time Slots Booking Form | CWE-89 | WordPress WP Time Slots Booking Form plugin <= 1.2.50 - SQL Injection vulnera… |
| CVE-2026-48964 | 8.5 | 26.1 | ELEXtensions | ELEX WordPress HelpDesk & Customer Ticketing System | CWE-89 | WordPress ELEX WordPress HelpDesk & Customer Ticketing System plugin <= 3.3.6… |
| CVE-2026-48709 | 3.7 | 25.7 | OliveTin | OliveTin | CWE-862 | OliveTin: ValidateArgumentType API Endpoint Missing Authentication Allows Act… |
| CVE-2026-11832 | 9.1 | 25.6 | BIAFRA | Dancer2::Plugin::Auth::OAuth | CWE-338 | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predi… |
| CVE-2016-20075 | 8.7 | 25.6 | Etoilewebdesign | Ultimate Product Catalog | CWE-863 | WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE |
| CVE-2026-40779 | 7.7 | 25.5 | Yannick Lefebvre | Link Library | CWE-22 | WordPress Link Library plugin <= 7.8.8 - Arbitrary File Deletion vulnerability |
| CVE-2026-34030 | 6.9 | 25.5 | Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | CWE-73 | Improper branch-code validation in Wertheim SafeController Software allows fi… |
| CVE-2026-50891 | 8.1 | 25.4 | n/a | n/a | CWE-284 | Incorrect access control in the /admin/api/config component of Filestash v0.4… |
| CVE-2026-49112 | 7.5 | 25.4 | Tammersoft | Shared Files | CWE-35 | WordPress Shared Files plugin <= 1.7.64 - Path Traversal vulnerability |
| CVE-2016-20082 | 6.9 | 25.4 | abtest | Abtest | CWE-98 | WordPress Plugin Abtest Local File Inclusion via abtest_admin.php |
| CVE-2025-69332 | 6.5 | 25.4 | myCred | Bookify | CWE-862 | WordPress Bookify plugin <= 1.1.1 - Broken Access Control vulnerability |
| CVE-2026-39584 | 6.5 | 25.4 | Webful Creations | RepairBuddy | CWE-862 | WordPress RepairBuddy plugin <= 4.1132 - Broken Access Control vulnerability |
| CVE-2026-40790 | 6.5 | 25.4 | VeronaLabs | WP SMS | CWE-288 | WordPress WP SMS plugin <= 7.2.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-48965 | 6.5 | 25.4 | watchful | XCloner | CWE-201 | WordPress XCloner plugin <= 4.8.6 - Sensitive Data Exposure vulnerability |
| CVE-2026-30121 | 9.1 | 25.2 | n/a | n/a | CWE-123 | remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file wr… |
| CVE-2026-50879 | 7.5 | 25.2 | n/a | n/a | CWE-400 | An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.… |
| CVE-2026-50882 | 7.5 | 25.2 | n/a | n/a | CWE-400 | An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows a… |
| CVE-2026-12200 | 5.5 | 25.2 | Ritlabs | TinyWeb Server | CWE-119 | Ritlabs TinyWeb Server Header libeay32.dll.html stack-based overflow |
| CVE-2026-34901 | 9.8 | 24.9 | Paul | iControlWP | CWE-266 | WordPress iControlWP plugin <= 5.5.3 - Privilege Escalation vulnerability |
| CVE-2026-39196 | 9.8 | 24.9 | n/a | n/a | CWE-89 | Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnera… |
| CVE-2026-50890 | 9.8 | 24.9 | n/a | n/a | CWE-89 | Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerabi… |
| CVE-2026-27333 | 8.1 | 24.5 | VideoWhisper.com | Paid Videochat Turnkey Site | CWE-502 | WordPress Paid Videochat Turnkey Site plugin <= 7.3.23 - Deserialization of u… |
| CVE-2026-42687 | 8.1 | 24.5 | EventPrime | EventPrime | CWE-502 | WordPress EventPrime plugin <= 4.3.2.1 - PHP Object Injection vulnerability |
| CVE-2026-42662 | 6.5 | 24.3 | Liquid Web / StellarWP | Event Tickets | CWE-290 | WordPress Event Tickets plugin <= 5.27.5 - Bypass Vulnerability vulnerability |
| CVE-2026-12208 | 5.5 | 24.1 | jsonata-js | jsonata | CWE-94 | jsonata-js jsonata Function Binding Frame System jsonata.js createFrame proto… |
| CVE-2026-12209 | 5.5 | 24.1 | RubyLouvre | avalon | CWE-94 | RubyLouvre avalon Template Filter index.js prototype pollution |
| CVE-2026-50886 | 9.1 | 23.9 | n/a | n/a | CWE-284 | Incorrect access control in the webhook management component of Project Firef… |
| CVE-2016-20071 | 8.8 | 24.0 | 404-redirection-manager | 404 Redirection Manager | CWE-89 | WordPress 404 Redirection Manager Plugin 1.0 SQL Injection |
| CVE-2026-40799 | 5.3 | 23.6 | RelyWP | Simple Cloudflare Turnstile | CWE-288 | WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authenticatio… |
| CVE-2026-50870 | 7.5 | 23.4 | n/a | n/a | CWE-200 | An information disclosure vulnerability in the configuration endpoint of Ben … |
| CVE-2026-40788 | 7.1 | 23.3 | QuantumCloud | ChatBot | CWE-862 | WordPress ChatBot plugin <= 7.9.7 - Broken Access Control vulnerability |
| CVE-2026-39534 | 7.5 | 23.2 | Wp Directory Kit | WP Directory Kit | CWE-862 | WordPress WP Directory Kit plugin <= 1.5.0 - Broken Access Control vulnerability |
| CVE-2026-52704 | 10.0 | 23.1 | Edgar Rojas | WooCommerce PDF Invoice Builder | CWE-94 | WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Remote Code Execu… |
| CVE-2026-48835 | 7.5 | 23.1 | Awesomemotive | Contact Form by WPForms | CWE-862 | WordPress Contact Form by WPForms plugin <= 1.10.0.4 - Broken Access Control … |
| CVE-2026-34027 | 5.3 | 23.1 | Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | CWE-434 | Upload restriction bypass in Wertheim SafeController Software allows authenti… |
| CVE-2026-5242 | 8.8 | 23.0 | MIA Technology Inc. | Pizzy Library | CWE-1236 | Code Injection in Mia Technologies' Pizzy Library |
| CVE-2026-34024 | 8.6 | 23.0 | Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | CWE-862 | Missing authorization checks in Wertheim SafeController Software allow low-pr… |
| CVE-2026-39533 | 7.5 | 23.0 | WPTasty | AWP Classifieds | CWE-862 | WordPress AWP Classifieds plugin <= 4.4.4 - Broken Access Control vulnerability |
| CVE-2026-47835 | 7.5 | 23.0 | Spring | Spring AI | CWE-943 | Spring AI vector store metadata filtering to handle special characters in Ela… |
| CVE-2026-34891 | 7.5 | 22.8 | IDPay | IDPay Payment Gateway for Woocommerce | CWE-497 | WordPress IDPay Payment Gateway for Woocommerce plugin <= 2.2.5 - Sensitive D… |
| CVE-2016-20068 | 8.8 | 22.8 | dwbooster | Booking Calendar Contact Form | CWE-89 | WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
| CVE-2026-39530 | 9.3 | 22.1 | SpeakOut! | SpeakOut! Email Petitions | CWE-89 | WordPress SpeakOut! Email Petitions plugin <= 4.6.5 - SQL Injection vulnerabi… |
| CVE-2026-39511 | 9.3 | 22.0 | Jacob N. Breetvelt | WP Photo Album Plus | CWE-89 | WordPress WP Photo Album Plus plugin <= 9.1.08.001 - SQL Injection vulnerability |
| CVE-2026-34892 | 6.5 | 22.1 | Rank Math SEO | Rank Math SEO | CWE-862 | WordPress Rank Math SEO plugin <= 1.0.271 - Broken Access Control vulnerability |
| CVE-2026-40781 | 7.5 | 21.9 | ReviewX | ReviewX | CWE-288 | WordPress ReviewX plugin <= 2.3.6 - Broken Authentication vulnerability |
| CVE-2026-40789 | 7.5 | 21.9 | TMS | Amelia | CWE-201 | WordPress Amelia plugin <= 2.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-42384 | 7.5 | 21.9 | NSquared | Simply Schedule Appointments | CWE-201 | WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exp… |
| CVE-2026-42667 | 7.5 | 21.9 | Bookly | Bookly | CWE-201 | WordPress Bookly plugin <= 27.4 - Sensitive Data Exposure vulnerability |
| CVE-2026-49066 | 7.5 | 21.9 | Conekta Group | Conekta Payment Gateway | CWE-497 | WordPress Conekta Payment Gateway plugin <= 6.0.0 - Sensitive Data Exposure v… |
| CVE-2026-39502 | 9.3 | 21.8 | 10Web | Form Maker by 10Web | CWE-89 | WordPress Form Maker by 10Web plugin <= 1.15.38 - SQL Injection vulnerability |
| CVE-2026-12204 | 5.5 | 21.7 | n/a | ShopXO | CWE-285 | ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization |
| CVE-2026-45439 | 9.3 | 21.6 | Realtyna | Realtyna Organic IDX plugin | CWE-89 | WordPress Realtyna Organic IDX plugin plugin <= 5.1.0 - SQL Injection vulnera… |
| CVE-2026-39527 | 5.4 | 21.6 | sc Internet Vivoo | WpStream | CWE-434 | WordPress WpStream plugin < 4.11.2 - Arbitrary File Upload vulnerability |
| CVE-2026-49062 | 8.8 | 21.5 | WP Engine | Faust.js | CWE-288 | WordPress Faust.js plugin <= 1.8.7 - Broken Authentication vulnerability |
| CVE-2026-49067 | 9.3 | 21.4 | yydevelopment | Advanced 301 and 302 Redirect | CWE-89 | WordPress Advanced 301 and 302 Redirect plugin <= 1.6.9 - SQL Injection vulne… |
| CVE-2026-49776 | 9.3 | 21.4 | JExtensions Store | GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites | CWE-89 | WordPress GPTranslate – Multilingual AI Translation for WordPress: Automatica… |
| CVE-2026-52693 | 9.3 | 21.4 | impleCode | eCommerce Product Catalog | CWE-89 | WordPress eCommerce Product Catalog plugin <= 3.5.5 - SQL Injection vulnerabi… |
| CVE-2026-12205 | 9.1 | 21.4 | TIMLEGGE | Crypt::DSA | CWE-323 | Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, … |
| CVE-2026-39197 | 6.5 | 21.4 | n/a | n/a | CWE-400 | An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0… |
| CVE-2026-50887 | 9.1 | 21.2 | n/a | n/a | CWE-918 | A Server-Side Request Forgery (SSRF) in the automatic short URL title resolut… |
| CVE-2018-25437 | 8.7 | 21.2 | Cherryframework | Cherry Framework Themes | CWE-306 | WordPress CherryFramework Themes 3.1.4 Backup File Download |
| CVE-2025-59133 | 7.5 | 21.2 | Projectopia | Projectopia | CWE-639 | WordPress Projectopia plugin <= 5.1.25.2 - Insecure Direct Object References … |
| CVE-2026-39513 | 7.5 | 21.2 | Easy Appointments | Easy Appointments | CWE-862 | WordPress Easy Appointments plugin <= 3.12.21 - Broken Access Control vulnera… |
| CVE-2026-40767 | 7.5 | 21.2 | Tomdever | wpForo Forum | CWE-281 | WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability |
| CVE-2026-50885 | 7.5 | 21.2 | n/a | n/a | CWE-284 | Incorrect access control in the share-based read endpoints of Sismics Docs (T… |
| CVE-2026-39594 | 6.4 | 21.2 | Themefic | Ultra Addons for WPForms | CWE-862 | WordPress Ultra Addons for WPForms plugin <= 1.0.11 - Broken Access Control v… |
| CVE-2026-50884 | 8.8 | 21.1 | n/a | n/a | CWE-284 | Incorrect access control in statping-ng v0.93.0 allows attackers to escalate … |
| CVE-2025-55645 | 5.5 | 21.1 | n/a | n/a | CWE-122 | A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.… |
| CVE-2025-55648 | 5.5 | 21.1 | n/a | n/a | CWE-122 | A heap buffer overflow in the gf_opus_parse_packet_header function (media_too… |
| CVE-2025-68713 | 8.0 | 20.9 | n/a | n/a | CWE-926 | An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android … |
| CVE-2026-44188 | 5.3 | 20.9 | Red Hat | Red Hat Ansible Automation Platform 2.7 | CWE-613 | Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized da… |
| CVE-2026-39441 | 9.3 | 20.8 | Naked Cat Plugins (by Webdados) | Feed KuantoKusta for WooCommerce – Free | CWE-89 | WordPress Feed KuantoKusta for WooCommerce – Free plugin <= 5.3 - SQL Injecti… |
| CVE-2026-39512 | 9.3 | 20.8 | Paolo | GeoDirectory | CWE-89 | WordPress GeoDirectory plugin <= 2.8.152 - SQL Injection vulnerability |
| CVE-2026-39519 | 9.3 | 20.8 | Ahmad | GeekyBot | CWE-89 | WordPress GeekyBot plugin <= 1.2.0 - SQL Injection vulnerability |
| CVE-2026-40771 | 9.3 | 20.8 | Wasiliy Strecker | Contest Gallery | CWE-89 | WordPress Contest Gallery plugin <= 28.1.6 - SQL Injection vulnerability |
| CVE-2026-40798 | 9.3 | 20.8 | Tomdever | wpForo Forum | CWE-89 | WordPress wpForo Forum plugin <= 3.0.4 - SQL Injection vulnerability |
| CVE-2026-42381 | 9.3 | 20.8 | FunnelKit | Funnel Builder by FunnelKit | CWE-89 | WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.1 - SQL Injection vuln… |
| CVE-2026-42386 | 9.3 | 20.8 | tychesoftwares | Order Delivery Date for WooCommerce | CWE-89 | WordPress Order Delivery Date for WooCommerce plugin <= 4.5.1 - SQL Injection… |
| CVE-2026-42639 | 9.3 | 20.8 | Dev4Press | GD Rating System | CWE-89 | WordPress GD Rating System plugin <= 3.6.2 - SQL Injection vulnerability |
| CVE-2026-42665 | 9.3 | 20.8 | Passionate Programmer Peter | WP Data Access | CWE-89 | WordPress WP Data Access plugin <= 5.5.70 - SQL Injection vulnerability |
| CVE-2026-48886 | 9.3 | 20.8 | Ahmad | JS Help Desk | CWE-89 | WordPress JS Help Desk plugin <= 3.0.9 - SQL Injection vulnerability |
| CVE-2026-49780 | 8.8 | 20.8 | Dokan, Inc. | Dokan | CWE-266 | WordPress Dokan plugin <= 5.0.2 - Privilege Escalation vulnerability |
| CVE-2026-39587 | 8.1 | 20.8 | Hakan Ozevin | WP BASE Booking | CWE-266 | WordPress WP BASE Booking plugin <= 5.9.0 - Privilege Escalation vulnerability |
| CVE-2026-34025 | 5.3 | 20.8 | Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | CWE-290 | IP restriction bypass in Wertheim SafeController Software allows logins from … |
| CVE-2026-50875 | 8.1 | 20.7 | n/a | n/a | CWE-284 | Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 … |
| CVE-2026-40773 | 6.5 | 20.4 | rtCamp Inc. | rtMedia for WordPress, BuddyPress and bbPress | CWE-862 | WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.9 - Bro… |
| CVE-2026-40793 | 6.5 | 20.4 | Groundhogg | Groundhogg | CWE-862 | WordPress Groundhogg plugin < 4.4.1 - Broken Access Control vulnerability |
| CVE-2026-40794 | 6.5 | 20.4 | myCred | myCred | CWE-862 | WordPress myCred plugin <= 3.0.3 - Broken Access Control vulnerability |
| CVE-2026-48881 | 9.1 | 20.3 | themetechmount | TrueBooker | CWE-862 | WordPress TrueBooker plugin <= 1.1.9 - Broken Access Control vulnerability |
| CVE-2026-39579 | 8.8 | 20.2 | bPlugins | B Blocks | CWE-266 | WordPress B Blocks plugin <= 2.0.31 - Privilege Escalation vulnerability |
| CVE-2026-5038 | 7.5 | 20.3 | multer | multer | CWE-459 | multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads |
| CVE-2026-5079 | 7.5 | 20.3 | multer | multer | CWE-400 | multer vulnerable to Denial of Service via deeply nested field names |
| CVE-2026-41708 | 7.5 | 20.2 | Spring | Spring Cloud Sleuth | CWE-400 | Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability |
| CVE-2026-42666 | 7.5 | 20.3 | Dimitri Grassi | Salon booking system | CWE-862 | WordPress Salon booking system plugin <= 10.30.25 - Broken Access Control vul… |
| CVE-2026-48868 | 7.5 | 20.3 | mra13 / Team Tips and Tricks HQ | Simple Shopping Cart | CWE-639 | WordPress Simple Shopping Cart plugin <= 5.2.9 - Insecure Direct Object Refer… |
| CVE-2026-39518 | 7.1 | 20.2 | EventPrime | EventPrime | CWE-639 | WordPress EventPrime plugin <= 4.3.0.0 - Insecure Direct Object References (I… |
| CVE-2026-10634 | 5.3 | 19.8 | zephyrproject | zephyr | CWE-416 | Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_… |
| CVE-2026-48599 | 7.6 | 19.7 | elixir-grpc | grpc | CWE-639 | Authorization bypass via path binding override in elixir-grpc/grpc HTTP trans… |
| CVE-2026-40795 | 6.5 | 19.3 | TMS | Amelia | CWE-862 | WordPress Amelia plugin <= 2.2 - Broken Access Control vulnerability |
| CVE-2026-42659 | 6.5 | 19.3 | Nasir Ahmed | Advanced Form Integration | CWE-862 | WordPress Advanced Form Integration plugin <= 1.126.12 - Broken Access Contro… |
| CVE-2016-20072 | 8.8 | 19.3 | bbsetheme | BBS e-Franchise | CWE-89 | BBS e-Franchise 1.1.1 WordPress Plugin SQL Injection via uid |
| CVE-2016-20073 | 8.8 | 19.3 | mattkaye | Answer My Question | CWE-89 | Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php |
| CVE-2026-8935 | 9.8 | 19.0 | Unknown | WP MAPS PRO | — | Advanced Google Maps < 6.1.1 - Unauthenticated Administrator Account Creation |
| CVE-2026-27089 | 7.5 | 18.9 | Magepeople inc. | WpTravelly | CWE-290 | WordPress WpTravelly plugin <= 2.1.7 - Bypass Vulnerability vulnerability |
| CVE-2026-9258 | 7.1 | 18.9 | Canon Inc. | EOS Network Setting Tool for Windows | CWE-295 | Improper validation of SSH host keys in Canon EOS Network Setting Tool Versio… |
| CVE-2026-49082 | 7.4 | 18.3 | Chatway Live Chat | Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons | CWE-201 | WordPress Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Cu… |
| CVE-2026-9262 | 7.1 | 18.3 | Canon Inc. | EOS Network Setting Tool for Windows | CWE-1188 | Use of a non-secure protocol as the default FTP configuration in Canon EOS Ne… |
| CVE-2026-45441 | 7.5 | 17.7 | Magepeople inc. | WpEvently | CWE-1284 | WordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerability |
| CVE-2026-48969 | 6.5 | 17.5 | Really Simple Plugins B.V. | Really Simple SSL | CWE-862 | WordPress Really Simple SSL plugin <= 9.5.9 - Broken Access Control vulnerabi… |
| CVE-2025-55652 | 5.5 | 17.2 | n/a | n/a | CWE-122 | A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ex… |
| CVE-2025-55660 | 5.5 | 17.2 | n/a | n/a | CWE-121 | A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.… |
| CVE-2025-55661 | 5.5 | 17.2 | n/a | n/a | CWE-122 | A heap buffer overflow in the Opus audio stream parser component of GPAC MP4B… |
| CVE-2026-42664 | 8.2 | 17.1 | Motive Commerce Search | AI Product Search for WooCommerce – Motive Commerce Search | CWE-862 | WordPress AI Product Search for WooCommerce – Motive Commerce Search plugin <… |
| CVE-2026-24637 | 8.5 | 16.9 | Blubrry Podcasting | PowerPress Podcasting | CWE-89 | WordPress PowerPress Podcasting plugin <= 11.15.10 - SQL Injection vulnerability |
| CVE-2026-49078 | 7.5 | 16.8 | WP Travel Engine | WP Travel Engine | CWE-1284 | WordPress WP Travel Engine plugin <= 6.7.10 - Other Vulnerability Type vulner… |
| CVE-2026-40743 | 6.5 | 16.8 | Themeum | Tutor LMS | CWE-862 | WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability |
| CVE-2026-34886 | 7.5 | 16.7 | wp.insider | Simple Membership | CWE-862 | WordPress Simple Membership plugin <= 4.7.1 - Broken Access Control vulnerabi… |
| CVE-2026-40762 | 7.5 | 16.7 | WPGraphQL | WPGraphQL | CWE-89 | WordPress WPGraphQL plugin < 2.11.1 - SQL Injection vulnerability |
| CVE-2026-40792 | 6.3 | 16.5 | Iqonic Design | KiviCare | CWE-639 | WordPress KiviCare plugin <= 4.2.1 - Insecure Direct Object References (IDOR)… |
| CVE-2026-42655 | 5.9 | 16.5 | WPManageNinja | Best Payments Plugin for WP | CWE-472 | WordPress Best Payments Plugin for WP plugin <= 4.6.19 - Payment Bypass vulne… |
| CVE-2026-50881 | 8.1 | 16.3 | n/a | n/a | CWE-284 | Incorrect access control in the impworks Bonsai v6.0 allows authenticated att… |
| CVE-2026-50888 | 8.1 | 16.3 | n/a | n/a | CWE-918 | An authenticated Server-Side Request Forgery (SSRF) in the custom scraper sub… |
| CVE-2026-34898 | 7.5 | 16.1 | WP Swings | Event Tickets Manager for WooCommerce | CWE-862 | WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.3 - Broken Acce… |
| CVE-2026-39503 | 7.5 | 16.0 | Awesomemotive | Easy Digital Downloads | CWE-862 | WordPress Easy Digital Downloads plugin <= 3.6.5 - Broken Access Control vuln… |
| CVE-2026-39524 | 7.5 | 16.0 | ThemeGrill | Masteriyo - LMS | CWE-862 | WordPress Masteriyo - LMS plugin <= 2.1.5 - Payment Bypass vulnerability |
| CVE-2026-40741 | 7.5 | 16.0 | Jose Conti | Redsys for WooCommerce Light | CWE-862 | WordPress Redsys for WooCommerce Light plugin <= 7.0.0 - Broken Access Contro… |
| CVE-2026-53703 | 7.1 | 15.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demu… |
| CVE-2016-20084 | 5.1 | 15.9 | dwbooster | Booking Calendar Contact | CWE-79 | WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS |
| CVE-2026-52695 | 7.5 | 15.7 | Al Monsor | ABC Crypto Checkout | CWE-201 | WordPress ABC Crypto Checkout plugin <= 1.8.2 - Sensitive Data Exposure vulne… |
| CVE-2025-55641 | 5.5 | 15.7 | n/a | n/a | CWE-476 | A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia… |
| CVE-2025-55643 | 5.5 | 15.7 | n/a | n/a | CWE-476 | A NULL pointer dereference in the TrackWriter handling component (filters/mux… |
| CVE-2025-55644 | 5.5 | 15.7 | n/a | n/a | CWE-416 | A heap use-after-free in the gf_node_get_tag function (scenegraph/base_sceneg… |
| CVE-2025-55647 | 5.5 | 15.7 | n/a | n/a | CWE-190 | An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c… |
| CVE-2025-55649 | 5.5 | 15.7 | n/a | n/a | CWE-476 | A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom… |
| CVE-2025-55650 | 5.5 | 15.7 | n/a | n/a | CWE-416 | A heap use-after-free in the gf_node_get_tag function (scenegraph/base_sceneg… |
| CVE-2025-55663 | 5.5 | 15.7 | n/a | n/a | CWE-476 | A segmentation violation in the Track_SetStreamDescriptor function (isomedia/… |
| CVE-2026-39525 | 6.5 | 15.6 | Booking Activities Team | Booking Activities | CWE-862 | WordPress Booking Activities plugin <= 1.16.48.1 - Broken Access Control vuln… |
| CVE-2026-40782 | 6.5 | 15.6 | Greg Winiarski | WPAdverts | CWE-862 | WordPress WPAdverts plugin <= 2.3.0 - Broken Access Control vulnerability |
| CVE-2025-68049 | 6.3 | 15.6 | bunny.net | bunny.net | CWE-862 | WordPress bunny.net plugin <= 2.3.6 - Broken Access Control vulnerability |
| CVE-2026-42651 | 6.3 | 15.6 | Mamunur Rashid | Classified Listing | CWE-862 | WordPress Classified Listing plugin <= 5.3.9 - Broken Access Control vulnerab… |
| CVE-2016-20069 | 8.8 | 15.4 | dwbooster | Booking Calendar Contact Form | CWE-89 | WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
| CVE-2026-49111 | 8.8 | 15.1 | ThemeGrill | Masteriyo - LMS | CWE-266 | WordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerability |
| CVE-2026-40774 | 7.5 | 15.1 | SaasProject | Booking Package | CWE-862 | WordPress Booking Package plugin <= 1.7.06 - Broken Access Control vulnerability |
| CVE-2026-48873 | 7.5 | 15.1 | Montonio | Montonio for WooCommerce | CWE-862 | WordPress Montonio for WooCommerce plugin <= 10.1.2 - Broken Access Control v… |
| CVE-2026-48883 | 7.5 | 15.1 | WPClever | WPC Product Bundles for WooCommerce | CWE-862 | WordPress WPC Product Bundles for WooCommerce plugin <= 8.5.3 - Broken Access… |
| CVE-2026-49064 | 7.5 | 15.0 | Stiofan | GetPaid | CWE-201 | WordPress GetPaid plugin <= 2.8.49 - Sensitive Data Exposure vulnerability |
| CVE-2026-49070 | 7.5 | 15.1 | Knit Pay | Knit Pay | CWE-862 | WordPress Knit Pay plugin <= 9.4.0.0 - Broken Access Control vulnerability |
| CVE-2026-52692 | 7.5 | 15.0 | wp.insider | Affiliates Manager | CWE-201 | WordPress Affiliates Manager plugin <= 2.9.50 - Sensitive Data Exposure vulne… |
| CVE-2026-52694 | 7.5 | 15.0 | WP E-Signature | Signature Add-On for WooCommerce | CWE-497 | WordPress Signature Add-On for WooCommerce plugin <= 2.0 - Sensitive Data Exp… |
| CVE-2026-49065 | 8.2 | 15.0 | hippooo | Hippoo Mobile App for WooCommerce | CWE-862 | WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.5 - Broken Access C… |
| CVE-2026-23970 | 7.1 | 14.9 | Themeisle | Redirection for Contact Form 7 | CWE-79 | WordPress Redirection for Contact Form 7 plugin <= 3.2.8 - Cross Site Scripti… |
| CVE-2026-39447 | 7.1 | 14.9 | NSquared | Simply Schedule Appointments | CWE-79 | WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Script… |
| CVE-2026-48838 | 7.1 | 14.9 | WPExperts | Post SMTP | CWE-79 | WordPress Post SMTP plugin <= 3.6.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-49110 | 7.5 | 14.8 | WP Swings | Upsell Order Bump Offer for WooCommerce | CWE-1284 | WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.4 - Price Man… |
| CVE-2026-42688 | 6.5 | 14.9 | WP Chill | Modula Image Gallery | CWE-79 | WordPress Modula Image Gallery plugin <= 2.14.23 - Cross Site Scripting (XSS)… |
| CVE-2026-11860 | 7.5 | 14.7 | OpenSolution | Quick.CMS | CWE-94 | Insecure Deserialisation via Plaintext HTTP leading to Remote Code Execution … |
| CVE-2026-48887 | 6.5 | 14.7 | Ahmad | JS Help Desk | CWE-862 | WordPress JS Help Desk plugin <= 3.0.9 - Broken Access Control vulnerability |
| CVE-2026-9260 | 6.9 | 14.3 | Canon Inc. | EOS Network Setting Tool for Windows | CWE-798 | Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Versio… |
| CVE-2016-20070 | 5.1 | 14.2 | dwbooster | Booking Calendar Contact Form | CWE-79 | WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS |
| CVE-2026-52699 | 7.5 | 14.1 | e4jvikwp | VikRentCar | CWE-639 | WordPress VikRentCar plugin <= 1.4.5 - Insecure Direct Object References (IDO… |
| CVE-2026-39449 | 7.1 | 14.1 | IT Path Solutions | Contact Form to Any API | CWE-79 | WordPress Contact Form to Any API plugin <= 3.0.3 - Cross Site Scripting (XSS… |
| CVE-2026-39463 | 7.1 | 14.1 | ManageWP | ManageWP Worker | CWE-79 | WordPress ManageWP Worker plugin <= 4.9.31 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-48871 | 7.1 | 14.1 | Takashi Kitajima | MW WP Form | CWE-79 | WordPress MW WP Form plugin <= 5.1.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-49055 | 7.1 | 14.1 | Glen Don Mongaya | Drag and Drop Multiple File Upload – Contact Form 7 | CWE-79 | WordPress Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.9… |
| CVE-2026-39491 | 6.5 | 14.0 | artbees | JupiterX Core | CWE-79 | WordPress JupiterX Core plugin <= 4.14.1 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-53704 | 7.1 | 13.8 | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | CWE-125 | Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demu… |
| CVE-2026-12210 | 2.1 | 13.8 | universal-tool-calling-protocol | python-utcp | CWE-918 | universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-si… |
| CVE-2019-25746 | 7.1 | 13.5 | SlicedInvoices | Sliced Invoices | CWE-89 | WordPress Sliced Invoices 3.8.2 SQL Injection via post Parameter |
| CVE-2026-12207 | 2.1 | 13.5 | medkey-org | medkey | CWE-99 | medkey-org medkey HTTP REST API PatientController.php actionGetPatientById re… |
| CVE-2026-45388 | 9.1 | 13.4 | n/a | n/a | CWE-295 | In OCaml-TLS before 2.1.0, the client implementation does insufficient checks… |
| CVE-2026-40775 | 7.3 | 13.2 | Royal Plugins | Royal MCP | CWE-862 | WordPress Royal MCP plugin <= 1.4.2 - Broken Access Control vulnerability |
| CVE-2026-42752 | 6.5 | 13.0 | mra13 / Team Tips and Tricks HQ | Stripe Payments | CWE-440 | WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerability |
| CVE-2026-42657 | 5.3 | 12.7 | Wasiliy Strecker | Contest Gallery | CWE-1284 | WordPress Contest Gallery plugin <= 28.1.7 - Other Vulnerability Type vulnera… |
| CVE-2026-25440 | 5.3 | 12.0 | WPDeveloper | Essential Addons for Elementor | CWE-862 | WordPress Essential Addons for Elementor plugin < 6.6.0 - Broken Access Contr… |
| CVE-2026-12202 | 1.9 | 12.1 | Intelliants | Subrion CMS | CWE-79 | Intelliants Subrion CMS Blocks Endpoint cross site scripting |
| CVE-2026-49063 | 7.3 | 11.8 | Webilia Inc. | Listdom | CWE-266 | WordPress Listdom plugin <= 5.5.0 - Privilege Escalation vulnerability |
| CVE-2026-40791 | 7.1 | 11.5 | codepeople | WP Time Slots Booking Form | CWE-79 | WordPress WP Time Slots Booking Form plugin <= 1.2.46 - Cross Site Scripting … |
| CVE-2026-12212 | 2.1 | 11.1 | hcengineering | Huly Platform | CWE-266 | hcengineering Huly Platform RPC operations.ts getMailboxSecret access control |
| CVE-2026-5233 | 7.1 | 10.8 | MIA Technology Inc. | Pizzy Library | CWE-799 | Missing Rate Limiting in Mia Technologies' Pizzy Library |
| CVE-2026-39540 | 6.5 | 10.8 | Amit Mittal | Shipment Tracker for Woocommerce | CWE-79 | WordPress Shipment Tracker for Woocommerce plugin <= 1.5.3.2 - Cross Site Scr… |
| CVE-2026-41556 | 6.5 | 10.8 | properfraction | ProfilePress | CWE-79 | WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-42656 | 6.5 | 10.8 | Wasiliy Strecker | Contest Gallery | CWE-79 | WordPress Contest Gallery plugin <= 28.1.6 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-48870 | 6.5 | 10.8 | King Addons | King Addons for Elementor | CWE-79 | WordPress King Addons for Elementor plugin <= 51.1.62 - Cross Site Scripting … |
| CVE-2026-48880 | 6.5 | 10.8 | Ahmad | WP Job Portal | CWE-79 | WordPress WP Job Portal plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-12213 | 2.1 | 10.6 | hcengineering | Huly Platform | CWE-266 | hcengineering Huly Platform User Information operations.ts getAccountInfo imp… |
| CVE-2026-8683 | 6.5 | 10.1 | Mattermost | Mattermost | CWE-770 | Overly long URLs crash the Mattermost Desktop App |
| CVE-2026-34021 | 8.6 | 9.7 | Wertheim GmbH | Wertheim SafeController 5400 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller) | CWE-294 | Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-4… |
| CVE-2025-64215 | 6.5 | 9.7 | StylemixThemes | MasterStudy LMS Pro | CWE-862 | WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnera… |
| CVE-2026-12206 | 2.1 | 9.7 | Grit42 | Grit | CWE-74 | Grit42 Grit data_table_entity.rb DataTableEntity sql injection |
| CVE-2026-42650 | 7.2 | 9.6 | Ruben Garcia | AutomatorWP | CWE-79 | WordPress AutomatorWP plugin <= 5.6.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-9259 | 7.1 | 9.5 | Canon Inc. | EOS Network Setting Tool for Windows | CWE-295 | Improper validation of server certificates in Canon EOS Network Setting Tool … |
| CVE-2016-20066 | 5.1 | 9.2 | dwbooster | CP Polls | CWE-79 | WordPress CP Polls 1.0.8 Persistent Cross-Site Scripting |
| CVE-2026-45389 | 7.4 | 9.1 | n/a | n/a | CWE-295 | In OCaml-TLS before 2.1.0, the server implementation does insufficient checks… |
| CVE-2026-49775 | 6.5 | 9.0 | info@welcart | Welcart e-Commerce | CWE-862 | WordPress Welcart e-Commerce plugin <= 2.11.28 - Broken Access Control vulner… |
| CVE-2026-42640 | 6.5 | 8.8 | Mamunur Rashid | Classified Listing | CWE-862 | WordPress Classified Listing plugin <= 5.3.8 - Broken Access Control vulnerab… |
| CVE-2026-6517 | 7.7 | 8.6 | Mattermost | Mattermost | CWE-522 | Mattermost Desktop App fails to restrict the allow list of domains which NTLM… |
| CVE-2025-68851 | 7.1 | 8.5 | ArrayHQ | Okay Toolkit | CWE-79 | WordPress Okay Toolkit plugin <= 2.3 - Reflected Cross Site Scripting (XSS) v… |
| CVE-2026-9261 | 7.6 | 8.3 | Canon Inc. | EOS Network Setting Tool for Windows | CWE-327 | Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Ve… |
| CVE-2026-36521 | 6.1 | 8.0 | n/a | n/a | CWE-79 | PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the s… |
| CVE-2026-37216 | 6.1 | 8.0 | n/a | n/a | CWE-79 | Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /sys… |
| CVE-2025-68840 | 7.1 | 7.2 | markbeljaars | iRobots.txt SEO | CWE-79 | WordPress iRobots.txt SEO plugin <= 1.1.2 - Reflected Cross Site Scripting (X… |
| CVE-2025-68872 | 7.1 | 7.2 | Eli | Eli's WordCents adSense Widget with Analytics | CWE-79 | WordPress Eli's WordCents adSense Widget with Analytics plugin <= 1.3.03.27 -… |
| CVE-2026-34900 | 7.1 | 7.2 | Liquid Web / StellarWP | GiveWP | CWE-79 | WordPress GiveWP plugin <= 4.14.2 - Reflected Cross Site Scripting (XSS) vuln… |
| CVE-2026-34902 | 7.1 | 7.2 | WC Product Table | WooCommerce Product Table Lite | CWE-79 | WordPress WooCommerce Product Table Lite plugin <= 4.6.3 - Cross Site Scripti… |
| CVE-2026-39435 | 7.1 | 7.2 | bgermann | CformsII | CWE-79 | WordPress CformsII plugin <= 15.1.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-39507 | 7.1 | 7.2 | Themeisle | Social Slider Feed | CWE-79 | WordPress Social Slider Feed plugin <= 2.3.2 - Cross Site Scripting (XSS) vul… |
| CVE-2026-39514 | 7.1 | 7.2 | Cozmoslabs | Paid Member Subscriptions | CWE-79 | WordPress Paid Member Subscriptions plugin <= 2.17.3 - Reflected Cross Site S… |
| CVE-2026-40732 | 7.1 | 7.3 | rainafarai | Notification for Telegram | CWE-79 | WordPress Notification for Telegram plugin <= 3.5 - Cross Site Scripting (XSS… |
| CVE-2026-40770 | 7.1 | 7.3 | RelyWP | Coupon Affiliates | CWE-79 | WordPress Coupon Affiliates plugin <= 7.5.3 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-40787 | 7.1 | 7.3 | ExpressTech | Quiz And Survey Master | CWE-79 | WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS… |
| CVE-2026-42649 | 7.1 | 7.2 | Archetyped | Favicon Rotator | CWE-79 | WordPress Favicon Rotator plugin <= 1.2.11 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-42658 | 7.1 | 7.2 | Mamunur Rashid | Classified Listing | CWE-79 | WordPress Classified Listing plugin <= 5.3.8 - Cross Site Scripting (XSS) vul… |
| CVE-2026-42775 | 7.1 | 7.2 | Ruben Garcia | AutomatorWP | CWE-79 | WordPress AutomatorWP plugin <= 5.7.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-45437 | 7.1 | 7.2 | Bhavin Thummar | Product Filter Widget for Elementor | CWE-79 | WordPress Product Filter Widget for Elementor plugin <= 1.0.6 - Cross Site Sc… |
| CVE-2026-48867 | 7.1 | 7.2 | ExpressTech | Quiz And Survey Master | CWE-79 | WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS… |
| CVE-2026-48876 | 7.1 | 7.2 | Web Guy | Stop Spammers | CWE-79 | WordPress Stop Spammers plugin <= 2026.3 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-48885 | 7.1 | 7.2 | Groundhogg | HollerBox | CWE-79 | WordPress HollerBox plugin <= 2.3.10.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-48966 | 7.1 | 7.2 | FunnelKit | Funnel Builder by FunnelKit | CWE-79 | WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.2 - Cross Site Scripti… |
| CVE-2026-39451 | 6.3 | 7.2 | jgwhite33 | WP Google Review Slider | CWE-79 | WordPress WP Google Review Slider plugin <= 18.0 - Cross Site Scripting (XSS)… |
| CVE-2026-5230 | 7.1 | 7.2 | MIA Technology Inc. | Pizzy Library | CWE-284 | Improper Access Control in Mia Technologies' Pizzy Library |
| CVE-2026-36933 | 6.8 | 7.1 | n/a | n/a | CWE-284 | An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically prox… |
| CVE-2026-48518 | 4.3 | 6.9 | juice-shop | multi-juicer | CWE-352 | MultiJuicer: Login CSRF allows attacker to force victims into their team |
| CVE-2026-50892 | 6.5 | 6.9 | n/a | n/a | CWE-284 | Incorrect access control in the "Let's Encrypt" certificate download endpoint… |
| CVE-2026-8358 | 5.4 | 6.9 | The Document Foundation | LibreOffice | CWE-787 | Heap buffer overflow in spreadsheet tracked-changes import |
| CVE-2025-70102 | 6.3 | 6.6 | n/a | n/a | CWE-476 | A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd … |
| CVE-2025-60175 | 4.4 | 6.5 | vynnus | PopAd | CWE-918 | WordPress PopAd Plugin <= 1.0.4 - Server Side Request Forgery (SSRF) Vulnerab… |
| CVE-2026-47777 | 7.5 | 6.4 | mastodon | mastodon | CWE-345 | Mastodon has a consent-check bypass in its remote Collections |
| CVE-2026-48157 | 6.1 | 6.4 | slimphp | Slim | CWE-79 | Slim has Reflected XSS in the HtmlErrorRenderer |
| CVE-2026-49773 | 6.5 | 6.4 | FolioVision | FV Flowplayer Video Player | CWE-79 | WordPress FV Flowplayer Video Player plugin < 7.5.51.7212 - Cross Site Script… |
| CVE-2025-56814 | 7.8 | 6.2 | n/a | n/a | CWE-77 | A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0… |
| CVE-2026-9595 | 4.3 | 6.0 | webpack-dev-server | webpack-dev-server | CWE-346 | webpack-dev-server vulnerable to HMR WebSocket interception via permissive us… |
| CVE-2026-50876 | 5.4 | 5.9 | n/a | n/a | CWE-79 | A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attac… |
| CVE-2026-42663 | 6.5 | 5.8 | wp.insider | Simple Membership | CWE-79 | WordPress Simple Membership plugin <= 4.7.2 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-9278 | 5.4 | 5.6 | Unknown | Form Builder CP | — | Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure |
| CVE-2026-6039 | 5.4 | 5.4 | The Document Foundation | LibreOffice | CWE-197 | Heap buffer overflow in DXF polyline import |
| CVE-2026-8357 | 5.4 | 5.3 | The Document Foundation | LibreOffice | CWE-193 | Heap buffer overflow in Calc formula compilation |
| CVE-2026-49043 | 4.7 | 5.0 | WP Engine | WP Migrate Lite | CWE-352 | WordPress WP Migrate Lite plugin <= 2.7.8 - Cross Site Request Forgery (CSRF)… |
| CVE-2026-49294 | 6.1 | 4.6 | valhalla | valhalla | CWE-79 | Valhalla has reflected XSS via unsanitized JSONP callback parameter |
| CVE-2026-12162 | 5.5 | 4.5 | Devolutions | Remote Desktop Manager | CWE-297 | Improper host validation in the social login autofill feature in Devolutions … |
| CVE-2026-52702 | 7.1 | 4.3 | wp-buy | SEO Redirection | CWE-79 | WordPress SEO Redirection plugin <= 9.17 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-48124 | 8.5 | 4.2 | cursor | cursor | CWE-94 | Cursor Desktop sandbox escape via Claude hook configuration |
| CVE-2026-42743 | 6.5 | 4.2 | ThemeGrill | Masteriyo - LMS | CWE-347 | WordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerability |
| CVE-2025-15658 | 5.9 | 3.8 | rewish | WP Emmet | CWE-79 | WordPress WP Emmet plugin <= 0.3.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-47825 | 8.6 | 3.8 | Spring | Spring Cloud Gateway | CWE-346 | Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certai… |
| CVE-2016-20083 | 6.9 | 3.7 | henrikmelin | More Fields | CWE-352 | WordPress More Fields Plugin 2.1 Cross-Site Request Forgery |
| CVE-2026-50100 | 8.5 | 3.2 | Ricoh Company, Ltd. | Multiple printer drivers | CWE-427 | Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA J… |
| CVE-2025-15659 | 6.5 | 3.1 | liseperu | Elizaibots | CWE-79 | WordPress Elizaibots plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-12057 | 7.8 | 3.0 | Foxit Software Inc. | Foxit AI | CWE-829 | DoS + Remote Code Execution via PDF JavaScript in Foxit AI |
| CVE-2026-12214 | 7.1 | 2.6 | Qihoo | 360 Total Security | CWE-693 | Qihoo 360 Total Security Nucleus Engine Monitoring Logic RpcStringBindingComp… |
| CVE-2026-11931 | 6.8 | 2.4 | AWS | Kiro IDE | CWE-276 | Insecure Permissions on Authentication Token Cache File in Kiro IDE |
| CVE-2026-34029 | 6.8 | 2.1 | Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | CWE-321 | Hard-coded cryptographic key in Wertheim SafeController Software allows decry… |
| CVE-2026-6045 | 5.4 | 2.1 | The Document Foundation | LibreOffice | CWE-190 | Heap buffer overflow in EMF+ gradient brush import |
| CVE-2026-6047 | 5.4 | 2.1 | The Document Foundation | LibreOffice | CWE-787 | Heap buffer overflow in OOXML text box element import |
| CVE-2026-8356 | 5.4 | 2.1 | The Document Foundation | LibreOffice | CWE-121 | Stack buffer overflow in PPT presentation import |
| CVE-2026-39118 | 8.4 | 2.0 | n/a | n/a | CWE-269 | An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacke… |
| CVE-2026-34022 | 7.1 | 1.9 | Wertheim GmbH | Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller) | CWE-321 | Weak custom cryptography and hard-coded keys in Wertheim SafeController 65000… |
| CVE-2016-20067 | 5.3 | 1.9 | dwbooster | CP Polls | CWE-352 | WordPress CP Polls 1.0.8 Cross-Site Request Forgery |
| CVE-2026-5064 | 8.5 | 1.7 | HP Inc. | HP One Agent Software | CWE-427 | HP One Agent Software – Security Update |
| CVE-2026-6040 | 5.4 | 1.7 | The Document Foundation | LibreOffice | CWE-416 | Heap use-after-free in ODF number-format blank-width parsing |
| CVE-2026-12216 | 1.9 | 1.6 | svaarala | duktape | CWE-119 | svaarala duktape duk_api_bytecode.c memory corruption |
| CVE-2026-12217 | 7.1 | 1.5 | DVDFab | Virtual Drive | CWE-266 | DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management |
| CVE-2026-52721 | 5.3 | 1.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gstreamer1-plugins-bad-free: gstreamer: multiple out-of-bounds reads in pcapp… |
| CVE-2016-20074 | 5.3 | 1.3 | leethompson | Lazy Content Slider Plugin | CWE-352 | WordPress Lazy Content Slider Plugin 3.4 CSRF |
| CVE-2026-12201 | 1.9 | 1.1 | IObit | Malware Fighter | CWE-266 | IObit Malware Fighter DLL permission |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-15 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.