| CVE-2026-52830 | 9.4 | 43.2 | leshchenko1979 | fast-mcp-telegram | CWE-22 | fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram ses… |
| CVE-2026-41106 | 9.3 | 42.4 | Microsoft | Microsoft 365 Copilot | CWE-601 | Microsoft 365 Copilot Elevation of Privilege Vulnerability |
| CVE-2026-55115 | 9.9 | 41.9 | Ubiquiti Inc | UniFi Protect Application | CWE-918 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-44941 | 8.8 | 41.8 | SUSE | libzypp | CWE-23 | libzypp path traversal via "keyhint" in repomd.xml |
| CVE-2026-54400 | 9.1 | 41.7 | Ubiquiti Inc | UniFi Access Application | CWE-284 | A malicious actor with access to the network and high privileges could exploi… |
| CVE-2026-38971 | 9.1 | 41.1 | n/a | n/a | CWE-125 | ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issu… |
| CVE-2026-58466 | 9.3 | 40.9 | EstrellaXD | Auto_Bangumi | CWE-1392 | AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user() |
| CVE-2026-13084 | 8.7 | 40.5 | WatchGuard | Fireware OS | CWE-476 | Null Pointer Dereference in WatchGuard Fireware OS iked Process |
| CVE-2026-50747 | 9.9 | 39.9 | Ubiquiti Inc | UniFi Talk Application | CWE-89 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-58652 | 7.7 | 39.4 | openwrt | luci-app-travelmate | CWE-78 | luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameter |
| CVE-2026-55952 | 8.2 | 39.4 | Erlang | OTP | CWE-1284 | TLS 1.3 server denial of service via malformed ClientHello pre-shared key ext… |
| CVE-2026-59094 | 8.7 | 38.7 | pathwaycom | pathway | CWE-407 | Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matc… |
| CVE-2026-52187 | 7.5 | 37.5 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52189 | 7.5 | 37.5 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52191 | 7.5 | 37.5 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-38970 | 7.5 | 37.4 | n/a | n/a | CWE-674 | pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service i… |
| CVE-2026-55116 | 9.8 | 34.5 | Ubiquiti Inc | Dream Machines | CWE-284 | A malicious actor with access to the network and under certain network config… |
| CVE-2026-44935 | 9.9 | 34.4 | SUSE | Rancher | CWE-1287 | Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated… |
| CVE-2026-52192 | 7.5 | 34.1 | n/a | n/a | CWE-400 | An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker … |
| CVE-2026-13369 | 7.5 | 34.0 | SaturdayDrive | Ninja Forms - File Uploads | CWE-22 | Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read vi… |
| CVE-2026-58467 | 8.2 | 33.9 | cockpit-hq | cockpit | CWE-22 | Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php |
| CVE-2026-55726 | 6.9 | 32.5 | Gardyn | Gardyn Home Firmware | CWE-497 | Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Co… |
| CVE-2026-59093 | 8.7 | 32.0 | weaviate | weaviate | CWE-266 | Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Ro… |
| CVE-2025-69133 | 7.5 | 32.0 | GoodLayers | Tourmaster | CWE-98 | WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability |
| CVE-2026-50721 | 5.9 | 31.8 | The Libreswan Project | libreswan | CWE-347 | IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentic… |
| CVE-2026-27436 | 9.1 | 31.7 | Rustaurius | Five Star Business Profile and Schema | CWE-94 | WordPress Five Star Business Profile and Schema plugin <= 2.3.19 - Arbitrary … |
| CVE-2026-55117 | 8.6 | 31.3 | Ubiquiti Inc | UniFi Access Application | CWE-22 | A malicious actor with access to the network could exploit a Path Traversal v… |
| CVE-2026-33592 | 7.5 | 31.4 | open62541 project / o6 Automation GmbH | open62541 | CWE-770 | FindServers Memory Exhaustion in open62541 |
| CVE-2026-11946 | 7.5 | 31.2 | open62541 project / o6 Automation GmbH | open62541 | CWE-770 | GetEndpoints Memory Exhaustion in open62541 |
| CVE-2026-12657 | 5.3 | 31.3 | latepoint | LatePoint – Calendar Booking Plugin for Appointments and Events | CWE-639 | LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbi… |
| CVE-2026-38968 | 9.8 | 31.1 | n/a | n/a | CWE-341 | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can … |
| CVE-2026-55950 | 8.7 | 31.1 | Erlang | OTP | CWE-367 | DTLS listener crash via race condition in dtls_packet_demux causes denial of … |
| CVE-2026-54406 | 8.7 | 30.8 | Ubiquiti Inc | UniFi Network Application | CWE-22 | A malicious actor with access to the network and high privileges could exploi… |
| CVE-2026-59092 | 7.0 | 30.8 | juicedata | juicefs | CWE-489 | JuiceFS - Authentication Bypass via pprof and metrics Endpoints |
| CVE-2026-8147 | 8.1 | 30.7 | mlflow | mlflow/mlflow | CWE-284 | Authorization Bypass in mlflow/mlflow |
| CVE-2026-56004 | 10.0 | 30.6 | openSUSE | buildservice | CWE-78 | obs-service-tar_scm: command injection via mercurial handler |
| CVE-2026-57347 | 6.5 | 30.2 | jetmonsters | Hotel Booking Lite | CWE-201 | WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulner… |
| CVE-2026-26145 | 9.8 | 29.0 | Microsoft | Azure Synapse | CWE-284 | Microsoft Azure Synapse Elevation of Privilege Vulnerability |
| CVE-2026-59099 | 9.3 | 28.7 | apereo | cas | CWE-323 | Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure |
| CVE-2026-27419 | 9.9 | 28.2 | Zozothemes | Zegen | CWE-434 | WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability |
| CVE-2026-13371 | 6.9 | 28.1 | WatchGuard | Fireware OS | CWE-502 | WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserializa… |
| CVE-2026-9563 | 7.5 | 27.6 | Eclipse Foundation | Eclipse Parsson | CWE-400 | In Eclipse Parsson published Maven Central artifacts before version 1.1.8, th… |
| CVE-2026-50722 | 5.9 | 27.7 | The Libreswan Project | libreswan | CWE-347 | IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authenticatio… |
| CVE-2026-12472 | 5.3 | 27.6 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-862 | Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Co… |
| CVE-2025-69132 | 6.5 | 27.5 | Zozothemes | Corpkit | CWE-201 | WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability |
| CVE-2026-5821 | 8.1 | 27.4 | elemntor | Image Optimizer – Optimize Images and Convert to WebP or AVIF | CWE-73 | Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion vi… |
| CVE-2026-59097 | 6.9 | 27.4 | taiga | taiga-back | CWE-862 | Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets |
| CVE-2026-49779 | 6.5 | 27.3 | Addify | Tax Exempt for WooCommerce | CWE-35 | WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerab… |
| CVE-2026-57669 | 6.5 | 27.0 | Vsourz Digital | Advanced Contact form 7 DB | CWE-862 | WordPress Advanced Contact form 7 DB plugin <= 2.0.9 - Broken Access Control … |
| CVE-2026-54405 | 7.5 | 26.9 | Ubiquiti Inc | UniFi Network Application | CWE-20 | A malicious actor with access to the network could exploit an Improper Input … |
| CVE-2026-55111 | 7.5 | 26.4 | Ubiquiti Inc | UniFi Protect Floodlight | CWE-22 | A malicious actor with access to the network could exploit a Path Traversal v… |
| CVE-2026-4767 | 9.8 | 26.2 | TR7 Cyber Defense Inc. | WAF-ASP | CWE-306 | Improper Access Control in TR7's WAF-ASP |
| CVE-2026-14249 | 7.5 | 26.2 | emarket-design | Request a Quote – Quote Forms for Any WordPress Site | CWE-74 | Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'pa… |
| CVE-2026-13459 | 5.3 | 26.2 | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | CWE-862 | JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive … |
| CVE-2026-54886 | 5.3 | 26.0 | Erlang | OTP | CWE-400 | SSH SFTP server denial of service via extended channel data infinite loop |
| CVE-2026-57621 | 9.8 | 25.5 | Arraytics | Booktics | CWE-502 | WordPress Booktics plugin <= 1.0.21 - PHP Object Injection vulnerability |
| CVE-2026-57677 | 9.8 | 25.5 | Novalnet | Novalnet Payment Gateway for WooCommerce | CWE-502 | WordPress Novalnet Payment Gateway for WooCommerce plugin <= 12.10.3 - PHP Ob… |
| CVE-2026-57623 | 9.0 | 25.1 | BoldGrid | W3 Total Cache | CWE-1284 | WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerabi… |
| CVE-2026-59101 | 6.9 | 24.9 | EstrellaXD | Auto_Bangumi | CWE-918 | AutoBangumi < 3.2.8 - SSRF via /api/v1/setup/test-downloader |
| CVE-2026-14029 | 6.5 | 24.6 | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | CWE-89 | Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Para… |
| CVE-2026-11896 | 5.3 | 24.0 | joedolson | My Calendar – Accessible Event Manager | CWE-639 | My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated S… |
| CVE-2026-54407 | 8.6 | 23.7 | Ubiquiti Inc | UniFi Protect Application | CWE-284 | A malicious actor with access to the network could exploit an Improper Access… |
| CVE-2026-9145 | 6.5 | 23.4 | crmperks | Database for Contact Form 7, WPforms, Elementor forms | CWE-22 | Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthentica… |
| CVE-2026-58578 | 7.1 | 23.1 | lobehub | lobehub | CWE-1333 | LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub … |
| CVE-2026-54408 | 9.8 | 23.0 | Ubiquiti Inc | UniFi Protect Application | CWE-284 | A malicious actor with access to the network could exploit an Improper Access… |
| CVE-2026-56037 | 8.8 | 22.5 | Themify | Themify Popup | CWE-502 | WordPress Themify Popup plugin <= 1.4.3 - PHP Object Injection vulnerability |
| CVE-2026-57353 | 6.5 | 22.5 | LinkWhisper | Link Whisper Premium | CWE-862 | WordPress Link Whisper Premium plugin <= 2.9.0 - Broken Access Control vulner… |
| CVE-2026-57355 | 6.5 | 22.5 | RadiusTheme | Classified Listing | CWE-862 | WordPress Classified Listing plugin <= 5.4.2 - Broken Access Control vulnerab… |
| CVE-2026-9188 | 5.3 | 22.3 | wappointment | Appointment Bookings for Zoom GoogleMeet and more – Wappointment | CWE-639 | Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - U… |
| CVE-2026-42382 | 8.1 | 21.9 | Elated-Themes | Audrey | CWE-98 | WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability |
| CVE-2026-57268 | 8.3 | 21.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57273 | 8.3 | 21.9 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57274 | 8.3 | 21.9 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57275 | 8.3 | 21.9 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57276 | 8.3 | 21.9 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2025-69134 | 7.5 | 21.6 | Merkulove | OpenAI Chatbot for WordPress – Helper | CWE-862 | WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary C… |
| CVE-2026-57277 | 8.3 | 21.2 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57278 | 8.3 | 21.2 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-12122 | 5.3 | 21.0 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-862 | Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Informat… |
| CVE-2026-57752 | 8.5 | 20.6 | iNET | iNET Webkit | CWE-89 | WordPress iNET Webkit plugin 1.2.4 - SQL Injection vulnerability |
| CVE-2026-54404 | 8.8 | 20.5 | Ubiquiti Inc | UniFi OS Server | CWE-89 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-56841 | 8.8 | 20.5 | Ubiquiti Inc | UniFi Protect Application | CWE-89 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-27060 | 8.8 | 20.4 | Repute Infosystems | ARMember Premium | CWE-502 | WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability |
| CVE-2026-27414 | 8.8 | 20.4 | Fuelthemes | Werkstatt | CWE-502 | WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability |
| CVE-2026-13357 | 4.9 | 20.4 | propertyhive | Houzez Property Feed | CWE-89 | Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection… |
| CVE-2026-57748 | 7.5 | 20.0 | Shopify Help Center | Shopify | CWE-98 | WordPress Shopify plugin <= 1.0.0 - Local File Inclusion vulnerability |
| CVE-2025-58902 | 8.1 | 19.8 | AncoraThemes | Lighthouse | CWE-98 | WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability |
| CVE-2026-27412 | 8.1 | 19.8 | StylemixThemes | Pearl - Corporate Business | CWE-98 | WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion v… |
| CVE-2026-8441 | 7.5 | 19.7 | https://wpreviewslider.com/ | WP Review Slider Pro | CWE-89 | WP Review Slider Pro <= 12.7.2 - Unauthenticated SQL Injection via 'notinstri… |
| CVE-2026-13722 | 8.6 | 19.6 | WatchGuard | Fireware OS | CWE-347 | WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS |
| CVE-2026-54409 | 8.1 | 19.6 | Ubiquiti Inc | UniFi Protect Application | CWE-665 | A malicious actor with access to the network and under certain conditions cou… |
| CVE-2026-11592 | 4.3 | 19.6 | icegram | Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | CWE-862 | Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenti… |
| CVE-2026-54477 | 5.1 | 19.3 | Gardyn | Gardyn Home Firmware | CWE-644 | Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax |
| CVE-2025-69094 | 8.5 | 19.2 | ThemeMove | Unicamp | CWE-89 | WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability |
| CVE-2026-57749 | 7.5 | 19.2 | ThemeBoy | SportsPress Pro | CWE-98 | WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerability |
| CVE-2026-14449 | 6.4 | 19.1 | u5CMS | u5CMS | CWE-79 | POST-based reflected XSS via the thanks parameter in form components |
| CVE-2026-8247 | 7.7 | 19.0 | WatchGuard | Fireware OS | CWE-787 | WatchGuard Firebox admd Out of Bounds Write Vulnerability |
| CVE-2026-10104 | 4.4 | 18.4 | nikhilgadhiya | Product Video Gallery for Woocommerce | CWE-79 | Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manage… |
| CVE-2026-5348 | 5.3 | 18.1 | kodezen | Academy LMS – WordPress LMS Plugin for Complete eLearning Solution | CWE-639 | Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Pr… |
| CVE-2026-53422 | 2.3 | 18.1 | Erlang | OTP | CWE-204 | SFTP REALPATH path-existence oracle allowing filesystem enumeration outside c… |
| CVE-2026-57625 | 9.6 | 18.0 | ASE | Admin and Site Enhancements (ASE) Pro | CWE-79 | WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site … |
| CVE-2026-55114 | 8.8 | 17.9 | Ubiquiti Inc | UniFi Network Application | CWE-284 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-53357 | 8.0 | 17.6 | Linux | Linux | CWE-416 | Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() |
| CVE-2026-39448 | 7.5 | 17.4 | CoderPress | NOWPayments for WooCommerce | CWE-862 | WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control… |
| CVE-2026-57685 | 4.3 | 17.1 | drfuri | Martfury - WooCommerce Marketplace WordPress Theme | CWE-862 | WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 -… |
| CVE-2026-57272 | 8.3 | 17.0 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-50281 | 7.1 | 17.0 | craftcms | cms | CWE-915 | Craft CMS: Mass assignment via id in newAttributes during bulk duplicate over… |
| CVE-2026-57680 | 6.5 | 16.9 | Themeum | Kirki | CWE-639 | WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) v… |
| CVE-2026-9272 | 8.7 | 16.9 | Progress Software | Flowmon ADS | CWE-89 | Possibility of unintended database operations when querying data related to d… |
| CVE-2026-57269 | 8.3 | 16.1 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-59096 | 8.2 | 16.1 | dapr | dapr | CWE-346 | Dapr - OIDC Discovery Issuer and JWKS URI Injection via Unvalidated X-Forward… |
| CVE-2026-27433 | 6.5 | 16.0 | StylemixThemes | Motors | CWE-862 | WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerability |
| CVE-2026-54887 | 6.3 | 15.7 | Erlang | OTP | CWE-1394 | DTLS server cookie bypass during startup window due to empty initial cookie s… |
| CVE-2026-57271 | 8.3 | 15.4 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57679 | 9.3 | 15.3 | Ahmadgb | GeekyBot | CWE-89 | WordPress GeekyBot plugin <= 1.2.5 - SQL Injection vulnerability |
| CVE-2026-57683 | 9.3 | 15.3 | Epsiloncool | WP Fast Total Search | CWE-89 | WordPress WP Fast Total Search plugin <= 1.80.280 - SQL Injection vulnerability |
| CVE-2026-10077 | 6.8 | 15.4 | Unknown | yootheme | — | YOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes |
| CVE-2026-54401 | 8.8 | 15.2 | Ubiquiti Inc | UniFi OS Server | CWE-918 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-59098 | 7.1 | 15.1 | lobehub | lobehub | CWE-639 | LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search |
| CVE-2026-13125 | 8.8 | 15.0 | GeoVision Inc. | GeoWebPlayer | CWE-306 | GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability |
| CVE-2026-52188 | 6.5 | 15.0 | n/a | n/a | CWE-119 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2025-71385 | 5.1 | 14.9 | netdata | netdata | CWE-79 | Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.… |
| CVE-2026-11600 | 4.3 | 14.8 | envothemes | Envo's Templates & Widgets for Elementor and WooCommerce | CWE-862 | Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing … |
| CVE-2026-59095 | 8.3 | 14.7 | lobehub | lobehub | CWE-918 | LobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl |
| CVE-2026-57688 | 8.2 | 14.6 | Gurmehub | POS Entegratör | CWE-862 | WordPress POS Entegratör plugin <= 3.7.103 - Broken Access Control vulnerability |
| CVE-2026-57746 | 7.1 | 14.6 | ThemeREX | Booked | CWE-862 | WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability |
| CVE-2026-13704 | 6.4 | 14.4 | stellarwp | GiveWP – Donation Plugin and Fundraising Platform | CWE-79 | GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting v… |
| CVE-2026-12134 | 4.3 | 14.3 | beardev | JoomSport – for Sports: Team & League, Football, Hockey & more | CWE-862 | JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arb… |
| CVE-2026-14336 | 8.2 | 13.7 | Eclipse Foundation | Eclipse CSI - PIA | CWE-918 | PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix chec… |
| CVE-2026-57267 | 8.3 | 13.4 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57270 | 8.3 | 13.4 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57681 | 6.4 | 13.2 | Paolo | GeoDirectory | CWE-918 | WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF)… |
| CVE-2026-55113 | 7.5 | 13.2 | Ubiquiti Inc | UniFi Talk Application | CWE-918 | A malicious actor with access to the network could exploit a Server-Side Requ… |
| CVE-2026-57689 | 4.3 | 13.0 | Fuelthemes | Werkstatt | CWE-862 | WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability |
| CVE-2026-57730 | 4.3 | 13.0 | UX-themes | Flatsome | CWE-862 | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability |
| CVE-2026-13131 | 8.3 | 12.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-13132 | 8.3 | 12.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57264 | 8.3 | 12.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57265 | 8.3 | 12.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57266 | 8.3 | 12.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-55119 | 8.1 | 12.9 | Ubiquiti Inc | UniFi Talk Application | CWE-284 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-57342 | 6.5 | 12.5 | ShortPixel | ShortPixel Adaptive Images | CWE-79 | WordPress ShortPixel Adaptive Images plugin <= 3.11.3 - Cross Site Scripting … |
| CVE-2026-57354 | 6.5 | 12.5 | Crocoblock. Jetimpex Inc. | JetReviews | CWE-79 | WordPress JetReviews plugin <= 3.0.0.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57687 | 8.5 | 12.0 | Hiroaki Miyashita | Custom Field Template | CWE-89 | WordPress Custom Field Template plugin <= 2.7.8 - SQL Injection vulnerability |
| CVE-2026-57756 | 8.5 | 12.0 | 友人a丶 | nicen-localize-image | CWE-89 | WordPress nicen-localize-image plugin <= 1.4.9 - SQL Injection vulnerability |
| CVE-2026-57765 | 8.5 | 12.0 | Levelfourdevelopment | WP EasyCart | CWE-89 | WordPress WP EasyCart plugin <= 5.9.0 - SQL Injection vulnerability |
| CVE-2026-56842 | 7.5 | 12.0 | Ubiquiti Inc | UniFi Network Application | CWE-863 | A malicious actor with access to the network and under certain conditions cou… |
| CVE-2026-10089 | 6.4 | 11.6 | figureone | Insert Pages | CWE-79 | Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting … |
| CVE-2026-57731 | 6.5 | 11.4 | UX-themes | Flatsome | CWE-862 | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability |
| CVE-2026-12166 | 5.5 | 11.3 | Little Orbit | GameFirst Anti-Cheat | — | CVE-2026-12166 |
| CVE-2025-66076 | 5.3 | 11.2 | dylan ngo | Woostify Sites Library | CWE-862 | WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vuln… |
| CVE-2026-8699 | 7.0 | 11.0 | TP-Link Systems Inc. | Archer C5 v6.8 | CWE-79 | Stored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management Interface |
| CVE-2026-50282 | 4.9 | 11.1 | craftcms | cms | CWE-862 | Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves |
| CVE-2026-55118 | 8.3 | 10.7 | Ubiquiti Inc | UniFi Network Application | CWE-284 | A malicious actor with access to the network,low privileges and under certain… |
| CVE-2026-57352 | 4.8 | 10.7 | VillaTheme | ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce | CWE-1390 | WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce p… |
| CVE-2026-57753 | 5.3 | 10.2 | Nathanbarry | Kit (formerly ConvertKit) for WooCommerce | CWE-497 | WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensiti… |
| CVE-2026-59102 | 2.1 | 10.0 | forgejo | forgejo | CWE-79 | Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering |
| CVE-2026-55112 | 8.8 | 9.9 | Ubiquiti Inc | Dream Machines | CWE-284 | A malicious actor with access to the network and low privileges and under cer… |
| CVE-2026-57348 | 7.2 | 9.7 | Cozmoslabs | Paid Member Subscriptions | CWE-918 | WordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request For… |
| CVE-2026-53358 | 8.8 | 9.6 | Linux | Linux | CWE-667 | Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() |
| CVE-2026-13252 | 6.4 | 9.6 | themeisle | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | CWE-79 | RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross… |
| CVE-2026-11781 | 2.7 | 8.8 | Unknown | Adminify | — | Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global … |
| CVE-2026-27426 | 7.1 | 8.5 | Themesuite | Automotive Car Dealership Business | CWE-79 | WordPress Automotive Car Dealership Business theme <= 13.3.3 - Reflected Cros… |
| CVE-2026-27430 | 7.1 | 8.5 | tranmautritam | TheFox | CWE-79 | WordPress TheFox theme <= 3.9.76 - Reflected Cross Site Scripting (XSS) vulne… |
| CVE-2026-57343 | 7.1 | 8.5 | Contempoinc | Real Estate 7 | CWE-79 | WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57344 | 7.1 | 8.5 | RadiusTheme | Classified Listing | CWE-79 | WordPress Classified Listing plugin <= 5.4.2 - Cross Site Scripting (XSS) vul… |
| CVE-2026-57345 | 7.1 | 8.5 | Webraketen | Internal Links Manager | CWE-79 | WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS)… |
| CVE-2026-57349 | 7.1 | 8.5 | etruel | WPeMatico RSS Feed Fetcher | CWE-79 | WordPress WPeMatico RSS Feed Fetcher plugin <= 2.8.17 - Cross Site Scripting … |
| CVE-2026-57350 | 7.1 | 8.5 | Andy Fragen | WP Debugging | CWE-79 | WordPress WP Debugging plugin <= 2.12.2 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57351 | 7.1 | 8.5 | Haktan Suren | HandL UTM Grabber | CWE-79 | WordPress HandL UTM Grabber plugin <= 2.9.2 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-57356 | 7.1 | 8.5 | Moreconvert Team | MC Woocommerce Wishlist | CWE-79 | WordPress MC Woocommerce Wishlist plugin <= 1.9.19 - Cross Site Scripting (XS… |
| CVE-2026-57357 | 7.1 | 8.5 | Search Atlas Group | Search Atlas SEO | CWE-79 | WordPress Search Atlas SEO plugin <= 2.6.6 - Reflected Cross Site Scripting (… |
| CVE-2026-57358 | 7.1 | 8.5 | SysBasics | Customize My Account for WooCommerce | CWE-79 | WordPress Customize My Account for WooCommerce plugin <= 4.3.9 - Reflected Cr… |
| CVE-2026-57359 | 7.1 | 8.5 | ReviewX | ReviewX | CWE-79 | WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57360 | 7.1 | 8.5 | impleCode | eCommerce Product Catalog | CWE-79 | WordPress eCommerce Product Catalog plugin <= 3.5.4 - Cross Site Scripting (X… |
| CVE-2026-57361 | 7.1 | 8.5 | Ays Pro | Survey Maker | CWE-79 | WordPress Survey Maker plugin <= 5.2.2.5 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57362 | 7.1 | 8.5 | QuantumCloud | ChatBot | CWE-79 | WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vuln… |
| CVE-2026-57366 | 7.1 | 8.5 | Greg Winiarski | WPAdverts | CWE-79 | WordPress WPAdverts plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57426 | 7.1 | 8.5 | Chill Media Labs S.R.L. | Modula - PRO | CWE-79 | WordPress Modula - PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57670 | 7.1 | 8.5 | Codepeople | Google Maps CP | CWE-79 | WordPress Google Maps CP plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57671 | 7.1 | 8.5 | Perfmatters | perfmatters | CWE-79 | WordPress perfmatters plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57672 | 7.1 | 8.5 | Melograno Venture Studio | wpDataTables | CWE-79 | WordPress wpDataTables plugin <= 6.5.1.1 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57673 | 7.1 | 8.5 | Optimole | Optimole | CWE-79 | WordPress Optimole plugin <= 4.2.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57674 | 7.1 | 8.5 | Arraytics | Timetics | CWE-79 | WordPress Timetics plugin <= 1.0.58 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57675 | 7.1 | 8.5 | Jacob N. Breetvelt | WP Photo Album Plus | CWE-79 | WordPress WP Photo Album Plus plugin <= 9.2.02.004 - Cross Site Scripting (XS… |
| CVE-2026-57682 | 7.1 | 8.5 | QuantumCloud | Simple Link Directory | CWE-79 | WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS)… |
| CVE-2026-57686 | 7.1 | 8.5 | WPXPO | WowAddons | CWE-79 | WordPress WowAddons plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-8079 | 8.7 | 8.0 | Progress Software | Flowmon | CWE-863 | Unintended limited set of actions with elevated privileges may be performed d… |
| CVE-2026-58579 | 5.1 | 8.0 | infiniflow | ragflow | CWE-79 | RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name |
| CVE-2026-38972 | 7.8 | 7.9 | n/a | n/a | CWE-427 | Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerabili… |
| CVE-2026-59100 | 2.3 | 7.9 | lobehub | lobehub | CWE-639 | LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Opera… |
| CVE-2026-57750 | 5.3 | 7.7 | Keksdieb | ez Form Calculator Premium | CWE-862 | WordPress ez Form Calculator Premium plugin <= 2.14.1.2 - Broken Access Contr… |
| CVE-2026-57760 | 5.3 | 7.7 | Sendcloud | Sendcloud Shipping | CWE-862 | WordPress Sendcloud Shipping plugin <= 1.0.29 - Broken Access Control vulnera… |
| CVE-2025-69152 | 7.1 | 7.2 | ThemeGoods | Artale | Wedding Photography WordPress | CWE-79 | WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site … |
| CVE-2025-69153 | 7.1 | 7.2 | designthemes | Trendy Travel | CWE-79 | WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) v… |
| CVE-2025-69154 | 7.1 | 7.2 | designthemes | SpaLab | Beauty Salon WordPress Theme | CWE-79 | WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scr… |
| CVE-2025-69155 | 7.1 | 7.2 | Designthemes | Fitness Zone WordPress Theme | CWE-79 | WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (X… |
| CVE-2025-69156 | 7.1 | 7.2 | Design themes | Kids Zone - Children WordPress Theme | CWE-79 | WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scri… |
| CVE-2026-27402 | 7.1 | 7.2 | Designthemes | Kids Life | Children School WordPress | CWE-79 | WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scr… |
| CVE-2026-27404 | 7.1 | 7.3 | Designthemes | LMS | CWE-79 | WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability |
| CVE-2026-27408 | 7.1 | 7.3 | imithemes | NativeChurch | CWE-79 | WordPress NativeChurch theme <= 4.8.8.2 - Reflected Cross Site Scripting (XSS… |
| CVE-2026-27425 | 7.1 | 7.3 | Themesuite | Automotive Listings | CWE-79 | WordPress Automotive Listings plugin <= 18.6 - Reflected Cross Site Scripting… |
| CVE-2026-12167 | 7.8 | 6.8 | Little Orbit | GameFirst Anti-Cheat | — | CVE-2026-12167 |
| CVE-2026-13373 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpa… |
| CVE-2026-13374 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Connect… |
| CVE-2026-13375 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotas… |
| CVE-2026-13376 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlo… |
| CVE-2026-13377 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Pro… |
| CVE-2026-11578 | 2.7 | 6.6 | Unknown | Fluent Forms | — | Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via… |
| CVE-2026-57684 | 6.5 | 6.3 | tranmautritam | TheFox | CWE-79 | WordPress TheFox theme <= 3.9.70 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-11965 | 6.5 | 6.1 | Unknown | User Registration & Membership | — | User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass |
| CVE-2026-12168 | 7.8 | 6.0 | Little Orbit | GameFirst Anti-Cheat | — | CVE-2026-12168 |
| CVE-2026-58653 | 5.3 | 5.5 | PraisonAI | PraisonAI | CWE-639 | PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/U… |
| CVE-2026-58580 | 6.0 | 5.1 | lobehub | lobehub | CWE-639 | LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Wr… |
| CVE-2026-57678 | 7.1 | 4.8 | ThemePunch | Slider Revolution | CWE-79 | WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) … |
| CVE-2026-55110 | 6.1 | 4.5 | Ubiquiti Inc | UniFi OS Server | CWE-942 | A malicious actor who lures an authenticated user to a malicious page could e… |
| CVE-2026-13728 | 5.9 | 4.5 | WatchGuard | Fireware OS | CWE-798 | WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resourc… |
| CVE-2026-8482 | 4.3 | 4.3 | Stormshield | Stormshield Network Security | CWE-532 | Information leak in NSRPC client history |
| CVE-2026-57762 | 5.9 | 4.2 | Andrew Fiebert | Simple URLs | CWE-79 | WordPress Simple URLs plugin <= 151 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57759 | 8.8 | 4.0 | Metagauss | ProfileGrid | CWE-352 | WordPress ProfileGrid plugin <= 5.9.9.7 - CSRF to Account Takeover vulnerability |
| CVE-2026-57766 | 8.8 | 4.0 | XplodedThemes | WPIDE – File Manager & Code Editor | CWE-352 | WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.6 - Cross Site Req… |
| CVE-2026-13079 | 7.3 | 3.9 | WatchGuard | Mobile VPN with SSL Client | CWE-732 | WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation |
| CVE-2026-57751 | 8.1 | 3.8 | Heateor Support | Heateor Social Login | CWE-352 | WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery … |
| CVE-2026-58460 | 7.0 | 3.7 | ajith-ab | react-native-receive-sharing-intent | CWE-22 | react-native-receive-sharing-intent Path Traversal via _display_name |
| CVE-2026-57754 | 6.5 | 3.4 | Livemesh | Livemesh Addons for WPBakery Page Builder | CWE-79 | WordPress Livemesh Addons for WPBakery Page Builder plugin <= 3.9.4 - Cross S… |
| CVE-2026-57755 | 6.5 | 3.4 | Misbah WP | Mosaic Gallery – Advanced Gallery | CWE-79 | WordPress Mosaic Gallery – Advanced Gallery plugin <= 1.2.0 - Cross Sit… |
| CVE-2026-57763 | 6.5 | 3.4 | Gordon Böhme | Structured Content | CWE-79 | WordPress Structured Content plugin <= 1.7.0 - Cross Site Scripting (XSS) vul… |
| CVE-2026-57764 | 6.5 | 3.4 | Surbma | Surbma | Yoast SEO Breadcrumb Shortcode | CWE-79 | WordPress Surbma | Yoast SEO Breadcrumb Shortcode plugin <= 1.2 - Cross Site … |
| CVE-2026-54891 | 6.3 | 3.4 | Erlang | OTP | CWE-924 | Plaintext APPLICATION_DATA injected during TLS handshake delivered to client … |
| CVE-2026-4772 | 5.4 | 3.3 | TR7 Cyber Defense Inc. | WAF-ASP | CWE-79 | Stored XSS in TR7's WAF-ASP |
| CVE-2026-4770 | 4.6 | 3.3 | TR7 Cyber Defense Inc. | WAF-ASP | CWE-79 | DOM-Based XSS in TR7's WAF-ASP |
| CVE-2026-54431 | 5.1 | 2.9 | OpenIDC | liboauth2 | CWE-358 | Improper Data Validation in liboauth2 |
| CVE-2026-57747 | 6.5 | 2.5 | ThemeREX | Booked | CWE-352 | WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerab… |
| CVE-2026-54430 | 5.1 | 2.3 | OpenIDC | liboauth2 | CWE-918 | Server-Site Request Forgery in liboauth2 |
| CVE-2026-58381 | 6.1 | 2.0 | Red Hat | Red Hat Enterprise Linux 6 | CWE-415 | Gimp: gimp: double-free in read_layer_block() |
| CVE-2026-57757 | 7.1 | 1.8 | ploudapp | pCloud WP Backup | CWE-352 | WordPress pCloud WP Backup plugin <= 2.0.2 - Cross Site Request Forgery (CSRF… |
| CVE-2026-13743 | 3.3 | 1.9 | CubeSpace | CW0057 Reaction Wheel | CWE-347 | Improper verification of cryptographic signature in CubeSpace CW0057 Reaction… |
| CVE-2026-57690 | 4.3 | 1.2 | Fuelthemes | Werkstatt | CWE-352 | WordPress Werkstatt theme <= 4.7.2 - Cross Site Request Forgery (CSRF) vulner… |
| CVE-2026-57758 | 7.1 | 0.7 | BeRocket | Permalink Manager for WooCommerce | CWE-352 | WordPress Permalink Manager for WooCommerce plugin <= 1.0.8.2 - CSRF to Store… |
| CVE-2026-57761 | 7.1 | 0.7 | BlueAstralThemes | SEOWP | CWE-352 | WordPress SEOWP theme <= 3.12.2 - CSRF to Stored XSS vulnerability |