| CVE-2026-8383 | 5.3 | 44.1 | Unknown | LearnPress | CWE-862 | LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure vi… |
| CVE-2026-49767 | 9.8 | 43.3 | Tomdever | wpForo Forum | CWE-288 | WordPress wpForo Forum plugin <= 3.1.0 - Broken Authentication vulnerability |
| CVE-2026-40783 | 9.9 | 43.0 | Creative Themes | Blocksy Companion Pro | CWE-94 | WordPress Blocksy Companion Pro plugin <= 2.1.37 - Remote Code Execution (RCE… |
| CVE-2026-27400 | 8.6 | 42.9 | Ovatheme | BookPro | CWE-22 | WordPress BookPro plugin <= 1.1.0 - Arbitrary File Deletion vulnerability |
| CVE-2025-60205 | 9.8 | 42.1 | ThemeREX | ThemeREX Addons | CWE-502 | WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerabi… |
| CVE-2026-53874 | 9.3 | 41.7 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Obfuscated eval Call |
| CVE-2026-12115 | 6.6 | 41.8 | wpcalc | Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress | CWE-502 | Counter Box <= 2.0.13 - Authenticated (Administrator+) PHP Object Injection v… |
| CVE-2026-42380 | 9.8 | 41.2 | jwsthemes | AI Lab | CWE-502 | WordPress AI Lab theme < 5.4.2 - PHP Object Injection vulnerability |
| CVE-2026-53872 | 8.7 | 41.1 | picklescan | picklescan | CWE-22 | picklescan - Arbitrary File Read via Unsafe Pickle Deserialization |
| CVE-2026-20190 | 7.5 | 40.8 | Cisco | Cisco Identity Services Engine Software | CWE-285 | Cisco Identity Services Engine Information Disclosure Vulnerability |
| CVE-2026-49268 | 8.8 | 40.2 | Apache Software Foundation | Apache Shiro | CWE-90 | Apache Shiro: LDAP DN Injection in DefaultLdapRealm |
| CVE-2026-52707 | 8.1 | 40.2 | Mikado-Themes | Kastell | CWE-35 | WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability |
| CVE-2026-50107 | 8.6 | 40.1 | F5 | NGINX Gateway Fabric | CWE-74 | NGINX Gateway Fabric vulnerability |
| CVE-2025-69130 | 8.8 | 39.5 | Themovation | Entrepreneur - Booking for Small Businesses WordPress Theme | CWE-502 | WordPress Entrepreneur - Booking for Small Businesses WordPress Theme theme <… |
| CVE-2025-71325 | 9.3 | 39.1 | picklescan | picklescan | CWE-391 | picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw |
| CVE-2024-52488 | 9.9 | 38.7 | Zidithemes | Grip | CWE-434 | WordPress Grip theme <= 1.0.9 - Arbitrary Plugin Activation/Deactivation to R… |
| CVE-2026-36418 | 9.1 | 38.7 | n/a | n/a | CWE-94 | JimuReport versions 2.3.4 and below are vulnerable to remote code execution d… |
| CVE-2026-9690 | 7.5 | 38.5 | Joomunited | WP Media folder Addon | CWE-22 | WordPress WP Media folder Addon plugin <= 4.0.1 - Arbitrary File Download vul… |
| CVE-2026-22334 | 7.5 | 38.5 | WPos | Woocommerce Book Price | CWE-22 | WordPress Woocommerce Book Price plugin <= 1.3 - Arbitrary File Download vuln… |
| CVE-2026-52706 | 9.8 | 38.4 | Jetimpex Inc. | JetEngine | CWE-502 | WordPress JetEngine plugin <= 3.8.10 - PHP Object Injection vulnerability |
| CVE-2026-22327 | 9.9 | 38.4 | Zozothemes | Restaurt | CWE-434 | WordPress Restaurt theme <= 1.0.4 - Arbitrary File Upload vulnerability |
| CVE-2026-53873 | 9.3 | 38.0 | picklescan | picklescan | CWE-184 | picklescan - Arbitrary Code Execution via profile.run() Blocklist Bypass |
| CVE-2025-69128 | 8.6 | 38.0 | EMV | JobCareer | CWE-22 | WordPress JobCareer theme <= 7.3 - Arbitrary File Deletion vulnerability |
| CVE-2026-9697 | 7.4 | 38.0 | undici | undici | CWE-295 | undici vulnerable to TLS certificate validation bypass via dropped requestTls… |
| CVE-2025-59872 | 9.8 | 37.6 | HCL Software | ZIE | CWE-434 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, |
| CVE-2025-69179 | 9.8 | 37.4 | Theme passion | Support Ticket Management System | CWE-266 | WordPress Support Ticket Management System plugin <= 1.9 - Privilege Escalati… |
| CVE-2026-54803 | 9.8 | 37.4 | Cozy Vision Technologies Pvt. Ltd. | SMS Alert Order Notifications | CWE-863 | WordPress SMS Alert Order Notifications plugin <= 3.9.4 - Privilege Escalatio… |
| CVE-2025-60223 | 7.7 | 37.4 | QuantumCloud | WPBot Pro Wordpress Chatbot | CWE-22 | WordPress WPBot Pro Wordpress Chatbot plugin <= 13.6.5 - Arbitrary File Delet… |
| CVE-2026-39589 | 9.9 | 37.3 | A WP Life | Webenvo | CWE-434 | WordPress Webenvo theme <= 0.0.6 - Arbitrary File Upload vulnerability |
| CVE-2025-60218 | 9.9 | 37.1 | WPLocker | PT Luxa Addons | CWE-434 | WordPress PT Luxa Addons Plugin <= 1.2.2 - Arbitrary File Upload Vulnerability |
| CVE-2026-54387 | 9.3 | 36.5 | tinyproxy | tinyproxy | CWE-444 | Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization |
| CVE-2026-54388 | 9.3 | 36.5 | tinyproxy | tinyproxy | CWE-444 | Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers |
| CVE-2026-54807 | 9.8 | 36.4 | ThemeGrill | Registration Form for WooCommerce | CWE-266 | WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escal… |
| CVE-2026-24611 | 9.1 | 36.4 | WPMet | MetForm Pro | CWE-862 | WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability |
| CVE-2026-41280 | 4.9 | 36.4 | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users w… |
| CVE-2025-69106 | 8.1 | 36.3 | ThemeREX | Imba | CWE-98 | WordPress Imba theme <= 1.5.0 - Local File Inclusion vulnerability |
| CVE-2025-69110 | 8.1 | 36.3 | ThemeREX | AirSupply | CWE-98 | WordPress AirSupply theme <= 2.0.0 - Local File Inclusion vulnerability |
| CVE-2025-69117 | 8.1 | 36.3 | ThemeREX | Ingenioso | CWE-98 | WordPress Ingenioso theme <= 1.14.0 - Local File Inclusion vulnerability |
| CVE-2025-69120 | 8.1 | 36.3 | ThemeREX | Dazzle | CWE-98 | WordPress Dazzle theme <= 1.0.0 - Local File Inclusion vulnerability |
| CVE-2025-69148 | 8.1 | 36.3 | ThemeREX | Quirky | CWE-98 | WordPress Quirky theme <= 1.23 - Local File Inclusion vulnerability |
| CVE-2025-69157 | 8.1 | 36.3 | ThemeREX | Gamic | CWE-98 | WordPress Gamic theme <= 1.15 - Local File Inclusion vulnerability |
| CVE-2025-69166 | 8.1 | 36.3 | ThemeREX | Gunslinger | CWE-98 | WordPress Gunslinger theme <= 1.7 - Local File Inclusion vulnerability |
| CVE-2025-69172 | 8.1 | 36.2 | ThemeREX | Resurs | CWE-98 | WordPress Resurs theme <= 1.3 - Local File Inclusion vulnerability |
| CVE-2025-69173 | 8.1 | 36.3 | ThemeREX | Tipsy | CWE-98 | WordPress Tipsy theme <= 1.1 - Local File Inclusion vulnerability |
| CVE-2026-25446 | 9.9 | 36.1 | WishList Products, LLC. | WishList Member X | CWE-434 | WordPress WishList Member X plugin <= 3.29.0 - Arbitrary File Upload vulnerab… |
| CVE-2026-40746 | 9.9 | 36.1 | themagnifico52 | Restaurant Zone | CWE-434 | WordPress Restaurant Zone theme <= 0.7.8 - Arbitrary File Upload vulnerability |
| CVE-2026-40747 | 9.9 | 36.1 | themagnifico52 | Ecommerce Zone | CWE-434 | WordPress Ecommerce Zone theme <= 0.9.7 - Arbitrary File Upload vulnerability |
| CVE-2026-40748 | 9.9 | 36.1 | themagnifico52 | Kids Gift Shop | CWE-434 | WordPress Kids Gift Shop theme <= 0.5.4 - Arbitrary File Upload vulnerability |
| CVE-2026-40749 | 9.9 | 36.1 | themagnifico52 | Charity Zone | CWE-434 | WordPress Charity Zone theme <= 1.1.1 - Arbitrary File Upload vulnerability |
| CVE-2026-53875 | 7.1 | 36.2 | picklescan | picklescan | CWE-95 | picklescan - Scanning Bypass via Dynamic Eval in scan_pytorch |
| CVE-2026-47340 | 6.5 | 36.1 | Apache Software Foundation | Apache DolphinScheduler | CWE-200 | Apache DolphinScheduler: An incorrect authorization vulnerability allows auth… |
| CVE-2025-69129 | 10.0 | 36.0 | Extendons | WordPress & WooCommerce Scraper Plugin, Import Data from Any Site | CWE-434 | WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site p… |
| CVE-2024-32729 | 7.5 | 35.8 | QuantumCloud | Conversational Forms for ChatBot | CWE-22 | WordPress ChatBot Conversational Forms plugin <= 1.1.8 - Arbitrary File Downl… |
| CVE-2025-60229 | 9.8 | 35.5 | Themeton | Lagom | CWE-502 | WordPress Lagom theme <= 2.0 - PHP Object Injection vulnerability |
| CVE-2025-60230 | 9.8 | 35.5 | Themeton | The Barber Shop | CWE-502 | WordPress The Barber Shop theme <= 1.9 - PHP Object Injection vulnerability |
| CVE-2026-12447 | 8.8 | 35.5 | Google | Chrome | CWE-122 | Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allow… |
| CVE-2026-12466 | 8.8 | 35.5 | Google | Chrome | CWE-122 | Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.782… |
| CVE-2026-9675 | 7.5 | 35.5 | undici | undici | CWE-400 | undici WebSocket client vulnerable to denial of service via cumulative fragme… |
| CVE-2025-58953 | 8.1 | 35.3 | ThemeREX | Joly | CWE-98 | WordPress Joly theme <= 1.22.0 - Local File Inclusion vulnerability |
| CVE-2025-58954 | 8.1 | 35.3 | ThemeREX | HomeRoofer | CWE-98 | WordPress HomeRoofer theme <= 2.11.0 - Local File Inclusion vulnerability |
| CVE-2026-39537 | 8.1 | 35.3 | Mikado-Themes | Mikado Core | CWE-98 | WordPress Mikado Core plugin <= 1.6 - Local File Inclusion vulnerability |
| CVE-2026-40731 | 8.1 | 35.3 | Mikado-Themes | ChapterOne | CWE-98 | WordPress ChapterOne theme <= 1.7 - Local File Inclusion vulnerability |
| CVE-2026-10839 | 5.1 | 35.0 | Password Manager | Password Manager | CWE-601 | Open redirection vulnerability in Password Manager |
| CVE-2026-54417 | 8.7 | 34.8 | rxi | microtar | CWE-190 | Integer Overflow in rxi/microtar mtar_next() Causes Infinite Loop DoS |
| CVE-2026-40724 | 6.5 | 34.3 | Client Portal Ltd. | Client Portal (Pro) | CWE-22 | WordPress Client Portal (Pro) plugin <= 5.6.2 - Arbitrary File Download vulne… |
| CVE-2026-40721 | 7.5 | 33.2 | BdThemes | Element Pack Pro | CWE-98 | WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability |
| CVE-2026-55738 | 8.7 | 33.0 | rxi | microtar | CWE-121 | Stack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated… |
| CVE-2026-48989 | 8.9 | 32.8 | CursorTouch | Windows-MCP | CWE-306 | Windows-MCP: HTTP transports expose unauthenticated PowerShell control with w… |
| CVE-2025-59554 | 9.3 | 32.8 | Advanced Ads GmbH | Advanced Ads – Tracking | CWE-89 | WordPress Advanced Ads – Tracking plugin < 3.0.7 - SQL Injection vulnerability |
| CVE-2026-12165 | 8.8 | 32.8 | contest-gallery | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | CWE-269 | Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via … |
| CVE-2026-12442 | 8.8 | 32.7 | Google | Chrome | CWE-416 | Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.1… |
| CVE-2026-39445 | 8.1 | 32.6 | PressLayouts | Alukas | CWE-502 | WordPress Alukas theme < 3.0.0 - PHP Object Injection vulnerability |
| CVE-2026-39545 | 8.1 | 32.6 | Select-Themes | Zermatt | CWE-502 | WordPress Zermatt theme <= 1.6.1 - PHP Object Injection vulnerability |
| CVE-2026-39573 | 8.1 | 32.6 | Select-Themes | Mildhill | CWE-502 | WordPress Mildhill theme <= 1.5 - PHP Object Injection vulnerability |
| CVE-2026-39576 | 8.1 | 32.6 | Elated-Themes | SingleMalt | CWE-502 | WordPress SingleMalt theme <= 1.5 - PHP Object Injection vulnerability |
| CVE-2026-40735 | 8.1 | 32.6 | Edge-Themes | Reina | CWE-502 | WordPress Reina theme <= 2.1 - PHP Object Injection vulnerability |
| CVE-2026-27868 | 6.9 | 32.5 | Teldat | Regesta Smart HD-PLC - TLDPH16D2 | CWE-201 | PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT |
| CVE-2026-27869 | 6.9 | 32.5 | Teldat | Regesta Smart HD-PLC - TLDPH16D2 | CWE-770 | WEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC… |
| CVE-2025-26240 | 8.4 | 32.4 | n/a | n/a | CWE-120 | In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution… |
| CVE-2026-32966 | 9.8 | 32.2 | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to … |
| CVE-2025-69138 | 8.8 | 32.1 | Jthemes | Genemy | CWE-266 | WordPress Genemy theme <= 1.6.6 - Privilege Escalation vulnerability |
| CVE-2026-55743 | 9.4 | 32.0 | tinyhumansai | OpenHuman | CWE-78 | OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command … |
| CVE-2025-69111 | 9.8 | 31.8 | ThemeREX | Reisen | CWE-502 | WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability |
| CVE-2025-69127 | 9.8 | 31.8 | ThemeREX | Plumbing | CWE-502 | WordPress Plumbing theme <= 1.6 - PHP Object Injection vulnerability |
| CVE-2026-45357 | 7.5 | 31.7 | harttle | liquidjs | CWE-400 | LiquidJS: Memory and render limit bypass via unbounded width padding in `date… |
| CVE-2026-45617 | 7.5 | 31.7 | harttle | liquidjs | CWE-1333 | LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex |
| CVE-2025-71322 | 8.7 | 31.5 | PickleScan | PickleScan | CWE-693 | PickleScan - Unsafe Globals Check Bypass via pty.spawn Function |
| CVE-2025-66391 | 8.8 | 31.5 | n/a | n/a | CWE-284 | In Citrix Cloud through 2025-11-10, an account with read-only access can trig… |
| CVE-2026-55202 | 8.8 | 31.3 | tinyproxy | tinyproxy | CWE-290 | Tinyproxy - Stathost Detection Bypass via Host Header Manipulation |
| CVE-2026-10094 | 9.8 | 31.2 | Dassault Systèmes | SOLIDWORKS Visualize | CWE-22 | Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS D… |
| CVE-2026-48988 | 5.3 | 31.0 | markdown-it | markdown-it | CWE-400 | markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt strin… |
| CVE-2025-59563 | 8.8 | 30.9 | SONAAR MUSIC | Sonaar | CWE-266 | WordPress Sonaar theme <= 4.27.4 - Privilege Escalation vulnerability |
| CVE-2026-54805 | 8.8 | 30.9 | sbouey | Falang multilanguage | CWE-266 | WordPress Falang multilanguage plugin <= 1.4.2 - Privilege Escalation vulnera… |
| CVE-2026-40725 | 9.8 | 30.6 | Barn2 Media Ltd | WooCommerce Product Filters | CWE-502 | WordPress WooCommerce Product Filters plugin < 2.0.6 - PHP Object Injection v… |
| CVE-2026-49075 | 9.8 | 30.6 | Jetimpex Inc. | JetEngine | CWE-502 | WordPress JetEngine plugin <= 3.8.9.1 - PHP Object Injection vulnerability |
| CVE-2026-49107 | 9.8 | 30.6 | Thrive Themes | Thrive Apprentice | CWE-502 | WordPress Thrive Apprentice plugin < 10.8.10.2 - PHP Object Injection vulnera… |
| CVE-2026-22340 | 9.3 | 30.3 | Jobster Marketplace | WPJobster | CWE-89 | WordPress WPJobster theme <= 6.3.5 - SQL Injection vulnerability |
| CVE-2026-39596 | 9.3 | 30.3 | Creative Themes | Blocksy Companion Pro | CWE-89 | WordPress Blocksy Companion Pro plugin < 2.1.29 - SQL Injection vulnerability |
| CVE-2026-48875 | 9.3 | 30.3 | Jetimpex Inc. | JetSmartFilters | CWE-89 | WordPress JetSmartFilters plugin <= 3.8.1 - SQL Injection vulnerability |
| CVE-2026-49076 | 9.3 | 30.3 | Jetimpex Inc. | JetEngine | CWE-89 | WordPress JetEngine plugin <= 3.8.9.1 - SQL Injection vulnerability |
| CVE-2026-54802 | 7.5 | 30.1 | Cozy Vision Technologies Pvt. Ltd. | SMS Alert Order Notifications | CWE-862 | WordPress SMS Alert Order Notifications plugin <= 3.9.3 - Broken Authenticati… |
| CVE-2026-48818 | 7.5 | 29.9 | Kludex | starlette | CWE-918 | Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Win… |
| CVE-2026-53871 | 8.6 | 29.6 | nesquena | hermes-webui | CWE-565 | Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged herm… |
| CVE-2026-8050 | 7.5 | 29.6 | SignalRGB | SignalRGB kernel driver | — | CVE-2026-8050 |
| CVE-2026-22325 | 8.1 | 29.4 | AxiomThemes | Promo | CWE-98 | WordPress Promo theme <= 1.3.0 - Local File Inclusion vulnerability |
| CVE-2026-22330 | 8.1 | 29.4 | Themeum | Right Way | CWE-98 | WordPress Right Way theme <= 4.0 - Local File Inclusion vulnerability |
| CVE-2026-22331 | 8.1 | 29.4 | ThemeREX | AutoParts | CWE-98 | WordPress AutoParts theme <= 1.5.8 - Local File Inclusion vulnerability |
| CVE-2026-9678 | 5.9 | 29.1 | undici | undici | CWE-524 | undici vulnerable to cross-user information disclosure via shared cache white… |
| CVE-2026-55706 | 8.3 | 28.5 | OpenBSD | OpenBSD | CWE-1284 | sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows auth… |
| CVE-2026-35065 | 8.8 | 28.4 | Dell | PowerFlex | CWE-306 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Aut… |
| CVE-2026-54415 | 8.6 | 27.8 | Azuriom | Azuriom CMS | CWE-269 | Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover |
| CVE-2025-69115 | 8.1 | 27.9 | ThemeREX | LuxMed | Medicine & Healthcare Doctor WordPress Theme | CWE-98 | WordPress LuxMed | Medicine & Healthcare Doctor WordPress Theme theme <= 1.2.… |
| CVE-2025-69123 | 8.1 | 27.9 | ThemeREX | Snow Club | CWE-98 | WordPress Snow Club theme <= 1.1 - Local File Inclusion vulnerability |
| CVE-2025-69126 | 8.1 | 27.9 | ThemeREX | Fortius | CWE-98 | WordPress Fortius theme <= 2.3.0 - Local File Inclusion vulnerability |
| CVE-2025-69144 | 8.1 | 27.9 | ThemeREX | Preservation | CWE-98 | WordPress Preservation theme <= 1.10 - Local File Inclusion vulnerability |
| CVE-2025-69145 | 8.1 | 27.9 | ThemeREX | Gat | CWE-98 | WordPress Gat theme <= 1.16 - Local File Inclusion vulnerability |
| CVE-2025-69158 | 8.1 | 27.9 | ThemeREX | Granola | CWE-98 | WordPress Granola theme <= 1.13 - Local File Inclusion vulnerability |
| CVE-2025-69161 | 8.1 | 27.9 | ThemeREX | Snowy | CWE-98 | WordPress Snowy theme <= 1.13 - Local File Inclusion vulnerability |
| CVE-2025-69164 | 8.1 | 27.9 | ThemeREX | Skyward | CWE-98 | WordPress Skyward theme <= 1.10 - Local File Inclusion vulnerability |
| CVE-2025-69170 | 8.1 | 27.9 | ThemeREX | Eventicity | CWE-98 | WordPress Eventicity theme <= 1.5 - Local File Inclusion vulnerability |
| CVE-2025-69171 | 8.1 | 27.9 | ThemeREX | Orpheus | CWE-98 | WordPress Orpheus theme <= 1.3 - Local File Inclusion vulnerability |
| CVE-2025-69174 | 8.1 | 27.9 | ThemeREX | Etude | CWE-98 | WordPress Etude theme <= 1.6 - Local File Inclusion vulnerability |
| CVE-2025-69175 | 8.1 | 27.9 | ThemeREX | Line Agency | CWE-98 | WordPress Line Agency theme <= 1.3.1 - Local File Inclusion vulnerability |
| CVE-2026-22335 | 8.5 | 27.7 | WC Lovers. | WooCommerce Frontend Manager – Ultimate | CWE-89 | WordPress WooCommerce Frontend Manager – Ultimate plugin < 6.7.7 - SQL Inject… |
| CVE-2026-49079 | 9.3 | 27.7 | Jetimpex Inc. | JetSearch | CWE-89 | WordPress JetSearch plugin <= 3.5.17 - SQL Injection vulnerability |
| CVE-2026-6734 | 8.8 | 27.5 | undici | undici | CWE-346 | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| CVE-2026-49133 | 7.1 | 27.3 | typemill | typemill | CWE-22 | Typemill < 2.24.0 Path Traversal via ControllerApiImage::getPagemedia() |
| CVE-2025-69135 | 8.5 | 27.2 | CurlyThemes | Events Schedule - WordPress Events Calendar Plugin | CWE-89 | WordPress Events Schedule - WordPress Events Calendar Plugin plugin <= 2.7.2 … |
| CVE-2026-52716 | 6.5 | 27.0 | purethemes | WorkScout-Core | CWE-22 | WordPress WorkScout-Core plugin <= 1.7.11 - Arbitrary File Deletion vulnerabi… |
| CVE-2026-50196 | 7.5 | 26.8 | SteeltoeOSS | Steeltoe.Discovery.Eureka | CWE-20 | Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire re… |
| CVE-2025-58952 | 8.1 | 26.7 | ThemeREX | Neuronet | CWE-98 | WordPress Neuronet theme < 1.14.0 - Local File Inclusion vulnerability |
| CVE-2026-22326 | 8.1 | 26.7 | AxiomThemes | Reprizo | CWE-98 | WordPress Reprizo theme <= 1.0.8 - Local File Inclusion vulnerability |
| CVE-2026-22338 | 8.1 | 26.7 | ThemeREX | EcoBlue | CWE-98 | WordPress EcoBlue theme <= 1.15 - Local File Inclusion vulnerability |
| CVE-2026-39523 | 8.1 | 26.7 | Elated-Themes | Solene Core | CWE-98 | WordPress Solene Core plugin <= 2.3.2 - Local File Inclusion vulnerability |
| CVE-2026-39558 | 8.1 | 26.7 | Elated-Themes | Malmö | CWE-98 | WordPress Malmö theme <= 2.2 - Local File Inclusion vulnerability |
| CVE-2026-39559 | 8.1 | 26.7 | codesupplyco | Uppercase | CWE-98 | WordPress Uppercase theme < 1.2.2 - Local File Inclusion vulnerability |
| CVE-2026-39582 | 8.1 | 26.7 | xtemos | Hitek | CWE-98 | WordPress Hitek theme < 1.8.3 - Local File Inclusion vulnerability |
| CVE-2026-39590 | 8.1 | 26.7 | ThemeMove | Atomlab | CWE-98 | WordPress Atomlab theme <= 2.4.5 - Local File Inclusion vulnerability |
| CVE-2026-32967 | 9.1 | 26.7 | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: The `/v2` experimental interface lacks permission ch… |
| CVE-2026-48967 | 8.5 | 26.1 | Dylan Kuhn | Geo Mashup | CWE-89 | WordPress Geo Mashup plugin <= 1.13.19 - SQL Injection vulnerability |
| CVE-2026-54185 | 8.5 | 26.1 | THEMECO | Cornerstone | CWE-89 | WordPress Cornerstone plugin < 7.8.8 - SQL Injection vulnerability |
| CVE-2026-12439 | 8.8 | 25.9 | Google | Chrome | CWE-416 | Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.15… |
| CVE-2026-54814 | 8.1 | 25.5 | StylemixThemes | Motors | CWE-98 | WordPress Motors plugin <= 1.4.109 - Local File Inclusion vulnerability |
| CVE-2026-54193 | 7.7 | 25.6 | ThemeFusion | Fusion Builder | CWE-22 | WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerabi… |
| CVE-2026-54816 | 7.5 | 25.5 | Monetizemore | Advanced Ads | CWE-94 | WordPress Advanced Ads plugin <= 2.0.21 - Remote Code Execution (RCE) vulnera… |
| CVE-2026-12199 | 7.5 | 25.3 | nltk | nltk/nltk | CWE-306 | Unauthenticated Denial of Service in nltk.app.wordnet_app |
| CVE-2026-25439 | 8.1 | 25.0 | fs-code | Booknetic | CWE-288 | WordPress Booknetic plugin <= 4.8.5 - Account Takeover vulnerability |
| CVE-2026-12360 | 7.5 | 25.0 | Crocoblock | JetEngine | CWE-89 | JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection via Listing Grid Load M… |
| CVE-2026-49058 | 9.8 | 24.9 | LoginPress | LoginPress Pro | CWE-266 | WordPress LoginPress Pro plugin <= 6.2.2 - Privilege Escalation vulnerability |
| CVE-2026-27041 | 9.9 | 24.7 | Studio Keren Aga LTD. | Unlimited Elements for Elementor (Premium) | CWE-434 | WordPress Unlimited Elements for Elementor (Premium) plugin <= 2.0.6 - Arbitr… |
| CVE-2026-44645 | 6.5 | 24.5 | harttle | liquidjs | CWE-400 | LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body |
| CVE-2026-42629 | 8.8 | 24.3 | Powerpackelements | PowerPack Pro for Elementor | CWE-288 | WordPress PowerPack Pro for Elementor plugin < v2.13.0 - Broken Authenticatio… |
| CVE-2026-10837 | 5.1 | 24.2 | Password Manager | Password Manager | CWE-601 | Open redirection vulnerability in Password Manager |
| CVE-2025-60231 | 9.8 | 24.1 | EMV | The Hospital | CWE-502 | WordPress The Hospital theme <= 1.8.1 - PHP Object Injection vulnerability |
| CVE-2025-60236 | 9.8 | 24.1 | EMV | Creatify | CWE-502 | WordPress Creatify theme <= 1.5 - PHP Object Injection vulnerability |
| CVE-2026-42357 | 6.5 | 23.9 | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users t… |
| CVE-2026-49072 | 6.5 | 23.5 | OPMC | WooCommerce Anti-Fraud | CWE-862 | WordPress WooCommerce Anti-Fraud plugin <= 7.2.6 - Broken Access Control vuln… |
| CVE-2026-54808 | 9.3 | 23.4 | WP Travel | WP Travel Gutenberg Blocks | CWE-89 | WordPress WP Travel Gutenberg Blocks plugin <= 3.9.4 - SQL Injection vulnerab… |
| CVE-2026-39442 | 8.1 | 23.4 | PressLayouts | PressMart | CWE-502 | WordPress PressMart theme <= 1.2.26 - PHP Object Injection vulnerability |
| CVE-2026-39556 | 8.1 | 23.4 | Elated-Themes | Konsept | CWE-502 | WordPress Konsept theme <= 1.9 - PHP Object Injection vulnerability |
| CVE-2026-39560 | 8.1 | 23.4 | Select-Themes | Hiroshi | CWE-502 | WordPress Hiroshi theme <= 1.5.1 - PHP Object Injection vulnerability |
| CVE-2026-40733 | 8.1 | 23.4 | Mikado-Themes | ShiftUp | CWE-502 | WordPress ShiftUp theme <= 1.3 - PHP Object Injection vulnerability |
| CVE-2026-40738 | 8.1 | 23.4 | Edge-Themes | Eldon | CWE-502 | WordPress Eldon theme <= 1.4.1 - PHP Object Injection vulnerability |
| CVE-2026-40752 | 8.1 | 23.4 | Select-Themes | Manufaktur Solutions | CWE-502 | WordPress Manufaktur Solutions theme <= 1.1.1 - PHP Object Injection vulnerab… |
| CVE-2026-40753 | 8.1 | 23.4 | Mikado-Themes | EasyMeals | CWE-502 | WordPress EasyMeals theme <= 1.5.1 - PHP Object Injection vulnerability |
| CVE-2026-10836 | 5.1 | 23.4 | Password Manager | Password Manager | CWE-644 | Improper neutralization of HTTP headers in Password Manager |
| CVE-2026-49071 | 6.5 | 23.1 | OPMC | WooCommerce Dropshipping | CWE-288 | WordPress WooCommerce Dropshipping plugin <= 5.2.4 - Broken Authentication vu… |
| CVE-2026-49108 | 9.8 | 23.0 | park_of_ideas | Moderno | CWE-502 | WordPress Moderno theme < 1.43 - PHP Object Injection vulnerability |
| CVE-2025-49403 | 7.5 | 23.0 | AA-Team | Premium Age Verification / Restriction for WordPress | CWE-98 | WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.… |
| CVE-2026-55201 | 7.4 | 23.0 | Hackplayers | evil-winrm | CWE-22 | Evil-WinRM - Path Traversal in download_dir() Function |
| CVE-2026-45436 | 6.5 | 23.0 | Rain-Task Ltd. | WPBakery Page Builder | CWE-862 | WordPress WPBakery Page Builder plugin <= 8.7.2 - Broken Access Control vulne… |
| CVE-2026-34888 | 7.5 | 22.8 | Bricksforge | Bricksforge | CWE-201 | WordPress Bricksforge plugin <= 3.1.8.4 - Sensitive Data Exposure vulnerability |
| CVE-2026-12530 | 8.4 | 22.7 | AWS | bedrock-agentcore | CWE-88 | Improper neutralization of argument delimiters in AWS Bedrock AgentCore Pytho… |
| CVE-2026-12441 | 8.8 | 22.7 | Google | Chrome | CWE-416 | Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.15… |
| CVE-2026-12437 | 8.3 | 22.4 | Google | Chrome | CWE-416 | Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.15… |
| CVE-2026-48814 | 9.1 | 22.3 | Jovancoding | Network-AI | CWE-306 | Network-AI: Empty default secret still authorizes all requests (Incomplete fi… |
| CVE-2026-30803 | 8.8 | 22.2 | RTI | Connext Micro | CWE-191 | Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Co… |
| CVE-2024-35690 | 6.5 | 21.9 | MarketingFire | Widget Options | CWE-201 | WordPress Widget Options plugin <= 4.0.1 - Subscriber+ User Meta Data Exposur… |
| CVE-2024-32949 | 8.3 | 21.8 | Prince | Integrate Google Drive | CWE-862 | WordPress Integrate Google Drive plugin <= 1.3.8 - Broken Access Control vuln… |
| CVE-2026-27870 | 4.8 | 21.8 | Teldat | Regesta Smart HD-PLC - TLDPH16D2 | CWE-79 | CROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC … |
| CVE-2026-32682 | 7.1 | 21.7 | F5 | NGINX Gateway Fabric | CWE-129 | NGINX Gateway Fabric vulnerability |
| CVE-2026-54445 | 6.9 | 21.7 | vantage6 | vantage6 | CWE-204 | Vantage6: Set admin user and password from environment or configuration |
| CVE-2026-49081 | 8.2 | 21.6 | ThemeGrill | User Registration Stripe | CWE-862 | WordPress User Registration Stripe plugin <= 1.3.12 - Broken Access Control v… |
| CVE-2026-50202 | 5.9 | 21.5 | SteeltoeOSS | Steeltoe.Security.Authentication.CloudFoundryBase | CWE-668 | Steeltoe's static JWKS cache shared across schemes and never invalidated |
| CVE-2026-54186 | 9.3 | 21.4 | eyecix | JobSearch | CWE-89 | WordPress JobSearch plugin <= 3.2.9 - SQL Injection vulnerability |
| CVE-2026-39546 | 7.6 | 21.3 | Techspawn | MultiLoca | CWE-266 | WordPress MultiLoca plugin <= 4.2.15 - Privilege Escalation vulnerability |
| CVE-2026-40768 | 7.3 | 21.3 | Dimitri Grassi | Salon booking system | CWE-639 | WordPress Salon booking system plugin <= 10.30.24 - Insecure Direct Object Re… |
| CVE-2026-52705 | 9.0 | 21.0 | BDthemes | SigmaForms Pro – AI Generated Forms | CWE-434 | WordPress SigmaForms Pro – AI Generated Forms plugin <= 1.4.5 - Arbitrary Fil… |
| CVE-2026-54533 | 6.9 | 21.0 | vantage6 | vantage6 | CWE-284 | vantage6 node has an Improper Access Control issue |
| CVE-2026-12529 | 6.9 | 20.9 | SourceCodester | CET Automated Grading System with AI Predictive Analytics | CWE-266 | SourceCodester CET Automated Grading System with AI Predictive Analytics Stud… |
| CVE-2026-22332 | 9.3 | 20.8 | Themeum | Tutor LMS Pro | CWE-89 | WordPress Tutor LMS Pro plugin <= 3.9.6 - SQL Injection vulnerability |
| CVE-2026-49084 | 9.3 | 20.8 | Jetimpex Inc. | JetEngine | CWE-89 | WordPress JetEngine plugin < 3.8.9.1 - SQL Injection vulnerability |
| CVE-2026-54187 | 9.3 | 20.8 | Jetimpex Inc. | JetEngine | CWE-89 | WordPress JetEngine plugin <= 3.8.10.1 - SQL Injection vulnerability |
| CVE-2026-54811 | 9.3 | 20.8 | Tips and Tricks HQ | WP eMember | CWE-89 | WordPress WP eMember plugin < v10.9.4 - SQL Injection vulnerability |
| CVE-2026-54812 | 9.3 | 20.8 | StylemixThemes | Motors | CWE-89 | WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerability |
| CVE-2026-10641 | 7.1 | 20.7 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_… |
| CVE-2026-54818 | 8.5 | 20.3 | VeronaLabs | Slimstat Analytics | CWE-89 | WordPress Slimstat Analytics plugin <= 5.4.11 - SQL Injection vulnerability |
| CVE-2024-27928 | 5.9 | 20.3 | vantage6 | vantage6 | CWE-308 | Vantage6: 2FA can be circumvented with hacked email access |
| CVE-2024-24769 | 2.1 | 20.2 | vantage6 | vantage6 | CWE-400 | Vantage6: No limit on emails sent for password/MFA reset |
| CVE-2026-54804 | 7.6 | 19.8 | melhorenvio | Melhor Envio | CWE-288 | WordPress Melhor Envio plugin <= 2.16.3 - Broken Authentication vulnerability |
| CVE-2026-27410 | 6.5 | 19.8 | VeronaLabs | Slimstat Analytics | CWE-502 | WordPress Slimstat Analytics plugin < 5.4.0 - Deserialization of untrusted da… |
| CVE-2026-11857 | 8.4 | 19.7 | Quanos Solutions GmbH | SCHEMA ST4 | CWE-502 | Insecure .NET Remoting deserialization in Quanos SCHEMA ST4 Client Update Ser… |
| CVE-2026-55197 | 7.1 | 19.6 | nesquena | hermes-webui | CWE-639 | Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint |
| CVE-2026-55198 | 7.1 | 19.6 | nesquena | hermes-webui | CWE-639 | Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session… |
| CVE-2026-48764 | 8.2 | 19.5 | baptisteArno | typebot.io | CWE-918 | TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass |
| CVE-2026-12462 | 7.5 | 19.3 | Google | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a re… |
| CVE-2026-44646 | 5.3 | 19.3 | harttle | liquidjs | CWE-693 | LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:tr… |
| CVE-2026-10741 | 5.9 | 19.2 | Sonatype | Nexus Repository Manager | CWE-863 | Nexus Repository Manager - Incorrect Authorization allows credential disclosu… |
| CVE-2026-10696 | 7.5 | 19.1 | Devolutions | UniGetUI | CWE-706 | Use of an incorrectly resolved name or reference in the pinget backend in Dev… |
| CVE-2024-37210 | 6.5 | 19.1 | ali2woo | AliNext | CWE-862 | WordPress AliExpress Dropshipping with AliNext Lite plugin <= 3.3.5 - Broken … |
| CVE-2026-48768 | 9.3 | 19.0 | baptisteArno | typebot.io | CWE-22 | TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via… |
| CVE-2026-48979 | 7.5 | 18.9 | php-standard-library | php-standard-library | CWE-444 | PHP Standard Library: HTTP/2 server-side missing content-length validation en… |
| CVE-2026-22343 | 8.6 | 18.0 | PremiumPress Limited. | WordPress Dating Theme | CWE-862 | WordPress WordPress Dating Theme theme <= 11.2.0 - Broken Access Control vuln… |
| CVE-2026-8607 | 6.4 | 18.0 | saadiqbal | Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred | CWE-79 | myCred – Points Management System For Gamification, Ranks, Badges, and Loyalt… |
| CVE-2026-24575 | 4.3 | 17.7 | WishList Member | WishList Member X | CWE-862 | WordPress WishList Member X plugin <= 3.29.0 - Broken Access Control vulnerab… |
| CVE-2026-48820 | 6.3 | 17.6 | cakephp | cakephp | CWE-22 | CakePHP: View::element() is missing a path containment check |
| CVE-2026-9679 | 5.9 | 17.5 | undici | undici | CWE-93 | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| CVE-2026-12452 | 8.8 | 17.4 | Google | Chrome | CWE-416 | Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.1… |
| CVE-2026-8494 | 6.4 | 17.4 | mbis | Permalink Manager Lite | CWE-79 | Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross… |
| CVE-2026-11975 | 6.2 | 17.4 | simplcommerce | SimplCommerce | CWE-79 | Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface |
| CVE-2026-12448 | 8.8 | 17.3 | Google | Chrome | CWE-269 | Inappropriate implementation in WebView in Google Chrome on Android prior to … |
| CVE-2026-30799 | 6.1 | 17.3 | RTI | Connext Professional | CWE-306 | Missing Authentication for Critical Function vulnerability in RTI Connext Pro… |
| CVE-2026-54184 | 8.2 | 17.1 | Alberto Hornero | Clean Login | CWE-639 | WordPress Clean Login plugin <= 1.15 - Insecure Direct Object References (IDO… |
| CVE-2026-54817 | 6.5 | 17.0 | FluxBuilder | MStore API | CWE-288 | WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability |
| CVE-2026-20220 | 6.3 | 17.0 | Cisco | Cisco Crosswork Network Change Automation | CWE-74 | Cisco Crosswork Network Controller Remote Code Execution Vulnerability |
| CVE-2026-12440 | 9.6 | 16.8 | Google | Chrome | CWE-416 | Use after free in DigitalCredentials in Google Chrome on Windows prior to 149… |
| CVE-2026-7300 | 8.8 | 16.8 | RTI | Connext Professional | CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulner… |
| CVE-2026-12568 | 6.5 | 16.7 | Black Lantern Security | BBOT | CWE-22 | Arbitrary File Write in postman_download module |
| CVE-2026-40756 | 8.1 | 16.6 | Mikado-Themes | Zoya | CWE-502 | WordPress Zoya theme <= 1.4 - PHP Object Injection vulnerability |
| CVE-2026-40757 | 8.1 | 16.6 | Mikado-Themes | Château | CWE-502 | WordPress Château theme <= 1.2.1 - PHP Object Injection vulnerability |
| CVE-2026-30802 | 8.8 | 16.4 | RTI | Connext Micro | CWE-125 | Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows… |
| CVE-2024-33909 | 5.3 | 16.5 | Avirtum | iPages Flipbook | CWE-862 | WordPress iPages Flipbook plugin <= 1.5.1 - Broken Access Control vulnerability |
| CVE-2026-40726 | 8.2 | 15.9 | ThemeGrill | User Registration Stripe | CWE-862 | WordPress User Registration Stripe plugin <= 1.3.14 - Broken Access Control v… |
| CVE-2026-22328 | 7.1 | 15.8 | VamTam | Auto Repair | CWE-79 | WordPress Auto Repair theme <= 22.6 - Reflected Cross Site Scripting (XSS) vu… |
| CVE-2026-24610 | 4.3 | 15.8 | WPMet | MetForm Pro | CWE-862 | WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability |
| CVE-2026-40723 | 4.3 | 15.8 | Bricks | Bricks Builder | CWE-862 | WordPress Bricks Builder theme <= 2.1.4 - Broken Access Control vulnerability |
| CVE-2026-12465 | 8.3 | 15.6 | Google | Chrome | CWE-20 | Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 al… |
| CVE-2026-12461 | 6.5 | 15.6 | Google | Chrome | CWE-125 | Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.… |
| CVE-2024-49269 | 7.1 | 15.4 | Mythemes | my flatonica | CWE-79 | WordPress my flatonica theme <= 0.0.8 - Reflected Cross Site Scripting (XSS) … |
| CVE-2026-54386 | 5.1 | 15.2 | marimo-team | marimo | CWE-79 | marimo < 0.23.9 XSS via file Query Parameter in assets.py |
| CVE-2026-12491 | 4.8 | 15.2 | vllm-project | vLLM | CWE-115 | Vllm: vllm: image exif rotation & png trns transparency not normalized, causi… |
| CVE-2026-50194 | 8.2 | 15.0 | SteeltoeOSS | Steeltoe.Management.Endpoint | CWE-288 | Steeltoe vulnerable to management-port isolation bypass via spoofed Host header |
| CVE-2026-52696 | 7.5 | 15.0 | Jetimpex Inc. | JetBlog | CWE-1258 | WordPress JetBlog plugin <= 2.4.8 - Sensitive Data Exposure vulnerability |
| CVE-2026-11525 | 3.7 | 15.1 | undici | undici | CWE-183 | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive s… |
| CVE-2026-54810 | 7.5 | 14.8 | Nexi Payments | Nexi XPay | CWE-862 | WordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerability |
| CVE-2026-54196 | 6.8 | 14.8 | Jetmonsters | JetFormBuilder | CWE-266 | WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability |
| CVE-2026-54809 | 9.3 | 14.6 | VillaTheme | GIFT4U | CWE-89 | WordPress GIFT4U plugin <= 1.0.10 - SQL Injection vulnerability |
| CVE-2026-50201 | 6.5 | 14.1 | SteeltoeOSS | Steeltoe.Management.Endpoint | CWE-269 | Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission |
| CVE-2025-59560 | 7.1 | 14.0 | SONAAR MUSIC | Sonaar | CWE-79 | WordPress Sonaar theme <= 4.27.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2025-68524 | 7.1 | 14.1 | ThemeGoods | Avante | CWE-79 | WordPress Avante theme < 3.0.5 - Reflected Cross Site Scripting (XSS) vulnera… |
| CVE-2026-22339 | 7.1 | 14.0 | Jobster Marketplace | WPJobster | CWE-79 | WordPress WPJobster theme <= 6.3.5 - Reflected Cross Site Scripting (XSS) vul… |
| CVE-2026-40765 | 7.1 | 14.0 | collectchat | collectchat | CWE-79 | WordPress collectchat plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-41557 | 7.1 | 14.0 | PressLayouts | Kapee | CWE-79 | WordPress Kapee theme < 1.7.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-42385 | 7.1 | 14.0 | Cozmoslabs | Profile Builder Pro | CWE-79 | WordPress Profile Builder Pro plugin <= 3.15.0 - Cross Site Scripting (XSS) v… |
| CVE-2026-54815 | 9.3 | 14.0 | Cargo RD | Cargo Shipping Location for WooCommerce | CWE-89 | WordPress Cargo Shipping Location for WooCommerce plugin <= 5.6 - SQL Injecti… |
| CVE-2026-54819 | 9.3 | 14.0 | Webilia Inc. | Listdom | CWE-89 | WordPress Listdom plugin <= 5.4.0 - SQL Injection vulnerability |
| CVE-2026-35069 | 8.0 | 13.9 | Dell | PowerFlex | CWE-89 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper N… |
| CVE-2026-32804 | 8.1 | 13.9 | Dell | PowerFlex | CWE-287 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2025-15657 | 5.3 | 13.7 | Mojoomla | School Management | CWE-639 | WordPress School Management plugin <= 93.1.0 - Insecure Direct Object Referen… |
| CVE-2026-12455 | 7.5 | 13.7 | Google | Chrome | CWE-416 | Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed … |
| CVE-2026-12528 | 5.4 | 13.5 | Red Hat | Red Hat Directory Server 11 | CWE-787 | 389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt() |
| CVE-2026-12515 | 4.3 | 13.1 | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | CWE-862 | Katello: missing repository authorization in content_uploads exposes cross-pr… |
| CVE-2026-12464 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a … |
| CVE-2026-12467 | 8.3 | 13.1 | Google | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed… |
| CVE-2026-54192 | 7.1 | 12.8 | Ays Pro | Popup box | CWE-79 | WordPress Popup box plugin <= 6.2.9 - Reflected Cross Site Scripting (XSS) vu… |
| CVE-2026-6733 | 3.7 | 12.7 | undici | undici | CWE-367 | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| CVE-2026-0092 | 10.0 | 12.5 | Google | Android | CWE-862 | In Package Manager, there is a possible device lock controller bypass due to … |
| CVE-2026-55748 | 6.0 | 12.5 | OpenStack | Horizon | CWE-78 | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downlo… |
| CVE-2026-20265 | 4.3 | 12.4 | Splunk | Splunk AI Toolkit | CWE-1188 | Insecure Default Domain Allowlist in Splunk AI Toolkit |
| CVE-2026-8089 | 7.1 | 12.2 | Unknown | weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce | CWE-79 | weMail < 2.1.3 - Reflected Cross-Site Scripting |
| CVE-2026-52698 | 7.4 | 12.0 | Syed Balkhi | PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget | CWE-201 | WordPress PushEngage – Web Push Notifications, eCommerce Automation & Chat Wi… |
| CVE-2026-22283 | 7.5 | 11.9 | Dell | PowerFlex | CWE-829 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion … |
| CVE-2026-48817 | 5.3 | 11.9 | Kludex | starlette | CWE-470 | Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via … |
| CVE-2026-2675 | 6.0 | 11.7 | RTI | Connext Professional | CWE-306 | Missing Authentication for Critical Function vulnerability in RTI Connext Pro… |
| CVE-2026-49502 | 8.1 | 11.4 | Dell | PowerFlex | CWE-287 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2026-35162 | 6.5 | 11.5 | Dell | PowerFlex | CWE-284 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2026-39595 | 4.7 | 11.4 | BoldGrid | W3 Total Cache | CWE-862 | WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability |
| CVE-2026-12565 | 5.3 | 11.3 | Black Lantern Security | BBOT | CWE-22 | Path Traversal (Zip-Slip) in unarchive module |
| CVE-2024-31435 | 4.3 | 11.2 | Inisev | Social Media & Share Icons | CWE-862 | WordPress Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.6 -… |
| CVE-2024-37496 | 4.3 | 11.2 | Rara Themes | Metro Magazine | CWE-862 | WordPress Metro Magazine theme <= 1.3.7 - Broken Access Control on Notice Dis… |
| CVE-2026-12438 | 8.3 | 11.1 | Google | Chrome | CWE-693 | Inappropriate implementation in WebView in Google Chrome on Android prior to … |
| CVE-2026-54813 | 8.5 | 10.8 | Brainstorm Force | SureDash | CWE-89 | WordPress SureDash plugin <= 1.8.0 - SQL Injection vulnerability |
| CVE-2025-62340 | 5.3 | 10.6 | HCL Software | iControl | CWE-613 | HCL iControl was affected by Inadequate Session Timeout vulnerability |
| CVE-2026-44644 | 6.1 | 10.6 | harttle | liquidjs | CWE-79 | LiquidJS's strip_html filter bypass via newline characters in HTML tags enabl… |
| CVE-2026-48759 | 7.1 | 10.5 | baptisteArno | typebot.io | CWE-639 | TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion) |
| CVE-2026-20178 | 4.3 | 10.5 | Cisco | Cisco Webex App | CWE-601 | A vulnerability in the browser-based version of Cisco Webex App could have al… |
| CVE-2026-3894 | 9.2 | 10.1 | RTI | Connext Professional | CWE-125 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries)… |
| CVE-2026-54195 | 7.1 | 9.9 | Jetmonsters | JetFormBuilder | CWE-79 | WordPress JetFormBuilder plugin <= 3.6.0.1 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-9591 | 6.9 | 9.8 | simplcommerce | SimplCommerce | CWE-352 | Cross-Site Request Forgery (CSRF) in SimplCommerce News Module |
| CVE-2026-12446 | 4.3 | 9.5 | Google | Chrome | CWE-863 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… |
| CVE-2026-35068 | 5.7 | 9.2 | Dell | PowerFlex | CWE-89 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper N… |
| CVE-2024-24709 | 4.3 | 9.2 | Shareaholic | Shareaholic | CWE-862 | WordPress Shareaholic plugin <= 9.7.11 - Broken Access Control vulnerability |
| CVE-2025-48571 | 4.3 | 9.0 | Google | Android | CWE-693 | In multiple functions of btm_sec.cc, there is a possible way for an attacker … |
| CVE-2026-12458 | 3.1 | 9.0 | Google | Chrome | CWE-451 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… |
| CVE-2026-2467 | 9.2 | 8.8 | RTI | Connext Professional | CWE-122 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Li… |
| CVE-2026-40722 | 5.5 | 8.7 | Yoast BV | Yoast SEO Premium | CWE-862 | WordPress Yoast SEO Premium plugin <= 26.6 - Broken Access Control vulnerability |
| CVE-2026-22329 | 7.1 | 8.5 | Themeum | Skillate | CWE-79 | WordPress Skillate theme <= 1.2.10 - Reflected Cross Site Scripting (XSS) vul… |
| CVE-2026-49778 | 7.1 | 8.5 | WPFunnels | WPFunnels Pro | CWE-79 | WordPress WPFunnels Pro plugin <= 2.9.4 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-12469 | 4.3 | 8.5 | Google | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 … |
| CVE-2026-50200 | 7.5 | 8.4 | SteeltoeOSS | Steeltoe.Management.Endpoint | CWE-200 | Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords |
| CVE-2026-22342 | 8.8 | 8.3 | PremiumPress Limited. | WordPress Dating Theme | CWE-352 | WordPress WordPress Dating Theme theme <= 11.2.0 - Cross Site Request Forgery… |
| CVE-2026-48117 | 6.8 | 8.3 | fduflyer | DroneAware-Node-Releases | CWE-287 | DroneAware's Improper Account Activation in Registration and SSO Flows Leads … |
| CVE-2026-12450 | 6.5 | 8.2 | Google | Chrome | CWE-269 | Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.15… |
| CVE-2026-35066 | 7.1 | 8.2 | Dell | PowerFlex | CWE-284 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2026-12459 | 6.1 | 7.9 | Google | Chrome | CWE-79 | Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.1… |
| CVE-2025-69140 | 7.1 | 7.8 | SeventhQueen | SweetDate Core | CWE-79 | WordPress SweetDate Core plugin < 1.1.5 - Reflected Cross Site Scripting (XSS… |
| CVE-2026-2674 | 4.8 | 7.9 | RTI | Connext Professional | CWE-787 | Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Servi… |
| CVE-2026-12453 | 4.2 | 7.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Input in Google Chrome prior to… |
| CVE-2025-69189 | 7.3 | 7.6 | EMV | JobBank | CWE-862 | WordPress JobBank plugin <= 1.2.3 - Broken Access Control vulnerability |
| CVE-2026-12451 | 8.3 | 7.5 | Google | Chrome | CWE-416 | Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155… |
| CVE-2026-39597 | 7.1 | 7.3 | WPZOOM | WPZOOM Addons for Elementor | CWE-79 | WordPress WPZOOM Addons for Elementor plugin <= 1.3.4 - Reflected Cross Site … |
| CVE-2026-40720 | 7.1 | 7.2 | Royal Elementor Addons | Royal Elementor Addons Pro | CWE-79 | WordPress Royal Elementor Addons Pro plugin < 1.7.1041 - Cross Site Scripting… |
| CVE-2026-49074 | 7.1 | 7.2 | Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.9.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-12566 | 3.1 | 6.4 | Black Lantern Security | BBOT | CWE-918 | SSRF via unvalidated WWW-Authenticate realm in docker_pull module |
| CVE-2026-0082 | 10.0 | 6.2 | Google | Android | CWE-453 | In tryStartActivity of NfcDispatcher.java, there is a possible automatic spec… |
| CVE-2026-10850 | 6.9 | 6.2 | Plane | Plane | CWE-79 | Plane 1.3.1 - Stored XSS in intake issue description_html |
| CVE-2025-15641 | 6.8 | 5.9 | Netskope | Netskope Client | CWE-782 | Netskope Client Exposed IOCTL with Insufficient Access Controls |
| CVE-2026-48990 | 5.3 | 5.9 | authlib | joserfc | CWE-400 | joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limit… |
| CVE-2026-12445 | 7.5 | 5.5 | Google | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed… |
| CVE-2026-0063 | 10.0 | 5.2 | Google | Android | CWE-269 | In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way … |
| CVE-2026-0071 | 10.0 | 5.2 | Google | Android | CWE-862 | In SettingsLib, there is a possible missing permission check due to a logic e… |
| CVE-2024-33685 | 4.3 | 5.1 | Jegstudio | Startupzy | CWE-862 | WordPress Startupzy theme <= 1.1.1 - Broken Access Control vulnerability |
| CVE-2026-12460 | 4.2 | 5.0 | Google | Chrome | CWE-284 | Insufficient policy enforcement in File System Access in Google Chrome prior … |
| CVE-2026-5667 | 7.2 | 4.8 | Mitsubishi Electric Corporation | Room Air Conditioners (for Japan) MSZ-BKR2223-W | CWE-798 | Information Disclosure, Information Tampering, or Denial-of-Service (DoS) Vul… |
| CVE-2026-35067 | 8.0 | 4.7 | Dell | PowerFlex | CWE-284 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2026-0081 | 10.0 | 4.5 | Google | Android | CWE-862 | In NFC, there is a possible way to spoof an NFC event due to a missing permis… |
| CVE-2026-28576 | 10.0 | 4.5 | Android | Android | CWE-89 | In Contacts Provider, there is a possible way to access the contacts database… |
| CVE-2026-12454 | 8.3 | 4.3 | Google | Chrome | CWE-362 | Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed… |
| CVE-2025-31013 | 7.1 | 4.4 | Themify | Themify Folo | CWE-79 | WordPress Themify Folo theme <= 1.9.6 - Reflected Cross Site Scripting (XSS) … |
| CVE-2026-9570 | 7.1 | 4.4 | Unknown | Taskbuilder | CWE-79 | Taskbuilder < 5.0.8 - Reflected XSS via Shortcode |
| CVE-2025-32748 | 6.1 | 4.3 | Dell | PowerFlex rack | CWE-601 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header… |
| CVE-2026-12468 | 8.3 | 4.1 | Google | Chrome | CWE-362 | Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a rem… |
| CVE-2025-15642 | 6.8 | 4.2 | Netskope | Netskope Client | CWE-276 | Netskope Client Service Insufficient Access Controls |
| CVE-2026-12444 | 5.5 | 4.1 | Google | Chrome | CWE-125 | Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7… |
| CVE-2026-54188 | 7.1 | 4.0 | Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.10 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-54189 | 7.1 | 4.0 | Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.10 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-7850 | 5.9 | 3.8 | Unknown | WP Magnific Popup | — | WP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute |
| CVE-2026-12456 | 4.2 | 3.6 | Google | Chrome | CWE-20 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… |
| CVE-2026-12457 | 4.2 | 3.5 | Google | Chrome | CWE-693 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… |
| CVE-2026-48591 | 4.8 | 3.3 | pragdave | earmark | CWE-83 | Stored XSS via unescaped HTML attribute values in earmark |
| CVE-2026-12463 | 4.7 | 3.3 | Google | Chrome | CWE-79 | Inappropriate implementation in Views in Google Chrome on Linux prior to 149.… |
| CVE-2026-48821 | 5.8 | 3.0 | shaarli | Shaarli | CWE-79 | Shaarli: DOM-based Cross-Site Scripting (XSS) in Thumbnail Synchronizer |
| CVE-2026-48991 | 5.5 | 2.8 | XianYuLauncher | XianYuLauncher | CWE-287 | XianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and st… |
| CVE-2024-35648 | 4.3 | 2.8 | Andy Moyle | Emergency Password Reset | CWE-352 | WordPress Emergency Password Reset plugin <= 8.0 - Cross Site Request Forgery… |
| CVE-2026-11858 | 8.4 | 2.7 | Quanos Solutions GmbH | SCHEMA ST4 | CWE-862 | Missing authorization in Quanos SCHEMA ST4 Client Update Service allows arbit… |
| CVE-2026-28575 | 10.0 | 2.6 | Google | Android | CWE-400 | In PackageInstaller.Session#transfer of frameworks/base/services/core/java/co… |
| CVE-2026-39199 | 2.9 | 2.6 | Snes9X team | Snes9X | CWE-787 | snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted… |
| CVE-2024-47477 | 6.5 | 2.5 | Dell | PowerFlex Manager | CWE-295 | Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certif… |
| CVE-2026-0068 | 10.0 | 2.5 | Google | Android | CWE-362 | In createSessionInternal of PackageInstallerService.java, there is a possible… |
| CVE-2026-28615 | 10.0 | 2.5 | Google | Android | CWE-862 | In Telecomm, there is a possible way to initiate an unauthorized phone call d… |
| CVE-2026-0064 | 10.0 | 2.4 | Google | Android | CWE-400 | In multiple places, there is a possible persistent denial of service due to r… |
| CVE-2026-0083 | 10.0 | 2.2 | Google | Android | CWE-362 | In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a… |
| CVE-2026-48822 | 5.8 | 2.2 | shaarli | Shaarli | CWE-79 | Shaarli has Stored Cross-Site Scripting (XSS) via Markdown Reference Links |
| CVE-2024-34810 | 4.3 | 1.9 | Extend Themes | Skyline WP | CWE-352 | WordPress Skyline WP theme <= 1.0.10 - Cross Site Request Forgery (CSRF) vuln… |
| CVE-2026-1288 | 5.5 | 1.8 | Autodesk | Revit | CWE-476 | RFA File Parsing Vulnerability in Autodesk Revit |
| CVE-2026-28587 | 10.0 | 1.8 | Google | Android | CWE-862 | In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve… |
| CVE-2026-48823 | 4.8 | 1.8 | shaarli | Shaarli | CWE-79 | Shaarli has Stored Cross-Site Scripting (XSS) via Tags Search |
| CVE-2026-8049 | 5.3 | 1.6 | SignalRGB | SignalRGB kernel driver | — | CVE-2026-8049 |
| CVE-2026-12449 | 7.8 | 1.4 | Google | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.… |
| CVE-2026-53870 | 6.8 | 1.4 | NousResearch | hermes-agent | CWE-276 | Hermes Agent < 0.16.0 - Sensitive File Permission Vulnerability in Store Files |
| CVE-2026-20246 | 6.0 | 1.2 | Cisco | Cisco Umbrella Insights Virtual Appliance | CWE-269 | Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability |
| CVE-2026-40641 | 4.8 | 1.0 | Dell | PowerFlex | CWE-327 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a B… |
| CVE-2026-32652 | 7.8 | 0.9 | Dell | AIOps | CWE-1392 | Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Crede… |
| CVE-2025-48640 | 8.0 | 0.7 | Google | Android | CWE-862 | In multiple locations, there is a possible 3rd party passkey entry pairing ap… |
| CVE-2026-12567 | 2.2 | 0.6 | Black Lantern Security | BBOT | CWE-59 | Symlink-following arbitrary write via github_workflows module |
| CVE-2025-48643 | 7.8 | 0.3 | Google | Android | CWE-20 | In multiple locations there is a possible provisioning bypass due to improper… |
| CVE-2026-0019 | 7.8 | 0.2 | Google | Android | CWE-269 | In SettingsLib, there is a possible way to disable system components due to a… |
| CVE-2025-48617 | 7.8 | 0.1 | Google | Android | CWE-862 | In overrideConfig of CarrierConfigLoader.java, there is a possible way to byp… |
| CVE-2026-50267 | 4.7 | 0.0 | SteeltoeOSS | Steeltoe.Configuration.Abstractions | CWE-312 | Steeltoe: TLS private keys written to /tmp with default permissions, never de… |
| CVE-2026-0057 | 3.3 | 0.0 | Google | Android | CWE-862 | In Contacts Provider, there is a possible way to access an incoming call's ph… |
| CVE-2026-50268 | 1.9 | 0.0 | SteeltoeOSS | Steeltoe.Configuration.Encryption | CWE-256 | Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding |